MIME-Version: 1.0
X-Document-Type: Workbook
Content-Type: multipart/related; boundary="----=_NextPart_01C5A89A.7EF40B40"

This document is a Single File Web Page, also known as a Web Archive file.  If you are seeing this message, your browser or editor doesn't support Web Archive files.  Please download a browser that supports Web Archive, such as Microsoft Internet Explorer.

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta name=3D"Excel Workbook Frameset">
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link rel=3DFile-List
href=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAccessC=
ontrolSystemDevelopment_files/filelist.xml">
<link rel=3DEdit-Time-Data
href=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAccessC=
ontrolSystemDevelopment_files/editdata.mso">
<link rel=3DOLE-Object-Data
href=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAccessC=
ontrolSystemDevelopment_files/oledata.mso">
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>Audit Services </o:Author>
  <o:LastAuthor>a</o:LastAuthor>
  <o:LastPrinted>2004-01-20T18:45:29Z</o:LastPrinted>
  <o:Created>2003-12-03T22:23:52Z</o:Created>
  <o:LastSaved>2005-08-24T14:56:35Z</o:LastSaved>
  <o:Company>Wells Fargo Services Co.</o:Company>
  <o:Version>11.5606</o:Version>
 </o:DocumentProperties>
 <o:CustomDocumentProperties>
  <o:_AdHocReviewCycleID dt:dt=3D"float">1750939052</o:_AdHocReviewCycleID>
  <o:_EmailSubject dt:dt=3D"string">Expectations Matrix</o:_EmailSubject>
  <o:_AuthorEmail dt:dt=3D"string">MargaretPrior@fsround.org</o:_AuthorEmai=
l>
  <o:_AuthorEmailDisplayName dt:dt=3D"string">Margaret Prior</o:_AuthorEmai=
lDisplayName>
  <o:_PreviousAdHocReviewCycleID dt:dt=3D"float">-1554206420</o:_PreviousAd=
HocReviewCycleID>
  <o:_ReviewingToolsShownOnce dt:dt=3D"string"></o:_ReviewingToolsShownOnce>
 </o:CustomDocumentProperties>
 <o:OfficeDocumentSettings>
  <o:DownloadComponents/>
  <o:LocationOfComponents HRef=3D"file:///C:\IN-OFF2K3UM\"/>
 </o:OfficeDocumentSettings>
</xml><![endif]--><![if !supportTabStrip]>
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet001.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet002.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet003.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet004.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet005.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet006.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet007.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet008.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet009.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet010.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet011.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet012.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet013.htm">
<link id=3D"shLink" href=3D"1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files/sheet014.htm">

<link id=3D"shLink">

<script language=3D"JavaScript">
<!--
 var c_lTabs=3D14;

 var c_rgszSh=3Dnew Array(c_lTabs);
 c_rgszSh[0] =3D "Cover";
 c_rgszSh[1] =3D "Intro";
 c_rgszSh[2] =3D "Contributors";
 c_rgszSh[3] =3D "Security&nbsp;Policy";
 c_rgszSh[4] =3D "Organizational&nbsp;Security";
 c_rgszSh[5] =3D "Asset&nbsp;Classification&nbsp;&amp;&nbsp;Control";
 c_rgszSh[6] =3D "Personnel&nbsp;Security";
 c_rgszSh[7] =3D "Physical&nbsp;&amp;&nbsp;Env&nbsp;Sec";
 c_rgszSh[8] =3D "Communication&nbsp;and&nbsp;Ops&nbsp;Mgmt";
 c_rgszSh[9] =3D "Access&nbsp;Control";
 c_rgszSh[10] =3D "SD&nbsp;and&nbsp;Maintenance";
 c_rgszSh[11] =3D "Business&nbsp;Continuity";
 c_rgszSh[12] =3D "Regulatory";
 c_rgszSh[13] =3D "Other";



 var c_rgszClr=3Dnew Array(8);
 c_rgszClr[0]=3D"window";
 c_rgszClr[1]=3D"buttonface";
 c_rgszClr[2]=3D"windowframe";
 c_rgszClr[3]=3D"windowtext";
 c_rgszClr[4]=3D"threedlightshadow";
 c_rgszClr[5]=3D"threedhighlight";
 c_rgszClr[6]=3D"threeddarkshadow";
 c_rgszClr[7]=3D"threedshadow";

 var g_iShCur;
 var g_rglTabX=3Dnew Array(c_lTabs);

function fnGetIEVer()
{
 var ua=3Dwindow.navigator.userAgent
 var msie=3Dua.indexOf("MSIE")
 if (msie>0 && window.navigator.platform=3D=3D"Win32")
  return parseInt(ua.substring(msie+5,ua.indexOf(".", msie)));
 else
  return 0;
}

function fnBuildFrameset()
{
 var szHTML=3D"<frameset rows=3D\"*,18\" border=3D0 width=3D0 frameborder=
=3Dno framespacing=3D0>"+
  "<frame src=3D\""+document.all.item("shLink")[6].href+"\" name=3D\"frShee=
t\" noresize>"+
  "<frameset cols=3D\"54,*\" border=3D0 width=3D0 frameborder=3Dno framespa=
cing=3D0>"+
  "<frame src=3D\"\" name=3D\"frScroll\" marginwidth=3D0 marginheight=3D0 s=
crolling=3Dno>"+
  "<frame src=3D\"\" name=3D\"frTabs\" marginwidth=3D0 marginheight=3D0 scr=
olling=3Dno>"+
  "</frameset></frameset><plaintext>";

 with (document) {
  open("text/html","replace");
  write(szHTML);
  close();
 }

 fnBuildTabStrip();
}

function fnBuildTabStrip()
{
 var szHTML=3D
  "<html><head><style>.clScroll {font:8pt Courier New;color:"+c_rgszClr[6]+=
";cursor:default;line-height:10pt;}"+
  ".clScroll2 {font:10pt Arial;color:"+c_rgszClr[6]+";cursor:default;line-h=
eight:11pt;}</style></head>"+
  "<body onclick=3D\"event.returnValue=3Dfalse;\" ondragstart=3D\"event.ret=
urnValue=3Dfalse;\" onselectstart=3D\"event.returnValue=3Dfalse;\" bgcolor=
=3D"+c_rgszClr[4]+" topmargin=3D0 leftmargin=3D0><table cellpadding=3D0 cel=
lspacing=3D0 width=3D100%>"+
  "<tr><td colspan=3D6 height=3D1 bgcolor=3D"+c_rgszClr[2]+"></td></tr>"+
  "<tr><td style=3D\"font:1pt\">&nbsp;<td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll\" onclick=3D\"parent.f=
nFastScrollTabs(0);\" onmouseover=3D\"parent.fnMouseOverScroll(0);\" onmous=
eout=3D\"parent.fnMouseOutScroll(0);\"><a>&#171;</a></td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll2\" onclick=3D\"parent.=
fnScrollTabs(0);\" ondblclick=3D\"parent.fnScrollTabs(0);\" onmouseover=3D\=
"parent.fnMouseOverScroll(1);\" onmouseout=3D\"parent.fnMouseOutScroll(1);\=
"><a>&lt</a></td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll2\" onclick=3D\"parent.=
fnScrollTabs(1);\" ondblclick=3D\"parent.fnScrollTabs(1);\" onmouseover=3D\=
"parent.fnMouseOverScroll(2);\" onmouseout=3D\"parent.fnMouseOutScroll(2);\=
"><a>&gt</a></td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll\" onclick=3D\"parent.f=
nFastScrollTabs(1);\" onmouseover=3D\"parent.fnMouseOverScroll(3);\" onmous=
eout=3D\"parent.fnMouseOutScroll(3);\"><a>&#187;</a></td>"+
  "<td style=3D\"font:1pt\">&nbsp;<td></tr></table></body></html>";

 with (frames['frScroll'].document) {
  open("text/html","replace");
  write(szHTML);
  close();
 }

 szHTML =3D
  "<html><head>"+
  "<style>A:link,A:visited,A:active {text-decoration:none;"+"color:"+c_rgsz=
Clr[3]+";}"+
  ".clTab {cursor:hand;background:"+c_rgszClr[1]+";font:9pt Arial;padding-l=
eft:3px;padding-right:3px;text-align:center;}"+
  ".clBorder {background:"+c_rgszClr[2]+";font:1pt;}"+
  "</style></head><body onload=3D\"parent.fnInit();\" onselectstart=3D\"eve=
nt.returnValue=3Dfalse;\" ondragstart=3D\"event.returnValue=3Dfalse;\" bgco=
lor=3D"+c_rgszClr[4]+
  " topmargin=3D0 leftmargin=3D0><table id=3DtbTabs cellpadding=3D0 cellspa=
cing=3D0>";

 var iCellCount=3D(c_lTabs+1)*2;

 var i;
 for (i=3D0;i<iCellCount;i+=3D2)
  szHTML+=3D"<col width=3D1><col>";

 var iRow;
 for (iRow=3D0;iRow<6;iRow++) {

  szHTML+=3D"<tr>";

  if (iRow=3D=3D5)
   szHTML+=3D"<td colspan=3D"+iCellCount+"></td>";
  else {
   if (iRow=3D=3D0) {
    for(i=3D0;i<iCellCount;i++)
     szHTML+=3D"<td height=3D1 class=3D\"clBorder\"></td>";
   } else if (iRow=3D=3D1) {
    for(i=3D0;i<c_lTabs;i++) {
     szHTML+=3D"<td height=3D1 nowrap class=3D\"clBorder\">&nbsp;</td>";
     szHTML+=3D
      "<td id=3DtdTab height=3D1 nowrap class=3D\"clTab\" onmouseover=3D\"p=
arent.fnMouseOverTab("+i+");\" onmouseout=3D\"parent.fnMouseOutTab("+i+");\=
">"+
      "<a href=3D\""+document.all.item("shLink")[i].href+"\" target=3D\"frS=
heet\" id=3DaTab>&nbsp;"+c_rgszSh[i]+"&nbsp;</a></td>";
    }
    szHTML+=3D"<td id=3DtdTab height=3D1 nowrap class=3D\"clBorder\"><a id=
=3DaTab>&nbsp;</a></td><td width=3D100%></td>";
   } else if (iRow=3D=3D2) {
    for (i=3D0;i<c_lTabs;i++)
     szHTML+=3D"<td height=3D1></td><td height=3D1 class=3D\"clBorder\"></t=
d>";
    szHTML+=3D"<td height=3D1></td><td height=3D1></td>";
   } else if (iRow=3D=3D3) {
    for (i=3D0;i<iCellCount;i++)
     szHTML+=3D"<td height=3D1></td>";
   } else if (iRow=3D=3D4) {
    for (i=3D0;i<c_lTabs;i++)
     szHTML+=3D"<td height=3D1 width=3D1></td><td height=3D1></td>";
    szHTML+=3D"<td height=3D1 width=3D1></td><td></td>";
   }
  }
  szHTML+=3D"</tr>";
 }

 szHTML+=3D"</table></body></html>";
 with (frames['frTabs'].document) {
  open("text/html","replace");
  charset=3Ddocument.charset;
  write(szHTML);
  close();
 }
}

function fnInit()
{
 g_rglTabX[0]=3D0;
 var i;
 for (i=3D1;i<=3Dc_lTabs;i++)
  with (frames['frTabs'].document.all.tbTabs.rows[1].cells[fnTabToCol(i-1)])
   g_rglTabX[i]=3DoffsetLeft+offsetWidth-6;
}

function fnTabToCol(iTab)
{
 return 2*iTab+1;
}

function fnNextTab(fDir)
{
 var iNextTab=3D-1;
 var i;

 with (frames['frTabs'].document.body) {
  if (fDir=3D=3D0) {
   if (scrollLeft>0) {
    for (i=3D0;i<c_lTabs&&g_rglTabX[i]<scrollLeft;i++);
    if (i<c_lTabs)
     iNextTab=3Di-1;
   }
  } else {
   if (g_rglTabX[c_lTabs]+6>offsetWidth+scrollLeft) {
    for (i=3D0;i<c_lTabs&&g_rglTabX[i]<=3DscrollLeft;i++);
    if (i<c_lTabs)
     iNextTab=3Di;
   }
  }
 }
 return iNextTab;
}

function fnScrollTabs(fDir)
{
 var iNextTab=3DfnNextTab(fDir);

 if (iNextTab>=3D0) {
  frames['frTabs'].scroll(g_rglTabX[iNextTab],0);
  return true;
 } else
  return false;
}

function fnFastScrollTabs(fDir)
{
 if (c_lTabs>16)
  frames['frTabs'].scroll(g_rglTabX[fDir?c_lTabs-1:0],0);
 else
  if (fnScrollTabs(fDir)>0) window.setTimeout("fnFastScrollTabs("+fDir+");"=
,5);
}

function fnSetTabProps(iTab,fActive)
{
 var iCol=3DfnTabToCol(iTab);
 var i;

 if (iTab>=3D0) {
  with (frames['frTabs'].document.all) {
   with (tbTabs) {
    for (i=3D0;i<=3D4;i++) {
     with (rows[i]) {
      if (i=3D=3D0)
       cells[iCol].style.background=3Dc_rgszClr[fActive?0:2];
      else if (i>0 && i<4) {
       if (fActive) {
        cells[iCol-1].style.background=3Dc_rgszClr[2];
        cells[iCol].style.background=3Dc_rgszClr[0];
        cells[iCol+1].style.background=3Dc_rgszClr[2];
       } else {
        if (i=3D=3D1) {
         cells[iCol-1].style.background=3Dc_rgszClr[2];
         cells[iCol].style.background=3Dc_rgszClr[1];
         cells[iCol+1].style.background=3Dc_rgszClr[2];
        } else {
         cells[iCol-1].style.background=3Dc_rgszClr[4];
         cells[iCol].style.background=3Dc_rgszClr[(i=3D=3D2)?2:4];
         cells[iCol+1].style.background=3Dc_rgszClr[4];
        }
       }
      } else
       cells[iCol].style.background=3Dc_rgszClr[fActive?2:4];
     }
    }
   }
   with (aTab[iTab].style) {
    cursor=3D(fActive?"default":"hand");
    color=3Dc_rgszClr[3];
   }
  }
 }
}

function fnMouseOverScroll(iCtl)
{
 frames['frScroll'].document.all.tdScroll[iCtl].style.color=3Dc_rgszClr[7];
}

function fnMouseOutScroll(iCtl)
{
 frames['frScroll'].document.all.tdScroll[iCtl].style.color=3Dc_rgszClr[6];
}

function fnMouseOverTab(iTab)
{
 if (iTab!=3Dg_iShCur) {
  var iCol=3DfnTabToCol(iTab);
  with (frames['frTabs'].document.all) {
   tdTab[iTab].style.background=3Dc_rgszClr[5];
  }
 }
}

function fnMouseOutTab(iTab)
{
 if (iTab>=3D0) {
  var elFrom=3Dframes['frTabs'].event.srcElement;
  var elTo=3Dframes['frTabs'].event.toElement;

  if ((!elTo) ||
   (elFrom.tagName=3D=3DelTo.tagName) ||
   (elTo.tagName=3D=3D"A" && elTo.parentElement!=3DelFrom) ||
   (elFrom.tagName=3D=3D"A" && elFrom.parentElement!=3DelTo)) {

   if (iTab!=3Dg_iShCur) {
    with (frames['frTabs'].document.all) {
     tdTab[iTab].style.background=3Dc_rgszClr[1];
    }
   }
  }
 }
}

function fnSetActiveSheet(iSh)
{
 if (iSh!=3Dg_iShCur) {
  fnSetTabProps(g_iShCur,false);
  fnSetTabProps(iSh,true);
  g_iShCur=3DiSh;
 }
}

 window.g_iIEVer=3DfnGetIEVer();
 if (window.g_iIEVer>=3D4)
  fnBuildFrameset();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:ExcelWorkbook>
  <x:ExcelWorksheets>
   <x:ExcelWorksheet>
    <x:Name>Cover</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet001.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Intro</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet002.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Contributors</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet003.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Security Policy</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet004.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Organizational Security</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet005.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Asset Classification &amp; Control</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet006.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Personnel Security</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet007.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Physical &amp; Env Sec</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet008.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Communication and Ops Mgmt</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet009.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Access Control</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet010.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>SD and Maintenance</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet011.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Business Continuity</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet012.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Regulatory</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet013.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Other</x:Name>
    <x:WorksheetSource
     HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/sheet014.htm"/>
   </x:ExcelWorksheet>
  </x:ExcelWorksheets>
  <x:Stylesheet
   HRef=3D"1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment_files/stylesheet.css"/>
  <x:WindowHeight>7665</x:WindowHeight>
  <x:WindowWidth>14895</x:WindowWidth>
  <x:WindowTopX>0</x:WindowTopX>
  <x:WindowTopY>1635</x:WindowTopY>
  <x:TabRatio>886</x:TabRatio>
  <x:ActiveSheet>6</x:ActiveSheet>
  <x:FirstVisibleSheet>5</x:FirstVisibleSheet>
  <x:ProtectStructure>False</x:ProtectStructure>
  <x:ProtectWindows>False</x:ProtectWindows>
 </x:ExcelWorkbook>
</xml><![endif]-->
</head>

<frameset rows=3D"*,39" border=3D0 width=3D0 frameborder=3Dno framespacing=
=3D0>
 <frame src=3D"1SecurityPolicyAssetClassificationControlPersonnelManagement=
AccessControlSystemDevelopment_files/sheet007.htm" name=3D"frSheet">
 <frame src=3D"1SecurityPolicyAssetClassificationControlPersonnelManagement=
AccessControlSystemDevelopment_files/tabstrip.htm" name=3D"frTabs" marginwi=
dth=3D0 marginheight=3D0>
 <noframes>
  <body>
   <p>This page uses frames, but your browser doesn't support them.</p>
  </body>
 </noframes>
</frameset>
</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/stylesheet.css
Content-Transfer-Encoding: quoted-printable
Content-Type: text/css; charset="us-ascii"

tr
	{mso-height-source:auto;}
col
	{mso-width-source:auto;}
br
	{mso-data-placement:same-cell;}
.style0
	{mso-number-format:General;
	text-align:general;
	vertical-align:bottom;
	white-space:nowrap;
	mso-rotate:0;
	mso-background-source:auto;
	mso-pattern:auto;
	color:windowtext;
	font-size:10.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Arial;
	mso-generic-font-family:auto;
	mso-font-charset:0;
	border:none;
	mso-protection:locked visible;
	mso-style-name:Normal;
	mso-style-id:0;}
.font6
	{color:windowtext;
	font-size:12.0pt;
	font-weight:700;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font8
	{color:windowtext;
	font-size:11.0pt;
	font-weight:700;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font9
	{color:windowtext;
	font-size:11.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font10
	{color:windowtext;
	font-size:8.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Times;
	mso-generic-font-family:auto;
	mso-font-charset:0;}
.font12
	{color:windowtext;
	font-size:7.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:"Times New Roman", serif;
	mso-font-charset:0;}
.font13
	{color:windowtext;
	font-size:11.0pt;
	font-weight:400;
	font-style:italic;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font14
	{color:red;
	font-size:11.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font23
	{color:black;
	font-size:11.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font25
	{color:black;
	font-size:11.0pt;
	font-weight:400;
	font-style:italic;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font28
	{color:black;
	font-size:12.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
td
	{mso-style-parent:style0;
	padding:0px;
	mso-ignore:padding;
	color:windowtext;
	font-size:10.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Arial;
	mso-generic-font-family:auto;
	mso-font-charset:0;
	mso-number-format:General;
	text-align:general;
	vertical-align:bottom;
	border:none;
	mso-background-source:auto;
	mso-pattern:auto;
	mso-protection:locked visible;
	white-space:nowrap;
	mso-rotate:0;}
.xl24
	{mso-style-parent:style0;
	text-align:center;}
.xl25
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;}
.xl26
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;}
.xl27
	{mso-style-parent:style0;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;}
.xl28
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl29
	{mso-style-parent:style0;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl30
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	white-space:normal;}
.xl31
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;}
.xl32
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;}
.xl33
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	white-space:normal;}
.xl34
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;}
.xl35
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;
	padding-left:48px;
	mso-char-indent-count:4;}
.xl36
	{mso-style-parent:style0;
	mso-number-format:Fixed;
	text-align:left;}
.xl37
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	white-space:normal;}
.xl38
	{mso-style-parent:style0;
	white-space:normal;}
.xl39
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl40
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl41
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl42
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	white-space:normal;}
.xl43
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl44
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	white-space:normal;}
.xl45
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:.5pt solid windowtext;
	border-bottom:none;
	border-left:none;
	white-space:normal;}
.xl46
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;}
.xl47
	{mso-style-parent:style0;
	text-align:center;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl48
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl49
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl50
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl51
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	white-space:normal;}
.xl52
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	white-space:normal;}
.xl53
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl54
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl55
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl56
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl57
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl58
	{mso-style-parent:style0;
	text-align:left;}
.xl59
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:48px;
	mso-char-indent-count:4;}
.xl60
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:24px;
	mso-char-indent-count:2;}
.xl61
	{mso-style-parent:style0;
	border:.5pt solid windowtext;}
.xl62
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl63
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl64
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl65
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl66
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl67
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl68
	{mso-style-parent:style0;
	color:red;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl69
	{mso-style-parent:style0;
	text-align:left;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl70
	{mso-style-parent:style0;
	text-align:left;
	border:.5pt solid windowtext;}
.xl71
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl72
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl73
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl74
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl75
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl76
	{mso-style-parent:style0;
	font-family:"Times New Roman", serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl77
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	border:.5pt solid windowtext;}
.xl78
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:48px;
	mso-char-indent-count:4;}
.xl79
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:96px;
	mso-char-indent-count:8;}
.xl80
	{mso-style-parent:style0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl81
	{mso-style-parent:style0;
	font-family:Arial, sans-serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl82
	{mso-style-parent:style0;
	mso-number-format:Fixed;
	text-align:left;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl83
	{mso-style-parent:style0;
	mso-number-format:Fixed;
	text-align:left;
	border:.5pt solid windowtext;}
.xl84
	{mso-style-parent:style0;
	font-family:Arial, sans-serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;}
.xl85
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl86
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl87
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl88
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl89
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl90
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl91
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;
	padding-left:36px;
	mso-char-indent-count:3;}
.xl92
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	padding-left:36px;
	mso-char-indent-count:3;}
.xl93
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;
	padding-left:36px;
	mso-char-indent-count:3;}
.xl94
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	white-space:normal;}
.xl95
	{mso-style-parent:style0;
	color:black;
	font-size:12.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	white-space:normal;}
.xl96
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl97
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl98
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Symbol, serif;
	mso-font-charset:2;
	text-align:left;
	white-space:normal;}
.xl99
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl100
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	text-align:left;
	white-space:normal;}
.xl101
	{mso-style-parent:style0;
	color:black;
	font-size:14.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl102
	{mso-style-parent:style0;
	color:black;
	font-size:14.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl103
	{mso-style-parent:style0;
	text-align:left;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl104
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl105
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl106
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl107
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl108
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl109
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl110
	{mso-style-parent:style0;
	color:black;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl111
	{mso-style-parent:style0;
	color:black;
	font-size:13.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	mso-number-format:"mmm\\-yy";
	text-align:center;}
.xl112
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl113
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl114
	{mso-style-parent:style0;
	font-size:14.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	mso-number-format:Fixed;
	text-align:left;}
.xl115
	{mso-style-parent:style0;
	font-size:14.0pt;
	font-weight:700;
	mso-number-format:Fixed;
	text-align:left;}
.xl116
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl117
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl118
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl119
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl120
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl121
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl122
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl123
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl124
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl125
	{mso-style-parent:style0;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	white-space:normal;}
.xl126
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl127
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl128
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl129
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl130
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl131
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl132
	{mso-style-parent:style0;
	font-size:11.0pt;
	text-decoration:underline;
	text-underline-style:single;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl133
	{mso-style-parent:style0;
	font-size:11.0pt;
	text-decoration:underline;
	text-underline-style:single;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl134
	{mso-style-parent:style0;
	font-size:11.0pt;
	text-decoration:underline;
	text-underline-style:single;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl135
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl136
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl137
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl138
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl139
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl140
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl141
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl142
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl143
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl144
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl145
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl146
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl147
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:24px;
	mso-char-indent-count:2;}
.xl148
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl149
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl150
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl151
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl152
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl153
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl154
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl155
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl156
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl157
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl158
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl159
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl160
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl161
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl162
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl163
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl164
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl165
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl166
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl167
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/tabstrip.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html>
<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\tabstrip.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<script language=3D"JavaScript">
<!--
if (window.name!=3D"frTabs")
 window.location.replace(document.all.item("Main-File").href);
//-->
</script>
<style>
<!--
A {
    text-decoration:none;
    color:#000000;
    font-size:9pt;
}
-->
</style>
</head>
<body topmargin=3D0 leftmargin=3D0 bgcolor=3D"#808080">
<table border=3D0 cellspacing=3D1>
 <tr>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet001.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Cover</font>=
</a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet002.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Intro</font>=
</a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet003.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Contributors=
</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet004.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Security Pol=
icy</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet005.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Organization=
al Security</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet006.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Asset Classi=
fication & Control</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet007.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Personnel Se=
curity</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet008.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Physical & E=
nv Sec</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet009.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Communicatio=
n and Ops Mgmt</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet010.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Access Contr=
ol</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet011.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">SD and Maint=
enance</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet012.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Business Con=
tinuity</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet013.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Regulatory</=
font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet014.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Other</font>=
</a>&nbsp;</small></small></b></td>

