GLI-33 - Gaming Laboratories International Event Wagering Systems
GLI-33: Audit, Significant Event Logging, Information Security, Change Control, Resilience

GLI-33 - Gaming Laboratories International Event Wagering Systems GLI33-Audit-Logging-InfoSec-ChangeControl: GLI-33 Audit, Significant Event Logging, Information Security, Change Control, Resilience

GLI-33 audit + logging + security + change + resilience. SIGNIFICANT EVENT LOGGING: every regulatorily significant event must be logged with timestamp (regulator-time-source-synced typically via NTP + Stratum-1) + actor + action + outcome + correlated session/wager/transaction; events include logon + logoff + admin actions + wager-acceptance/rejection + settlement + payout + change-control + system-start + system-stop + parameter-change + security-event + integrity-event + responsible-gaming-event + AML-event + KYC-failure + geolocation-failure; logs IMMUTABLE (write-once or signed/hashed) + retained per state regulator (typically 5 years) + accessible to regulator on demand. INFORMATION SECURITY: typically per GLI-27 (Standards for Network Security) + ISO 27001 + NIST CSF; specific GLI-33 requirements include (a) encryption at rest + in transit (TLS 1.2+ + AES-256); (b) access control (RBAC + least-privilege + MFA for privileged + privileged-access-management); (c) penetration testing (quarterly external + annual internal); (d) vulnerability management; (e) IDS/IPS + SIEM; (f) endpoint protection; (g) HSM-protected cryptographic keys for wager signing + payment; (h) secure key lifecycle. CHANGE CONTROL: regulator-approved change-management procedure; emergency vs planned changes; software-change submitted to GLI for re-certification when triggering test scope; software signature verification (typically HMAC-SHA-256 + integrity check on every boot/load + tamper-detection); regulator-notification timelines (typically 30 days advance for planned changes + immediate for emergency). DISASTER RECOVERY + BUSINESS CONTINUITY: hot/warm-standby or active-active DR; RTO + RPO defined per regulator + business; tested annually; documentation + procedures; remote DR site geographically separated; data backup + tested-restore + immutable backup against ransomware.

Maintained by Gerard BlokdykControl text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.