GLI-33 - Gaming Laboratories International Event Wagering Systems
Appendix B: Operational audit for technical security controls (system operation and security, backup and recovery, communications, third parties, technical controls, remote access and firewalls, change management, security testing) – GLI-33 - Gaming Laboratories International Event Wagering Systems

GLI-33 - Gaming Laboratories International Event Wagering Systems B.2.3: B.2.3 Logical Access Control

The system is logically secured by authentication credentials the regulator allows (passwords, multi-factor, certificates, PINs, biometrics, cards): each user has an individual credential issued through a formal process; credential records are kept and changes forced; stored credentials are secure and any hard-coded credentials are encrypted; the fallback for failed authentication is no weaker than the main method; lost, compromised and terminated users' credentials are deactivated promptly; multiple access levels control viewing, changing and deleting critical files, with procedures to assign, review, modify and remove rights that provide separation of duties, limit who can adjust critical parameters and enforce credential length and expiry; suspect accounts with possibly stolen credentials are identified and flagged; every logical access attempt to applications or operating systems is logged securely; and utility programs that can override controls are restricted; passwords are recommended to change every 90 days, be at least 8 characters and mix two character classes.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • MICS-IT-7 IT MICS #7 Logical security and password parameters

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Appendix B: Operational audit for technical security controls (system operation and security, backup and recovery, communications, third parties, technical controls, remote access and firewalls, change management, security testing) – GLI-33 - Gaming Laboratories International Event Wagering Systems

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.