Skip to content

Evidence request lists

Nevada Gaming Control Board Cybersecurity Requirements

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Audit and Oversight

NGCB-8
Annual Independent Cybersecurity Assessment + Reporting + Board Oversight

Engage independent third-party for annual cybersecurity assessment per NGC 5.260(k) covering the cybersecurity programme effectiveness + risk assessment validation + control testing + compliance with NGC 5.260 + recommendations. Submit summary to NGCB upon request. Report cybersecurity programme status to Board of Directors or equivalent governing body at least annually including: programme status + material matters + risk assessment results + service provider arrangements + testing results + cyber attacks and response + recommendations for material changes. Maintain assessment reports + board minutes for at least 5 years.

Artefacts an auditor will ask for
  • Annual independent assessment report
  • Assessor qualifications and independence
  • Findings + recommendations + remediation plan
  • NGCB submission
  • Annual board report
  • Board meeting minutes
  • 5-year retention archive
Where this commonly fails
  • No independent assessment
  • Assessor lacks independence
  • No board reporting
  • Inadequate retention

Data Protection and Vendor

NGCB-7
Patron and Employee Data Protection + Data Inventory + Vendor Management

Protect patron data + employee data + financial transaction data + responsible gaming data per NGC 5.260(i). Maintain data inventory + classification scheme (confidential + restricted + internal + public) + data flow mapping. Apply Nevada Revised Statutes 603A (Nevada data breach notification law) for breach response including notification to affected residents within 45 days + Office of the Attorney General if 1000+ residents. Manage vendor risk including pre-engagement due diligence + contractual cybersecurity clauses + ongoing assessment + SOC 2 Type II review + termination/exit clauses + return/destruction of data. Apply heightened controls for gaming system integrators + slot machine manufacturers + IT outsourcing.

Artefacts an auditor will ask for
  • Data inventory with classification
  • Data flow maps
  • NRS 603A breach response procedures
  • Vendor inventory
  • Due diligence questionnaires
  • Contractual cyber clauses
  • SOC 2 reports
  • Annual vendor reassessment
Where this commonly fails
  • No data inventory
  • Missing classification
  • No breach response
  • No vendor management

Framework Adoption

NGCB-2
Cybersecurity Best Practices Framework Adoption

Adopt a recognised cybersecurity framework per NGC Regulation 5.260 including NIST Cybersecurity Framework 2.0 + NIST SP 800-53 + ISO 27001/27002 + CIS Controls v8 + PCI DSS 4.0 + FedRAMP + AICPA SOC 2 Type II. Document framework selection rationale + mapping to NGC Regulation 5.260 requirements + annual review of framework currency + cross-framework crosswalk where multiple frameworks adopted (e.g., NIST CSF + PCI DSS for payment processing).

Artefacts an auditor will ask for
  • Selected framework documentation
  • Selection rationale
  • NGC 5.260 to framework crosswalk
  • Annual framework currency review
  • Multi-framework crosswalk where applicable
Where this commonly fails
  • No documented framework
  • Outdated framework version
  • Missing crosswalk
  • No annual review

Incident Response

NGCB-6
Incident Response, 72-Hour NGCB Notification, and Independent Investigation

Maintain a written Incident Response Plan covering preparation + identification + containment + eradication + recovery + lessons learned per NGC 5.260(g) and (h). Conduct annual tabletop exercises + post-incident root cause analysis + lessons learned within 90 days. Notify the Nevada Gaming Control Board within 72 hours of confirming a Cyber Attack per NGC 5.260(h) using NGCB Cyber Attack Notification Form. Engage independent third-party investigator for Cyber Attacks with material impact. Coordinate with FBI + Secret Service + CISA + Information Sharing and Analysis Center for Gaming (G-ISAC) + Multi-State Information Sharing and Analysis Center (MS-ISAC) as appropriate.