 </tr>
</table>
</body>
</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet001.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<link rel=3DOLE-Object-Data href=3Doledata.mso>
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
x\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]--><![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet001.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(0);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Zoom>50</x:Zoom>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>36</x:ActiveRow>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1"/>
 </o:shapelayout></xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D637 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:478pt'>
 <col width=3D637 style=3D'mso-width-source:userset;mso-width-alt:23296;wid=
th:478pt'>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 width=3D637 style=3D'height:12.75pt;width:478pt' align=3D=
left
  valign=3Dtop><!--[if gte vml 1]><v:group id=3D"_x0000_s1025" style=3D'pos=
ition:absolute;
   margin-left:157.5pt;margin-top:11.25pt;width:162pt;height:108pt;z-index:=
1'
   coordorigin=3D"5616,3456" coordsize=3D"2448,1728">
   <v:rect id=3D"_x0000_s1026" style=3D'position:absolute;left:5616;top:345=
6;
    width:2448;height:1728' stroked=3D"f"/>
   <v:shapetype id=3D"_x0000_t75" coordsize=3D"21600,21600" o:spt=3D"75"
    o:preferrelative=3D"t" path=3D"m@4@5l@4@11@9@11@9@5xe" filled=3D"f" str=
oked=3D"f">
    <v:stroke joinstyle=3D"miter"/>
    <v:formulas>
     <v:f eqn=3D"if lineDrawn pixelLineWidth 0"/>
     <v:f eqn=3D"sum @0 1 0"/>
     <v:f eqn=3D"sum 0 0 @1"/>
     <v:f eqn=3D"prod @2 1 2"/>
     <v:f eqn=3D"prod @3 21600 pixelWidth"/>
     <v:f eqn=3D"prod @3 21600 pixelHeight"/>
     <v:f eqn=3D"sum @0 0 1"/>
     <v:f eqn=3D"prod @6 1 2"/>
     <v:f eqn=3D"prod @7 21600 pixelWidth"/>
     <v:f eqn=3D"sum @8 21600 0"/>
     <v:f eqn=3D"prod @7 21600 pixelHeight"/>
     <v:f eqn=3D"sum @10 21600 0"/>
    </v:formulas>
    <v:path o:extrusionok=3D"f" gradientshapeok=3D"t" o:connecttype=3D"rect=
"/>
    <o:lock v:ext=3D"edit" aspectratio=3D"t"/>
   </v:shapetype><v:shape id=3D"_x0000_s1027" type=3D"#_x0000_t75" style=3D=
'position:absolute;
    left:5760;top:3600;width:2160;height:1440;visibility:visible;
    mso-wrap-edited:f'>
    <v:imagedata src=3D"image001.emz" o:title=3D""/>
    <x:ClientData ObjectType=3D"Pict">
     <x:CF>Pict</x:CF>
    </x:ClientData>
   </v:shape></v:group><![if gte mso 9]><o:OLEObject Type=3D"Embed"
   ProgID=3D"Word.Picture.8" ShapeID=3D"_x0000_s1027" DrawAspect=3D"Content"
   ObjectID=3D"MBD001965B6">
  </o:OLEObject>
 <![endif]><![endif]--><![if !vml]><span style=3D'mso-ignore:vglayout;posit=
ion:
  absolute;z-index:1;margin-left:210px;margin-top:15px;width:216px;height:1=
44px'><img
  width=3D216 height=3D144 src=3Dimage002.gif v:shapes=3D"_x0000_s1025 _x00=
00_s1026 _x0000_s1027"></span><![endif]><span
  style=3D'mso-ignore:vglayout2'>
  <table cellpadding=3D0 cellspacing=3D0>
   <tr>
    <td height=3D17 width=3D637 style=3D'height:12.75pt;width:478pt'></td>
   </tr>
  </table>
  </span></td>
 </tr>
 <tr height=3D527 style=3D'height:395.25pt;mso-xlrowspan:31'>
  <td height=3D527 style=3D'height:395.25pt'></td>
 </tr>
 <tr class=3Dxl24 height=3D25 style=3D'height:18.75pt'>
  <td height=3D25 class=3Dxl101 style=3D'height:18.75pt'>BITS IT Service Pr=
ovider</td>
 </tr>
 <tr class=3Dxl24 height=3D25 style=3D'height:18.75pt'>
  <td height=3D25 class=3Dxl101 style=3D'height:18.75pt'>Expectations Matri=
x</td>
 </tr>
 <tr class=3Dxl24 height=3D25 style=3D'height:18.75pt'>
  <td height=3D25 class=3Dxl101 style=3D'height:18.75pt'></td>
 </tr>
 <tr class=3Dxl24 height=3D22 style=3D'height:16.5pt'>
  <td height=3D22 class=3Dxl111 style=3D'height:16.5pt' x:str=3D"'January 2=
004">January
  2004</td>
 </tr>
 <tr class=3Dxl24 height=3D25 style=3D'height:18.75pt'>
  <td height=3D25 class=3Dxl101 style=3D'height:18.75pt'></td>
 </tr>
 <tr class=3Dxl24 height=3D25 style=3D'height:18.75pt'>
  <td height=3D25 class=3Dxl101 style=3D'height:18.75pt'></td>
 </tr>
 <tr class=3Dxl24 height=3D25 style=3D'height:18.75pt'>
  <td height=3D25 class=3Dxl101 style=3D'height:18.75pt'></td>
 </tr>
 <tr class=3Dxl24 height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl110 style=3D'height:15.75pt' x:str=3D"BITS ">BI=
TS<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr class=3Dxl24 height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl110 style=3D'height:15.75pt'>1001 Pennsylvania =
Avenue NW,
  Suite 500 South</td>
 </tr>
 <tr class=3Dxl24 height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl110 style=3D'height:15.75pt'>Washington, DC 200=
04</td>
 </tr>
 <tr class=3Dxl24 height=3D25 style=3D'height:18.75pt'>
  <td height=3D25 class=3Dxl102 style=3D'height:18.75pt'>(<font class=3D"fo=
nt28">202)
  289-4322<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>www.bitsinfo=
.org</font></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D637 style=3D'width:478pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/image001.emz
Content-Transfer-Encoding: base64
Content-Type: image/x-emz

