MIME-Version: 1.0
X-Document-Type: Workbook
Content-Type: multipart/related; boundary="----=_NextPart_01C5B3D5.8A1E1380"

This document is a Single File Web Page, also known as a Web Archive file.  If you are seeing this message, your browser or editor doesn't support Web Archive files.  Please download a browser that supports Web Archive, such as Microsoft Internet Explorer.

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta name=3D"Excel Workbook Frameset">
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link rel=3DFile-List
href=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/filelist.xml">
<link rel=3DEdit-Time-Data
href=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/editdata.mso">
<link rel=3DOLE-Object-Data
href=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAc=
cessControlSystemDevelopment_files/oledata.mso">
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>Audit Services </o:Author>
  <o:LastAuthor>a</o:LastAuthor>
  <o:LastPrinted>2004-01-20T18:45:29Z</o:LastPrinted>
  <o:Created>2003-12-03T22:23:52Z</o:Created>
  <o:LastSaved>2005-09-07T21:56:57Z</o:LastSaved>
  <o:Company>Wells Fargo Services Co.</o:Company>
  <o:Version>11.6360</o:Version>
 </o:DocumentProperties>
 <o:CustomDocumentProperties>
  <o:_AdHocReviewCycleID dt:dt=3D"float">1750939052</o:_AdHocReviewCycleID>
  <o:_EmailSubject dt:dt=3D"string">Expectations Matrix</o:_EmailSubject>
  <o:_AuthorEmail dt:dt=3D"string">MargaretPrior@fsround.org</o:_AuthorEmai=
l>
  <o:_AuthorEmailDisplayName dt:dt=3D"string">Margaret Prior</o:_AuthorEmai=
lDisplayName>
  <o:_PreviousAdHocReviewCycleID dt:dt=3D"float">-1554206420</o:_PreviousAd=
HocReviewCycleID>
  <o:_ReviewingToolsShownOnce dt:dt=3D"string"></o:_ReviewingToolsShownOnce>
 </o:CustomDocumentProperties>
 <o:OfficeDocumentSettings>
  <o:DownloadComponents/>
  <o:LocationOfComponents HRef=3D"file:///C:\IN-OFF2K3UM\"/>
 </o:OfficeDocumentSettings>
</xml><![endif]--><![if !supportTabStrip]>
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet001.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet002.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet003.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet004.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet005.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet006.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet007.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet008.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet009.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet010.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet011.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet012.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet013.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet014.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet015.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet016.htm">
<link id=3D"shLink" href=3D"2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files/sheet017.htm">

<link id=3D"shLink">

<script language=3D"JavaScript">
<!--
 var c_lTabs=3D17;

 var c_rgszSh=3Dnew Array(c_lTabs);
 c_rgszSh[0] =3D "Cover";
 c_rgszSh[1] =3D "Intro";
 c_rgszSh[2] =3D "Contributors";
 c_rgszSh[3] =3D "Security&nbsp;Policy";
 c_rgszSh[4] =3D "Security&nbsp;Policy&nbsp;(2)";
 c_rgszSh[5] =3D "Security&nbsp;Policy&nbsp;(3)";
 c_rgszSh[6] =3D "Security&nbsp;Policy&nbsp;(4)";
 c_rgszSh[7] =3D "Organizational&nbsp;Security";
 c_rgszSh[8] =3D "Asset&nbsp;Classification&nbsp;&amp;&nbsp;Control";
 c_rgszSh[9] =3D "Personnel&nbsp;Security";
 c_rgszSh[10] =3D "Physical&nbsp;&amp;&nbsp;Env&nbsp;Sec";
 c_rgszSh[11] =3D "Communication&nbsp;and&nbsp;Ops&nbsp;Mgmt";
 c_rgszSh[12] =3D "Access&nbsp;Control";
 c_rgszSh[13] =3D "SD&nbsp;and&nbsp;Maintenance";
 c_rgszSh[14] =3D "Business&nbsp;Continuity";
 c_rgszSh[15] =3D "Regulatory";
 c_rgszSh[16] =3D "Other";



 var c_rgszClr=3Dnew Array(8);
 c_rgszClr[0]=3D"window";
 c_rgszClr[1]=3D"buttonface";
 c_rgszClr[2]=3D"windowframe";
 c_rgszClr[3]=3D"windowtext";
 c_rgszClr[4]=3D"threedlightshadow";
 c_rgszClr[5]=3D"threedhighlight";
 c_rgszClr[6]=3D"threeddarkshadow";
 c_rgszClr[7]=3D"threedshadow";

 var g_iShCur;
 var g_rglTabX=3Dnew Array(c_lTabs);

function fnGetIEVer()
{
 var ua=3Dwindow.navigator.userAgent
 var msie=3Dua.indexOf("MSIE")
 if (msie>0 && window.navigator.platform=3D=3D"Win32")
  return parseInt(ua.substring(msie+5,ua.indexOf(".", msie)));
 else
  return 0;
}

function fnBuildFrameset()
{
 var szHTML=3D"<frameset rows=3D\"*,18\" border=3D0 width=3D0 frameborder=
=3Dno framespacing=3D0>"+
  "<frame src=3D\""+document.all.item("shLink")[0].href+"\" name=3D\"frShee=
t\" noresize>"+
  "<frameset cols=3D\"54,*\" border=3D0 width=3D0 frameborder=3Dno framespa=
cing=3D0>"+
  "<frame src=3D\"\" name=3D\"frScroll\" marginwidth=3D0 marginheight=3D0 s=
crolling=3Dno>"+
  "<frame src=3D\"\" name=3D\"frTabs\" marginwidth=3D0 marginheight=3D0 scr=
olling=3Dno>"+
  "</frameset></frameset><plaintext>";

 with (document) {
  open("text/html","replace");
  write(szHTML);
  close();
 }

 fnBuildTabStrip();
}

function fnBuildTabStrip()
{
 var szHTML=3D
  "<html><head><style>.clScroll {font:8pt Courier New;color:"+c_rgszClr[6]+=
";cursor:default;line-height:10pt;}"+
  ".clScroll2 {font:10pt Arial;color:"+c_rgszClr[6]+";cursor:default;line-h=
eight:11pt;}</style></head>"+
  "<body onclick=3D\"event.returnValue=3Dfalse;\" ondragstart=3D\"event.ret=
urnValue=3Dfalse;\" onselectstart=3D\"event.returnValue=3Dfalse;\" bgcolor=
=3D"+c_rgszClr[4]+" topmargin=3D0 leftmargin=3D0><table cellpadding=3D0 cel=
lspacing=3D0 width=3D100%>"+
  "<tr><td colspan=3D6 height=3D1 bgcolor=3D"+c_rgszClr[2]+"></td></tr>"+
  "<tr><td style=3D\"font:1pt\">&nbsp;<td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll\" onclick=3D\"parent.f=
nFastScrollTabs(0);\" onmouseover=3D\"parent.fnMouseOverScroll(0);\" onmous=
eout=3D\"parent.fnMouseOutScroll(0);\"><a>&#171;</a></td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll2\" onclick=3D\"parent.=
fnScrollTabs(0);\" ondblclick=3D\"parent.fnScrollTabs(0);\" onmouseover=3D\=
"parent.fnMouseOverScroll(1);\" onmouseout=3D\"parent.fnMouseOutScroll(1);\=
"><a>&lt</a></td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll2\" onclick=3D\"parent.=
fnScrollTabs(1);\" ondblclick=3D\"parent.fnScrollTabs(1);\" onmouseover=3D\=
"parent.fnMouseOverScroll(2);\" onmouseout=3D\"parent.fnMouseOutScroll(2);\=
"><a>&gt</a></td>"+
  "<td valign=3Dtop id=3DtdScroll class=3D\"clScroll\" onclick=3D\"parent.f=
nFastScrollTabs(1);\" onmouseover=3D\"parent.fnMouseOverScroll(3);\" onmous=
eout=3D\"parent.fnMouseOutScroll(3);\"><a>&#187;</a></td>"+
  "<td style=3D\"font:1pt\">&nbsp;<td></tr></table></body></html>";

 with (frames['frScroll'].document) {
  open("text/html","replace");
  write(szHTML);
  close();
 }

 szHTML =3D
  "<html><head>"+
  "<style>A:link,A:visited,A:active {text-decoration:none;"+"color:"+c_rgsz=
Clr[3]+";}"+
  ".clTab {cursor:hand;background:"+c_rgszClr[1]+";font:9pt Arial;padding-l=
eft:3px;padding-right:3px;text-align:center;}"+
  ".clBorder {background:"+c_rgszClr[2]+";font:1pt;}"+
  "</style></head><body onload=3D\"parent.fnInit();\" onselectstart=3D\"eve=
nt.returnValue=3Dfalse;\" ondragstart=3D\"event.returnValue=3Dfalse;\" bgco=
lor=3D"+c_rgszClr[4]+
  " topmargin=3D0 leftmargin=3D0><table id=3DtbTabs cellpadding=3D0 cellspa=
cing=3D0>";

 var iCellCount=3D(c_lTabs+1)*2;

 var i;
 for (i=3D0;i<iCellCount;i+=3D2)
  szHTML+=3D"<col width=3D1><col>";

 var iRow;
 for (iRow=3D0;iRow<6;iRow++) {

  szHTML+=3D"<tr>";

  if (iRow=3D=3D5)
   szHTML+=3D"<td colspan=3D"+iCellCount+"></td>";
  else {
   if (iRow=3D=3D0) {
    for(i=3D0;i<iCellCount;i++)
     szHTML+=3D"<td height=3D1 class=3D\"clBorder\"></td>";
   } else if (iRow=3D=3D1) {
    for(i=3D0;i<c_lTabs;i++) {
     szHTML+=3D"<td height=3D1 nowrap class=3D\"clBorder\">&nbsp;</td>";
     szHTML+=3D
      "<td id=3DtdTab height=3D1 nowrap class=3D\"clTab\" onmouseover=3D\"p=
arent.fnMouseOverTab("+i+");\" onmouseout=3D\"parent.fnMouseOutTab("+i+");\=
">"+
      "<a href=3D\""+document.all.item("shLink")[i].href+"\" target=3D\"frS=
heet\" id=3DaTab>&nbsp;"+c_rgszSh[i]+"&nbsp;</a></td>";
    }
    szHTML+=3D"<td id=3DtdTab height=3D1 nowrap class=3D\"clBorder\"><a id=
=3DaTab>&nbsp;</a></td><td width=3D100%></td>";
   } else if (iRow=3D=3D2) {
    for (i=3D0;i<c_lTabs;i++)
     szHTML+=3D"<td height=3D1></td><td height=3D1 class=3D\"clBorder\"></t=
d>";
    szHTML+=3D"<td height=3D1></td><td height=3D1></td>";
   } else if (iRow=3D=3D3) {
    for (i=3D0;i<iCellCount;i++)
     szHTML+=3D"<td height=3D1></td>";
   } else if (iRow=3D=3D4) {
    for (i=3D0;i<c_lTabs;i++)
     szHTML+=3D"<td height=3D1 width=3D1></td><td height=3D1></td>";
    szHTML+=3D"<td height=3D1 width=3D1></td><td></td>";
   }
  }
  szHTML+=3D"</tr>";
 }

 szHTML+=3D"</table></body></html>";
 with (frames['frTabs'].document) {
  open("text/html","replace");
  charset=3Ddocument.charset;
  write(szHTML);
  close();
 }
}

function fnInit()
{
 g_rglTabX[0]=3D0;
 var i;
 for (i=3D1;i<=3Dc_lTabs;i++)
  with (frames['frTabs'].document.all.tbTabs.rows[1].cells[fnTabToCol(i-1)])
   g_rglTabX[i]=3DoffsetLeft+offsetWidth-6;
}

function fnTabToCol(iTab)
{
 return 2*iTab+1;
}

function fnNextTab(fDir)
{
 var iNextTab=3D-1;
 var i;

 with (frames['frTabs'].document.body) {
  if (fDir=3D=3D0) {
   if (scrollLeft>0) {
    for (i=3D0;i<c_lTabs&&g_rglTabX[i]<scrollLeft;i++);
    if (i<c_lTabs)
     iNextTab=3Di-1;
   }
  } else {
   if (g_rglTabX[c_lTabs]+6>offsetWidth+scrollLeft) {
    for (i=3D0;i<c_lTabs&&g_rglTabX[i]<=3DscrollLeft;i++);
    if (i<c_lTabs)
     iNextTab=3Di;
   }
  }
 }
 return iNextTab;
}

function fnScrollTabs(fDir)
{
 var iNextTab=3DfnNextTab(fDir);

 if (iNextTab>=3D0) {
  frames['frTabs'].scroll(g_rglTabX[iNextTab],0);
  return true;
 } else
  return false;
}

function fnFastScrollTabs(fDir)
{
 if (c_lTabs>16)
  frames['frTabs'].scroll(g_rglTabX[fDir?c_lTabs-1:0],0);
 else
  if (fnScrollTabs(fDir)>0) window.setTimeout("fnFastScrollTabs("+fDir+");"=
,5);
}

function fnSetTabProps(iTab,fActive)
{
 var iCol=3DfnTabToCol(iTab);
 var i;

 if (iTab>=3D0) {
  with (frames['frTabs'].document.all) {
   with (tbTabs) {
    for (i=3D0;i<=3D4;i++) {
     with (rows[i]) {
      if (i=3D=3D0)
       cells[iCol].style.background=3Dc_rgszClr[fActive?0:2];
      else if (i>0 && i<4) {
       if (fActive) {
        cells[iCol-1].style.background=3Dc_rgszClr[2];
        cells[iCol].style.background=3Dc_rgszClr[0];
        cells[iCol+1].style.background=3Dc_rgszClr[2];
       } else {
        if (i=3D=3D1) {
         cells[iCol-1].style.background=3Dc_rgszClr[2];
         cells[iCol].style.background=3Dc_rgszClr[1];
         cells[iCol+1].style.background=3Dc_rgszClr[2];
        } else {
         cells[iCol-1].style.background=3Dc_rgszClr[4];
         cells[iCol].style.background=3Dc_rgszClr[(i=3D=3D2)?2:4];
         cells[iCol+1].style.background=3Dc_rgszClr[4];
        }
       }
      } else
       cells[iCol].style.background=3Dc_rgszClr[fActive?2:4];
     }
    }
   }
   with (aTab[iTab].style) {
    cursor=3D(fActive?"default":"hand");
    color=3Dc_rgszClr[3];
   }
  }
 }
}

function fnMouseOverScroll(iCtl)
{
 frames['frScroll'].document.all.tdScroll[iCtl].style.color=3Dc_rgszClr[7];
}

function fnMouseOutScroll(iCtl)
{
 frames['frScroll'].document.all.tdScroll[iCtl].style.color=3Dc_rgszClr[6];
}

function fnMouseOverTab(iTab)
{
 if (iTab!=3Dg_iShCur) {
  var iCol=3DfnTabToCol(iTab);
  with (frames['frTabs'].document.all) {
   tdTab[iTab].style.background=3Dc_rgszClr[5];
  }
 }
}

function fnMouseOutTab(iTab)
{
 if (iTab>=3D0) {
  var elFrom=3Dframes['frTabs'].event.srcElement;
  var elTo=3Dframes['frTabs'].event.toElement;

  if ((!elTo) ||
   (elFrom.tagName=3D=3DelTo.tagName) ||
   (elTo.tagName=3D=3D"A" && elTo.parentElement!=3DelFrom) ||
   (elFrom.tagName=3D=3D"A" && elFrom.parentElement!=3DelTo)) {

   if (iTab!=3Dg_iShCur) {
    with (frames['frTabs'].document.all) {
     tdTab[iTab].style.background=3Dc_rgszClr[1];
    }
   }
  }
 }
}

function fnSetActiveSheet(iSh)
{
 if (iSh!=3Dg_iShCur) {
  fnSetTabProps(g_iShCur,false);
  fnSetTabProps(iSh,true);
  g_iShCur=3DiSh;
 }
}

 window.g_iIEVer=3DfnGetIEVer();
 if (window.g_iIEVer>=3D4)
  fnBuildFrameset();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:ExcelWorkbook>
  <x:ExcelWorksheets>
   <x:ExcelWorksheet>
    <x:Name>Cover</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet001.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Intro</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet002.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Contributors</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet003.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Security Policy</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet004.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Security Policy (2)</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet005.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Security Policy (3)</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet006.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Security Policy (4)</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet007.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Organizational Security</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet008.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Asset Classification &amp; Control</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet009.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Personnel Security</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet010.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Physical &amp; Env Sec</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet011.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Communication and Ops Mgmt</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet012.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Access Control</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet013.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>SD and Maintenance</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet014.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Business Continuity</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet015.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Regulatory</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet016.htm"/>
   </x:ExcelWorksheet>
   <x:ExcelWorksheet>
    <x:Name>Other</x:Name>
    <x:WorksheetSource
     HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment_files/sheet017.htm"/>
   </x:ExcelWorksheet>
  </x:ExcelWorksheets>
  <x:Stylesheet
   HRef=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment_files/stylesheet.css"/>
  <x:WindowHeight>7665</x:WindowHeight>
  <x:WindowWidth>14895</x:WindowWidth>
  <x:WindowTopX>0</x:WindowTopX>
  <x:WindowTopY>1635</x:WindowTopY>
  <x:TabRatio>975</x:TabRatio>
  <x:ProtectStructure>False</x:ProtectStructure>
  <x:ProtectWindows>False</x:ProtectWindows>
 </x:ExcelWorkbook>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"2049"/>
</xml><![endif]-->
</head>

<frameset rows=3D"*,39" border=3D0 width=3D0 frameborder=3Dno framespacing=
=3D0>
 <frame src=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManag=
ementAccessControlSystemDevelopment_files/sheet001.htm" name=3D"frSheet">
 <frame src=3D"2-mht-SecurityPolicyAssetClassificationControlPersonnelManag=
ementAccessControlSystemDevelopment_files/tabstrip.htm" name=3D"frTabs" mar=
ginwidth=3D0 marginheight=3D0>
 <noframes>
  <body>
   <p>This page uses frames, but your browser doesn't support them.</p>
  </body>
 </noframes>
</frameset>
</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/stylesheet.css
Content-Transfer-Encoding: quoted-printable
Content-Type: text/css; charset="us-ascii"

tr
	{mso-height-source:auto;}
col
	{mso-width-source:auto;}
br
	{mso-data-placement:same-cell;}
.style0
	{mso-number-format:General;
	text-align:general;
	vertical-align:bottom;
	white-space:nowrap;
	mso-rotate:0;
	mso-background-source:auto;
	mso-pattern:auto;
	color:windowtext;
	font-size:10.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Arial;
	mso-generic-font-family:auto;
	mso-font-charset:0;
	border:none;
	mso-protection:locked visible;
	mso-style-name:Normal;
	mso-style-id:0;}
.font6
	{color:windowtext;
	font-size:12.0pt;
	font-weight:700;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font8
	{color:windowtext;
	font-size:11.0pt;
	font-weight:700;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font9
	{color:windowtext;
	font-size:11.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font10
	{color:windowtext;
	font-size:8.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Times;
	mso-generic-font-family:auto;
	mso-font-charset:0;}
.font12
	{color:windowtext;
	font-size:7.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:"Times New Roman", serif;
	mso-font-charset:0;}
.font13
	{color:windowtext;
	font-size:11.0pt;
	font-weight:400;
	font-style:italic;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font14
	{color:red;
	font-size:11.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font23
	{color:black;
	font-size:11.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font25
	{color:black;
	font-size:11.0pt;
	font-weight:400;
	font-style:italic;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font28
	{color:black;
	font-size:12.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.font30
	{color:red;
	font-size:11.0pt;
	font-weight:700;
	font-style:normal;
	text-decoration:none;
	font-family:Garamond, serif;
	mso-font-charset:0;}
td
	{mso-style-parent:style0;
	padding:0px;
	mso-ignore:padding;
	color:windowtext;
	font-size:10.0pt;
	font-weight:400;
	font-style:normal;
	text-decoration:none;
	font-family:Arial;
	mso-generic-font-family:auto;
	mso-font-charset:0;
	mso-number-format:General;
	text-align:general;
	vertical-align:bottom;
	border:none;
	mso-background-source:auto;
	mso-pattern:auto;
	mso-protection:locked visible;
	white-space:nowrap;
	mso-rotate:0;}
.xl24
	{mso-style-parent:style0;
	text-align:center;}
.xl25
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;}
.xl26
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;}
.xl27
	{mso-style-parent:style0;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;}
.xl28
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl29
	{mso-style-parent:style0;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl30
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	white-space:normal;}
.xl31
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;}
.xl32
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;}
.xl33
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	white-space:normal;}
.xl34
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;}
.xl35
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;
	padding-left:48px;
	mso-char-indent-count:4;}
.xl36
	{mso-style-parent:style0;
	mso-number-format:Fixed;
	text-align:left;}
.xl37
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	white-space:normal;}
.xl38
	{mso-style-parent:style0;
	white-space:normal;}
.xl39
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl40
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl41
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl42
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	white-space:normal;}
.xl43
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl44
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	white-space:normal;}
.xl45
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:.5pt solid windowtext;
	border-bottom:none;
	border-left:none;
	white-space:normal;}
.xl46
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;}
.xl47
	{mso-style-parent:style0;
	text-align:center;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl48
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl49
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl50
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl51
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	white-space:normal;}
.xl52
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	white-space:normal;}
.xl53
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl54
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl55
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl56
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl57
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl58
	{mso-style-parent:style0;
	text-align:left;}
.xl59
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:48px;
	mso-char-indent-count:4;}
.xl60
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:24px;
	mso-char-indent-count:2;}
.xl61
	{mso-style-parent:style0;
	border:.5pt solid windowtext;}
.xl62
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl63
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl64
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl65
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl66
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl67
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl68
	{mso-style-parent:style0;
	color:red;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl69
	{mso-style-parent:style0;
	text-align:left;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl70
	{mso-style-parent:style0;
	text-align:left;
	border:.5pt solid windowtext;}
.xl71
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl72
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl73
	{mso-style-parent:style0;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl74
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl75
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl76
	{mso-style-parent:style0;
	font-family:"Times New Roman", serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl77
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	border:.5pt solid windowtext;}
.xl78
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:48px;
	mso-char-indent-count:4;}
.xl79
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	white-space:normal;
	padding-left:96px;
	mso-char-indent-count:8;}
.xl80
	{mso-style-parent:style0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl81
	{mso-style-parent:style0;
	font-family:Arial, sans-serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl82
	{mso-style-parent:style0;
	mso-number-format:Fixed;
	text-align:left;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFCC99;
	mso-pattern:auto none;}
.xl83
	{mso-style-parent:style0;
	mso-number-format:Fixed;
	text-align:left;
	border:.5pt solid windowtext;}
.xl84
	{mso-style-parent:style0;
	font-family:Arial, sans-serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;}
.xl85
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl86
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl87
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl88
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl89
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl90
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;}
.xl91
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;
	padding-left:36px;
	mso-char-indent-count:3;}
.xl92
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	padding-left:36px;
	mso-char-indent-count:3;}
.xl93
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	white-space:normal;
	padding-left:36px;
	mso-char-indent-count:3;}
.xl94
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	white-space:normal;}
.xl95
	{mso-style-parent:style0;
	color:black;
	font-size:12.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	white-space:normal;}
.xl96
	{mso-style-parent:style0;
	color:black;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl97
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl98
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Symbol, serif;
	mso-font-charset:2;
	text-align:left;
	white-space:normal;}
.xl99
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	white-space:normal;}
.xl100
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	text-align:left;
	white-space:normal;}
.xl101
	{mso-style-parent:style0;
	color:black;
	font-size:14.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl102
	{mso-style-parent:style0;
	color:black;
	font-size:14.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl103
	{mso-style-parent:style0;
	text-align:left;
	border:.5pt solid windowtext;
	white-space:normal;}
.xl104
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl105
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl106
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl107
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl108
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl109
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl110
	{mso-style-parent:style0;
	color:black;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;}
.xl111
	{mso-style-parent:style0;
	color:black;
	font-size:13.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	mso-number-format:"mmm\\-yy";
	text-align:center;}
.xl112
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl113
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:center;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFCC99;
	mso-pattern:auto none;
	white-space:normal;}
.xl114
	{mso-style-parent:style0;
	font-size:14.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	mso-number-format:Fixed;
	text-align:left;}
.xl115
	{mso-style-parent:style0;
	font-size:14.0pt;
	font-weight:700;
	mso-number-format:Fixed;
	text-align:left;}
.xl116
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl117
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl118
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl119
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl120
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl121
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl122
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl123
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl124
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl125
	{mso-style-parent:style0;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	white-space:normal;}
.xl126
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl127
	{mso-style-parent:style0;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;}
.xl128
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl129
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl130
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl131
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl132
	{mso-style-parent:style0;
	font-size:11.0pt;
	text-decoration:underline;
	text-underline-style:single;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl133
	{mso-style-parent:style0;
	font-size:11.0pt;
	text-decoration:underline;
	text-underline-style:single;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl134
	{mso-style-parent:style0;
	font-size:11.0pt;
	text-decoration:underline;
	text-underline-style:single;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl135
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl136
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl137
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl138
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl139
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl140
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl141
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl142
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl143
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl144
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl145
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl146
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:12px;
	mso-char-indent-count:1;}
.xl147
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;
	padding-left:24px;
	mso-char-indent-count:2;}
.xl148
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl149
	{mso-style-parent:style0;
	font-size:12.0pt;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border:.5pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl150
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl151
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl152
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl153
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl154
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl155
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl156
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl157
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl158
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:none;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl159
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl160
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:none;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl161
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl162
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl163
	{mso-style-parent:style0;
	font-family:Symbol, serif;
	mso-font-charset:2;
	vertical-align:top;
	border-top:none;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl164
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:1.0pt solid windowtext;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl165
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:none;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl166
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	border-top:1.0pt solid windowtext;
	border-right:1.0pt solid windowtext;
	border-bottom:1.0pt solid windowtext;
	border-left:none;
	background:#FFFF99;
	mso-pattern:auto none;
	white-space:normal;}
.xl167
	{mso-style-parent:style0;
	font-size:11.0pt;
	font-weight:700;
	font-family:Garamond, serif;
	mso-font-charset:0;
	text-align:left;
	vertical-align:top;
	background:silver;
	mso-pattern:auto none;
	white-space:normal;}
.xl168
	{mso-style-parent:style0;
	mso-number-format:Fixed;
	text-align:left;
	border:.5pt solid windowtext;
	background:yellow;
	mso-pattern:auto none;}
.xl169
	{mso-style-parent:style0;
	font-size:24.0pt;
	font-family:Arial, sans-serif;
	mso-font-charset:0;}

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/tabstrip.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html>
<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\tabstrip.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<script language=3D"JavaScript">
<!--
if (window.name!=3D"frTabs")
 window.location.replace(document.all.item("Main-File").href);
//-->
</script>
<style>
<!--
A {
    text-decoration:none;
    color:#000000;
    font-size:9pt;
}
-->
</style>
</head>
<body topmargin=3D0 leftmargin=3D0 bgcolor=3D"#808080">
<table border=3D0 cellspacing=3D1>
 <tr>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet001.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Cover</font>=
</a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet002.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Intro</font>=
</a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet003.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Contributors=
</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet004.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Security Pol=
icy</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet005.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Security Pol=
icy (2)</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet006.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Security Pol=
icy (3)</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet007.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Security Pol=
icy (4)</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet008.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Organization=
al Security</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet009.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Asset Classi=
fication & Control</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet010.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Personnel Se=
curity</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet011.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Physical & E=
nv Sec</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet012.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Communicatio=
n and Ops Mgmt</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet013.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Access Contr=
ol</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet014.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">SD and Maint=
enance</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet015.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Business Con=
tinuity</font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet016.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Regulatory</=
font></a>&nbsp;</small></small></b></td>
 <td bgcolor=3D"#FFFFFF" nowrap><b><small><small>&nbsp;<a href=3D"sheet017.=
htm" target=3D"frSheet"><font face=3D"Arial" color=3D"#000000">Other</font>=
</a>&nbsp;</small></small></b></td>

 </tr>
</table>
</body>
</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet001.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<link rel=3DOLE-Object-Data href=3Doledata.mso>
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
x\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]--><![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet001.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(0);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:DefaultRowHeight>645</x:DefaultRowHeight>
  <x:Unsynced/>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Zoom>50</x:Zoom>
  <x:Selected/>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1"/>
 </o:shapelayout></xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1789 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1342pt'>
 <col width=3D637 style=3D'mso-width-source:userset;mso-width-alt:23296;wid=
th:478pt'>
 <col width=3D64 span=3D18 style=3D'width:48pt'>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl169 colspan=3D14 width=3D1469 style=3D'height:3=
2.25pt;
  mso-ignore:colspan;width:1102pt'>1SecurityPolicyAssetClassificationContro=
lPersonnelManagementAccessControlSystemDevelopment.xls</td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl169 colspan=3D19 style=3D'height:32.25pt;mso-ig=
nore:colspan'
  x:str=3D"C:\_Acc306\CISA\(ISACA&reg;)InformationSystemsAuditControlAssoci=
ation\1ManagementPlanningOrganizationOfIS(11%)\XLS ">C:\_Acc306\CISA\(ISACA=
&reg;)InformationSystemsAuditControlAssociation\1ManagementPlanningOrganiza=
tionOfIS(11%)\XLS<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 style=3D'height:32.25pt' align=3Dleft valign=3Dtop><!--[i=
f gte vml 1]><v:group
   id=3D"_x0000_s1025" style=3D'position:absolute;margin-left:151.5pt;margi=
n-top:1.5pt;
   width:162pt;height:283.5pt;z-index:1' coordorigin=3D"5616,3456" coordsiz=
e=3D"2448,1728">
   <v:rect id=3D"_x0000_s1026" style=3D'position:absolute;left:5616;top:345=
6;
    width:2448;height:1728' stroked=3D"f"/>
   <v:shapetype id=3D"_x0000_t75" coordsize=3D"21600,21600" o:spt=3D"75"
    o:preferrelative=3D"t" path=3D"m@4@5l@4@11@9@11@9@5xe" filled=3D"f" str=
oked=3D"f">
    <v:stroke joinstyle=3D"miter"/>
    <v:formulas>
     <v:f eqn=3D"if lineDrawn pixelLineWidth 0"/>
     <v:f eqn=3D"sum @0 1 0"/>
     <v:f eqn=3D"sum 0 0 @1"/>
     <v:f eqn=3D"prod @2 1 2"/>
     <v:f eqn=3D"prod @3 21600 pixelWidth"/>
     <v:f eqn=3D"prod @3 21600 pixelHeight"/>
     <v:f eqn=3D"sum @0 0 1"/>
     <v:f eqn=3D"prod @6 1 2"/>
     <v:f eqn=3D"prod @7 21600 pixelWidth"/>
     <v:f eqn=3D"sum @8 21600 0"/>
     <v:f eqn=3D"prod @7 21600 pixelHeight"/>
     <v:f eqn=3D"sum @10 21600 0"/>
    </v:formulas>
    <v:path o:extrusionok=3D"f" gradientshapeok=3D"t" o:connecttype=3D"rect=
"/>
    <o:lock v:ext=3D"edit" aspectratio=3D"t"/>
   </v:shapetype><v:shape id=3D"_x0000_s1027" type=3D"#_x0000_t75" style=3D=
'position:absolute;
    left:5760;top:3600;width:2160;height:1440;visibility:visible;
    mso-wrap-edited:f'>
    <v:imagedata src=3D"image001.emz" o:title=3D""/>
    <x:ClientData ObjectType=3D"Pict">
     <x:CF>Pict</x:CF>
    </x:ClientData>
   </v:shape></v:group><![if gte mso 9]><o:OLEObject Type=3D"Embed"
   ProgID=3D"Word.Picture.8" ShapeID=3D"_x0000_s1027" DrawAspect=3D"Content"
   ObjectID=3D"MBD001965B6">
  </o:OLEObject>
 <![endif]><![endif]--><![if !vml]><span style=3D'mso-ignore:vglayout;posit=
ion:
  absolute;z-index:1;margin-left:202px;margin-top:2px;width:216px;height:37=
8px'><img
  width=3D216 height=3D378 src=3Dimage002.gif v:shapes=3D"_x0000_s1025 _x00=
00_s1026 _x0000_s1027"></span><![endif]><span
  style=3D'mso-ignore:vglayout2'>
  <table cellpadding=3D0 cellspacing=3D0>
   <tr>
    <td height=3D43 class=3Dxl169 width=3D637 style=3D'height:32.25pt;width=
:478pt'></td>
   </tr>
  </table>
  </span></td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D344 style=3D'height:258.0pt;mso-xlrowspan:8'>
  <td height=3D344 colspan=3D19 style=3D'height:258.0pt;mso-ignore:colspan'=
></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl101 style=3D'height:32.25pt'>BITS IT Service Pr=
ovider</td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl101 style=3D'height:32.25pt'>Expectations Matri=
x</td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl101 style=3D'height:32.25pt'></td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl111 style=3D'height:32.25pt' x:str=3D"'January =
2004">January
  2004</td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl101 style=3D'height:32.25pt'></td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl101 style=3D'height:32.25pt'></td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl101 style=3D'height:32.25pt'></td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl110 style=3D'height:32.25pt' x:str=3D"BITS ">BI=
TS<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl110 style=3D'height:32.25pt'>1001 Pennsylvania =
Avenue NW,
  Suite 500 South</td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl110 style=3D'height:32.25pt'>Washington, DC 200=
04</td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl102 style=3D'height:32.25pt'>(<font class=3D"fo=
nt28">202)
  289-4322<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>www.bitsinfo=
.org</font></td>
  <td colspan=3D18 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D430 style=3D'height:322.5pt;mso-xlrowspan:10'>
  <td height=3D430 colspan=3D19 style=3D'height:322.5pt;mso-ignore:colspan'=
></td>
 </tr>
 <tr class=3Dxl24 height=3D473 style=3D'mso-height-source:userset;height:35=
4.75pt;
  mso-xlrowspan:11'>
  <td height=3D473 colspan=3D19 class=3Dxl24 style=3D'height:354.75pt;mso-i=
gnore:colspan'></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D637 style=3D'width:478pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/image001.emz
Content-Transfer-Encoding: base64
Content-Type: image/x-emz

