Nevada Gaming Control Board Cybersecurity Requirements
Technical Controls

Nevada Gaming Control Board Cybersecurity Requirements NGCB-5: Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging

Implement baseline technical cybersecurity controls including: identity and access management with MFA for privileged access + privileged access management with session recording + just-in-time access + network segmentation isolating gaming systems from corporate IT and patron-facing networks + perimeter and internal firewalls + intrusion detection and prevention systems + encryption of patron + employee + financial data at rest (AES-256) and in transit (TLS 1.3) + key management + vulnerability scanning + patch management (Critical 30 days + High 60 days + Medium 90 days) + security event logging with 1-year online retention + 5-year archive + SIEM aggregation + 24x7 SOC monitoring.

What else in your programme already covers this

This control maps to 106 controls across 63 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29134:2023 · 3 controls

API 1164 · 2 controls

IEEE 1686 · 2 controls

ISO/IEC 27014:2020 · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MARS-E · 1 control

MTCS (Singapore) · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • 3.11 Encrypt Sensitive Data at Rest
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

South Korea PIPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 106 it maps to, and the evidence behind each claim, over MCP and REST.