Artefacts an auditor will ask for
  • Written IR Plan
  • Annual tabletop exercise reports
  • NGCB Cyber Attack Notification Form readiness
  • Independent investigator engagement letter
  • FBI/Secret Service/CISA liaison
  • G-ISAC + MS-ISAC membership
  • Lessons learned within 90 days
Where this commonly fails
  • No written IR Plan
  • Missed 72-hour notification
  • No independent investigation
  • Missing federal coordination

Personnel and Training

NGCB-4
Designated Cybersecurity Officer and Personnel Training

Designate a Cybersecurity Responsible Person per NGC 5.260(j) with sufficient authority + qualifications + resources to oversee the cybersecurity programme. May be in-house or contracted. Document appointment in board minutes + bylaws + organisational chart. Provide cybersecurity awareness training to all personnel annually + role-based training for IT staff + privileged users + casino floor staff + customer service staff. Include phishing simulation testing + social engineering awareness + insider threat indicators. Maintain training records for at least 3 years.

Artefacts an auditor will ask for
  • Designated Cyber Person appointment letter
  • Officer qualifications + CV
  • Authority and resource documentation
  • Annual training completion records
  • Role-based training records
  • Phishing simulation results
  • 3-year training retention
Where this commonly fails
  • No designated officer
  • Officer lacks authority
  • Missing annual training
  • No phishing simulation

Risk Management

NGCB-3
Risk Assessment, Risk Management, and Ongoing Risk Monitoring

Conduct initial cybersecurity risk assessment per NGC 5.260(d) including identification of internal and external risks to the gaming system + supporting infrastructure + patron data + employee data + financial data + intellectual property. Reassess annually and upon material change. Implement ongoing risk monitoring per 5.260(f). Document risk treatment decisions (accept + mitigate + transfer + avoid) + risk register + risk acceptance by Designated Cybersecurity Responsible Person + reporting to executive management quarterly.

Artefacts an auditor will ask for
  • Initial risk assessment report
  • Annual reassessment
  • Ongoing monitoring evidence
  • Risk register with treatment decisions
  • Quarterly risk reports to executive management
  • Risk acceptance by Designated Cyber Person
Where this commonly fails
  • No initial assessment
  • Stale reassessment
  • No ongoing monitoring
  • Missing executive reporting

Scope and Applicability

NGCB-1
Regulation 5.260 Scope, Applicability, and Licensee Categories

Comply with Nevada Gaming Commission Regulation 5.260 Cybersecurity Best Practices effective 31 December 2022 + amended subsequent years + applies to: Group I non-restricted licensees (annual gaming revenue USD 10 million+) + Group II non-restricted licensees (USD 2 million to 10 million) + service providers + manufacturers + interactive gaming licensees + sportsbook operators. Confirm Nevada Gaming Control Board (NGCB) regulatory jurisdiction + coordinate with Nevada Gaming Commission (NGC) policy adoption + Gaming Control Board Chair (Kirk Hendrick since 2023) + Nevada Gaming Commission Chair (Jennifer Togliatti since 2021).

Artefacts an auditor will ask for
  • Licensee classification determination
  • Gaming license documentation
  • Annual revenue determination
  • NGCB jurisdiction confirmation
  • Annual compliance attestation
  • Service provider/manufacturer status documentation
Where this commonly fails
  • Misclassified licensee group
  • No NGCB jurisdiction confirmation
  • Stale compliance attestation

Technical Controls

NGCB-5
Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging

Implement baseline technical cybersecurity controls including: identity and access management with MFA for privileged access + privileged access management with session recording + just-in-time access + network segmentation isolating gaming systems from corporate IT and patron-facing networks + perimeter and internal firewalls + intrusion detection and prevention systems + encryption of patron + employee + financial data at rest (AES-256) and in transit (TLS 1.3) + key management + vulnerability scanning + patch management (Critical 30 days + High 60 days + Medium 90 days) + security event logging with 1-year online retention + 5-year archive + SIEM aggregation + 24x7 SOC monitoring.

Artefacts an auditor will ask for
  • MFA deployment evidence
  • PAM solution + session recording
  • Network segmentation diagram
  • Encryption inventory (at rest + in transit)
  • Vulnerability scan reports with SLA tracking
  • SIEM logs with retention
  • 24x7 SOC roster
Where this commonly fails
  • MFA gaps on privileged accounts
  • No segmentation
  • Patches over SLA
  • Inadequate log retention
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nevada Gaming Control Board Cybersecurity Requirements framework page.