GLI-33 - Gaming Laboratories International Event Wagering Systems
Appendix B: Operational audit for technical security controls (system operation and security, backup and recovery, communications, third parties, technical controls, remote access and firewalls, change management, security testing) – GLI-33 - Gaming Laboratories International Event Wagering Systems

GLI-33 - Gaming Laboratories International Event Wagering Systems B.6.2: B.6.2 Cryptographic Controls

A cryptographic controls policy is developed and implemented: player data and sensitive information are encrypted when crossing a network of lower trust; data that need not be hidden but must be authenticated uses message authentication; authentication uses a certificate from an approved organisation; the encryption grade matches the data's sensitivity; algorithms are reviewed periodically for continued security; weaknesses are corrected as soon as practical or the algorithm replaced; and keys are stored on secure redundant media after being encrypted by a different method or key.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Appendix B: Operational audit for technical security controls (system operation and security, backup and recovery, communications, third parties, technical controls, remote access and firewalls, change management, security testing) – GLI-33 - Gaming Laboratories International Event Wagering Systems

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.