22,033 sections across 1,018 Arkansas regulatory chapters.
23.8.A.355-355-1604 23 CAR § 355-1604. Ticket redemption
1.3K chars
23 CAR § 355-1604. Ticket redemption. (a) Tickets may be inserted in any EGS participating in the validation system providing that no credits are issued to the EGS prior to confirmation of ticket validity. (b) The customer may also redeem a ticket at a validation terminal (i.e., …
23.8.A.355-355-1605 23 CAR § 355-1605. Invalid ticket notification
0.6K chars
23 CAR § 355-1605. Invalid ticket notification. The ticket validation system must have the ability to identify duplicate tickets invalid tickets and notify the EGS to reject the ticket or advise the cashier that one (1) of the following conditions exists: (1) Ticket cannot be fou…
23.8.A.355-355-1606 23 CAR § 355-1606. Required reports
1.0K chars
23 CAR § 355-1606. Required reports. (a) The following reports shall be generated at a minimum and reconciled with all validated/redeemed tickets: (1) Ticket issuance report; (2) Ticket redemption report; (3) Ticket liability report; (4) Ticket drop variance report; (5) Transacti…
23.8.A.355-355-1607 23 CAR § 355-1607. Security of ticket information
0.7K chars
23 CAR § 355-1607. Security of ticket information. (a) Once the validation information is stored in the database, the data may not be altered in any way. (b) The validation system database must be encrypted or password-protected and should possess a nonalterable user audit trail …
23.8.A.355-355-1608 23 CAR § 355-1608. Unredeemed tickets/vouchers
0.7K chars
23 CAR § 355-1608. Unredeemed tickets/vouchers. (a) Beginning January 1, 2010 and continuing on each January 1 annually thereafter, all EGS tickets/vouchers that are more than one (1) year old as of such January 1 and have not been presented for payment otherwise redeemed prior t…
23.8.A.355-355-1701 23 CAR § 355-1701. Generally
0.3K chars
23 CAR § 355-1701. Generally. (a) A cashless system may be entirely integrated into an online monitoring system or exist as an entirely separate entity. (b) Cashless systems may include promotional, bonusing, or player account based systems.
23.8.A.355-355-1702 23 CAR § 355-1702. Error conditions
0.4K chars
23 CAR § 355-1702. Error conditions. The following sections outline the error conditions that apply to the cashless system, which must be monitored, and a message must be displayed to the patron at the host card reader for the following: (1) Invalid PIN or player identification (…
23.8.A.355-355-1703 23 CAR § 355-1703. Transfer of transactions
0.4K chars
23 CAR § 355-1703. Transfer of transactions. If a player initiates a cashless transaction and that transaction would exceed game configured limits (i.e. the credit limit, etc.) then this transaction may only be processed provided that the patron is clearly notified that he or she…
23.8.A.355-355-1704 23 CAR § 355-1704. Security requirements
1.0K chars
23 CAR § 355-1704. Security requirements. (a) The communication process used by the EGS and the host system must be robust and stable enough to secure each cashless transaction such that a failure event or events can be identified and logged for subsequent audit and reconciliatio…
23.8.A.355-355-1705 23 CAR § 355-1705. Prevention of unauthorized transactions
1.2K chars
23 CAR § 355-1705. Prevention of unauthorized transactions. The following minimal controls shall be implemented by the host system to ensure that games are prevented from responding to commands for crediting outside of properly authorized cashless transactions (hacking): (1) The …
23.8.A.355-355-1706 23 CAR § 355-1706. Diagnostic tests on a cashless EGS
0.5K chars
23 CAR § 355-1706. Diagnostic tests on a cashless EGS. (a) Controls must be in place for any diagnostic functionality available at the device such that all activity must be reported to the system that would reflect the specific account or accounts and the individual or individual…
23.8.A.355-355-1707 23 CAR § 355-1707. Transaction auditing
0.3K chars
23 CAR § 355-1707. Transaction auditing. (a) The cashless system shall have the ability to produce logs for all pending and completed cashless transactions. (b) These logs shall be capable of being filtered by: (1) Machine number; (2) Patron account; and (3) Time/date.…
23.8.A.355-355-1708 23 CAR § 355-1708. Financial and player reports
1.6K chars
23 CAR § 355-1708. Financial and player reports. The system shall have the ability to produce the following financial and player reports: (1)(A) Patron account summary and detail reports. (B) These reports shall be immediately available to a patron upon request. (C) These reports…
23.8.A.355-355-1709 23 CAR § 355-1709. Account balance
0.3K chars
23 CAR § 355-1709. Account balance. Current account balance information should be available on demand from any participating EGS via the associated card reader (or equivalent) after confirmation of patron identity and be presented, in terms of currency, to the patron.