H4sIAAAAAAACC+y8CTRV3xv4vV0zx1TSMUTiixDHLJKxWyKZZb43mTJPlaHMV+USSZRkrAwhVDIP
NzdpokwZK5EQKakUvddUKvX79l3vWv/3/66ete45+5xn7+fs/Tl7ePbeBzIAgDP4JidIP+tl16+Y
AKikA2D9tl1oAMiAKCsZIF2SQj8IBelHDsAGkqL7B1WTMwXAmJMDkgEgSvqtJ/1I5kTIVMgAFynM
PGePuaZrziZm8TcX10EWAAvZhbgbVCgAtGiPm5RuKcy/LMyrQv01jKig5u1SzF8FKdOoAMoaGQCu
ynx71o8yd++Yrs52BjqOuSIyaO7Q0AeAxpRkpYaMVDbAuT5RYs6mveouVQAKj8YnTl4kXVPpahtu
I52/fPly4XFKDylE677D1AuALnYAylFk57ZhFedKramhanjo3KvkXSfzKk6f17QPe5Sn4Fpm1MLc
7X3HX1iGQi5XT8/9maxr8cWbUfsNHxmk2gUR1nGpXklOrTZ5+FD8Oe5uce/RccVSVTMzP+DIG+Zw
XvRCVWlnKOcxbBBMdfT/lcMQGzK92rkiBdPPhuDGrhyLx8ISUNO0R3eUfw3ME7FLFCI4fPTpjkqq
kbeKe3mrJjE6pR8i34VAGWlKY0QljOit0LAqUmgXpmKdbPPVWz03aPEEncu7EmJzPhpedimlxF/z
5bp6ZV8NzJmGMOLIymjxU6nhGy0Z6tMdQza1bMJsyTDxjCbuk7lIxbrDazW8/VPbPhnjfSwKcq4o
vlwpGifalGn9UMqMtIwK/5ohJitBGzpit/x+RzlGX4+TMFWW8oHkAGOZ5qEbokNvWPH1u88PH/U8
5VjIdPp8rjw0fjNVKhPrnFOVezdMIkACf76hua2OxsJGLoTFxctYUsuEIePN8/W7PiICkpbH0hEq
ychASQk8B+yjusHxpQhmy/HK9WKHKUOrLosahaM0ZJR4qjjQTX406Gj1QlToGz+ZRrrmd2uEB7uY
G59bTTN7R2WjRjZE98qqWbncwnpjqesEK0foa3ZYbzzBAXvhorwj4/Up0IlX/b3ZqRj41k0bWgrK
2pTtntaHM3a+dU8KgfGT8V1tTUPNqHX5XBEsG/uEHytIS8CJV8ilsnP4pS962HmPtiL8Dod3oj1N
S15XkhNeNCvdsX33+ERBMEtpkP2l3kNsCpqbYD49J8XPDpF6HRcizs2qwaEjHzBFSqOZbFDWoe0u
l53VeAOFLn5Rg61K3Tm2jmZC5Ptqg8Yy+UraZDgqb3PvDz5RR9O3Lf9I3q5w7gNm9FQWPXtesuzM
KzW/EyQRwI4/1pG3bn/Pq9d8wOaesIxoluPRAT34qY00c/m7+L7Ork2w7kj03dGxhkcOnsobNM38
TF5nosf3MsVxFtC3vnPuuWq4oeT+4fsSNPuhM9dOhuWn8uPvlaeaiOjZe21QeAzjbBsktPwY1u3c
pqEz1XGd+DpfGr9xFXR/X3aOx+UQMkvrbZlkyAZNtfKHyGka/LEDZ7YWyeJV13Z/lF0tFh5Pydex
6wL2Msslvy8f3DhO1AS1ZTLEc7Ja7EvjjyDVs/KG5Lcs8JVLFc1IK62VjVaHMxV+64GHMeGNoSOU
Nh8isUHE9Xi8gVLW2hr3HpkD5Nvd5FHk03G6tapnqARp+CT7xMmJzCNFL+F9ChQ2Oz6xPqTHhL2n
YOzdmTzwGMHvro/CBbOMSlbRoXm2AIjcm4YoZZkRI4nRsIqVp+CzGFQxjMOmrj69brV8V7a265fu
xqYEAs3jHkb1mtcBNESuxwm6VPjXTkbbMXefWtzhhe20kaGDOxJqEzdERCNnmAiG2YcCXtzBhinc
kJjeWs8Cq5ftJLOtgbuazvMh0zvWIxJQhg0yef9Zbb54BEuZu037pGu72DVAXNXFbpSCk7iWpkSN
EbXyUb2p60GGt+/MDfLEcJWGM12r8pqsedfra4BSb9+oe+BqhwhGu1nLT7vmKLVxRqdpZ4ldTWI1
igi7jM4IekCEN3FiN+if9xr5rf4ygKD8cVm5kS90aaGe5FNTeZuR6C3CNLU7zt2MwCSaT+ygPSWN
v+L09MKFYazGmGm8+TtE+0JDZbN+NSsaQ3njn6cvn5zv34bgMs2vSmLCEjJyIyQE72MLXtjCp1O8
ay3Xl+hyihBMGPGYjHNk/QcR+6vZ1hZ7tiGTY3VVMtRoXXYEdXaVXMcIL1zmtqniWDUNMUZhfwRm
qOoa0nSDBp0S0qz4TjRk4rMVctawXxaZo0N1rfxu7gjmZrF2BAY/0cNrSW6za3qzouwdjCEVR3vN
6zoa4XDbYohoYZLrhNHWhHO9DO9gRPsgdE6aPZzqhTlV399eAz9yZdyOGVLJEOXmEQuWyLzD6WIR
jrRIiEWWudLbkGrGBzQy7U2B8IRI5Mxsc7Uk57Ogz6uv6mWnymJDmz9rc8FuYarNirwlHhwbTVRu
NY+y5sWXZY1UIThlCuK51QxRJOPB1enMk6tgg+i4qU4CRG5IkyHGTcqBFga/uf7xSHxC3dDAbPqh
z1VIGylNzBpoXYhE5ioNqR4m3DtZckINTzhy0Y2cTzxURi6fA33MXg6H3fVILDzN4Gowxan8oKf3
5Gj2bE+Y9YbvsMB3DgYXPvf5IjKLgVP3w/+8K5OAtEhPpLOZEUP0DWaEjAhC7HM8J8q9ldnQ+3v5
LujDRiV5a2uFrO4HY4OOiOKfrkHQ8el3JXBk0ZVcaGs9DsKVN02UB9MgmQxFiPwmomJSI7SrOhsm
WjzlIABLYGMLowuC9aRafFjw+VeFcGTT2Yi+m2LcXng9jkwYN6cgw08myYUtjlBZ3OjajreUCDGh
pik0Fer/GIU5FegWuqhSNV1bA1uR22BgYwmI/DgW1r0rF9TcHgDFYPecGQopx5DGHA6jk5/V5q2J
BTUjEB+ObP5Zfiz447QcEPmkHzx79tnm+XvfDtNpiB0Oa78XjjmGVRHAkZ2xIrOxgzXOuq8ymS/V
8oM3A97k7gMMbDinLYiQkPj6jPlD5/bU45HLzaemQBkim47Pj781q6/NZW5oA0z5MnxpUBYkfJi+
NgPjTO73YO9ChNuTanDJkXivB5PvnGikoJb3wRPvRB4qb8dh5x+fien2u5dc+tqdljR078bpbdlw
F1F5F3ms2y+NUCpNyOdhyNgkSnraESF8OBbeZFTfSnB4S/+xFJkeJ8+Y5J7dThCq3IyFU/1gynyS
hRHslm3RdelHZPH5l7OmfW7R05VBaHNjVgKQgJgJoJUgJPRcEg4fmHGGwycOSeAHSAPze65w9bpW
xHX2n76qD0eVArfg87OEcFjbdHpGMz1N11nLD1Vb7jwI5410jjyeg9PTLxjBnHqXV0+qp5QZzhoZ
HGjzsceUSCOKYb46oM9cysraC9uE26+tG9p5fPol0nkyPQdLsZq5DKB3XTJhzPhihRyfNsaR5YTr
tdhb0mQ0PNCHnXbxrq3Zo78mzZA+Y2iyfBXaPCabDd28rike2XlcNLwwYDXs11323M8OTjWDt7WW
rULf7tHcCMWnbxLqN4MpS48I4y/dbx18sTE8LeTMqur8cD1mCsM6IU7pUhS6oDj+eRr9GOolO5XD
hyNIZ8iWuS5qRjeAd2sBLpZnVXzdkBZ9hzclZGlXGywSrmeU64R93ndjdg/sNxMSgibVVjrs5QtT
By0hvvKR3DCWjnVNaxDt6wFu9NispLZVJfkRzXaDG8P01gRZodSZfNbcMKfOeN0Tnot9PrgPTlWD
MzrM5R9P0sF23oJ9fWpwkZnLMXO5oNjHT0iAqhkgqbK4cfd1eMmS/OA0+p5T7Q1r6o6O75r2YcdX
VJBaM1WGGKikIjrUNpTpNGIaZi4UGPUBdNttCyqbnNxH/yBPrsu8B8a1DpEVZTRUvdkujQ36VDaX
J4YFEMlGEi1JWN3Zfk9CzZWxlrOXP32QhB/buViiCNG3ks6djsYGHcc0KNY+a2UdJ+M7DEViROON
yqjQ4w93DIqHSLw47xZNypPWva0ypOZKQ2R9nDDQpoXFi+EzgzfARfq2W5XGyfl89rPWMpc3VicH
MEAvdFwMOB/oodSnLtc7JVlTEBhUH90qpCDqDzx6KwxPfTgUTUvqJoL1us5YUBDoVePaNWkhvUtv
3Op6adDdaFr8kT6D3iNWlBniSjJ0mAaBjE3eL33ZIUvnsWw9YJPvNXexoeloSgcJC7DpPmh4NcWk
1n27aqiMgXBQrADnw23IUearx677fkTapqctKEKPl6VfOrAVv9n3NKUPCyTZdPTM7QgJ/loqnzWQ
Zf4F96xaROUx4u00eXiD7t5Dgu6pF4qwMKF+qyVVKCS9IUKKE11wMN5ayKQ2lTzKndITm9rj9qab
n9UhTD3KAibn8Dp40XsNXqWPo0IHphJajTtcdzjSUTtpGkRhPMueiO2/1nTpDoaiLE43I5aa4HKa
vofUFFMVaestTZEtSX1P1kRaTuaZrVa45oVhDrgTQFJmUTJYCELkp3ASzznpXyrAmW93ZXkx1O4Y
mqUnp4ki+/LyaMUq4oyJsYeU4gaX1robn/Zr69eOhU1mshF72l/q033cbUVKbkjfP5a7VfhdGp33
vr1lTzJ3bilnRg+NhUGMOVhdoloZM/oK2tBdl6F/kMdVl+6AYIuPFSmcQvZwWH32oKFZGQanRxGK
sD2MR4gxX8LE3yF0FqT2eEWR16ypIjb/PHJghMmKM/5qamlGf9W9EM52EWwYZ9TpHTvXdvtu7Hmb
t56qkpXYRPFckYCoUD5KtODQOHlKmTSMHFXVEqiPvl4o25WihaUw11XWF/bryyxxHmgf1YefsrUU
m7ydSjc80ue3Cf+Zs/1sQsCFN5/aSA1RjmO+oza6c1fjEXMZG/qIilWJjkmaV3sdTYRlctwVVxfl
tOsdSU4YivLV7ZiBZ1m2RuUweious5Ey/qAtNcdaQsORz6Q+Nf7O2/HGKrdKDrTD1izz4M4TlaON
PoP74doIvE5R5+6IbatLy7iITU2eosaB/oU3y0nuWkhTm44xZEPXRTfsCZ8xCCe5ATDVeQ+XiyLt
BNgRvp9nJgE5q3qRR42QXDsTRaP5K7dnBREsHJ9Gzml41x4QbsFoD6At5YJYbpgW7zpNUCk+c74b
oJ/Y5V1bJQHpboZGdeqyRXsAej3NtXXCEcF4QrbDdrEw1feCB9bqMpKTJ8o+iFWsSf0UJydIa+me
YCtT7FkSpNqXskdTGAMRDe1afOjhyezmxxuHQvI0rsNUDp8vIg037hSZkpGLVd099JkbaTBvZ1tt
WBOkIyzFXU0LyV946VWOQvumeqyGb9fPCmNS7+2RzCivWW/GMNJN6i444MMGQ32WGN122rH8YAkO
A5fTTCXBquc41o3mB+t9tuzoqlmvE8U41VYTpMInPlzGBMlnHyOYkpOjosapCDz9qgkw1agSDZ84
dzUTFFhDz2TPAN00H6x9h1SQiW85J4MgTQ1vnqCRCoN+BELgXS8uVJNBB2vo1ZuE4X453NNwjuTH
Pqzo06ElIWT3pfDFWJUt5wee5GFupFHtyQshi9JNMpglXZETqt2ZSEBe9B0MezopyOxjVBsktSnX
733IUwvB7ViV95MMWPldQhqWUL8GbHpwv1woti+FC9cc6ATrBIZ0vQwp13YyPRE7RkWo0lGorGTE
5fe8D8O+F0zutaImbxpkPSIHp5m8gok8TOSf7eFLdUGvt57XHTqAXN6R0Zr0RRtuc0/wyGGkiokS
ZC3jgSp0dMJi+5/OYJ64VNCmsxOxMHPdwKFDyjAcep6G79KR96Gq1TIG1BnuKv04BI1TNQ2/UbgK
XbB6UHvnDV4ILz0pi6tFLnO233fOoB/rvnud6MZEaHmiAW8OTT0YplofFY/cfdQ2Thd6nPPLHrjJ
YctdAVL34noMG0PrhbvlRmvjvKVg1gImihGCxjS2U8cjqTaNQu9PI9oZtUhqMwYWrAuK+Sejw7+u
6WlwNCPJWZwe3cqCxkW+D0sbf+YTsYeWHEcuaVGxEX8e+8FVAi9IuCItTNivvglyEbKPfr0LOzSm
4fIhDjskpjd/crKcyQ/Hog92eqcdDG9WxLFTEa7M6ONOEBqynlhitaOfmsE3U033HAxP0y55856H
QZ2SI+/zzHaCbjBaJFAKvxqT6FHtBqlvs8z7/NGeAMO4Zky5DxeaSBHVVQc/CMZSqVZL4Y/NLWX0
yRI6rnYYkUpQs/48NsLHHN6NIxtmx7EQQDIDn01Z32Es9KIGPkKBb85BETDwTohcet59MyMZ1USI
PGRz/ipEXr/o7M24mn5JpR/TN4apGlLieNqisBBEmHfaHPbNxbuJbBl5Q00yFO3zMYODeBc5mtnH
SaxD8Ee24u+6DbuSnL/5JRbmOW+K5FIloxbszztykwaYSYgwZAHLnWO989W7PPVOSWojyYudz/Ri
yiaq/tfO1ddSQ37yRUmHQEa8rOX6+Wi5WOmX/GaceEIuP7KQknTIoxSTnDv3rCM2k7xMquE2pCzg
LcmNFcPjUexzLugYY0Z84JcJZFoK2z3hnzdvdbPciZ3zASV4K9Qf3RceuBn/MaLGAabKtIVjprRh
doMyK6aM1HP3rkwnYRFoh78A/pynG2QTycwY2JaI1dV0o+V70bmGRMAL+/zQIS9YwVChQtooOkIO
V/g5AP4onk3KcClykjalJCJNPEd5HYme88iL2oaNEwPImxdb7w8ZyeAn7GvgB2GxRqLzxbuDfS64
rnlMDzZ9NTX/Jg7kGSjnYKESXPOggNIatPE7VyjDfo7v1dogHpLL1nj8MsY4uyAi1lLXiw4/e6sG
SXtISs0oOef2PmcMMeuvhfq14dveSUcU8DJrOy+2ExrWDZuJXlJD9ClFYNNt8+AqudFj5Tu6drjm
BrbWMVsHNmxBzZN5Hy5hZsdU1zDyQDyoeeACl06wxBcuWOClKuxyIFYcF3vm+hc+zPPNdideIXgp
jPY/sz1r0TY+R3nhjTar0AlGzymRNztJ9S5Wxu0SN/HGpcaAGn8yfIWDux2Mjnu1miBPhtsRv9nZ
nXSPIP3Y+ERtA9f+CoDuTe5MpOZ7OjUthXGO9hl8IQGfiSf1zwkvYavdtzBXfe9bkvGJeBCQy2GC
NXtcmfguCX1i0YfR6Y9OIWVbXozREY4RnbANYWfm4l3KSHoQLNHDjdbZMkSRqgofo3Ft1Mz0ocRz
9Y1SU0L9EGxz/9rcdfc/xQofDtOgx0SPltcNJe/jhWnND7PgZ+lg9uweP+M6ZsdO7RdiwbEH7vt1
+RowoxPExLrKtTCZdzxxoexEWqSNC7OngRJ5yND5/GJOaOHzqyLzlzOzQ9dFVeHmk9Xk+KsHK52K
GXE7EmbMumWQsnP7jNPX47P6bAaNsulJLrnwR1KrosNoOCmcMnrFAWfXHSBEp3jXbkY6LV7kB8cO
61w/3+o6FYKkX5yWnLuxv8+/4LQqrGewQTNhhGRw1eGRYUVDygwEyCA7t3aMfZpsuHcy/shEgTcO
+1FzLZfSbTqb/GLM1VLTIrHG28rnsfCJsOSQs5YUfNzUUbMsTISjrEp2p2zXetLiP2RrfViNY9l8
G4cvbhJ7vgpuRtv8E32JwWY/fgN1lfjbV5JwISTlsYUdNyA4qwZjb2n5t93B3DS7FnwFxrGMmdNH
HMgPZfHyeP/yqSvBmg0vtu/S6ONnb9Xgp1wiRuE0+O0NTYlbqCvVGGsSJXMGd7yg+SSvN6ZB8lbu
V92VcR9rRerab6sUzk8uj9fQXIspsj/8vOwABz79ms0znfznvTR45rai2y6nvf5JGZg6nBPEsl9V
sIhOFt8cMpHKEHVMCnnWTXJVKkZvJ0vALnd1NSvFwppP0t40emZ5VQIOFqloKn6hChMvccDe69Cd
3ARQj2laa9HMmVc+ac9Bqu7RvoWMJ9xRbiasaE6PaNGw08F6D4entxrVpkqGW1VexUKyUNFk1QfY
mi5UYX863ewa1nDV+lVvhDfSpkTXIltba18zJW2R+CwgxBjqUERUu3WeUqp+B3tKEZNKxSpJB34O
MhxZEXaSEfpyldGcbmQvPHuoTSy9VavGQT1/YPraSxh6vVFOazIm2pPPw1UQc2MgISDSgN71C/c/
H7ekeBYfujZEY2+WI/Sh0M/Y4sjwTaGz5u40VNOnkm4VoEc+qT3Xqr1Cdv952ym0TV5ACNV0i+0g
bw7vG7FBOR9XKSiG0ibt8hahW8eHvWiIauWr1hhFDameLsLc3Sf7yFmjECeje90zfrNWnT4jProh
gUxdj6t/D2F4F/GNatPtt3x5EFtwV75Kbf2e4gCR6ogI9ZjDsbYtqRfemCLEzKizwqab9PR0nqbq
jfkamZPjsPFrhOQvFm3lHSdz1an3ZFIro/JWj0YazsfrmxgmkxVf32ZqmSJJn59HVkfjI5DfOH3r
nYrVQd2nsQkbTUNr3uGQaW3YRc+H6+Y2355E+dW2RVRMCjw1qSEeO8N7+nlPZsSV5+zYzXsRIqdA
cNrwCfXWjWovtwX7tmu6MEBQ+0hM49maWrmYlNL3Uvbvho9xaAicPxpYXN5adCT+aoy/J37fGD6U
pUBF3lsE12zXxv+srR6p+7gTu0VSZJXXiBlsKc9DAGvqDu1r4xtui0fSbdfWCvFcLefEy54tEK/O
ni39YX3l/9rDScTTJONLrJ/94rAtBrUJ/P+iYD8dUnfCIwVcj3ZxNqzrGHNwPLs9X10vatdbtt4u
6RzJVURRLcv3X3anVJ8+8Gnki1LKF/PRjyMvAnE1e2c//yP1Snb2xECw2KBypl58eWvgbO+U99WE
FOmBNDPDXupRg8D7KY8vzRQErlE+H+ibs2kD2eWr+ZFtpy8+SE6W3P9QLue1ZjsBCc9xeancYt1l
NsUUp9XuxDKlYLlJvrFYomXPGdFXbGbSF53vflD/PGwowVR9Y+aSd28hf/uzQHvYvjbxJILGjoeG
SNjVJmofsQxnq5xpCE2TPMiP/4eHeFn2FWWiwiQH8ZHnBIOssqwuDw4f3ByahuAnZh7tg3B35Zyq
/Uvz2s01no5/uhh95WrrNXMueFil0bo4/0NW3tSgE1OK8t2+SB1F1fe8dHBLM+dlDvKdQjWtlwqN
BnjyhJ1bAxMfohnMZpptPPzJIjslNyPEB6uoqIlFPC16s2bXJFyeP2okzyHHUB0m1hzj1RfffyeM
fxPsldVuXhISweTtpm+UeLN29sJhw/yK3Bni0IaT2X40WsW4wuQLGdo9I8OBo46G11p4ci9WPSms
L4safs27wdFks4yc7hd7m1oV7VTbYuRIqv9uo3CfO5kS+VQ4VzS+2dQQozsWaXk4N+Bj9xYp6GPx
W+wOaiU4hZa7sZQxh/zF9VKKK6bxPUen2kPI3llfVkr11ZLOPrWhNTX3dTSUjuDkXl7wtuaSsHXs
mRKTxvdevzJzIRrNTHz2sWizsGcUNWb0Ug5psJu4xLn5iMJ681h2xaqDXYcn/A2vda7LxEKNwjVN
9sLG1JgP9tmOLvYM5G52RZjRtLscQYUpoaEKju/+SY1+v/e4wT8FspCtZtMB7CQZnPGGC3u5w+cM
DxVu+PQOOLc1mAI7unlUxN114sVQre4mspqmGRyDuukq5MgdS1m8HmlYLdu6Zx0nznPnx5y34u8Q
KhSuSrk7UG23SOXLgWpA6JLbg2jQ30MOJAObQtTO1XTX98cN7zOhw62zN82j3VHzIXLgPIONLMLt
6XXp8yP0dkvV0t01uurCfNcZGfGmvijEm38v17UIS+3R3uFdw+5fjM9sgtkaAeQxcwvboC8NDWyo
aZJhtz2zCnf8rQ1iyBjWfHsa3m5AcvSqjc4aYC6zQT0s91hgBWYuWw72otwkgYr1nphRK1Nk8Isd
ISZbBnrV89ZNmMHQd5rnIzJ7z/NB+ET+8Tgx4QIGaPWTrFhZahycHWPMTiymwUk7ExzSFHJMmxHv
1fnka6mJ5J7UmKOrijCiEnCnoKkA4VBbzR7DdRA+UBc3gW4NmUgxDKVBWqoykFPPlVIp+1/W6opx
wJGyGdxgBxwYX33FmxqXHxo80ddqFIHMslseNjkciUtTPLjuBiZe2Uv5bsEGeGo3uXpHIgMU//iq
FSOUTfbqIvbzbqNMBvKc1/ljzjJQg9gXH8zVwXZaxJA149YoA/6lBczUavJkR9/eWvgOBtJig5wU
adVvlZ5s1KgdarkeIToDQ45M2D0sA58yqWrj6Qe5LZX2FmMuCxJ0B14qBpDbtCDGHyPICRxJtjBG
hkGd4fNjZP3Hcg5bA6SNKOx+sB03EdlrM3CFKyfiaacSRYbBPb59n1wIurspIKgg5MbA+5dIZvnw
FDnmQzEUXQvTwrupcVfSMaK08AMuuHLAWwYaz8aTk7+3r9HNyMU8v8dBcdhEvdgX2dqvoeFLB+lF
pvkLU5vZKlES/B4m4NLGTtU2lJNnrA3nhF89Yqn70BCKTX7iAfeTwUzpO3CxlOoMpmYImh4X0J2D
ubsRPvRPBNb7gwg1zq91vAcGYA373LcAwzaYjgdOBx4jaNGt9LgdNviAXmZswrt87cHaPW8we25p
917cejllkCLOw24rpJTkeJOCEYqnwmYNsmAC5JF9LfG0/SYCkPRJSvUoCbaaK9zvOpFJ6S30OHyZ
KLz63M3xYY/cEOw9K+Yi7PpGZmgvWyh1RqtjiZKfPIE0920vRWriuWDJpiDqrjxydVkRX2TQAjam
YQ6XiMAeaqPER+jQrsHC4ci+SOZg3qR4ki/Bhn+c8nHfxZON2OoInfKZa0NaG2jVGVydETODHVT4
x+ETvurS6of7UopMb4dKPBbiQ2qOBzWbKjNAei84YCfyXQaM0ObXdAi3GNQ8KQKrcxH56IkP9zAo
kdnIksuhiOJxJfXrTjvDu8+lORASzeMJuMIvx2uZg4nZiLFTnRyD+gxrhNMU9i4ZPBhCOJOwmUTA
FhPQu27vzZl8bn8OuLNK7JG8TKeQOiIqNxCGvz+9ufbyo4OTVRRoJhM+Ak1dk/o2Nsg3CSAKa4n6
qIw7oRJ7DE7KRbRcRtUTKQwVoVeHuYiumgnKw47tNP0M+/trmO/ZcFHZKVNTlW0UJDgVf9rU+eSK
ZIQiHeGsQtU9uM1HBuFIpJuLlhEs4W3c9CVfoHSgdsjllCoc19P0CUHUOk6E52PJ8JQXz5BD5/Rc
CMx6a2sOlSEaLfHU/e+lmIjOcpPc0LnIUpPQMCyd/v0uxDjLhw3ycKKuPcZkc6KMFXqmRJb1xlwA
L/hBvTZxPb7n1oz2JzNgU3w55YkkXg3OZSK/5VRSPZVUWnHn+T00O47M1Q85y+S0xy4Cq5AUImvj
dPZUmjbctdvgkwtzfXChHOkl93ph91T2DgY/CruaeDW0MNm7/fj40TNX+obN2kmdV+9I53hJIyN+
ZmdjSKEd4Ypf5aZQ7tdrkNe1s8bpL/1PqiY4OmHzo1Z7Uz6DmjfII9rNn4AqL/7g3hO5a/yVBFHv
MFcPDbNppO4+5LJRBLVGLyG40FpPDF9yl1MmVpGaiur5WFRn12r1IiU1MxFsYkkZTBo1unO4ZPFK
FK22myhIp3shhc8JsHbueF0T3xu1C8jdQ1RV9onUNtUbfTCJVrOW8PBOTAWL/5Z7YpDL9cCSF0rO
ofIj1J+d48Ol8UYlW32RqUiVBCUD5LrIRnriOSab8B2PgycmwkxuUeAvrCJKgVDuqbhgNBfxwD/J
DDaReU1K/t7duIngyDX8WFirvHw8R150E5ShCvu37y97cPjWAdoXtU1ypWPc1jYQ1VZ8DyrhTFBs
wFF+C/GQwu2WHMTeF9qM+E3D+shd3aDT2W/OO9wNfVoBOxJUnitCBg7s0IywJEEoojA81QM2L/ZU
wD/GpQmMfkTOuwudZ0eMG/Zbrb7jS/eF9Wk+rpB6yt1LFCttyY0fc0zD1+5xhtFdu3NPMeBkz+Ce
ygvy7tM+HLB121s4YuJueGGfi20dUjDFglwuPP6qokXAY6fa3sFob0uze6R3WkCFfs+PCbDSpKNq
TmutRUpC+fHWxmpeu83pbIRCC3e5tqCnVFkT73wU23TdFPET3MZKZA7GWqJSZkYxR9bUwew4PV58
nq92zQdI1ZqecDZdWtrS7Uitc/VNCPvST/CyHeGQA191PRs18cW9cyGF0lbB8QhRCJIfTkHuZllv
xGdDxOsXI2U3TJ3pfyO27tCdYN6L7TV6eTiskfd+7qDBSCx0bzuK+OJ2BobZZP8mqFNpFc5ne19O
WC8NP5mNWJiE7HjjUS4ND2zA9NSJh+Ew/gINkTU0WD0vJY2BgNCyU/EH8OKzfb0widSCHERlobWf
7e7UxAj1VSpdn1Vn0yoTTOGqSe58+FmJ1mYSZywK73Vp0Idfd2+kyJAL9abClSldDmcZ2YW+sdn0
bHUoKz8+cM2XDqTs1ZcLCOZ4KpfTJAb/2ls/5dz+K3omvo1hvL1kUXU1n2qvfRTnh+LQlQpHUPhL
1AR+X5MBu9oYIR/X0u2bbNLvrMm2hANjlev5dvVL4dcpexAzNPvrOjYZ1SEjXPcZoXcVe12Pxhkw
ODiNEwF+wlGEHre5wRGmp+3nXeVTFK3jKElNQI7XfbAV1EMwHFP78un0tCnxShnU6jJtz2IFLGbJ
YIEoenX8y/FrBsVOxVhIDJoRKzT10PxkEx3BcUQSMXPUaU/nwL1DnZV5xNX+QNfR7iXp1XCykhPq
kcmdrvubzZlwfi7jx26pMyqf8e9WzSSD3+T4d54kRPlBhqzpjAVh2Er5t4iyO9mGeLSSYQLSxofY
8eC61euauhRiiRFpAQnIEyqLD1XjPBkIUnFVbZfF2Z0u7UjmBaa3gW60d1kh+Y664dFa+K6tkwCh
Qdpu1ZkGGQHsKLsFXExJTgfVNcWeKbsggNGGCJ+VeXDC4gzkdTY+lLnvLj9Eus0VWc5FNYrQqieP
oKiqTilQYYaid+1aW3LleBJ5q6QjPBV1MVgii274dfla88li1FzSeltagq7jP/uYiOVGZd6713FQ
ErhUnVxonGi1z6B3P4g9TYGXMzBeh9c5veG9A/xaaNs6pkAlXV8gA/l+rL3K6fj0nnCPaYSqfKib
vw4ZnONmec/iQk/o04SOMnOfF/YdiPalCz3sXHCZis8kdjDTFSvAoL5OndZGtvQ9fzG1TUmOdXgM
I8ObEuTEne06Q8qMD0Za2xVfVn1QP9e3d6aDlxPnVZ6dm8FjLiqwz6HVen+t7hqH+wIeL1wdREd2
fuo65JdnbvrP4UNJcqK2chgCMrhPJDfl6e0m3c/WXMoDcoRD04i7WJTRzgI3397WKh2/3Ny3utwl
nSE0NZOtaZVJlvCbKdcrt0Sex1BYBPvnmB7U9wzrDUuWqqtZG2YrkmuuKmHraYwcMb13TLhr7Kx3
