Designate a Cybersecurity Responsible Person per NGC 5.260(j) with sufficient authority + qualifications + resources to oversee the cybersecurity programme. May be in-house or contracted. Document appointment in board minutes + bylaws + organisational chart. Provide cybersecurity awareness training to all personnel annually + role-based training for IT staff + privileged users + casino floor staff + customer service staff. Include phishing simulation testing + social engineering awareness + insider threat indicators. Maintain training records for at least 3 years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.