There was no international security standard available until the mid 1990s. The Security Control Standards© were created to fill this gap.
The World Lottery Association (WLA) represents state licensed lottery companies from 74 countries. The goal is to achieve and sustain public confidence in the operation of a lottery game. The Security Control Standards© are similar in nature to the Information Security Management System standard ISO/IEC 27001, but they are written to target the security challenges specific to lottery operations. While ISO/IEC 27001 is a generic standard, the WLA Security Control Standards© are industry specific. This means that the Standards are applicably only to the lottery industry as it has been tailor made for lottery operations.
Managing more than IT security risks
The WLA Security Control Standards© comprehensively cover security issues. The Standards cover a range of aspects in your company’s operations, including:
- Security organisation
- Physical and environmental security
- Contingency planning
- Information protection
- IT security management
- IT access control
- Risk management
- Systems development and change management
- Network and telecommunications
- Criminal incident reporting and investigation
- Human resources
- Instant tickets
- Lottery draws
- Retailer security
- Unclaimed prize money
Obtaining a certificate of compliance
To manage your security risks by developing and implementing a logical, physical, and procedural security system is the first step. WLA recommends that all its members obtain a certificate of compliance from a third party certification body.
Certification to the WLA Security Control Standards© by an independent third party offers an independent assurance to a company’s board of directors, controlling bodies, bankers, external auditors, insurers, staff, players, customers, and the media. A certificate conveys that:
- the company has a good security culture,
- the lottery is produced in a satisfactory manner so that the players can have confidence in them,
- IT production routines are satisfactory,
- personnel routines may be able to prevent security breaches,
- and that the security department is skilled and focused.
Where do I go from here?
For third party certification, you need to implement an effective security system complying with the requirements of the Standards. The first step is to get on the road to certification.