23.8.A.355-355-1801 23 CAR § 355-1801. Progressive system
0.3K chars
23 CAR § 355-1801. Progressive system. A progressive system is a computerized system linking EGS in one (1) or more licensed facilities within the State of Arkansas and offering one (1) or more common progressive payouts based on the amounts wagered.
23.8.A.355-355-1802 23 CAR § 355-1802. Progressive meter/display
4.1K chars
23 CAR § 355-1802. Progressive meter/display. (a) A progressive meter/display can be one (1) or more progressive EGS that are linked, directly or indirectly, to a display (e.g., mechanical, electrical, or electronic device, including the video display, if applicable) that shows t…
23.8.A.355-355-1803 23 CAR § 355-1803. Progressive controllers
6.4K chars
23 CAR § 355-1803. Progressive controllers. (a) The requirements of this section are intended to apply equally to one (1) progressive EGS linked to a progressive controller or that is internally controlled, as well as several progressive EGS linked to one (1) progressive controll…
23.8.A.355-355-1804 23 CAR § 355-1804. Linked EGS odds
0.5K chars
23 CAR § 355-1804. Linked EGS odds. (a) Each device on the link shall have the same probability of winning the progressive, adjusted for the denomination played. (b) For instance, the probability shall remain the same for multiple denomination games based on the monetary value of…
23.8.A.355-355-1805 23 CAR § 355-1805. Multisite progressive
7.2K chars
23 CAR § 355-1805. Multisite progressive. (a) Multisite progressive EGS are interconnected in more than one (1) franchise holder in Arkansas. (b) The purpose of a multisite progressive system is to offer a common progressive jackpot (system jackpot) at all participating locations…
23.8.A.355-355-1901 23 CAR § 355-1901. Generally
0.9K chars
23 CAR § 355-1901. Generally. (a) A client-server system can be fragmentally defined as a server-base game system, a server-supported game system, or a hybrid of the two (2), all of which can be defined as the combination of a central server, client terminals, and all interface e…
23.8.A.355-355-1902 23 CAR § 355-1902. Server-based game systems (SBGS) defined
0.4K chars
23 CAR § 355-1902. Server-based game systems (SBGS) defined. (a) SBGS is the combination of a server and client terminals in which the entire or integral portion of game content resides on the server. (b) This system works collectively in a fashion in which the client terminal wi…
23.8.A.355-355-1903 23 CAR § 355-1903. Server-supported game system (SSGS) defined
1.0K chars
23 CAR § 355-1903. Server-supported game system (SSGS) defined. (a) SSGS is the combination of a server and a client terminal or terminals which together allow the transfer of the entire control program and game content to the client terminal or terminals for the purpose of downl…
23.8.A.355-355-1904 23 CAR § 355-1904. Communication protocol
0.5K chars
23 CAR § 355-1904. Communication protocol. (a) Each component of a CSS must function as indicated by the communication protocol implemented. (b) All protocols must use communication techniques that have proper error detection and/or recovery mechanisms, which are designed to prev…
23.8.A.355-355-1905 23 CAR § 355-1905. Loss of communication
0.9K chars
23 CAR § 355-1905. Loss of communication. (a) For a server-based game system, a client must be rendered unplayable if communication from the server or system portion of the client terminal is lost. (b) If a game is in progress, either: (1) The client terminal must have the capabi…
23.8.A.355-355-1906 23 CAR § 355-1906. System security
0.4K chars
