11 CSR 45-20.300
Integrity and Security Assessment
PURPOSE: This rule establishes standards for integrity and security
assessments.
(1) Each Retail and Mobile licensee shall ensure a system
integrity and security assessment of sports wagering systems
and online sports wagering platforms is conducted by an
independent security assessment professional within ninety
(90) days of commencing operations, and annually thereafter.
(2) The scope of the assessment shall include, at a minimum,
the following:
(A) A vulnerability assessment of the online sports wagering
platform, sports wagering system, internal, external, and
wireless networks with the intent of identifying vulnerabilities
of all devices, platforms, and applications connected to or
present on the networks;
(B) A penetration test of all online sports wagering platforms,
sports wagering systems, internal, external, and wireless
networks to confirm if identified vulnerabilities of all devices,
platforms, and applications are susceptible to compromise;
(C) A policy and procedures review against the current International Organization for Standardization (ISO) 27001 standard
or another similar standard approved by the commission;
(D) A review of the firewall rules to verify the operating
condition of the firewall and the effectiveness of its security
configuration; and
(E) Any other specific criteria or standards for the integrity
and security assessment that align with industry best practices
as requested by the commission to ensure the integrity of the
sports wagering operation.
(3) The independent security assessment professional’s report
on the assessment shall be submitted to the commission and
shall include—
(A) Assessment procedures and scope of the review;
(B) Name and company affiliation of the individual(s) who
conducted the assessment;
(C) Date of assessment;
(D) Findings;
(E) Recommended corrective action, if applicable; and
(F) The licensee’s response to the findings and recommended
corrective action.
(4) The independent security assessment professional’s report
on the assessment shall be submitted to the commission
within sixty (60) days after the conclusion of the integrity and
security assessment.
AUTHORITY: section 39(g) of Article III, Mo. Const., section 313.004,
RSMo 2016, and sections 313.800–313.850, RSMo 2016 and Supp.
2025.* Original rule filed May 14, 2025, effective Nov. 30, 2025.
*Original authority: 313.004, RSMo 1993, amended 1994, 2014, and 313.800-313.850,
see Revised Statutes of Missouri, 2016 and Supp. 2025.