dTbvJisfDiPPXJosZcOui7mX25OSvclz5JwPXPbFPwxnku+OTFxF17f/EM24zzEpDvhpU6PB7viS
o5ovhEUfd4cNasw4VW7rDCoo2tLam3ut5J1QypmRi5zmlCaHiZjWuKRWQ2MZJivtWBcOJuIRVu/X
j3L3JQ/0AUsheI+ov/8971tSHaevB95j0M0Yhj7eE1RiO1T41HLcyeisC6Hjw0jw2IUK9pOVfrnY
mNLt8ealOLkndOhcxct6giNXA82phnQwzzI26tgeGQouq71+NUo78bwYNW7yUWZL60tnWKrF4SZ7
NDdedYCx7sr+fRj4S6fgffv6YycY8ZT0sLNWnWfuWwloFdXNtwweZyA2aKaZJyjYayiMXuGs49E7
/Iw2sgdCka0MIwKyNOrgUGg1GXHvbJg836aDoo0JMmnM61uzC3uF0mxRx/85dyCcb9gx0+rNrpEv
F+O2vI7os2RrTOlg1ptU98GysQWjYGXrlRbf/w8fvLXg5oTP1bolERPta08n0Wco3/isHmu8hz7U
jI0w3dZ6jDSt14ajqg+0rN0vI1J0mRUauXNMsFHUfq15pO31tYW1o1GmqY0T/k3gtozPRYEbjFFW
FSJXHt4dZX+ko3/7k26rnymuWDq+m9uM79It0V7Gd9tZIP916829ULjZJ1eu6WUGUpwbVetdjZxN
zb60Z+eJKUUy9cC+DVComYkgJfnpe1JnQ6aEH+BVCFc2NZQ0ZUrX9CrmsRUXcXrcf9m5ypgFrbVm
53mxWgMXRqR1AMHbw8SqVQOwg/TUAB/1w1SrpMNvDiaFC/lXN75ldODv6V57qttYwJoe43yrOEnz
BnmP9O1rqvfevLHzcfSYzBbdS9kczn9hbf/ZmdyHiUk05XUuRc3nr1t+2nvGiwzfo/omJiptTfXN
ky2V1DZ9vXG24p7xxsdPWSXGBmFP77mAOXrh2docx64EsjVU2dc9LxQMHn6r3Zr0QTc7JuipWPBG
ppvwDY5a/4Jz1o1rAi9ZwYcFGKsthM6V6QgUXhm+znMabqWr6TBBBB/06VKVGo6oEVJNUuNSSt9W
X5vUrmkSIW7H6G4by22mh2/czNKHiHE4lj0fdtfsYccJBYjwARuByFgn4bjMJzapszo9Z/WQ5/vr
pJ7O6KjUJJrnaJc96prJcL0+jLm8r1hkhNMh6VQJP9TaGoZl7rMw6NvVO/Ugr0SOxqa6WKBKMyVk
IhNLoVMUMRkcVEjEDLnRirLAGlBRwRYz2tCyRANkdhe7rk9iKDJZ9kx648Cmx6JZD/5hWZto6l3u
c5CBmFbfRRsZoNiJZebpYiQkZiB+6TsVQlLFtxvJ0qrnXeIMVg3LD5Sql8SX16xHiczIWJa56NvG
IS36s6SnHEoMmbDejUsz3n4Ao6t3cZaVycNHELtlSnkvcpR7tC9KnRU/Edis7qmID3eX/MDe4gkT
WOC9bhBVawlHxBiVOhN+tclBFFF5sPb1nQA1gwHHD5eEoPRntHBnEEPo8IUkP/gLv5cGVvfVqXEh
h8SXTzXnV60SahDrG5MjrBETDyS3s1K12nyKDhELK0RBXwb5GfutOT6fS87zg6sT6LFXpwtg6L1/
8IN1OIQnXDVcsyojtW/fe99Up1aqk8iTuGYNDeaI5uwTifWYptCqgxGq4dtp4TezAVEEmi0tQ1n3
Uvys2XFt4cgTr4QBhCgeosoYcp6J8LYm5OmrXTUxl4xYqTaHsAUX9pJTsXD/g2lgGfTCBlAMsmjC
TIEPHBGcDXKTeocNYuy3Q4ou9KbgLSnu2fPy+Or95OyItmOhUFgY7y3X3eESghhmf5gqaxVufC2J
8QsKiP1SMn2GTP+u0zczUI171uFr5Vp5SFO2M4+wMZv3Yx1eWMBb35Bs97cJ4WtuWDMTJ4/Wrt99
tiC4uczfgJTNYFXuI2Shoz4jGOaLgMoj8EwIL1WYTrjE1tHx85y7S/SHzthDBNLjUnI309iIDFvA
lhRUybmMVCwdPKG8ak3F2Jjam4yhrmYZSBvAx7sDZQ1rRvXJJA9YnR2fFlqRNRvFVXxEACNKBkvJ
bJtghjwu+Yvh7WnQDn4+FETy6jpXQuLRuNH1eKUwZU6qygKmu8zRtVcubpPCr8fH0vQx1nWQXzPA
TqZJPN/6gUNtDf68UP96/OHzr7KRI7ewp8L7eWGmMsuQ1Sde89LabOUkyppGnz9ctEsxvSDOE2aY
EXiIhccFCR+O1qZai9AQHCbSXiYQOqw3HWLBK3GJH6mQl4AMiPTY0XHTc7Q2vbnaPVl32Otu5r+h
kW7S5AkrrN7nJQtN1x7jIt8UrtqbtGXoY/x2rLP4JCkyXZW2YEqSbqH+x6jOnToyinQ29NL3K5yS
Q5pJNLj08krDBbkpuSIKk0vEw1Tvu9vPfQjxvBxNSu7WTkquXZM6eKe1Zr0gq6q6vpdbUfU6z62Q
ME1W+ISJC8DGuNm+o+l/OnYvuDkTw6qkwVGCyi7h4Yf2V3XfweoWz5RdOlp2P0zCeWuMevKLuvWf
hjKQ63YfDeEuu2dkpSGq9zSzzqSoTjW/ZvNeh09zfBDQVuYWXedQqQSRvz1HaaMCn6cfnI29UUeB
L/y4o0boLPFUiGpUiNEum/ReNXL4ZpcQO3JxcEYbHt/7gtDnJQkNn6Zlw2aFTrA78AvciNc+bGFN
QziI0YCr3BzhFNXWkjDVyvDTtDZRtR8S3mKOpsGe1wUJoJICVxqbZlUY48+HTA+O2yCNvcKH1kHD
vFOs4Wnb+bLtVOvgs9WfopGspLjbkwEtARsrhTVgYsfnF/L47bgMv7dW4p6HPnvDLeGpJbE2eY7w
6s37aN02+Mz2ctakWlc8xG78uENt8GhN4oMwCQmoYUoSngTpnWi/VBP3t5a6SJs8NK2pyowTiuDy
jUW4q+LqJjYbEvkZ5BEapskgqo+yhqTq23OckGpfH0iJ30hSzWLhT4wTJxSZpKlCA25vZ4fNA/tM
amCNzS/qmprTriVzqLR0PUOOHt5vTuocqt3ZwnidTxJ0eU5bxoRJhDXC8SltB/bmVBxrvp2dNYw2
UXAc98+SZoHTZDAoxA8bx8G9tmsDn24gfTzvRgnScONYc3jTnffa1Qd3VnWkiqUHu1vWwjYIatyz
nfD6vRDcm5EsDw0Pauz2SxdAD6s+O0/Sr0+5lXghmzvsMQJ9ZPI4TQff5ItfD1UeP2djKBalKa3t
16VyzXtYxurNKj8hen6oMOGI+no4MWdKAeLbcv9J666P6w8eQrImOEujDn1Rs9ZoGT7MQbW5Gb1Z
rZo6Bvd0fI3PMajskP8zpOGah1Gq6vkHbzZyXcvPcDR0hPOucO/pS6gKaKOBnirqnQ57ekL5tiQb
bgJfe4gm9AivZydVT/ptNtv0ztXsm9BYCrRKKNJ7ufv0Adhw9yY3oj0KHaloASvpHb2rVj3LJxgS
+0qzwFlPfV9RNYOPQPA6LVb09vctbwJ4lMSfxww+r4uJSKGjff5h7ePiHNOsfVdSsR9ct7TuTQvm
/NBUpkGF2x7YY7/ToAdv8aBrnGF7uR0HuoBRuRWOjIzdmhIxuAmJdlRgGd7A8dx0nYNkg1dLmGFY
yt6OsDLHWCdo+pbvlQJRSpv4R5lZ76K2xXDDJT1o+cDmkbdnUsNhKvP6XF7v+FreB2smxodKJruu
Wil0vEp2W5XK9CGajrAek3V1X1+ZtZkhuBywfp313S3SgY7Cbz2Soq+WNRV3oM9gJyMN2XisLtZm
Fxv3j6qQmg95q0y4nZBTnIa/ZFLO9O5EtoHtNfsxwp/WOyl+8B94v7nhpaw09CpUQVEJ5qu/HsGV
GdoycS/06Vo7yfaa9RWj5LbhWO+iL3zWA2ccn6sZYF7YC2VYc8zmlnv1vHgVQRu5uax38CmvsSrP
kaeC1/ZF2z/xEiqKeD+9vzR1OsdptITiedY2ni1h2clqX853BDJJQLpZJz7w1f9/zUf9dmj5EvjU
FYVes6t/+9wfZGlu09HIV8OEkII0KmQ0/KQzvOxvxch/+PstThWgIk06Cy3+LRdquTKGchsAiRpL
aWLmjxjAO2eb9NtL+kGL6fRIv0Pdv/6buCVZT4pcQzrrzj2TgpRm7o/NOhZ14O78MzCL+VmKSzb/
tBX+8GxRvnz5AmZnZwEejwfOzs6gsrIStLa2Anp6evDy5UtAJBIBHR0dePv2LXj37h2YmJgAnz59
AvLy8kBGRgYMDAyA27dvAxiGgZ2dHRgcHAQ5OTkgKCgIaGlpAQ4ODkBLSwtYWVmBtrY2cHd3B3Fx
ceDGjRtgaGgIXLp0CYSHh4Nz586BvLw8UFdXB9ra2sD4+Di4cOECSEhIAP7+/oCCggI4OjqCkJAQ
sH37dkBGRgauXr0K4uPjgYKCAkChUEBYWBh4e3uDoqIicOLECWBpaQkUFRUBBEFgzZo1QF9fH4yO
joLg4GDAy8sLLCwsQEBAAJCSkgIzMzOgt7cX+Pj4gC1btoCIiAjQ2dkJqKioABMTE9i/fz9QU1MD
QkJCgJ2dHdja2oLMzEzAyMgIVq9eDTIyMoCEhAT48OEDYGZmBmg0Gnh6eoLy8nKAxWKBmZkZiI6O
Bvz8/EBdXR00NDSAW7duARoaGnD37l1w7NgxwMfHBwQFBQELCwu4f/8+6OvrA6qqqkBXVxcUFhaC
jx8/gidPngBlZWXw5s0bMDY2Bqanp8GpU6eAg4MDEBMTAz09PcDY2BiIiooCDw8PsGrVKiAtLQ1q
amrA2rVrwc2bN4GmpiYoKCgAu3btAlu3bgUdHR3g+vXrQFxcHNy5cwdQU1OD/Px8UF1dDS5evAga
GxvB+vXrQXNzM/jnn38AFxcXuHfvHpiamgJNTU0gKSkJPHv2DAwPD4Nt27aBQ4cOAVlZWXDgwAHg
5eUFduzYAVpaWkB7ezsgEAjA1dUVBAYGgg0bNoDa2lqQmpoKrKysgImJCZicnARKSkpARUUFaGho
gPT0dIAgCPj8+TPYvHkzICcnB4aGhqCrqwskJycDNzc3QElJCfbt2wf27t0LdHR0QFVVFTA3NwdZ
WVng+PHj4MiRI8DU1BQ4OTkBBgYG8Pz5c3D+/HkQExMDHj9+DJ4+fQpevHgB2NjYgI2NDSgpKQHc
3NyAk5MTZGdnAyMjI3Dw4EFQUVEBrK2tgZ6eHigtLQWvX78GR48eBZs2bQJhYWGgvr4evHr1CuTm
5oL+/n6AwWBAd3c32LhxI5CUlATv378HcnJyYPfu3WDdunXA3t4eXL58GYyMjIAHDx6AtLQ0UFxc
DAwMDEBiYiLw9fUFIiIigIeHB+BwOODi4gIOHz4M/Pz8wJkzZ0BoaCi4cuUKKCsrAwICAuD06dNg
586dICoqCuzZswfExsaClJQU8OjRI3D27Fnw8OFDcPLkSRAZGQmuXbs212b+yl/5K3/lr/yVv/JX
/spf+bU4M3isdJvkUzv/JtUFBgboX9j+vxXKbXMtrUE2UsDI5iVz6M962QOR2tpiqlW/SM5CoV/E
HjnqsoLK+p6W1j3ThbD90M/60UwtMe1yeZWOk62/MJ59QEvrvTzLT/fr7mldzXAjBYTktbQyeH7Q
vmjUqtdWKRYO/9lgu3mx1pw0aj9R/0ElNDiv0bLSPvO9IpaDQ4N0yq0HYgw/GYwpFk9xR6HobaSv
r1iCdluRO7Eon7JhjRWUUBdX90KoNWd0BX0gEPkUg1L3v3dw4heAmpiAxUr3u+8PLgQQYPvzk3mB
iK56+6RvygoJR0HfF9IkkRxL89ObHgbFJI11qd4PdcF219xRF+z6+UWpy4PFFy/h+3mljFKAkfmz
zf6VtB02iwEvsBIfGhC8ELDJu/0LQMLgxIr3eWxzF/Uff1ZWgai5kwU4+rOOHyxQW/fmJ5WYeNP8
ufiHzPTM8WFkl1qhcX0BnYtdkvNLv5V6Fb0Gt4WqcpNhBXXKzMKZCH7BZ7EWqG/2PbUyH3IwveJ9
aLhg/syEc/9ZeQqcn6/b4MDPunAgN3/eUf2TSj5vMYrnCnwswJGfjcUcBJNL4USw9+cIDmCp3rw/
tkIpXrct1NwG8Wu/5YPiATJ/xgdlZjB3NKJmQq3EZ9vcSQl4/6zrX+Szgizx+VHm+ChF5tX+rMEA
8LV1PwAqK3TBQHgxNN78Sz7QWXDe//d8GKTYGf6MD9u1uePdFbku8mH5f5HPNvBkBQ036MldCj8T
t12Jz8bF0MDoL/mwAkeP/8EHZQn++TM+3bc2cHNzXwLhv+azAVz9D3xqfuazc0MxwBJW6j+Wt2Cs
/u/4pP2Sz0fx1XGo/8VnEET8GR/Uvc2nT5/WVGT8JZ83viIaf87nmeTPfG7y80uozazIx+vbUJv3
3/hMG2OPo/4nH4o/5kMrhkIVrNTm5/gonz79TjNsAPVnfEB879nVnSu2L9Rju58rFqoZ7F42aP4n
Pm4vQTbqf/OJ/2M+KLVW0qBCXJkPbHp7XepR1B/ykdJob2/ZvDIf1AG6uJ80Tsva1zgI+y98ioGK
+r/g4wuS/5TPHiHU/SIG1C/bVzM2FvUf+p/6X/DRAj97BDR5kUZL4WKg9R/4sAHD+SJc/z2fJDBM
/6d8Qu4z7HRE/ZqPIAj6L3zW/5LP1M9JhgBmafi6KRXyOz43VuTDZ0e94HZX/57PPbAJ9ad8UDmh
YPY3fDxA53/hg/oFn8vg8AqzT/2lDvoTMEH9js/HFfnYLU1Pfs+nn2P4pwnuueRlfBJXyreoFWj5
DZ9asHkF3dH/yact6Yf77LvmpwCWKw2Vd3ELLrA19b72FdROoHQxNLXSBEwUeC8a3b7S7OTxAh/1
L4qr+39SEh42feXDorZSea6DgO6VW94cH/WOFUnwr9RMFuTSAp9gt++n72bixhbcT6gfUq2YKDms
ggVVe3pn8AruNeO5LNCFmZug0R9P5RT6cRVIYEwTWC84c3ydmjVuP8G9CPpSuLkrujRFWVZ4Mrtt
Ijf3ZiDDzT267+1KWXOTylgxy9VW4K3cSDw4FPPzfJHfG3S+WXEtqru6UryZm7vMEfs9dEJo+pwc
9/gFVaPAsYvBa9+spIbmUwrODf5zgR+byJf09LbFZjqn/qkjCWmZT/80/MKKD+54nf5V4BVzd3jl
WT8+cC5JoMMKqmfz1pRWSrVm6Vk3/i9ZuFv/d0H3r/yVv/JX/spf+St/5f+AqDPMyTf3dP5yYVHD
jRRaWnXwWdhGoV/ca85lWNLFLEt+avkUzTkJSb9t7b78KXNmGecCc5Myo7kAtGRrQX7OXoz1c4Pp
pTVw+q8RF2YORl9zob7D+uv0CLPMHXeej537rbR1aenphxe3Bpc9eHHG4SxwLN36+2noBXNFUHng
2+bo1Wgg/i5tPnhIB0ifXkgZs7hLWboP7J+bMxdkagLL+c2/Y2qgIWNh5cOD69sejwdb5HAF94Ze
rNf8Pm6MGTvI2z+3EexgroArn9u7mrgMwOXncxOcq6kAUF/WdtXXXPPTasTO4bVyWSaLE4JZNQAU
/LS1D0rNb16gHlwCwHYtKdBaDg6kLaXhWrbfTBskBYwzlzzx3NCehny5mUy6rPlSnfKyBYCuS1v7
7eLqyqmo1RTcGQk7vs+DBfhu9SANfF10GtDz+DoRX6S6Pm9xzfuWwuJTBaXsFyN5gq98oEZQOJ8H
Hmr+hTumIH9Rd1J/4X0mg9TF12YPfOdeKaPVpx/5FL6d2zboaFzcLI/JA+fmzrJLS71dYL4unAW9
X+uIh913u4IwSP9aeQ4Blfm6Zb9z8UFUwG5u2q3+aH6/FcW2eg7N1rcXfpjxy343XwWNS8HPS2v5
pWCJD+qIxMKsP2/LUizcYnU9kfeNTwZY2uRPX1wAqvu61H9Kc2HJbC14tBQdwPOnved/5BM/v0RK
CVYtzenZF871i7tBJmCupR0DCU1fk6QDTqNlFu4B06XgdlC+9OJLFgNF7xbO6PkyPNKd70oA7x/y
sa4Up1viw1uyuK739ZOCxW2xKlugsMTnLnj4tQNZ3ILv/rYVcmRs/qS9UBfm+XQsrJf8tEJXuEAe
tC3xiV+kvfgxgIkeKV8XVhfRfksyCNAT3/FZWloKkbr1bKmObVjiY75wPj6/vS06362tB3f+jA9D
DrivtsSnLmy+UeSDr/tlOQunO8DRaolP5req8XV55RufY9rz7VLPDvUDn1+J7PwWyHI+S2KiQzpM
gsxla5Li7Ka7v+PjsxjSAhU/WV7is1w+r8jH6NwKfMTmm+0oCLrwlQ/q0ty7ctP/tpm6wIcNsLd+
5XMTxP2GD6TMML/0mPgv+UCXQNp3fJS+4yM4XLRsqWcEDDE+vLASn07wYGU+6t+vzt371mMt45PM
vQIflYWSKzehvvHhfqmlpXUWpHzPJ8Su8jpqiU+s+E7G3/BB1TuSTFh+7VT+Bx+WTLDPbTkfetZv
fHxzc4eWp85FAwHUq+wV+MTgROhX5lO1Z/l4vg34xv3Ap5Cf/9jmX/HZweEbjlrGJ86uOj09C1B+
x8d5/kOPJT7+4CXqd3we+M39WY2Cx7/ig1QCjq8jNnuYgIDAyW/txATsfwfEHy9vHKTs0MIr8GkC
2J+NF5mQ7A2t/XbDYTOQ0kX9wEd7w4bRXb/gQ28I5jZWv/FBaZMGwWjOmO/4mIG5peAlPmyA6bd8
3A1jUPjlvcGv+ah7SoHV3/pH9jxmZua+ZXxESGPVmc5vH3yVzm/5BLusxGf1CnwqSfY4v/FxogOV
G1GoP2hfxfMlX85nw0lUnXg5ajmf23lRSsv47JC69Vs+KPmjqHFg8G/4IADkL/Ma59uXw5Pv+2eU
49fcqXcaz/VF5LM/8zGiXqn+zLWvlq98avPAwx93dxb50NOuyOe21EPBH/i0x6NOAr7lfPwrRQRQ
y/igInExv+VzTBhlounwb/ioga3LLxf65/Qf+BwDgYvXAsBsvsvax/hz/+wt7rAyn5gXS5eswEoQ
tTKfFcf3XiodzYVxbRkf1OWmKOpln8PluCsvfmX2lU8xuLukNXJfgY9SD4TjQv0LPu4AVv+Zzw/j
O+o6KFu83goWtjTiaX/mY7P4qeS8c7Hy+N5nu8KXtIt84p79zMf2MhhffI/LPvdMKRW/uCy9dy8o
z/2eTxVd79c5yuQKfFCNn5Zl9jd8HBaeX0X/PZ80o+/4zHzl08e+4EjzwT/7h+7saks37Uu/57Pk
Yvetmzs+a1+Jz3jSz3wAQC82FP1lH28K6Hw3Y0sFtov948Wv84utUshiqGKxcq75js9M1HcffoGS
X/DJXegttwp8z+e+4Pf9D2Bb7D+WPkkgGDf9PL+Q+NorlEl8x8fj/tKrnh/ps6t/mJ/OFYHGe83S
ZPHskuYj0FuED2GXD3qrwTJ/3l5KZMnv4vzquDJWKDotwF8CRfvdx6RNIHpZu7EGPb/qf07PTTzj
LBfbiBt2ns/0raXZ6MM5R+uT1EOPpf5j6YNi6aUaFfTV90apb1VcCCfv5F2qnvN8eN8tzd3CSNXB
2dX0uymOItinra3dBxb4nPcGOPl5dzWkoxJQLM4dLgLlZVXmzjf3r6mefcm79zwC6EpYvq5vqB0p
5ebO1Eydn+Y7n3kLFDqWLTy8+0arVYsZSNVjVubT2pjJPXXQeKH8tMEAR8pqMHXDgvJoFwD3n3QZ
UywsJex4LwWYF2qSV6VeyVwhaDPoQEPh10+ATU2yVLm5WekUF9ZzeHOAL8neZo73S9V1jLn0gwn4
bqddYHGJSHBhsSGWFKyb76W61zMQFlvXY9LNZU6Y87eC5hYwMCw6twWCDAwujMvWx3TT0ydiF3oK
dVI0hvZlfrz7t2+XGPEkXdUvvn9GMa5KTx9YrNqnTi3mlebr6tc5a2uNpc6JgYWBwX2h73BhYCDM
eRynSLcYCr6tjzEKHEtPN7Bf/FJAo3XR3rOvxdEwSL+tkft32fSv/JW/8lf+yl/5K3/lr/yVv/JX
/sr/14Rb/q8sF7O/VeKv/JW/8lf+yl/5K3/lr/yVv/JX/s8I74Z/JTb8oQV/blxoZWMb/72FN7/I
z/F/k9j/NwVq5vff8e/4yKeCfyVFtvfl8H/IJ/EA+49mLhX/EZ8nW/b9aEGnce2/46P6+wLleWdY
xP4LMwyeduBfSpHJsT+sQgzHbi03MEz5x9v/EIL+Lg+FSv82per/LhD2soXR/zY0vlLSyvLTk+nJ
c/8T0PpB+ogKdvG22N4/LJ8PbplRzH/pA5qkl1nY8u8Br8zn0v450f96fSvlf/4D0JiGH43carb+
4V9MQm9G6eZVetv/sHhB38z2/rdO8vZ/I/wDH80DNYEC3/7PRUFo6aWieYUy3x8UYU4a2FZEuv7M
gnp3958NAd8MW/w3Pmu+WViN+m98NLX83X6OIcivPa/lEvy9pT3f18Bnv+wuReYj3Puj0pl+syz7
H0dZuq8W0P+ND8WaX0XCBM/p3/5+dBZejkeS4TdlVZiPsuePOqBvpo/+Rz62Xy1c+y98ekx/1/+X
SpGiSMf9ztLJZXgifxuzTXw+0sb/xof2P/I5+NWC/H/gc/7C7+O1BJAiGRL+JZ8XvzfG+v+0d+Z/
UZRhAH8/LyCGy6roZgIBKYiJuCqKQgbqIgoIKbAqZV4pXiiuComaJ97XlmfikRZqomZKWKLk7Uft
UEuRNDsss8vsL6iZ3Z0D3HfmnYPdefezz0/LzjPPO/Pd4b3mOeyd9A45fGKgYj5zpPN5IqpYU0qp
3cTj4zTnIk/KQ2xqdy2k8NmGoTnjEKX4CIvPa2K2HLq7sS9Tb3QnnwSsH7JlFnV1VTh8IsVM3Ttt
0wvAX4+5k09ABzzdfyndUjMGnxRRU+2AxEHenXx64iovoJQfi/OJ0+P2J3GrCeATfB5XuY4a5f3r
xPlgmJpvVw0lgE81vvYJyvpJUT6vY1g6blc11mqfT1d8bT96YWVRgw+z3H+ieT7HAvG1zfTSIFwN
Pn6MboXW+fhKaeQIZf6IGnw+YpTLtM7nttRdlHyTCnzYaqmPtc5nkJRG6MqzoIkKfCzrmZW+xvmk
maQ0oluO/Mml8YH7HMrpGuezX1ormZT9h2ryAfO0zUfaPp6tg56tKp9/tM3nXel8SirU5PNY23zO
SOcDCtXk09rz+ExTk08fbfN5R1or/ZH7O3L5dNc2H2mvS+4Fq8SnIJ3RLvUkPkVAJT6BgAw+EzdK
aiRHLT5lhPCRKJ+oxSfPI/ncsvtRrFbO56hH8vGxN6DC/OekxLfhRPDRXbDZ9zcr55MAyJj/SJK/
7fbHK19/6dJY7b88hs8yx00tUs5nNfey7E9P4TONccIcoJxPJcfntofwqc1l7D9QzMecyPGJ9gw+
GzNZ7wyzYj48d7D+0CP4DAlmzWdAxXzuc3xOeQKf63fiRB24JPCp4VkL8gA+eX/wfMN6mBTz2cJZ
m19BPJ9m1fU8U1He7/h8CkM4a7guUprlE/EovR6e33WK+czhrGneP0FEBvVNq+/2HbMTKuVTFSO5
d9YmH91vLZ6KPLgGlfKpyeI5cgYSy8ca9fD004EZNy1K+Vhv8sxdgYTyObsrxFncSolASUg8PuUH
eOYkeGZpiY8lvtR5pFOakLsgFp+3Z/OD1MpJ5FPwy2VEIFjwr1AZn1u+h/nmHkDy+OhXJaPi5Ibu
gUr4WOouxvDNGasgeXx+bo4MI0wXxsPjs6a2npzLy7sUtqV5gwDMsT9B4viYrpQg8WxtCXH54MgP
UZA4PgU/Im/Hf6aozzfHx5jISrBzc8tb34PE8Wn6PYqO8f4k8dOd9j/m2trITsXZ9c0l3qmRfHHu
51P3HQrP3aU45wv0z5aO3OuKC1dH3pJxdW7nszYbQSf1Np6HovD49a194rP8jMy7czcfw3incBIv
Yocziozv1kr7Ld7Qk8hHn+os00H3bwz4JkTnh0n2o8XXCeRzw8lSdE6QJBPi8+cv7Ye3W4njY0hs
mHfjq691Em2I8yl0pFjIsJLGp3V9Out3jZPePsb66wvHXbYhjE+Tejs9+/YGymkfZ/1+1XGP8WTx
ucajM7yrvAEGi88GRwaXyzqS+OiGcllFrsgurYO1/xPqUDlBEp9LnC/OJvlLfyw+C5n+fwxBfC4y
y6yBEDYyHzZLSDU5fEwXHOeFwcbnw4yUAeeI4XOeSVFicgGfFxklH2L4OEJlN5uhC/gMkpOEx718
zth3l89CV/CpYPag/ctJ4VOpzkszzPeDbBqnKFL4TLHtvutcxGczo/U5KXxCZXQH8vksYLQ+I4WP
bWfvBVfxOcVozSKKT42XjxCf0xYvH5SMQoYMNAafzsTxocevBJfxWUAcn2ovH0E56VI+E4gb31e6
lA+TAxp8SgqfCOqUN13FZwmrNZqY/bEsAIbpXcSnF6MUYiWGD52VLsJFfCrJ29+AK6hzqlzDx8qk
jZKU3djNfAKPAXDcNXzY7cP8TeTwgR8DsM41fNjZzxFIEJ9wAIx4qXSPRini42eUmwXcrXwqDmGm
KVp5eIcSPpb9jMoBSBIf+CEA2UXiapuSDyr6/2rP9j5Sh0sdcCsffS4AH4hucZTvA7FK+JTlyxy8
3Jhf3SF74gDYK6JT8D4ARQr4GNYxCttNjcSnbIdCPjtRDnO7qIdexIl3NwDvKRi/NrLx86XS3/Jz
fIxC+T43T1XIZwvqWPRWAOY2E7rEbVQXKZQMsJMwnyD26Vm/RPrzvQGrPkh0QFOFfJKQ85yUZAAm
o9dE5mLaslCpK18hPpaBbAWmCSkyOo8VWHxW+Svtf5IAMoQrZQ31BKH+xdbatm3yhVaxiwT4+C1m
D85eIqdz5RWv6YjW6pJmUMhnBOiHPLaUGl5Klzk9lGMv4SZU2XxGKxQfy8zpXD6AWbJ89yAvrA6d
r7ooDhQbFPEJLwFz0Rcxbz4AYzOeTg71FrMqWChwByOBEz6mwJzYwVzhJDBqtCw6cAwv4cLYcSit
N2zJiSYghAvEzkep0D9xzET0ZUyaTAdRTplawPtuWq/p7NBaiDzT0JMXB56eQUuXwYMzs/h+n61e
kVtaaMhQvp3sHIRaLlBDhJxrzd2G0SrDho8IG5KXFx7W5tXcOPGyMb16JySKNPpSn9j4l2Wx6ZjU
u4exgbXkvv2czDANRlX49BecnKUMQJ2XOhA18xCq79k+MjIyqkM0lC349T07gZjO7RRKbBejWD2H
6G7d4xrGf/XoGW+AWpfmLVqqYCWolfhK3fBsm+fa2kL/QtqGPh8WHgEJkCb+TVWx80xAM7wlcyAl
ekiM+PioZMjXD3rFK17xilc8WujCuvy4XnqXZjTvbytd65jeTgUHed8uSnb+2bnQlfjo3ef/KKGD
ZGlvUjpt04DM1BjY136MFj1dCsHxuYXj8/+oTEfwLBQBAB==

