Read this if you are a part of the gaming industry.
BerryDunn has been servicing the gaming and lottery industry for over 25 years. Our experience performing SOC examinations in the gaming and sportsbook industry provides you with trusted professionals who understand your environment, regulations, and customer expectations. As more states pass legislation allowing for sports betting, new rules and regulations are included in the legislation. These rules and regulations are typically focused on maintaining the integrity of systems and public confidence in the sportsbooks and other vendors. SOC 2 has quickly become the international standard for reporting on internal controls over security, availability, processing integrity, confidentiality, and privacy. States have included wording in proposed rules and regulations for SOC 2 examinations to be completed annually by key vendors.
What is SOC 2?
Developed by the American Institute of Certified Public Accountants (AICPA), SOC 2 defines criteria for managing customer data based on five “trust service criteria” (TSC): Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Organizations design their own controls to address specific, pre-defined criteria within one (minimum TSC is Security) or more TSC. The SOC 2 report provides sportsbook providers with important information about how they manage data and systems and is shared with their customers and other relevant stakeholders such as regulatory bodies and auditors. We have explained how each TSC applies to a sportsbook environment below:
Security (often referred to as the common criteria)
The security TSC focuses on the protection and management of information and systems. This includes criteria on policies and procedures, operations, change management, incident management, logical security, and risk mitigation.
Applicability to sportsbook environments
Sportsbooks require a secure approach to help ensure that all data in the environment is securely designed, managed, and protected. Whether you are processing, managing, or storing data for your customer for the use of back-office administration, data feed providers, or traders, or players are making transactions in the environment, all data must be secure.
Controls may include human resource, board, or management oversight, policies and procedures, third-party risk management, user access management, securing your environment (assessing firewall, anti-virus, intrusion protection, vulnerability scanning), operational management and incident handling, and change management.
Availability
The availability TSC refers to ensuring both information and systems are available for operation and accessible to users.
Applicability to sportsbook environments
As a sportsbook, you provide your customers with an environment that requires continuous up-time and system and business recovery measures to be in place for both full system recovery, and where required, failovers to backup hot sites. This TSC allows you to demonstrate to your customer the controls in place for your own environment, service providers (data centers), and data feed providers.
Controls may include high-availability clusters, backup processes, operational monitoring, incident management, capacity management, and data recovery.
Processing integrity
The processing integrity TSC addresses whether the system processing is complete, valid, accurate, timely, and authorized to meet the entity’s objectives.
Applicability to sportsbook environments
As a sportsbook, the integrity and correctness of data and transaction processing are essential to your system. Whether that processing entails odds, quotations, results, bets placed, or payouts—all data within the sportsbook requires accurate and consistent processing.
Controls may include database logs of all transactions with unique IDs, game changes, failure messages, results processing, system checks and balances, and reporting functionality.
Confidentiality
The confidentiality TSC assesses that information designated as confidential is protected to meet the entity’s objectives. (Confidential data focuses more on protecting business sensitive, trade secret data, and proprietary information that is not for public consumption.)
Applicability to sportsbook environments
Confidentiality in a sportsbook environment includes confidentiality for the bettors and confidentiality of the business. Sportsbooks hold the transactional data of players' accounts that are confidential to the individual. Additionally, other data you or your customer have contractually committed to protecting requires confidential safeguards in place more than non-critical or pieces of data. Most often, in sportsbooks we focus on the confidentiality of transactions, movement of data from one location to another, encryption in rest and in transit, and the destruction of data in a secure manner.
Controls may include policies and processes for the handling, maintenance, storage, backup distribution or transmission of data, and destruction of confidential information.
Privacy
The privacy TSC addresses how personal information is collected, used, retained, disclosed, and disposed of to meet the entity’s objectives and is designed to protect against unauthorized use or access.
Applicability to sportsbook environments
Privacy focuses on how an organization manages Personal Identifiable Information (PII). Sportsbooks house PII of their players (bettors) including name, address, birth date, social security number, banking information, or other government-issued identification, among other types of data. PII is used to validate a player’s identity and location. In many instances, third parties may be used for player validation and controls may also focus on third-party management and due diligence.
Controls may include policies and procedures, safeguards in place to protect PII, role-based access, disclosures, choices and consent, monitoring, and enforcement.
Do I already have required controls in place?
In many cases, you likely already have many of the needed internal controls in place because of the nature of the highly regulated gaming industry. SOC 2s may easily leverage the controls you already have in place for other frameworks and requirements, such as NIST, ISO, and PCI.
Preparing for a SOC 2 examination may take a significant amount of time (six months to a year) and we highly recommend you complete a readiness assessment first. In a readiness assessment, we take inventory of your current controls in place for all aspects discussed above and map the control for each TSC. Where gaps may be present, guidance is provided on ways to implement new controls or to enhance current practices. More information on preparing for a SOC 2 can be found here.
Contact us for a SOC 2 readiness assessment
Our team has conducted over 50 iGaming and Sportsbook SOC audits and has over 10 years of experience in the industry. Using industry experts for SOC 2 examinations allows you to get the most value from the process and helps you refine controls to reflect industry best practices. Please contact Josh Clark if you have questions about SOC 2 or your specific operation.