H4sIAAAAAAACC+y8CTRV3xv4vV0zx1TSMUTiixDHLJKxWyKZZb43mTJPlaHMV+USSZRkrAwhVDIP
NzdpokwZK5EQKakUvddUKvX79l3vWv/3/66ete45+5xn7+fs/Tl7ePbeBzIAgDP4JidIP+tl16+Y
AKikA2D9tl1oAMiAKCsZIF2SQj8IBelHDsAGkqL7B1WTMwXAmJMDkgEgSvqtJ/1I5kTIVMgAFynM
PGePuaZrziZm8TcX10EWAAvZhbgbVCgAtGiPm5RuKcy/LMyrQv01jKig5u1SzF8FKdOoAMoaGQCu
ynx71o8yd++Yrs52BjqOuSIyaO7Q0AeAxpRkpYaMVDbAuT5RYs6mveouVQAKj8YnTl4kXVPpahtu
I52/fPly4XFKDylE677D1AuALnYAylFk57ZhFedKramhanjo3KvkXSfzKk6f17QPe5Sn4Fpm1MLc
7X3HX1iGQi5XT8/9maxr8cWbUfsNHxmk2gUR1nGpXklOrTZ5+FD8Oe5uce/RccVSVTMzP+DIG+Zw
XvRCVWlnKOcxbBBMdfT/lcMQGzK92rkiBdPPhuDGrhyLx8ISUNO0R3eUfw3ME7FLFCI4fPTpjkqq
kbeKe3mrJjE6pR8i34VAGWlKY0QljOit0LAqUmgXpmKdbPPVWz03aPEEncu7EmJzPhpedimlxF/z
5bp6ZV8NzJmGMOLIymjxU6nhGy0Z6tMdQza1bMJsyTDxjCbuk7lIxbrDazW8/VPbPhnjfSwKcq4o
vlwpGifalGn9UMqMtIwK/5ohJitBGzpit/x+RzlGX4+TMFWW8oHkAGOZ5qEbokNvWPH1u88PH/U8
5VjIdPp8rjw0fjNVKhPrnFOVezdMIkACf76hua2OxsJGLoTFxctYUsuEIePN8/W7PiICkpbH0hEq
ychASQk8B+yjusHxpQhmy/HK9WKHKUOrLosahaM0ZJR4qjjQTX406Gj1QlToGz+ZRrrmd2uEB7uY
G59bTTN7R2WjRjZE98qqWbncwnpjqesEK0foa3ZYbzzBAXvhorwj4/Up0IlX/b3ZqRj41k0bWgrK
2pTtntaHM3a+dU8KgfGT8V1tTUPNqHX5XBEsG/uEHytIS8CJV8ilsnP4pS962HmPtiL8Dod3oj1N
S15XkhNeNCvdsX33+ERBMEtpkP2l3kNsCpqbYD49J8XPDpF6HRcizs2qwaEjHzBFSqOZbFDWoe0u
l53VeAOFLn5Rg61K3Tm2jmZC5Ptqg8Yy+UraZDgqb3PvDz5RR9O3Lf9I3q5w7gNm9FQWPXtesuzM
KzW/EyQRwI4/1pG3bn/Pq9d8wOaesIxoluPRAT34qY00c/m7+L7Ork2w7kj03dGxhkcOnsobNM38
TF5nosf3MsVxFtC3vnPuuWq4oeT+4fsSNPuhM9dOhuWn8uPvlaeaiOjZe21QeAzjbBsktPwY1u3c
pqEz1XGd+DpfGr9xFXR/X3aOx+UQMkvrbZlkyAZNtfKHyGka/LEDZ7YWyeJV13Z/lF0tFh5Pydex
6wL2Msslvy8f3DhO1AS1ZTLEc7Ja7EvjjyDVs/KG5Lcs8JVLFc1IK62VjVaHMxV+64GHMeGNoSOU
Nh8isUHE9Xi8gVLW2hr3HpkD5Nvd5FHk03G6tapnqARp+CT7xMmJzCNFL+F9ChQ2Oz6xPqTHhL2n
YOzdmTzwGMHvro/CBbOMSlbRoXm2AIjcm4YoZZkRI4nRsIqVp+CzGFQxjMOmrj69brV8V7a265fu
xqYEAs3jHkb1mtcBNESuxwm6VPjXTkbbMXefWtzhhe20kaGDOxJqEzdERCNnmAiG2YcCXtzBhinc
kJjeWs8Cq5ftJLOtgbuazvMh0zvWIxJQhg0yef9Zbb54BEuZu037pGu72DVAXNXFbpSCk7iWpkSN
EbXyUb2p60GGt+/MDfLEcJWGM12r8pqsedfra4BSb9+oe+BqhwhGu1nLT7vmKLVxRqdpZ4ldTWI1
igi7jM4IekCEN3FiN+if9xr5rf4ygKD8cVm5kS90aaGe5FNTeZuR6C3CNLU7zt2MwCSaT+ygPSWN
v+L09MKFYazGmGm8+TtE+0JDZbN+NSsaQ3njn6cvn5zv34bgMs2vSmLCEjJyIyQE72MLXtjCp1O8
ay3Xl+hyihBMGPGYjHNk/QcR+6vZ1hZ7tiGTY3VVMtRoXXYEdXaVXMcIL1zmtqniWDUNMUZhfwRm
qOoa0nSDBp0S0qz4TjRk4rMVctawXxaZo0N1rfxu7gjmZrF2BAY/0cNrSW6za3qzouwdjCEVR3vN
6zoa4XDbYohoYZLrhNHWhHO9DO9gRPsgdE6aPZzqhTlV399eAz9yZdyOGVLJEOXmEQuWyLzD6WIR
jrRIiEWWudLbkGrGBzQy7U2B8IRI5Mxsc7Uk57Ogz6uv6mWnymJDmz9rc8FuYarNirwlHhwbTVRu
NY+y5sWXZY1UIThlCuK51QxRJOPB1enMk6tgg+i4qU4CRG5IkyHGTcqBFga/uf7xSHxC3dDAbPqh
z1VIGylNzBpoXYhE5ioNqR4m3DtZckINTzhy0Y2cTzxURi6fA33MXg6H3fVILDzN4Gowxan8oKf3
5Gj2bE+Y9YbvsMB3DgYXPvf5IjKLgVP3w/+8K5OAtEhPpLOZEUP0DWaEjAhC7HM8J8q9ldnQ+3v5
LujDRiV5a2uFrO4HY4OOiOKfrkHQ8el3JXBk0ZVcaGs9DsKVN02UB9MgmQxFiPwmomJSI7SrOhsm
WjzlIABLYGMLowuC9aRafFjw+VeFcGTT2Yi+m2LcXng9jkwYN6cgw08myYUtjlBZ3OjajreUCDGh
pik0Fer/GIU5FegWuqhSNV1bA1uR22BgYwmI/DgW1r0rF9TcHgDFYPecGQopx5DGHA6jk5/V5q2J
BTUjEB+ObP5Zfiz447QcEPmkHzx79tnm+XvfDtNpiB0Oa78XjjmGVRHAkZ2xIrOxgzXOuq8ymS/V
8oM3A97k7gMMbDinLYiQkPj6jPlD5/bU45HLzaemQBkim47Pj781q6/NZW5oA0z5MnxpUBYkfJi+
NgPjTO73YO9ChNuTanDJkXivB5PvnGikoJb3wRPvRB4qb8dh5x+fien2u5dc+tqdljR078bpbdlw
F1F5F3ms2y+NUCpNyOdhyNgkSnraESF8OBbeZFTfSnB4S/+xFJkeJ8+Y5J7dThCq3IyFU/1gynyS
hRHslm3RdelHZPH5l7OmfW7R05VBaHNjVgKQgJgJoJUgJPRcEg4fmHGGwycOSeAHSAPze65w9bpW
xHX2n76qD0eVArfg87OEcFjbdHpGMz1N11nLD1Vb7jwI5410jjyeg9PTLxjBnHqXV0+qp5QZzhoZ
HGjzsceUSCOKYb46oM9cysraC9uE26+tG9p5fPol0nkyPQdLsZq5DKB3XTJhzPhihRyfNsaR5YTr
tdhb0mQ0PNCHnXbxrq3Zo78mzZA+Y2iyfBXaPCabDd28rike2XlcNLwwYDXs11323M8OTjWDt7WW
rULf7tHcCMWnbxLqN4MpS48I4y/dbx18sTE8LeTMqur8cD1mCsM6IU7pUhS6oDj+eRr9GOolO5XD
hyNIZ8iWuS5qRjeAd2sBLpZnVXzdkBZ9hzclZGlXGywSrmeU64R93ndjdg/sNxMSgibVVjrs5QtT
By0hvvKR3DCWjnVNaxDt6wFu9NispLZVJfkRzXaDG8P01gRZodSZfNbcMKfOeN0Tnot9PrgPTlWD
MzrM5R9P0sF23oJ9fWpwkZnLMXO5oNjHT0iAqhkgqbK4cfd1eMmS/OA0+p5T7Q1r6o6O75r2YcdX
VJBaM1WGGKikIjrUNpTpNGIaZi4UGPUBdNttCyqbnNxH/yBPrsu8B8a1DpEVZTRUvdkujQ36VDaX
J4YFEMlGEi1JWN3Zfk9CzZWxlrOXP32QhB/buViiCNG3ks6djsYGHcc0KNY+a2UdJ+M7DEViROON
yqjQ4w93DIqHSLw47xZNypPWva0ypOZKQ2R9nDDQpoXFi+EzgzfARfq2W5XGyfl89rPWMpc3VicH
MEAvdFwMOB/oodSnLtc7JVlTEBhUH90qpCDqDzx6KwxPfTgUTUvqJoL1us5YUBDoVePaNWkhvUtv
3Op6adDdaFr8kT6D3iNWlBniSjJ0mAaBjE3eL33ZIUvnsWw9YJPvNXexoeloSgcJC7DpPmh4NcWk
1n27aqiMgXBQrADnw23IUearx677fkTapqctKEKPl6VfOrAVv9n3NKUPCyTZdPTM7QgJ/loqnzWQ
Zf4F96xaROUx4u00eXiD7t5Dgu6pF4qwMKF+qyVVKCS9IUKKE11wMN5ayKQ2lTzKndITm9rj9qab
n9UhTD3KAibn8Dp40XsNXqWPo0IHphJajTtcdzjSUTtpGkRhPMueiO2/1nTpDoaiLE43I5aa4HKa
vofUFFMVaestTZEtSX1P1kRaTuaZrVa45oVhDrgTQFJmUTJYCELkp3ASzznpXyrAmW93ZXkx1O4Y
mqUnp4ki+/LyaMUq4oyJsYeU4gaX1robn/Zr69eOhU1mshF72l/q033cbUVKbkjfP5a7VfhdGp33
vr1lTzJ3bilnRg+NhUGMOVhdoloZM/oK2tBdl6F/kMdVl+6AYIuPFSmcQvZwWH32oKFZGQanRxGK
sD2MR4gxX8LE3yF0FqT2eEWR16ypIjb/PHJghMmKM/5qamlGf9W9EM52EWwYZ9TpHTvXdvtu7Hmb
t56qkpXYRPFckYCoUD5KtODQOHlKmTSMHFXVEqiPvl4o25WihaUw11XWF/bryyxxHmgf1YefsrUU
m7ydSjc80ue3Cf+Zs/1sQsCFN5/aSA1RjmO+oza6c1fjEXMZG/qIilWJjkmaV3sdTYRlctwVVxfl
tOsdSU4YivLV7ZiBZ1m2RuUweious5Ey/qAtNcdaQsORz6Q+Nf7O2/HGKrdKDrTD1izz4M4TlaON
PoP74doIvE5R5+6IbatLy7iITU2eosaB/oU3y0nuWkhTm44xZEPXRTfsCZ8xCCe5ATDVeQ+XiyLt
BNgRvp9nJgE5q3qRR42QXDsTRaP5K7dnBREsHJ9Gzml41x4QbsFoD6At5YJYbpgW7zpNUCk+c74b
oJ/Y5V1bJQHpboZGdeqyRXsAej3NtXXCEcF4QrbDdrEw1feCB9bqMpKTJ8o+iFWsSf0UJydIa+me
YCtT7FkSpNqXskdTGAMRDe1afOjhyezmxxuHQvI0rsNUDp8vIg037hSZkpGLVd099JkbaTBvZ1tt
WBOkIyzFXU0LyV946VWOQvumeqyGb9fPCmNS7+2RzCivWW/GMNJN6i444MMGQ32WGN122rH8YAkO
A5fTTCXBquc41o3mB+t9tuzoqlmvE8U41VYTpMInPlzGBMlnHyOYkpOjosapCDz9qgkw1agSDZ84
dzUTFFhDz2TPAN00H6x9h1SQiW85J4MgTQ1vnqCRCoN+BELgXS8uVJNBB2vo1ZuE4X453NNwjuTH
Pqzo06ElIWT3pfDFWJUt5wee5GFupFHtyQshi9JNMpglXZETqt2ZSEBe9B0MezopyOxjVBsktSnX
733IUwvB7ViV95MMWPldQhqWUL8GbHpwv1woti+FC9cc6ATrBIZ0vQwp13YyPRE7RkWo0lGorGTE
5fe8D8O+F0zutaImbxpkPSIHp5m8gok8TOSf7eFLdUGvt57XHTqAXN6R0Zr0RRtuc0/wyGGkiokS
ZC3jgSp0dMJi+5/OYJ64VNCmsxOxMHPdwKFDyjAcep6G79KR96Gq1TIG1BnuKv04BI1TNQ2/UbgK
XbB6UHvnDV4ILz0pi6tFLnO233fOoB/rvnud6MZEaHmiAW8OTT0YplofFY/cfdQ2Thd6nPPLHrjJ
YctdAVL34noMG0PrhbvlRmvjvKVg1gImihGCxjS2U8cjqTaNQu9PI9oZtUhqMwYWrAuK+Sejw7+u
6WlwNCPJWZwe3cqCxkW+D0sbf+YTsYeWHEcuaVGxEX8e+8FVAi9IuCItTNivvglyEbKPfr0LOzSm
4fIhDjskpjd/crKcyQ/Hog92eqcdDG9WxLFTEa7M6ONOEBqynlhitaOfmsE3U033HAxP0y55856H
QZ2SI+/zzHaCbjBaJFAKvxqT6FHtBqlvs8z7/NGeAMO4Zky5DxeaSBHVVQc/CMZSqVZL4Y/NLWX0
yRI6rnYYkUpQs/48NsLHHN6NIxtmx7EQQDIDn01Z32Es9KIGPkKBb85BETDwTohcet59MyMZ1USI
PGRz/ipEXr/o7M24mn5JpR/TN4apGlLieNqisBBEmHfaHPbNxbuJbBl5Q00yFO3zMYODeBc5mtnH
SaxD8Ee24u+6DbuSnL/5JRbmOW+K5FIloxbszztykwaYSYgwZAHLnWO989W7PPVOSWojyYudz/Ri
yiaq/tfO1ddSQ37yRUmHQEa8rOX6+Wi5WOmX/GaceEIuP7KQknTIoxSTnDv3rCM2k7xMquE2pCzg
LcmNFcPjUexzLugYY0Z84JcJZFoK2z3hnzdvdbPciZ3zASV4K9Qf3RceuBn/MaLGAabKtIVjprRh
doMyK6aM1HP3rkwnYRFoh78A/pynG2QTycwY2JaI1dV0o+V70bmGRMAL+/zQIS9YwVChQtooOkIO
V/g5AP4onk3KcClykjalJCJNPEd5HYme88iL2oaNEwPImxdb7w8ZyeAn7GvgB2GxRqLzxbuDfS64
rnlMDzZ9NTX/Jg7kGSjnYKESXPOggNIatPE7VyjDfo7v1dogHpLL1nj8MsY4uyAi1lLXiw4/e6sG
SXtISs0oOef2PmcMMeuvhfq14dveSUcU8DJrOy+2ExrWDZuJXlJD9ClFYNNt8+AqudFj5Tu6drjm
BrbWMVsHNmxBzZN5Hy5hZsdU1zDyQDyoeeACl06wxBcuWOClKuxyIFYcF3vm+hc+zPPNdideIXgp
jPY/sz1r0TY+R3nhjTar0AlGzymRNztJ9S5Wxu0SN/HGpcaAGn8yfIWDux2Mjnu1miBPhtsRv9nZ
nXSPIP3Y+ERtA9f+CoDuTe5MpOZ7OjUthXGO9hl8IQGfiSf1zwkvYavdtzBXfe9bkvGJeBCQy2GC
NXtcmfguCX1i0YfR6Y9OIWVbXozREY4RnbANYWfm4l3KSHoQLNHDjdbZMkSRqgofo3Ft1Mz0ocRz
9Y1SU0L9EGxz/9rcdfc/xQofDtOgx0SPltcNJe/jhWnND7PgZ+lg9uweP+M6ZsdO7RdiwbEH7vt1
+RowoxPExLrKtTCZdzxxoexEWqSNC7OngRJ5yND5/GJOaOHzqyLzlzOzQ9dFVeHmk9Xk+KsHK52K
GXE7EmbMumWQsnP7jNPX47P6bAaNsulJLrnwR1KrosNoOCmcMnrFAWfXHSBEp3jXbkY6LV7kB8cO
61w/3+o6FYKkX5yWnLuxv8+/4LQqrGewQTNhhGRw1eGRYUVDygwEyCA7t3aMfZpsuHcy/shEgTcO
+1FzLZfSbTqb/GLM1VLTIrHG28rnsfCJsOSQs5YUfNzUUbMsTISjrEp2p2zXetLiP2RrfViNY9l8
G4cvbhJ7vgpuRtv8E32JwWY/fgN1lfjbV5JwISTlsYUdNyA4qwZjb2n5t93B3DS7FnwFxrGMmdNH
HMgPZfHyeP/yqSvBmg0vtu/S6ONnb9Xgp1wiRuE0+O0NTYlbqCvVGGsSJXMGd7yg+SSvN6ZB8lbu
V92VcR9rRerab6sUzk8uj9fQXIspsj/8vOwABz79ms0znfznvTR45rai2y6nvf5JGZg6nBPEsl9V
sIhOFt8cMpHKEHVMCnnWTXJVKkZvJ0vALnd1NSvFwppP0t40emZ5VQIOFqloKn6hChMvccDe69Cd
3ARQj2laa9HMmVc+ac9Bqu7RvoWMJ9xRbiasaE6PaNGw08F6D4entxrVpkqGW1VexUKyUNFk1QfY
mi5UYX863ewa1nDV+lVvhDfSpkTXIltba18zJW2R+CwgxBjqUERUu3WeUqp+B3tKEZNKxSpJB34O
MhxZEXaSEfpyldGcbmQvPHuoTSy9VavGQT1/YPraSxh6vVFOazIm2pPPw1UQc2MgISDSgN71C/c/
H7ekeBYfujZEY2+WI/Sh0M/Y4sjwTaGz5u40VNOnkm4VoEc+qT3Xqr1Cdv952ym0TV5ACNV0i+0g
bw7vG7FBOR9XKSiG0ibt8hahW8eHvWiIauWr1hhFDameLsLc3Sf7yFmjECeje90zfrNWnT4jProh
gUxdj6t/D2F4F/GNatPtt3x5EFtwV75Kbf2e4gCR6ogI9ZjDsbYtqRfemCLEzKizwqab9PR0nqbq
jfkamZPjsPFrhOQvFm3lHSdz1an3ZFIro/JWj0YazsfrmxgmkxVf32ZqmSJJn59HVkfjI5DfOH3r
nYrVQd2nsQkbTUNr3uGQaW3YRc+H6+Y2355E+dW2RVRMCjw1qSEeO8N7+nlPZsSV5+zYzXsRIqdA
cNrwCfXWjWovtwX7tmu6MEBQ+0hM49maWrmYlNL3Uvbvho9xaAicPxpYXN5adCT+aoy/J37fGD6U
pUBF3lsE12zXxv+srR6p+7gTu0VSZJXXiBlsKc9DAGvqDu1r4xtui0fSbdfWCvFcLefEy54tEK/O
ni39YX3l/9rDScTTJONLrJ/94rAtBrUJ/P+iYD8dUnfCIwVcj3ZxNqzrGHNwPLs9X10vatdbtt4u
6RzJVURRLcv3X3anVJ8+8Gnki1LKF/PRjyMvAnE1e2c//yP1Snb2xECw2KBypl58eWvgbO+U99WE
FOmBNDPDXupRg8D7KY8vzRQErlE+H+ibs2kD2eWr+ZFtpy8+SE6W3P9QLue1ZjsBCc9xeancYt1l
NsUUp9XuxDKlYLlJvrFYomXPGdFXbGbSF53vflD/PGwowVR9Y+aSd28hf/uzQHvYvjbxJILGjoeG
SNjVJmofsQxnq5xpCE2TPMiP/4eHeFn2FWWiwiQH8ZHnBIOssqwuDw4f3ByahuAnZh7tg3B35Zyq
/Uvz2s01no5/uhh95WrrNXMueFil0bo4/0NW3tSgE1OK8t2+SB1F1fe8dHBLM+dlDvKdQjWtlwqN
BnjyhJ1bAxMfohnMZpptPPzJIjslNyPEB6uoqIlFPC16s2bXJFyeP2okzyHHUB0m1hzj1RfffyeM
fxPsldVuXhISweTtpm+UeLN29sJhw/yK3Bni0IaT2X40WsW4wuQLGdo9I8OBo46G11p4ci9WPSms
L4safs27wdFks4yc7hd7m1oV7VTbYuRIqv9uo3CfO5kS+VQ4VzS+2dQQozsWaXk4N+Bj9xYp6GPx
W+wOaiU4hZa7sZQxh/zF9VKKK6bxPUen2kPI3llfVkr11ZLOPrWhNTX3dTSUjuDkXl7wtuaSsHXs
mRKTxvdevzJzIRrNTHz2sWizsGcUNWb0Ug5psJu4xLn5iMJ681h2xaqDXYcn/A2vda7LxEKNwjVN
9sLG1JgP9tmOLvYM5G52RZjRtLscQYUpoaEKju/+SY1+v/e4wT8FspCtZtMB7CQZnPGGC3u5w+cM
DxVu+PQOOLc1mAI7unlUxN114sVQre4mspqmGRyDuukq5MgdS1m8HmlYLdu6Zx0nznPnx5y34u8Q
KhSuSrk7UG23SOXLgWpA6JLbg2jQ30MOJAObQtTO1XTX98cN7zOhw62zN82j3VHzIXLgPIONLMLt
6XXp8yP0dkvV0t01uurCfNcZGfGmvijEm38v17UIS+3R3uFdw+5fjM9sgtkaAeQxcwvboC8NDWyo
aZJhtz2zCnf8rQ1iyBjWfHsa3m5AcvSqjc4aYC6zQT0s91hgBWYuWw72otwkgYr1nphRK1Nk8Isd
ISZbBnrV89ZNmMHQd5rnIzJ7z/NB+ET+8Tgx4QIGaPWTrFhZahycHWPMTiymwUk7ExzSFHJMmxHv
1fnka6mJ5J7UmKOrijCiEnCnoKkA4VBbzR7DdRA+UBc3gW4NmUgxDKVBWqoykFPPlVIp+1/W6opx
wJGyGdxgBxwYX33FmxqXHxo80ddqFIHMslseNjkciUtTPLjuBiZe2Uv5bsEGeGo3uXpHIgMU//iq
FSOUTfbqIvbzbqNMBvKc1/ljzjJQg9gXH8zVwXZaxJA149YoA/6lBczUavJkR9/eWvgOBtJig5wU
adVvlZ5s1KgdarkeIToDQ45M2D0sA58yqWrj6Qe5LZX2FmMuCxJ0B14qBpDbtCDGHyPICRxJtjBG
hkGd4fNjZP3Hcg5bA6SNKOx+sB03EdlrM3CFKyfiaacSRYbBPb59n1wIurspIKgg5MbA+5dIZvnw
FDnmQzEUXQvTwrupcVfSMaK08AMuuHLAWwYaz8aTk7+3r9HNyMU8v8dBcdhEvdgX2dqvoeFLB+lF
pvkLU5vZKlES/B4m4NLGTtU2lJNnrA3nhF89Yqn70BCKTX7iAfeTwUzpO3CxlOoMpmYImh4X0J2D
ubsRPvRPBNb7gwg1zq91vAcGYA373LcAwzaYjgdOBx4jaNGt9LgdNviAXmZswrt87cHaPW8we25p
917cejllkCLOw24rpJTkeJOCEYqnwmYNsmAC5JF9LfG0/SYCkPRJSvUoCbaaK9zvOpFJ6S30OHyZ
KLz63M3xYY/cEOw9K+Yi7PpGZmgvWyh1RqtjiZKfPIE0920vRWriuWDJpiDqrjxydVkRX2TQAjam
YQ6XiMAeaqPER+jQrsHC4ci+SOZg3qR4ki/Bhn+c8nHfxZON2OoInfKZa0NaG2jVGVydETODHVT4
x+ETvurS6of7UopMb4dKPBbiQ2qOBzWbKjNAei84YCfyXQaM0ObXdAi3GNQ8KQKrcxH56IkP9zAo
kdnIksuhiOJxJfXrTjvDu8+lORASzeMJuMIvx2uZg4nZiLFTnRyD+gxrhNMU9i4ZPBhCOJOwmUTA
FhPQu27vzZl8bn8OuLNK7JG8TKeQOiIqNxCGvz+9ufbyo4OTVRRoJhM+Ak1dk/o2Nsg3CSAKa4n6
qIw7oRJ7DE7KRbRcRtUTKQwVoVeHuYiumgnKw47tNP0M+/trmO/ZcFHZKVNTlW0UJDgVf9rU+eSK
ZIQiHeGsQtU9uM1HBuFIpJuLlhEs4W3c9CVfoHSgdsjllCoc19P0CUHUOk6E52PJ8JQXz5BD5/Rc
CMx6a2sOlSEaLfHU/e+lmIjOcpPc0LnIUpPQMCyd/v0uxDjLhw3ycKKuPcZkc6KMFXqmRJb1xlwA
L/hBvTZxPb7n1oz2JzNgU3w55YkkXg3OZSK/5VRSPZVUWnHn+T00O47M1Q85y+S0xy4Cq5AUImvj
dPZUmjbctdvgkwtzfXChHOkl93ph91T2DgY/CruaeDW0MNm7/fj40TNX+obN2kmdV+9I53hJIyN+
ZmdjSKEd4Ypf5aZQ7tdrkNe1s8bpL/1PqiY4OmHzo1Z7Uz6DmjfII9rNn4AqL/7g3hO5a/yVBFHv
MFcPDbNppO4+5LJRBLVGLyG40FpPDF9yl1MmVpGaiur5WFRn12r1IiU1MxFsYkkZTBo1unO4ZPFK
FK22myhIp3shhc8JsHbueF0T3xu1C8jdQ1RV9onUNtUbfTCJVrOW8PBOTAWL/5Z7YpDL9cCSF0rO
ofIj1J+d48Ol8UYlW32RqUiVBCUD5LrIRnriOSab8B2PgycmwkxuUeAvrCJKgVDuqbhgNBfxwD/J
DDaReU1K/t7duIngyDX8WFirvHw8R150E5ShCvu37y97cPjWAdoXtU1ypWPc1jYQ1VZ8DyrhTFBs
wFF+C/GQwu2WHMTeF9qM+E3D+shd3aDT2W/OO9wNfVoBOxJUnitCBg7s0IywJEEoojA81QM2L/ZU
wD/GpQmMfkTOuwudZ0eMG/Zbrb7jS/eF9Wk+rpB6yt1LFCttyY0fc0zD1+5xhtFdu3NPMeBkz+Ce
ygvy7tM+HLB121s4YuJueGGfi20dUjDFglwuPP6qokXAY6fa3sFob0uze6R3WkCFfs+PCbDSpKNq
TmutRUpC+fHWxmpeu83pbIRCC3e5tqCnVFkT73wU23TdFPET3MZKZA7GWqJSZkYxR9bUwew4PV58
nq92zQdI1ZqecDZdWtrS7Uitc/VNCPvST/CyHeGQA191PRs18cW9cyGF0lbB8QhRCJIfTkHuZllv
xGdDxOsXI2U3TJ3pfyO27tCdYN6L7TV6eTiskfd+7qDBSCx0bzuK+OJ2BobZZP8mqFNpFc5ne19O
WC8NP5mNWJiE7HjjUS4ND2zA9NSJh+Ew/gINkTU0WD0vJY2BgNCyU/EH8OKzfb0widSCHERlobWf
7e7UxAj1VSpdn1Vn0yoTTOGqSe58+FmJ1mYSZywK73Vp0Idfd2+kyJAL9abClSldDmcZ2YW+sdn0
bHUoKz8+cM2XDqTs1ZcLCOZ4KpfTJAb/2ls/5dz+K3omvo1hvL1kUXU1n2qvfRTnh+LQlQpHUPhL
1AR+X5MBu9oYIR/X0u2bbNLvrMm2hANjlev5dvVL4dcpexAzNPvrOjYZ1SEjXPcZoXcVe12Pxhkw
ODiNEwF+wlGEHre5wRGmp+3nXeVTFK3jKElNQI7XfbAV1EMwHFP78un0tCnxShnU6jJtz2IFLGbJ
YIEoenX8y/FrBsVOxVhIDJoRKzT10PxkEx3BcUQSMXPUaU/nwL1DnZV5xNX+QNfR7iXp1XCykhPq
kcmdrvubzZlwfi7jx26pMyqf8e9WzSSD3+T4d54kRPlBhqzpjAVh2Er5t4iyO9mGeLSSYQLSxofY
8eC61euauhRiiRFpAQnIEyqLD1XjPBkIUnFVbZfF2Z0u7UjmBaa3gW60d1kh+Y664dFa+K6tkwCh
Qdpu1ZkGGQHsKLsFXExJTgfVNcWeKbsggNGGCJ+VeXDC4gzkdTY+lLnvLj9Eus0VWc5FNYrQqieP
oKiqTilQYYaid+1aW3LleBJ5q6QjPBV1MVgii274dfla88li1FzSeltagq7jP/uYiOVGZd6713FQ
ErhUnVxonGi1z6B3P4g9TYGXMzBeh9c5veG9A/xaaNs6pkAlXV8gA/l+rL3K6fj0nnCPaYSqfKib
vw4ZnONmec/iQk/o04SOMnOfF/YdiPalCz3sXHCZis8kdjDTFSvAoL5OndZGtvQ9fzG1TUmOdXgM
I8ObEuTEne06Q8qMD0Za2xVfVn1QP9e3d6aDlxPnVZ6dm8FjLiqwz6HVen+t7hqH+wIeL1wdREd2
fuo65JdnbvrP4UNJcqK2chgCMrhPJDfl6e0m3c/WXMoDcoRD04i7WJTRzgI3397WKh2/3Ny3utwl
nSE0NZOtaZVJlvCbKdcrt0Sex1BYBPvnmB7U9wzrDUuWqqtZG2YrkmuuKmHraYwcMb13TLhr7Kx3
