1 gaming, privacy and security egaming experience in british columbia british columbia lottery...

15
1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal Audit

Upload: tobias-norris

Post on 26-Dec-2015

217 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

1

Gaming, Privacy and SecurityeGaming Experience in British Columbia

British Columbia Lottery Corporation

October 5, 2013

Gurmit Aujla – Director, Internal Audit

Page 2: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

22

PlayNow.Com TimelineLaunch

PlayNow.com July 2010 Mobile

June 2013

PokerFebruary 2011

SportsJuly 2012

Lottery B2B August 2013

Casino B2BJanuary 2013

Page 3: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

33

Old World – Ways to Play

Page 4: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

44

Page 7: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

77

Top 5 Risk Areas

Information Security & Privacy

Regulatory Compliance

Infrastructure

Vendors

Public Support (Integrity)

Page 8: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

88

Manitoba & Western Canada Concern Areas

Contract compliance, SLA's

Regulatory – multiple jurisdictions

Gaming integrity

Communication Risks

Availability

Page 9: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

99

Governance Participants (Internal Vs. External)

eGaming SecurityeGaming Security

Information Security

Information Security

Audit ServicesAudit Services

Regulator (GPEB)Regulator (GPEB)External AuditorExternal Auditor

Steering CommitteeSteering

Committee

eGaming Oversight

BCLC

Page 10: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

1010

Assurance MapAssurance Coverage Map (Internal) – eGaming Key Risk AreasDepartment Sub-Department Key Business Process eSec. Int. Audit Info Sec. Regulator Ext. Audit

eGaming Marketing

eGaming Operations

eGaming Security

eGaming Business Development Responsible Gambling

   

Detailed data redacted

Page 11: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

1111

What our B2B customer wantedAssurance Coverage Map (External) – eGaming Key Risk Areas

CoverageWhat our Customer

cares about External Auditor Regulator

SOC1

IT General Controls

Product Certification    

Change Management Controls   

IT Security      

     

 

 

Detailed data redacted

Detailed data redacted

Page 12: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

1212

Example Only

New World ReportingControl Areas Status

Executive Dashboard

PlayNow Continuous Monitoring

eSecurity

Internal Assurance

External Assurance

eGaming Risk Registry & Risk Coverage

  

  

  

  

 

  

 

 

 

 

 

  

  

  

  

 

  

 

 

 

  

  

  

  

  

 

  

 

 

 

 

 

  

  

  

  

 

  

 

 

 

  

  

  

  

  

 

  

 

 

 

  

   

   

    

  

  

 

 

 

  

Page 13: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

1313

Internal Audit Resource Allocation

18%

82%

Old World

Technology Focus

Casino/Lottery Operations

40%

60%

New WorldTechnology Focus

Casino/Lottery Operations

Page 14: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

1414

Risks Vs. Controls Mapping

Information Security & Privacy

• Security & Privacy Requirements• Security Testing & Penetration Tests• Privacy Impact Assessment

• Design Assessment• Change Management• QA & Compliance Testing

• Requirements Management• Vendor SLA measurement• Contract Management

• Regulator Coordination• Independent Testing• Verification of Gaming Standards

• Communications Management• Advertising

Infrastructure

Vendors

Regulatory Compliance

Player / Public Support

Page 15: 1 Gaming, Privacy and Security eGaming Experience in British Columbia British Columbia Lottery Corporation October 5, 2013 Gurmit Aujla – Director, Internal

1515

Questions?