°¨¼ö | Object to be audited in Inspection | ÊøÞÛ
Increase the reliability and stability of printed (produced) lottery tickets by identifying and clearly classifying nonconforming lottery tickets, and check if the printed (produced) lottery tickets meet the target of lottery printing business.
- Log Protection
-
Check List
Main events concerning ticketing must be recorded and maintained
Purpose
To assure that the main log taking place throughout the entire process from registering the production order to the delivery of the lottery, must be safely kept and managed
Audit resources
Procedure
Verification
Document
Log management system, various log analysis materials
Product
Detailed study list and method
- Check if detailed recording is carried out on program user¡¯s login and logoff including game data generation, audit, reconcile, as well as date and time of event
- Check if information on user with special rights is being recorded
- Check if the connected devices and network addresses are being recorded
- Check if modified system setting information is being recorded
- Check if information concerning access to and change in lottery data is being recorded
Check List
Check if management of the log is appropriate.
Purpose
To assure that all created logs must be safely kept and managed to prevent manipulation or loss.
Audit resources
Procedure
Verification
Document
Log Analysis
Product
Detailed study list and method
- Check if log is produced and managed for game data generation, printing machine operation and monitoring equipment, according to organizational policies and the following procedures are followed.
- Check if access control is in place to prevent deletion or modification of log information.
- Check if storage capacity is properly managed to prevent inability to login due to exceeded log file capacity or to prevent data overwriting.
- Check if log is managed from remote system and not local system.
- Check if log information of the game data generation & printing machine system manager and operator us regularly examined.
Check List
Practicability of use of the log in the event of system failure
Purpose
To review whether the log can be used to analyze the cause and to enable trace management in the event of system failure and accident
Audit resources
Procedure
Verification
Document
Log Analysis
Product
Detailed study list and method
- Check if relevant log is examined to resolve problems in the event of system failure.
- Check if all logs and analysis materials recorded during system failure are kept for future reference.
The Criteria to Winner: Security and Risk Management for Printed Lottery by Hyejung Moon is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License.
Based on a work at www.itpolicy.co.kr.
Permissions beyond the scope of this license may be available at http://www.lulu.com.
- reply : 0
-
- list
-
- prev
- next