Implement baseline technical cybersecurity controls including: identity and access management with MFA for privileged access + privileged access management with session recording + just-in-time access + network segmentation isolating gaming systems from corporate IT and patron-facing networks + perimeter and internal firewalls + intrusion detection and prevention systems + encryption of patron + employee + financial data at rest (AES-256) and in transit (TLS 1.3) + key management + vulnerability scanning + patch management (Critical 30 days + High 60 days + Medium 90 days) + security event logging with 1-year online retention + 5-year archive + SIEM aggregation + 24x7 SOC monitoring.
What else in your programme already covers this
This control maps to 106 controls across 63 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.