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/image002.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODdh2AB6AXcAACH+GlNvZnR3YXJlOiBNaWNyb3NvZnQgT2ZmaWNlACwAAAAA2AB6AYcAAAAB
AQEaGhoQEBASEhIcHBwNDQ0eHh4TExMODg4PDw8FBQUGBgYKCgoDAwMXFxcUFBQLCwsCAgIdHR0I
CAgfHx8bGxsJCQkVFRUWFhYMDAwYGBgHBwcREREEBAQZGRkmJiYlJSU2NjYvLy8oKCg3Nzc0NDQg
ICAiIiIqKiosLCw8PDwhISEwMDA5OTk7Ozs+Pj4yMjI6OjouLi4nJyc9PT01NTUjIyMrKyszMzMx
MTEpKSkkJCQtLS04ODg/Pz9NTU1CQkJPT09GRkZDQ0NVVVVBQUFISEhaWlpERERWVlZUVFRYWFhS
UlJXV1dOTk5QUFBKSkpdXV1eXl5HR0dZWVlJSUlRUVFfX19LS0tcXFxFRUVTU1NMTExbW1tAQEBi
YmJra2t+fn5gYGB8fHx0dHR5eXlwcHBnZ2dqampkZGR6enptbW1ycnJxcXF7e3tvb29/f39paWl1
dXV3d3dubm52dnZjY2NoaGh4eHhzc3NhYWFmZmZ9fX1lZWVsbGyMjIyampqDg4OXl5eNjY2Li4uO
jo6EhISAgICWlpaCgoKJiYmRkZGVlZWbm5uHh4eIiIiZmZmfn5+SkpKKioqcnJyFhYWYmJidnZ2G
hoaUlJSenp6Pj4+BgYGQkJCTk5O9vb2xsbGqqqqtra20tLS3t7eysrKvr6+1tbWrq6ugoKC4uLi5
ubmoqKi8vLy7u7ulpaWioqKmpqasrKy2tra6urq/v7+np6ehoaGjo6Ourq6wsLCpqamzs7OkpKS+
vr7R0dHNzc3GxsbQ0NDHx8fIyMjY2NjS0tLe3t7KysrMzMzf39/W1tbU1NTJycnBwcHb29vc3NzC
wsLOzs7V1dXLy8vAwMDa2trFxcXT09PX19fZ2dnPz8/d3d3Dw8PExMT9/f36+vr7+/v09PT+/v7p
6en8/Pzl5eXt7e3x8fHu7u7v7+/y8vL39/f4+Pjz8/Ph4eH19fXn5+f29vbw8PDo6Ojr6+v5+fnj
4+Pg4ODm5ubi4uLq6urs7Ozk5OT///8I/wD/CRxIsKDBgwgTKlzIsKHDhxAjSpxIsaLFixgzatzI
saPHjyBDihxJsqTJkyhTqlzJsqXLlzBjypxJs6bNmzhz6tzJs6fPn0CDCh1KtKjRo0iTKl3KtKnT
p1CjSp1KtarVq1izat3KtavXr2DDih1LtqzZs2jTql3Ltq3bt3Djyp1Lt67du3jz6t3Lt6/fv4Bz
ggv3UlzgkuMAkWtZLtBhkubAnGsJTNBjkmFAtRxE6PLIQmJaAgl1UdSYIEGEkAnmmeAoEOhWChMw
rCKpIQEA6NY9gEigdC3NASNWrLjx48iJGVOn7iS4Y8SRSyeGbGEyAEWESd/Ovbv3ZKVAEP+YPNFQ
7t3odRtRxnJdgfTw4RsIEeJImWMk2R2IHx/JwmUI8CfggATGJwJhEplRIAAJnNGOSu4cIsKC/AmA
BjMihWNKGgoMGAIixCz0zggUlmgiGhMNct6CSTSzEjhqxBfAAgwwQGABrI10yorpgQBPQ+QQYeKQ
BVoWUTMN7OYACUqMUUKH8a3BUjwmwPcAKsU4I0oiZhjBHwTPkLREfA6k8hATRKbJnyoRhSOkbk08
485AzCgSAXxOtLQIfAe8Y5AoScR3gjwjrRIfCg86tIaajO4mASsRpbIbGwiVEkJ6I7RUCnwTEGpQ
OIzE9wQ4IkFzZ3pjQNQKAAo04sorsMb/KqussAyQXgqz5jprGgAQYAxE86igGyKLIcTMe7uhQA9L
0UC5W6cJOUIBfGaGVE8F8HX2kDQAhPaQOg+ktwJE7aRgQXMPqaIbFKQqtMoFu2EQDUvlsJAetAk9
Al8L44Q0TpXpxQIRMgO8AhE8GaTnQkRjkNBuQ+K8AAAE1THUxm4UJMMSOiTc6ylC4AABnywiRQEf
aQ/ZU8I0ByeM3sIQuQEDRMrk9oZD6Eyw2ywsjRODxwsNo0F6T4jkBHylQETOEho/hLDCEcEBBkSF
MEjNQ3HsxghL7rgA9EJwpMcAeyCNAR8tEbFRTctQQ8QGJA/N0wIAUkCUs25ksHSPDF8r/wRPuOiV
EVLY6aESERm1sP1yRGeQ7BAoEjBgS0RVAzBFS0P0rZAct84D0hzpBQApRIDAovhuMD9ExyoP1QHA
DA87ZM8GAKxQrEpUaJ7QNBygJ4E1IJWRXgL4QcRKJKfrlrqiVzfEDg0AGBmRHQCcsOxKuaOH70Lm
1JCeG8Gn10HzD6WzTPIALN/QNfc4VAwHC2AzETALIAANS9k/+/FCgKRngjkfER56BuAikTxtcSDp
XwjYMZFwiMADa8Oe7hLCjGntJgLF68jFBljAkBwQdSERAgCYUBF9jQ53E0TIPGyQnlt8RBHpIeBI
Pqg8kKDjBgCQREWysYBJ4C+FCGFDev/u8JH+cXCGLgPhR44hAQ1giCLgsAEefqi9/S1kFukJgec6
QokYdhAkNEwfSCoBgBEkiiKWiAIV9fcQbdhoNx3Yhke6eEQDJrGGHzkDAKpwEWm8YI262R5D1AEC
9ATAFHP0IhLb1hFyiExKFkmHFfAhwSpC5ArpgRsXFWlHRnIEHYUcBUYucY1KsvEhnEMPHBJZRw/e
UYweyUcHJBCii8QOJfkLpBX5l54hsHI3MuwkAjsSjAB04IlDySUABMkQbKQHBX7iCB2B+cWPhFF9
GiFjAepRFGUycyHISAB6HnA+aXLSlZ7cCBleNyeieHOXCikHDndzgQhuZJq8qaZHrvn/ESwAIAtG
eSdE2EGi3QTAFZtsJRhfiU2MkMMKANBCQIGIkHDwDT2YSCg1FznMjdADBwCgVDcpipAxoWcRGs0n
R5XIEX3o7GYjtSREeIUeOqQUAMFEZ0c1gowOACATE5Wp6tIj0nuec6HpzEgzHAAATQT1lA/JRHqw
cNOcInWnGSmGbjbxVF1GhBPpUUJV9dkRfnaEFbqpRFeXCU+F4CI9WxjrSvHIkUukda3fXEgs0pME
uQqTpRuBxF1jClWHvBU9fTWnQq3JUI8oCABqJaxXIRIKvvpVp4DVCPUgi9e2JgStiL3sVTObkTxs
tbMRMVRoFbvRv9J1I3rQjSFQCxHV/+4msUZd7D4b25E96AaokmVrai3LWpW6FpYc8S0AIOlOkh4E
tLshgmgZm1SMKLeoyXSuQUyRHjUWF6dk5YhZk6sbPgY3r25Nj3++a1XqYhUjZgNAEG4nFIFCJBfp
kSh7w7uR8W4kDLqhQTSzK1SHbCI9YZjubqt7EdMCgJzn9SxCjLibPCi4rLzlCB100wBuRDgigkjP
bPc7V+RuBHS6cWFzC9wQAe4GFxcWb4Y3EmLdrHLFhW0IH3w3ORIft6EXMcRtP/wQchQBPcSLcX9n
rBFd7CYD+cDxZB0iDu/t5gP7ULJG/KsRV6DHcATO8ULikQP0oCAeWs4Il7OKngSHef/KDSkHCtBz
hF8aF7Ov1Qg1PJAsBtZXuwRZhq12w9zcthbPJtYINMS5m6T9mcVBkwB6LmFn8JYYyBaRB7Z2s4c3
C/chZNwNA8KUZoysGSNUQk8HygkU+zqEcLrZADdLfZFTYwSTbX60mBXCBfRs4ZYZwaelf/wRPKSH
APdrNaAFMg4doKcRHxF2exf8XowcAj5iVTakEwINeOkmAD2mtUVsfREnp0cCKvaJqxliWwDcAF3i
rgi5LcKMN6KnALVR97L/gWLdTDHaR3UvaTOiDwvEZwex6cm6FRIk9JwCJNLm75aZrBE38acG/FD4
smW5mxtkHOC6xTCDMQJr+ByBPDr/WXhCdoGeM4Qk4pcGyWH5I4N+pXzZO/42QiEecGoPPCPUsHd8
qoDmnKj8IO9IwW5msEWQH3q0ed6IOi41ICQABydHNwgvMCoSmBP7I+TwJ4FcIGGXZJ0g9/CSbkYw
YKffGeqJ5siBC/QCYNzk7AMxNwAWwIuReB3RmMZIN5w1IBb8qCZ4/wcod8OCWb+85yKvdkbA0QUK
zWBeNMH7O47sqBWAmechl/HIMxLqBb0gyzM5uzumEB8JdOLxoV/y6DFyjlcOKAoAlIkyK9B0gohj
E1bmD0rdPmzAj2SdJRKc7tOjADNk4vnPFwQSgi8gBmim0tOO/M83Ag3CE8gBO4eJ/zIbVb1+YF/i
aqa4R+JLoRAk/CXjJ/8czh/zkXAjSSUCn/jTs4Ab0OD/APh/KHABkjYgCSBHPmZ8JBEjJUIBOWJ2
9+IP5iAOFFiB5vAOweANhcADA2JhCQh3gbcRgmYiMwN/9/Jx8aQJGMAfFYCCwQZ5oid5HeEJQ9IK
JrhtB9EIPIIepPCBAhd1IKEOBlciNXCDu4YQlsAf5qURfweCJ5EKTEUhDgiBOHgQ9+A18LEB+mBo
b/eDcScSMFQidUCFR4gQweBt6bELXFh8TngS5IBrC4IAlARIn/YQWhAfabCG2ReD22dD1Ecgg9AS
iWcQ0hCF6JEC7fOCsTdxs/cRy/+gdAtCBfSFS/smEPMwA/AxNkwIg7IngyHhDz9TIAaQbChUhQnx
WOnhGIr4dF4YgiERDW9CIE5lSnDmEMKwAPCxXhjRhK3YEuMABQXiS7RYhw9xD852K2dkEbzoc0B4
EvdgbAOSAf4wjOi1EKmEHhRgT8rIiYzoiSQRD2hAIL1AjWWHEHqHHo5zEcuofc2YEqwnIPNXimWo
ENfgfQAwfOrIjenXiIjxBAKiA4lIiaaYEO7AQmG1il3IjF+4EukwN/ERR/JYiw/RBPCxA4aRj4u4
j954EtowaPCBSCkxiAiBfOhxAu9XEevIh+24EpsFH4kQkcQIEaIAH76yi/poaur/1xIENXQwWY0L
oQzxwToYyYoK6YopQQsFiB4x0JPliBD6IADwkQs2mZE4yY8pAYzpcQLwZhIieRAWBR+cMJVEyY4L
6RLDwGeqhkxcWYkF4Y/pEY/bSJW1lpMvkXPogTYCOY8LAY3oQVVDmZBkaZQq0Q2MthtclZcS+RA1
hh4yIJaAqZJl+RJHgx6KEJJsSRCvAB89AGwRkZKd2IcuUQs8koeIGZMQcQ29gx4gUHQoeZNzaZUq
MQ47gB5BYJkD6TevVAH28Jds2Is40W9lZJt6qRD2QHXDuRCe2Y2g6RK2sCIkEJAl0ZUH0WzpIS+8
uYefuZIvwQ9QqRsnYH4nIZ0G/2EOypQB3XCd6FeVG8kS4ICVAIBlpemTDCEFzJdBFJGcGrmcLoEI
8UKK0XmZBMGXHKaNE4Gf6qmfLTGTupEAdheeADoQwAkAEUA2rSmX40aXMbENQ8Mq2RCfTZkQnZAe
E4qe9YcT/cCBANAATbOWt6kQYIUeIxqXYwmZgskSEbMb4+igLZoQiSCiFHqfrnmhsMkSSrAbPaij
x5kQkuCjJPp1OdEHRuqhFoFFMPqjBRqk8oahEiEM/pkRdqUbR8qiSYoQo8CkMvqY2RmZErEJ0tAR
pxClSJqYD1ENSZmiBCoRBvqa6+kQsCAMHQEKcCqmcuoQzGCIDNKgFTqjaVqjDf8BC7W0EdUQqP+5
owixVOhhnWfam0XJEbFAahthqQAQppM6pgcBqroBAV2Kp1hKEfMmEY6AlxuBD90JkoJqmhBhqu85
h4mKpsqpnRHxqh2hD/txAcUgpRWBq7rZpAqoEcDKEeegMwqQnhwhngaBqyxwkldqoVk6pAxRCY62
Ec8KAAaAqKM6qA2BqzsAndmqqL2qphHRCKLkrDoDAaUUp7b6ELg6A7m3q5oamBzhCemmEeEqAKhX
q/K5ELjKqAiRp0K6pw3BCDDWUvtxArtprwerELi6hPyKne2qsAvBCJ/QEbIKAKtprBRRqDXlmP1K
oxzBCI/QEZaqAsJprgyhDHX/ClyZyrH56asQ8Ql80BFACQA+MLP36hBUuhuOoLI6e6A8+xCfoF8b
AagAwAVEe7EJUabogTI5K60Ni6AO8QkAxRFvCgB5Y7IT4Qvo0QB3qqrayqpaGhGaUAIdMXdbY7YS
MQjosQGHt7UlmhGNQAOTeBGVE7DlWrQNgU8g0HtA2rYT0aoRkQgV0HYYcQe6kTh2GxFQuhvjorRc
u60OyxCRwAFWehFb0Cu/crlugx5ygJAru6gc4QgAoIYaQWYAwALXY7GONxFegB6zqKxtyKwAkFEa
UQ8nAAAlELgjoUwWMI0UQQ6Zsxuy67u+CbyvpxHdMDRTQ7QIcLoTsZO6EQEs/8O5fYsRsJsnGiG1
gACT21sR8lC8uoECW7mxneu23LoQsJsDyDsRlVMtpUkAahkRy0AAu1FnrLu0euq1DQG7FpC7FmE2
EZBvpam2FcFEu3EIm8i4EuG4EAG7DPCokQRSIJCMtcoAfkoRmvBlF8yuO+uuG6wbwnsR0XAnUFua
ACCUE8GXHZCqi6vCTMvCDwG7ANBpGCELuuELwwgAgUgRJqMbJnCRGFE5PHzATesQQMwDNmcRrMcB
a0sS4wdTEkEPHaMbbpYR+oLBEaHBP6wb9XQR7zCbTHfEdTMRw+BwG+FivLrCHqsQQAwAlHARz6Ab
KHLERpC/C1F6CLC3GGHHrf/bsa+7Gy/gxLoLABIgqjT8AcwbEUWqG1bAEYp8TON7EXu8AN9QEc0C
AIdMhwDgAfITEelQSLrRx3UsNqN8XHK7EXsMAF5QEQAGAEuAOfFRmal1HhTgDJwMH5SskDgAyaCM
HgoAwRABDQHiAN+aEnsTHzmwrw7hB7vRxBwRoQAAq2AEOLuRAgiSEbeMHYScEOFIslecEu7gA/Hh
AbPsEPjgU7qBPBxBU+gxzR9xDRu6G8lsy2AZEdZgQcC8EvMwIfHxbw7Ro2rMvRrxjnQsEm6UHjdw
deYMHzeAcgzRDtmjAeSaEuowm/GhxQ7RDzqjG0LAmRZxh+lhxCLBDYa6TAz/bBHnrBs10M4KAQa7
EccsQbwCUgLl0BDKJcknpBHkcATwUbchwS3ViXkZHR9bsKII0Q98aQDksxIEMyBW4IIGQQ5iQJvK
jBHp0APw4YEhcbS7wQElHNUPWQleLRDg4AqhqBve0hLWsIPwQQI8cxD4IDK74QFULbDivBtFIxIk
iR6mA7wDUgFMYAj6oA/ykA15EAQ8sgXlzBIvSiAMkAR5MAvf8AzewAt2YJy6YQcfIQwzXbt+9hHg
8AXxoQcCvSAfIAACIMA9AtEsUbrktxsiILkaUdTo4QCW+xHBIHS7AQLqWhE3PSQa4A0wkYS9rRs5
oKv/ipbwYQO3yxHHAFL8/xEHjK0mFeCpK3EPvAAGep0mEYAFrKYR4uALnBfUgtCmGlENWDCE/BEA
WtAIUWYRkaAmFMAEHuYS9AA9M7IACJ7gCr7gC+4BDHAATeDBG/EOIHXgDL4AaKkGgaUbHnDhCH4e
0UsRmNDhHn7hHmABWVDcLmEO3IANwvDiMB7jMj7jL+4M8csR5jAMLk7jMe4NUE17O87jMO4NNx4R
5RDkQh7j2DDUrdHkTv7kUB7lUj7lVF7lVn7lWJ7lWr7lXN7lXv7lYB7mYj7mZF7mZn7mGDEO/LDm
bN7mbv7mcB7ncj7ndF7ndn7neJ7ner7nb14OIvwRjaADJjDohF7ohn7oiP+e6Iq+6Ize6I7+6JAe
6ZI+6YbeArpAEvDwDUm+6Zze6Z7+6aAe6qI+6qS+6d9Q02ie6qq+6qze6q7+6rAe67I+67Re67Z+
67ie67q+67ze677+68Ae7B1xDvTADsZOD4koDvCQDurgKeBgD+hwxe2gD+zAD6w5EMAgwv3QD639
D+ewDuqArf/QDrEgCLiwP8ROD/1dEMYwifVQD+9wDte+EMdwCKLQTv8wD+Vg7OyQDvTwMO1AD9qg
DBU7EPWQDtsuEPdgD+xwDoZBD/B+8AahDpEgCLEAb+TgD8Vu7OqA7wJBD5rwCZcMEl4QAijwAR/A
AyXMDkFAAygQyPEABSz/cNfIMAMkoALVNA9IYN3/wAgHsAVXrAYocAJ3LRDkoAQasB8o0N/hcAUg
EALCSBD44AeTmAksoAIzwLX8kAI607vXwAPm8gEW8APwlgc8gIsfYDADsQcggAJh+Q/lYAQk4APr
8A+0cAA9gAI2bIkwoAA60wJzSA5cQAMsUNsnEH4CMQYZwABGMBLVMABfoAmA8AB4SQ7foAAjoA0D
gQ0J0JgCIQ670AGZIMLZIABdqg9dEADIdA0lQAPt/Q+KQALnWQse8JICMQwbAAIDThC0kAIGUQ+c
cwl/jhBx0AfkUAcarvBhIAGIoAlnIAC6WgsQUAK2kAQEULDKMAAksIX//2AOlZAAPUYPCmIGOo0G
VIAP5IBftGoLDCAEmsAJKMAmAzEMQ7AOrIADw88RQTCLhvB5/0AFAKHn38CBUyDwI/gPCLOEA6sx
SNbwHzEAuBIqctNQHgtWBIt0Slhlj8R/tyqwk7iqwz6SJMl5yfYvWJiE31AQlIMs4Riayyh8Ssgk
SEJgVhJyuzCs4bET2wjWOJXQhq+Bg1QlLOTon7k76Fp+BduSC6WByVwlXJKnYSYAtAiC08KwISkA
qSSe0zAlISFNDS/pSOhr0c4/JB8Z0LkUBbywBOt1UfdPHSFyBLnRoDcQU0yCbdoMTOIloSYVCXsh
IopALkE8ThJS2pUwyP+lgdNuJXRSayAleY19gx07kNmzhE3sNDwEgM5bmBJzOQDasF6GE5EHVrpK
kNwWQQmZYUpYp7BENgSIN8y2w95vbTDE/btXyZxlzANFTUt45sxAPjjAEeylgswGSgSWhIYhgLOB
3lGhlYRqMZCgIWj7Z59NCDKnC2Gui+Y3DyUK7p9zjCnuOKwYgCEhPVhq6JMHyJBInxEAkIYgRy4k
iJ4dQElomUQSmmO8huYAQReJjlHvt2FMICib/wa6bEBlOiRIv4EOYSEcgpL54ByCDkHlQAy0Sega
FMgkqJoIB9qCQnV4HCgcICL6J5t1PsRzoBAlMq6hQbwgYBmCOhlHokf/oFBDon3mGKC7gW5MSBkL
nCIInVISKkNIguKBRIZAjkzSN25SiIekKFuy8p9UQtByIGgg+IYgNqg5qgB8TDspoXyCSahNksz5
oqM8h/1nz4b6TMgRWBhwcKA4UEqoHUj+OEKiZRohwob5/oGUoEp4aCchcO7BVNOB/PlECEcTQnI9
36ipABpT6yMp1V54aPWfd2iQZaB74CjVMlsTEgMwcZ9kk8KGwBFBEmKHDbGyEhtyxBgXsCDo2YbK
ISSQG95LCBlMCAmAs24HEmSFsDKVSJlN0tACVHcbW0YBIyU69Z55Gkp1FB5AHugHsv4pR61abyWo
iSvC8hUc6wYipwaj/x7GM8RfgP4HWYIiQWaNDLz6R+OEtokkmwm8DPmSZiTI7uR/8ABiZXP/qSWV
QZhcKtTG5kkhiXkzo6bG/Pb7J5IuGmKCjYGaMaMhbgZ+ysSvfH0nF4kHKoMBEqn2kAtABtqE3KQl
HygSaJIB4BVnoSXoF17wOeGYhpD5BBwfqHgUx4GgUEJuiW4BhZUQRCeo3c4DUN3xHch9ZsP8Mvrn
jzcasiOJ/17p6+i3TLCE6QvZyaUhWADAg/POh34Da61LN2YdDEwUm6BUUKEHBFtmn+SfQhSoh1vd
/3EBH3zXkEgEgxsT6B+79NaYQAAgB8QbyDAqMAx8FIJX+anDQIZwqf+EyEIAXmmFbrQ3kHHs4BBh
oUIn/AEKSDSEGR5oQDPM55sq8KANWfjCsUhXOBlO4Qalip9mhCGOHVgkZPkrBgBC4T+CuGMEGQQL
yxqCiHNAowKUKt4CwyKPDQBgEA1phgMC4AENAINnUvjHN5IQroQ4owMkakQxHAc5fdEgf2CBAgAW
AADCYagJAODCDBvjBQWMoAAi0CEBZZiKBXAjbKwbSCbkRQSQHPEf8aABGk/mRCh+RYoEEcccJDOB
syhwZr4xAwB04A52KcAPdqgBfhJiBwiMAQWfasg1EFAjMfhjjkjTFwkIEZYs/CAPXNjhP6rRgAhs
TpBi6Z49+ICwrO3/MBIyxMcFyBLEfyxBBlmAQCcHgow7YmEC/6jE/2SAxiiaqx1DoMIPPHAbU34I
HxAIgDOOQoL3nKIaDSnDDKagRInwQwCYMIcetiUwYLKDBt0DSxIcJo/oNEQNAODEM7/ChWH+wxP5
qqYi/0EOK9jgH4iApDtW8AABXKAK+BsIKjxAjFjojhwvCGQ7NUKDD1jAA4zI2yl94wiMHoUG6fiH
Ne6XEDjspwcCXJgPyKCOSo7wkilQBNMiIRmHSYQaCpiaRkE0tFGAdH2F48wiLnCOQ0DSH24g1yF8
cLl/kHMg9HjAHHLxPyf4TacJqUYZRtoFgdTzQ/OYQO/okxl8KGgg/2f4DBh2QJIm3EEbhsAZHcnh
g7k1xFfuMAU1CQIGCwRMrAkJETvoelZPyPEf1+AAIxYBSW6c8B+rOADYxnnHfwhhBpHo6kDCEIMB
EiQU9JxDWAdiPDzhgQhGHZBErCSLByCkIXBYASlEkVlg/iMJ1QKLr8Cyiwyg7bQEMdbE9hKrf7gj
BiYwwzsSgoov/oMaE6DSbgniiwTggSoEeUQB7uRJc2mCFAP5xAFM+w/mfmgTNYAuqvYDDAYsNVkV
MITgrPoPL+CArhIR71euUQFnnrdYQ+PTDg2BDYLAwQFdYCVBNhGmf0SDBY4kiF0HAg8NnICeA5HF
BWhFYJ7BCRUfKP+HYRvDxn+gogcRrldG0CEAoDbEGw84w5CPMgFfEoQOFdjZ5BSWkHtsCx8jkJ2J
9YTiRCZkxQQpBQBmgLVJ/GIg9bBfQrrB23iYIAD/dQgHNDxSViw0SOLCgjIcggAsMjhU4OjHhxNy
ixjX4gX7ROpAysHkM6RhpDVggrUO8IUkO+4DgiLIKQxwjYSk4zwJI8g73PULM/4DHy1Is5rTO7qG
vHkg/cBACLBGhn9eUgU/ti9qCPIGAIQvRxNoIUHYkQmEtUFT6wBCl7eRAdculwTW5UcswEIId9XC
r1AKwdMSAcwzvPQfYTgABP+xDhS0gCQIkiFBuuGB7RLkGhmV0Fb/ByKMJTY5efiwQaPPu4SOgmg5
CeEEiwcCDi6gAGjimAKltmO0xYkTG80+1gzK1IeEgEFT+ViCxPSxAWcLhwX5GMg1fvSVRyj6H7No
ArsyIJdwmIHJbnD3Kjygz4SYowRQIAkwEKDlrcBgCQn5RcP/sYWGt8ItyqTQMlzwNBNHoY8NEcIO
11DKgdxC2ARRhxOiC4aYEYQZniZIPwQQ3IGYwgFE51bjCCIFuA8kG+7WFwjikJBkdABNoOAtScgA
cEJE2yEXqDU++v6PM4jmH/DgwBokogWaSAQYA0ATQTShAWDCAZcDeUEfwyC4YehFJkeQtFhLIASS
uIMERWiIErRC/5B8bIF418hCfkiQkGIgEjen99cIUvSPcOwge6gH70BUgXuCuEC5sgBAIeKRDidk
pyWbIO4/nsDegcS5EfGIhyDukBAgLB8cP7hJQ/IgdYKgIgAFJ4g9BuCHX7MATszfARDYh3DgBhWQ
l3+AhhtgDEtIJo0ihz8AAACQg4ZohyqIQIj6B0AAAA8ILnAIA324sxwAAIg6BQoAgCmoDH8IAQA4
gt54lN0jPAegAmxRACoJBzSIQMX5h18wALYZCESIQDEYCF8YgAisgA8AAG8AC2UgnzAIAuL5hQww
wgoAAL0LmwhMlH84BQDohIX6h0swBYmoBgwAgAEghobYQiCIhP8cKIB+GIhzMIIIpAAQ8AALAJkS
MoFMmAFWUzNywAVCAATka69IMARAmIVUA4RF4KCBGAWY+wd0KARA6LdvWARDGIT/4AdIMIRCcMOB
6AZrIAleiAEM+AEa+wdxqARCIITdC4ZHKAQREgVV/K9aeARPIIRDsIRG4DqJEAdKOIAZcJ7ayARP
AIRDOARAUAr7IARD6CpwWAMvyLSBAIViSwhtGMZMYLqBiAUdyIAh0DB7yARD4ARIEARIaBZptIEM
GDM1Y0fzAQfdakeJeAd5Ixa6AgfR8o13zBNziK549Md/BMiAFMiBJMiCNMiDRMiEVMiFZMiGdMiH
hMiIlMiJpMj/irTIi8TIjNTIjeTIjvTIjwTJkBTJkSTJkjTJk0TJlFTJlWTJlnTJiIw0kqwH83qL
TgwLL3zJBfEGWtiFWmAy35CEE8gCHAuLbQiFUkCFQmmHUmDKQmmJYyAFiXMIVCCFEpMIehiGUjCF
U3AssMiGOiCFoySFXaCFRng1sAgFSGoJcsCHV0CFXVgNsCAGWiiFV4i9hpgHVtDKXegFW/jJ89pC
AFAAABACemyJQWiBTTCBBMivr7gyAOgCpGIHLwCAGhgwkhifD7BJRQAACbiZlkgEBgAADkgAD7gC
+QoLipCABNAjAojACwILe6ACxggLcXiCCGwABhiFxhCDCByD/7tMiHHwAQCgANfUAFRTM3QoAhDo
hkoAucaAhxHglXJIAcsLC0PQAGeCBx6QypYQAwmgk0t6AjwAzn/QhxdAAWCIBkqQADcoz3/QhRYg
hmgYAUTYh11QgVz7CmM4gLj8Ci7BA2YYAnr5iniIggO4zLCwhQSYhX1gBREgSjXbhBIYCBmIPrA4
hJHQRg5wRLBYBRYIM/iQApokiW4AgOcLm0ZojEM4N0IAgFr7ikoQt3+IAvD4B0GAza8YBkH7DSPY
qmnwACUMC0oYAg85Bx7gDEagRjW7BeMTBBrAx4a4hxe4OvMkAEEkCW+gAaAhhzqwrq+Ahwt4OoL4
hH4btxwaiP95YIGvI4lIoJQhqK9ZkCWwAAUAWJOwiAKgSocD+JywEIQLDYtz6AE6+YbwVLNdMD5Z
yIAu+wpqwIFSG4ggOJzUpIF8AYc26EeSgIcPEAAXRCcRAgtAQNOBsAMQQM2WSIYwg9OBeIbQ+4pW
gAA2A4s83YoagJGwYARABQt+yAE6YQbyUzNdML5niAD9JAlRKI2SA4HGEIZKfYszSFCSQIYxuACp
jIRF/ApRTQhRWABj/YpV/QdweM9/aIQfYNOvoFUancCwqARd/YpyiAE6IQecPC9hHQhsuIA5bYk+
wJ2EuAQEYJGvaNZ8IYc1iFaJiAZFsIDBuw5sbQltJYhmiAD/UA0LcP0NQ9iDMfiNdD0CUQqLQHDX
loBXQ41He00jDehKiYCBziMIUAgAIRVYZyUIQTjYhtgGR1gCHyAIXRCWUB3VR5yAxAMLi20McbAE
QoAw30jXFGKgkCWJkQ1Ik/0GCAjY2usBgCOIYSAosBjYi6jZhDAGVXCEC+DDUOjZbP3ZcIgBjfUN
og2LeogDVkCBv2wJWnWHEuiXj3VaiYDafchGEzPZUFABrJEIdKgAQYyGBTCimAUpRfhagjAGR4CG
BqCQXTjbh/3Zf4CBSW0MtwULamgEamABEq3b/JEHFeBDsABZD4HaaTBFdjRZRrDOljgHAqiEhjBc
+pOIriUI/8cNC2P4ohzIKcttDIgliCjI3G+tL9/Ahk3wBx7wVpKwgi9qBP5rWtbNAYY4BvyDXRcY
iCf4zJbIBwPYzYSghxvQ3Ybg3YHwXbAwhh/pAwIAQeINC+MVrqFo2+VtjFLQBXbAgUH7iiagASIA
gHNU3b1tCH7AgTpohCewi3jchR0whluAgmgUXwPghYZ4B2EKi/X9h/bdzx9xBgCICvr1WYDC387V
37BoBBazARgEiyYQACvAAOa83t/ohxDoACQMXzVDBT0CgCoDi3yIABhmvhzoU8b12t/9EXY4gEAy
YbQdkhSu2BUGCzdgtSO4VTwthH94BgAorAP2EH6YgV8YB/83yGAIpoFZUIDJa4llaAAbBaUc6GKu
lVmUedyBeN+BSAMCWIdeuFySsF8OS96W8Ny13IIdMIEIcOO6zZ4rMD4x/o1yyAH8cIYeBlwZ+Icx
yAF6bYh9UICKGoh4SAGh3d07Pqk8/oc9/oc4A4VVCGSJGOQtKNL8/Q12gAERKIEPGFM8rTJGwABI
bYnVneR4ZTCKDVZEyoUISN2WsIcJEKd/OF9AawlhAAHiIYcyyFSJYGV+QAA3YIVYbohB/gLXsGXf
MIb1I1ccAKm6rTJiiACb+wpi9g2oHYddBFxEagYNEGeCmAcVCL6EgIcMeF2SIIYJ0C1zeAPDBNuZ
22QeyIX/5DlhgriH+vyNQyaJXxgaabCAL0XXKosGDIDZYUbghIBagLTXPWVYsHCBHGgIaniAfPtP
AWBUdigDT25ogqAFAEgDUKzfn6U3ZBtaK24JWIiKf9iGCnBVd3aVBxhpkqDnxjjpfzTZLqDilpiD
AjjVHeSBGPuKZhAALcsHHXRfheGiDrCzn9aVCjjDc24MRhCWfeCBbvvopgZWqC5pgpjqcTUfk40D
AcDnueAAx8qFSwuLaPiAtq6T6SlKNhMCAPg/KSaIVUABtVTe31AE5+kHGnBYkoiC7LmGA4hQknCE
6MsHGH1aYx4Ib+iGdjwF45sFAFhSktgGDwjfMPiMsCiH/w3wPlAYjLDIBtLpzch+WCoWhOf6DSpY
x7Xcg3wjZaJuiC7Qu2M4ANJtCEIIK2/obJPOAWpMBKs8rVyg0H8YXwxsCXMwAcAjhyDoZ1B6Aaj6
h0Mw4Jbghtx+PLL7CkMwqYkrARX9jR9waLB4hykYkPVuwIbIAteThf3G0KT9h1ZI65bAhxtQbDqw
bo0KBJHbChd4gSjdiwQYkGB4AbolCTbYAJQwhyHwT5I4BvjWlx5YhcYwhA1wyg+9cJKwgTp+29n1
g34Fix+YGikon7BYBBaQGDeYbekYgEOUjCwg8Wd6hyiQAKL7BADIUZJQBwFIlHsIAhQFi28AACDY
BjnYgv/GMIdM2IDEGIg6KGiJUIckqEJ9MIUPwNKWAIePi4JtXhhcSIEBa4clAAC8I4l9+AAPAAVD
eIClvgsRZAIy+IMCaMyGMAdJAAAeWAMyAIIoaMdcCAEcOAJW4ocd8IHuIgldSIAfKAEuCNGwAIcx
AIALIIBg/IpqwAEcaIIQ3YUYBwsyQIED6IAYYIE2INyv2AcRmIEKECyw2AcZAAEd5IUU6AEo8GqJ
qAMQYIETwIH/aYk2QAETIAEa0IAccMqk44EcUAEaOAAJ0Dx2rAd6AIdokBhjgANP/YpeUII2aOew
YAcywIIIB4t10AdygAagUYeqJYl8WIdyyIZgaG0PmQenMrGHA/yKeTiHeOBDeViPfPDwGtu+adBz
iUAG0/IH2myJd0jddqAGVc7JlWf5lnf5l4f5mJf5maf5mrf5m8f5nNf5nef5nvf5nwf6oBf6oSf6
ojf6o0f6pFf6pWf6pnf6p4f6qJf6qaf6qrf6q8f6rNf6ref6rvf6rwf7sBf7sSf7sjf7s0f7tFf7
tWf7tnf7t4f7uJf7uaf7urf7u8f7vNf7vd/6gAAAOw==

