Conduct initial cybersecurity risk assessment per NGC 5.260(d) including identification of internal and external risks to the gaming system + supporting infrastructure + patron data + employee data + financial data + intellectual property. Reassess annually and upon material change. Implement ongoing risk monitoring per 5.260(f). Document risk treatment decisions (accept + mitigate + transfer + avoid) + risk register + risk acceptance by Designated Cybersecurity Responsible Person + reporting to executive management quarterly.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.