Current through Register Vol. XLI, No. 50, December 13, 2024
Section 179-10-16 - Access to equipment16.1. The interactive gaming operator or MSP shall limit and control access to the primary servers and any secondary servers by ensuring all of the following controls are implemented: 16.1.1. Maintain access codes and other computer security controls; 16.1.2. Maintain logs of user access, security incidents, and unusual events; 16.1.3. Coordinate and develop an education and training program on information security and privacy matters for employees and other authorized users; 16.1.4. Ensure compliance with all state and federal information security policies and rules; 16.1.5. Prepare and maintain security-related reports and data; 16.1.6. Develop and implement an incident reporting and response system to address security breaches and policy violations; and 16.1.7. Develop and implement an ongoing risk assessment program that targets information security and privacy matters by identifying methods for vulnerability detection and remediation. 16.2. Remote access to an interactive gaming system is only permitted as follows: 16.2.1. For the Director upon request and without limitation; 16.2.2. For testing purposes with prior approval and as limited by the Director; and, 16.2.3. By employees of an interactive gaming license holder with prior approval from and as limited by the Director. 16.3. All interactive gaming systems must be available for independent testing as directed by the Commission without limitation. W. Va. Code R. § 179-10-16