Ohio Administrative Code
Title 3772 - Casino Control Commission
Chapter 3772-10 - Internal Control Systems
Section 3772-10-15 - Information technology controls
Current through all regulations passed and filed through September 16, 2024
(A) The casino operator's information technology ("IT") department is responsible for the quality, reliability, accuracy, security, and integrity of all gaming-related computer systems, regardless of the system's location.
(B) Each casino operator must provide hardware and software, approved by the executive director, for the exclusive use of the commission to facilitate access to the casino operator's gaming-related systems from commission offices.
(C) Each casino operator must provide the commission with a comprehensive list of all gaming-related computer systems in a format approved by the executive director. Each casino operator must provide updates to the list as changes occur.
(D) The area where the gaming-related system servers and core components are located must be secured and access restricted to appropriate personnel. Access to the secured area must be logged. The log must be reviewed for accuracy and completion by a member of the IT department at least monthly. At a minimum, the log must include the following information:
(E) Logical access and security measures must be implemented on all gaming-related systems to segregate incompatible functions, prohibit unauthorized access, and prevent loss of data integrity. The measures must include:
(F) Gaming-related system data must be backed-up and recoverable. The back-up and recovery process must be logged.
(G) Gaming-related system security event logs must be monitored and reviewed for suspicious activity and abnormal operation. The commission must be notified upon confirmation of any activity or abnormal operation that results in unauthorized access to, or loss of, gaming-related system data.
(H) Remote access to gaming-related systems may be allowed, but must adhere to the following guidelines:
(I) Each casino operator's internal controls must contain provisions for IT, which include, but are not limited to:
Replaces: 3772-10-15