The operator documents and follows system procedures that at least cover monitoring of the critical components and data transmissions of the whole system including communications, packets, networks and any third-party services, for integrity, reliability and accessibility; maintenance of every aspect of system security including protection from hacking and tampering; defining security incidents (breaches among them) and monitoring, recording, reporting, investigating, answering and closing them, including breaches and suspected hacking; monitoring and adjusting resource consumption with a performance log and reports; and investigating, documenting and resolving malfunctions by determining the cause, reviewing records, reports, logs and surveillance, repairing or replacing the component, verifying its integrity before restoring it, sending the regulator an incident report that records date, time, reason and restoration time, and voiding or cancelling wagers and pays where full recovery is impossible.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.