dTbvJisfDiPPXJosZcOui7mX25OSvclz5JwPXPbFPwxnku+OTFxF17f/EM24zzEpDvhpU6PB7viS
o5ovhEUfd4cNasw4VW7rDCoo2tLam3ut5J1QypmRi5zmlCaHiZjWuKRWQ2MZJivtWBcOJuIRVu/X
j3L3JQ/0AUsheI+ov/8971tSHaevB95j0M0Yhj7eE1RiO1T41HLcyeisC6Hjw0jw2IUK9pOVfrnY
mNLt8ealOLkndOhcxct6giNXA82phnQwzzI26tgeGQouq71+NUo78bwYNW7yUWZL60tnWKrF4SZ7
NDdedYCx7sr+fRj4S6fgffv6YycY8ZT0sLNWnWfuWwloFdXNtwweZyA2aKaZJyjYayiMXuGs49E7
/Iw2sgdCka0MIwKyNOrgUGg1GXHvbJg836aDoo0JMmnM61uzC3uF0mxRx/85dyCcb9gx0+rNrpEv
F+O2vI7os2RrTOlg1ptU98GysQWjYGXrlRbf/w8fvLXg5oTP1bolERPta08n0Wco3/isHmu8hz7U
jI0w3dZ6jDSt14ajqg+0rN0vI1J0mRUauXNMsFHUfq15pO31tYW1o1GmqY0T/k3gtozPRYEbjFFW
FSJXHt4dZX+ko3/7k26rnymuWDq+m9uM79It0V7Gd9tZIP916829ULjZJ1eu6WUGUpwbVetdjZxN
zb60Z+eJKUUy9cC+DVComYkgJfnpe1JnQ6aEH+BVCFc2NZQ0ZUrX9CrmsRUXcXrcf9m5ypgFrbVm
53mxWgMXRqR1AMHbw8SqVQOwg/TUAB/1w1SrpMNvDiaFC/lXN75ldODv6V57qttYwJoe43yrOEnz
BnmP9O1rqvfevLHzcfSYzBbdS9kczn9hbf/ZmdyHiUk05XUuRc3nr1t+2nvGiwzfo/omJiptTfXN
ky2V1DZ9vXG24p7xxsdPWSXGBmFP77mAOXrh2docx64EsjVU2dc9LxQMHn6r3Zr0QTc7JuipWPBG
ppvwDY5a/4Jz1o1rAi9ZwYcFGKsthM6V6QgUXhm+znMabqWr6TBBBB/06VKVGo6oEVJNUuNSSt9W
X5vUrmkSIW7H6G4by22mh2/czNKHiHE4lj0fdtfsYccJBYjwARuByFgn4bjMJzapszo9Z/WQ5/vr
pJ7O6KjUJJrnaJc96prJcL0+jLm8r1hkhNMh6VQJP9TaGoZl7rMw6NvVO/Ugr0SOxqa6WKBKMyVk
IhNLoVMUMRkcVEjEDLnRirLAGlBRwRYz2tCyRANkdhe7rk9iKDJZ9kx648Cmx6JZD/5hWZto6l3u
c5CBmFbfRRsZoNiJZebpYiQkZiB+6TsVQlLFtxvJ0qrnXeIMVg3LD5Sql8SX16xHiczIWJa56NvG
IS36s6SnHEoMmbDejUsz3n4Ao6t3cZaVycNHELtlSnkvcpR7tC9KnRU/Edis7qmID3eX/MDe4gkT
WOC9bhBVawlHxBiVOhN+tclBFFF5sPb1nQA1gwHHD5eEoPRntHBnEEPo8IUkP/gLv5cGVvfVqXEh
h8SXTzXnV60SahDrG5MjrBETDyS3s1K12nyKDhELK0RBXwb5GfutOT6fS87zg6sT6LFXpwtg6L1/
8IN1OIQnXDVcsyojtW/fe99Up1aqk8iTuGYNDeaI5uwTifWYptCqgxGq4dtp4TezAVEEmi0tQ1n3
Uvys2XFt4cgTr4QBhCgeosoYcp6J8LYm5OmrXTUxl4xYqTaHsAUX9pJTsXD/g2lgGfTCBlAMsmjC
TIEPHBGcDXKTeocNYuy3Q4ou9KbgLSnu2fPy+Or95OyItmOhUFgY7y3X3eESghhmf5gqaxVufC2J
8QsKiP1SMn2GTP+u0zczUI171uFr5Vp5SFO2M4+wMZv3Yx1eWMBb35Bs97cJ4WtuWDMTJ4/Wrt99
tiC4uczfgJTNYFXuI2Shoz4jGOaLgMoj8EwIL1WYTrjE1tHx85y7S/SHzthDBNLjUnI309iIDFvA
lhRUybmMVCwdPKG8ak3F2Jjam4yhrmYZSBvAx7sDZQ1rRvXJJA9YnR2fFlqRNRvFVXxEACNKBkvJ
bJtghjwu+Yvh7WnQDn4+FETy6jpXQuLRuNH1eKUwZU6qygKmu8zRtVcubpPCr8fH0vQx1nWQXzPA
TqZJPN/6gUNtDf68UP96/OHzr7KRI7ewp8L7eWGmMsuQ1Sde89LabOUkyppGnz9ctEsxvSDOE2aY
EXiIhccFCR+O1qZai9AQHCbSXiYQOqw3HWLBK3GJH6mQl4AMiPTY0XHTc7Q2vbnaPVl32Otu5r+h
kW7S5AkrrN7nJQtN1x7jIt8UrtqbtGXoY/x2rLP4JCkyXZW2YEqSbqH+x6jOnToyinQ29NL3K5yS
Q5pJNLj08krDBbkpuSIKk0vEw1Tvu9vPfQjxvBxNSu7WTkquXZM6eKe1Zr0gq6q6vpdbUfU6z62Q
ME1W+ISJC8DGuNm+o+l/OnYvuDkTw6qkwVGCyi7h4Yf2V3XfweoWz5RdOlp2P0zCeWuMevKLuvWf
hjKQ63YfDeEuu2dkpSGq9zSzzqSoTjW/ZvNeh09zfBDQVuYWXedQqQSRvz1HaaMCn6cfnI29UUeB
L/y4o0boLPFUiGpUiNEum/ReNXL4ZpcQO3JxcEYbHt/7gtDnJQkNn6Zlw2aFTrA78AvciNc+bGFN
QziI0YCr3BzhFNXWkjDVyvDTtDZRtR8S3mKOpsGe1wUJoJICVxqbZlUY48+HTA+O2yCNvcKH1kHD
vFOs4Wnb+bLtVOvgs9WfopGspLjbkwEtARsrhTVgYsfnF/L47bgMv7dW4p6HPnvDLeGpJbE2eY7w
6s37aN02+Mz2ctakWlc8xG78uENt8GhN4oMwCQmoYUoSngTpnWi/VBP3t5a6SJs8NK2pyowTiuDy
jUW4q+LqJjYbEvkZ5BEapskgqo+yhqTq23OckGpfH0iJ30hSzWLhT4wTJxSZpKlCA25vZ4fNA/tM
amCNzS/qmprTriVzqLR0PUOOHt5vTuocqt3ZwnidTxJ0eU5bxoRJhDXC8SltB/bmVBxrvp2dNYw2
UXAc98+SZoHTZDAoxA8bx8G9tmsDn24gfTzvRgnScONYc3jTnffa1Qd3VnWkiqUHu1vWwjYIatyz
nfD6vRDcm5EsDw0Pauz2SxdAD6s+O0/Sr0+5lXghmzvsMQJ9ZPI4TQff5ItfD1UeP2djKBalKa3t
16VyzXtYxurNKj8hen6oMOGI+no4MWdKAeLbcv9J666P6w8eQrImOEujDn1Rs9ZoGT7MQbW5Gb1Z
rZo6Bvd0fI3PMajskP8zpOGah1Gq6vkHbzZyXcvPcDR0hPOucO/pS6gKaKOBnirqnQ57ekL5tiQb
bgJfe4gm9AivZydVT/ptNtv0ztXsm9BYCrRKKNJ7ufv0Adhw9yY3oj0KHaloASvpHb2rVj3LJxgS
+0qzwFlPfV9RNYOPQPA6LVb09vctbwJ4lMSfxww+r4uJSKGjff5h7ePiHNOsfVdSsR9ct7TuTQvm
/NBUpkGF2x7YY7/ToAdv8aBrnGF7uR0HuoBRuRWOjIzdmhIxuAmJdlRgGd7A8dx0nYNkg1dLmGFY
yt6OsDLHWCdo+pbvlQJRSpv4R5lZ76K2xXDDJT1o+cDmkbdnUsNhKvP6XF7v+FreB2smxodKJruu
Wil0vEp2W5XK9CGajrAek3V1X1+ZtZkhuBywfp313S3SgY7Cbz2Soq+WNRV3oM9gJyMN2XisLtZm
Fxv3j6qQmg95q0y4nZBTnIa/ZFLO9O5EtoHtNfsxwp/WOyl+8B94v7nhpaw09CpUQVEJ5qu/HsGV
GdoycS/06Vo7yfaa9RWj5LbhWO+iL3zWA2ccn6sZYF7YC2VYc8zmlnv1vHgVQRu5uax38CmvsSrP
kaeC1/ZF2z/xEiqKeD+9vzR1OsdptITiedY2ni1h2clqX853BDJJQLpZJz7w1f9/zUf9dmj5EvjU
FYVes6t/+9wfZGlu09HIV8OEkII0KmQ0/KQzvOxvxch/+PstThWgIk06Cy3+LRdquTKGchsAiRpL
aWLmjxjAO2eb9NtL+kGL6fRIv0Pdv/6buCVZT4pcQzrrzj2TgpRm7o/NOhZ14O78MzCL+VmKSzb/
tBX+8GxRvnz5AmZnZwEejwfOzs6gsrIStLa2Anp6evDy5UtAJBIBHR0dePv2LXj37h2YmJgAnz59
AvLy8kBGRgYMDAyA27dvAxiGgZ2dHRgcHAQ5OTkgKCgIaGlpAQ4ODkBLSwtYWVmBtrY2cHd3B3Fx
ceDGjRtgaGgIXLp0CYSHh4Nz586BvLw8UFdXB9ra2sD4+Di4cOECSEhIAP7+/oCCggI4OjqCkJAQ
sH37dkBGRgauXr0K4uPjgYKCAkChUEBYWBh4e3uDoqIicOLECWBpaQkUFRUBBEFgzZo1QF9fH4yO
joLg4GDAy8sLLCwsQEBAAJCSkgIzMzOgt7cX+Pj4gC1btoCIiAjQ2dkJqKioABMTE9i/fz9QU1MD
QkJCgJ2dHdja2oLMzEzAyMgIVq9eDTIyMoCEhAT48OEDYGZmBmg0Gnh6eoLy8nKAxWKBmZkZiI6O
Bvz8/EBdXR00NDSAW7duARoaGnD37l1w7NgxwMfHBwQFBQELCwu4f/8+6OvrA6qqqkBXVxcUFhaC
jx8/gidPngBlZWXw5s0bMDY2Bqanp8GpU6eAg4MDEBMTAz09PcDY2BiIiooCDw8PsGrVKiAtLQ1q
amrA2rVrwc2bN4GmpiYoKCgAu3btAlu3bgUdHR3g+vXrQFxcHNy5cwdQU1OD/Px8UF1dDS5evAga
GxvB+vXrQXNzM/jnn38AFxcXuHfvHpiamgJNTU0gKSkJPHv2DAwPD4Nt27aBQ4cOAVlZWXDgwAHg
5eUFduzYAVpaWkB7ezsgEAjA1dUVBAYGgg0bNoDa2lqQmpoKrKysgImJCZicnARKSkpARUUFaGho
gPT0dIAgCPj8+TPYvHkzICcnB4aGhqCrqwskJycDNzc3QElJCfbt2wf27t0LdHR0QFVVFTA3NwdZ
WVng+PHj4MiRI8DU1BQ4OTkBBgYG8Pz5c3D+/HkQExMDHj9+DJ4+fQpevHgB2NjYgI2NDSgpKQHc
3NyAk5MTZGdnAyMjI3Dw4EFQUVEBrK2tgZ6eHigtLQWvX78GR48eBZs2bQJhYWGgvr4evHr1CuTm
5oL+/n6AwWBAd3c32LhxI5CUlATv378HcnJyYPfu3WDdunXA3t4eXL58GYyMjIAHDx6AtLQ0UFxc
DAwMDEBiYiLw9fUFIiIigIeHB+BwOODi4gIOHz4M/Pz8wJkzZ0BoaCi4cuUKKCsrAwICAuD06dNg
586dICoqCuzZswfExsaClJQU8OjRI3D27Fnw8OFDcPLkSRAZGQmuXbs212b+yl/5K3/lr/yVv/JX
/spf+bU4M3isdJvkUzv/JtUFBgboX9j+vxXKbXMtrUE2UsDI5iVz6M962QOR2tpiqlW/SM5CoV/E
HjnqsoLK+p6W1j3ThbD90M/60UwtMe1yeZWOk62/MJ59QEvrvTzLT/fr7mldzXAjBYTktbQyeH7Q
vmjUqtdWKRYO/9lgu3mx1pw0aj9R/0ElNDiv0bLSPvO9IpaDQ4N0yq0HYgw/GYwpFk9xR6HobaSv
r1iCdluRO7Eon7JhjRWUUBdX90KoNWd0BX0gEPkUg1L3v3dw4heAmpiAxUr3u+8PLgQQYPvzk3mB
iK56+6RvygoJR0HfF9IkkRxL89ObHgbFJI11qd4PdcF219xRF+z6+UWpy4PFFy/h+3mljFKAkfmz
zf6VtB02iwEvsBIfGhC8ELDJu/0LQMLgxIr3eWxzF/Uff1ZWgai5kwU4+rOOHyxQW/fmJ5WYeNP8
ufiHzPTM8WFkl1qhcX0BnYtdkvNLv5V6Fb0Gt4WqcpNhBXXKzMKZCH7BZ7EWqG/2PbUyH3IwveJ9
aLhg/syEc/9ZeQqcn6/b4MDPunAgN3/eUf2TSj5vMYrnCnwswJGfjcUcBJNL4USw9+cIDmCp3rw/
tkIpXrct1NwG8Wu/5YPiATJ/xgdlZjB3NKJmQq3EZ9vcSQl4/6zrX+Szgizx+VHm+ChF5tX+rMEA
8LV1PwAqK3TBQHgxNN78Sz7QWXDe//d8GKTYGf6MD9u1uePdFbku8mH5f5HPNvBkBQ036MldCj8T
t12Jz8bF0MDoL/mwAkeP/8EHZQn++TM+3bc2cHNzXwLhv+azAVz9D3xqfuazc0MxwBJW6j+Wt2Cs
/u/4pP2Sz0fx1XGo/8VnEET8GR/Uvc2nT5/WVGT8JZ83viIaf87nmeTPfG7y80uozazIx+vbUJv3
3/hMG2OPo/4nH4o/5kMrhkIVrNTm5/gonz79TjNsAPVnfEB879nVnSu2L9Rju58rFqoZ7F42aP4n
Pm4vQTbqf/OJ/2M+KLVW0qBCXJkPbHp7XepR1B/ykdJob2/ZvDIf1AG6uJ80Tsva1zgI+y98ioGK
+r/g4wuS/5TPHiHU/SIG1C/bVzM2FvUf+p/6X/DRAj97BDR5kUZL4WKg9R/4sAHD+SJc/z2fJDBM
/6d8Qu4z7HRE/ZqPIAj6L3zW/5LP1M9JhgBmafi6KRXyOz43VuTDZ0e94HZX/57PPbAJ9ad8UDmh
YPY3fDxA53/hg/oFn8vg8AqzT/2lDvoTMEH9js/HFfnYLU1Pfs+nn2P4pwnuueRlfBJXyreoFWj5
DZ9asHkF3dH/yact6Yf77LvmpwCWKw2Vd3ELLrA19b72FdROoHQxNLXSBEwUeC8a3b7S7OTxAh/1
L4qr+39SEh42feXDorZSea6DgO6VW94cH/WOFUnwr9RMFuTSAp9gt++n72bixhbcT6gfUq2YKDms
ggVVe3pn8AruNeO5LNCFmZug0R9P5RT6cRVIYEwTWC84c3ydmjVuP8G9CPpSuLkrujRFWVZ4Mrtt
Ijf3ZiDDzT267+1KWXOTylgxy9VW4K3cSDw4FPPzfJHfG3S+WXEtqru6UryZm7vMEfs9dEJo+pwc
9/gFVaPAsYvBa9+spIbmUwrODf5zgR+byJf09LbFZjqn/qkjCWmZT/80/MKKD+54nf5V4BVzd3jl
WT8+cC5JoMMKqmfz1pRWSrVm6Vk3/i9ZuFv/d0H3r/yVv/JX/spf+St/5f+AqDPMyTf3dP5yYVHD
jRRaWnXwWdhGoV/ca85lWNLFLEt+avkUzTkJSb9t7b78KXNmGecCc5Myo7kAtGRrQX7OXoz1c4Pp
pTVw+q8RF2YORl9zob7D+uv0CLPMHXeej537rbR1aenphxe3Bpc9eHHG4SxwLN36+2noBXNFUHng
2+bo1Wgg/i5tPnhIB0ifXkgZs7hLWboP7J+bMxdkagLL+c2/Y2qgIWNh5cOD69sejwdb5HAF94Ze
rNf8Pm6MGTvI2z+3EexgroArn9u7mrgMwOXncxOcq6kAUF/WdtXXXPPTasTO4bVyWSaLE4JZNQAU
/LS1D0rNb16gHlwCwHYtKdBaDg6kLaXhWrbfTBskBYwzlzzx3NCehny5mUy6rPlSnfKyBYCuS1v7
7eLqyqmo1RTcGQk7vs+DBfhu9SANfF10GtDz+DoRX6S6Pm9xzfuWwuJTBaXsFyN5gq98oEZQOJ8H
Hmr+hTumIH9Rd1J/4X0mg9TF12YPfOdeKaPVpx/5FL6d2zboaFzcLI/JA+fmzrJLS71dYL4unAW9
X+uIh913u4IwSP9aeQ4Blfm6Zb9z8UFUwG5u2q3+aH6/FcW2eg7N1rcXfpjxy343XwWNS8HPS2v5
pWCJD+qIxMKsP2/LUizcYnU9kfeNTwZY2uRPX1wAqvu61H9Kc2HJbC14tBQdwPOnved/5BM/v0RK
CVYtzenZF871i7tBJmCupR0DCU1fk6QDTqNlFu4B06XgdlC+9OJLFgNF7xbO6PkyPNKd70oA7x/y
sa4Up1viw1uyuK739ZOCxW2xKlugsMTnLnj4tQNZ3ILv/rYVcmRs/qS9UBfm+XQsrJf8tEJXuEAe
tC3xiV+kvfgxgIkeKV8XVhfRfksyCNAT3/FZWloKkbr1bKmObVjiY75wPj6/vS06362tB3f+jA9D
DrivtsSnLmy+UeSDr/tlOQunO8DRaolP5req8XV55RufY9rz7VLPDvUDn1+J7PwWyHI+S2KiQzpM
gsxla5Li7Ka7v+PjsxjSAhU/WV7is1w+r8jH6NwKfMTmm+0oCLrwlQ/q0ty7ctP/tpm6wIcNsLd+
5XMTxP2GD6TMML/0mPgv+UCXQNp3fJS+4yM4XLRsqWcEDDE+vLASn07wYGU+6t+vzt371mMt45PM
vQIflYWSKzehvvHhfqmlpXUWpHzPJ8Su8jpqiU+s+E7G3/BB1TuSTFh+7VT+Bx+WTLDPbTkfetZv
fHxzc4eWp85FAwHUq+wV+MTgROhX5lO1Z/l4vg34xv3Ap5Cf/9jmX/HZweEbjlrGJ86uOj09C1B+
x8d5/kOPJT7+4CXqd3we+M39WY2Cx7/ig1QCjq8jNnuYgIDAyW/txATsfwfEHy9vHKTs0MIr8GkC
2J+NF5mQ7A2t/XbDYTOQ0kX9wEd7w4bRXb/gQ28I5jZWv/FBaZMGwWjOmO/4mIG5peAlPmyA6bd8
3A1jUPjlvcGv+ah7SoHV3/pH9jxmZua+ZXxESGPVmc5vH3yVzm/5BLusxGf1CnwqSfY4v/FxogOV
G1GoP2hfxfMlX85nw0lUnXg5ajmf23lRSsv47JC69Vs+KPmjqHFg8G/4IADkL/Ma59uXw5Pv+2eU
49fcqXcaz/VF5LM/8zGiXqn+zLWvlq98avPAwx93dxb50NOuyOe21EPBH/i0x6NOAr7lfPwrRQRQ
y/igInExv+VzTBhlounwb/ioga3LLxf65/Qf+BwDgYvXAsBsvsvax/hz/+wt7rAyn5gXS5eswEoQ
tTKfFcf3XiodzYVxbRkf1OWmKOpln8PluCsvfmX2lU8xuLukNXJfgY9SD4TjQv0LPu4AVv+Zzw/j
O+o6KFu83goWtjTiaX/mY7P4qeS8c7Hy+N5nu8KXtIt84p79zMf2MhhffI/LPvdMKRW/uCy9dy8o
z/2eTxVd79c5yuQKfFCNn5Zl9jd8HBaeX0X/PZ80o+/4zHzl08e+4EjzwT/7h+7saks37Uu/57Pk
Yvetmzs+a1+Jz3jSz3wAQC82FP1lH28K6Hw3Y0sFtov948Wv84utUshiqGKxcq75js9M1HcffoGS
X/DJXegttwp8z+e+4Pf9D2Bb7D+WPkkgGDf9PL+Q+NorlEl8x8fj/tKrnh/ps6t/mJ/OFYHGe83S
ZPHskuYj0FuED2GXD3qrwTJ/3l5KZMnv4vzquDJWKDotwF8CRfvdx6RNIHpZu7EGPb/qf07PTTzj
LBfbiBt2ns/0raXZ6MM5R+uT1EOPpf5j6YNi6aUaFfTV90apb1VcCCfv5F2qnvN8eN8tzd3CSNXB
2dX0uymOItinra3dBxb4nPcGOPl5dzWkoxJQLM4dLgLlZVXmzjf3r6mefcm79zwC6EpYvq5vqB0p
5ebO1Eydn+Y7n3kLFDqWLTy8+0arVYsZSNVjVubT2pjJPXXQeKH8tMEAR8pqMHXDgvJoFwD3n3QZ
UywsJex4LwWYF2qSV6VeyVwhaDPoQEPh10+ATU2yVLm5WekUF9ZzeHOAL8neZo73S9V1jLn0gwn4
bqddYHGJSHBhsSGWFKyb76W61zMQFlvXY9LNZU6Y87eC5hYwMCw6twWCDAwujMvWx3TT0ydiF3oK
dVI0hvZlfrz7t2+XGPEkXdUvvn9GMa5KTx9YrNqnTi3mlebr6tc5a2uNpc6JgYWBwX2h73BhYCDM
eRynSLcYCr6tjzEKHEtPN7Bf/FJAo3XR3rOvxdEwSL+tkft32fSv/JW/8lf+yl/5K3/lr/yVv/JX
/sr/14Rb/q8sF7O/VeKv/JW/8lf+yl/5K3/lr/yVv/JX/s8I74Z/JTb8oQV/blxoZWMb/72FN7/I
z/F/k9j/NwVq5vff8e/4yKeCfyVFtvfl8H/IJ/EA+49mLhX/EZ8nW/b9aEGnce2/46P6+wLleWdY
xP4LMwyeduBfSpHJsT+sQgzHbi03MEz5x9v/EIL+Lg+FSv82per/LhD2soXR/zY0vlLSyvLTk+nJ
c/8T0PpB+ogKdvG22N4/LJ8PbplRzH/pA5qkl1nY8u8Br8zn0v450f96fSvlf/4D0JiGH43carb+
4V9MQm9G6eZVetv/sHhB38z2/rdO8vZ/I/wDH80DNYEC3/7PRUFo6aWieYUy3x8UYU4a2FZEuv7M
gnp3958NAd8MW/w3Pmu+WViN+m98NLX83X6OIcivPa/lEvy9pT3f18Bnv+wuReYj3Puj0pl+syz7
H0dZuq8W0P+ND8WaX0XCBM/p3/5+dBZejkeS4TdlVZiPsuePOqBvpo/+Rz62Xy1c+y98ekx/1/+X
SpGiSMf9ztLJZXgifxuzTXw+0sb/xof2P/I5+NWC/H/gc/7C7+O1BJAiGRL+JZ8XvzfG+v+0d+Z/
UZRhAH8/LyCGy6roZgIBKYiJuCqKQgbqIgoIKbAqZV4pXiiuComaJ97XlmfikRZqomZKWKLk7Uft
UEuRNDsss8vsL6iZ3Z0D3HfmnYPdefezz0/LzjPPO/Pd4b3mOeyd9A45fGKgYj5zpPN5IqpYU0qp
3cTj4zTnIk/KQ2xqdy2k8NmGoTnjEKX4CIvPa2K2HLq7sS9Tb3QnnwSsH7JlFnV1VTh8IsVM3Ttt
0wvAX4+5k09ABzzdfyndUjMGnxRRU+2AxEHenXx64iovoJQfi/OJ0+P2J3GrCeATfB5XuY4a5f3r
xPlgmJpvVw0lgE81vvYJyvpJUT6vY1g6blc11mqfT1d8bT96YWVRgw+z3H+ieT7HAvG1zfTSIFwN
Pn6MboXW+fhKaeQIZf6IGnw+YpTLtM7nttRdlHyTCnzYaqmPtc5nkJRG6MqzoIkKfCzrmZW+xvmk
maQ0oluO/Mml8YH7HMrpGuezX1ormZT9h2ryAfO0zUfaPp6tg56tKp9/tM3nXel8SirU5PNY23zO
SOcDCtXk09rz+ExTk08fbfN5R1or/ZH7O3L5dNc2H2mvS+4Fq8SnIJ3RLvUkPkVAJT6BgAw+EzdK
aiRHLT5lhPCRKJ+oxSfPI/ncsvtRrFbO56hH8vGxN6DC/OekxLfhRPDRXbDZ9zcr55MAyJj/SJK/
7fbHK19/6dJY7b88hs8yx00tUs5nNfey7E9P4TONccIcoJxPJcfntofwqc1l7D9QzMecyPGJ9gw+
GzNZ7wyzYj48d7D+0CP4DAlmzWdAxXzuc3xOeQKf63fiRB24JPCp4VkL8gA+eX/wfMN6mBTz2cJZ
m19BPJ9m1fU8U1He7/h8CkM4a7guUprlE/EovR6e33WK+czhrGneP0FEBvVNq+/2HbMTKuVTFSO5
d9YmH91vLZ6KPLgGlfKpyeI5cgYSy8ca9fD004EZNy1K+Vhv8sxdgYTyObsrxFncSolASUg8PuUH
eOYkeGZpiY8lvtR5pFOakLsgFp+3Z/OD1MpJ5FPwy2VEIFjwr1AZn1u+h/nmHkDy+OhXJaPi5Ibu
gUr4WOouxvDNGasgeXx+bo4MI0wXxsPjs6a2npzLy7sUtqV5gwDMsT9B4viYrpQg8WxtCXH54MgP
UZA4PgU/Im/Hf6aozzfHx5jISrBzc8tb34PE8Wn6PYqO8f4k8dOd9j/m2trITsXZ9c0l3qmRfHHu
51P3HQrP3aU45wv0z5aO3OuKC1dH3pJxdW7nszYbQSf1Np6HovD49a194rP8jMy7czcfw3incBIv
Yocziozv1kr7Ld7Qk8hHn+os00H3bwz4JkTnh0n2o8XXCeRzw8lSdE6QJBPi8+cv7Ye3W4njY0hs
mHfjq691Em2I8yl0pFjIsJLGp3V9Out3jZPePsb66wvHXbYhjE+Tejs9+/YGymkfZ/1+1XGP8WTx
ucajM7yrvAEGi88GRwaXyzqS+OiGcllFrsgurYO1/xPqUDlBEp9LnC/OJvlLfyw+C5n+fwxBfC4y
y6yBEDYyHzZLSDU5fEwXHOeFwcbnw4yUAeeI4XOeSVFicgGfFxklH2L4OEJlN5uhC/gMkpOEx718
zth3l89CV/CpYPag/ctJ4VOpzkszzPeDbBqnKFL4TLHtvutcxGczo/U5KXxCZXQH8vksYLQ+I4WP
bWfvBVfxOcVozSKKT42XjxCf0xYvH5SMQoYMNAafzsTxocevBJfxWUAcn2ovH0E56VI+E4gb31e6
lA+TAxp8SgqfCOqUN13FZwmrNZqY/bEsAIbpXcSnF6MUYiWGD52VLsJFfCrJ29+AK6hzqlzDx8qk
jZKU3djNfAKPAXDcNXzY7cP8TeTwgR8DsM41fNjZzxFIEJ9wAIx4qXSPRini42eUmwXcrXwqDmGm
KVp5eIcSPpb9jMoBSBIf+CEA2UXiapuSDyr6/2rP9j5Sh0sdcCsffS4AH4hucZTvA7FK+JTlyxy8
3Jhf3SF74gDYK6JT8D4ARQr4GNYxCttNjcSnbIdCPjtRDnO7qIdexIl3NwDvKRi/NrLx86XS3/Jz
fIxC+T43T1XIZwvqWPRWAOY2E7rEbVQXKZQMsJMwnyD26Vm/RPrzvQGrPkh0QFOFfJKQ85yUZAAm
o9dE5mLaslCpK18hPpaBbAWmCSkyOo8VWHxW+Svtf5IAMoQrZQ31BKH+xdbatm3yhVaxiwT4+C1m
D85eIqdz5RWv6YjW6pJmUMhnBOiHPLaUGl5Klzk9lGMv4SZU2XxGKxQfy8zpXD6AWbJ89yAvrA6d
r7ooDhQbFPEJLwFz0Rcxbz4AYzOeTg71FrMqWChwByOBEz6mwJzYwVzhJDBqtCw6cAwv4cLYcSit
N2zJiSYghAvEzkep0D9xzET0ZUyaTAdRTplawPtuWq/p7NBaiDzT0JMXB56eQUuXwYMzs/h+n61e
kVtaaMhQvp3sHIRaLlBDhJxrzd2G0SrDho8IG5KXFx7W5tXcOPGyMb16JySKNPpSn9j4l2Wx6ZjU
u4exgbXkvv2czDANRlX49BecnKUMQJ2XOhA18xCq79k+MjIyqkM0lC349T07gZjO7RRKbBejWD2H
6G7d4xrGf/XoGW+AWpfmLVqqYCWolfhK3fBsm+fa2kL/QtqGPh8WHgEJkCb+TVWx80xAM7wlcyAl
ekiM+PioZMjXD3rFK17xilc8WujCuvy4XnqXZjTvbytd65jeTgUHed8uSnb+2bnQlfjo3ef/KKGD
ZGlvUjpt04DM1BjY136MFj1dCsHxuYXj8/+oTEfwLBQBAB==

