Remote licensees must apply the RTS security requirements, drawn from ISO/IEC 27001:2022 Annex A controls (security policies, access and identity management, supplier and cloud security, incident management, awareness, remote working, equipment and media protection, endpoint, privileged access, malware, backup, logging, clock synchronisation, network security and segregation, cryptography, secure development and testing, environment separation and change management), to critical systems: those handling sensitive customer data, random number generation, game results and state, their entry and exit points and the networks carrying customer data. Remote betting, casino, bingo, host and larger lottery licences need a full security audit by an independent auditor under the testing strategy.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.