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet002.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet002.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:.5in .75in .9in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.92in;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(1);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>33</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>40</x:ActiveRow>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
 <x:PageBreaks>
  <x:RowBreaks>
   <x:RowBreak>
    <x:Row>28</x:Row>
   </x:RowBreak>
  </x:RowBreaks>
 </x:PageBreaks>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D637 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:478pt'>
 <col class=3Dxl38 width=3D637 style=3D'mso-width-source:userset;mso-width-=
alt:23296;
 width:478pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl94 width=3D637 style=3D'height:15.0pt;width:478=
pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl94 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 style=3D'height:15.75pt'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 width=3D637 style=3D'height:15.75pt;width:47=
8pt'>BITS IT
  Service Provider Expectations Matrix</td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 style=3D'height:15.75pt'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl95 style=3D'height:15.75pt'></td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl96 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>The <font
  class=3D"font25">BITS IT Service Provider Expectations Matrix </font><font
  class=3D"font23">was created to promote a common understanding among inte=
rested
  parties of the financial services industry&#8217;s needs related to
  information technology practices, processes and controls. By providing
  financial institutions, service providers, and audit and assessment
  organizations with a comprehensive set of expectations, the </font><font
  class=3D"font25">Expectations Matrix</font><font class=3D"font23"> helps
  financial services companies to identify risks and comply with regulatory
  requirements, as well as to eliminate gaps in the audit and assessment
  processes.<span style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl97 width=3D637 style=3D'height:45.0pt;width:478=
pt'>Presented
  in a spreadsheet, the <font class=3D"font13">Expectations Matrix </font><=
font
  class=3D"font9">outlines in detail service-provider practices, processes =
and
  controls relevant to financial services industry and regulatory requireme=
nts.
  Using ISO 17799 as a guide, the </font><font class=3D"font13">Expectations
  Matrix</font><font class=3D"font9"> covers ten security control areas:<sp=
an
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Security Policy</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Organizational Security</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Asset Classification and Control</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Personnel Security<span style=3D'mso-spacerun:yes'>&nbsp;=
</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Physical and Environmental Security</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Communication and Operations Management<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Access Control</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">System Development and Maintenance<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Business Continuity Management<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl98 width=3D637 style=3D'height:15.0pt;width:478=
pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font9">Compliance with Legal/Regulatory Requirements</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl96 width=3D637 style=3D'height:45.0pt;width:478=
pt'>While
  the specific controls and requirements will vary with risk and the nature=
 of
  the outsourced service, the expectations provide a template for the
  information financial institutions need in order to understand and manage
  risk.<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;</span>=
</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Background</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl97 width=3D637 style=3D'height:60.0pt;width:478=
pt'
  x:str=3D"When applications, systems and services are outsourced, responsi=
bility for reputation, transactional, regulatory and other risks associated=
 with the outsourcing relationship remains with the financial institution. =
To develop an appropriate risk-mitigation strategy, the institution must be=
 able to identify and understand the controls on which the service provider=
 relies to address risks associated with outsourced services.  ">When
  applications, systems and services are outsourced, responsibility for
  reputation, transactional, regulatory and other risks associated with the
  outsourcing relationship remains with the financial institution. To devel=
op
  an appropriate risk-mitigation strategy, the institution must be able to
  identify and understand the controls on which the service provider relies=
 to
  address risks associated with outsourced services.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Using
  the Expectations Matrix</td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl97 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>For
  each control area, the <font class=3D"font13">Expectations Matrix</font><=
font
  class=3D"font9"> identifies a high-level industry expectation and the doc=
uments
  a financial institution or audit/assessment organization may request. Sam=
ple
  questions are then listed, along with one or more possible summary questi=
ons,
  to provide direction on the specific areas of interest necessary to valid=
ate
  the high-level expectation. Answers to these questions will allow the
  financial institution to gain the information it requires to evaluate ris=
k,
  create mitigation strategies, and satisfy regulatory requirements.</font>=
</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'page-break-before:always;height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Expectations
  Matrix Benefits</td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl97 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>Increasingly,
  financial institutions are deploying their own internal resources or third
  parties to perform due diligence and ongoing reviews to fill gaps in their
  assessment requirements.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Consequently, service providers, which may have spent considerable
  resources preparing audit and assessment reports, often receive additional
  and inconsistent demands for information about their operations. The
  Expectations Matrix provides financial institutions, service providers, a=
nd
  audit and assessment organizations with a tool to help streamline their
  processes. For example:</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl100 width=3D637 style=3D'height:30.0pt;width:47=
8pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font8">Financial institutions</font><font class=3D"font9"> can u=
se the </font><font
  class=3D"font13">Expectations Matrix</font><font class=3D"font9"> as they=
 develop
  internal due-diligence and monitoring questionnaires for service provider
  operations.</font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl100 width=3D637 style=3D'height:30.0pt;width:47=
8pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font8">Service providers</font><font class=3D"font9"> can use th=
e </font><font
  class=3D"font13">Expectations Matrix</font><font class=3D"font9"> as they=
 respond
  to financial institution questionnaires and define control objectives for
  audits and assessments.</font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl100 width=3D637 style=3D'height:30.0pt;width:47=
8pt'>&middot;<font
  class=3D"font12">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </font>=
<font
  class=3D"font8">Audit and assessment organizations</font><font class=3D"f=
ont9">
  can use the </font><font class=3D"font13">Expectations Matrix</font><font
  class=3D"font9"> as they work with financial institutions and service pro=
viders
  to verify and test controls.</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl97 width=3D637 style=3D'height:30.0pt;width:478=
pt'
  x:str=3D"For more information about the BITS IT Service Provider Expectat=
ions Matrix, contact Faith Boettger, Senior Consultant, faith@fsround.org. =
">For
  more information about the BITS IT Service Provider Expectations Matrix,
  contact Faith Boettger, Senior Consultant, faith@fsround.org.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 width=3D637 style=3D'height:15.0pt;width:478=
pt'
  x:str=3D"About BITS ">About BITS<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl97 width=3D637 style=3D'height:90.0pt;width:47=
8pt'>BITS
  was created in 1996 to foster the growth and development of electronic
  financial services and e-commerce for the benefit of financial institutio=
ns
  and their customers. A nonprofit industry consortium that shares membersh=
ip
  with The Financial Services Roundtable, BITS seeks to sustain consumer
  confidence and trust by ensuring the security, privacy and integrity of
  financial transactions. BITS works as a strategic brain trust to provide
  intellectual capital and address emerging issues where financial services,
  technology and commerce intersect. For more information about BITS, go to
  www.bitsinfo.org.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl99 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'
  x:str=3D"BITS ">BITS<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>1001
  Pennsylvania Avenue NW</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Suite
  500 South</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>Washington,
  DC 20004</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>(202)
  289-4322</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl96 width=3D637 style=3D'height:15.0pt;width:478=
pt'>www.bitsinfo.org</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl97 style=3D'height:15.0pt'></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D637 style=3D'width:478pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet003.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet003.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(2);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>14</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>21</x:ActiveRow>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D567 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:425pt'>
 <col width=3D291 style=3D'mso-width-source:userset;mso-width-alt:10642;wid=
th:218pt'>
 <col width=3D276 style=3D'mso-width-source:userset;mso-width-alt:10093;wid=
th:207pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 colspan=3D2 width=3D567 style=3D'height:15.0=
pt;mso-ignore:
  colspan;width:425pt'>BITS IT Service Providers Working Group Security
  Assessments Project Team</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl87 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>IT
  Service Providers Working Group Co-Chairs</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>Lari
  Sue Taylor, FleetBoston Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>Viveca
  Ware, Independent Community Bankers of America</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 style=3D'height:15.0pt'>Security Assessments=
 Project
  Team Chair</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'>Wayne
  Browning, FleetBoston Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl89 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl86 style=3D'height:15.0pt'>BITS Staff</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'>Faith Boettger, Seni=
or
  Consultant</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'>John Carlson, Senior=
 Director</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl88 style=3D'height:15.0pt'>Margaret Prior, Admi=
nistrative
  Assistant</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl90 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl90 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl87 colspan=3D2 style=3D'height:15.0pt;mso-ignor=
e:colspan'
  x:str=3D"Security Assessments Project Team Participating Institutions ">S=
ecurity
  Assessments Project Team Participating Institutions<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>America&#8217;s
  Community Bankers</td>
  <td class=3Dxl92>Lauritzen Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>American
  Bankers Association</td>
  <td class=3Dxl92>M&amp;T Bank Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Association
  for Payment Clearing Services</td>
  <td class=3Dxl92>Marshall &amp; Ilsley Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Bank of
  America Corporation</td>
  <td class=3Dxl92>MBNA Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl93 width=3D291 style=3D'height:15.0pt;width:218=
pt'>The Bank
  of New York Company, Inc./</td>
  <td class=3Dxl92>Mellon Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl93 width=3D291 style=3D'height:15.0pt;width:218=
pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Pershing LLC<f=
ont
  class=3D"font23"><span style=3D'mso-spacerun:yes'>&nbsp;</span></font></t=
d>
  <td class=3Dxl92>National City Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>BANK ONE
  CORPORATION</td>
  <td class=3Dxl92 x:str=3D"Nationwide ">Nationwide<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>BB&amp;T
  Corporation</td>
  <td class=3Dxl92>The PNC Financial Services Group, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Capital
  One Financial Corporation</td>
  <td class=3Dxl92>Providian Financial Group, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Citigroup
  Inc.</td>
  <td class=3Dxl92>Regions Financial Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Comerica
  Incorporated</td>
  <td class=3Dxl92>Sky Financial Group, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Compass
  Bancshares, Inc.</td>
  <td class=3Dxl92>SouthTrust Bank</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Credit
  Suisse First Boston</td>
  <td class=3Dxl92>State Farm Insurance Companies</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Credit
  Union National Association</td>
  <td class=3Dxl92>SunTrust Banks, Inc.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>First
  Virginia Banks, Inc.</td>
  <td class=3Dxl92>U.S. Department of Navy CIO</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Fifth
  Third Bancorp</td>
  <td class=3Dxl92>Visa U.S.A.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>FleetBoston
  Financial Corporation</td>
  <td class=3Dxl92>Wachovia Corporation</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Fortis,
  Inc./Assurant Group</td>
  <td class=3Dxl92>Wells Fargo &amp; Company</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>The
  Goldman Sachs Group, Inc.</td>
  <td class=3Dxl92></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>Harris
  Bankcorp, Inc.</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'
  x:str=3D"HSBC USA, Inc.  ">HSBC USA, Inc.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl91 width=3D291 style=3D'height:30.0pt;width:218=
pt'>Independent
  Community Bankers of America</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>J.P.
  Morgan Chase &amp; Co.</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl91 width=3D291 style=3D'height:15.0pt;width:218=
pt'>LaSalle
  Bank Corporation</td>
  <td></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl93 style=3D'height:15.0pt'></td>
  <td></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D291 style=3D'width:218pt'></td>
  <td width=3D276 style=3D'width:207pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet004.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet004.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(3);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>1</x:ActiveRow>
    <x:ActiveCol>3</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1329 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:998pt'>
 <col class=3Dxl36 width=3D50 style=3D'mso-width-source:userset;mso-width-a=
lt:1828;
 width:38pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D307 style=3D'mso-width-source:userset;mso-width-alt:11227;wid=
th:230pt'>
 <col width=3D150 style=3D'mso-width-source:userset;mso-width-alt:5485;widt=
h:113pt'>
 <col width=3D119 style=3D'mso-width-source:userset;mso-width-alt:4352;widt=
h:89pt'>
 <col width=3D48 style=3D'mso-width-source:userset;mso-width-alt:1755;width=
:36pt'>
 <col width=3D46 style=3D'mso-width-source:userset;mso-width-alt:1682;width=
:35pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:987'>
 <col width=3D53 style=3D'mso-width-source:userset;mso-width-alt:1938;width=
:40pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:2340'>
 <col width=3D64 span=3D2 style=3D'width:48pt'>
 <col width=3D300 style=3D'mso-width-source:userset;mso-width-alt:10971;wid=
th:225pt'>
 <col width=3D64 style=3D'width:48pt'>
 <tr height=3D25 style=3D'mso-height-source:userset;height:18.75pt'>
  <td colspan=3D3 height=3D25 class=3Dxl114 width=3D421 style=3D'height:18.=
75pt;
  width:316pt'>BITS IT Service Provider Expectations Matrix</td>
  <td width=3D150 style=3D'width:113pt'></td>
  <td width=3D119 style=3D'width:89pt'></td>
  <td width=3D48 style=3D'width:36pt'></td>
  <td width=3D46 style=3D'width:35pt'></td>
  <td width=3D0></td>
  <td width=3D53 style=3D'width:40pt'></td>
  <td width=3D0></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D300 style=3D'width:225pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D90 style=3D'mso-height-source:userset;height:67.5pt'>
  <td height=3D90 class=3Dxl36 style=3D'height:67.5pt'></td>
  <td colspan=3D2 class=3Dxl125 width=3D371 style=3D'width:278pt'>Note:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>For each step, select if it is
  applicable for your assigned domains.<span style=3D'mso-spacerun:yes'>&nb=
sp;
  </span>Add additional steps, if necessary, under each topic area.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Please add any other steps not c=
overed
  by one of the topics under the &quot;other&quot; tab.</td>
  <td colspan=3D11 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D13 rowspan=3D3 height=3D50 class=3Dxl116 width=3D1265 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:37.5pt;width:950=
pt'>1.0
  SECURITY POLICY:<span style=3D'mso-spacerun:yes'>&nbsp; </span><font
  class=3D"font9">A set of rules and procedures regulating the use of
  information, including its processing, storage, distribution, and
  presentation. The set of laws, rules, and practices that regulate how an
  organization manages, protects, and distributes sensitive information.</f=
ont></td>
  <td rowspan=3D3 class=3Dxl30 width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D0 style=3D'display:none;mso-height-source:userset;mso-height-=
alt:
  300'>
 </tr>
 <tr height=3D0 style=3D'display:none;mso-height-source:userset;mso-height-=
alt:
  270'>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D13 height=3D45 class=3Dxl55 width=3D1265 style=3D'border-ri=
ght:1.0pt solid black;
  height:33.75pt;width:950pt'>Security Policy High-Level Expectation: <font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;</span>All vendors=
 and
  Service Providers should have and adhere to a written and comprehensive s=
et
  of information security policy documents, which act as the rules and
  guidelines for dealing with the protection of information and information
  assets.</font></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D13 height=3D45 class=3Dxl55 width=3D1265 style=3D'border-ri=
ght:1.0pt solid black;
  height:33.75pt;width:950pt'>Documents that May Be Requested:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Security p=
olicy,
  document update schedule, audit report of security policy. (If unable to
  provide a copy of the security policies, please provide a list of the are=
as
  covered by the policies, e.g., table of contents.)</font></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl82 style=3D'height:30.0pt;border-top:none'>&nbs=
p;</td>
  <td colspan=3D3 class=3Dxl48 width=3D521 style=3D'width:391pt'>Questions/=
Control
  Activities</td>
  <td class=3Dxl48 width=3D119 style=3D'border-top:none;width:89pt'>Applica=
ble Domain</td>
  <td class=3Dxl49 width=3D48 style=3D'border-top:none;width:36pt'>Yes</td>
  <td colspan=3D2 class=3Dxl49 width=3D46 style=3D'width:35pt'>No</td>
  <td colspan=3D2 class=3Dxl49 width=3D53 style=3D'width:40pt'>NA</td>
  <td colspan=3D3 class=3Dxl49 width=3D428 style=3D'border-right:1.0pt soli=
d black;
  width:321pt'>Comments/Testing Performed and Results</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td height=3D59 class=3Dxl83 style=3D'height:44.25pt'>1.1.</td>
  <td colspan=3D3 class=3Dxl62 width=3D521 style=3D'border-left:none;width:=
391pt'>Does
  the Service Provider have formal and documented security policies, standa=
rds,
  plans and procedures?</td>
  <td class=3Dxl62 width=3D119 style=3D'border-left:none;width:89pt'>(Hosti=
ng,
  Storage, and/or Managed Services)</td>
  <td class=3Dxl75 width=3D48 style=3D'border-left:none;width:36pt'>&nbsp;<=
/td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.1=
.2</td>
  <td colspan=3D3 class=3Dxl59 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"Are they available for review?  ">Are they available for review?=
<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl83 style=3D'height:33.0pt;border-top:none'>1.1.=
3</td>
  <td colspan=3D3 class=3Dxl59 width=3D521 style=3D'border-left:none;width:=
391pt'>If
  the documents are not available for review, is there an independent audit
  report of security policy available?</td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl83 style=3D'height:33.75pt;border-top:none'>1.2=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"Indicate if the policy includes the following components and lis=
t the date management last approved the policy, if applicable.  ">Indicate
  if the policy includes the following components and list the date managem=
ent
  last approved the policy, if applicable.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td colspan=3D8 class=3Dxl63 width=3D575 style=3D'border-left:none;width:=
432pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.1.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Information
  classification policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.2.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Data-handling
  policy (to include secure use, storage and destruction of sensitive data)=
</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.3.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Internet/intranet
  access and use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.4.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Authorized
  use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.5.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Acceptable
  use policy (to include restriction on using corporate computing resources=
 for
  purposes other than business, e.g., personal email, browsing)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.6.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Email
  use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.7.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Encryption
  policy and standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl83 style=3D'height:34.5pt;border-top:none'>1.2.=
8.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  configuration standards for networks, operating systems, applications and
  desktops</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.1</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Security
  patches</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.2</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Vulnerability
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.3</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Default
  passwords</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.4</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Registry
  settings</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.5</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Version
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.6</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>File
  directory rights and permissions</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.7</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Prevention
  and detection of computer viruses</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.8</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Secure
  configuration</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl83 style=3D'height:34.5pt;border-top:none'>1.2.=
9</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Software
  development, acquisition and installation policy and procedures, including
  change management (guidelines)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.10</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Change
  control policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.11</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>User
  system access policies (Principle of Least Privilege) (See 7.1)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.12</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  incident management policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.13</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Network
  security/access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.14</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Application
  security standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.15</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Remote
  access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.16</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Privacy
  policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.17</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Personnel
  security and termination policies</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl83 style=3D'height:32.25pt;border-top:none'>1.2=
.18</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Physical
  access policy and procedures (e.g., hardware, software, storage media, pa=
per
  recorders, photo copiers, mail, fax, facilities)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl83 style=3D'height:17.25pt;border-top:none'>1.2=
.19</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Computer
  and communications system use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.20</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  awareness program</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl83 style=3D'height:17.25pt;border-top:none'>1.2=
.21</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Disaster
  recovery and business continuity plans</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl83 style=3D'height:30.75pt;border-top:none'>1.3=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Does
  the information security policy have an owner who is responsible for poli=
cy
  maintenance?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.4=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Are
  the policy documents updated regularly?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.5=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"How often is the policy communicated to staff?  ">How often is t=
he
  policy communicated to staff?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl83 style=3D'height:15.0pt;border-top:none'>1.5.=
1</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to offsite locations?  ">Is the policy
  communicated to offsite locations?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl83 style=3D'height:45.0pt;border-top:none'>1.5.=
2</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to dependent Service Providers or are=
 the Service Providers' policies reviewed by the Receiving Company? ">Is
  the policy communicated to dependent Service Providers or are the Service
  Providers' policies reviewed by the Receiving Company?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D27 style=3D'mso-height-source:userset;height:20.25pt'>
  <td height=3D27 class=3Dxl83 style=3D'height:20.25pt;border-top:none'>1.5=
.3</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'>Is
  the policy communicated to contract employees?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.6=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Is
  the adoption of the policy monitored and enforced?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.6=
.1</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Are
  consequences for non-compliance with policies clearly documented?</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D50 style=3D'width:38pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D307 style=3D'width:230pt'></td>
  <td width=3D150 style=3D'width:113pt'></td>
  <td width=3D119 style=3D'width:89pt'></td>
  <td width=3D48 style=3D'width:36pt'></td>
  <td width=3D46 style=3D'width:35pt'></td>
  <td width=3D0></td>
  <td width=3D53 style=3D'width:40pt'></td>
  <td width=3D0></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D300 style=3D'width:225pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet005.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet005.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(4);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>1</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
    <x:RangeSelection>$B$2:$D$2</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1329 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:998pt'>
 <col class=3Dxl36 width=3D50 style=3D'mso-width-source:userset;mso-width-a=
lt:1828;
 width:38pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D307 style=3D'mso-width-source:userset;mso-width-alt:11227;wid=
th:230pt'>
 <col width=3D150 style=3D'mso-width-source:userset;mso-width-alt:5485;widt=
h:113pt'>
 <col width=3D119 style=3D'mso-width-source:userset;mso-width-alt:4352;widt=
h:89pt'>
 <col width=3D48 style=3D'mso-width-source:userset;mso-width-alt:1755;width=
:36pt'>
 <col width=3D46 style=3D'mso-width-source:userset;mso-width-alt:1682;width=
:35pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:987'>
 <col width=3D53 style=3D'mso-width-source:userset;mso-width-alt:1938;width=
:40pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:2340'>
 <col width=3D64 span=3D2 style=3D'width:48pt'>
 <col width=3D300 style=3D'mso-width-source:userset;mso-width-alt:10971;wid=
th:225pt'>
 <col width=3D64 style=3D'width:48pt'>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl82 width=3D50 style=3D'height:30.0pt;width:38pt=
'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl48 width=3D521 style=3D'width:391pt'>Questions/=
Control
  Activities</td>
  <td class=3Dxl48 width=3D119 style=3D'width:89pt'>Applicable Domain</td>
  <td class=3Dxl49 width=3D48 style=3D'width:36pt'>Yes</td>
  <td colspan=3D2 class=3Dxl49 width=3D46 style=3D'width:35pt'>No</td>
  <td colspan=3D2 class=3Dxl49 width=3D53 style=3D'width:40pt'>NA</td>
  <td colspan=3D3 class=3Dxl49 width=3D428 style=3D'border-right:1.0pt soli=
d black;
  width:321pt'>Comments/Testing Performed and Results</td>
  <td class=3Dxl30 width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td height=3D59 class=3Dxl83 style=3D'height:44.25pt'>1.1.</td>
  <td colspan=3D3 class=3Dxl62 width=3D521 style=3D'border-left:none;width:=
391pt'>Does
  the Service Provider have formal and documented security policies, standa=
rds,
  plans and procedures?</td>
  <td class=3Dxl62 width=3D119 style=3D'border-left:none;width:89pt'>(Hosti=
ng,
  Storage, and/or Managed Services)</td>
  <td class=3Dxl75 width=3D48 style=3D'border-left:none;width:36pt'>&nbsp;<=
/td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.1=
.2</td>
  <td colspan=3D3 class=3Dxl59 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"Are they available for review?  ">Are they available for review?=
<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl83 style=3D'height:33.0pt;border-top:none'>1.1.=
3</td>
  <td colspan=3D3 class=3Dxl59 width=3D521 style=3D'border-left:none;width:=
391pt'>If
  the documents are not available for review, is there an independent audit
  report of security policy available?</td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl83 style=3D'height:33.75pt;border-top:none'>1.2=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"Indicate if the policy includes the following components and lis=
t the date management last approved the policy, if applicable.  ">Indicate
  if the policy includes the following components and list the date managem=
ent
  last approved the policy, if applicable.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td colspan=3D8 class=3Dxl63 width=3D575 style=3D'border-left:none;width:=
432pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.1.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Information
  classification policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.2.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Data-handling
  policy (to include secure use, storage and destruction of sensitive data)=
</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.3.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Internet/intranet
  access and use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.4.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Authorized
  use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.5.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Acceptable
  use policy (to include restriction on using corporate computing resources=
 for
  purposes other than business, e.g., personal email, browsing)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.6.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Email
  use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.7.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Encryption
  policy and standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl83 style=3D'height:34.5pt;border-top:none'>1.2.=
8.</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  configuration standards for networks, operating systems, applications and
  desktops</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.1</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Security
  patches</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.2</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Vulnerability
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.3</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Default
  passwords</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.4</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Registry
  settings</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.5</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Version
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.6</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>File
  directory rights and permissions</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.7</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Prevention
  and detection of computer viruses</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.8.8</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D457 style=3D'border-left:none;width:=
343pt'>Secure
  configuration</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl83 style=3D'height:34.5pt;border-top:none'>1.2.=
9</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Software
  development, acquisition and installation policy and procedures, including
  change management (guidelines)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.10</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Change
  control policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.11</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>User
  system access policies (Principle of Least Privilege) (See 7.1)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.12</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  incident management policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.13</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Network
  security/access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.14</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Application
  security standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.15</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Remote
  access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.16</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Privacy
  policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.17</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Personnel
  security and termination policies</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl83 style=3D'height:32.25pt;border-top:none'>1.2=
.18</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Physical
  access policy and procedures (e.g., hardware, software, storage media, pa=
per
  recorders, photo copiers, mail, fax, facilities)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl83 style=3D'height:17.25pt;border-top:none'>1.2=
.19</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Computer
  and communications system use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.2=
.20</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Security
  awareness program</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl83 style=3D'height:17.25pt;border-top:none'>1.2=
.21</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Disaster
  recovery and business continuity plans</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl83 style=3D'height:30.75pt;border-top:none'>1.3=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Does
  the information security policy have an owner who is responsible for poli=
cy
  maintenance?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.4=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Are
  the policy documents updated regularly?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.5=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'
  x:str=3D"How often is the policy communicated to staff?  ">How often is t=
he
  policy communicated to staff?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl83 style=3D'height:15.0pt;border-top:none'>1.5.=
1</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to offsite locations?  ">Is the policy
  communicated to offsite locations?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl83 style=3D'height:45.0pt;border-top:none'>1.5.=
2</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to dependent Service Providers or are=
 the Service Providers' policies reviewed by the Receiving Company? ">Is
  the policy communicated to dependent Service Providers or are the Service
  Providers' policies reviewed by the Receiving Company?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D27 style=3D'mso-height-source:userset;height:20.25pt'>
  <td height=3D27 class=3Dxl83 style=3D'height:20.25pt;border-top:none'>1.5=
.3</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'>Is
  the policy communicated to contract employees?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.6=
.</td>
  <td colspan=3D3 class=3Dxl63 width=3D521 style=3D'border-left:none;width:=
391pt'>Is
  the adoption of the policy monitored and enforced?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl83 style=3D'height:15.75pt;border-top:none'>1.6=
.1</td>
  <td colspan=3D3 class=3Dxl60 width=3D521 style=3D'border-left:none;width:=
391pt'>Are
  consequences for non-compliance with policies clearly documented?</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D50 style=3D'width:38pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D307 style=3D'width:230pt'></td>
  <td width=3D150 style=3D'width:113pt'></td>
  <td width=3D119 style=3D'width:89pt'></td>
  <td width=3D48 style=3D'width:36pt'></td>
  <td width=3D46 style=3D'width:35pt'></td>
  <td width=3D0></td>
  <td width=3D53 style=3D'width:40pt'></td>
  <td width=3D0></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D300 style=3D'width:225pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet006.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet006.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(5);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>12</x:ActiveRow>
    <x:ActiveCol>2</x:ActiveCol>
    <x:RangeSelection>$C$13:$E$13</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1620 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1216pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col class=3Dxl36 width=3D50 style=3D'mso-width-source:userset;mso-width-a=
lt:1828;
 width:38pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D307 style=3D'mso-width-source:userset;mso-width-alt:11227;wid=
th:230pt'>
 <col width=3D377 style=3D'mso-width-source:userset;mso-width-alt:13787;wid=
th:283pt'>
 <col width=3D119 style=3D'mso-width-source:userset;mso-width-alt:4352;widt=
h:89pt'>
 <col width=3D48 style=3D'mso-width-source:userset;mso-width-alt:1755;width=
:36pt'>
 <col width=3D46 style=3D'mso-width-source:userset;mso-width-alt:1682;width=
:35pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:987'>
 <col width=3D53 style=3D'mso-width-source:userset;mso-width-alt:1938;width=
:40pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:2340'>
 <col width=3D64 span=3D2 style=3D'width:48pt'>
 <col width=3D300 style=3D'mso-width-source:userset;mso-width-alt:10971;wid=
th:225pt'>
 <col width=3D64 style=3D'width:48pt'>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 width=3D64 style=3D'height:30.0pt;width:48pt'></td>
  <td class=3Dxl82 width=3D50 style=3D'width:38pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl48 width=3D748 style=3D'width:561pt'>Questions/=
Control
  Activities</td>
  <td class=3Dxl48 width=3D119 style=3D'width:89pt'>Applicable Domain</td>
  <td class=3Dxl49 width=3D48 style=3D'width:36pt'>Yes</td>
  <td colspan=3D2 class=3Dxl49 width=3D46 style=3D'width:35pt'>No</td>
  <td colspan=3D2 class=3Dxl49 width=3D53 style=3D'width:40pt'>NA</td>
  <td colspan=3D3 class=3Dxl49 width=3D428 style=3D'border-right:1.0pt soli=
d black;
  width:321pt'>Comments/Testing Performed and Results</td>
  <td class=3Dxl30 width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D30 style=3D'mso-height-source:userset;height:22.5pt'>
  <td height=3D30 align=3Dright style=3D'height:22.5pt' x:num>1</td>
  <td class=3Dxl83>1.1.</td>
  <td colspan=3D3 class=3Dxl62 width=3D748 style=3D'border-left:none;width:=
561pt'>Service
  Provider have formal and documented security policies, standards, plans a=
nd
  procedures?</td>
  <td class=3Dxl62 width=3D119 style=3D'border-left:none;width:89pt'>(Hosti=
ng,
  Storage, and/or Managed Services)</td>
  <td class=3Dxl75 width=3D48 style=3D'border-left:none;width:36pt'>&nbsp;<=
/td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>2</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.1.2</td>
  <td colspan=3D3 class=3Dxl62 width=3D748 style=3D'border-left:none;width:=
561pt'>Service
  Provider documented security policies, standards, plans and procedures are
  available for review</td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 align=3Dright style=3D'height:33.0pt' x:num>3</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.1.3</td>
  <td colspan=3D3 class=3Dxl59 width=3D748 style=3D'border-left:none;width:=
561pt'>There
  is an independent audit report of security policy available of the Service
  Provider documented security policies, standards, plans and procedures and
  they are available for review</td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 align=3Dright style=3D'height:17.25pt' x:num>4</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.</td>
  <td colspan=3D3 class=3Dxl63 width=3D748 style=3D'border-left:none;width:=
561pt'
  x:str=3D"The policy includes the following components and is listing the =
date management last approved the policy.  ">The
  policy includes the following components and is listing the date manageme=
nt
  last approved the policy.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</s=
pan></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td colspan=3D8 class=3Dxl63 width=3D575 style=3D'border-left:none;width:=
432pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>5</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.1.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Information
  classification policy is documented and dated as to the last management
  approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>6</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.2.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Data-handling
  policy (to include secure use, storage and destruction of sensitive data)=
</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>7</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.3.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Internet/intranet
  access and use policy<span style=3D'mso-spacerun:yes'>&nbsp; </span>is
  documented and dated as to the last management approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>8</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.4.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Authorized
  use policy is documented and dated as to the last management approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>9</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.5.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Acceptable
  use policy (to include restriction on using corporate computing resources=
 for
  purposes other than business, e.g., personal email, browsing) is document=
ed
  and dated as to the last management approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>10</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.6.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Email
  use policy<span style=3D'mso-spacerun:yes'>&nbsp; </span>is documented and
  dated as to the last management approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>11</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.7.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Encryption
  policy and standards is documented and dated as to the last management
  approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 align=3Dright style=3D'height:34.5pt' x:num>1</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Security
  configuration standards for networks, operating systems, applications and
  desktops<span style=3D'mso-spacerun:yes'>&nbsp; </span>is documented and =
dated
  as to the last management approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.1</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>Security
  patches</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.2</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>Vulnerability
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.3</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>Default
  passwords</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.4</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>Registry
  settings</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.5</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>Version
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.6</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>File
  directory rights and permissions</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.7</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>Prevention
  and detection of computer viruses</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.8</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D684 style=3D'border-left:none;width:=
513pt'>Secure
  configuration</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 style=3D'height:34.5pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.9</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Software
  development, acquisition and installation policy and procedures, including
  change management (guidelines)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.10</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Change
  control policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.11</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>User
  system access policies (Principle of Least Privilege) (See 7.1)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.12</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Security
  incident management policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.13</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Network
  security/access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.14</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Application
  security standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.15</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Remote
  access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.16</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Privacy
  policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.17</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Personnel
  security and termination policies</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 style=3D'height:32.25pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.18</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Physical
  access policy and procedures (e.g., hardware, software, storage media, pa=
per
  recorders, photo copiers, mail, fax, facilities)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 style=3D'height:17.25pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.19</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Computer
  and communications system use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.20</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Security
  awareness program</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 style=3D'height:17.25pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.21</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Disaster
  recovery and business continuity plans</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 style=3D'height:30.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.3.</td>
  <td colspan=3D3 class=3Dxl63 width=3D748 style=3D'border-left:none;width:=
561pt'>Does
  the information security policy have an owner who is responsible for poli=
cy
  maintenance?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.4.</td>
  <td colspan=3D3 class=3Dxl63 width=3D748 style=3D'border-left:none;width:=
561pt'>Are
  the policy documents updated regularly?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.</td>
  <td colspan=3D3 class=3Dxl63 width=3D748 style=3D'border-left:none;width:=
561pt'
  x:str=3D"How often is the policy communicated to staff?  ">How often is t=
he
  policy communicated to staff?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 style=3D'height:15.0pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.1</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to offsite locations?  ">Is the policy
  communicated to offsite locations?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 style=3D'height:45.0pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.2</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to dependent Service Providers or are=
 the Service Providers' policies reviewed by the Receiving Company? ">Is
  the policy communicated to dependent Service Providers or are the Service
  Providers' policies reviewed by the Receiving Company?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D27 style=3D'mso-height-source:userset;height:20.25pt'>
  <td height=3D27 style=3D'height:20.25pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.3</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'>Is
  the policy communicated to contract employees?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.6.</td>
  <td colspan=3D3 class=3Dxl63 width=3D748 style=3D'border-left:none;width:=
561pt'>Is
  the adoption of the policy monitored and enforced?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 style=3D'height:15.75pt'></td>
  <td class=3Dxl83 style=3D'border-top:none'>1.6.1</td>
  <td colspan=3D3 class=3Dxl60 width=3D748 style=3D'border-left:none;width:=
561pt'>Are
  consequences for non-compliance with policies clearly documented?</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D50 style=3D'width:38pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D307 style=3D'width:230pt'></td>
  <td width=3D377 style=3D'width:283pt'></td>
  <td width=3D119 style=3D'width:89pt'></td>
  <td width=3D48 style=3D'width:36pt'></td>
  <td width=3D46 style=3D'width:35pt'></td>
  <td width=3D0></td>
  <td width=3D53 style=3D'width:40pt'></td>
  <td width=3D0></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D300 style=3D'width:225pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet007.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet007.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(6);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1714 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1286pt'>
 <col width=3D64 span=3D2 style=3D'width:48pt'>
 <col class=3Dxl36 width=3D50 style=3D'mso-width-source:userset;mso-width-a=
lt:1828;
 width:38pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D307 style=3D'mso-width-source:userset;mso-width-alt:11227;wid=
th:230pt'>
 <col width=3D407 style=3D'mso-width-source:userset;mso-width-alt:14884;wid=
th:305pt'>
 <col width=3D119 style=3D'mso-width-source:userset;mso-width-alt:4352;widt=
h:89pt'>
 <col width=3D48 style=3D'mso-width-source:userset;mso-width-alt:1755;width=
:36pt'>
 <col width=3D46 style=3D'mso-width-source:userset;mso-width-alt:1682;width=
:35pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:987'>
 <col width=3D53 style=3D'mso-width-source:userset;mso-width-alt:1938;width=
:40pt'>
 <col width=3D0 style=3D'display:none;mso-width-source:userset;mso-width-al=
t:2340'>
 <col width=3D64 span=3D2 style=3D'width:48pt'>
 <col width=3D300 style=3D'mso-width-source:userset;mso-width-alt:10971;wid=
th:225pt'>
 <col width=3D64 style=3D'width:48pt'>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 align=3Dright width=3D64 style=3D'height:15.75pt;width:48=
pt' x:num>0</td>
  <td align=3Dright width=3D64 style=3D'width:48pt' x:num>1</td>
  <td class=3Dxl168 width=3D50 style=3D'width:38pt'>1.1.2</td>
  <td colspan=3D3 class=3Dxl62 width=3D778 style=3D'border-left:none;width:=
583pt'>Service
  Provider documented security policies, standards, plans and procedures are
  available for review</td>
  <td class=3Dxl59 width=3D119 style=3D'border-left:none;width:89pt'>&nbsp;=
</td>
  <td class=3Dxl75 width=3D48 style=3D'border-left:none;width:36pt'>&nbsp;<=
/td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30 width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 align=3Dright style=3D'height:33.0pt' x:num>1</td>
  <td align=3Dright x:num>2</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.1.3</td>
  <td colspan=3D3 class=3Dxl59 width=3D778 style=3D'border-left:none;width:=
583pt'>There
  is <font class=3D"font30">no</font><font class=3D"font8"> independent aud=
it
  report of security policy available of the Service Provider documented
  security policies, standards, plans and procedures and they are available=
 for
  review</font></td>
  <td class=3Dxl59 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>2</td>
  <td align=3Dright x:num>3</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.1.</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Information
  classification policy is <font class=3D"font14">NOT</font><font class=3D"=
font9">
  documented and dated as to the last management approval</font></td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>3</td>
  <td align=3Dright x:num>4</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.2.</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Data-handling
  policy (to include secure use, storage and destruction of sensitive data)=
</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>4</td>
  <td align=3Dright x:num>5</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.3.</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Internet/intranet
  access and use policy is <font class=3D"font14">NOT</font><font class=3D"=
font9">
  documented and dated as to the last management approval</font></td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>5</td>
  <td align=3Dright x:num>6</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.4.</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Authorized
  use policy is <font class=3D"font14">NOT</font><font class=3D"font9"> docu=
mented
  and dated as to the last management approval</font></td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>6</td>
  <td align=3Dright x:num>7</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.5.</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Acceptable
  use policy (to include restriction on using corporate computing resources=
 for
  purposes other than business, e.g., personal email, browsing) is document=
ed
  and dated as to the last management approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>7</td>
  <td align=3Dright x:num>8</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.6.</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Email
  use policy is <font class=3D"font14">NOT</font><font class=3D"font9"> doc=
umented
  and dated as to the last management approval</font></td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>8</td>
  <td align=3Dright x:num>9</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.7.</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Encryption
  policy and standards is documented and dated as to the last management
  approval</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>9</td>
  <td align=3Dright x:num>10</td>
  <td class=3Dxl168 style=3D'border-top:none'>1.2.8.1</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>Security
  patches configuration standards for networks, operating systems, applicat=
ions
  and desktops is documented and dated as to the last management approval</=
td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>11</td>
  <td align=3Dright x:num>11</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.2</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>Vulnerability
  management configuration standards for networks, operating systems,
  applications and desktops is documented and dated as to the last manageme=
nt
  approval</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>12</td>
  <td align=3Dright x:num>12</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.3</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>Default
  passwords</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 align=3Dright style=3D'height:15.75pt' x:num>13</td>
  <td align=3Dright x:num>13</td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.4</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>Registry
  settings</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.5</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>Version
  management</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.6</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>File
  directory rights and permissions</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.7</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>Prevention
  and detection of computer viruses</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.8.8</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl63 width=3D714 style=3D'border-left:none;width:=
535pt'>Secure
  configuration</td>
  <td class=3Dxl78 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl78 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 colspan=3D2 style=3D'height:34.5pt;mso-ignore:colspan'></=
td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.9</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Software
  development, acquisition and installation policy and procedures, including
  change management (guidelines)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.10</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Change
  control policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.11</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>User
  system access policies (Principle of Least Privilege) (See 7.1)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.12</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Security
  incident management policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.13</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Network
  security/access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.14</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Application
  security standards</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.15</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Remote
  access policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.16</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Privacy
  policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.17</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Personnel
  security and termination policies</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 colspan=3D2 style=3D'height:32.25pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.18</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Physical
  access policy and procedures (e.g., hardware, software, storage media, pa=
per
  recorders, photo copiers, mail, fax, facilities)</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 colspan=3D2 style=3D'height:17.25pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.19</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Computer
  and communications system use policy</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.20</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Security
  awareness program</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 colspan=3D2 style=3D'height:17.25pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.2.21</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Disaster
  recovery and business continuity plans</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 colspan=3D2 style=3D'height:30.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.3.</td>
  <td colspan=3D3 class=3Dxl63 width=3D778 style=3D'border-left:none;width:=
583pt'>Does
  the information security policy have an owner who is responsible for poli=
cy
  maintenance?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.4.</td>
  <td colspan=3D3 class=3Dxl63 width=3D778 style=3D'border-left:none;width:=
583pt'>Are
  the policy documents updated regularly?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D46 style=3D'border-left:none;width:3=
5pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl75 width=3D53 style=3D'border-left:none;width:4=
0pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl63 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.</td>
  <td colspan=3D3 class=3Dxl63 width=3D778 style=3D'border-left:none;width:=
583pt'
  x:str=3D"How often is the policy communicated to staff?  ">How often is t=
he
  policy communicated to staff?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 colspan=3D2 style=3D'height:15.0pt;mso-ignore:colspan'></=
td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.1</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to offsite locations?  ">Is the policy
  communicated to offsite locations?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 colspan=3D2 style=3D'height:45.0pt;mso-ignore:colspan'></=
td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.2</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'
  x:str=3D"Is the policy communicated to dependent Service Providers or are=
 the Service Providers' policies reviewed by the Receiving Company? ">Is
  the policy communicated to dependent Service Providers or are the Service