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/image002.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODdh2ACQAHcAACH+GlNvZnR3YXJlOiBNaWNyb3NvZnQgT2ZmaWNlACwAAAAA2ACQAIcAAAAU
FBQEBAQdHR0NDQ0MDAwDAwMVFRUICAgKCgofHx8SEhIQEBAcHBwREREODg4XFxcCAgILCwsWFhYT
ExMBAQEYGBgPDw8FBQUJCQkHBwcZGRkbGxsaGhoeHh4GBgYzMzM4ODg5OTk/Pz82NjYuLi43Nzc1
NTUnJyclJSUmJiYoKCg0NDQrKystLS09PT0gICAqKio8PDw+Pj4kJCQiIiIvLy8pKSkhISExMTE7
OzsyMjIsLCwwMDA6OjojIyNLS0tfX19DQ0NPT09YWFhISEhGRkZSUlJNTU1BQUFZWVlbW1teXl5C
QkJMTExFRUVHR0dQUFBOTk5ERERUVFRJSUlVVVVAQEBaWlpdXV1TU1NKSkpWVlZRUVFcXFxXV1d4
eHhvb29oaGhnZ2dsbGx2dnZ3d3djY2N8fHxpaWl0dHRubm5ra2tycnJiYmJ1dXV5eXlwcHBtbW1g
YGBkZGRhYWF/f39+fn5zc3Nqamp6enp9fX1lZWVxcXFmZmZ7e3uSkpKWlpaOjo6NjY2CgoKVlZWF
hYWcnJyMjIyXl5eYmJiAgICLi4ubm5uenp6UlJSHh4eKioqTk5OIiIiGhoaBgYGDg4OQkJCPj4+f
n5+dnZ2ZmZmRkZGampqJiYmEhIS7u7u9vb2xsbG+vr6ysrKsrKytra2np6e2tra6urqurq6mpqa0
tLS5ubm4uLigoKCwsLCqqqqpqam1tbWoqKijo6Orq6uzs7O8vLylpaWvr6+/v7+ioqKkpKShoaG3
t7fKysrd3d3Gxsbb29vMzMzIyMje3t7ExMTAwMDNzc3Z2dnPz8/BwcHFxcXS0tLOzs7T09PV1dXU
1NTHx8fW1tba2trJycnDw8PLy8vR0dHQ0NDf39/Y2NjCwsLX19fc3Nz8/Pzx8fHy8vL7+/vm5ub+
/v7v7+/29vb5+fnw8PDt7e3z8/P4+Pjs7Oz09PT6+vr39/fk5OTp6en19fXo6Ojl5eXj4+P9/f3n
5+fu7u7h4eHr6+vg4ODq6uri4uL///8I/wD/CRxIsKDBgwgTKlzIsKHDhxAjSpxIsaLFixgzatzI
saPHjyBDihxJsqTJkyhTqlzJsqXLlzBjypxJs6bNmzhz6tzJs6fPn0CDCh1KtKjRo0iTKl3KtKlT
mODCvRT3tOrBcWDItQQGKOO4ceVklgtn7hy6s2jTqg2Lslw6devUpmUXrp27hYGABJPLt6/fv+je
nRMGAhRFc6EEBRESQsSIIWEGiRoGjiU8QkRIlDDBufMJFClSqECBYgULIUWIiAE0Kp5IdIXGGGnR
uTYLF0fIkFpIjkAAEydYCB9OvDiL2pxJGF8+nAQIASHeSSRGZgCA69izAyjwQkwpcynLnf+TZ2qF
dgACyhgyZIbMGSQwDGg/QMRU5Y/s3AFLcv46mmDzSLeQEv0VaOCBCB4SET1pXBfAEoicgkoqpSSi
BgkIaMdES8UkoJ0C8Bj0jjGqMLGAdk0cI1I9AZy3BkSkAOCEKKOEYuONOOJ4CgPatZDjjzke0oAD
9kCEDAoAmLCKPAjdk8waD2AHAZMrrRODdgPgo5AyaUSQXQGKiFTEeaxAFM4Jy0CUDwTayRARG09A
xIwEACzCTkPLzIBdKSyN8wKWWi5EigLaMRISGee1EpEZrkCkzwTaiRARGY081AwFADgCkTttXOdG
S1AA2pAzNGRXwSsgvaFdAc9EtAwzjkL/mp2kEJniWkP6wABAIhM9AoAF+7AUanZZOgSMA9ldAM1H
cGjnQDQjPRopSOVEAUAQFUECACzCiuqQr9mNcGdHkWjHgDTRyoodrR7BAkANwVYkhhTdEhtoQ+zY
oF0sHpWb3bnpTuvROHoictE8YVCZ0rDYFfsQuNhBwdZG/mIHsEjSzvrRNBEQMExG9y3srUP4sImd
BNSQay66GKt7HbscsQHADCELxfB1Djt0zxTaVcpRxdddHFLG63oUzg0AxGHUzQDk7JCq2cmh8r8s
D+0yADBrRA0GAEiy9MgOKaIdElNbXDVIRL/s0SnXaVoU0043JAuKZQd99kdpY+0RGm1//21vRK1o
N0XdAAiN9tVZZxTGdV6/DXZDrghOuOF4I+7RHNeV4XfD9zo0d3ZUTH63R3knjhEd140wsc2PMwSI
dm+IHrDGHalxHQGj/wR35w0tnh2fP688e9EdTYJdHY7//RA4TWR3QD2ytywwR6lgJ4AqRO0OETku
z9Gv8NLTzlE1GWDnwDRDaf9QINllkGb0Vk+/ETsiZDcBt0Gpj28J2RHyEdCFyx1HSvcRSmhHAG3Q
iu5al5BCZKcK44Lf4eS3EX7wSDswQMPHeqK/hVADWdcJgcIkWDkKbqRZ/bmAFVZxF510MCH0qF8I
iwQSAFKOdJb7iDxwcCAb2MEaNaPJC/8Pcg19AUADsROJDQW4EQKCJBUZQtALKqEMmzBNAfNIyDpC
cYYoAkACQZAENkKyxOGpLSSv4BqCAEAAK4giiC5hGgMscYk61hETd4jDFEpVIA1UARX/A1/8xAcS
WJhsjQC4AiBjwjQDbKABHIhkJC0wAQow4AAFOBATRpiRMoaPeCLJhp4QeR0sbDCO2mmAPcbxjla2
chzgQEc/yOEMVSBCBgViAT+CRzUz6o0k56CEh0hpAVShklj9cAg7ZoHL84hAHRQT5AQJORJruIFO
iKyAII7JOYiwAwz9wUI0e/nJM55EG3jQFSL9V69uRgRq2lFQJ6VZQmqaxBy0YMIG1hj/ppUMkSH3
sJZ2LLBLjHhykKBcCTlqIQVs9icDwPAnAxmyjUNiBwzzJCdCzekSbZihAwXKgVREpjyJmOE8CgDP
RQ46zYS+pB5h0EB/GoeSfzZEGRfQTgV2s1J64tCEL7mGDs4Tg3OQ1J0TGcJ5lNZTjbaUozJxBziz
EwFF1XSiDbHFeXZwj6aazZemi0kj5IOdPBwVZ7yDiDz2Sax4VYSl9XQpTQaRHR7AUSQ2bQg4mEYB
bnjVbmDViROws4FbmSSvDelUdiRAjL8GMLA5sUYUCaCNq5Z0IpfQDmMde8OOODEnQrhOBax6WKw2
JBaaHaNF4PpTe1pkGfroCPuucwvL/yJ1IsTwEnYoy1kmauSzGclENzoyDezwtLSXlQg1yHodCBij
t5DViCZI+9sDACACuLAtWi0iDeYCAAYqfatPPZtDjWyiTBwhB6GUpd2mpRUi0fAuCVY3EdaSF6gV
4UQuOkIODwCgAfRob9wiog3v4sGg4x1geTMCCDt0xBsZKsFdQ4JYhqhCO9iDbjl/qRFJkI0jrLgO
Gc7qXotIIjsdSKaGN8rhjAQCBkbdyFRr214PBLgiiMKOGDL61Q2HlSKdAMAiM8KOHgAAB/kgsQW2
URF2mAA7H1Dtip/aYow0AgCf0kgzuKYHlTCNAMuiCDUcmgWN2FfB+KXIlSkQ24wMNv8AzyVxBGZR
EcUCwAHV0AgiEtzEBVvZUxmpxXU2IVHtpIEiwwAhAB6xkT04C1ob9gFHrgyACmTiIsA4kRa6qpIx
ace5EikHErCDBfpaBA+rSka0LAqAEEz6ZJemiC4g1QNOmgQcI+jPE6gCEd8B4AXQ3AiqtdMokfCj
RXWd8EQoLdo1tPkh69CDAADQgzirZB78608SVN0QfmDuOjqw9UWYcB5bjIQa084ODtKxEWY3LBLG
MLVB5NEIIz7BsCrhRpQKJAEi1MIb4ggiOOQxiziA9LppCPZG3nEl7UhNJJk4zwdgpRF3Z8cBV0DD
K0CxDHzQgx72KIYoPHEEk+FAEOj/aAk3toBIA9QABFMAwhaAIAQQnOg6CXCCYThSjm806DwCOEUL
O9IOVSBbOyAIM0YSQUoHOGABmcwOCDihQJXAoxBhAEEAGsD1rnud6x2AwAIuUAAJmL0ADBiACNiw
icpyBB2ByMMJKPB1rlugAViAw3Exco01OGEDE6h7AwKwAzLswa8WWYXgvc6BDmzgAJA/AA5OwIdE
TIPTLLkHP75Bjnao4/OgD73oR58PZWPkHvrgvOdHr45+bEMZN85IPr7hj36w/vPk+IYyhk4Rdtz+
9+pIuVWGT/ziG//4yE++8pfP/OY7//nQ1wg+tJGN6lv/+tjPvva3z/3ue//74A+///jHT/7yY18b
Cg8JN0Rxi/a7//3wj7/850//+tv//vjPv/73z//+wx8WzxZ9AjiABFiABniACJiACriADNiADviA
37ANwSAN0vAN4wIO1LB5cXYPw/ANWSQQ8CAN/OANH0gQ5BBE+BANbvUPwdCB+CYQ9rALuBAK3zAQ
5VAN22AM3nAQsTcQ8RAN9RANJcgQzpAKzLAOA3EO3hAP1CAN0eAPE0MOxkAN0wBpAxEMwbANgfIO
w7AN0VAZ5iAN9SAN4TUQw4ALaBiAw6APw0CB1RBBAkEOodAK/jASuJADS5AJnQAE2fUP70AKLLAF
wiAQ4JAKJ7AFAyEOq3ACnlCG///ADzxwSgLhDWygAFY4DVEABe8jEOUQCX3AC6bACS4APOWACzog
BNQlEMcwA5gnEM6gBhwACI6YEIewCLHAB10mEOEABynACY7ACFBgWM3gAzPgCH3gBDsoEMhAAiGA
eOegCD0ACykXD3fQAXcAPUm4CHvQC6UACSiAPgIxCzfAB5mgCVJgbgNBDH1wCoMABSEiEkhgKP9g
DchAEFKQRAPhaJxAEEoQDAZBCwDgCwZBDghAAu/4D5JAUwIRB1wwdLAACQTBBztmEHpAANlgENDQ
AEnWEP4wA+PwD+wQCJiXDTDwjq+gdP/ABn0gEFMwBRPTCTVAELEAkQMRDRIgieP/cARqMDGPIJAD
8QKdIBDQ0As2aAWjIBCFUHUgQQWRkIQEoQWaQxCJQAcM4Hb/sAeOWA6Q4ARKYBDx0AYdwAYDoQk+
qYocQEMCcQ4RNRBl8HAEIQ6WIAIKKRDSEAPt4BDPgEVpOTHagAIjBQ9D2Acr+Q+2sAEC8g/40AHD
tZBMNhDa0AEBuAolSRDtYIX/YAT99A8KBw4kwFPncJggoQX7+A/OsDpHEJUD0Qn8EAY0cJf/sAhI
SBDKEAjXoAAr+A/G4AjMoAHy1AhuIxBiYAQLoQYjVhCjIAuXcAUG4Qw3cJsJkQ4oYAWzuAw38JHx
IIn/EAdJ9AhG0IpaIJb/oAxo/1AQy9AAhlUOSXBoCjEFsaYiBJEGAQCOJMEFUcAKikAErXiaBbEJ
3IAOJgAEXWUHvDYQtdAM/xADGTYQxtAVvIAAg+ibAwEOLACeCUGcBjEI9bANHVCHBMGczpkQoCAB
MJCKzhAAdjAIVrCWA9EGWlANx5AFzlAQtzABWtEI9UgQ5YmW7oACmLAQW+AEmBAGcFAQ9EACAmAw
8xkEu2AKTFAz+kkQnQAt+nAAQ1oJAyoQS0AGlVADZkUQCyoQcjAA+8ALvymh3qMQFkoQ7gAFd1AG
BbAKBeGhEPEMPoABFCcQ2uABrWANkDCIBIEHV9ALDkCTBBEOHuAI71AGcPgPOf86EO6gAp6wEEWA
B9jQjQaxDn0AAJE6EqIpEMHgpKgpEJLQWP8wChngCJ9wpdLwBsMQDIpwA1dqDI0zDkIgBIBgTAJB
ByAwnMU5EL9ACd8QDHMwBHHanBExDlIgnANBnSn3DrcZB5rDCByQfgLBBkkQCmW5rOZpgyNwBAvx
BG4TgAQBCBMgbhxBBUhqEFpgBgWBCQYqEJ4AAEYAh52wSPTgASrKgqP5D+TAARawXwPhCgLAbQPB
DRPTlgWRB6o1CgvQOdLQAhv5DxF7EJsYCj1AENpwA7EpsRHUByPGDj8QqgKRDAfABQWFsRwQgICQ
AOlXDpJoBJowEOOwkcHgmu3/cANWCRJAcAcIUQVtUBCWsJj/UA5K0AAhMw5zgJZGoAYEwQ0U+g+4
AACxJhD3cAY7cLKjAAYTEwR+QBDbIAUf+Q/mYAFBORAl6o//8AyFoBB28AsC4QjYMhDZ8AA1KLZm
sLFsEDr/IAoVQGMDcQ8iUAUH4QwakDJJuAVFwG4C8Qo9OhA6sAcDIQlu+w/IwE7UYAKuCRKtwAJJ
UGwRqgs98ATu+Q/FMAV+YJXrwAfBNg+AoAN+qgxH4AKiIBDrYAkkQAtDRwlESRDgYAhdIAmq8AhV
QHHlgAomMANWxQ9yMAUscw058AIUBw1r0AFzUAiXIAWpoBCgIAKN8App8Gz8//BRblAIhbAEizAQ
3XAFIUBn/0AJPMAKNSMJpzCQZsABeICNAuEOeMAEgaALiGAEyegOvGADORAJirAIRhAv6lAFlkAL
eOC3IEEO5BAPSvkP90DB9qBi/7AP9rANZSgO7zgO+lAPKhYO9UAONPQO/FAP/BC2QztSRHoMo1AM
EVsO9VAPFEy721APG9kP+GAPN5YP27APxvANw8ChCuEPo3AMG/sP6zDERfwNFjgQ8mAPNzwQ2+AM
oCkOMUYQ5wDFQygQ9SDD1jB077AN9EAO1fAN1ZB+6yDD+PuAcjzHdFzHdnzHeMwQwqcUrci7C2gP
gjAJh3AJpiBvBwEMmgAIlf8wCJmbEPpQCJZgCiHCDqRQCbTQxQZBDZMgCZjHp4yAnQVRDZIACZvQ
CJtgC7yHENDgBYlwCJEgCY4ACGWAkgiBDpoAwwlRDqFgCIPQCZeQjArRDJRgCa5gyATBDqdgCYkQ
y4wwix0RDnKgANQwCiDglgrRCWIgDevwDWqwA2ibEO8gCQlADWFRDsZgAsfQx16sCQBQthKLBW2A
yQbRDkRAA9oQDanQBy9AsAjhCHJADNHAA2CgDMfABfmKENkAAKOrENxQA2QgDYJQA1KGEPSsAhWM
EOWADASQC9wwDWNQDCTBCiYgELCQAdaGEMegAo08BU+gzgWBDStQEGXQxAf/IQ8+sACI9w+asHMK
AQhNQBBg4AHvNRBVJBBF4DP60IMI8QoKUAkOgQSBIBAhEAYMsQlA8BD5AAJuFw4nGxKqQAICQQwf
YLhNUgVdOhCgAAAgrRDCgAKguQjOLJv3eQLvGAupeBCIoJwDkQ4T0JQNYQS84hDw8Amc4APGTBBb
ENgzQKgJ0QhF8BDyoNX/AA40DRKq4Gr/gAlc4MI1TQG1UBDy4ACMxtZuTRCWENcF2wjpoAJnIBCi
cNcGkdcFIQVC4BCA/RDL4Aj9UAOgfBBI0AfAwAhLsMcJ0QmP7RDy0AO2MAyngF4jIQoeoAh+IAa4
fBDGkAG0UBDoYAOTsBBt/w2ap70Q3BDV2VAA3f3aDCHbBNEGM2Dbgd0QhLAK3BADa8sQQ4AEcBsC
Q1bcx90Q/dACaqAJQjC/JKELPJANRaADDBEPDyCPA8EONzCXBtEMpT0Qd4DaAjHeAqFVrDAKsF0Q
6j0QUgAF7u0Q6bAFdjAJV4CIDFEFgb0IFjDUqdnfDCEPO9Aq3iCfInHZ/0APASDhBfEOIqDgBBEM
AUCqCWENDeBW7IAHxH0Q3JCZiLAAahAK6a3XAsEONTDaDHHbDQELUf0P2KBKDLEFo+0PF3CjjU3j
CxHZE00St4DZkUAASIwQrRABd9q+UcAQ/hAAk/sPwjCeC/ENmyoQXAAAR/+5EJzw0wPRCDtQ2QhR
BDHbEHDAMvPQAgmaEFKwqd4wAUVd3Cz+iDlrEOawA0oXCi/YEetQBgGwS+cwAyGAlghhCCWAC+LQ
DqVABLKeEHhAA79gD9cQBBepEO9wCklQdfLwvguRD36QANdQD9ygCUPAzwkBDt/AAWwwsQcBDs2g
Awp0DlfAAnVuEP2wAiXwDc5AB+yqEPuQBQwwCsQwDUzgpwfxDqFQAXeADcTACkOguCBRDY9wCaIQ
FurwB5NQ3QYxCnowCJzwCtqeEPcQCF+AB5WA5AmxD68gCa0QMs9AywaBDY/wCYygC6+QC/6+EO4Q
C5wACGudEO5wCpLgp8ZkoAmCMAvGfA2XMAmawAv7jRDNAAiAsAmvwAiecJAGkQ+JLAmZsAl6gD8p
8Q4ubRCfORGgmcdWf/VYn/Vav/Vc3/Ve//VgH/ZiP/ZkX/Zmf/Zon/Zqv/Zs3/Zu//ZwH/dy/xMB
AQA7

