205 CMR 141.09
Access to the Monitoring Room
A surveillance plan must provide for limited access to the monitoring room which, at a
minimum, shall include:
(1) That the entrances to the monitoring room not be visible from the gaming area or any other
public area;
(2) Identification by position of each employee allowed access to the monitoring room or any
other designated area capable of receiving CCTV transmission. Any person who enters any
monitoring room or such designated area, who is not a surveillance department employee, shall
sign the Monitoring Room Entry Log upon entering the restricted area. The Monitoring Room
Entry Log shall be:
(a) Kept in the CCTV monitoring room;
(b) Maintained in a book with bound numbered pages that cannot be readily removed or via
an electronic equivalent;
(c) Signed by each person whose presence is not expressly authorized in accordance with
205 CMR 141.09(2), with each entry containing, at a minimum, the following information:
1. The date and time of entering into the monitoring room or designated area;
2. The entering person’s name and his or her department or affiliation;
3. The reason for entering the monitoring room or designated area;
4. The name of the person authorizing the person’s entry into the monitoring room or
designated area; and
5. The date and time of exiting the monitoring room or designated area.
(3) The Monitoring Room Entry Log shall be made available for inspection by the Commission
at all times.
(4) For server based monitoring systems, a plan for restricting access to monitoring and
recording by unauthorized personnel such as IT personnel and members of management.
(5) All servers and related equipment associated with the surveillance system shall be under
control of the surveillance department.
(6) There shall be limited access to the surveillance server equipment. Notification in writing
shall be made to the on-site IEB in advance of any outside vendor having access to the
surveillance system. Emergency service access notification may be made via telephone to the
on-site IEB, but shall be followed up with notification in writing as to the nature of the
emergency. An electronic log shall be generated for any remote access into the system. The log
entries shall contain the name of the person and company accessing the system, their license or
registration number, the identity of the individual authorizing the access, the access method, the
reason for access, the date of the access, and the time access was started and ended.