11 CSR 45-20.300

Integrity and Security Assessment

Last amended: 2025Year: 2026Length: 355 wordsOfficial source
PURPOSE: This rule establishes standards for integrity and security assessments. (1) Each Retail and Mobile licensee shall ensure a system integrity and security assessment of sports wagering systems and online sports wagering platforms is conducted by an independent security assessment professional within ninety (90) days of commencing operations, and annually thereafter. (2) The scope of the assessment shall include, at a minimum, the following: (A) A vulnerability assessment of the online sports wagering platform, sports wagering system, internal, external, and wireless networks with the intent of identifying vulnerabilities of all devices, platforms, and applications connected to or present on the networks; (B) A penetration test of all online sports wagering platforms, sports wagering systems, internal, external, and wireless networks to confirm if identified vulnerabilities of all devices, platforms, and applications are susceptible to compromise; (C) A policy and procedures review against the current International Organization for Standardization (ISO) 27001 standard or another similar standard approved by the commission; (D) A review of the firewall rules to verify the operating condition of the firewall and the effectiveness of its security configuration; and (E) Any other specific criteria or standards for the integrity and security assessment that align with industry best practices as requested by the commission to ensure the integrity of the sports wagering operation. (3) The independent security assessment professional’s report on the assessment shall be submitted to the commission and shall include— (A) Assessment procedures and scope of the review; (B) Name and company affiliation of the individual(s) who conducted the assessment; (C) Date of assessment; (D) Findings; (E) Recommended corrective action, if applicable; and (F) The licensee’s response to the findings and recommended corrective action. (4) The independent security assessment professional’s report on the assessment shall be submitted to the commission within sixty (60) days after the conclusion of the integrity and security assessment. AUTHORITY: section 39(g) of Article III, Mo. Const., section 313.004, RSMo 2016, and sections 313.800–313.850, RSMo 2016 and Supp. 2025.* Original rule filed May 14, 2025, effective Nov. 30, 2025. *Original authority: 313.004, RSMo 1993, amended 1994, 2014, and 313.800-313.850, see Revised Statutes of Missouri, 2016 and Supp. 2025.
11 CSR 45-20.300: Integrity and Security Assessment | Justis AI