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet002.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet002.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:.5in .75in .9in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.92in;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(1);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>10</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>12</x:ActiveRow>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
 <x:PageBreaks>
  <x:RowBreaks>
   <x:RowBreak>
    <x:Row>28</x:Row>
   </x:RowBreak>
  </x:RowBreaks>
 </x:PageBreaks>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D637 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:478pt'>
 <col class=3Dxl38 width=3D637 style=3D'mso-width-source:userset;mso-width-=
alt:23296;
 width:478pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl94 width=3D637 style=3D'height:15.0pt;width:478=
pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl94 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 style=3D'height:15.75pt'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 width=3D637 style=3D'height:15.75pt;width:47=
8pt'>BITS IT
  Service Provider Expectations Matrix</td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 style=3D'height:15.75pt'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 style=3D'height:15.75pt'></td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl96 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>The <font
  class=3D"font25">BITS IT Service Provider Expectations Matrix </font><font
  class=3D"font23">was created to promote a common understanding among inte=
rested
  parties of the financial services industry&#8217;s needs related to
  information technology practices, processes and controls. By providing
  financial institutions, service providers, and audit and assessment
  organizations with a comprehensive set of expectations, the </font><font
  class=3D"font25">Expectations Matrix</font><font class=3D"font23"> helps
  financial services companies to identify risks and comply with regulatory
  requirements, as well as to eliminate gaps in the audit and assessment
  processes.<span style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl97 width=3D637 style=3D'height:45.0pt;width:478=
pt'>Presented
  in a spreadsheet, the <font class=3D"font13">Expectations Matrix </font><=
font
  class=3D"font9">outlines in detail service-provider practices, processes =
and
  controls relevant to financial services industry and regulatory requireme=
nts.
  Using ISO 17799 as a guide, the </font><font class=3D"font13">Expectations
  Matrix</font><font class=3D"font9"> covers ten security control areas:<sp=
an
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Security Policy</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Organizational Security</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Asset Classification and Control</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Personnel Security<span style=3D'mso-spacerun:yes'>&nbsp;=
</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Physical and Environmental Security</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Communication and Operations Management<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Access Control</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">System Development and Maintenance<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Business Continuity Management<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Compliance with Legal/Regulatory Requirements</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl96 width=3D637 style=3D'height:45.0pt;width:478=
pt'>While
  the specific controls and requirements will vary with risk and the nature=
 of
  the outsourced service, the expectations provide a template for the
  information financial institutions need in order to understand and manage
  risk.<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;</span>=
</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Background</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl97 width=3D637 style=3D'height:60.0pt;width:478=
pt'
  x:str=3D"When applications, systems and services are outsourced, responsi=
bility for reputation, transactional, regulatory and other risks associated=
 with the outsourcing relationship remains with the financial institution. =
To develop an appropriate risk-mitigation strategy, the institution must be=
 able to identify and understand the controls on which the service provider=
 relies to address risks associated with outsourced services.  ">When
  applications, systems and services are outsourced, responsibility for
  reputation, transactional, regulatory and other risks associated with the
  outsourcing relationship remains with the financial institution. To devel=
op
  an appropriate risk-mitigation strategy, the institution must be able to
  identify and understand the controls on which the service provider relies=
 to
  address risks associated with outsourced services.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Using
  the Expectations Matrix</td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl97 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>For
  each control area, the <font class=3D"font13">Expectations Matrix</font><=
font
  class=3D"font9"> identifies a high-level industry expectation and the doc=
uments
  a financial institution or audit/assessment organization may request. Sam=
ple
  questions are then listed, along with one or more possible summary questi=
ons,
  to provide direction on the specific areas of interest necessary to valid=
ate
  the high-level expectation. Answers to these questions will allow the
  financial institution to gain the information it requires to evaluate ris=
k,
  create mitigation strategies, and satisfy regulatory requirements.</font>=
</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'page-break-before:always;height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Expectations
  Matrix Benefits</td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl97 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>Increasingly,
  financial institutions are deploying their own internal resources or third
  parties to perform due diligence and ongoing reviews to fill gaps in their
  assessment requirements.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Consequently, service providers, which may have spent considerable
  resources preparing audit and assessment reports, often receive additional
  and inconsistent demands for information about their operations. The
  Expectations Matrix provides financial institutions, service providers, a=
nd
  audit and assessment organizations with a tool to help streamline their
  processes. For example:</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl100 width=3D637 style=3D'height:30.0pt;width:47=
8pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font8">Financial institutions</font><font class=3D"font9"> can u=
se the </font><font
  class=3D"font13">Expectations Matrix</font><font class=3D"font9"> as they=
 develop
  internal due-diligence and monitoring questionnaires for service provider
  operations.</font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl100 width=3D637 style=3D'height:30.0pt;width:47=
8pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font8">Service providers</font><font class=3D"font9"> can use th=
e </font><font
  class=3D"font13">Expectations Matrix</font><font class=3D"font9"> as they=
 respond
  to financial institution questionnaires and define control objectives for
  audits and assessments.</font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl100 width=3D637 style=3D'height:30.0pt;width:47=
8pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font8">Audit and assessment organizations</font><font class=3D"f=
ont9">
  can use the </font><font class=3D"font13">Expectations Matrix</font><font
  class=3D"font9"> as they work with financial institutions and service pro=
viders
  to verify and test controls.</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl97 width=3D637 style=3D'height:30.0pt;width:478=
pt'
  x:str=3D"For more information about the BITS IT Service Provider Expectat=
ions Matrix, contact Faith Boettger, Senior Consultant, faith@fsround.org. =
">For
  more information about the BITS IT Service Provider Expectations Matrix,
  contact Faith Boettger, Senior Consultant, faith@fsround.org.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'
  x:str=3D"About BITS ">About BITS<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl97 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>BITS
  was created in 1996 to foster the growth and development of electronic
  financial services and e-commerce for the benefit of financial institutio=
ns
  and their customers. A nonprofit industry consortium that shares membersh=
ip
  with The Financial Services Roundtable, BITS seeks to sustain consumer
  confidence and trust by ensuring the security, privacy and integrity of
  financial transactions. BITS works as a strategic brain trust to provide
  intellectual capital and address emerging issues where financial services,
  technology and commerce intersect. For more information about BITS, go to
  www.bitsinfo.org.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'
  x:str=3D"BITS ">BITS<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>1001
  Pennsylvania Avenue NW</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Suite
  500 South</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Washington,
  DC 20004</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>(202)
  289-4322</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>www.bitsinfo.org</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D637 style=3D'width:478pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet003.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet003.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(2);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>5</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D567 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:425pt'>
 <col width=3D291 style=3D'mso-width-source:userset;mso-width-alt:10642;wid=
th:218pt'>
 <col width=3D276 style=3D'mso-width-source:userset;mso-width-alt:10093;wid=
th:207pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 colspan=3D2 width=3D567 style=3D'height:15.0=
pt;mso-ignore:
  colspan;width:425pt'>BITS IT Service Providers Working Group Security
  Assessments Project Team</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl87 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>IT
  Service Providers Working Group Co-Chairs</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>Lari
  Sue Taylor, FleetBoston Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>Viveca
  Ware, Independent Community Bankers of America</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 style=3D'height:15.0pt'>Security Assessments=
 Project
  Team Chair</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>Wayne
  Browning, FleetBoston Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl89 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 style=3D'height:15.0pt'>BITS Staff</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'>Faith Boettger, Seni=
or
  Consultant</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'>John Carlson, Senior=
 Director</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'>Margaret Prior, Admi=
nistrative
  Assistant</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl90 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl90 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl87 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'
  x:str=3D"Security Assessments Project Team Participating Institutions ">S=
ecurity
  Assessments Project Team Participating Institutions<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>America&#8217;s
  Community Bankers</td>
  <td class=3Dxl92>Lauritzen Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>American
  Bankers Association</td>
  <td class=3Dxl92>M&amp;T Bank Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Association
  for Payment Clearing Services</td>
  <td class=3Dxl92>Marshall &amp; Ilsley Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Bank of
  America Corporation</td>
  <td class=3Dxl92>MBNA Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl93 width=3D291 style=3D'height:15.0pt;width:218=
pt'>The Bank
  of New York Company, Inc./</td>
  <td class=3Dxl92>Mellon Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl93 width=3D291 style=3D'height:15.0pt;width:218=
pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Pershing LLC<f=
ont
  class=3D"font23"><span style=3D'mso-spacerun:yes'>&nbsp;</span></font></t=
d>
  <td class=3Dxl92>National City Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>BANK ONE
  CORPORATION</td>
  <td class=3Dxl92 x:str=3D"Nationwide ">Nationwide<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>BB&amp;T
  Corporation</td>
  <td class=3Dxl92>The PNC Financial Services Group, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Capital
  One Financial Corporation</td>
  <td class=3Dxl92>Providian Financial Group, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Citigroup
  Inc.</td>
  <td class=3Dxl92>Regions Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Comerica
  Incorporated</td>
  <td class=3Dxl92>Sky Financial Group, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Compass
  Bancshares, Inc.</td>
  <td class=3Dxl92>SouthTrust Bank</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Credit
  Suisse First Boston</td>
  <td class=3Dxl92>State Farm Insurance Companies</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Credit
  Union National Association</td>
  <td class=3Dxl92>SunTrust Banks, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>First
  Virginia Banks, Inc.</td>
  <td class=3Dxl92>U.S. Department of Navy CIO</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Fifth
  Third Bancorp</td>
  <td class=3Dxl92>Visa U.S.A.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>FleetBoston
  Financial Corporation</td>
  <td class=3Dxl92>Wachovia Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Fortis,
  Inc./Assurant Group</td>
  <td class=3Dxl92>Wells Fargo &amp; Company</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>The
  Goldman Sachs Group, Inc.</td>
  <td class=3Dxl92></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Harris
  Bankcorp, Inc.</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'
  x:str=3D"HSBC USA, Inc.  ">HSBC USA, Inc.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl91 width=3D291 style=3D'height:30.0pt;width:218=
pt'>Independent
  Community Bankers of America</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>J.P.
  Morgan Chase &amp; Co.</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>LaSalle
  Bank Corporation</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl93 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D291 style=3D'width:218pt'></td>
  <td width=3D276 style=3D'width:207pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet004.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet004.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(3);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:RangeSelection>$A$1:$C$1</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1329 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:998pt'>
 <col class=3Dxl36 width=3D50 style=3D'mso-width-source:userset;mso-width-a=
lt:1828;
 width:38pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D307 style=3D'mso-width-source:userset;mso-width-alt:11227;wid=
th:230pt'>
 <col width=3D150 style=3D'mso-width-source:userset;mso-width-alt:5485;widt=
h:113pt'>
 <col width=3D119 style=3D'mso-width-source:userset;mso-width-alt:4352;widt=
h:89pt'>
 <col width=3D48 style=3D'mso-width-source:userset;mso-width-alt:1755;width=
:36pt'>
 <col width=3D46 style=3D'mso-width-source:userset;mso-width-alt:1682;width=
:35pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:987'>
 <col width=3D53 style=3D'mso-width-source:userset;mso-width-alt:1938;width=
:40pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:2340'>
 <col width=3D64 span=3D2 style=3D'width:48pt'>
 <col width=3D300 style=3D'mso-width-source:userset;mso-width-alt:10971;wid=
th:225pt'>
 <col width=3D64 style=3D'width:48pt'>
 <tr height=3D25 style=3D'mso-height-source:userset;height:18.75pt'>
  <td colspan=3D3 height=3D25 class=3Dxl114 width=3D421 style=3D'height:18.=
75pt;
  width:316pt'>BITS IT Service Provider Expectations Matrix</td>
  <td width=3D150 style=3D'width:113pt'></td>
  <td width=3D119 style=3D'width:89pt'></td>
  <td width=3D48 style=3D'width:36pt'></td>
  <td width=3D46 style=3D'width:35pt'></td>
  <td width=3D0></td>
  <td width=3D53 style=3D'width:40pt'></td>
  <td width=3D0></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D300 style=3D'width:225pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D90 style=3D'mso-height-source:userset;height:67.5pt'>
  <td height=3D90 class=3Dxl36 style=3D'height:67.5pt'></td>
  <td colspan=3D2 class=3Dxl125 width=3D371 style=3D'width:278pt'>Note:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>For each step, select if it is
  applicable for your assigned domains.<span style=3D'mso-spacerun:yes'>&nb=
sp;
  </span>Add additional steps, if necessary, under each topic area.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Please add any other steps not c=
overed
  by one of the topics under the &quot;other&quot; tab.</td>
  <td colspan=3D11 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D13 rowspan=3D3 height=3D50 class=3Dxl116 width=3D1265 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:37.5pt;width:950=
pt'>1.0
  SECURITY POLICY:<span style=3D'mso-spacerun:yes'>&nbsp; </span><font
  class=3D"font9">A set of rules and procedures regulating the use of
  information, including its processing, storage, distribution, and
  presentation. The set of laws, rules, and practices that regulate how an
  organization manages, protects, and distributes sensitive information.</f=
ont></td>
  <td rowspan=3D3 class=3Dxl30 width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D0 style=3D'display:none;mso-height-source:userset;mso-height-=
alt:
  300'>
 </tr>
 <tr height=3D0 style=3D'display:none;mso-height-source:userset;mso-height-=
alt:
  270'>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D13 height=3D45 class=3Dxl55 width=3D1265 style=3D'border-ri=
ght:1.0pt solid black;
  height:33.75pt;width:950pt'>Security Policy High-Level Expectation: <font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;</span>All vendors=
 and
  Service Providers should have and adhere to a written and comprehensive s=
et
  of information security policy documents, which act as the rules and
  guidelines for dealing with the protection of information and information
  assets.</font></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D13 height=3D45 class=3Dxl55 width=3D1265 style=3D'border-ri=
ght:1.0pt solid black;
  height:33.75pt;width:950pt'>Documents that May Be Requested:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Security p=
olicy,
  document update schedule, audit report of security policy. (If unable to
  provide a copy of the security policies, please provide a list of the are=
as
  covered by the policies, e.g., table of contents.)</font></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl82 style=3D'height:30.0pt;border-top:none'>&nbs=
p;</td>
  <td colspan=3D3 class=3Dxl48 width=3D521 style=3D'width:391pt'>Questions/=
Control
  Activities</td>
  <td class=3Dxl48 width=3D119 style=3D'border-top:none;width:89pt'>Applica=
ble Domain</td>
  <td class=3Dxl49 width=3D48 style=3D'border-top:none;width:36pt'>Yes</td>
  <td colspan=3D2 class=3Dxl49 width=3D46 style=3D'width:35pt'>No</td>
  <td colspan=3D2 class=3Dxl49 width=3D53 style=3D'width:40pt'>NA</td>
  <td colspan=3D3 class=3Dxl49 width=3D428 style=3D'border-right:1.0pt soli=
d black;
  width:321pt'>Comments/Testing Performed and Results</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td height=3D59 class=3Dxl83 style=3D'height:44.25pt'>1.1.</td>
  <td colspan=3D3 class=3Dxl62 width=3D521 style=3D'border-left:none;width:=
391pt'>Does
  the Service Provider have formal and documented security policies, standa=
rds,
  plans and procedures?</td>
  <td class=3Dxl62 width=3D119 style=3D'border-left:none;width:89pt'>(Hosti=
ng,
  Storage, and/or Managed Services)</td>
  <td class=3Dxl75 width=3D48 style=3D'border-left:none;width:36pt'>&nbsp;<=
/td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.1=
.2</td>
  <td colspan=3D3 class=3Dxl59 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"Are they available for review?  ">Are they available for review?=
<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl83 style=3D'height:33.0pt;border-top:none'>1.1.=
3</td>
  <td colspan=3D3 class=3Dxl59 width=3D521 style=3D'border-left:none;width:=
391pt'>If
  the documents are not available for review, is there an independent audit
  report of security policy available?</td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl83 style=3D'height:33.75pt;border-top:none'>1.2=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"Indicate if the policy includes the following components and lis=
t the date management last approved the policy, if applicable.  ">Indicate
  if the policy includes the following components and list the date managem=
ent
  last approved the policy, if applicable.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td colspan=3D8 class=3Dxl63 width=3D575 style=3D'border-left:none;width:=
432pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.1.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Information
  classification policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.2.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Data-handling
  policy (to include secure use, storage and destruction of sensitive data)=
</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.3.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Internet/intranet
  access and use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.4.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Authorized
  use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.5.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Acceptable
  use policy (to include restriction on using corporate computing resources=
 for
  purposes other than business, e.g., personal email, browsing)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.6.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Email
  use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.7.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Encryption
  policy and standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl83 style=3D'height:34.5pt;border-top:none'>1.2.=
8.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  configuration standards for networks, operating systems, applications and
  desktops</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.1</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Security
  patches</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.2</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Vulnerability
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.3</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Default
  passwords</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.4</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Registry
  settings</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.5</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Version
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.6</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>File
  directory rights and permissions</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.7</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Prevention
  and detection of computer viruses</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.8</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Secure
  configuration</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl83 style=3D'height:34.5pt;border-top:none'>1.2.=
9</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Software
  development, acquisition and installation policy and procedures, including
  change management (guidelines)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.10</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Change
  control policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.11</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>User
  system access policies (Principle of Least Privilege) (See 7.1)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.12</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  incident management policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.13</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Network
  security/access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.14</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Application
  security standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.15</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Remote
  access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.16</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Privacy
  policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.17</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Personnel
  security and termination policies</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl83 style=3D'height:32.25pt;border-top:none'>1.2=
.18</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Physical
  access policy and procedures (e.g., hardware, software, storage media, pa=
per
  recorders, photo copiers, mail, fax, facilities)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl83 style=3D'height:17.25pt;border-top:none'>1.2=
.19</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Computer
  and communications system use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.20</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  awareness program</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl83 style=3D'height:17.25pt;border-top:none'>1.2=
.21</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Disaster
  recovery and business continuity plans</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl83 style=3D'height:30.75pt;border-top:none'>1.3=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Does
  the information security policy have an owner who is responsible for poli=
cy
  maintenance?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.4=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Are
  the policy documents updated regularly?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.5=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"How often is the policy communicated to staff?  ">How often is t=
he
  policy communicated to staff?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl83 style=3D'height:15.0pt;border-top:none'>1.5.=
1</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to offsite locations?  ">Is the policy
  communicated to offsite locations?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl83 style=3D'height:45.0pt;border-top:none'>1.5.=
2</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to dependent Service Providers or are=
 the Service Providers' policies reviewed by the Receiving Company? ">Is
  the policy communicated to dependent Service Providers or are the Service
  Providers' policies reviewed by the Receiving Company?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D27 style=3D'mso-height-source:userset;height:20.25pt'>
  <td height=3D27 class=3Dxl83 style=3D'height:20.25pt;border-top:none'>1.5=
.3</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'>Is
  the policy communicated to contract employees?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.6=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Is
  the adoption of the policy monitored and enforced?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.6=
.1</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Are
  consequences for non-compliance with policies clearly documented?</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D50 style=3D'width:38pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D307 style=3D'width:230pt'></td>
  <td width=3D150 style=3D'width:113pt'></td>
  <td width=3D119 style=3D'width:89pt'></td>
  <td width=3D48 style=3D'width:36pt'></td>
  <td width=3D46 style=3D'width:35pt'></td>
  <td width=3D0></td>
  <td width=3D53 style=3D'width:40pt'></td>
  <td width=3D0></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D300 style=3D'width:225pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet005.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet005.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(4);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>33</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>21</x:ActiveRow>
    <x:RangeSelection>$A$22:$L$22</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1615 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1212pt'>
 <col width=3D64 span=3D6 style=3D'width:48pt'>
 <col width=3D134 style=3D'mso-width-source:userset;mso-width-alt:4900;widt=
h:101pt'>
 <col width=3D68 style=3D'mso-width-source:userset;mso-width-alt:2486;width=
:51pt'>
 <col width=3D64 span=3D3 style=3D'width:48pt'>
 <col width=3D486 style=3D'mso-width-source:userset;mso-width-alt:17773;wid=
th:365pt'>
 <col width=3D287 style=3D'mso-width-source:userset;mso-width-alt:10496;wid=
th:215pt'>
 <col width=3D64 style=3D'width:48pt'>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td colspan=3D12 rowspan=3D3 height=3D60 class=3Dxl116 width=3D1264 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:45.0pt;width:949=
pt'>2.0
  Organizational Security: <font class=3D"font9">One or more security rules,
  procedures, practices, or guidelines imposed by an organization upon its
  operations. The set of laws, rules, and practices that regulate how an
  organization manages, protects, and distributes sensitive information.</f=
ont></td>
  <td width=3D287 style=3D'width:215pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr class=3Dxl38 height=3D40 style=3D'mso-height-source:userset;height:30.=
0pt'>
  <td height=3D40 colspan=3D2 class=3Dxl38 style=3D'height:30.0pt;mso-ignor=
e:colspan'></td>
 </tr>
 <tr height=3D0 style=3D'display:none;mso-height-source:userset;mso-height-=
alt:
  330'>
  <td height=3D0 colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D71 style=3D'mso-height-source:userset;height:53.25pt'>
  <td colspan=3D12 height=3D71 class=3Dxl55 width=3D1264 style=3D'border-ri=
ght:1.0pt solid black;
  height:53.25pt;width:949pt'>Documents that May Be Requested:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Information
  security organization chart (including where information security resides=
 in
  the organization), roles and responsibilities, job descriptions, overview=
 of
  access administration process and procedures, third-party security
  reviews/assessments and SAS 70 or SAS 70-equivalent reports, due diligence
  performed on third parties, performance reporting for third parties, legal
  clauses and templates</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D12 height=3D45 class=3Dxl55 width=3D1264 style=3D'border-ri=
ght:1.0pt solid black;
  height:33.75pt;width:949pt'>2.1 Information Security Infrastructure
  High-Level Expectation:<span style=3D'mso-spacerun:yes'>&nbsp; </span><fo=
nt
  class=3D"font9">A management framework should be established to initiate =
and
  control the implementation of information security within the Service
  Provider&#8217;s organization.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D35 style=3D'mso-height-source:userset;height:26.25pt'>
  <td height=3D35 class=3Dxl54 style=3D'height:26.25pt;border-top:none'>&nb=
sp;</td>
  <td colspan=3D6 class=3Dxl48 width=3D454 style=3D'width:341pt'>Questions/=
Control
  Activities</td>
  <td class=3Dxl48 width=3D68 style=3D'border-top:none;width:51pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D486 style=3D'border-top:none;width:365pt'>Commen=
ts/Testing
  Performed and Results</td>
  <td class=3Dxl44></td>
  <td class=3Dxl45 width=3D64 style=3D'width:48pt'>&nbsp;</td>
 </tr>
 <tr class=3Dxl38 height=3D44 style=3D'mso-height-source:userset;height:33.=
0pt'>
  <td height=3D44 class=3Dxl103 width=3D64 style=3D'height:33.0pt;width:48p=
t' x:num>2.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'>Who
  is/are the person(s) responsible for information security?</td>
  <td class=3Dxl62 width=3D68 style=3D'border-left:none;width:51pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D44 style=3D'mso-height-source:userset;height:33.=
0pt'>
  <td height=3D44 class=3Dxl103 width=3D64 style=3D'height:33.0pt;border-to=
p:none;
  width:48pt' x:num>2.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Are
  there written job descriptions for all information technology/security job
  functions?</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D44 style=3D'mso-height-source:userset;height:33.=
0pt'>
  <td height=3D44 class=3Dxl103 width=3D64 style=3D'height:33.0pt;border-to=
p:none;
  width:48pt' x:num>2.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'
  x:str=3D"Please document the following roles and responsibilities, indica=
ting if the responsibilities are outsourced: ">Please
  document the following roles and responsibilities, indicating if the
  responsibilities are outsourced:<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.1</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  user administration</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Application
  security</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  management</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.4</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Governance
  of security functions</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.5</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  policy and standards creation/enforcement</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D58 style=3D'mso-height-source:userset;height:43.=
5pt'>
  <td height=3D58 class=3Dxl80 width=3D64 style=3D'height:43.5pt;border-top=
:none;
  width:48pt'>2.3.6</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  incident response planning and management (including public relations in
  cases where a security breach becomes a public issue)</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.7</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  awareness and training</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.8</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Vulnerability
  management/threat assessment</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.9</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  event monitoring</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.10</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Physical
  security</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.11</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Architecture
  and engineering of security infrastructure</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D22 style=3D'mso-height-source:userset;height:16.=
5pt'>
  <td height=3D22 class=3Dxl80 width=3D64 style=3D'height:16.5pt;border-top=
:none;
  width:48pt'>2.3.12</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Disaster
  recovery and business continuity planning</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D12 height=3D50 class=3Dxl112 width=3D1264 style=3D'height:3=
7.5pt;
  width:949pt'>2.2 Security of Third-Party Access High-Level Expectation:<s=
pan
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Service Pr=
oviders
  should have and adhere to a policy to control third-party access to the
  organization&#8217;s information or information system, including physical
  and logical access.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D64 style=3D'mso-height-source:userset;height:48.0pt'>
  <td height=3D64 class=3Dxl80 width=3D64 style=3D'height:48.0pt;border-top=
:none;
  width:48pt'>2.2.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'>What
  are the procedures and policies to control third-party access to informai=
ton
  and information systems, including physical and logical access?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl80 width=3D64 style=3D'height:30.75pt;border-to=
p:none;
  width:48pt'>2.2.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Does
  the policy apply to contract employees (offsite and onsite), dependent
  Service Providers, etc.?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D56 style=3D'mso-height-source:userset;height:42.0pt'>
  <td height=3D56 class=3Dxl80 width=3D64 style=3D'height:42.0pt;border-top=
:none;
  width:48pt'>2.2.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Have
  any third-party service providers been granted remote access privileges a=
nd
  is there a business requirement for such remote access?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D33 style=3D'mso-height-source:userset;height:24.75pt'>
  <td height=3D33 class=3Dxl80 width=3D64 style=3D'height:24.75pt;border-to=
p:none;
  width:48pt'>2.2.4</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'
  x:str=3D"Are requirements, reviews and approvals of access documented? ">=
Are
  requirements, reviews and approvals of access documented?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D12 height=3D50 class=3Dxl112 width=3D1264 style=3D'height:3=
7.5pt;
  width:949pt'>2.3 Outsourcing High-Level Expectation:<font class=3D"font9"=
><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>The Service Provider should have=
 a
  process to review all dependent Service Providers&#8217; security policies
  and procedures to ensure that appropriate security language is incorporat=
ed
  into all third-party agreements.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Service Providers should ensure that affected financial institutio=
ns
  are aware of any outsourcing and that any required due diligence is
  completed.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'>Are
  dependent providers engaged in providing any services related to the Rece=
iver
  Company's outsourced application, service or system?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.1.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If YES, what
  services are being performed by dependent providers?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D79 style=3D'mso-height-source:userset;height:59.25pt'>
  <td height=3D79 class=3Dxl80 width=3D64 style=3D'height:59.25pt;border-to=
p:none;
  width:48pt'>2.3.1.2</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Does the Servi=
ce
  Provider review of the dependent Service Provider(s) include due diligenc=
e,
  risk assessment, contract review, site visits, disaster recovery/business
  continuity planning and ongoing performance monitoring?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl81 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Do
  Service Provider's contracts with third parties incorporate appropriate
  elements of the information security policy requirements and document rol=
es
  and responsibilities?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.2.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp; </span><font class=3D"font9=
"><span
  style=3D'mso-spacerun:yes'>&nbsp;</span>If YES, how is compliance demonst=
rated?</font></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Please
  describe the Service Provider&#8217;s service record and experience with
  dependent Service Providers.</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.4</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Do
  the Service Provider&#8217;s procedures include issuing notification
  procedures, communication procedures, and contingency plans for dependent
  Service Providers?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl80 width=3D64 style=3D'height:30.75pt;border-to=
p:none;
  width:48pt'>2.3.5</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Has
  interoperability security between Service Provider and dependent providers
  been ensured?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D27 style=3D'mso-height-source:userset;height:20.25pt'>
  <td height=3D27 class=3Dxl80 width=3D64 style=3D'height:20.25pt;border-to=
p:none;
  width:48pt'>2.3.6</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'
  x:str=3D"Please explain how terminations are handled.  ">Please explain h=
ow
  terminations are handled.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</s=
pan></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D49 style=3D'mso-height-source:userset;height:36.75pt'>
  <td height=3D49 class=3Dxl80 width=3D64 style=3D'height:36.75pt;border-to=
p:none;
  width:48pt'>2.3.7</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Has a
  process been established to review invoices (i.e., ensure proper charges =
for
  services rendered, rate changes, and new service charges)?<font class=3D"=
font10">&nbsp;</font></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D84 style=3D'mso-height-source:userset;height:63.0pt'>
  <td height=3D84 class=3Dxl80 width=3D64 style=3D'height:63.0pt;border-top=
:none;
  width:48pt'>2.3.8</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Has a
  process been established to review service provider/subcontractor perform=
ance
  relative to service-level agreements, determine if contractual terms and
  conditions are being met and the need for revisions to service-level
  agreements is evaluated?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D36 style=3D'mso-height-source:userset;height:27.0pt'>
  <td height=3D36 class=3Dxl80 width=3D64 style=3D'height:27.0pt;border-top=
:none;
  width:48pt'>2.3.9</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Are
  appropriate documents and records maintained regarding contract complianc=
e,
  revision and dispute resolution?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D122 style=3D'mso-height-source:userset;height:91.5pt'>
  <td height=3D122 class=3Dxl80 width=3D64 style=3D'height:91.5pt;border-to=
p:none;
  width:48pt'>2.3.10</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Does
  the service agreement include a clear specification of all relevant terms,
  conditions, responsibilities, and liabilities of both parties?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Examples include:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>compliance, audit reporting, on-=
site
  review, notification of change/risk, SLAs, data ownership, insurance,
  liability, privacy, dispute resolution, problem reporting and escalation
  procedures, ongoing monitoring, and requirements for service providers
  outside of the United States?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D134 style=3D'width:101pt'></td>
  <td width=3D68 style=3D'width:51pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D486 style=3D'width:365pt'></td>
  <td width=3D287 style=3D'width:215pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet006.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet006.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(5);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>18</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>6</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1224 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:918pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D488 style=3D'mso-width-source:userset;mso-width-alt:17846;wid=
th:366pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D416 style=3D'mso-width-source:userset;mso-width-alt:15213;wid=
th:312pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 rowspan=3D3 height=3D124 class=3Dxl116 width=3D1224 style=
=3D'border-bottom:
  1.0pt solid black;height:93.0pt;width:918pt'>3.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>ASSET CLASSIFICATION AND CONTROL=
:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Asset
  Classification and Control addresses the ability of the security
  infrastructure to protect organizational assets, including:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><br>
    Accountability and inventory &#8211; Mechanisms to maintain an accurate
  inventory of assets and establish ownership and stewardship of all assets.
  <br>
    Classification &#8211; Mechanisms to classify assets based on business
  impact, including privacy violations. &middot;&nbsp; <br>
    Labeling &#8211; Labeling standards unambiguously brand assets to their
  classification.&nbsp; <br>
    Handling &#8211; Handling standards, including introduction, transfer,
  removal, and disposal of all assets, are based on asset classification.</=
font></td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
 </tr>
 <tr height=3D90 style=3D'mso-height-source:userset;height:67.5pt'>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td colspan=3D7 height=3D21 class=3Dxl55 width=3D1224 style=3D'height:15.=
75pt;
  width:918pt'>Document that May Be Requested:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Asset cont=
rol
  policy</font></td>
 </tr>
 <tr height=3D47 style=3D'mso-height-source:userset;height:35.25pt'>
  <td colspan=3D7 height=3D47 class=3Dxl55 width=3D1224 style=3D'height:35.=
25pt;
