• Skip to main content
  • Skip to site footer
NIGC Logo

National Indian Gaming Commission

MENUMENU
  • HOME
  • Commission
        • About Us
          • History
          • Agency Strategic Goals
          • Contact Us
          • Organizational Structure
          • Strategic Plan
          • Federal Employee Viewpoint Survey
          • Performance Dashboard
        • Commission Actions
          • Bulletins
          • Commission Final Decisions
          • Dear Tribal Letters
          • Enforcement Actions
          • NEPA Decision of Records
            • Categorical Exclusion Administrative
        • Commissioners
          • Speeches
          • Tribal Consultations
        • Past Commissioners
        • Frequently Asked Questions
        • Human Trafficking Resources
        • Office of Self-Regulation
        • Reports and Publications
  • Office of Chief of Staff
        • Compliance
          • Alternate Standards
          • Audit
          • Bulletins
          • Checklists and Worksheets
          • Regional Offices
        • Finance
          • Annual Commission Budgets
          • Annual Fees
          • Fingerprint Fees
          • Gross Gaming Revenue Reports
          • Management Contracts
        • Public Affairs
          • Biographies
          • Community Impact
          • Featured Articles
          • Legislative Affairs
          • Media Center
            • Seals and Graphics
            • Press Conferences & Transcripts
          • News Release
          • Reflecting on 30 Years of IGRA
          • Social Media
        • Technology
          • CJIS Resource Materials
          • Fingerprint Process
          • IT Vulnerability Assessment
          • Kiteworks Guide for External Users
          • Tech Alerts and Warnings
          • Tribal Access Portal
        • Training
          • Catalog of Courses
          • Environment, Public Health and Safety
          • Toolkits
          • Training Event Calendar
          • Video Library
  • Office of General Counsel
        • Compacts
        • Gaming Ordinances
        • Game Classification Opinions
        • Legal Opinions
          • Declination Letters
          • Indian Lands Opinions
          • Game Classification Opinions
        • NIGC Serves Cheat Sheet
        • Laws and Regulations
          • Indian Gaming Regulatory Act
          • Commission Regulations
          • EPHS Interpretive Rule
          • DOI Gaming Regulations
          • Johnson Act
          • Gaming Criminal Laws and Penalties
          • National Environmental Policy Act
  • I want to…
    • Contact the nearest NIGC office
    • Submit electronic financial statements
    • View upcoming training & events
    • Find the Minimum Internal Control Standards
    • See agency decisions and actions
    • View NIGC’s Indian gaming regulations
    • Request a legal opinion
    • Report A Violation
MENUMENU
  • HOME
  • Commission
        • About Us
          • History
          • Agency Strategic Goals
          • Contact Us
          • Organizational Structure
          • Strategic Plan
          • Federal Employee Viewpoint Survey
          • Performance Dashboard
        • Commission Actions
          • Bulletins
          • Commission Final Decisions
          • Dear Tribal Letters
          • Enforcement Actions
          • NEPA Decision of Records
            • Categorical Exclusion Administrative
        • Commissioners
          • Speeches
          • Tribal Consultations
        • Past Commissioners
        • Frequently Asked Questions
        • Human Trafficking Resources
        • Office of Self-Regulation
        • Reports and Publications
  • Office of Chief of Staff
        • Compliance
          • Alternate Standards
          • Audit
          • Bulletins
          • Checklists and Worksheets
          • Regional Offices
        • Finance
          • Annual Commission Budgets
          • Annual Fees
          • Fingerprint Fees
          • Gross Gaming Revenue Reports
          • Management Contracts
        • Public Affairs
          • Biographies
          • Community Impact
          • Featured Articles
          • Legislative Affairs
          • Media Center
            • Seals and Graphics
            • Press Conferences & Transcripts
          • News Release
          • Reflecting on 30 Years of IGRA
          • Social Media
        • Technology
          • CJIS Resource Materials
          • Fingerprint Process
          • IT Vulnerability Assessment
          • Kiteworks Guide for External Users
          • Tech Alerts and Warnings
          • Tribal Access Portal
        • Training
          • Catalog of Courses
          • Environment, Public Health and Safety
          • Toolkits
          • Training Event Calendar
          • Video Library
  • Office of General Counsel
        • Compacts
        • Gaming Ordinances
        • Game Classification Opinions
        • Legal Opinions
          • Declination Letters
          • Indian Lands Opinions
          • Game Classification Opinions
        • NIGC Serves Cheat Sheet
        • Laws and Regulations
          • Indian Gaming Regulatory Act
          • Commission Regulations
          • EPHS Interpretive Rule
          • DOI Gaming Regulations
          • Johnson Act
          • Gaming Criminal Laws and Penalties
          • National Environmental Policy Act
  • I want to…
    • Contact the nearest NIGC office
    • Submit electronic financial statements
    • View upcoming training & events
    • Find the Minimum Internal Control Standards
    • See agency decisions and actions
    • View NIGC’s Indian gaming regulations
    • Request a legal opinion
    • Report A Violation
Technology

IT Vulnerability Assessment

Home › Office of Chief of Staff › Technology › IT Vulnerability Assessment

The National Indian Gaming Commission offers no-cost IT vulnerability assessment testing for tribes and tribal regulators, which provides a tribal gaming facility with a comprehensive vulnerability analysis of their IT systems and operational processes.

IT vulnerability assessment testing is a high-level tool that assists requesting tribes with valuable insight into their IT security posture relative to its gaming systems and operational processes. The engagement provides a solid baseline for internally mitigating any risks identified or to assist in justifying funding for third-party assistance if needed.

ITVA-web

IT vulnerability assessment testing consists of external and internal testing. The external test scans and detects security vulnerabilities visible from outside of the gaming system network. The scan considers all security layers on the network between the scanner machine and the target system. The internal network test provides an overview of vulnerabilities visible from inside the local gaming system network, considering host-based security controls on the target system.

The services will typically be performed on-site by a team of two NIGC network engineers who will conduct the network assessments.

The internal network assessment will include the following activities:

  • Network level port scanning of the system and workstations.
  • Identification of vulnerabilities against a published national vulnerability database.
  • Identify areas of weaknesses that a potential hacker can leverage to gain access.
  • Policy review and operational testing and validation to identify policy violations by employees.
Internal Control Assessment

At the conclusion of the assessment, a detailed technical report will be provided summarizing the methods of testing and the results of the tests, which include:

  • Scope – Defined targets, goals, and objectives of the overall testing phases and policy review.
  • Approach – A breakdown of the methods and tools used during the testing of the internal systems and networks to conduct the risk assessment.
  • Findings – A detailed report containing the test results from the assessment with identified risks and weaknesses will be generated.
  • Recommendations – Identification of strengths and weaknesses based on assessment findings and policy review presented for the tribe’s review. Provide recommendations to help improve areas of concern.

If you would like to request an ITVA to include requesting an Internal Control Assessment in conjunction with your ITVA, find out more information here.

Contact

Division of Technology
Email: itsupport@nigc.gov

  • SUBSCRIBE

Enter your email address to subscribe to NIGC news and updates
Please enable JavaScript in your browser to complete this form.
Choose a category for updates:
Loading

About Us

Contact Us

Employment Opportunities

Equal Employment Opportunity

No Fear Act

Privacy Act

Accessibility Statement

Freedom of Information Act

Report A Violation

Terms of Use

Web and Privacy Policy

Vulnerability Disclosure Policy

NIGC Logo in Black

National Indian Gaming Commission

Return to top

  • Facebook
  • X
  • LinkedIn
  • YouTube

Copyright © 2025 · All Rights Reserved by NIGC.gov