  Providers' policies reviewed by the Receiving Company?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D27 style=3D'mso-height-source:userset;height:20.25pt'>
  <td height=3D27 colspan=3D2 style=3D'height:20.25pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.5.3</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D307 style=3D'border-top:none;border-left:none;wi=
dth:230pt'>Is
  the policy communicated to contract employees?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl37></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.6.</td>
  <td colspan=3D3 class=3Dxl63 width=3D778 style=3D'border-left:none;width:=
583pt'>Is
  the adoption of the policy monitored and enforced?</td>
  <td class=3Dxl63 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 colspan=3D2 style=3D'height:15.75pt;mso-ignore:colspan'><=
/td>
  <td class=3Dxl83 style=3D'border-top:none'>1.6.1</td>
  <td colspan=3D3 class=3Dxl60 width=3D778 style=3D'border-left:none;width:=
583pt'>Are
  consequences for non-compliance with policies clearly documented?</td>
  <td class=3Dxl60 width=3D119 style=3D'border-top:none;border-left:none;wi=
dth:89pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D48 style=3D'border-top:none;border-left:none;wid=
th:36pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D46 style=3D'border-top:none;border-left:none;wid=
th:35pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td class=3Dxl64 width=3D53 style=3D'border-top:none;border-left:none;wid=
th:40pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D0 style=3D'border-top:none;border-left:none'>&nb=
sp;</td>
  <td colspan=3D3 class=3Dxl75 width=3D428 style=3D'border-left:none;width:=
321pt'>&nbsp;</td>
  <td class=3Dxl30></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D50 style=3D'width:38pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D307 style=3D'width:230pt'></td>
  <td width=3D407 style=3D'width:305pt'></td>
  <td width=3D119 style=3D'width:89pt'></td>
  <td width=3D48 style=3D'width:36pt'></td>
  <td width=3D46 style=3D'width:35pt'></td>
  <td width=3D0></td>
  <td width=3D53 style=3D'width:40pt'></td>
  <td width=3D0></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D300 style=3D'width:225pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet008.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet008.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(7);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>21</x:ActiveRow>
    <x:RangeSelection>$A$22:$L$22</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1615 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1212pt'>
 <col width=3D64 span=3D6 style=3D'width:48pt'>
 <col width=3D134 style=3D'mso-width-source:userset;mso-width-alt:4900;widt=
h:101pt'>
 <col width=3D68 style=3D'mso-width-source:userset;mso-width-alt:2486;width=
:51pt'>
 <col width=3D64 span=3D3 style=3D'width:48pt'>
 <col width=3D486 style=3D'mso-width-source:userset;mso-width-alt:17773;wid=
th:365pt'>
 <col width=3D287 style=3D'mso-width-source:userset;mso-width-alt:10496;wid=
th:215pt'>
 <col width=3D64 style=3D'width:48pt'>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td colspan=3D12 rowspan=3D3 height=3D60 class=3Dxl116 width=3D1264 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:45.0pt;width:949=
pt'>2.0
  Organizational Security: <font class=3D"font9">One or more security rules,
  procedures, practices, or guidelines imposed by an organization upon its
  operations. The set of laws, rules, and practices that regulate how an
  organization manages, protects, and distributes sensitive information.</f=
ont></td>
  <td width=3D287 style=3D'width:215pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr class=3Dxl38 height=3D40 style=3D'mso-height-source:userset;height:30.=
0pt'>
  <td height=3D40 colspan=3D2 class=3Dxl38 style=3D'height:30.0pt;mso-ignor=
e:colspan'></td>
 </tr>
 <tr height=3D0 style=3D'display:none;mso-height-source:userset;mso-height-=
alt:
  330'>
  <td height=3D0 colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D71 style=3D'mso-height-source:userset;height:53.25pt'>
  <td colspan=3D12 height=3D71 class=3Dxl55 width=3D1264 style=3D'border-ri=
ght:1.0pt solid black;
  height:53.25pt;width:949pt'>Documents that May Be Requested:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Information
  security organization chart (including where information security resides=
 in
  the organization), roles and responsibilities, job descriptions, overview=
 of
  access administration process and procedures, third-party security
  reviews/assessments and SAS 70 or SAS 70-equivalent reports, due diligence
  performed on third parties, performance reporting for third parties, legal
  clauses and templates</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D12 height=3D45 class=3Dxl55 width=3D1264 style=3D'border-ri=
ght:1.0pt solid black;
  height:33.75pt;width:949pt'>2.1 Information Security Infrastructure
  High-Level Expectation:<span style=3D'mso-spacerun:yes'>&nbsp; </span><fo=
nt
  class=3D"font9">A management framework should be established to initiate =
and
  control the implementation of information security within the Service
  Provider&#8217;s organization.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D35 style=3D'mso-height-source:userset;height:26.25pt'>
  <td height=3D35 class=3Dxl54 style=3D'height:26.25pt;border-top:none'>&nb=
sp;</td>
  <td colspan=3D6 class=3Dxl48 width=3D454 style=3D'width:341pt'>Questions/=
Control
  Activities</td>
  <td class=3Dxl48 width=3D68 style=3D'border-top:none;width:51pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D486 style=3D'border-top:none;width:365pt'>Commen=
ts/Testing
  Performed and Results</td>
  <td class=3Dxl44></td>
  <td class=3Dxl45 width=3D64 style=3D'width:48pt'>&nbsp;</td>
 </tr>
 <tr class=3Dxl38 height=3D44 style=3D'mso-height-source:userset;height:33.=
0pt'>
  <td height=3D44 class=3Dxl103 width=3D64 style=3D'height:33.0pt;width:48p=
t' x:num>2.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'>Who
  is/are the person(s) responsible for information security?</td>
  <td class=3Dxl62 width=3D68 style=3D'border-left:none;width:51pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D44 style=3D'mso-height-source:userset;height:33.=
0pt'>
  <td height=3D44 class=3Dxl103 width=3D64 style=3D'height:33.0pt;border-to=
p:none;
  width:48pt' x:num>2.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Are
  there written job descriptions for all information technology/security job
  functions?</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D44 style=3D'mso-height-source:userset;height:33.=
0pt'>
  <td height=3D44 class=3Dxl103 width=3D64 style=3D'height:33.0pt;border-to=
p:none;
  width:48pt' x:num>2.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'
  x:str=3D"Please document the following roles and responsibilities, indica=
ting if the responsibilities are outsourced: ">Please
  document the following roles and responsibilities, indicating if the
  responsibilities are outsourced:<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.1</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  user administration</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Application
  security</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  management</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.4</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Governance
  of security functions</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.5</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  policy and standards creation/enforcement</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D58 style=3D'mso-height-source:userset;height:43.=
5pt'>
  <td height=3D58 class=3Dxl80 width=3D64 style=3D'height:43.5pt;border-top=
:none;
  width:48pt'>2.3.6</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  incident response planning and management (including public relations in
  cases where a security breach becomes a public issue)</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.7</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  awareness and training</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.8</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Vulnerability
  management/threat assessment</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.9</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Security
  event monitoring</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.10</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Physical
  security</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl80 width=3D64 style=3D'height:15.75pt;border-to=
p:none;
  width:48pt'>2.3.11</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Architecture
  and engineering of security infrastructure</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr class=3Dxl38 height=3D22 style=3D'mso-height-source:userset;height:16.=
5pt'>
  <td height=3D22 class=3Dxl80 width=3D64 style=3D'height:16.5pt;border-top=
:none;
  width:48pt'>2.3.12</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Disaster
  recovery and business continuity planning</td>
  <td class=3Dxl63 width=3D68 style=3D'border-top:none;border-left:none;wid=
th:51pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl38 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D12 height=3D50 class=3Dxl112 width=3D1264 style=3D'height:3=
7.5pt;
  width:949pt'>2.2 Security of Third-Party Access High-Level Expectation:<s=
pan
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Service Pr=
oviders
  should have and adhere to a policy to control third-party access to the
  organization&#8217;s information or information system, including physical
  and logical access.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D64 style=3D'mso-height-source:userset;height:48.0pt'>
  <td height=3D64 class=3Dxl80 width=3D64 style=3D'height:48.0pt;border-top=
:none;
  width:48pt'>2.2.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'>What
  are the procedures and policies to control third-party access to informai=
ton
  and information systems, including physical and logical access?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl80 width=3D64 style=3D'height:30.75pt;border-to=
p:none;
  width:48pt'>2.2.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Does
  the policy apply to contract employees (offsite and onsite), dependent
  Service Providers, etc.?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D56 style=3D'mso-height-source:userset;height:42.0pt'>
  <td height=3D56 class=3Dxl80 width=3D64 style=3D'height:42.0pt;border-top=
:none;
  width:48pt'>2.2.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Have
  any third-party service providers been granted remote access privileges a=
nd
  is there a business requirement for such remote access?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D33 style=3D'mso-height-source:userset;height:24.75pt'>
  <td height=3D33 class=3Dxl80 width=3D64 style=3D'height:24.75pt;border-to=
p:none;
  width:48pt'>2.2.4</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'
  x:str=3D"Are requirements, reviews and approvals of access documented? ">=
Are
  requirements, reviews and approvals of access documented?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D12 height=3D50 class=3Dxl112 width=3D1264 style=3D'height:3=
7.5pt;
  width:949pt'>2.3 Outsourcing High-Level Expectation:<font class=3D"font9"=
><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>The Service Provider should have=
 a
  process to review all dependent Service Providers&#8217; security policies
  and procedures to ensure that appropriate security language is incorporat=
ed
  into all third-party agreements.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Service Providers should ensure that affected financial institutio=
ns
  are aware of any outsourcing and that any required due diligence is
  completed.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'>Are
  dependent providers engaged in providing any services related to the Rece=
iver
  Company's outsourced application, service or system?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.1.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If YES, what
  services are being performed by dependent providers?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D79 style=3D'mso-height-source:userset;height:59.25pt'>
  <td height=3D79 class=3Dxl80 width=3D64 style=3D'height:59.25pt;border-to=
p:none;
  width:48pt'>2.3.1.2</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Does the Servi=
ce
  Provider review of the dependent Service Provider(s) include due diligenc=
e,
  risk assessment, contract review, site visits, disaster recovery/business
  continuity planning and ongoing performance monitoring?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl81 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.2</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Do
  Service Provider's contracts with third parties incorporate appropriate
  elements of the information security policy requirements and document rol=
es
  and responsibilities?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.2.1</td>
  <td colspan=3D6 class=3Dxl62 width=3D454 style=3D'border-left:none;width:=
341pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp; </span><font class=3D"font9=
"><span
  style=3D'mso-spacerun:yes'>&nbsp;</span>If YES, how is compliance demonst=
rated?</font></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.3</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Please
  describe the Service Provider&#8217;s service record and experience with
  dependent Service Providers.</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl80 width=3D64 style=3D'height:46.5pt;border-top=
:none;
  width:48pt'>2.3.4</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Do
  the Service Provider&#8217;s procedures include issuing notification
  procedures, communication procedures, and contingency plans for dependent
  Service Providers?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl80 width=3D64 style=3D'height:30.75pt;border-to=
p:none;
  width:48pt'>2.3.5</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Has
  interoperability security between Service Provider and dependent providers
  been ensured?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D27 style=3D'mso-height-source:userset;height:20.25pt'>
  <td height=3D27 class=3Dxl80 width=3D64 style=3D'height:20.25pt;border-to=
p:none;
  width:48pt'>2.3.6</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'
  x:str=3D"Please explain how terminations are handled.  ">Please explain h=
ow
  terminations are handled.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</s=
pan></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D49 style=3D'mso-height-source:userset;height:36.75pt'>
  <td height=3D49 class=3Dxl80 width=3D64 style=3D'height:36.75pt;border-to=
p:none;
  width:48pt'>2.3.7</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Has a
  process been established to review invoices (i.e., ensure proper charges =
for
  services rendered, rate changes, and new service charges)?<font class=3D"=
font10">&nbsp;</font></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D84 style=3D'mso-height-source:userset;height:63.0pt'>
  <td height=3D84 class=3Dxl80 width=3D64 style=3D'height:63.0pt;border-top=
:none;
  width:48pt'>2.3.8</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Has a
  process been established to review service provider/subcontractor perform=
ance
  relative to service-level agreements, determine if contractual terms and
  conditions are being met and the need for revisions to service-level
  agreements is evaluated?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D36 style=3D'mso-height-source:userset;height:27.0pt'>
  <td height=3D36 class=3Dxl80 width=3D64 style=3D'height:27.0pt;border-top=
:none;
  width:48pt'>2.3.9</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Are
  appropriate documents and records maintained regarding contract complianc=
e,
  revision and dispute resolution?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D122 style=3D'mso-height-source:userset;height:91.5pt'>
  <td height=3D122 class=3Dxl80 width=3D64 style=3D'height:91.5pt;border-to=
p:none;
  width:48pt'>2.3.10</td>
  <td colspan=3D6 class=3Dxl63 width=3D454 style=3D'border-left:none;width:=
341pt'>Does
  the service agreement include a clear specification of all relevant terms,
  conditions, responsibilities, and liabilities of both parties?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Examples include:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>compliance, audit reporting, on-=
site
  review, notification of change/risk, SLAs, data ownership, insurance,
  liability, privacy, dispute resolution, problem reporting and escalation
  procedures, ongoing monitoring, and requirements for service providers
  outside of the United States?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D134 style=3D'width:101pt'></td>
  <td width=3D68 style=3D'width:51pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D486 style=3D'width:365pt'></td>
  <td width=3D287 style=3D'width:215pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet009.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet009.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(8);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>1</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>6</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1310 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:983pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D574 style=3D'mso-width-source:userset;mso-width-alt:20992;wid=
th:431pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D416 style=3D'mso-width-source:userset;mso-width-alt:15213;wid=
th:312pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 rowspan=3D3 height=3D124 class=3Dxl116 width=3D1310 style=
=3D'border-bottom:
  1.0pt solid black;height:93.0pt;width:983pt'>3.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>ASSET CLASSIFICATION AND CONTROL=
:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Asset
  Classification and Control addresses the ability of the security
  infrastructure to protect organizational assets, including:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><br>
    Accountability and inventory &#8211; Mechanisms to maintain an accurate
  inventory of assets and establish ownership and stewardship of all assets.
  <br>
    Classification &#8211; Mechanisms to classify assets based on business
  impact, including privacy violations. &middot;&nbsp; <br>
    Labeling &#8211; Labeling standards unambiguously brand assets to their
  classification.&nbsp; <br>
    Handling &#8211; Handling standards, including introduction, transfer,
  removal, and disposal of all assets, are based on asset classification.</=
font></td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
 </tr>
 <tr height=3D90 style=3D'mso-height-source:userset;height:67.5pt'>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td colspan=3D7 height=3D21 class=3Dxl55 width=3D1310 style=3D'height:15.=
75pt;
  width:983pt'>Document that May Be Requested:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Asset cont=
rol
  policy</font></td>
 </tr>
 <tr height=3D47 style=3D'mso-height-source:userset;height:35.25pt'>
  <td colspan=3D7 height=3D47 class=3Dxl55 width=3D1310 style=3D'height:35.=
25pt;
  width:983pt'>3.1 Accountability For Assets High-Level Expectation:<font
  class=3D"font9"> Service Providers should have in place an appropriate as=
set
  control policy structure, including appropriate ownership, management,
  licensing and other controls that address the following asset types:
  information assets, software assets, physical assets, and services.</font=
></td>
 </tr>
 <tr class=3Dxl24 height=3D21 style=3D'mso-height-source:userset;height:15.=
75pt'>
  <td height=3D21 class=3Dxl47 style=3D'height:15.75pt;border-top:none'>&nb=
sp;</td>
  <td class=3Dxl48 width=3D574 style=3D'border-top:none;width:431pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl49 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl50 width=3D416 style=3D'border-top:none;width:312pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt'>3.1.1</td>
  <td class=3Dxl62 width=3D574 style=3D'border-left:none;width:431pt'>Does =
the
  Service Provider have asset control and security policies and procedures?=
</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
2</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Is
  an inventory of assets maintained for hardware, software, information ass=
ets,
  physical assets, and services?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>3.1.=
3</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'
  x:str=3D"Are levels of security maintained for different types of assets?=
  ">Are
  levels of security maintained for different types of assets?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 class=3Dxl61 style=3D'height:12.75pt;border-top:none'>3.1=
.4</td>
  <td rowspan=3D2 class=3Dxl63 width=3D574 style=3D'border-top:none;width:4=
31pt'
  x:str=3D"Who/what functions have been assigned accountability for managin=
g the policy by each type of asset? ">Who/what
  functions have been assigned accountability for managing the policy by ea=
ch
  type of asset?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D30 style=3D'mso-height-source:userset;height:22.5pt'>
  <td height=3D30 class=3Dxl61 style=3D'height:22.5pt;border-top:none'><span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>3.1.=
4.1</td>
  <td class=3Dxl78 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>How
  often is accountability reviewed and updated?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
5</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Are
  there procedures and controls for how equipment and/or software is purcha=
sed?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
6</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Are
  there procedures and controls for disposal and reuse of equipment and
  software?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
6</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Are
  there procedures and controls for ordering new hardware assets, software
  assets, physical assets and services?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
7</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Does
  information technology (IT) management authorize all hardware acquisition=
s?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.1.=
8</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Do
  the server site, network database and application management teams coordi=
nate
  the installation and testing of all hardware changes?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'><span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D76 style=3D'mso-height-source:userset;height:57.0pt'>
  <td colspan=3D7 height=3D76 class=3Dxl112 width=3D1310 style=3D'height:57=
.0pt;
  width:983pt'>3.2 Information Classification High-Level Expectation:<font
  class=3D"font9"> The information and materials processed, stored or trans=
mitted
  by the Service Provider on behalf of the Receiver Company should be handl=
ed
  in accordance with the classification (e.g., confidential, sensitive, pub=
lic)
  of the information as stated in applicable laws, regulations and Receiver
  Company&#8217;s policies and standards as communicated to the Service
  Provider. The Service Provider&#8217;s physical and electronic procedures
  should maintain the Receiver Company&#8217;s defined classification of the
  information assets.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></=
font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.2.=
1</td>
  <td class=3Dxl62 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Does
  the Service Provider&#8217;s program support information classifications
  defined by the Receiver Company?</td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>3.2.=
2</td>
  <td class=3Dxl63 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Are
  there any inconsistencies between definitions of various classes of
  information between the Service Provider and the Receiving Company?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>3.2.=
3</td>
  <td class=3Dxl64 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Are
  there any applicable laws, regulations or policies that could impact the
  Service Provider&#8217;s ability to comply with the Receiver Company
  information classification requirements?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td height=3D59 class=3Dxl61 style=3D'height:44.25pt;border-top:none'>3.2=
.4</td>
  <td class=3Dxl64 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'
  x:str=3D"Are there Service Provider procedures for labeling printed repor=
ts, screen displays, magnetic media, and electronic messages and file trans=
fers for Receiver Company data? ">Are
  there Service Provider procedures for labeling printed reports, screen
  displays, magnetic media, and electronic messages and file transfers for
  Receiver Company data?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D81 style=3D'mso-height-source:userset;height:60.75pt'>
  <td height=3D81 class=3Dxl61 style=3D'height:60.75pt;border-top:none'>3.2=
.5</td>
  <td class=3Dxl64 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'>Are
  there information-handling procedures for copying, storage, packaging for
  internal mail, packaging for external mail, electronic transmission, spok=
en
  transmission, wireless and cell phone communication, and destruction based
  upon the information classification requirements?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>3.2.=
6</td>
  <td class=3Dxl64 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'
  x:str=3D"Are there Service Provider procedures for handling backups?  ">A=
re
  there Service Provider procedures for handling backups?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>3.2.=
6.1</td>
  <td class=3Dxl64 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Are they maint=
ained
  onsite or offsite?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>3.2=
.6.2</td>
  <td class=3Dxl64 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'
  x:str=3D"     If maintained offsite, does the contract or SLA with the st=
orage vendor contain written information classification requirements, secur=
ity responsibilities, and liabilities?  "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If maintained
  offsite, does the contract or SLA with the storage vendor contain written
  information classification requirements, security responsibilities, and
  liabilities?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D48 style=3D'mso-height-source:userset;height:36.0pt'>
  <td height=3D48 class=3Dxl61 style=3D'height:36.0pt;border-top:none'>3.2.=
6.3</td>
  <td class=3Dxl64 width=3D574 style=3D'border-top:none;border-left:none;wi=
dth:431pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>As backups age=
 off
  the schedule, are they securely destroyed or is the media reused?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D574 style=3D'width:431pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D416 style=3D'width:312pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet010.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet010.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(9);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>7</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1542 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1156pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D475 style=3D'mso-width-source:userset;mso-width-alt:17371;wid=
th:356pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D299 style=3D'mso-width-source:userset;mso-width-alt:10934;wid=
th:224pt'>
 <col width=3D64 span=3D7 style=3D'width:48pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 rowspan=3D3 height=3D52 class=3Dxl116 width=3D1094 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:39.0pt;width:820=
pt'>4.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>PERSONNEL SECURITY:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Personnel includes employees,
  consultants, vendors, part-time employees, etc.</td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D7 style=3D'height:12.75pt;mso-ignore:colspan'><=
/td>
 </tr>
 <tr height=3D18 style=3D'height:13.5pt'>
  <td height=3D18 colspan=3D7 style=3D'height:13.5pt;mso-ignore:colspan'></=
td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl55 width=3D1094 style=3D'border-rig=
ht:1.0pt solid black;
  height:33.75pt;width:820pt'>Documents that May Be Requested:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Employment=
 policy,
  non-disclosure agreements, background check documents for staff supporting
  very sensitive services or data, copy of insurance declaration pages</fon=
t></td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td colspan=3D7 height=3D41 class=3Dxl55 width=3D1094 style=3D'border-rig=
ht:1.0pt solid black;
  height:30.75pt;width:820pt'>4.1 Security in Job Definition and Resourcing
  High-Level Expectation: <font class=3D"font9">Service Providers should ha=
ve and
  adhere to policies and procedures in place to perform background checks f=
or
  those individuals who will be administering systems or have access to
  Receiver Company information.<span style=3D'mso-spacerun:yes'>&nbsp; </sp=
an>These
  policies and procedures should ensure that personnel responsible for desi=
gn,
  development, implementation and operation are qualified to fulfill their
  responsibilities.</font></td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl54 style=3D'height:27.75pt;border-top:none'>&nb=
sp;</td>
  <td class=3Dxl48 width=3D475 style=3D'border-top:none;width:356pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D299 style=3D'border-top:none;width:224pt'>Testing
  Performed and Results</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl84 style=3D'height:29.25pt'>4.1.1</td>
  <td class=3Dxl85 width=3D475 style=3D'border-left:none;width:356pt'>What =
are the
  Service Provider's policies and procedures for pre-employment screening?<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl61 style=3D'height:29.25pt;border-top:none'>4.1=
.2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  there any limitations on resources that are available for non-U.S. based
  locations?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  the policy and procedure include:</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.1</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"     Criminal background checks (local, state, national, and int=
ernational)? "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Criminal backg=
round
  checks (local, state, national, and international)?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Credit backgro=
und
  checks?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Reference chec=
ks?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Drug screening=
?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
3.5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Biometric scans
  (e.g., fingerprint, retinal scans)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl61 style=3D'height:29.25pt;border-top:none'>4.1=
.4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  criminal, credit or reference checks performed on permanent employees,
  part-time employees, consultants, and temporary and contract employees?</=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D28 style=3D'mso-height-source:userset;height:21.0pt'>
  <td height=3D28 class=3Dxl61 style=3D'height:21.0pt;border-top:none'>4.1.=
5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  the policy require periodic reviews based upon differing levels of access=
?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D33 style=3D'mso-height-source:userset;height:24.75pt'>
  <td height=3D33 class=3Dxl61 style=3D'height:24.75pt;border-top:none'>4.1=
.6</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  employees sign and abide by a non-disclosure or confidentiality agreement=
?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.1=
.7</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  terms and conditions of employment clearly state information security
  responsibilities?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>4.1.=
8</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Is the annual rate of personnel turnover for both exempt and non=
-exempt workers at a level consistent with the industry?  ">Is
  the annual rate of personnel turnover for both exempt and non-exempt work=
ers
  at a level consistent with the industry?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
9</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Are employees bonded?  ">Are employees bonded?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.1.=
9.1</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If so, what le=
vel
  and type?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>4.1=
.10</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>What
  industry or security certifications are held by Service Provider employees
  (e.g., CISA, CISSP, TISCA)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D65 style=3D'mso-height-source:userset;height:48.75pt'>
  <td colspan=3D7 height=3D65 class=3Dxl112 width=3D1094 style=3D'height:48=
.75pt;
  width:820pt'>4.2 User Training High-Level Expectation:<font class=3D"font=
9">
  All employees of the Service Provider&#8217;s organization, and where
  relevant, third-party users, should be made aware of information-security
  threats and concerns, and should be equipped to support the organizational
  security policy in the course of their normal work. Users should be train=
ed
  in information-security procedures and the correct use of
  information-processing facilities to minimize possible security threats.<=
/font></td>
  <td colspan=3D7 class=3Dxl44 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.2=
.1</td>
  <td class=3Dxl65 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  the Service Provider have formal Security Training and Awareness Programs=
<font
  class=3D"font9">?</font></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>4.2.=
2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  all new employees (permanent, temporary or contract) receive
  information-security awareness presentations and information-security
  training as appropriate?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  security training and awareness include a testing component?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>4.2=
.4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Please describe any training that should be provided by the serv=
ice provider to customer personnel.  ">Please
  describe any training that should be provided by the service provider to
  customer personnel.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>4.2=
.5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  there any user groups or forums in which customer personnel should
  participate?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D49 style=3D'mso-height-source:userset;height:36.75pt'>
  <td height=3D49 class=3Dxl61 style=3D'height:36.75pt;border-top:none'>4.2=
.6</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  the security training commensurate with levels of responsibilities and
  access, and does it include security policies, procedures and processes?<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
7</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  employees specifically made aware of &#8220;social engineering&#8221; ris=
ks?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>4.2.=
8</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Does security awareness training cover the employee&#8217;s resp=
onsibility to report security incidents?  ">Does
  security awareness training cover the employee&#8217;s responsibility to
  report security incidents?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</=
span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
9</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  security training repeated at regular intervals for all staff?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
10</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  security training performed on a recurring basis?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.2=
.11</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  resources available for employees on information-security training (e.g.,
  website for security and security issues, brochures, etc.)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl61 style=3D'height:29.25pt;border-top:none'>4.2=
.12</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Do all employees periodically sign a certification document atte=
sting to their understanding and awareness of the policy and procedures?  "=
>Do
  all employees periodically sign a certification document attesting to the=
ir
  understanding and awareness of the policy and procedures?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.2.=
12.1</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>How
  is it enforced?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>4.2=
.13</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>For
  job functions designated in the escalation line for incident response, are
  staff fully aware of their responsibilities and involved in testing those
  plans?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>4.2=
.14</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>For
  job functions designated in the escalation line for disaster recovery pla=
ns,
  are staff fully aware of their responsibilities and involved in testing t=
hose
  plans?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D86 style=3D'mso-height-source:userset;height:64.5pt'>
  <td colspan=3D7 height=3D86 class=3Dxl104 width=3D1094 style=3D'height:64=
.5pt;
  width:820pt'>4.3 Responding to Security Incidents and Software Malfunctio=
ns
  High-Level Expectation:<font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Incidents affecting security sho=
uld be
  reported through appropriate management channels as quickly as possible. =
All
  employees and contractors should be made aware of the procedures for
  reporting different types of incidents (security breach, threats,
  vulnerabilities, or security-related software malfunction) that might hav=
e an
  impact on the Receiver Company&#8217;s operations.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>All employees and contractors sh=
ould
  be required to report any observed or suspected threats, vulnerabilities,=
 or
  incidents as quickly as possible to the designated point of contact.</fon=
t></td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
1</td>
  <td class=3Dxl65 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Do
  the Service Provider&#8217;s corporate policy and procedures include resp=
onse
  for security breaches, threats, vulnerabilities and software malfunctions=
?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
2</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Does
  the Service Provider have SLAs or contracts in place with business partne=
rs,
  vendors, customers, etc. that document security responsibilities and
  liabilities in case of a breach?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
3</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Does the Service Provider have insurance coverage?  ">Does the S=
ervice
  Provider have insurance coverage?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
3.1</td>
  <td class=3Dxl78 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"If so, what type(s) and limits? ">If so, what type(s) and limits=
?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
4</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Are there provisions in the policy to cover information-security=
 incidents that occur outside of normal business hours or is the same polic=
y invoked irrespective of time of day?  ">Are
  there provisions in the policy to cover information-security incidents th=
at
  occur outside of normal business hours or is the same policy invoked
  irrespective of time of day?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
5</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Is
  the execution of responsibilities during an incident tested?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>4.3.=
6</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  information-security incidents reported and tracked within the Service
  Provider company, and communicated to the Receiver Company and regulators=
?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
7</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'
  x:str=3D"Is there a continuous improvement process in place for the polic=
y? ">Is
  there a continuous improvement process in place for the policy?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>4.3.=
8</td>
  <td class=3Dxl64 width=3D475 style=3D'border-top:none;border-left:none;wi=
dth:356pt'>Are
  there disciplinary processes in place for employees who violate the polic=
y?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D14 style=3D'height:12.75pt;mso-ignore:colspan'>=
</td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D14 style=3D'height:12.75pt;mso-ignore:colspan'>=
</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D475 style=3D'width:356pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D299 style=3D'width:224pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet011.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet011.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(10);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>3</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>32</x:ActiveRow>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1207 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:905pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D400 style=3D'mso-width-source:userset;mso-width-alt:14628;wid=
th:300pt'>
 <col width=3D72 style=3D'mso-width-source:userset;mso-width-alt:2633;width=
:54pt'>
 <col width=3D64 span=3D3 style=3D'width:48pt'>
 <col width=3D479 style=3D'mso-width-source:userset;mso-width-alt:17517;wid=
th:359pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl116 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>5. PHYSICAL AND ENVIRONMENTAL SECURITY: <font
  class=3D"font9">Physical and Environmental Security control addresses risk
  inherent to organizational premises, including:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Location &#8211; Organizational premises shou=
ld
  be analyzed for environmental hazards.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl132 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Physical security perimeter &#8211; The
  premises&#8217; security perimeter should be clearly defined and physical=
ly
  sound. A given premises may have multiple zones based on classification l=
evel
  or other organizational requirements.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Access control &#8211; Ingress/egress locatio=
ns
  in the physical security perimeter should have appropriate entry/exit
  controls commensurate with their classification level.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Equipment &#8211; Equipment should be sited
  within the premises to ensure physical and environmental integrity and
  availability.</td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl108 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:905pt'>Asset transfer &#8211; Mechanisms should exis=
t to
  track entry and exit of assets through the security perimeter.</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl129 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:905pt'>General &#8211; Policies and standards, such as
  utilization of shredding equipment, secure storage, and &quot;clean
  desk&quot; principles, should exist to govern operational security within=
 the
  workspace.</td>
 </tr>
 <tr height=3D29 style=3D'mso-height-source:userset;height:21.75pt'>
  <td colspan=3D7 height=3D29 class=3Dxl55 width=3D1207 style=3D'border-rig=
ht:1.0pt solid black;
  height:21.75pt;width:905pt'>Documents that May Be Requested:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Floor plan=
, badge
  control policy, physical access logging policy, copy of insurance declara=
tion
  pages</font></td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td colspan=3D7 height=3D59 class=3Dxl105 width=3D1207 style=3D'border-ri=
ght:1.0pt solid black;
  height:44.25pt;width:905pt'>5.1 Secure Areas High-Level Expectation:<font
  class=3D"font9"> Business information processing, storage or distribution
  facilities should be housed in secure areas, protected by a defined secur=
ity
  perimeter, with appropriate security barriers and entry controls. Facilit=
ies
  should be physically protected from unauthorized access, damage and
  interference.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Access should=
 be
  logged and logs should be securely maintained.</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl54 style=3D'height:15.0pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D400 style=3D'border-top:none;width:300pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D72 style=3D'border-top:none;width:54pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D479 style=3D'border-top:none;width:359pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt'>5.1.1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-left:none;width:300pt'>Are t=
here
  policies and procedures in place for protecting and monitoring the physic=
al
  infrastructure for staff and assets where business information processing,
  storage or distribution is performed?</td>
  <td class=3Dxl62 width=3D72 style=3D'border-left:none;width:54pt'>&nbsp;<=
/td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider own each of the facilities at which Receiver Company
  work is being conducted?<span style=3D'mso-spacerun:yes'>&nbsp; </span>(If
  leased, please document when the lease expires.)</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is the physical perimeter adequately protected for each location=
 where Receiver Company work is being conducted? ">Is
  the physical perimeter adequately protected for each location where Recei=
ver
  Company work is being conducted?<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D100 style=3D'height:75.0pt'>
  <td height=3D100 class=3Dxl61 style=3D'height:75.0pt;border-top:none'>5.1=
.4</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there any specific issues related to external physical risks=
 such as nuclear power facilities, chemical plants or other hazardous manuf=
acturing facilities, natural gas, petroleum or other pipelines or pipeline =
processing facilities, or natural disasters such as flooding, tornadoes or =
earthquakes? ">Are
  there any specific issues related to external physical risks such as nucl=
ear
  power facilities, chemical plants or other hazardous manufacturing
  facilities, natural gas, petroleum or other pipelines or pipeline process=
ing
  facilities, or natural disasters such as flooding, tornadoes or
  earthquakes?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
4.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, please describe these issues.</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>5.1.=
5</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Where facilities are shared, please indicate the number of tenan=
t-occupied floors.  Describe the building tenants with common walls, floors=
 or ceilings that are contiguous to areas occupied by the Service Provider.=
  ">Where
  facilities are shared, please indicate the number of tenant-occupied
  floors.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Describe the buildi=
ng
  tenants with common walls, floors or ceilings that are contiguous to areas
  occupied by the Service Provider.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
6</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there any specific issues related to war, terrorism, or othe=
r regional risks?  ">Are
  there any specific issues related to war, terrorism, or other regional
  risks?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
6.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, please describe these issues.</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
7</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is identification of buildings or facilities kept to a minimum? =
">Is
  identification of buildings or facilities kept to a minimum?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
8</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there an isolated delivery or loading area?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
8.1</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>If YES, is access to the delivery or loading area controlled or
  monitored?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
9</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Please describe how the data center is secured. ">Please describ=
e how
  the data center is secured.<span style=3D'mso-spacerun:yes'>&nbsp;</span>=
</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
10</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are the controls employed for the data center the same as other =
facilities?   ">Are
  the controls employed for the data center the same as other facilities?<s=
pan
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
10.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"If NO, please describe how these controls are different from con=
trols protecting other facilities. ">If
  NO, please describe how these controls are different from controls protec=
ting
  other facilities.<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"How is the security of the data center verified? ">How is the se=
curity
  of the data center verified?<span style=3D'mso-spacerun:yes'>&nbsp;</span=
></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.1</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"      Please supply the results of the two most recent tests. ">=
<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Please s=
upply
  the results of the two most recent tests.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
11.2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"      How is access to sites, buildings and rooms restricted to =
authorized personnel only (e.g.,   badge, reception desk, guards, escort, l=
ocks, and biometrics)? "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>How is a=
ccess
  to sites, buildings and rooms restricted to authorized personnel only
  (e.g.,<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>badge, recepti=
on
  desk, guards, escort, locks, and biometrics)?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.3</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are dual controls employed for access? ">Are dual controls emplo=
yed
  for access?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
11.4</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Do
  access requests for the card access system, including changes, require
  written approval of the site operations manager?</td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.5</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are all access points monitored in &#8220;real time&#8221;?   ">=
Are
  all access points monitored in &#8220;real time&#8221;?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
11.6</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are visitors to the premises escorted at all times? ">Are visito=
rs to
  the premises escorted at all times?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
11.7</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are associates, contractors, visitors or temporary employees phy=
sically differentiated while on premises? ">Are
  associates, contractors, visitors or temporary employees physically
  differentiated while on premises?<span style=3D'mso-spacerun:yes'>&nbsp;<=
/span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
12</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Describe
  the process for monitoring building safety, personnel and visitor access,
  including reviewing access logs, procedures followed during business and
  outside of business hours, etc.</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>5.1.=
13</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  do security personnel monitor the facility, including such things as hour=
s of
  coverage, use of employees or contractors, different types of badges, and
  whether the area is patrolled at regular intervals?</td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
14</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>For
  how long are logs securely maintained?</td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
15</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there security cameras, motion detectors and alarms in place=
 and monitored?    ">Are
  there security cameras, motion detectors and alarms in place and
  monitored?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;</span=
></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
15.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"If YES, please describe their monitoring, management and mainten=
ance support. ">If
  YES, please describe their monitoring, management and maintenance
  support.<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
16</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is environmental protection equipment (fire suppression, firepro=
ofing, water flooding, heat/air conditioning, power supply) installed, test=
ed, and monitored?     ">Is
  environmental protection equipment (fire suppression, fireproofing, water
  flooding, heat/air conditioning, power supply) installed, tested, and
  monitored?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
16.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"If YES, what is the schedule for testing this equipment?   ">If =
YES,
  what is the schedule for testing this equipment?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
17</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the data center (i.e., server/computer room) have temperature and humidity
  control systems that are separate from the rest of the facility?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
17.1</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there separate and independent power supplies? ">Are there
  separate and independent power supplies?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
17.1.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  tests performed to verify the power supply (i.e., building or data center
  power down tests)?</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
17.2</td>
  <td class=3Dxl60 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are failover systems or data centers employed?     ">Are failover
  systems or data centers employed?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl60 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
17.2.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is an inventory of &#8220;hot swaps&#8221; maintained for critic=
al equipment?   ">Is
  an inventory of &#8220;hot swaps&#8221; maintained for critical
  equipment?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.1.=
18</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is access to areas where work is performed for Receiver Company =
physically separated from that of other receiving companies? ">Is
  access to areas where work is performed for Receiver Company physically
  separated from that of other receiving companies?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.1.=
19</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Describe
  insurance policies that are in place.</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.1.=
20</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the contract for facilities insurance sufficient to mitigate any compromi=
se
  of physical security?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl104 width=3D1207 style=3D'height:33=
.75pt;
  width:905pt'>5.2 Equipment Security High-Level Expectation:<font class=3D=
"font9">
  Equipment should be physically protected from security threats and
  environmental hazards in order to prevent loss, damage or compromise of
  assets and interruption to business activities.</font></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.2.=
1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  there policies/procedures in place for protecting and monitoring the
  equipment for security threats or environmental hazards?</td>
  <td class=3Dxl62 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.2.=
2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  controls or safeguards in place to prevent unauthorized interception or
  damage to network, power or telecommunications cabling?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  emissions (wire in conduit, monitors, wireless broadcasts) shielded to
  prevent compromise of network security?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.2.=
4</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  all phone/cable closets secured?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D140 style=3D'height:105.0pt'>
  <td height=3D140 class=3Dxl61 style=3D'height:105.0pt;border-top:none'>5.=
2.5</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  continuous power supply equipment installed and maintained for critical
  systems in support of the service required for the Receiver Company?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>How long does the UPS (uninterru=
ptible
  power supply) system last?<span style=3D'mso-spacerun:yes'>&nbsp; </span>=
How
  long does it take for the generators to start up and take over?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>How long will the generators run
  without refueling?<span style=3D'mso-spacerun:yes'>&nbsp; </span>What ste=
ps
  have been taken to ensure timely refueling?<font class=3D"font13"><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></font></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
6</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is all production server/computer equipment located in the data =
center (i.e., server/computer room)?  ">Is
  all production server/computer equipment located in the data center (i.e.,
  server/computer room)?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span=
></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.2.=
7</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  all equipment (hardware, cables) labeled or otherwise identified?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
8</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"What equipment is located or held off-site (e.g., data centers, =
third-party support, employees with laptop computers)?  ">What
  equipment is located or held off-site (e.g., data centers, third-party
  support, employees with laptop computers)?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
8.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  policies, procedures and safeguards in place that apply to off-site
  equipment?</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>5.2.=
9</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Can maintenance of equipment be performed remotely?  ">Can maint=
enance
  of equipment be performed remotely?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.2.=
9.1</td>
  <td class=3Dxl78 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, please describe who has access and how this access is secured and
  controlled.</td>
  <td class=3Dxl78 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>5.2.=
10</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>When
  disposing of or reusing equipment (hardware and software), are there
  procedures that govern the secure destruction of any data held on such
  equipment?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td colspan=3D7 height=3D44 class=3Dxl104 width=3D1207 style=3D'height:33=
.0pt;
  width:905pt'>5.3 General Controls High-Level Expectation: <font class=3D"=
font9">Information
  and information-processing facilities should be protected from disclosure=
 to,
  modification of, or theft by unauthorized persons. Controls should be in
  place to minimize loss or damage.</font></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>5.3.=
1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the policy to secure information consistent with information-security
  classification (e.g., locked cabinets, document control, and clear
  screen/screen timeout policies)?</td>
  <td class=3Dxl62 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.3.=
2</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  there procedures in place to document authorized removal of property for
  business purposes?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>5.3.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  there procedures in place to prevent the unauthorized removal of property=
?</td>
  <td class=3Dxl63 width=3D72 style=3D'border-top:none;border-left:none;wid=
th:54pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D400 style=3D'width:300pt'></td>
  <td width=3D72 style=3D'width:54pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D479 style=3D'width:359pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet012.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet012.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(11);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:RangeSelection>$A$1:$G$1</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1259 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:944pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col class=3Dxl38 width=3D400 style=3D'mso-width-source:userset;mso-width-=
alt:14628;
 width:300pt'>
 <col width=3D84 style=3D'mso-width-source:userset;mso-width-alt:3072;width=
:63pt'>
 <col width=3D64 span=3D3 style=3D'width:48pt'>
 <col width=3D519 style=3D'mso-width-source:userset;mso-width-alt:18980;wid=
th:389pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl135 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>6.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>COMMUNICATIONS AND OPERATIONS MANAGEMENT:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span><font class=3D"font9">Communicat=
ion and
  Operations Management addresses an organization's ability to ensure corre=
ct
  and secure operation of its assets, including:</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Operational Procedures &#8211; Comprehensive s=
et
  of procedures in support of organizational standards and policies.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Change Control &#8211; Process to manage change
  and configuration control.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Incident Management &#8211; Team, procedures, =
and
  tools to ensure timely and effective response to and reporting of any
  security incidents.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Segregation of Duties &#8211; Segregation and
  rotation of duties minimize the potential for collusion and uncontrolled
  exposure.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Capacity Planning &#8211; Tools and procedures=
 to
  monitor and project organizational capacity to ensure uninterrupted
  availability.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>System Acceptance &#8211; Methodology to evalu=
ate
  system changes to ensure continued confidentiality, integrity, and
  availability.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Malicious Code &#8211; Controls to mitigate ri=
sk
  from introduction of malicious code.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Housekeeping &#8211; Policies, standards,
  guidelines, and procedures to address routine housekeeping activities suc=