  width:918pt'>3.1 Accountability For Assets High-Level Expectation:<font
  class=3D"font9"> Service Providers should have in place an appropriate as=
set
  control policy structure, including appropriate ownership, management,
  licensing and other controls that address the following asset types:
  information assets, software assets, physical assets, and services.</font=
></td>
 </tr>
 <tr class=3Dxl24 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl47 style=3D'height:15.75pt;border-top:none'>&nb=
sp;</td>
  <td class=3Dxl48 width=3D488 style=3D'border-top:none;width:366pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl50 width=3D416 style=3D'border-top:none;width:312pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt'>3.1.1</td>
  <td class=3Dxl62 width=3D488 style=3D'border-left:none;width:366pt'>Does =
the
  Service Provider have asset control and security policies and procedures?=
</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
2</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Is
  an inventory of assets maintained for hardware, software, information ass=
ets,
  physical assets, and services?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>3.1.=
3</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'
  x:str=3D"Are levels of security maintained for different types of assets?=
  ">Are
  levels of security maintained for different types of assets?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 class=3Dxl61 style=3D'height:12.75pt;border-top:none'>3.1=
.4</td>
  <td rowspan=3D2 class=3Dxl63 width=3D488 style=3D'border-top:none;width:3=
66pt'
  x:str=3D"Who/what functions have been assigned accountability for managin=
g the policy by each type of asset? ">Who/what
  functions have been assigned accountability for managing the policy by ea=
ch
  type of asset?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D30 style=3D'mso-height-source:userset;height:22.5pt'>
  <td height=3D30 class=3Dxl61 style=3D'height:22.5pt;border-top:none'><span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>3.1.=
4.1</td>
  <td class=3Dxl78 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>How
  often is accountability reviewed and updated?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
5</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Are
  there procedures and controls for how equipment and/or software is purcha=
sed?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
6</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Are
  there procedures and controls for disposal and reuse of equipment and
  software?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
6</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Are
  there procedures and controls for ordering new hardware assets, software
  assets, physical assets and services?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
7</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Does
  information technology (IT) management authorize all hardware acquisition=
s?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
8</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Do
  the server site, network database and application management teams coordi=
nate
  the installation and testing of all hardware changes?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'><span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D76 style=3D'mso-height-source:userset;height:57.0pt'>
  <td colspan=3D7 height=3D76 class=3Dxl112 width=3D1224 style=3D'height:57=
.0pt;
  width:918pt'>3.2 Information Classification High-Level Expectation:<font
  class=3D"font9"> The information and materials processed, stored or trans=
mitted
  by the Service Provider on behalf of the Receiver Company should be handl=
ed
  in accordance with the classification (e.g., confidential, sensitive, pub=
lic)
  of the information as stated in applicable laws, regulations and Receiver
  Company&#8217;s policies and standards as communicated to the Service
  Provider. The Service Provider&#8217;s physical and electronic procedures
  should maintain the Receiver Company&#8217;s defined classification of the
  information assets.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></=
font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.2.=
1</td>
  <td class=3Dxl62 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Does
  the Service Provider&#8217;s program support information classifications
  defined by the Receiver Company?</td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.2.=
2</td>
  <td class=3Dxl63 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Are
  there any inconsistencies between definitions of various classes of
  information between the Service Provider and the Receiving Company?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>3.2.=
3</td>
  <td class=3Dxl64 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Are
  there any applicable laws, regulations or policies that could impact the
  Service Provider&#8217;s ability to comply with the Receiver Company
  information classification requirements?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td height=3D59 class=3Dxl61 style=3D'height:44.25pt;border-top:none'>3.2=
.4</td>
  <td class=3Dxl64 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'
  x:str=3D"Are there Service Provider procedures for labeling printed repor=
ts, screen displays, magnetic media, and electronic messages and file trans=
fers for Receiver Company data? ">Are
  there Service Provider procedures for labeling printed reports, screen
  displays, magnetic media, and electronic messages and file transfers for
  Receiver Company data?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D81 style=3D'mso-height-source:userset;height:60.75pt'>
  <td height=3D81 class=3Dxl61 style=3D'height:60.75pt;border-top:none'>3.2=
.5</td>
  <td class=3Dxl64 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'>Are
  there information-handling procedures for copying, storage, packaging for
  internal mail, packaging for external mail, electronic transmission, spok=
en
  transmission, wireless and cell phone communication, and destruction based
  upon the information classification requirements?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>3.2.=
6</td>
  <td class=3Dxl64 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'
  x:str=3D"Are there Service Provider procedures for handling backups?  ">A=
re
  there Service Provider procedures for handling backups?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>3.2.=
6.1</td>
  <td class=3Dxl64 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Are they maint=
ained
  onsite or offsite?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>3.2=
.6.2</td>
  <td class=3Dxl64 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'
  x:str=3D"     If maintained offsite, does the contract or SLA with the st=
orage vendor contain written information classification requirements, secur=
ity responsibilities, and liabilities?  "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If maintained
  offsite, does the contract or SLA with the storage vendor contain written
  information classification requirements, security responsibilities, and
  liabilities?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D48 style=3D'mso-height-source:userset;height:36.0pt'>
  <td height=3D48 class=3Dxl61 style=3D'height:36.0pt;border-top:none'>3.2.=
6.3</td>
  <td class=3Dxl64 width=3D488 style=3D'border-top:none;border-left:none;wi=
dth:366pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>As backups age=
 off
  the schedule, are they securely destroyed or is the media reused?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D488 style=3D'width:366pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D416 style=3D'width:312pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet007.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet007.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(6);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Selected/>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>14</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1542 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1156pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D475 style=3D'mso-width-source:userset;mso-width-alt:17371;wid=
th:356pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D299 style=3D'mso-width-source:userset;mso-width-alt:10934;wid=
th:224pt'>
 <col width=3D64 span=3D7 style=3D'width:48pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 rowspan=3D3 height=3D52 class=3Dxl116 width=3D1094 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:39.0pt;width:820=
pt'>4.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>PERSONNEL SECURITY:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Personnel includes employees,
  consultants, vendors, part-time employees, etc.</td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D7 style=3D'height:12.75pt;mso-ignore:colspan'><=
/td>
 </tr>
 <tr height=3D18 style=3D'height:13.5pt'>
  <td height=3D18 colspan=3D7 style=3D'height:13.5pt;mso-ignore:colspan'></=
td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl55 width=3D1094 style=3D'border-rig=
ht:1.0pt solid black;
  height:33.75pt;width:820pt'>Documents that May Be Requested:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Employment=
 policy,
  non-disclosure agreements, background check documents for staff supporting
  very sensitive services or data, copy of insurance declaration pages</fon=
t></td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td colspan=3D7 height=3D41 class=3Dxl55 width=3D1094 style=3D'border-rig=
ht:1.0pt solid black;
  height:30.75pt;width:820pt'>4.1 Security in Job Definition and Resourcing
  High-Level Expectation: <font class=3D"font9">Service Providers should ha=
ve and
  adhere to policies and procedures in place to perform background checks f=
or
  those individuals who will be administering systems or have access to
  Receiver Company information.<span style=3D'mso-spacerun:yes'>&nbsp; </sp=
an>These
  policies and procedures should ensure that personnel responsible for desi=
gn,
  development, implementation and operation are qualified to fulfill their
  responsibilities.</font></td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl54 style=3D'height:27.75pt;border-top:none'>&nb=
sp;</td>
  <td class=3Dxl48 width=3D475 style=3D'border-top:none;width:356pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D299 style=3D'border-top:none;width:224pt'>Testing
  Performed and Results</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl84 style=3D'height:29.25pt'>4.1.1</td>
  <td class=3Dxl85 width=3D475 style=3D'border-left:none;width:356pt'>What =
are the
  Service Provider's policies and procedures for pre-employment screening?<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl61 style=3D'height:29.25pt;border-top:none'>4.1=
.2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  there any limitations on resources that are available for non-U.S. based
  locations?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  the policy and procedure include:</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.1</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"     Criminal background checks (local, state, national, and int=
ernational)? "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Criminal backg=
round
  checks (local, state, national, and international)?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Credit backgro=
und
  checks?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Reference chec=
ks?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Drug screening=
?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Biometric scans
  (e.g., fingerprint, retinal scans)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl61 style=3D'height:29.25pt;border-top:none'>4.1=
.4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  criminal, credit or reference checks performed on permanent employees,
  part-time employees, consultants, and temporary and contract employees?</=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D28 style=3D'mso-height-source:userset;height:21.0pt'>
  <td height=3D28 class=3Dxl61 style=3D'height:21.0pt;border-top:none'>4.1.=
5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  the policy require periodic reviews based upon differing levels of access=
?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D33 style=3D'mso-height-source:userset;height:24.75pt'>
  <td height=3D33 class=3Dxl61 style=3D'height:24.75pt;border-top:none'>4.1=
.6</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  employees sign and abide by a non-disclosure or confidentiality agreement=
?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.1=
.7</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  terms and conditions of employment clearly state information security
  responsibilities?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>4.1.=
8</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Is the annual rate of personnel turnover for both exempt and non=
-exempt workers at a level consistent with the industry?  ">Is
  the annual rate of personnel turnover for both exempt and non-exempt work=
ers
  at a level consistent with the industry?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
9</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Are employees bonded?  ">Are employees bonded?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
9.1</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If so, what le=
vel
  and type?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>4.1=
.10</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>What
  industry or security certifications are held by Service Provider employees
  (e.g., CISA, CISSP, TISCA)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D65 style=3D'mso-height-source:userset;height:48.75pt'>
  <td colspan=3D7 height=3D65 class=3Dxl112 width=3D1094 style=3D'height:48=
.75pt;
  width:820pt'>4.2 User Training High-Level Expectation:<font class=3D"font=
9">
  All employees of the Service Provider&#8217;s organization, and where
  relevant, third-party users, should be made aware of information-security
  threats and concerns, and should be equipped to support the organizational
  security policy in the course of their normal work. Users should be train=
ed
  in information-security procedures and the correct use of
  information-processing facilities to minimize possible security threats.<=
/font></td>
  <td colspan=3D7 class=3Dxl44 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.2=
.1</td>
  <td class=3Dxl65 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  the Service Provider have formal Security Training and Awareness Programs=
<font
  class=3D"font9">?</font></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>4.2.=
2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  all new employees (permanent, temporary or contract) receive
  information-security awareness presentations and information-security
  training as appropriate?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  security training and awareness include a testing component?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>4.2=
.4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Please describe any training that should be provided by the serv=
ice provider to customer personnel.  ">Please
  describe any training that should be provided by the service provider to
  customer personnel.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>4.2=
.5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  there any user groups or forums in which customer personnel should
  participate?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D49 style=3D'mso-height-source:userset;height:36.75pt'>
  <td height=3D49 class=3Dxl61 style=3D'height:36.75pt;border-top:none'>4.2=
.6</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  the security training commensurate with levels of responsibilities and
  access, and does it include security policies, procedures and processes?<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
7</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  employees specifically made aware of &#8220;social engineering&#8221; ris=
ks?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>4.2.=
8</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Does security awareness training cover the employee&#8217;s resp=
onsibility to report security incidents?  ">Does
  security awareness training cover the employee&#8217;s responsibility to
  report security incidents?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</=
span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
9</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  security training repeated at regular intervals for all staff?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
10</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  security training performed on a recurring basis?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.2=
.11</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  resources available for employees on information-security training (e.g.,
  website for security and security issues, brochures, etc.)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl61 style=3D'height:29.25pt;border-top:none'>4.2=
.12</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Do all employees periodically sign a certification document atte=
sting to their understanding and awareness of the policy and procedures?  "=
>Do
  all employees periodically sign a certification document attesting to the=
ir
  understanding and awareness of the policy and procedures?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
12.1</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>How
  is it enforced?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>4.2=
.13</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>For
  job functions designated in the escalation line for incident response, are
  staff fully aware of their responsibilities and involved in testing those
  plans?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.2=
.14</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>For
  job functions designated in the escalation line for disaster recovery pla=
ns,
  are staff fully aware of their responsibilities and involved in testing t=
hose
  plans?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D86 style=3D'mso-height-source:userset;height:64.5pt'>
  <td colspan=3D7 height=3D86 class=3Dxl104 width=3D1094 style=3D'height:64=
.5pt;
  width:820pt'>4.3 Responding to Security Incidents and Software Malfunctio=
ns
  High-Level Expectation:<font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Incidents affecting security sho=
uld be
  reported through appropriate management channels as quickly as possible. =
All
  employees and contractors should be made aware of the procedures for
  reporting different types of incidents (security breach, threats,
  vulnerabilities, or security-related software malfunction) that might hav=
e an
  impact on the Receiver Company&#8217;s operations.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>All employees and contractors sh=
ould
  be required to report any observed or suspected threats, vulnerabilities,=
 or
  incidents as quickly as possible to the designated point of contact.</fon=
t></td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
1</td>
  <td class=3Dxl65 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  the Service Provider&#8217;s corporate policy and procedures include resp=
onse
  for security breaches, threats, vulnerabilities and software malfunctions=
?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  the Service Provider have SLAs or contracts in place with business partne=
rs,
  vendors, customers, etc. that document security responsibilities and
  liabilities in case of a breach?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Does the Service Provider have insurance coverage?  ">Does the S=
ervice
  Provider have insurance coverage?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
3.1</td>
  <td class=3Dxl78 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"If so, what type(s) and limits? ">If so, what type(s) and limits=
?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Are there provisions in the policy to cover information-security=
 incidents that occur outside of normal business hours or is the same polic=
y invoked irrespective of time of day?  ">Are
  there provisions in the policy to cover information-security incidents th=
at
  occur outside of normal business hours or is the same policy invoked
  irrespective of time of day?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  the execution of responsibilities during an incident tested?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
6</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  information-security incidents reported and tracked within the Service
  Provider company, and communicated to the Receiver Company and regulators=
?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
7</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Is there a continuous improvement process in place for the polic=
y? ">Is
  there a continuous improvement process in place for the policy?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
8</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  there disciplinary processes in place for employees who violate the polic=
y?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D14 style=3D'height:12.75pt;mso-ignore:colspan'>=
</td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D14 style=3D'height:12.75pt;mso-ignore:colspan'>=
</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D475 style=3D'width:356pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D299 style=3D'width:224pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet008.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet008.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(7);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>3</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>32</x:ActiveRow>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1207 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:905pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D400 style=3D'mso-width-source:userset;mso-width-alt:14628;wid=
th:300pt'>
 <col width=3D72 style=3D'mso-width-source:userset;mso-width-alt:2633;width=
:54pt'>
 <col width=3D64 span=3D3 style=3D'width:48pt'>
 <col width=3D479 style=3D'mso-width-source:userset;mso-width-alt:17517;wid=
th:359pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl116 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>5. PHYSICAL AND ENVIRONMENTAL SECURITY: <font
  class=3D"font9">Physical and Environmental Security control addresses risk
  inherent to organizational premises, including:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Location &#8211; Organizational premises shou=
ld
  be analyzed for environmental hazards.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl132 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Physical security perimeter &#8211; The
  premises&#8217; security perimeter should be clearly defined and physical=
ly
  sound. A given premises may have multiple zones based on classification l=
evel
  or other organizational requirements.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Access control &#8211; Ingress/egress locatio=
ns
  in the physical security perimeter should have appropriate entry/exit
  controls commensurate with their classification level.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Equipment &#8211; Equipment should be sited
  within the premises to ensure physical and environmental integrity and
  availability.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Asset transfer &#8211; Mechanisms should exis=
t to
  track entry and exit of assets through the security perimeter.</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl129 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:905pt'>General &#8211; Policies and standards, such as
  utilization of shredding equipment, secure storage, and &quot;clean
  desk&quot; principles, should exist to govern operational security within=
 the
  workspace.</td>
 </tr>
 <tr height=3D29 style=3D'mso-height-source:userset;height:21.75pt'>
  <td colspan=3D7 height=3D29 class=3Dxl55 width=3D1207 style=3D'border-rig=
ht:1.0pt solid black;
  height:21.75pt;width:905pt'>Documents that May Be Requested:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Floor plan=
, badge
  control policy, physical access logging policy, copy of insurance declara=
tion
  pages</font></td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td colspan=3D7 height=3D59 class=3Dxl105 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:44.25pt;width:905pt'>5.1 Secure Areas High-Level Expectation:<font
  class=3D"font9"> Business information processing, storage or distribution
  facilities should be housed in secure areas, protected by a defined secur=
ity
  perimeter, with appropriate security barriers and entry controls. Facilit=
ies
  should be physically protected from unauthorized access, damage and
  interference.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Access should=
 be
  logged and logs should be securely maintained.</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl54 style=3D'height:15.0pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D400 style=3D'border-top:none;width:300pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D72 style=3D'border-top:none;width:54pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D479 style=3D'border-top:none;width:359pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt'>5.1.1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-left:none;width:300pt'>Are t=
here
  policies and procedures in place for protecting and monitoring the physic=
al
  infrastructure for staff and assets where business information processing,
  storage or distribution is performed?</td>
  <td class=3Dxl62 width=3D72 style=3D'border-left:none;width:54pt'>&nbsp;<=
/td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider own each of the facilities at which Receiver Company
  work is being conducted?<span style=3D'mso-spacerun:yes'>&nbsp; </span>(If
  leased, please document when the lease expires.)</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is the physical perimeter adequately protected for each location=
 where Receiver Company work is being conducted? ">Is
  the physical perimeter adequately protected for each location where Recei=
ver
  Company work is being conducted?<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D100 style=3D'height:75.0pt'>
  <td height=3D100 class=3Dxl61 style=3D'height:75.0pt;border-top:none'>5.1=
.4</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there any specific issues related to external physical risks=
 such as nuclear power facilities, chemical plants or other hazardous manuf=
acturing facilities, natural gas, petroleum or other pipelines or pipeline =
processing facilities, or natural disasters such as flooding, tornadoes or =
earthquakes? ">Are
  there any specific issues related to external physical risks such as nucl=
ear
  power facilities, chemical plants or other hazardous manufacturing
  facilities, natural gas, petroleum or other pipelines or pipeline process=
ing
  facilities, or natural disasters such as flooding, tornadoes or
  earthquakes?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
4.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, please describe these issues.</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>5.1.=
5</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Where facilities are shared, please indicate the number of tenan=
t-occupied floors.  Describe the building tenants with common walls, floors=
 or ceilings that are contiguous to areas occupied by the Service Provider.=
  ">Where
  facilities are shared, please indicate the number of tenant-occupied
  floors.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Describe the buildi=
ng
  tenants with common walls, floors or ceilings that are contiguous to areas
  occupied by the Service Provider.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
6</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there any specific issues related to war, terrorism, or othe=
r regional risks?  ">Are
  there any specific issues related to war, terrorism, or other regional
  risks?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
6.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, please describe these issues.</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
7</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is identification of buildings or facilities kept to a minimum? =
">Is
  identification of buildings or facilities kept to a minimum?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
8</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there an isolated delivery or loading area?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
8.1</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>If YES, is access to the delivery or loading area controlled or
  monitored?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
9</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Please describe how the data center is secured. ">Please describ=
e how
  the data center is secured.<span style=3D'mso-spacerun:yes'>&nbsp;</span>=
</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
10</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are the controls employed for the data center the same as other =
facilities?   ">Are
  the controls employed for the data center the same as other facilities?<s=
pan
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
10.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"If NO, please describe how these controls are different from con=
trols protecting other facilities. ">If
  NO, please describe how these controls are different from controls protec=
ting
  other facilities.<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"How is the security of the data center verified? ">How is the se=
curity
  of the data center verified?<span style=3D'mso-spacerun:yes'>&nbsp;</span=
></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.1</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"      Please supply the results of the two most recent tests. ">=
<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Please s=
upply
  the results of the two most recent tests.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
11.2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"      How is access to sites, buildings and rooms restricted to =
authorized personnel only (e.g.,   badge, reception desk, guards, escort, l=
ocks, and biometrics)? "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>How is a=
ccess
  to sites, buildings and rooms restricted to authorized personnel only
  (e.g.,<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>badge, recepti=
on
  desk, guards, escort, locks, and biometrics)?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.3</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are dual controls employed for access? ">Are dual controls emplo=
yed
  for access?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
11.4</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Do
  access requests for the card access system, including changes, require
  written approval of the site operations manager?</td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.5</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are all access points monitored in &#8220;real time&#8221;?   ">=
Are
  all access points monitored in &#8220;real time&#8221;?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.6</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are visitors to the premises escorted at all times? ">Are visito=
rs to
  the premises escorted at all times?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
11.7</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are associates, contractors, visitors or temporary employees phy=
sically differentiated while on premises? ">Are
  associates, contractors, visitors or temporary employees physically
  differentiated while on premises?<span style=3D'mso-spacerun:yes'>&nbsp;<=
/span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
12</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Describe
  the process for monitoring building safety, personnel and visitor access,
  including reviewing access logs, procedures followed during business and
  outside of business hours, etc.</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>5.1.=
13</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  do security personnel monitor the facility, including such things as hour=
s of
  coverage, use of employees or contractors, different types of badges, and
  whether the area is patrolled at regular intervals?</td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
14</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>For
  how long are logs securely maintained?</td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
15</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there security cameras, motion detectors and alarms in place=
 and monitored?    ">Are
  there security cameras, motion detectors and alarms in place and
  monitored?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;</span=
></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
15.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"If YES, please describe their monitoring, management and mainten=
ance support. ">If
  YES, please describe their monitoring, management and maintenance
  support.<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
16</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is environmental protection equipment (fire suppression, firepro=
ofing, water flooding, heat/air conditioning, power supply) installed, test=
ed, and monitored?     ">Is
  environmental protection equipment (fire suppression, fireproofing, water
  flooding, heat/air conditioning, power supply) installed, tested, and
  monitored?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
16.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"If YES, what is the schedule for testing this equipment?   ">If =
YES,
  what is the schedule for testing this equipment?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
17</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the data center (i.e., server/computer room) have temperature and humidity
  control systems that are separate from the rest of the facility?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
17.1</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there separate and independent power supplies? ">Are there
  separate and independent power supplies?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
17.1.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  tests performed to verify the power supply (i.e., building or data center
  power down tests)?</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
17.2</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are failover systems or data centers employed?     ">Are failover
  systems or data centers employed?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
17.2.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is an inventory of &#8220;hot swaps&#8221; maintained for critic=
al equipment?   ">Is
  an inventory of &#8220;hot swaps&#8221; maintained for critical
  equipment?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
18</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is access to areas where work is performed for Receiver Company =
physically separated from that of other receiving companies? ">Is
  access to areas where work is performed for Receiver Company physically
  separated from that of other receiving companies?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
19</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Describe
  insurance policies that are in place.</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
20</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the contract for facilities insurance sufficient to mitigate any compromi=
se
  of physical security?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl104 width=3D1207 style=3D'height:33=
.75pt;
  width:905pt'>5.2 Equipment Security High-Level Expectation:<font class=3D=
"font9">
  Equipment should be physically protected from security threats and
  environmental hazards in order to prevent loss, damage or compromise of
  assets and interruption to business activities.</font></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.2.=
1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  there policies/procedures in place for protecting and monitoring the
  equipment for security threats or environmental hazards?</td>
  <td class=3Dxl62 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.2.=
2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  controls or safeguards in place to prevent unauthorized interception or
  damage to network, power or telecommunications cabling?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  emissions (wire in conduit, monitors, wireless broadcasts) shielded to
  prevent compromise of network security?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.2.=
4</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  all phone/cable closets secured?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D140 style=3D'height:105.0pt'>
  <td height=3D140 class=3Dxl61 style=3D'height:105.0pt;border-top:none'>5.=
2.5</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  continuous power supply equipment installed and maintained for critical
  systems in support of the service required for the Receiver Company?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>How long does the UPS (uninterru=
ptible
  power supply) system last?<span style=3D'mso-spacerun:yes'>&nbsp; </span>=
How
  long does it take for the generators to start up and take over?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>How long will the generators run
  without refueling?<span style=3D'mso-spacerun:yes'>&nbsp; </span>What ste=
ps
  have been taken to ensure timely refueling?<font class=3D"font13"><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></font></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
6</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is all production server/computer equipment located in the data =
center (i.e., server/computer room)?  ">Is
  all production server/computer equipment located in the data center (i.e.,
  server/computer room)?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span=
></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.2.=
7</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  all equipment (hardware, cables) labeled or otherwise identified?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
8</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"What equipment is located or held off-site (e.g., data centers, =
third-party support, employees with laptop computers)?  ">What
  equipment is located or held off-site (e.g., data centers, third-party
  support, employees with laptop computers)?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
8.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  policies, procedures and safeguards in place that apply to off-site
  equipment?</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.2.=
9</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Can maintenance of equipment be performed remotely?  ">Can maint=
enance
  of equipment be performed remotely?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
9.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, please describe who has access and how this access is secured and
  controlled.</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.2.=
10</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>When
  disposing of or reusing equipment (hardware and software), are there
  procedures that govern the secure destruction of any data held on such
  equipment?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td colspan=3D7 height=3D44 class=3Dxl104 width=3D1207 style=3D'height:33=
.0pt;
  width:905pt'>5.3 General Controls High-Level Expectation: <font class=3D"=
font9">Information
  and information-processing facilities should be protected from disclosure=
 to,
  modification of, or theft by unauthorized persons. Controls should be in
  place to minimize loss or damage.</font></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>5.3.=
1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the policy to secure information consistent with information-security
  classification (e.g., locked cabinets, document control, and clear
  screen/screen timeout policies)?</td>
  <td class=3Dxl62 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.3.=
2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  there procedures in place to document authorized removal of property for
  business purposes?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.3.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  there procedures in place to prevent the unauthorized removal of property=
?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D400 style=3D'width:300pt'></td>
  <td width=3D72 style=3D'width:54pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D479 style=3D'width:359pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet009.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet009.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(8);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>45</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1259 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:944pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col class=3Dxl38 width=3D400 style=3D'mso-width-source:userset;mso-width-=
alt:14628;
 width:300pt'>
 <col width=3D84 style=3D'mso-width-source:userset;mso-width-alt:3072;width=
:63pt'>
 <col width=3D64 span=3D3 style=3D'width:48pt'>
 <col width=3D519 style=3D'mso-width-source:userset;mso-width-alt:18980;wid=
th:389pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl135 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>6.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>COMMUNICATIONS AND OPERATIONS MANAGEMENT:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Communicat=
ion and
  Operations Management addresses an organization's ability to ensure corre=
ct
  and secure operation of its assets, including:</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Operational Procedures &#8211; Comprehensive s=
et
  of procedures in support of organizational standards and policies.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Change Control &#8211; Process to manage change
  and configuration control.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Incident Management &#8211; Team, procedures, =
and
  tools to ensure timely and effective response to and reporting of any
  security incidents.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Segregation of Duties &#8211; Segregation and
  rotation of duties minimize the potential for collusion and uncontrolled
  exposure.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Capacity Planning &#8211; Tools and procedures=
 to
  monitor and project organizational capacity to ensure uninterrupted
  availability.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>System Acceptance &#8211; Methodology to evalu=
ate
  system changes to ensure continued confidentiality, integrity, and
  availability.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Malicious Code &#8211; Controls to mitigate ri=
sk
  from introduction of malicious code.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Housekeeping &#8211; Policies, standards,
  guidelines, and procedures to address routine housekeeping activities suc=
h as
  backup schedules, deactivating access rights, and logging.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl141 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'><span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;
  </span>External Processing Facilities Management &#8211; Appropriate to t=
he
  level of risk, sufficient controls at third-party facilities are agreed u=
pon,
  implemented, and incorporated into the contract.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Network Management &#8211; A range of procedur=
es
  and other controls implemented to achieve and maintain security in networ=
ks.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Media Handling &#8211; Policies and procedures=
 for
  handling, storage, transport, and disposal of electronic storage media.</=
td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Information and Software Exchanges &#8211;
  Agreements (formal and informal), procedures, standards and other controls
  ensure the protection of production,</td>
 </tr>
 <tr height=3D29 style=3D'mso-height-source:userset;height:21.75pt'>
  <td colspan=3D7 height=3D29 class=3Dxl144 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:21.75pt;width:944pt'>e-commerce, messaging, office (non-production=
),
  and publicly available data, exchanges and systems in compliance with
  relevant legislation.</td>
 </tr>
 <tr height=3D0 style=3D'display:none'>
  <td colspan=3D7 class=3Dxl147 width=3D1259 style=3D'width:944pt'>&nbsp;</=
