The venue provides a secure location for wagering equipment (devices, displays, communications) with security policies reviewed periodically so risks are identified, mitigated and covered by contingency plans: equipment is installed to a defined plan with records of every installed unit; sited or protected against environmental threats, unauthorised access, power failures and utility disruptions; accessed by employees only through a secure logon or approved process, with configuration changes impossible without an authorised process; employee sessions are tied to the user account and time out or lock after 5 minutes without input, or the regulator's period; equipment receives regular maintenance, inspection and servicing; and before disposal or reuse, storage media are checked so licensed software, player account information and sensitive data are removed or securely overwritten, not merely deleted.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.