h as
  backup schedules, deactivating access rights, and logging.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl141 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'><span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;
  </span>External Processing Facilities Management &#8211; Appropriate to t=
he
  level of risk, sufficient controls at third-party facilities are agreed u=
pon,
  implemented, and incorporated into the contract.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Network Management &#8211; A range of procedur=
es
  and other controls implemented to achieve and maintain security in networ=
ks.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Media Handling &#8211; Policies and procedures=
 for
  handling, storage, transport, and disposal of electronic storage media.</=
td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl138 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:944pt'>Information and Software Exchanges &#8211;
  Agreements (formal and informal), procedures, standards and other controls
  ensure the protection of production,</td>
 </tr>
 <tr height=3D29 style=3D'mso-height-source:userset;height:21.75pt'>
  <td colspan=3D7 height=3D29 class=3Dxl144 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:21.75pt;width:944pt'>e-commerce, messaging, office (non-production=
),
  and publicly available data, exchanges and systems in compliance with
  relevant legislation.</td>
 </tr>
 <tr height=3D0 style=3D'display:none'>
  <td colspan=3D7 class=3Dxl147 width=3D1259 style=3D'width:944pt'>&nbsp;</=
td>
 </tr>
 <tr height=3D69 style=3D'mso-height-source:userset;height:51.75pt'>
  <td colspan=3D7 height=3D69 class=3Dxl105 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:51.75pt;width:944pt'>Documents that May Be Requested:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Network di=
agram,
  dataflow diagram, runbooks, SOPs (standard operating procedures) and desk=
top
  procedures; operations (network, processing) and incident response team
  organization charts; office/employee awareness materials and corporate
  policies (signed annually); change control manual, minutes and records;
  system and network outage and capacity utilization records;
  incident-identification and response records; test plans and results;
  third-party due diligence records and contracts; policies, standards and
  guidelines; system and network criteria; planning and acceptance records.=
</font></td>
 </tr>
 <tr height=3D81 style=3D'mso-height-source:userset;height:60.75pt'>
  <td colspan=3D7 height=3D81 class=3Dxl105 width=3D1259 style=3D'border-ri=
ght:1.0pt solid black;
  height:60.75pt;width:944pt'>6.1 Operational Procedures and Responsibiliti=
es
  High-Level Expectation:<font class=3D"font9"> Responsibilities and proced=
ures
  for the management and operation of all information-processing facilities
  should be established and adhered to. This includes the development of
  appropriate operating instructions, and change control and incident-respo=
nse
  procedures. Segregation of duties and environments&#8212;development,
  testing, staging, and production&#8212;should be implemented where
  appropriate to reduce the risk of negligent, inadvertent or deliberate mi=
suse
  of information-processing facilities and systems.</font></td>
 </tr>
 <tr height=3D38 style=3D'mso-height-source:userset;height:28.5pt'>
  <td height=3D38 class=3Dxl54 style=3D'height:28.5pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D400 style=3D'border-top:none;width:300pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D84 style=3D'border-top:none;width:63pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D519 style=3D'border-top:none;width:389pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt'>6.1.1</td>
  <td class=3Dxl62 width=3D400 style=3D'border-left:none;width:300pt'>What =
are the
  policies and procedures in place for management and operation of business
  processing facilities?</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
2</td>
  <td class=3Dxl62 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  operating and control procedures documented and communicated?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
3</td>
  <td class=3Dxl63 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the policy include documented procedures for:</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Processing
  and handling of information?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Scheduling
  requirements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Handling
  errors? (e.g., transport of data, printing, copies)</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Segregation
  of duties to reduce opportunities for unauthorized modification, misuse of
  information, or services?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Escalation
  via a call tree for both Service Provider and Receiver Company?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Generating and handling special output? ">Generating and handling
  special output?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Restarting and recovering systems? ">Restarting and recovering
  systems?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Maintenance
  and troubleshooting of systems?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Routine
  backups?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Safety?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D100 style=3D'height:75.0pt'>
  <td height=3D100 class=3Dxl61 style=3D'height:75.0pt;border-top:none'>6.1=
.14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Please
  describe the reporting structure for application development, computer
  operations, security administration, program change and control, nerwork
  services, technical support, database adminstration, and disaster recovery
  services.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Do they report to
  different managers and function independently?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does a segregation of duties exist between the following functio=
ns: ">Does
  a segregation of duties exist between the following functions:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
15.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Individuals who
  authorize access, personnel who enable access, and personnel who verify
  access?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
15.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Personnel who =
enable
  access and those who review audit trails and/or violation logs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.1=
.15.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Personnel who
  install and maintain the logical access control process and those who rev=
iew
  audit trails and/or violation logs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the formal change control process (or SDLC) detail whether it includes:</=
td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Testing
  (including regression and security testing, as appropriate)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>6.1.=
16.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Independence between persons testing security from the persons a=
dministering security assessment? ">Independence
  between persons testing security from the persons administering security
  assessment?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Formal
  approval?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Backout
  or contingency plans?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Separation
  of development and production software and systems?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Separation
  of development and production teams?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
16.7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Provisions
  for emergency changes?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.1=
.16.8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Documentation
  of changes and incorporation of documentation back into system manuals?</=
td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.1=
.17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are there operating release management processes and procedures =
in place?  ">Are
  there operating release management processes and procedures in place?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
18</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are the releases controlled?  ">Are the releases controlled?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
19</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  new release functionality tested, scheduled, and deployed?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td height=3D63 class=3Dxl61 style=3D'height:47.25pt;border-top:none'>6.1=
.20</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Please describe any significant upgrades or other changes to the=
 Service Provider&#8217;s systems and networks over the past two years whic=
h may affect audits or assessments provided to validate controls. ">Please
  describe any significant upgrades or other changes to the Service
  Provider&#8217;s systems and networks over the past two years which may
  affect audits or assessments provided to validate controls.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D83 style=3D'mso-height-source:userset;height:62.25pt'>
  <td height=3D83 class=3Dxl61 style=3D'height:62.25pt;border-top:none'>6.1=
.21</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  system enhancement is planned for the next year that would impact Receiver
  Company systems and networks? (e.g., What changes may result in the need =
for
  additional testing or network connectivity changes?)</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.1=
.22</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider monitor and internally escalate the following:</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  incidents?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Internal
  fraud (information as well as transaction)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Unauthorized/unacceptable
  employee activity?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
22.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Other
  suspicious activities?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.1.=
23</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have documented incident-management procedures that
  address the following:</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Information
  system failures or losses of service?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Denial
  of service attacks?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  infrastructure exploits?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Errors
  resulting from incomplete or inaccurate business data?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Errors
  resulting from system or device misconfiguration?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Breaches
  or loss of confidentiality?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Contingency
  plans for recovery from specific incidents?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Gathering
  of evidenced and documentation as well as chain of custody protection?</t=
d>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.1.=
23.9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Carefully
  controlled and tested recovery processes?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.24</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Please describe the process to address production problems (e.g.=
, personnel involved, documentation, retention, and timeliness).  ">Please
  describe the process to address production problems (e.g., personnel
  involved, documentation, retention, and timeliness).<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>6.1.=
25</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is a problem-tracking log produced that details all processing p=
roblems occurring during the previous 24 hours?  Is a unique number assigne=
d to each problem?  ">Is
  a problem-tracking log produced that details all processing problems
  occurring during the previous 24 hours?<span style=3D'mso-spacerun:yes'>&=
nbsp;
  </span>Is a unique number assigned to each problem?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D44 style=3D'mso-height-source:userset;height:33.0pt'>
  <td height=3D44 class=3Dxl61 style=3D'height:33.0pt;border-top:none'>6.1.=
26</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  changes resulting from a production problem subject to the same process as
  program change management?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>6.1.=
27</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a documented process to track completion of follow-up actions to
  prevent reoccurrence of production problems?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.1.=
28</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider ensure that the security-event monitoring system has
  current signature files?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.29</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  training or qualifications have the various incident-response teams recei=
ved?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D25 style=3D'mso-height-source:userset;height:18.75pt'>
  <td height=3D25 class=3Dxl61 style=3D'height:18.75pt;border-top:none'>6.1=
.30</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the incident-response team available at all times?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.1=
.31</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  mechanisms are in place to allow employees to promptly report security
  incidents, weaknesses, and software malfunctions?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td height=3D63 class=3Dxl61 style=3D'height:47.25pt;border-top:none'>6.1=
.32</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have procedures to notify or handle inquiries from
  customers or clients, news media, government offices, outside investigato=
rs,
  shareholders, etc.?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.1=
.33</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  periodic meetings scheduled between the Service Provider and Receiver Com=
pany
  to discuss performance and operational issues?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl104 width=3D1259 style=3D'height:33=
.75pt;
  width:944pt'>6.2 System Planning and Acceptance High-Level Expectation:<f=
ont
  class=3D"font9"> Future capacity requirements should be projected and pla=
nned
  for to help ensure system availability and reduce the risk of systems
  overload. Operational requirements for new systems should be established,
  documented and tested prior to the system&#8217;s acceptance and use.</fo=
nt></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl64 width=3D64 style=3D'height:33.75pt;border-to=
p:none;
  width:48pt'>6.2.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider plan and monitor capacity, performance, transaction
  levels, etc.?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.2.=
2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  application, system and network architectures designed for high availabil=
ity
  and operational redundancy?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D66 style=3D'mso-height-source:userset;height:49.5pt'>
  <td height=3D66 class=3Dxl61 style=3D'height:49.5pt;border-top:none'>6.2.=
3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have formal acceptance procedures and criteria
  (including security) for new applications, systems and networks?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.2.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider ensure that implemented applications, systems and
  networks meet design requirements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td colspan=3D7 height=3D42 class=3Dxl104 width=3D1259 style=3D'height:31=
.5pt;
  width:944pt'>6.3 Protection Against Malicious Software High-Level
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Controls should be in place to prevent and detect the introduction=
 and
  dissemination of malicious software.<span style=3D'mso-spacerun:yes'>&nbs=
p;
  </span>Recovery plans should be prepared, updated and tested regularly.</=
font></td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a virus protection policy and procedures?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.2</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a policy and procedures in place for<font
  class=3D"font6"> reviewing application source code and executables to find
  exposures, vulnerabilities and malicious code before the application is
  deployed (i.e., code scanning)?</font></td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  antivirus software deployed, updated and maintained for desktops, servers,
  firewalls, and Internet email gateways?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  messages scanned for malicious code, worms, Trojan horses, back doors, fo=
rm
  input validation, and SQL injection?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the virus protection policy and procedures communicated internally?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the code scanning policy and procedures communicated internally?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.3.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  compliance with corporate policy tested?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.3.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Can
  end users override the antivirus software?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.3.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a virus protection response team?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  remote users and laptop computer users covered under the virus protection
  program?</td>
  <td class=3Dxl66 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.3=
.11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  malicious code filtered at the network perimeter?</td>
  <td class=3Dxl66 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl104 width=3D1259 style=3D'height:33=
.75pt;
  width:944pt'>6.4 Backup High-Level Expectation:<font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Routine backup procedures should=
 be
  established and adhered to for carrying out the agreed backup strategy, s=
uch
  as taking backup copies of data, rehearsing their timely restoration, log=
ging
  events and faults, and, where appropriate, monitoring the equipment
  environment.</font></td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.4.=
1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Describe
  the Service Provider&#8217;s policies and procedures for system and data
  back-ups.</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  regular backups performed?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.4=
.3</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the backups protected from unauthorized access and tampering?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  often are backups performed?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are copies of the backups taken and stored offsite?  ">Are copie=
s of
  the backups taken and stored offsite?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Will
  the distance between the production environment and where the backups are
  stored allow for a speedy recovery?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Do the same access controls exist over data backups when stored =
offsite? ">Do
  the same access controls exist over data backups when stored offsite?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a specific or dedicated unit that performs this backup/recovery
  function?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  controls exist to ensure that backups are not rotated out until new backu=
ps
  are in place?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>What
  processes and procedures are in place to allow for the destruction of bac=
kups
  in compliance with document-retention policies, laws or Receiver Company
  requirements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  long are operator logs retained?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>For
  how long are backups retained?<font class=3D"font14"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span></font><font class=3D"font9">Are=
 the
  backup media refreshed to prevent loss due to deterioration?</font></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are backup systems tested?  ">Are backup systems tested?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"How often? ">How often?<span style=3D'mso-spacerun:yes'>&nbsp;</=
span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Who
  participates?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  backups audited to ensure they function properly?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.4.=
17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  maintenance or upgrade logs kept for hardware and/or software?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D36 style=3D'mso-height-source:userset;height:27.0pt'>
  <td colspan=3D7 height=3D36 class=3Dxl112 width=3D1259 style=3D'height:27=
.0pt;
  width:944pt'>6.5 Network Management High-Level Expectation:<font class=3D=
"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>The Service Provider should ensu=
re the
  managed network is secure so that data is protected when transmitted over
  both trusted and untrusted networks.</font></td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the following<span style=3D'mso-spacerun:yes'>&nbsp; </span>included in t=
he
  Service Provider&#8217;s network management program:</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Design,
  application and implementation of security/control domains (perimeter, DM=
Z,
  etc.) and perimeters?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  configuration development and implementation for network devices in
  accordance with their function in security/control zones (such as
  public/untrusted networks, semi-private networks, DMZs) and perimeters?</=
td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Remote access (administrator as well as &#8220;user&#8221; dial-=
in/dial-out, maintenance dial-in), remote access servers (including AAA), r=
emote access management utilities/tools appropriate to each security/contro=
l domain? ">Remote
  access (administrator as well as &#8220;user&#8221; dial-in/dial-out,
  maintenance dial-in), remote access servers (including AAA), remote access
  management utilities/tools appropriate to each security/control domain?<s=
pan
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Regular,
  periodic vulnerability and penetration testing in accordance with the ris=
k of
  each security/control domain and perimeter?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ne=
twork
  and system monitoring?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Ne=
twork
  redundancy and diverse routing?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.5.=
6.3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"       Controls to prevent unauthorized deployment of network co=
nnections and equipment?   "><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Co=
ntrols
  to prevent unauthorized deployment of network connections and equipment?<=
span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>Deployment of Network IDSs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
6.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>Host-based IDS?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does the audit log review/network monitoring include the followi=
ng: ">Does
  the audit log review/network monitoring include the following:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Access
  failures and classification of data compromised?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Logon
  patterns for indications of abnormal use or revived user IDs?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Allocation
  and use of accounts with a privileged access capability?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Tracking
  of selected transactions?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.5.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Use
  of sensitive resources?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Dial-up
  activity?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Firewall
  activity?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>OS
  and application access attempts?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Security
  administration activity?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>The
  use of automated tools to perform this review on a frequent and periodic
  basis?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.18</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>The
  placement of intrusion-detection systems in the overall network architect=
ure?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.19</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Logs of security-related events should sufficiently assign accou=
ntability?  ">Logs
  of security-related events should sufficiently assign accountability?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.20</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Logs should be appropriately secured against unauthorized access=
, change, and deletion for an adequate time period? ">Logs
  should be appropriately secured against unauthorized access, change, and
  deletion for an adequate time period?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'mso-height-source:userset;height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>6.5=
.21</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Detecting
  rogue devices and services?</td>
  <td class=3Dxl67 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D7 height=3D50 class=3Dxl104 width=3D1259 style=3D'height:37=
.5pt;
  width:944pt'>6.6 Media Handling and Security High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Appropriate
  operational procedures should be established and followed to protect
  documents, computer media (tapes, disks, cassettes, etc.), input/output d=
ata
  and system documentation from damage, theft and unauthorized access.<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>6.6.=
1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a policy/procedure for handling and destroying
  various media?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>6.6=
.2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Do the Service Provider's procedures ensure media are disposed o=
f securely? ">Do
  the Service Provider's procedures ensure media are disposed of securely?<=
span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D38 style=3D'mso-height-source:userset;height:28.5pt'>
  <td height=3D38 class=3Dxl61 style=3D'height:28.5pt;border-top:none'>6.6.=
3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the Service Provider have a records-retention and destruction policy and
  related procedures?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>6.6.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does the Service Provider have a documented process for how medi=
a is labeled, stored and kept?  ">Does
  the Service Provider have a documented process for how media is labeled,
  stored and kept?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D38 style=3D'mso-height-source:userset;height:28.5pt'>
  <td height=3D38 class=3Dxl61 style=3D'height:28.5pt;border-top:none'>6.6.=
5</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  a tape management software package used to track backup tapes that are se=
nt
  offsite?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D48 style=3D'mso-height-source:userset;height:36.0pt'>
  <td height=3D48 class=3Dxl61 style=3D'height:36.0pt;border-top:none'>6.6.=
5.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"     If YES, what tape-management software package is used? "><s=
pan
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If YES, what
  tape-management software package is used?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td colspan=3D7 height=3D59 class=3Dxl104 width=3D1259 style=3D'height:44=
.25pt;
  width:944pt'>6.7 Exchanges of Information and Software High-Level
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>All exchanges of information and software between the Service
  Provider, suppliers of services to the Service Provider, and the Receiver
  Company should be controlled and compliant with contractual, legal and re=
gulatory
  requirements.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Exchanges sho=
uld be
  carried out on the basis of agreements.<span style=3D'mso-spacerun:yes'>&=
nbsp;
  </span>Procedures and standards should be established to protect informat=
ion
  and media in transit.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span>=
</font></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.7=
.1</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"What are all the Service Provider&#8217;s supportable means of e=
xchanging information? ">What
  are all the Service Provider&#8217;s supportable means of exchanging
  information?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
2</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are safeguards in place for each means of exchange?  ">Are safeg=
uards
  in place for each means of exchange?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
3</td>
  <td class=3Dxl65 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  safeguards in place for the content of all such exchanges?</td>
  <td class=3Dxl65 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Can
  the Service Provider support information-exchange agreements?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.7=
.5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Can
  the Service Provider support software-exchange agreements (including soft=
ware
  escrow)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>6.7=
.6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Is there a review and authorization process that controls inform=
ation that is made publicly available? ">Is
  there a review and authorization process that controls information that is
  made publicly available?<span style=3D'mso-spacerun:yes'>&nbsp;</span></t=
d>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>6.7.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are information and transactions protected while conducting e-co=
mmerce?  ">Are
  information and transactions protected while conducting e-commerce?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>6.7=
.8</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Does that protection extend to intermediate and long-term storag=
e of information (e.g., on database)?  ">Does
  that protection extend to intermediate and long-term storage of informati=
on
  (e.g., on database)?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span><=
/td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D22 style=3D'mso-height-source:userset;height:16.5pt'>
  <td height=3D22 class=3Dxl61 style=3D'height:16.5pt;border-top:none'>6.7.=
9</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the protection extend to the entire supply chain?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
10</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  the following maintained in the e-commerce system:</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
11</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Confidentiality?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
12</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Transaction
  authentication?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
13</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Authorization?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
14</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Non-repudiation?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
15</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Transaction
  integrity?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
16</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>How
  is authentication performed?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
17</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  online registration and authentication managed for e-commerce/e-banking
  systems?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
18</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  sufficient tendering, vetting, settlement, and pricing information trust =
and
  liability controls available for e-commerce/e-banking transactions with o=
r by
  the Service Provider?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
19</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  the Service Provider capable of meeting encryption key management
  requirements?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.7.=
20</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  access codes encrypted in storage and transmission?</td>
  <td class=3Dxl68 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td colspan=3D7 height=3D40 class=3Dxl148 width=3D1259 style=3D'height:30=
.0pt;
  width:944pt'>6.8 <font class=3D"font8">Website High-Level Expectation:</f=
ont><font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Appropriate
  operational procedures and practices should be established and followed to
  protect the website from damage, theft and unauthorized access.</font></t=
d>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  all unnecessary daemons disabled and removed from the system?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
2</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'
  x:str=3D"Are periodic reviews of router and firewall logs performed to va=
lidate filter operation? ">Are
  periodic reviews of router and firewall logs performed to validate filter
  operation?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
3</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Are
  all services that are not required (e.g., Telnet) turned off?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
4</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  a security software product (e.g., Internet Security Systems&#8217;
  Safesuite) periodically executed to determine potential security
  vulnerabilities on such interfacing domain components as routers, Web
  servers, mail servers, FTP servers, name servers, firewalls and network
  monitors (i.e., tested from inside and outside the firewall)?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
4.1</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  YES, what product(s) are used?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
5</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>If
  any Service Provider software is branded with a Receiver Company brand, d=
oes
  the website include the Receiver Company data privacy statement?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>If it is branded with the Service
  Provider&#8217;s brand, is a commensurate statement in place?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
6</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Is
  there a mechanism in place to capture and record consent of data privacy
  preferences, if necessary by law?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'mso-height-source:userset;height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>6.8.=
7</td>
  <td class=3Dxl64 width=3D400 style=3D'border-top:none;border-left:none;wi=
dth:300pt'>Does
  the privacy statement contain details of cookies or click stream methods
  used?</td>
  <td class=3Dxl64 width=3D84 style=3D'border-top:none;border-left:none;wid=
th:63pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D519 style=3D'border-top:none;border-left:none;wi=
dth:389pt'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D400 style=3D'width:300pt'></td>
  <td width=3D84 style=3D'width:63pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D519 style=3D'width:389pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet013.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet013.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(12);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>135</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>58</x:ActiveRow>
    <x:RangeSelection>$A$59:$G$59</x:RangeSelection>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1204 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:903pt'>
 <col class=3Dxl58 width=3D59 style=3D'mso-width-source:userset;mso-width-a=
lt:2157;
 width:44pt'>
 <col width=3D417 style=3D'mso-width-source:userset;mso-width-alt:15250;wid=
th:313pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D472 style=3D'mso-width-source:userset;mso-width-alt:17261;wid=
th:354pt'>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl116 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>7.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;
  </span>ACCESS CONTROL:<span style=3D'mso-spacerun:yes'>&nbsp; </span><font
  class=3D"font9">Addresses an organization's ability to control access to =
assets
  based on business and security requirements, including:</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>Business requirements &#8211; Policy-controlli=
ng
  access to organizational assets based on business requirements and &quot;=
need
  to know.&quot;</td>
 </tr>
 <tr height=3D81 style=3D'mso-height-source:userset;height:60.75pt'>
  <td colspan=3D7 height=3D81 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:60.75pt;width:903pt'>User management &#8211; Mechanisms to:<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;
  </span>&sect; Register and deregister users<br>
    &sect; Control and review access and privileges<br>
    &sect; Manage passwords<br>
    </td>
 </tr>
 <tr height=3D145 style=3D'mso-height-source:userset;height:108.75pt'>
  <td colspan=3D7 height=3D145 class=3Dxl108 width=3D1204 style=3D'border-r=
ight:1.0pt solid black;
  height:108.75pt;width:903pt'>Host access control &#8211; Mechanisms(when
  appropriate) to:<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>&sect; Automatically identify terminal<br>
    &sect; Securely log on (i.e., encrypted login session)<br>
    &sect; Authenticate users<br>
    &sect; Manage passwords<br>
    &sect; Secure system utilities<br>
    &sect; Furnish user duress capability, such as &#8220;panic
  buttons&#8221;<br>
    &sect; Enable terminal, user, or connection timeouts<br>
    </td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>Application access control &#8211; Limits acce=
ss
  to applications based on user or application authorization levels.</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td colspan=3D7 height=3D20 class=3Dxl108 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.0pt;width:903pt'>Access monitoring &#8211; Mechanisms to monitor
  system access and system use to detect unauthorized activities.</td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td colspan=3D7 height=3D21 class=3Dxl129 width=3D1204 style=3D'border-ri=
ght:1.0pt solid black;
  height:15.75pt;width:903pt'>Mobile computing &#8211; Policies and standar=
ds
  to address asset protection, secure access, and user responsibilities.</t=
d>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td colspan=3D7 height=3D46 class=3Dxl55 width=3D1204 style=3D'border-rig=
ht:1.0pt solid black;
  height:34.5pt;width:903pt'>Documents that May Be Requested:<font class=3D=
"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Security policy with access poli=
cy,
  user policy and network access controls, network architecture diagram
  (including placement of firewalls), application access control procedures,
  dataflow diagram<span style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
 </tr>
 <tr height=3D89 style=3D'mso-height-source:userset;height:66.75pt'>
  <td colspan=3D7 height=3D89 class=3Dxl150 width=3D1204 style=3D'height:66=
.75pt;
  width:903pt'>7.1 Business Requirements for Access Control High-Level
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Service Providers should have and adhere to a documented policy to
  ensure that only properly approved users are granted access to financial
  institution information systems and assets. Users should be granted acces=
s on
  a need-to-know basis, according to job responsibilities. The access-contr=
ol
  policy should employ methods designed to physically and logically restrict
  access to equipment, ensure the identification and authentication of
  individuals who access computing resources, and restrict an
  individual&#8217;s access to information once the individual has accessed=
 a
  system. Depending on the level of protection required (based on the asset
  classification), a combination of access-control techniques may need to be
  employed.</font></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl69 style=3D'height:15.0pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D417 style=3D'border-top:none;width:313pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl48 width=3D472 style=3D'border-top:none;width:354pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt'>7.1.1</td>
  <td class=3Dxl62 width=3D417 style=3D'border-left:none;width:313pt'>What =
is the
  access and control policy?</td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl62 width=3D472 style=3D'border-left:none;width:354pt'>&nbsp=
;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Is access to resources controlled by any combination of the foll=
owing: ">Is
  access to resources controlled by any combination of the following:<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Method or
  location of accessing user</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Time of =
day</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Day of w=
eek</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Calendar=
 date</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
2.5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Specific
  program used to access the resource?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  the authorization engine for the system fails, will the access control ru=
les
  default to &#8220;no access&#8221;?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  access rights specified by job type or on a &#8220;need-to-know&#8221; ba=
sis?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Please
  describe the process for granting access.</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Please
  list the person(s)/group(s) responsible for granting access.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>How is this authority documented=
, and
  from whom is it received?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.1.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  is the process used to verify the signature or identity of a person who is
  granted access, and of the person who authorizes access?<font class=3D"fo=
nt14"><span
  style=3D'mso-spacerun:yes'>&nbsp;</span></font></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.1.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  the Receiver Company review requests for access in some or all cases?</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.1.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  all developers granted the same access rights?</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl68 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D55 style=3D'mso-height-source:userset;height:41.25pt'>
  <td colspan=3D7 height=3D55 class=3Dxl104 width=3D1204 style=3D'height:41=
.25pt;
  width:903pt'>7.2 User Access Management High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>To protect=
 the
  confidentiality and privacy of data and information, user access capabili=
ties
  should be configured with least privilege.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>User access rights and privileges
  should be consistent with users&#8217; assigned job responsibilities for
  performing a particular function or transaction.</font></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl70 style=3D'height:60.0pt;border-top:none'>7.2.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  is the procedure for authorization and release of user information, such =
as
  access rights, including how often user IDs (infrastructure and applicati=
on)
  are reviewed for appropriate access?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.2.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  access-control reports and related monitoring reports provided to a Recei=
ver
  Company information owner to identify suspicious activity associated with=
 the
  account?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.2.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  special privileges allowing security account setup and administration lim=
ited
  to a segregated security user administration function?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  the security administrator receive feeds from the human resources system
  identifying terminated employees?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  are the procedures for managing the on-boarding and off-boarding of users=
 of
  token authentication</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  corporate property collected and are user rights and permissions turned o=
ff
  immediately?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.2.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  privileged users controlled and monitored by a formal approval process?</=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.2.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  users informed of the access rights that they have been provided?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.2.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  default user IDs renamed or disabled?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl70 style=3D'height:17.25pt;border-top:none'>7.2=
.10</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  any temporary/generic/guest/anonymous user IDs in use?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D23 style=3D'mso-height-source:userset;height:17.25pt'>
  <td height=3D23 class=3Dxl70 style=3D'height:17.25pt;border-top:none'>7.2=
.10.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  so, how are they shared?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D50 style=3D'mso-height-source:userset;height:37.5pt'>
  <td colspan=3D7 height=3D50 class=3Dxl112 width=3D1204 style=3D'height:37=
.5pt;
  width:903pt'>7.3 User Responsibilities High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Users shou=
ld be
  aware of their responsibilities for maintaining effective access controls,
  particularly as they relate to password security and user equipment.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Service Providers should have a
  written authorized user accountability policy that incorporates
  authentication standards and clearly articulates user responsibilities.</=
font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Describe
  the Service Provider&#8217;s access control policies and procedures.</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  the guidelines provided to users for generating secure passwords?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are these guidelines communicated to the users?  ">Are these
  guidelines communicated to the users?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.3.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Do
  guidelines include simple instructions, such as &#8220;passwords must not=
 be
  shared,&#8221;<span style=3D'mso-spacerun:yes'>&nbsp; </span>&#8220;passw=
ords
  must not be written down and stored in obvious places,&#8221; etc.?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are password lists maintained?  ">Are password lists maintained?=
<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
.5.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  YES, how are they managed?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  the system require the user to change his or her initial password during
  first logon?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  is the minimum length of a password?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  the length configurable?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
10</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are all passwords set to expire after a certain period of time? =
 ">Are
  all passwords set to expire after a certain period of time?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
11</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  this interval configurable?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
12</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Can
  users change their own passwords at any time?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
13</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  are the Service Provider&#8217;s help desk procedures (manual or automate=
d)
  for password reset?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl70 style=3D'height:60.0pt;border-top:none'>7.3.=
14</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  restrictions placed on passwords to ensure appropriate strength (i.e., us=
er
  ID not equal to password, password not equal to &#8220;password&#8221;, l=
imit
  repetitive characters, require alphanumeric and special characters)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
15</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are controls in place to prevent the reuse of previous passwords=
?  ">Are
  controls in place to prevent the reuse of previous passwords?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
16</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Is this number configurable?  ">Is this number configurable?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
17</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Does the system disconnect or force reauthentication of users af=
ter a specified period of inactivity?  ">Does
  the system disconnect or force reauthentication of users after a specified
  period of inactivity?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span>=
</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
18</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  this period configurable?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
19</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Does the system disable or suspend user IDs after a fixed number=
 of unsuccessful logon attempts?  ">Does
  the system disable or suspend user IDs after a fixed number of unsuccessf=
ul
  logon attempts?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.3.=
20</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  the number configurable?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.3.=
21</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  users required to log off, lock or use a password-protected screen saver
  whenever their computer is left unattended?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D68 style=3D'mso-height-source:userset;height:51.0pt'>
  <td colspan=3D7 height=3D68 class=3Dxl112 width=3D1204 style=3D'height:51=
.0pt;
  width:903pt'>7.4 Network Access Control High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>The design=
 of the
  Service Provider&#8217;s internal and external networks should demonstrat=
e a
  commitment to secure networking.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>The design must be documented, on paper or in an electronic chart,
  including notes.<span style=3D'mso-spacerun:yes'>&nbsp; </span>External
  connections should be managed carefully; connections to networks for third
  parties should only be created after security due diligence has been
  completed.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Procedures should
  verify the authenticity of the counter party providing electronic
  instructions or transactions through trusted exchange of passwords, token=
s,
  or cryptographic keys.</font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Describe the processes and procedures developed for managing net=
work services and controlling network access.  ">Describe
  the processes and procedures developed for managing network services and
  controlling network access.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;<=
/span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  remote access paths restricted to designated gateways and/or resources?</=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  routine electronic assessment performed on the network to detect
  unauthorized/undocumented modems/network devices/services?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  is the process for requesting and approving modem connections to servers =
or
  desktops?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Do
  routers do ingress and egress filtering?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  routing access-control lists used for security?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Who maintains the access-control lists (ACLs)?  ">Who maintains =
the
  access-control lists (ACLs)?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl70 style=3D'height:60.0pt;border-top:none'>7.4.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  any additional forms of access control used to safeguard against unauthor=
ized
  access from external connections (e.g., dial back, two-part authenticatio=
n,
  challenge-response, time-of-day or week restriction, read-only restrictio=
ns,
  etc.)</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  there an authorization process in place for new external connections?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
10</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Do all external connections go through a firewall(s)? ">Do all
  external connections go through a firewall(s)?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
11</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  the internal address range protected (e.g., NAT)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
12</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are all external connections documented?  ">Are all external
  connections documented?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</spa=
n></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
13</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  area manages these external connections?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
14</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  external IP access, including system-to-system authentication, using sess=
ion
  encryption?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
15</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  access codes encrypted during transmission and storage?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
16</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  the LAN/WAN fully switched?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
17</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"How are data switches remotely supported? ">How are data switches
  remotely supported?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
18</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"How are internal network segments segregated? ">How are internal
  network segments segregated?<span style=3D'mso-spacerun:yes'>&nbsp;</span=
></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
19</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>How
  is access controlled to network devices?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
20</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"How is authorization achieved on a network level?  ">How is
  authorization achieved on a network level?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
21</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  there a list of protocols authorized for use through access-control point=
s?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
22</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>How
  is external IP network access restricted at the firewall?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
23</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Who
  is responsible for maintaining and monitoring these firewalls?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.4.=
24</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  Simple Network Management Protocol (SNMP) used?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.4.=
24.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  YES, what &#8220;best practices&#8221; have been implemented to reduce the
  security threat to the network?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td colspan=3D7 height=3D46 class=3Dxl104 width=3D1204 style=3D'height:34=
.5pt;
  width:903pt'>7.5 Operating System Access Control High-Level Expectation:<=
font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Service Pr=
oviders
  should implement operating system access controls that protect the systems
  from compromise.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Protections
  should include but are not limited to appropriate system authorization and
  management.</font></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.5.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Describe all mechanisms in place to identify the system and/or t=
he organization, legal warnings, error conditions, and logon help messages.=
   ">Describe
  all mechanisms in place to identify the system and/or the organization, l=
egal
  warnings, error conditions, and logon help messages.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.5.=
1.1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If these mecha=
nisms
  are in place, at what point are these messages displayed?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.5.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  the passwords for super-user accounts (i.e., root &#8211; UNIX, Administr=
ator
  &#8211; NT, etc.) unique to each server?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D100 style=3D'height:75.0pt'>
  <td height=3D100 class=3Dxl70 style=3D'height:75.0pt;border-top:none'>7.5=
.3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"How is authorization achieved on a host level?  Please describe =
how administrator accounts are set up and how super-user accounts are utili=
zed (e.g., day-to-day accounts versus super-user accounts, privileges assig=
ned to accounts, uniqueness of accounts, accountability).  ">How
  is authorization achieved on a host level?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Please describe how administrator
  accounts are set up and how super-user accounts are utilized (e.g.,
  day-to-day accounts versus super-user accounts, privileges assigned to
  accounts, uniqueness of accounts, accountability).<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.5.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Where are the master and sub-master consoles located?  ">Where a=
re the
  master and sub-master consoles located?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.5.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>Are full administrative privileges only allowed from the console?<=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.5.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  are the controls around access to these?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.5.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Have limitations and/or restrictions been placed on connection t=
imes for activities such as batch processing? (i.e., restricting connection=
s, time-outs, and/or inactivity)? ">Have
  limitations and/or restrictions been placed on connection times for
  activities such as batch processing? (i.e., restricting connections,
  time-outs, and/or inactivity)?<span style=3D'mso-spacerun:yes'>&nbsp;</sp=
an></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td colspan=3D7 height=3D42 class=3Dxl104 width=3D1204 style=3D'height:31=
.5pt;
  width:903pt'>7.6 Application Access Control High-Level Expectations:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>The Service
  Provider should maintain and adhere to policies and processes that restri=
ct
  user access to information and application functions, and prevent
  unauthorized access to information systems.</font></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  an application performs authentication and access control functions:</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
2</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Does the application user identifier and password conform to the=
 policies and standards?  ">Does
  the application user identifier and password conform to the policies and
  standards?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.6.=
2.1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  NO, describe exceptions.</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
3</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>List
  the typical roles users may have while accessing the application.</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
4</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  shared or group IDs are used, describe their use and associated controls.=
</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.6.=
5</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  security events are logged at the application level?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl70 style=3D'height:15.75pt;border-top:none'>7.6=
.6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  a segregation of duties exist among the following functions:</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
6.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp; </span>Individuals who auth=
orize
  access, personnel who enable access, and personnel who verify access?</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D61 style=3D'height:45.75pt'>
  <td height=3D61 class=3Dxl70 style=3D'height:45.75pt;border-top:none'>7.6=
.6.2</td>
  <td class=3Dxl71 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span><font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp;</span>Business managers who approve acc=
ess
  and persons with information custodian responsibilities (other than for
  system software)?</font></td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D41 style=3D'height:30.75pt'>
  <td height=3D41 class=3Dxl70 style=3D'height:30.75pt;border-top:none'>7.6=
.6.3</td>
  <td class=3Dxl71 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span><font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp;</span>Business managers who approve acc=
ess
  and personnel with technology/business security administration
  responsibilities?</font></td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
6.4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp; </span>Information owners a=
nd
  personnel with technology/business security administration responsibiliti=
es?</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
6.5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp; </span>Personnel who enable
  access and those who review audit trails and/or violation logs?</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  testing conducted to ensure an application does not compromise the securi=
ty
  of other applications or systems?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.6.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Does
  the application conform to BITS Product Certification criteria or other