23 CAR § 355-1906. System security. (a) In the even the CSS server is utilized in conjunction with other networks, all communication, including remote access, must pass through at least one (1) approved application-level firewall and must have a facility that allows for an altern…
23.8.A.355-355-1907 23 CAR § 355-1907. Firewall audit logs
0.6K chars
23 CAR § 355-1907. Firewall audit logs. The firewall application must maintain an audit log of the following information and must disable all communication and generate an error event if the audit log becomes full: (1) All changes to configuration of the firewall; (2) All success…
23.8.A.355-355-1908 23 CAR § 355-1908. Remote access
0.9K chars
23 CAR § 355-1908. Remote access. (a) Remote access is defined as any access to the system outside of the trusted network. (b) Remote access, where permitted, shall authenticate all computer systems based on the authorized settings of the CSS or firewall application that establis…
23.8.A.355-355-1909 23 CAR § 355-1909. Remote access auditing
0.5K chars
23 CAR § 355-1909. Remote access auditing. The CSS server must maintain an activity log either automatically or have the ability to manually enter the logs depicting all remote access information that includes: (1) The log on name; (2) Time and date the connection was made; (3) D…
23.8.A.355-355-1910 23 CAR § 355-1910. Wide area network communication
0.8K chars
23 CAR § 355-1910. Wide area network communication. Wide area network (WAN) communication within the CSS is permitted provided that the following criteria is met: (1) The communication over the WAN are secured from intrusion, interference, and eavesdropping via techniques such as…
23.8.A.355-355-1911 23 CAR § 355-1911. CSS server requirements
0.6K chars
23 CAR § 355-1911. CSS server requirements. (a) This section covers the elements common to the back of the house operations of a CSS. (b) The game server or servers may be located locally, within a single facility or may be remotely located outside of the facility such as over a …
23.8.A.355-355-1912 23 CAR § 355-1912. Multiple servers
0.4K chars
23 CAR § 355-1912. Multiple servers. (a) A CSS may in fact be a collection of servers for load balancing, redundancy, or functionality reasons. (b) For example, there might be two (2) or more game servers, a finance server, monitoring server, download server, etc. (c) The system …
23.8.A.355-355-1913 23 CAR § 355-1913. Operations and server security
1.0K chars
23 CAR § 355-1913. Operations and server security. (a) For a server-based game system and hybrid systems as applicable, the game server shall generate and transmit to the client terminals control, configuration, and information data, depending upon the actual implementation. (b) …
23.8.A.355-355-1914 23 CAR § 355-1914. Intrusion protection
0.1K chars
23 CAR § 355-1914. Intrusion protection. All servers shall have sufficient physical/logical intrusion protection against unauthorized access.
23.8.A.355-355-1915 23 CAR § 355-1915. Configuration access requirements
0.2K chars
23 CAR § 355-1915. Configuration access requirements. The CSS interface element setup/configuration menu or menus must not be available unless using an authorized access method that is secure.
23.8.A.355-355-1916 23 CAR § 355-1916. Server programming
0.5K chars
23 CAR § 355-1916. Server programming. (a) There shall be no means available for an operator to conduct programming on the server in any configuration (e.g. the operator should not be able to perform SQL statements to modify the database). (b) However, it is acceptable for a netw…
23.8.A.355-355-1917 23 CAR § 355-1917. Virus protection
0.1K chars
23 CAR § 355-1917. Virus protection. It is recommended all servers and client devices should have adequate virus protection.
