±âȹ¡¤Á¶Á÷ | Object to be audited in Plan and Organization | 计划 & 组织
Check whether the target and scope of the lottery printing business are understood and defined clearly in terms of management of instant lottery based developing business and there is any risk.
- Access Control Policy [2]
-
Check List
Access control according to the necessary business authority
Purpose
To check if an access to ticketing-related information assets is appropriately restricted according to functions and responsibilities of the staff & third party personnel associated with instant lottery ticketing.
Audit resources
Procedure
Verification
Document
Access Control Policy Guide, Access Rights Plan
Product
Detailed study list and method
- Check if an access control policy is established according to the levels of information assets related to ticketing
- Clearly stated roles and access rights according to user classification
- Establishment of registration and deletion procedure for information system users
- Modification/deletion of information on user rights at the time of staff transfer or resignation
- Documentation of a special user¡¯s work and a periodical check of the documentation.
Check List
Remote user access management
Purpose
To ensure authorized remote user access and to prevent unauthorized access to gaming information systems.
Audit resources
Procedure
Verification
Document
Product
Detailed study list and method
- Check if gaming systems are accessed from locations under control of lottery organization, excluding player participation in organization-offered games, in case of accident.
- Check if the functional area is defined in conjunction with the process owner and manager, function of security and IT
- Check if all activities about user access are logged, reported and reviewed.
- Check every remote user access a security incident refection.
The Criteria to Winner: Security and Risk Management for Printed Lottery by Hyejung Moon is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License.
Based on a work at www.itpolicy.co.kr.
Permissions beyond the scope of this license may be available at http://www.lulu.com.
- reply : 2
-
JINNY 10-10-07 23:46
-
ÀڷḦ ÆíÁýÇÒ¶§¸¶´Ù <br>űװ¡ 2¹è·Î ´Ã¾î³ª³×?
Áø¼ö°¡ °íÃ帴ø°¡ ¾Æ´Ï¸é ¹ÚÁ¤ÈÆ[010-6614-5675]¾¾¿¡°Ô ¿¬¶ôÇØº¸¼¼¿ä
±×¸®°í ¸ðµÎ ¿ÞÂÊ Á¤·Ä ºÎŹÇÕ´Ï´Ù.
-
JINNY 10-10-07 23:48
-
¿ÞÂÊÁ¤·ÄÀº ¾Æ¹«·¡µµ ½ºÅ¸ÀÏ·Î »çÀüÁ¤Àǵȵí
ÀÏ´Ü ccl »ðÀÔ°ú brÅÂ±× Áߺ¹ ÇØ°áÇØº¸¼¼¿ä.
-
- list
-
- prev
- next