Nevada Gaming Control Board Cybersecurity Requirements
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Audit and Oversight
Engage independent third-party for annual cybersecurity assessment per NGC 5.260(k) covering the cybersecurity programme effectiveness + risk assessment validation + control testing + compliance with NGC 5.260 + recommendations. Submit summary to NGCB upon request. Report cybersecurity programme status to Board of Directors or equivalent governing body at least annually including: programme status + material matters + risk assessment results + service provider arrangements + testing results + cyber attacks and response + recommendations for material changes. Maintain assessment reports + board minutes for at least 5 years.
- Annual independent assessment report
- Assessor qualifications and independence
- Findings + recommendations + remediation plan
- NGCB submission
- Annual board report
- Board meeting minutes
- 5-year retention archive
- No independent assessment
- Assessor lacks independence
- No board reporting
- Inadequate retention
Data Protection and Vendor
Protect patron data + employee data + financial transaction data + responsible gaming data per NGC 5.260(i). Maintain data inventory + classification scheme (confidential + restricted + internal + public) + data flow mapping. Apply Nevada Revised Statutes 603A (Nevada data breach notification law) for breach response including notification to affected residents within 45 days + Office of the Attorney General if 1000+ residents. Manage vendor risk including pre-engagement due diligence + contractual cybersecurity clauses + ongoing assessment + SOC 2 Type II review + termination/exit clauses + return/destruction of data. Apply heightened controls for gaming system integrators + slot machine manufacturers + IT outsourcing.
- Data inventory with classification
- Data flow maps
- NRS 603A breach response procedures
- Vendor inventory
- Due diligence questionnaires
- Contractual cyber clauses
- SOC 2 reports
- Annual vendor reassessment
- No data inventory
- Missing classification
- No breach response
- No vendor management
Framework Adoption
Adopt a recognised cybersecurity framework per NGC Regulation 5.260 including NIST Cybersecurity Framework 2.0 + NIST SP 800-53 + ISO 27001/27002 + CIS Controls v8 + PCI DSS 4.0 + FedRAMP + AICPA SOC 2 Type II. Document framework selection rationale + mapping to NGC Regulation 5.260 requirements + annual review of framework currency + cross-framework crosswalk where multiple frameworks adopted (e.g., NIST CSF + PCI DSS for payment processing).
- Selected framework documentation
- Selection rationale
- NGC 5.260 to framework crosswalk
- Annual framework currency review
- Multi-framework crosswalk where applicable
- No documented framework
- Outdated framework version
- Missing crosswalk
- No annual review
Incident Response
Maintain a written Incident Response Plan covering preparation + identification + containment + eradication + recovery + lessons learned per NGC 5.260(g) and (h). Conduct annual tabletop exercises + post-incident root cause analysis + lessons learned within 90 days. Notify the Nevada Gaming Control Board within 72 hours of confirming a Cyber Attack per NGC 5.260(h) using NGCB Cyber Attack Notification Form. Engage independent third-party investigator for Cyber Attacks with material impact. Coordinate with FBI + Secret Service + CISA + Information Sharing and Analysis Center for Gaming (G-ISAC) + Multi-State Information Sharing and Analysis Center (MS-ISAC) as appropriate.
- Written IR Plan
- Annual tabletop exercise reports
- NGCB Cyber Attack Notification Form readiness
- Independent investigator engagement letter
- FBI/Secret Service/CISA liaison
- G-ISAC + MS-ISAC membership
- Lessons learned within 90 days
- No written IR Plan
- Missed 72-hour notification
- No independent investigation
- Missing federal coordination
Personnel and Training
Designate a Cybersecurity Responsible Person per NGC 5.260(j) with sufficient authority + qualifications + resources to oversee the cybersecurity programme. May be in-house or contracted. Document appointment in board minutes + bylaws + organisational chart. Provide cybersecurity awareness training to all personnel annually + role-based training for IT staff + privileged users + casino floor staff + customer service staff. Include phishing simulation testing + social engineering awareness + insider threat indicators. Maintain training records for at least 3 years.
- Designated Cyber Person appointment letter
- Officer qualifications + CV
- Authority and resource documentation
- Annual training completion records
- Role-based training records
- Phishing simulation results
- 3-year training retention
- No designated officer
- Officer lacks authority
- Missing annual training
- No phishing simulation
Risk Management
Conduct initial cybersecurity risk assessment per NGC 5.260(d) including identification of internal and external risks to the gaming system + supporting infrastructure + patron data + employee data + financial data + intellectual property. Reassess annually and upon material change. Implement ongoing risk monitoring per 5.260(f). Document risk treatment decisions (accept + mitigate + transfer + avoid) + risk register + risk acceptance by Designated Cybersecurity Responsible Person + reporting to executive management quarterly.
- Initial risk assessment report
- Annual reassessment
- Ongoing monitoring evidence
- Risk register with treatment decisions
- Quarterly risk reports to executive management
- Risk acceptance by Designated Cyber Person
- No initial assessment
- Stale reassessment
- No ongoing monitoring
- Missing executive reporting
Scope and Applicability
Comply with Nevada Gaming Commission Regulation 5.260 Cybersecurity Best Practices effective 31 December 2022 + amended subsequent years + applies to: Group I non-restricted licensees (annual gaming revenue USD 10 million+) + Group II non-restricted licensees (USD 2 million to 10 million) + service providers + manufacturers + interactive gaming licensees + sportsbook operators. Confirm Nevada Gaming Control Board (NGCB) regulatory jurisdiction + coordinate with Nevada Gaming Commission (NGC) policy adoption + Gaming Control Board Chair (Kirk Hendrick since 2023) + Nevada Gaming Commission Chair (Jennifer Togliatti since 2021).
- Licensee classification determination
- Gaming license documentation
- Annual revenue determination
- NGCB jurisdiction confirmation
- Annual compliance attestation
- Service provider/manufacturer status documentation
- Misclassified licensee group
- No NGCB jurisdiction confirmation
- Stale compliance attestation
Technical Controls
Implement baseline technical cybersecurity controls including: identity and access management with MFA for privileged access + privileged access management with session recording + just-in-time access + network segmentation isolating gaming systems from corporate IT and patron-facing networks + perimeter and internal firewalls + intrusion detection and prevention systems + encryption of patron + employee + financial data at rest (AES-256) and in transit (TLS 1.3) + key management + vulnerability scanning + patch management (Critical 30 days + High 60 days + Medium 90 days) + security event logging with 1-year online retention + 5-year archive + SIEM aggregation + 24x7 SOC monitoring.
- MFA deployment evidence
- PAM solution + session recording
- Network segmentation diagram
- Encryption inventory (at rest + in transit)
- Vulnerability scan reports with SLA tracking
- SIEM logs with retention
- 24x7 SOC roster
- MFA gaps on privileged accounts
- No segmentation
- Patches over SLA
- Inadequate log retention
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nevada Gaming Control Board Cybersecurity Requirements framework page.