td>
 </tr>
 <tr height=3D69 style=3D'mso-height-source:userset;height:51.75pt'>
  <td colspan=3D7 height=3D69 class=3Dxl105 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:51.75pt;width:944pt'>Documents that May Be Requested:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Network di=
agram,
  dataflow diagram, runbooks, SOPs (standard operating procedures) and desk=
top
  procedures; operations (network, processing) and incident response team
  organization charts; office/employee awareness materials and corporate
  policies (signed annually); change control manual, minutes and records;
  system and network outage and capacity utilization records;
  incident-identification and response records; test plans and results;
  third-party due diligence records and contracts; policies, standards and
  guidelines; system and network criteria; planning and acceptance records.=
</font></td>
 </tr>
 <tr height=3D81 style=3D'mso-height-source:userset;height:60.75pt'>
  <td colspan=3D7 height=3D81 class=3Dxl105 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:60.75pt;width:944pt'>6.1 Operational Procedures and Responsibiliti=
es
  High-Level Expectation:<font class=3D"font9"> Responsibilities and proced=
ures
  for the management and operation of all information-processing facilities
  should be established and adhered to. This includes the development of
  appropriate operating instructions, and change control and incident-respo=
nse
  procedures. Segregation of duties and environments&#8212;development,
  testing, staging, and production&#8212;should be implemented where
  appropriate to reduce the risk of negligent, inadvertent or deliberate mi=
suse
  of information-processing facilities and systems.</font></td>
 </tr>
 <tr height=3D38 style=3D'mso-height-source:userset;height:28.5pt'>
  <td height=3D38 class=3Dxl54 style=3D'height:28.5pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D400 style=3D'border-top:none;width:300pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D84 style=3D'border-top:none;width:63pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D519 style=3D'border-top:none;width:389pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt'>6.1.1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-left:none;width:300pt'>What =
are the
  policies and procedures in place for management and operation of business
  processing facilities?</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
2</td>
  <td class=3Dxl62 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  operating and control procedures documented and communicated?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the policy include documented procedures for:</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Processing
  and handling of information?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Scheduling
  requirements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Handling
  errors? (e.g., transport of data, printing, copies)</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Segregation
  of duties to reduce opportunities for unauthorized modification, misuse of
  information, or services?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Escalation
  via a call tree for both Service Provider and Receiver Company?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Generating and handling special output? ">Generating and handling
  special output?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Restarting and recovering systems? ">Restarting and recovering
  systems?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Maintenance
  and troubleshooting of systems?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Routine
  backups?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Safety?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D100 style=3D'height:75.0pt'>
  <td height=3D100 class=3Dxl61 style=3D'height:75.0pt;border-top:none'>6.1=
.14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Please
  describe the reporting structure for application development, computer
  operations, security administration, program change and control, nerwork
  services, technical support, database adminstration, and disaster recovery
  services.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Do they report to
  different managers and function independently?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does a segregation of duties exist between the following functio=
ns: ">Does
  a segregation of duties exist between the following functions:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
15.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Individuals who
  authorize access, personnel who enable access, and personnel who verify
  access?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
15.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Personnel who =
enable
  access and those who review audit trails and/or violation logs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.1=
.15.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Personnel who
  install and maintain the logical access control process and those who rev=
iew
  audit trails and/or violation logs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the formal change control process (or SDLC) detail whether it includes:</=
td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Testing
  (including regression and security testing, as appropriate)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>6.1.=
16.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Independence between persons testing security from the persons a=
dministering security assessment? ">Independence
  between persons testing security from the persons administering security
  assessment?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Formal
  approval?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Backout
  or contingency plans?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Separation
  of development and production software and systems?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Separation
  of development and production teams?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Provisions
  for emergency changes?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.1=
.16.8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Documentation
  of changes and incorporation of documentation back into system manuals?</=
td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.1=
.17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there operating release management processes and procedures =
in place?  ">Are
  there operating release management processes and procedures in place?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
18</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are the releases controlled?  ">Are the releases controlled?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
19</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  new release functionality tested, scheduled, and deployed?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td height=3D63 class=3Dxl61 style=3D'height:47.25pt;border-top:none'>6.1=
.20</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Please describe any significant upgrades or other changes to the=
 Service Provider&#8217;s systems and networks over the past two years whic=
h may affect audits or assessments provided to validate controls. ">Please
  describe any significant upgrades or other changes to the Service
  Provider&#8217;s systems and networks over the past two years which may
  affect audits or assessments provided to validate controls.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D83 style=3D'mso-height-source:userset;height:62.25pt'>
  <td height=3D83 class=3Dxl61 style=3D'height:62.25pt;border-top:none'>6.1=
.21</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  system enhancement is planned for the next year that would impact Receiver
  Company systems and networks? (e.g., What changes may result in the need =
for
  additional testing or network connectivity changes?)</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.1=
.22</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider monitor and internally escalate the following:</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  incidents?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Internal
  fraud (information as well as transaction)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Unauthorized/unacceptable
  employee activity?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Other
  suspicious activities?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.1.=
23</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have documented incident-management procedures that
  address the following:</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Information
  system failures or losses of service?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Denial
  of service attacks?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  infrastructure exploits?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Errors
  resulting from incomplete or inaccurate business data?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Errors
  resulting from system or device misconfiguration?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Breaches
  or loss of confidentiality?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Contingency
  plans for recovery from specific incidents?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Gathering
  of evidenced and documentation as well as chain of custody protection?</t=
d>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Carefully
  controlled and tested recovery processes?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.24</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Please describe the process to address production problems (e.g.=
, personnel involved, documentation, retention, and timeliness).  ">Please
  describe the process to address production problems (e.g., personnel
  involved, documentation, retention, and timeliness).<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>6.1.=
25</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is a problem-tracking log produced that details all processing p=
roblems occurring during the previous 24 hours?  Is a unique number assigne=
d to each problem?  ">Is
  a problem-tracking log produced that details all processing problems
  occurring during the previous 24 hours?<span style=3D'mso-spacerun:yes'>&=
nbsp;
  </span>Is a unique number assigned to each problem?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>6.1.=
26</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  changes resulting from a production problem subject to the same process as
  program change management?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>6.1.=
27</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a documented process to track completion of follow-up actions to
  prevent reoccurrence of production problems?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
28</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider ensure that the security-event monitoring system has
  current signature files?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.29</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  training or qualifications have the various incident-response teams recei=
ved?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D25 style=3D'mso-height-source:userset;height:18.75pt'>
  <td height=3D25 class=3Dxl61 style=3D'height:18.75pt;border-top:none'>6.1=
.30</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the incident-response team available at all times?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.31</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  mechanisms are in place to allow employees to promptly report security
  incidents, weaknesses, and software malfunctions?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td height=3D63 class=3Dxl61 style=3D'height:47.25pt;border-top:none'>6.1=
.32</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have procedures to notify or handle inquiries from
  customers or clients, news media, government offices, outside investigato=
rs,
  shareholders, etc.?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.1=
.33</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  periodic meetings scheduled between the Service Provider and Receiver Com=
pany
  to discuss performance and operational issues?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl104 width=3D1259 style=3D'height:33=
.75pt;
  width:944pt'>6.2 System Planning and Acceptance High-Level Expectation:<f=
ont
  class=3D"font9"> Future capacity requirements should be projected and pla=
nned
  for to help ensure system availability and reduce the risk of systems
  overload. Operational requirements for new systems should be established,
  documented and tested prior to the system&#8217;s acceptance and use.</fo=
nt></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl64 width=3D64 style=3D'height:33.75pt;border-to=
p:none;
  width:48pt'>6.2.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider plan and monitor capacity, performance, transaction
  levels, etc.?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.2.=
2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  application, system and network architectures designed for high availabil=
ity
  and operational redundancy?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D66 style=3D'mso-height-source:userset;height:49.5pt'>
  <td height=3D66 class=3Dxl61 style=3D'height:49.5pt;border-top:none'>6.2.=
3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have formal acceptance procedures and criteria
  (including security) for new applications, systems and networks?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.2.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider ensure that implemented applications, systems and
  networks meet design requirements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td colspan=3D7 height=3D42 class=3Dxl104 width=3D1259 style=3D'height:31=
.5pt;
  width:944pt'>6.3 Protection Against Malicious Software High-Level
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Controls should be in place to prevent and detect the introduction=
 and
  dissemination of malicious software.<span style=3D'mso-spacerun:yes'>&nbs=
p;
  </span>Recovery plans should be prepared, updated and tested regularly.</=
font></td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a virus protection policy and procedures?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.2</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a policy and procedures in place for<font
  class=3D"font6"> reviewing application source code and executables to find
  exposures, vulnerabilities and malicious code before the application is
  deployed (i.e., code scanning)?</font></td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  antivirus software deployed, updated and maintained for desktops, servers,
  firewalls, and Internet email gateways?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  messages scanned for malicious code, worms, Trojan horses, back doors, fo=
rm
  input validation, and SQL injection?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the virus protection policy and procedures communicated internally?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the code scanning policy and procedures communicated internally?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.3.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  compliance with corporate policy tested?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.3.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Can
  end users override the antivirus software?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.3.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a virus protection response team?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  remote users and laptop computer users covered under the virus protection
  program?</td>
  <td class=3Dxl66 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  malicious code filtered at the network perimeter?</td>
  <td class=3Dxl66 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl104 width=3D1259 style=3D'height:33=
.75pt;
  width:944pt'>6.4 Backup High-Level Expectation:<font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Routine backup procedures should=
 be
  established and adhered to for carrying out the agreed backup strategy, s=
uch
  as taking backup copies of data, rehearsing their timely restoration, log=
ging
  events and faults, and, where appropriate, monitoring the equipment
  environment.</font></td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.4.=
1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Describe
  the Service Provider&#8217;s policies and procedures for system and data
  back-ups.</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  regular backups performed?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.4=
.3</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the backups protected from unauthorized access and tampering?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  often are backups performed?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are copies of the backups taken and stored offsite?  ">Are copie=
s of
  the backups taken and stored offsite?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Will
  the distance between the production environment and where the backups are
  stored allow for a speedy recovery?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Do the same access controls exist over data backups when stored =
offsite? ">Do
  the same access controls exist over data backups when stored offsite?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a specific or dedicated unit that performs this backup/recovery
  function?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  controls exist to ensure that backups are not rotated out until new backu=
ps
  are in place?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  processes and procedures are in place to allow for the destruction of bac=
kups
  in compliance with document-retention policies, laws or Receiver Company
  requirements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  long are operator logs retained?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>For
  how long are backups retained?<font class=3D"font14"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span></font><font class=3D"font9">Are=
 the
  backup media refreshed to prevent loss due to deterioration?</font></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are backup systems tested?  ">Are backup systems tested?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"How often? ">How often?<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Who
  participates?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  backups audited to ensure they function properly?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  maintenance or upgrade logs kept for hardware and/or software?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D36 style=3D'mso-height-source:userset;height:27.0pt'>
  <td colspan=3D7 height=3D36 class=3Dxl112 width=3D1259 style=3D'height:27=
.0pt;
  width:944pt'>6.5 Network Management High-Level Expectation:<font class=3D=
"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>The Service Provider should ensu=
re the
  managed network is secure so that data is protected when transmitted over
  both trusted and untrusted networks.</font></td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the following<span style=3D'mso-spacerun:yes'>&nbsp; </span>included in t=
he
  Service Provider&#8217;s network management program:</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Design,
  application and implementation of security/control domains (perimeter, DM=
Z,
  etc.) and perimeters?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  configuration development and implementation for network devices in
  accordance with their function in security/control zones (such as
  public/untrusted networks, semi-private networks, DMZs) and perimeters?</=
td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Remote access (administrator as well as &#8220;user&#8221; dial-=
in/dial-out, maintenance dial-in), remote access servers (including AAA), r=
emote access management utilities/tools appropriate to each security/contro=
l domain? ">Remote
  access (administrator as well as &#8220;user&#8221; dial-in/dial-out,
  maintenance dial-in), remote access servers (including AAA), remote access
  management utilities/tools appropriate to each security/control domain?<s=
pan
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Regular,
  periodic vulnerability and penetration testing in accordance with the ris=
k of
  each security/control domain and perimeter?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ne=
twork
  and system monitoring?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ne=
twork
  redundancy and diverse routing?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.5.=
6.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"       Controls to prevent unauthorized deployment of network co=
nnections and equipment?   "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Co=
ntrols
  to prevent unauthorized deployment of network connections and equipment?<=
span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>Deployment of Network IDSs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>Host-based IDS?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does the audit log review/network monitoring include the followi=
ng: ">Does
  the audit log review/network monitoring include the following:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Access
  failures and classification of data compromised?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Logon
  patterns for indications of abnormal use or revived user IDs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Allocation
  and use of accounts with a privileged access capability?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Tracking
  of selected transactions?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Use
  of sensitive resources?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Dial-up
  activity?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Firewall
  activity?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>OS
  and application access attempts?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  administration activity?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>The
  use of automated tools to perform this review on a frequent and periodic
  basis?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.18</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>The
  placement of intrusion-detection systems in the overall network architect=
ure?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.19</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Logs of security-related events should sufficiently assign accou=
ntability?  ">Logs
  of security-related events should sufficiently assign accountability?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.20</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Logs should be appropriately secured against unauthorized access=
, change, and deletion for an adequate time period? ">Logs
  should be appropriately secured against unauthorized access, change, and
  deletion for an adequate time period?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.21</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Detecting
  rogue devices and services?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D7 height=3D50 class=3Dxl104 width=3D1259 style=3D'height:37=
.5pt;
  width:944pt'>6.6 Media Handling and Security High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Appropriate
  operational procedures should be established and followed to protect
  documents, computer media (tapes, disks, cassettes, etc.), input/output d=
ata
  and system documentation from damage, theft and unauthorized access.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>6.6.=
1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a policy/procedure for handling and destroying
  various media?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.6=
.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Do the Service Provider's procedures ensure media are disposed o=
f securely? ">Do
  the Service Provider's procedures ensure media are disposed of securely?<=
span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D38 style=3D'mso-height-source:userset;height:28.5pt'>
  <td height=3D38 class=3Dxl61 style=3D'height:28.5pt;border-top:none'>6.6.=
3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a records-retention and destruction policy and
  related procedures?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.6.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does the Service Provider have a documented process for how medi=
a is labeled, stored and kept?  ">Does
  the Service Provider have a documented process for how media is labeled,
  stored and kept?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D38 style=3D'mso-height-source:userset;height:28.5pt'>
  <td height=3D38 class=3Dxl61 style=3D'height:28.5pt;border-top:none'>6.6.=
5</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  a tape management software package used to track backup tapes that are se=
nt
  offsite?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D48 style=3D'mso-height-source:userset;height:36.0pt'>
  <td height=3D48 class=3Dxl61 style=3D'height:36.0pt;border-top:none'>6.6.=
5.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"     If YES, what tape-management software package is used? "><s=
pan
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If YES, what
  tape-management software package is used?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td colspan=3D7 height=3D59 class=3Dxl104 width=3D1259 style=3D'height:44=
.25pt;
  width:944pt'>6.7 Exchanges of Information and Software High-Level
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>All exchanges of information and software between the Service
  Provider, suppliers of services to the Service Provider, and the Receiver
  Company should be controlled and compliant with contractual, legal and re=
gulatory
  requirements.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Exchanges sho=
uld be
  carried out on the basis of agreements.<span style=3D'mso-spacerun:yes'>&=
nbsp;
  </span>Procedures and standards should be established to protect informat=
ion
  and media in transit.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span>=
</font></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.7=
.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"What are all the Service Provider&#8217;s supportable means of e=
xchanging information? ">What
  are all the Service Provider&#8217;s supportable means of exchanging
  information?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
2</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are safeguards in place for each means of exchange?  ">Are safeg=
uards
  in place for each means of exchange?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
3</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  safeguards in place for the content of all such exchanges?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Can
  the Service Provider support information-exchange agreements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.7=
.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Can
  the Service Provider support software-exchange agreements (including soft=
ware
  escrow)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.7=
.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is there a review and authorization process that controls inform=
ation that is made publicly available? ">Is
  there a review and authorization process that controls information that is
  made publicly available?<span style=3D'mso-spacerun:yes'>&nbsp;</span></t=
d>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.7.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are information and transactions protected while conducting e-co=
mmerce?  ">Are
  information and transactions protected while conducting e-commerce?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.7=
.8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does that protection extend to intermediate and long-term storag=
e of information (e.g., on database)?  ">Does
  that protection extend to intermediate and long-term storage of informati=
on
  (e.g., on database)?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span><=
/td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D22 style=3D'mso-height-source:userset;height:16.5pt'>
  <td height=3D22 class=3Dxl61 style=3D'height:16.5pt;border-top:none'>6.7.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the protection extend to the entire supply chain?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the following maintained in the e-commerce system:</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Confidentiality?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Transaction
  authentication?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Authorization?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Non-repudiation?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Transaction
  integrity?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  is authentication performed?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  online registration and authentication managed for e-commerce/e-banking
  systems?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
18</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  sufficient tendering, vetting, settlement, and pricing information trust =
and
  liability controls available for e-commerce/e-banking transactions with o=
r by
  the Service Provider?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
19</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the Service Provider capable of meeting encryption key management
  requirements?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
20</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  access codes encrypted in storage and transmission?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td colspan=3D7 height=3D40 class=3Dxl148 width=3D1259 style=3D'height:30=
.0pt;
  width:944pt'>6.8 <font class=3D"font8">Website High-Level Expectation:</f=
ont><font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Appropriate
  operational procedures and practices should be established and followed to
  protect the website from damage, theft and unauthorized access.</font></t=
d>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  all unnecessary daemons disabled and removed from the system?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are periodic reviews of router and firewall logs performed to va=
lidate filter operation? ">Are
  periodic reviews of router and firewall logs performed to validate filter
  operation?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  all services that are not required (e.g., Telnet) turned off?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  a security software product (e.g., Internet Security Systems&#8217;
  Safesuite) periodically executed to determine potential security
  vulnerabilities on such interfacing domain components as routers, Web
  servers, mail servers, FTP servers, name servers, firewalls and network
  monitors (i.e., tested from inside and outside the firewall)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
4.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, what product(s) are used?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  any Service Provider software is branded with a Receiver Company brand, d=
oes
  the website include the Receiver Company data privacy statement?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>If it is branded with the Service
  Provider&#8217;s brand, is a commensurate statement in place?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a mechanism in place to capture and record consent of data privacy
  preferences, if necessary by law?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the privacy statement contain details of cookies or click stream methods
  used?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D400 style=3D'width:300pt'></td>
  <td width=3D84 style=3D'width:63pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D519 style=3D'width:389pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5A89A.7EF40B40
Content-Location: file:///C:/E5382234/1SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet010.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../1SecurityPolicyAssetClassificationControlPersonnelManagementAcce=
ssControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\1SecurityPolicyAssetClassificationControlPerson=
nelManagementAccessControlSystemDevelopment_files\sheet010.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(9);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../1SecurityPolicyAssetClassificationControlPerso=
nnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>135</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>58</x:ActiveRow>
    <x:RangeSelection>$A$59:$G$59</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1204 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:903pt'>
 <col class=3Dxl58 width=3D59 style=3D'mso-width-source:userset;mso-width-a=
lt:2157;
 width:44pt'>
 <col width=3D417 style=3D'mso-width-source:userset;mso-width-alt:15250;wid=
th:313pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D472 style=3D'mso-width-source:userset;mso-width-alt:17261;wid=
th:354pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl116 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>7.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;
  </span>ACCESS CONTROL:<span style=3D'mso-spacerun:yes'>&nbsp; </span><font
  class=3D"font9">Addresses an organization's ability to control access to =
assets
  based on business and security requirements, including:</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>Business requirements &#8211; Policy-controlli=
ng
  access to organizational assets based on business requirements and &quot;=
need
  to know.&quot;</td>
 </tr>
 <tr height=3D81 style=3D'mso-height-source:userset;height:60.75pt'>
  <td colspan=3D7 height=3D81 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:60.75pt;width:903pt'>User management &#8211; Mechanisms to:<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;
  </span>&sect; Register and deregister users<br>
    &sect; Control and review access and privileges<br>
    &sect; Manage passwords<br>
    </td>
 </tr>
 <tr height=3D145 style=3D'mso-height-source:userset;height:108.75pt'>
  <td colspan=3D7 height=3D145 class=3Dxl108 width=3D1204 style=3D'border-r=
ight:1.0pt solid black;
  height:108.75pt;width:903pt'>Host access control &#8211; Mechanisms(when
  appropriate) to:<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>&sect; Automatically identify terminal<br>
    &sect; Securely log on (i.e., encrypted login session)<br>
    &sect; Authenticate users<br>
    &sect; Manage passwords<br>
    &sect; Secure system utilities<br>
    &sect; Furnish user duress capability, such as &#8220;panic
  buttons&#8221;<br>
    &sect; Enable terminal, user, or connection timeouts<br>
    </td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>Application access control &#8211; Limits acce=
ss
  to applications based on user or application authorization levels.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>Access monitoring &#8211; Mechanisms to monitor
  system access and system use to detect unauthorized activities.</td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td colspan=3D7 height=3D21 class=3Dxl129 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.75pt;width:903pt'>Mobile computing &#8211; Policies and standar=
ds
  to address asset protection, secure access, and user responsibilities.</t=
d>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td colspan=3D7 height=3D46 class=3Dxl55 width=3D1204 style=3D'border-rig=
ht:1.0pt solid black;
  height:34.5pt;width:903pt'>Documents that May Be Requested:<font class=3D=
"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Security policy with access poli=
cy,
  user policy and network access controls, network architecture diagram
  (including placement of firewalls), application access control procedures,
  dataflow diagram<span style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D89 style=3D'mso-height-source:userset;height:66.75pt'>
  <td colspan=3D7 height=3D89 class=3Dxl150 width=3D1204 style=3D'height:66=
.75pt;
  width:903pt'>7.1 Business Requirements for Access Control High-Level
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Service Providers should have and adhere to a documented policy to
  ensure that only properly approved users are granted access to financial
  institution information systems and assets. Users should be granted acces=
s on
  a need-to-know basis, according to job responsibilities. The access-contr=
ol
  policy should employ methods designed to physically and logically restrict
  access to equipment, ensure the identification and authentication of
  individuals who access computing resources, and restrict an
  individual&#8217;s access to information once the individual has accessed=
 a
  system. Depending on the level of protection required (based on the asset
  classification), a combination of access-control techniques may need to be
  employed.</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl69 style=3D'height:15.0pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D417 style=3D'border-top:none;width:313pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl48 width=3D472 style=3D'border-top:none;width:354pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt'>7.1.1</td>
  <td class=3Dxl62 width=3D417 style=3D'border-left:none;width:313pt'>What =
is the
  access and control policy?</td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D472 style=3D'border-left:none;width:354pt'>&nbsp=
;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Is access to resources controlled by any combination of the foll=
owing: ">Is
  access to resources controlled by any combination of the following:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Method or
  location of accessing user</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Time of =
day</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Day of w=
eek</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Calendar=
 date</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Specific
  program used to access the resource?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  the authorization engine for the system fails, will the access control ru=
les
  default to &#8220;no access&#8221;?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  access rights specified by job type or on a &#8220;need-to-know&#8221; ba=
sis?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Please
  describe the process for granting access.</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Please
  list the person(s)/group(s) responsible for granting access.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>How is this authority documented=
, and
  from whom is it received?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.1.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  is the process used to verify the signature or identity of a person who is
  granted access, and of the person who authorizes access?<font class=3D"fo=
nt14"><span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  the Receiver Company review requests for access in some or all cases?</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  all developers granted the same access rights?</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D55 style=3D'mso-height-source:userset;height:41.25pt'>
  <td colspan=3D7 height=3D55 class=3Dxl104 width=3D1204 style=3D'height:41=
.25pt;
  width:903pt'>7.2 User Access Management High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>To protect=
 the
  confidentiality and privacy of data and information, user access capabili=
ties
  should be configured with least privilege.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>User access rights and privileges
  should be consistent with users&#8217; assigned job responsibilities for
  performing a particular function or transaction.</font></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl70 style=3D'height:60.0pt;border-top:none'>7.2.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  is the procedure for authorization and release of user information, such =
as
  access rights, including how often user IDs (infrastructure and applicati=
on)
  are reviewed for appropriate access?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.2.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  access-control reports and related monitoring reports provided to a Recei=
ver
  Company information owner to identify suspicious activity associated with=
 the
  account?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.2.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  special privileges allowing security account setup and administration lim=
ited
  to a segregated security user administration function?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  the security administrator receive feeds from the human resources system
  identifying terminated employees?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  are the procedures for managing the on-boarding and off-boarding of users=
 of
  token authentication</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  corporate property collected and are user rights and permissions turned o=
ff
  immediately?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  privileged users controlled and monitored by a formal approval process?</=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.2.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  users informed of the access rights that they have been provided?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.2.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  default user IDs renamed or disabled?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl70 style=3D'height:17.25pt;border-top:none'>7.2=
.10</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  any temporary/generic/guest/anonymous user IDs in use?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl70 style=3D'height:17.25pt;border-top:none'>7.2=
.10.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  so, how are they shared?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D7 height=3D50 class=3Dxl112 width=3D1204 style=3D'height:37=
.5pt;
  width:903pt'>7.3 User Responsibilities High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Users shou=
ld be
  aware of their responsibilities for maintaining effective access controls,
  particularly as they relate to password security and user equipment.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Service Providers should have a
  written authorized user accountability policy that incorporates
  authentication standards and clearly articulates user responsibilities.</=
font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Describe
  the Service Provider&#8217;s access control policies and procedures.</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  the guidelines provided to users for generating secure passwords?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are these guidelines communicated to the users?  ">Are these
  guidelines communicated to the users?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.3.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Do
  guidelines include simple instructions, such as &#8220;passwords must not=
 be
  shared,&#8221;<span style=3D'mso-spacerun:yes'>&nbsp; </span>&#8220;passw=
ords
  must not be written down and stored in obvious places,&#8221; etc.?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are password lists maintained?  ">Are password lists maintained?=
<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
.5.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  YES, how are they managed?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  the system require the user to change his or her initial password during
  first logon?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  is the minimum length of a password?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  the length configurable?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
10</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are all passwords set to expire after a certain period of time? =
 ">Are
  all passwords set to expire after a certain period of time?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
11</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  this interval configurable?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
12</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Can
  users change their own passwords at any time?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3