As part of its internal controls submission in accordance with 205 CMR 138.01, a gaming licensee shall annually submit an infrastructure and data security plan to the Commission for review and approval. The plan should employ best practices (i.e., NIST SP 800-53 or ISO/IEC 27001) for protecting infrastructure and data.
205 CMR, § 143.12