Connecticut Administrative Code
Title 12 - Taxation
865 - Online Casino Gaming, Retail and Online Sports Wagering, Fantasy Contests, Keno and Online Sale of Lottery Tickets
Section 12-865-33 - Cybersecurity
Current through September 9, 2024
(a) Each gaming entity licensee shall maintain a cybersecurity program designed to protect the confidentiality, integrity and availability of the electronic wagering platform and a gaming entity licensee's associated information systems.
(b) The cybersecurity program shall be based on a risk assessment and designed to perform the following core cybersecurity functions as outlined under the NIST Cybersecurity Framework 1.1, or other requirements set forth by the department under section 12-865-3(n) of the Regulations of Connecticut State Agencies, including:
(c) All documentation and information relevant to the gaming entity licensee's cybersecurity program shall be made available to the department upon request.
(d) The cybersecurity program for each gaming entity licensee shall include monitoring and testing, developed in accordance with the gaming entity licensee's risk assessment, designed to assess the effectiveness of the gaming entity licensee's cybersecurity program. The monitoring and testing shall include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent effective continuous monitoring, or other systems to detect, on an ongoing basis, changes in information systems that may create or indicate vulnerabilities, gaming entity licensees shall conduct:
(e) Each gaming entity licensee shall securely maintain systems that, to the extent applicable and based on its risk assessment:
(f) As part of its cybersecurity program, based on the gaming entity licensee's risk assessment, each gaming entity licensee shall limit user access privileges to information systems that provide access to nonpublic information and shall periodically review such access privileges.
(g) As part of its cybersecurity program, each gaming entity licensee shall include policies and procedures for the secure deletion on a periodic basis of any patron information that is no longer necessary for business operations or for other legitimate business purposes of the gaming entity licensee, except where such information is otherwise required to be retained by law or regulation.
(h) Each gaming entity licensee shall implement controls, including encryption, to protect patron information and other nonpublic information held or transmitted by the gaming entity licensee both in transit over external networks and at rest.
(i) As part of its cybersecurity program, each gaming entity licensee shall establish a written incident response plan designed to promptly respond to, and recover from, any cybersecurity event materially affecting the confidentiality, integrity or availability of the gaming entity licensee's information systems or the continuing functionality of any aspect of the gaming entity licensee's business or operations. Such incident response plan shall address the following areas: