Object to be audited in Actual Printing
Ensure that the printing business meets the target, by verifying the quality of test lottery tickets and producing lottery tickets meeting the requirements of the production order.
- Lottery printing related system Security
-
Check List
Check if security review procedures are carried out at introduction of lottery production system (game data generation program, printing machine, other security devices)
Purpose
To check if security review by internal and external security specialists is being conducted at the introduction of lottery production system. Here, the internal security specialist means the computer personnel in charge, and external security specialists denote LOTTERY ORGANIZATION, auditor, and security consultants
Audit resources
Procedure
Verification
Document
Equipment list, Maintenance and repair register, various system introduction documents and contracts, proposals, etc.
Product
Detailed study list and method
- Check if the list of security-related items for checking at the introduction of instant lottery ticketing system or upgrading is stipulated
- Check if testing is carried out on items for checking prior to introduction
Check List
Check if a countermeasure for a malicious code is implemented
Purpose
To check if a countermeasure against virus, worm, spy-ware, add-ware and other malicious code is in operation. Even if a closed network or stand-alone system, virus may come through mobile storage devices, hence a relevant countermeasure must be in place.
Audit resources
Procedure
Verification
Document
Vaccine program purchase invoice and contract, license documents, other anti spy-ware documents
Product
Detailed study list and method
- Check if a vaccine program is installed and periodic checking and update is carried out
- Check if anti spy-ware is installed and periodic checking and update is carried out
Check List
Check if the necessary patches are installed in timely manner
Purpose
To check if appropriate patches are taking place on operating system and system software
Audit resources
Procedure
Verification
Document
Patch-related document
Product
Detailed study list and method
- Check if the system, capable of enabling the manager to apply the central policy, is equipped
- Check if procedures concerning the application of security patches are established
- Check if automatic patch installation is being carried out
- Check if systems without patches are isolated from the network (optional)
- Check if user is checking before the installation when Active X or Java Aplet is run
- Check if the installation of execute programs is controlled by the central system
The Criteria to Winner: Security and Risk Management for Printed Lottery by Hyejung Moon is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License.
Based on a work at www.itpolicy.co.kr.
Permissions beyond the scope of this license may be available at http://www.lulu.com.
- reply : 0
-
- list
-
- prev
- next