23.8.A.355-355-1918 23 CAR § 355-1918. Copy protection
0.4K chars
23 CAR § 355-1918. Copy protection. Copy protection to prevent unauthorized proliferation or modification of software, for servers or clients, may be implemented provided that the method of copy protection is fully documented and provided to the third party independent test labor…
23.8.A.355-355-1919 23 CAR § 355-1919. System failure
0.9K chars
23 CAR § 355-1919. System failure. (a)(1) The CSS shall be designed to protect the integrity of pertinent data in the event of a failure. (2) Audit logs, system databases, and any other pertinent data must be stored using reasonable protection methods. (3) If hard disk drives are…
23.8.A.355-355-1920 23 CAR § 355-1920. Recovery requirements
0.4K chars
23 CAR § 355-1920. Recovery requirements. (a) In the event of a catastrophic failure where the CSS cannot be restarted in any other way, it shall be possible to reload the database from the last viable backup point. (b) This must fully recover the contents of that backup and shal…
23.8.A.355-355-1921 23 CAR § 355-1921. Self-monitoring
0.8K chars
23 CAR § 355-1921. Self-monitoring. (a) The CSS must implement self-monitoring of all critical interface elements (e.g. central hosts, network devices, firewalls, links to their parties, etc.) and shall have the ability to effectively notify the system administrator of the condit…
23.8.A.355-355-1922 23 CAR § 355-1922. CSS software verification
0.7K chars
23 CAR § 355-1922. CSS software verification. (a) Each integral component of the CSS must have a method to be verified via a third-party verification procedure. (b) The client terminal and/or the applicable server side critical game components shall provide the ability to conduct…
23.8.A.355-355-1923 23 CAR § 355-1923. Verification of devices that cannot be interrogated
0.6K chars
23 CAR § 355-1923. Verification of devices that cannot be interrogated. Program devices that cannot be interrogated, such as smart cards, may be used provided they are able to be verified by the following methodology: (1) A challenge is sent by the peer device, such as a hashing …
23.8.A.355-355-1924 23 CAR § 355-1924. Server recall requirements
3.0K chars
23 CAR § 355-1924. Server recall requirements. (a)(1) The server that supports a server-based game must be able to provide the following game history information. (2) In the case of a hybrid system it is allowable for this information to be stored either on the server or at the c…
23.8.A.355-355-1925 23 CAR § 355-1925. Download data library
0.3K chars
23 CAR § 355-1925. Download data library. The download data library refers to the formal storage of all approved data files that may be downloaded to client terminals including control and game software, peripheral firmware, configuration data, etc.
23.8.A.355-355-1926 23 CAR § 355-1926. Update of download data library
0.5K chars
23 CAR § 355-1926. Update of download data library. (a) Where applicable, the CSS download data library shall only be written to, with secure access that is controlled by the Arkansas Racing Commission, in which case the manufacturer and/or operator will be able to access the dow…
23.8.A.355-355-1927 23 CAR § 355-1927. Download data library audit log
0.5K chars
23 CAR § 355-1927. Download data library audit log. Any changes that are made to the download data library, including the addition, changing, or deletion of game programs, must be stored in an unalterable audit log, which shall include: (1) Time and date of the access and/or even…
23.8.A.355-355-1928 23 CAR § 355-1928. Download activity audit log
0.7K chars
23 CAR § 355-1928. Download activity audit log. (a) Any record of activity between the server and the client that involves the downloading of program logic, the adjustment of client settings/configurations, or the activation of previously downloaded program logic, must be stored …
23.8.A.355-355-1929 23 CAR § 355-1929. Download of client terminal data files and control programs
0.5K chars
23 CAR § 355-1929. Download of client terminal data files and control programs. This will outline the requirements of the CSS when downloading software, games, and other configuration data to client terminals, if the server provides the functionality of downloading control progra…
23.8.A.355-355-1930 23 CAR § 355-1930. Authentication of control programs
1.1K chars
23 CAR § 355-1930. Authentication of control programs. (a) The CSS shall authenticate all critical files including, but not limited to, executables, data, and other files which may affect the game outcome or the compliant operation of the CSS during the following: (1) Any process…
23.8.A.355-355-1931 23 CAR § 355-1931. Control program
1.9K chars
23 CAR § 355-1931. Control program. (a) These minimum technical rules shall be met, where applicable, when downloading/activating control programs from the CSS Server to the client terminal. (b)(1) The client terminal and/or the CSS server must have a method to monitor and report…