61D-14.074. Security Requirements, System Access, and Firewalls  


Effective on Tuesday, May 30, 2017
  • 1(1) The firewall application shall maintain an audit log and disable all communications and generate an error event if the audit log becomes full. An audit log shall contain the following information:

    33(a) All changes to configuration of the firewall;

    41(b) All successful and unsuccessful connection attempts through the firewall; and,

    52(c) The source and destination IP addresses, port numbers and MAC addresses.

    64(2) Except as provided in this section, the facility based monitoring system shall not allow for remote access and all access to the facility based monitoring system shall be conducted from within the slot machine licensee’s facility. A slot machine licensee shall provide in its system of internal controls a method of providing limited remote access to the facility based monitoring system for a business or person licensed as a business occupational license pursuant to Section 140551.107(2)(a)3., F.S., 142for performance of maintenance or diagnostics of the facility based monitoring system that cannot be performed by the slot machine licensee’s onsite personnel. The system of internal controls for such remote access shall provide for the following:

    179(a) Designation of an officer required to sign for acknowledgement of internal controls in subsection 19461D-14.058(4), 195F.A.C., who shall be responsible for determining the need for remote access to the facility based monitoring system;

    213(b) The device or method through which remote access is given shall be taken offline when remote access is not required;

    234(c) Limited access to any device or method used to establish remote access including:

    2481. A list of persons authorized to modify or enable such a device or method used to establish remote access; and,

    2692. Storage of any such device or method in a secure location that is not readily accessible to any person other than those listed under subparagraph (c)1.; and,

    2973. A log with separate entries for each person and the dates and times when the remote access is enabled, disabled or modified.

    320(d) Maintenance of a log of each time remote access is provided, enabled, disabled or modified with a separate entry for each of the following:

    3451. The specific reason for which remote access was provided to another person or entity,

    3602. The name and occupational license number of the employee who authorized remote access to be provided to another person or entity,

    3823. The name and occupational license number of the employee of the slot machine licensee who established a remote access connection to the person or entity, if such employee is different from the employee provided in subparagraph (d)2.,

    4204. The name and occupational license number of the person and entity with whom remote access is established. If remote access is provided to an employee of a business occupational licensee, the name and occupational license number of both the employee and the business entity shall be entered on the log,

    4715. The date and time that remote access is established; and,

    4826. The date and time that remote access is terminated.

    492(e) A written report to be provided to the division in no less than 24 hours after the remote access has been completed which shall include:

    5181. The reason that remote access was provided, enabled, disabled or modified,

    5302. The name of the employee of the slot machine licensee that authorized the remote access,

    5463. The name of the slot machine employee who established the remote access on behalf of the slot machine licensee,

    5664. The name of the person and entity with whom remote access was established,

    5805. The date and time remote access was established and concluded; and,

    5926. A narrative report that shall describe:

    599a. Each component of the facility based monitoring system that was accessed; and,

    612b. Whether the remote access was successful in resolving the issue described in subparagraph (d)1.

    627(3) Automated ticket redemption machines are only to be used for the purpose of accepting, validating and providing payment for tickets inserted, or converting bills into smaller denominations. Automated ticket redemption machines shall not incorporate other functions. Automated ticket redemption machines shall use a communication protocol that shall not permit the automated ticket redemption machine to write directly to the system database and only process payments based on commands from the system. Automated ticket redemption machines shall meet the slot machine hardware requirements for security and player safety, as set forth in Rules 61D-14.022-.044, F.A.C.

    722(4) Automated ticket redemption machines shall be capable of detecting and displaying the following error conditions:

    738(a) Power loss or power reset;

    744(b) Interpretation of communication with the automated ticket redemption machine;

    754(c) Cash dispenser empty or timed out;

    761(d) RAM error;

    764(e) Low RAM battery;

    768(f) Ticket in jam;

    772(g) Door open;

    775(h) Bill acceptor stacker full;

    780(i) Bill acceptor door open;

    785(j) Bill stacker door open or bill stacker removed; and,

    795(k) Printer errors.

    798(5) The error conditions referenced in subsection (4), shall illuminate the tower light alarm. The automated ticket redemption machine shall be able to recover to its prior operating condition.

    827(6) Error conditions listed in paragraphs (4)(a)-(g) and (k), shall require a slot machine attendant to intervene and clear the error from the automated ticket redemption machine prior to the resumption of operation.

    860(7) There shall be a maximum ticket value of $1,199.99 that can be paid by an automated ticket redemption machine, per individual ticket.

    884(8) The automated ticket redemption machine shall maintain the following meters:

    895(a) A “total in” meter that accumulates the total value of tickets or vouchers accepted by the automated ticket redemption machine; and,

    917(b) A “total out” meter(s) for payments issued by the machine;

    928(c) Separate “out meters” shall report the value of all bills dispensed by denomination.

    942(9) A log shall be maintained in critical memory or on a paper log housed within the individual automated ticket redemption machine that consists of the following:

    969(a) An event log which shall record the following information about the ticket redeemed:

    9831. Date/time of redemption,

    9872. Amount of ticket; and,

    9923. At least last 4-digits of validation number; and,

    1001(b) The automated ticket redemption machine shall maintain the most recent 35 events in the event log.

    1018(10) Tickets may only be accepted by the automated ticket redemption machine when:

    1031(a) All communication links are intact;

    1037(b) Tickets inserted into an automated ticket redemption machine shall be rejected in the event of a communication failure; and,

    1057(c) Payment shall only be made when the ticket is collected and physically housed within the bill stacker.

    1075(11) A business occupational licensee who provides maintenance or diagnostic services under this section for a slot machine licensee by remote access shall maintain a log each time remote access is provided by a slot machine licensee with a separate entry for each of the following:

    1121(a) The specific slot machine licensee;

    1127(b) The name and occupational license number of the employee of the slot machine licensee who requested remote access;

    1146(c) The name and occupational license number of the employee of the slot machine licensee who established a remote access connection to the business occupational license, if such employee is different from the employee provided in paragraph (11)(b);

    1184(d) The name and occupational license number of the employee of the business occupational license who provides services to the slot machine licensee by remote access;

    1210(e) The date and time that remote access is established; and,

    1221(f) The date and time that remote access is terminated.

    1231(12) A written report shall be provided by a business occupational licensee that performs maintenance or diagnostic services under subsection (11) to the division at the division’s office located at the slot machine licensee’s facility to whom services were provided by remote access. The report shall be postmarked for no less than 24 hours after the remote access has been completed which shall include:

    1295(a) The reason that remote access was provided;

    1303(b) The name of the employee of the slot machine licensee that authorized the access;

    1318(c) The name of the slot machine employee who established the remote access on behalf of the slot machine licensee;

    1338(d) The name of the person and entity with whom remote access was established;

    1352(e) The date and time remote access was established and concluded; and,

    1364(f) A narrative report that shall describe:

    13711. Each component of the facility based monitoring system that was accessed; and,

    13842. Whether the remote access was successful in resolving the issue described in subparagraph (2)(d)1.

    1399Rulemaking Authority 1401551.103(1), 1402551.122 FS. 1404Law Implemented 1406551.103(1)(d), 1407(g), (i) FS. History–New 8-13-06, Amended 5-30-17.

     

Rulemaking Events:

Historical Versions(1)

Select effective date to view different version.