  recognized certifications?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.6.=
8.1</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  YES, which certification?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D472 style=3D'border-top:none;border-left:none;wi=
dth:354pt'>&nbsp;</td>
 </tr>
 <tr height=3D67 style=3D'mso-height-source:userset;height:50.25pt'>
  <td colspan=3D7 height=3D67 class=3Dxl104 width=3D1204 style=3D'height:50=
.25pt;
  width:903pt'>7.7 Monitoring System Access and Use High-Level Expectation<=
font
  class=3D"font9">:<span style=3D'mso-spacerun:yes'>&nbsp; </span>Service P=
roviders
  should be able to monitor the use and administration of systems.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>The monitoring system should pro=
duce
  an audit trail that allows the Service Provider to respond quickly to
  high-risk events.<span style=3D'mso-spacerun:yes'>&nbsp; </span>The monit=
oring
  system should be based on current vulnerability and risk analysis, and sh=
ould
  be integrated with an incident-response capability.</font></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl70 style=3D'height:60.0pt;border-top:none'>7.7.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are logs created and reviewed to identify use or attempted use, =
and modification or attempted modification of critical systems components (=
files, registry entries, configurations, security settings/parameters, audi=
t logs)? ">Are
  logs created and reviewed to identify use or attempted use, and modificat=
ion
  or attempted modification of critical systems components (files, registry
  entries, configurations, security settings/parameters, audit logs)?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.7.=
2</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Are there other security event monitoring and logging capabiliti=
es?  ">Are
  there other security event monitoring and logging capabilities?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.7.=
2.1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  YES, please list.</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.7.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"How long are logs maintained (both online and archived)?  ">How =
long
  are logs maintained (both online and archived)?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.7.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  this information protected from alteration or deletion?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D120 style=3D'height:90.0pt'>
  <td height=3D120 class=3Dxl70 style=3D'height:90.0pt;border-top:none'>7.7=
.5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Please
  describe the process used to retrieve the audit log for investigative
  purposes?<span style=3D'mso-spacerun:yes'>&nbsp; </span>What areas or fun=
ctions
  have access to these logs?<span style=3D'mso-spacerun:yes'>&nbsp; </span>=
How
  frequently are logs reviewed?<span style=3D'mso-spacerun:yes'>&nbsp; </sp=
an>Do
  procedures exist?<span style=3D'mso-spacerun:yes'>&nbsp; </span>How are e=
vents
  investigated/resolved? Are passwords included in the audit log (masked or
  unmasked)? What areas or functions have access to these logs?</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl71 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.7.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Are
  alerting mechanisms used to notify appropriate individuals that security
  events have occurred?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.7.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Describe
  the clock synchronization process, including the time source and
  synchronization process.</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D47 style=3D'mso-height-source:userset;height:35.25pt'>
  <td colspan=3D7 height=3D47 class=3Dxl104 width=3D1204 style=3D'height:35=
.25pt;
  width:903pt'>7.8 Mobile Computing and Teleworking High-Level Expectation:=
<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Service Pr=
oviders
  should maintain and adhere to policy, standards, procedures, and controls=
 for
  governing the security of information and systems accessed from outside
  company facilities, as well as the security of information stored on mobi=
le
  and telecommuting equipment.</font></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.8.=
1</td>
  <td class=3Dxl65 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>How
  do mobile users and telecommuters remotely connect to company systems and
  information (e.g., dedicated corporate dial-up servers, public networks,
  etc.)?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
2</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>How
  is the confidentiality of sensitive information ensured during remote
  connectivity (encryption, VPN client technology, etc.)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
3</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>How
  is confidentiality of sensitive information ensured during wireless acces=
s?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
4</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>How
  is the identity of remote users authenticated?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
5</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Does the remote access client prohibit split tunneling? ">Does t=
he
  remote access client prohibit split tunneling?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
6</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  all remote access devices configured to prevent war dialing?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
7</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Please
  describe how this access has been configured to prevent war dialing.</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
8</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  token-based authentication is utilized, does the token expire or require
  renewal after a period of time?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
9</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>If
  remote access privileges are not exercised for a period of time, is the
  access disabled, either automatically or manually?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
10</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>What
  controls are required for the remote user (e.g., two-factor authenticatio=
n,
  personal firewalls)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
11</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>For
  remote access, does the corporate policy include:</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
12</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Removal
  of information from company facilities (e.g., classification of informati=
on
  that may be held)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
13</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Equipment
  that can be used for mobile computing and teleworking (company-owned vers=
es
  personal equipment)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
14</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Physical
  security of mobile computing equipment and of teleworking site?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
15</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Security
  requirements for information held offsite (encryption, access control, et=
c.)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
16</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Backup
  of information taken offsite?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
17</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Requirement
  for personnel to sign an agreement indicating they have read and will com=
ply
  with the remote access policy?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
18</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'
  x:str=3D"Training and testing on remote access policies?  ">Training and
  testing on remote access policies?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
19</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Is
  desktop remote control allowed?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.8.=
20</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Strong
  audit trail requirements for all activities carried out by remote users
  (sufficient to state beyond a reasonable doubt what the remote user did)?=
</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl70 style=3D'height:30.0pt;border-top:none'>7.8.=
21</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Strong
  containment requirements that are enforced by technology (user must enter
  contained environment)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
22</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Do
  procedures and control arrangements include:</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl70 style=3D'height:45.0pt;border-top:none'>7.8.=
23</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Methods
  for protecting information and computing equipment while offsite or at
  teleworking facility (e.g., double-wrapped envelopes, locked
  briefcases/cabinets, encrypted data, digital certificates, etc.)?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
24</td>
  <td class=3Dxl64 width=3D417 style=3D'border-top:none;border-left:none;wi=
dth:313pt'>Virus
  protection against malicious code?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl70 style=3D'height:15.0pt;border-top:none'>7.8.=
25</td>
  <td colspan=3D5 class=3Dxl63 width=3D673 style=3D'border-left:none;width:=
505pt'>How
  often are remote access user accounts reviewed?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D59 style=3D'width:44pt'></td>
  <td width=3D417 style=3D'width:313pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D472 style=3D'width:354pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet014.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet014.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(13);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:DefaultRowHeight>555</x:DefaultRowHeight>
  <x:Unsynced/>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>57</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1427 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1071pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D353 style=3D'mso-width-source:userset;mso-width-alt:12909;wid=
th:265pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D498 style=3D'mso-width-source:userset;mso-width-alt:18212;wid=
th:374pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td colspan=3D7 rowspan=3D3 height=3D70 class=3Dxl116 width=3D1171 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:52.5pt;width:879=
pt'>8.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>SYSTEMS DEVELOPMENT AND
  MAINTENANCE:<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>Refers t=
o all
  actions, functions or activities performed by organizations for the purpo=
se
  of defining, acquiring, developing, enhancing, modifying, testing, or
  implementing information systems.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Maintenance refers to the necessary activities needed to maintain =
or
  improve the functionality, efficiency and effectiveness of existing
  information systems.</td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D33 style=3D'mso-height-source:userset;height:24.75pt'>
  <td height=3D33 colspan=3D4 style=3D'height:24.75pt;mso-ignore:colspan'><=
/td>
 </tr>
 <tr height=3D0 style=3D'display:none;mso-height-source:userset;mso-height-=
alt:
  555'>
  <td height=3D0 colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td colspan=3D7 height=3D59 class=3Dxl151 width=3D1171 style=3D'border-ri=
ght:1.0pt solid black;
  height:44.25pt;width:879pt'>Documents that May Be Requested:<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Application security policy, net=
work
  diagram, dataflow diagram, change control policy, programming standard and
  guidelines, certifications of encryption algorithms, documentation of
  security reviews of application code, vulnerability assessments of
  application and environment.</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D61 style=3D'mso-height-source:userset;height:45.75pt'>
  <td colspan=3D7 height=3D61 class=3Dxl105 width=3D1171 style=3D'border-ri=
ght:1.0pt solid black;
  height:45.75pt;width:879pt'>8.1 Security Requirements of Systems High-Lev=
el
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Service Providers should have and adhere to an established process=
 for
  developing secure infrastructure, systems, and/or applications.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Programs written for and/or used=
 by
  the Receiver Company should be certified as free from malicious code and
  patent-infringement issues and appropriate for use by the Receiver
  Company.<span style=3D'mso-spacerun:yes'>&nbsp; </span>The programs shoul=
d also
  be protected from unauthorized copy, use, duplication, and storage, with
  asset-management requirements specified.</font></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl73 style=3D'height:27.75pt'>&nbsp;</td>
  <td class=3Dxl72 width=3D353 style=3D'width:265pt'>Questions/Control Acti=
vities</td>
  <td class=3Dxl72 width=3D64 style=3D'width:48pt'>Domain</td>
  <td class=3Dxl72 width=3D64 style=3D'width:48pt'>Yes</td>
  <td class=3Dxl72 width=3D64 style=3D'width:48pt'>No</td>
  <td class=3Dxl72 width=3D64 style=3D'width:48pt'>NA</td>
  <td class=3Dxl74 width=3D498 style=3D'width:374pt'>Testing Performed and =
Results</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt'>8.1.1</td>
  <td class=3Dxl65 width=3D353 style=3D'border-left:none;width:265pt'
  x:str=3D"Are systems or applications developed internally?  ">Are systems=
 or
  applications developed internally?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl75 width=3D498 style=3D'border-left:none;width:374pt'>&nbsp=
;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.1.1</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  YES, does the Service Provider have an application development process or
  methodology?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.1.2</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  YES, does this process include project costing, resource requirements, and
  required date of implementation?</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl65 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.2</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Does
  the Service Provider use other development facilities?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.2.1</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  YES, please list.</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.3</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Are applications independently evaluated or certified?  ">Are
  applications independently evaluated or certified?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.3.1</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"If YES, by whom? ">If YES, by whom?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.3.2</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  YES, how often?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.4</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Has
  the application code been reviewed for security flaws and backdoors?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td height=3D63 class=3Dxl61 style=3D'height:47.25pt;border-top:none'>8.1=
.5</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  a third party provides the code, are there procedures for ensuring that t=
he
  code is free from malicious code and does not compromise the security of =
the
  application?</td>
  <td class=3Dxl76 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl76 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl76 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl76 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl76 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D59 style=3D'mso-height-source:userset;height:44.25pt'>
  <td height=3D59 class=3Dxl61 style=3D'height:44.25pt;border-top:none'>8.1=
.6</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Will
  the Service Provider certify that its applications do not contain any hid=
den
  exposures (e.g., worms, viruses, trapdoors, etc.)?</td>
  <td class=3Dxl77 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.7</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Who
  owns the intellectual property of the code?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.1=
.8</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Are
  there any issues relating to international patent infringement?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td></td>
 </tr>
 <tr height=3D69 style=3D'mso-height-source:userset;height:51.75pt'>
  <td colspan=3D7 height=3D69 class=3Dxl104 width=3D1171 style=3D'height:51=
.75pt;
  width:879pt'>8.2 Security in Application Systems High-Level Expectation:<=
font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Appropriate
  controls and audit trails or activity logs should be incorporated into the
  application system&#8217;s design.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>These controls should include the validation of input data, intern=
al
  processing and output data.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Application systems should also provide controls to allow the Rece=
iver
  Company to segregate the duties of employees using the applications.</fon=
t></td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td></td>
 </tr>
 <tr height=3D65 style=3D'mso-height-source:userset;height:48.75pt'>
  <td height=3D65 class=3Dxl61 style=3D'height:48.75pt;border-top:none'>8.2=
.1</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>What
  procedures exist to routinely verify the validity of the processing
  capability of application systems to ensure data integrity?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td></td>
 </tr>
 <tr height=3D57 style=3D'mso-height-source:userset;height:42.75pt'>
  <td height=3D57 class=3Dxl61 style=3D'height:42.75pt;border-top:none'>8.2=
.2</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Are
  controls in place to prevent changes to the application from being made i=
n an
  unauthorized manner?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D61 style=3D'mso-height-source:userset;height:45.75pt'>
  <td height=3D61 class=3Dxl61 style=3D'height:45.75pt;border-top:none'>8.2=
.3</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Are
  the documented application access control procedures in place to protect =
the
  source code, binaries, or actual databases or data?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D64 style=3D'mso-height-source:userset;height:48.0pt'>
  <td height=3D64 class=3Dxl61 style=3D'height:48.0pt;border-top:none'>8.2.=
4</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Are
  tools available in the production application environment that would allow
  data to be altered without the production of an audit trail?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.2=
.5</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"How are audit trails and activity logs stored and handled secure=
ly?  ">How
  are audit trails and activity logs stored and handled securely?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl61 style=3D'height:33.75pt;border-top:none'>8.2=
.6</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Is
  a host-based intrusion-detection system employed in the production
  application environment?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td colspan=3D7 height=3D46 class=3Dxl104 width=3D1171 style=3D'height:34=
.5pt;
  width:879pt'>8.3 Cryptographic Controls High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Service Pr=
oviders
  should use internationally or nationally accepted cryptographic methods a=
nd
  key-management techniques to protect information when other controls do n=
ot
  provide adequate protection or if the Receiver Company&#8217;s
  information-classification policy dictates.</font></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D82 style=3D'mso-height-source:userset;height:61.5pt'>
  <td height=3D82 class=3Dxl61 style=3D'height:61.5pt;border-top:none'>8.3.=
1</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Is there an encryption policy that would include the entire end-=
to-end transaction (e.g., origination, storage, network path, backups, reco=
very and legally mandated provisions)? ">Is
  there an encryption policy that would include the entire end-to-end
  transaction (e.g., origination, storage, network path, backups, recovery =
and
  legally mandated provisions)?<span style=3D'mso-spacerun:yes'>&nbsp;</spa=
n></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td colspan=3D2 class=3Dxl39 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D81 style=3D'mso-height-source:userset;height:60.75pt'>
  <td height=3D81 class=3Dxl61 style=3D'height:60.75pt;border-top:none'>8.3=
.2</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Please state the algorithm and strength of the encryption used f=
or securing authentication credentials (e.g., passwords, PINs) and other da=
ta during transmission/storage. ">Please
  state the algorithm and strength of the encryption used for securing
  authentication credentials (e.g., passwords, PINs) and other data during
  transmission/storage.<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.3=
.4</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Is
  a risk-assessment methodology employed to determine the level of encrypti=
on
  necessary within the environment?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl61 style=3D'height:32.25pt;border-top:none'>8.3=
.5</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Does
  the Service Provider&#8217;s data-security policy dictate when and how
  encryption should be employed to guard the data?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D65 style=3D'mso-height-source:userset;height:48.75pt'>
  <td height=3D65 class=3Dxl61 style=3D'height:48.75pt;border-top:none'>8.3=
.6</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Is
  other sensitive information (e.g., Receiver Company information) protecte=
d en
  route to and while it is stored at the Service Provider&#8217;s site?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td colspan=3D2 class=3Dxl39 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D68 style=3D'mso-height-source:userset;height:51.0pt'>
  <td height=3D68 class=3Dxl61 style=3D'height:51.0pt;border-top:none'>8.3.=
7</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Is
  personal data encrypted in storage or are appropriate access-authorization
  models in place to ensure adherence to the Rule of Least Privilege?</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>8.3.=
7.1</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"If YES and data is not encrypted, please describe the authorizat=
ion model implemented (i.e., who has access to data)?  ">If
  YES and data is not encrypted, please describe the authorization model
  implemented (i.e., who has access to data)?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl67 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td height=3D63 class=3Dxl61 style=3D'height:47.25pt;border-top:none'>8.3=
.8</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  proprietary encryption algorithms are used, have their strength and integ=
rity
  been certified by an authorized evaluation agency?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td colspan=3D2 class=3Dxl39 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'mso-height-source:userset;height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>8.3.=
9</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>What
  cryptographic methods are employed (e.g., hardware or software) and where=
 are
  they deployed? What is the nature of the data being encrypted?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.3=
.10</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Are there cryptographic key management policies and procedures? =
 ">Are
  there cryptographic key management policies and procedures?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td colspan=3D2 class=3Dxl39 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl61 style=3D'height:15.75pt;border-top:none'>8.3=
.10.1</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If YES, who is
  responsible?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.3=
.10.2</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If YES, do the=
se
  policies include maximum key life provisions?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.3=
.11</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Are digital certificates or other public key technologies used? =
 ">Are
  digital certificates or other public key technologies used?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.3=
.11.1</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  YES, what is being used and has it been tested for interoperability betwe=
en
  solutions?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.3=
.12</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Does
  the Service Provider rely on an internal or external certification author=
ity?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D47 style=3D'mso-height-source:userset;height:35.25pt'>
  <td height=3D47 class=3Dxl61 style=3D'height:35.25pt;border-top:none'>8.3=
.13</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Which
  non-repudiation methods are used (e.g., time stamping, voice recording,
  digital signatures)?</td>
  <td class=3Dxl66 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D498 style=3D'border-top:none;border-left:none;wi=
dth:374pt'>&nbsp;</td>
  <td colspan=3D3 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl30></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td colspan=3D7 height=3D37 class=3Dxl112 width=3D1171 style=3D'height:27=
.75pt;
  width:879pt'>8.4 Security of System Files High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Service Pr=
oviders
  should document, control and maintain system files.</font></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.4=
.1</td>
  <td colspan=3D5 class=3Dxl62 width=3D609 style=3D'border-left:none;width:=
457pt'>Please
  describe the service policy for management and security of system files.<=
/td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.4=
.2</td>
  <td colspan=3D5 class=3Dxl63 width=3D609 style=3D'border-left:none;width:=
457pt'>Is
  authorized access to system files established, controlled and maintained?=
</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.4=
.3</td>
  <td colspan=3D5 class=3Dxl63 width=3D609 style=3D'border-left:none;width:=
457pt'>Does
  the Service Provider back up system libraries regularly so that they are
  available to be recovered in the event of a system problem?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.4=
.5</td>
  <td colspan=3D5 class=3Dxl63 width=3D609 style=3D'border-left:none;width:=
457pt'>Are
  system source libraries controlled?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.4=
.6</td>
  <td colspan=3D5 class=3Dxl63 width=3D609 style=3D'border-left:none;width:=
457pt'>Are
  critical system files ensured for integrity?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td colspan=3D7 height=3D63 class=3Dxl104 width=3D1171 style=3D'height:47=
.25pt;
  width:879pt'>8.5 Security in Development and Support High-Level Expectati=
on:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Service Pr=
oviders
  should ensure all proposed system changes are reviewed and tested to be s=
ure
  they do not compromise the security of either the system or the operating
  environment.</font></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.5=
.1</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"What is the documented change-control process?  ">What is the
  documented change-control process?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.5=
.2</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Who
  is responsible for that process?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.5=
.3</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Does
  the change-control process include a review of code changes by information
  security?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D62 style=3D'mso-height-source:userset;height:46.5pt'>
  <td height=3D62 class=3Dxl61 style=3D'height:46.5pt;border-top:none'>8.5.=
4</td>
  <td class=3Dxl65 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Are
  procedures in place that require emergency changes to be supported by
  appropriate documentation (e.g., evidence of management approval, code
  review)?</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.5=
.5</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Is the development/test system segregated from the operational s=
ystem?  ">Is
  the development/test system segregated from the operational system?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.5=
.5.1</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>If
  YES, are test data or live data used in the testing process?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D61 style=3D'mso-height-source:userset;height:45.75pt'>
  <td height=3D61 class=3Dxl61 style=3D'height:45.75pt;border-top:none'>8.5=
.6</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"If Receiver Company personal data are hosted at the Service Prov=
ider, are they masked/anonymized in the development, test and/or production=
 environments?   ">If
  Receiver Company personal data are hosted at the Service Provider, are th=
ey
  masked/anonymized in the development, test and/or production
  environments?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;</span></=
td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D66 style=3D'mso-height-source:userset;height:49.5pt'>
  <td height=3D66 class=3Dxl61 style=3D'height:49.5pt;border-top:none'>8.5.=
6.1</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If personal da=
ta are
  not masked, is a procedure in place to ensure they are deleted from the
  development and test environments when no longer needed?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.5=
.7</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Have developers been trained in programming techniques that prov=
ide for more secure applications?  ">Have
  developers been trained in programming techniques that provide for more
  secure applications?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span><=
/td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D64 style=3D'mso-height-source:userset;height:48.0pt'>
  <td height=3D64 class=3Dxl61 style=3D'height:48.0pt;border-top:none'>8.5.=
8</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'
  x:str=3D"Is there an effective process by which the feedback from testing=
, employees&#8217; performance metrics, and quality assurance efforts are i=
ncorporated back into training?  ">Is
  there an effective process by which the feedback from testing,
  employees&#8217; performance metrics, and quality assurance efforts are
  incorporated back into training?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D65 style=3D'mso-height-source:userset;height:48.75pt'>
  <td height=3D65 class=3Dxl61 style=3D'height:48.75pt;border-top:none'>8.5=
.9</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Does
  the Service Provider use a programmer&#8217;s development manual to guide
  programmers in creating safe and secure code?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D63 style=3D'mso-height-source:userset;height:47.25pt'>
  <td height=3D63 class=3Dxl61 style=3D'height:47.25pt;border-top:none'>8.5=
.10</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Is
  there a process and required timeframe in place to allow for testing and
  application of up-to-date security patches from vendors?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl61 style=3D'height:27.75pt;border-top:none'>8.5=
.11</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Is
  interoperability tested between new and existing applications?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D70 style=3D'mso-height-source:userset;height:52.5pt'>
  <td height=3D70 class=3Dxl61 style=3D'height:52.5pt;border-top:none'>8.5.=
12</td>
  <td class=3Dxl64 width=3D353 style=3D'border-top:none;border-left:none;wi=
dth:265pt'>Does
  the Service Provider perform security acceptance testing of the updated
  application, environment and supporting components?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D353 style=3D'width:265pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D498 style=3D'width:374pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet015.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet015.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(14);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>57</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1263 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:948pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D370 style=3D'mso-width-source:userset;mso-width-alt:13531;wid=
th:278pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D445 style=3D'mso-width-source:userset;mso-width-alt:16274;wid=
th:334pt'>
 <col width=3D64 span=3D2 style=3D'width:48pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl155 width=3D1135 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:852pt'>9.<span style=3D'mso-spacerun:yes'>&nbsp;
  </span>BUSINESS CONTINUITY MANAGEMENT:<span style=3D'mso-spacerun:yes'>&n=
bsp;
  </span><font class=3D"font9">Business Continuity Management control addre=
sses
  an organization's ability to counteract interruptions to normal operation=
s,
  including:</font></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl158 width=3D1135 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:852pt'>&middot;<font class=3D"font12">&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </font><font class=3D"font9">Business continuity planning &#8211; Governe=
d by
  corporate policy, business continuity strategy based on a business impact
  analysis and documented plans.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 height=3D17 class=3Dxl158 width=3D1135 style=3D'border-ri=
ght:1.0pt solid black;
  height:12.75pt;width:852pt'>&middot;<font class=3D"font12">&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </font><font class=3D"font9">Business continuity testing &#8211; Regular,
  periodic testing and documentation of business continuity strategy and
  follow-up actions.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D26 style=3D'mso-height-source:userset;height:19.5pt'>
  <td colspan=3D7 height=3D26 class=3Dxl161 width=3D1135 style=3D'border-ri=
ght:1.0pt solid black;
  height:19.5pt;width:852pt'>&middot;<font class=3D"font12">&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </font><font class=3D"font9">Business continuity maintenance &#8211; Iden=
tifies
  ownership of business continuity strategy as well as ongoing reassessment=
 and
  regular, periodic maintenance.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D49 style=3D'mso-height-source:userset;height:36.75pt'>
  <td colspan=3D7 height=3D49 class=3Dxl154 width=3D1135 style=3D'height:36=
.75pt;
  width:852pt'>Documents that May Be Requested:<font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Business continuity plan, techno=
logy
  recovery plan(s), testing schedule, latest test results or generic test
  results, contract, copy of insurance declaration pages</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D65 style=3D'mso-height-source:userset;height:48.75pt'>
  <td colspan=3D7 height=3D65 class=3Dxl105 width=3D1135 style=3D'border-ri=
ght:1.0pt solid black;
  height:48.75pt;width:852pt'>9.1 Aspects of Business Continuity Planning
  High-Level Expectation:<font class=3D"font9"> Service Providers are expec=
ted to
  have comprehensive business continuity plans, including having technology
  solutions that ensure recovery of services to Receiver Company during a t=
ime
  of business interruption.<span style=3D'mso-spacerun:yes'>&nbsp; </span>T=
hese
  plans should be tested at least annually and results of the tests should =
be
  made available to the Receiver Company.<span style=3D'mso-spacerun:yes'>&=
nbsp;
  </span>The Service Provider is responsible for ensuring its suppliers have
  business continuity programs and that those plans are included in recovery
  testing.</font></td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D26 style=3D'mso-height-source:userset;height:19.5pt'>
  <td height=3D26 class=3Dxl54 style=3D'height:19.5pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D370 style=3D'border-top:none;width:278pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D445 style=3D'border-top:none;width:334pt'>Testing
  Performed and Results</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt'>9.1.1</td>
  <td class=3Dxl65 width=3D370 style=3D'border-left:none;width:278pt'
  x:str=3D"What is the business continuity strategy? ">What is the business
  continuity strategy?<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl65 width=3D64 style=3D'border-left:none;width:48pt'>&nbsp;<=
/td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>9.1.=
2</td>
  <td class=3Dxl64 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the business continuity strategy include the following components:</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
3</td>
  <td class=3Dxl65 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Risk
  Analysis<font class=3D"font9">:</font></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>9.1.=
3.1</td>
  <td class=3Dxl64 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>What
  approach and tools have been used to conduct risk assessments?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
3.2</td>
  <td class=3Dxl64 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  the site adequate to recover management-identified critical systems?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D42 style=3D'mso-height-source:userset;height:31.5pt'>
  <td height=3D42 class=3Dxl61 style=3D'height:31.5pt;border-top:none'>9.1.=
3.3</td>
  <td class=3Dxl64 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  the site adequate to recover management-identified critical business
  processing?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl61 style=3D'height:34.5pt;border-top:none'>9.1.=
3.4</td>
  <td class=3Dxl64 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Has
  a business impact analysis been conducted or refreshed during the past 12
  months?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D41 style=3D'mso-height-source:userset;height:30.75pt'>
  <td height=3D41 class=3Dxl61 style=3D'height:30.75pt;border-top:none'>9.1=
.3.5</td>
  <td class=3Dxl64 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  there a risk matrix for defining criticality, business processes, financi=
al
  risk, customer risk, and legal/regulatory risk?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
4</td>
  <td class=3Dxl65 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Recovery
  Service Levels<font class=3D"font9">:</font></td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl65 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td colspan=3D2 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>9.1.=
4.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Can
  the Service Provider meet the recovery time objective(s) (RTO) and recove=
ry
  point objective(s) (RPO) defined by the Receiver Company for each service=
 or
  product provided by the Service Provider?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
4.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Can
  the Service Provider meet throughput and response time objectives defined=
 by
  the Receiver Company while operating in recovery mode?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
5</td>
  <td class=3Dxl62 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Plans<font
  class=3D"font9">:</font></td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
5.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the Service Provider have a plan?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
5.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  the plan reviewed by senior management and the board of directors at least
  annually?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
5.3</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the plan cover the management-identified critical business functions?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
5.4</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Has
  the plan been maintained annually or updated when major changes/enhanceme=
nts
  have been implemented?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
5.5</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Has
  a quality assurance review been completed for the plan during the past 12
  months?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
5.6</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Have
  third-party vendors that provide services, information, or supplies to
  Service Provider been identified and documented in the appropriate BCP or=
 DR
  plan?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
6</td>
  <td class=3Dxl62 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Test
  Testing<font class=3D"font9">:<span style=3D'mso-spacerun:yes'>&nbsp;</sp=
an></font></td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
6.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"Does an annual recovery testing program exist, and does it inclu=
de a strategy for testing the plans, frequency of tests, test schedule, and=
 type of tests conducted (e.g., tabletop, live test)?  ">Does
  an annual recovery testing program exist, and does it include a strategy =
for
  testing the plans, frequency of tests, test schedule, and type of tests
  conducted (e.g., tabletop, live test)?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
6.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"Is the Receiver Company involved in test exercises? ">Is the Rec=
eiver
  Company involved in test exercises?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
6.3</td>
  <td class=3Dxl64 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Are
  third-party providers involved in the test exercises?</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
6.4</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"Is documentation maintained on historical test objectives, outco=
mes and issues, including followed-up responsibilities and an ongoing updat=
e process for existing plans?  ">Is
  documentation maintained on historical test objectives, outcomes and issu=
es,
  including followed-up responsibilities and an ongoing update process for
  existing plans?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
6.5</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  testing targeted toward thorough end-to-end exercises of the plans to ens=
ure
  all components are tested concurrently?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
7</td>
  <td class=3Dxl62 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Availability</td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
7.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  the backup server/computer facility provided internally?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
7.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"     If NO, please indicate the name of the service provider.  "=
><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If NO, please
  indicate the name of the service provider.<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
7.3</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>How many miles=
 away
  is the backup site from the primary site?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
7.4</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>Does the backup
  processing facility have electrical power supplied via a UPS system and d=
oes
  it have emergency power generators to protect against local power outages=
?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
7.5</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp; </span>Are communications l=
inks
  to and from the backup recovery facility maintained and tested as part of=
 the
  back-up service&#8217;s ongoing disaster preparedness program?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
7.6</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the recovery site use a different power grid and telecommunications grid =
from
  those used by the primary site?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
7.7</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Where
  the primary site is located out of region (i.e., offshore), is there also=
 an
  in-region (i.e., onshore) recovery site?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
7.8</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"Does a process exist to evaluate the political stability of each=
 country in which the Service Provider operates?  ">Does
  a process exist to evaluate the political stability of each country in wh=
ich
  the Service Provider operates?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
7.9</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
  </span>Please describe any impact this evaluation has had on the choice of
  recovery sites.</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
8</td>
  <td class=3Dxl62 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Event
  Management<font class=3D"font9">:<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp;</span></font></td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
8.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the Service Provider have a strategy for disaster declaration and
  notification to its customers and third-party providers?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
8.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  there a designated command center where management can meet, organize, and
  conduct emergency operations?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
8.3</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the Service Provider have an internal processes for handling incident
  management (e.g., production assurance, help desk, ticketing, escalation)=
?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
8.4</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the Service Provider have a crisis management plan?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
8.5</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Is
  there a communication plan for notifying Receiver Company that a major ev=
ent
  has occurred and could potentially impact service delivery?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>9.1.=
8.6</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Are
  there react procedures, including the strategy and plan to provide a
  workaround, timely processing of outstanding work, minimize customer impa=
ct,
  and return to normal working conditions?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
9</td>
  <td class=3Dxl62 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Governance<font
  class=3D"font9">:</font></td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
9.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the Service Provider have formal governance body for business continuity?=
</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
9.1.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If YES, please
  describe the governance process and organization.</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
9.1.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'><span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;&nbsp;&nbsp; </span>If NO, is ther=
e plan
  to have such a body in the near future?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
9.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"Does audit play any role (formal or informal) in the governance =
process? ">Does
  audit play any role (formal or informal) in the governance process?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
9.3</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"Have key Service-Provider positions been identified and appropri=
ate succession planning performed?  ">Have
  key Service-Provider positions been identified and appropriate succession
  planning performed?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></=
td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl63 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl34 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>9.1.=
10</td>
  <td class=3Dxl62 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Insurance<font
  class=3D"font9">:<span style=3D'mso-spacerun:yes'>&nbsp;</span></font></t=
d>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td colspan=3D2 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
10.1</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'
  x:str=3D"Does the Service Provider have insurance coverage for business i=
nterruptions or general services interruption regardless of the reason?  ">=
Does
  the Service Provider have insurance coverage for business interruptions or
  general services interruption regardless of the reason?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td class=3Dxl33></td>
  <td class=3Dxl34></td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>9.1.=
10.2</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the Service Provider have insurance coverage specifically for significant
  outages?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td class=3Dxl33></td>
  <td class=3Dxl34></td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>9.1.=
10.3</td>
  <td class=3Dxl63 width=3D370 style=3D'border-top:none;border-left:none;wi=
dth:278pt'>Does
  the Service Provider have insurance coverage pertaining to specific produ=
cts
  and services provided to the Receiving Company?</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl64 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D445 style=3D'border-top:none;border-left:none;wi=
dth:334pt'>&nbsp;</td>
  <td class=3Dxl33></td>
  <td class=3Dxl34></td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D370 style=3D'width:278pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D445 style=3D'width:334pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet016.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet016.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(15);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:TopRowVisible>33</x:TopRowVisible>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>39</x:ActiveRow>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1105 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:829pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D364 style=3D'mso-width-source:userset;mso-width-alt:13312;wid=
th:273pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D421 style=3D'mso-width-source:userset;mso-width-alt:15396;wid=
th:316pt'>
 <tr height=3D54 style=3D'mso-height-source:userset;height:40.5pt'>
  <td colspan=3D7 height=3D54 class=3Dxl164 width=3D1105 style=3D'border-ri=
ght:1.0pt solid black;
  height:40.5pt;width:829pt'>10.<span style=3D'mso-spacerun:yes'>&nbsp;&nbs=
p;
  </span>COMPLIANCE WITH LEGAL/REGULATORY REQUIREMENTS:<font class=3D"font9=
"> The
  process for researching, evaluating, and complying with all national and
  other laws and regulations that are relevant to the business, process, or
  activity being undertaken in the particular jurisdiction.</font></td>
 </tr>
 <tr height=3D67 style=3D'mso-height-source:userset;height:50.25pt'>
  <td colspan=3D7 height=3D67 class=3Dxl167 width=3D1105 style=3D'height:50=
.25pt;
  width:829pt'>Documents that May Be Requested:<font class=3D"font9"><span
  style=3D'mso-spacerun:yes'>&nbsp; </span>If Receiver Company is a current
  customer of the Service Provider, obtain Technology Service Provider audit
  report from FFIEC, third-party assessment reports, regulatory reports, an=
nual
  report (if a publicly traded company), financial statements for prior two
  years (audited, if available), and current service provider credit rating=
s.</font></td>
 </tr>
 <tr height=3D64 style=3D'mso-height-source:userset;height:48.0pt'>
  <td colspan=3D7 height=3D64 class=3Dxl105 width=3D1105 style=3D'border-ri=
ght:1.0pt solid black;
  height:48.0pt;width:829pt'>10.1 Compliance with Legal Requirements High-L=
evel
  Expectation:<font class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp;
  </span>Service Providers should establish and adhere to policies to ensure
  compliance with applicable legal and regulatory requirements, including
  agency legal opinions and guidelines.<span style=3D'mso-spacerun:yes'>&nb=
sp;
  </span>These regulatory requirements should reflect any international
  environments that must be accommodated based on processing locations.</fo=
nt></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl54 style=3D'height:15.0pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl48 width=3D364 style=3D'border-top:none;width:273pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl48 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl53 width=3D421 style=3D'border-top:none;width:316pt'>Testing
  Performed and Results</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt'>10.1.1</td>
  <td class=3Dxl62 width=3D364 style=3D'border-left:none;width:273pt'
  x:str=3D"Is there a compliance officer/department?  ">Is there a complian=
ce
  officer/department?<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></=
td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.1=
.1.1</td>
  <td class=3Dxl59 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>If
  NO, who is responsible for ensuring compliance with applicable laws and
  regulations?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>10.1=
.2</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  procedures employed to ensure compliance with privacy laws/regulation
  requirements related to maintaining security, confidentiality and protect=
ion
  of customer information?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>10.1=
.3</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Have
  the Service Provider&#8217;s operations been audited for compliance with
  privacy laws/regulations?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D160 style=3D'height:120.0pt'>
  <td height=3D160 class=3Dxl61 style=3D'height:120.0pt;border-top:none'>10=
.1.4</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  procedures employed to assure compliance with the USA Patriot Act regulat=
ion
  on customer identification and verification for account opening,&nbsp;and=
 the
  institution's customer identification program (CIP) required under the ru=
le
  (for example, the rule's requirement to retain records regarding identify=
ing
  information obtained and the information used for verification)?<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Please indicate any differences
  imposed by Service Provider&#8217;s requirements.</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.1=
.5</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  procedures implemented to avoid using material that would infringe on
  copyright or other intellectual property restrictions?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>10.1=
.6</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Is
  there a policy in place to protect intellectual property rights (ownership
  for the information system, source code, processes, concepts, etc.) that =
are
  owned by or used for Receiver Company processing?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>10.1=
.7</td>
  <td class=3Dxl78 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>If
  the Service Provider retains ownership over source code, are escrowing is=
sues
  detailed?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>10.1=
.8</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  software products developed on behalf of the Receiver Company registered =
with
  the proper authority in a timely manner so they have appropriate patent,
  trademark or copyright protection?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>10.1=
.9</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  Internet domain names registered with the proper authority?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>10.1=
.10</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'
  x:str=3D"When transferring encrypted information or cryptographic control=
s to another country, is there a process in place to ensure interoperabilit=
y, compliance with international law, and support? ">When
  transferring encrypted information or cryptographic controls to another
  country, is there a process in place to ensure interoperability, complian=
ce
  with international law, and support?<span
  style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.1=
.11</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'
  x:str=3D"Are procedures in place to collect adequate evidence in support =
of a legal action against a person (either internal or external) or organiz=
ation?  ">Are
  procedures in place to collect adequate evidence in support of a legal ac=
tion
  against a person (either internal or external) or organization?<span
  style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.1=
.12</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  information systems compliant with published standards or codes of practi=
ce
  for the production of admissible evidence in court?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.1=
.13</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  procedures followed to ensure a strong evidence trail for incidents invol=
ving
  paper documents and/or information on computer media?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>10.1=
.14</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Where
  appropriate, is customer advocacy performance and compliance monitored?</=
td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>10.1=
.15</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  Service Provider financial obligations to subcontractors being met in a
  timely manner?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td colspan=3D7 height=3D43 class=3Dxl104 width=3D1105 style=3D'height:32=
.25pt;
  width:829pt'>10.2 Review of Security Policy and Technical Compliance
  High-Level Expectation<font class=3D"font9">: Information systems should =
be
  audited regularly for compliance with the Service Provider&#8217;s securi=
ty
  policies and standards.</font></td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td rowspan=3D2 height=3D83 class=3Dxl61 style=3D'height:62.25pt;border-t=
op:none'>10.2.1</td>
  <td rowspan=3D2 class=3Dxl62 width=3D364 style=3D'border-top:none;width:2=
73pt'
  x:str=3D"Does the Service Provider have in place a review process for sta=
ndard security configurations for networks, operating systems, applications=
, and desktops, including: ">Does
  the Service Provider have in place a review process for standard security
  configurations for networks, operating systems, applications, and desktop=
s,
  including:<span style=3D'mso-spacerun:yes'>&nbsp;</span></td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D66 style=3D'mso-height-source:userset;height:49.5pt'>
  <td height=3D66 class=3Dxl61 style=3D'height:49.5pt;border-top:none;borde=
r-left:
  none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.1.1</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Security
  patches</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.1.2</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Vulnerability
  management</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.1.3</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Default
  passwords</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.1.4</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Registry
  settings</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.1.5</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Version
  management</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.1.6</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>File
  directory rights and permissions</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>10.2=
.2</td>
  <td class=3Dxl64 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Are
  the following regularly reviewed to ensure compliance with security polic=
ies
  and standards?</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.2.1</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Information
  systems</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.2.2</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Systems
  providers</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D40 style=3D'height:30.0pt'>
  <td height=3D40 class=3Dxl61 style=3D'height:30.0pt;border-top:none'>10.2=
.2.3</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Owners
  of information and information assets</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.2.4</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Users</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl61 style=3D'height:15.0pt;border-top:none'>10.2=
.2.5</td>
  <td class=3Dxl79 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Management</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
  <td class=3Dxl61 style=3D'border-top:none;border-left:none'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.2=
.3</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Please
  describe the technical compliance checking of operational systems to ensu=
re
  that hardware and software controls have been implemented correctly.</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D4 class=3Dxl63 width=3D613 style=3D'border-left:none;width:=
460pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.2=
.4</td>
  <td class=3Dxl63 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>What
  security tools are used for vulnerability or penetration testing, monitor=
ing,
  policy compliance, antivirus, firewall, application gateways, and guards?=
</td>
  <td class=3Dxl63 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D4 class=3Dxl63 width=3D613 style=3D'border-left:none;width:=
460pt'>&nbsp;</td>
 </tr>
 <tr height=3D92 style=3D'mso-height-source:userset;height:69.0pt'>
  <td colspan=3D7 height=3D92 class=3Dxl104 width=3D1105 style=3D'height:69=
.0pt;
  width:829pt'>10.3 System Audit Considerations High-Level Expectation:<font
  class=3D"font9"><span style=3D'mso-spacerun:yes'>&nbsp; </span>Based on t=
he risk
  assessment of the services to be outsourced, an annual assessment of the
  Service Provider by an independent auditor or assessor, including testing=
 of
  controls and onsite testing and validation, may be required.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>The scope of the report should i=
nclude
  the environment used to process Receiver Company&#8217;s applications and
  data and a follow-up review to confirm that recommendations have been imp=
lemented.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>The Receiver Company should reta=
in the
  right to audit in order to ensure that controls are verified as deemed
  necessary by the results of the Receiver Company&#8217;s risk assessment.=
</font></td>
 </tr>
 <tr height=3D80 style=3D'height:60.0pt'>
  <td height=3D80 class=3Dxl61 style=3D'height:60.0pt;border-top:none'>10.3=
.1</td>
  <td class=3Dxl62 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>Please
  provide third-party assessment reports for the last two years from intern=
al
  and external auditors and indicate if examinations have been conducted by=
 any
  regulatory agencies.</td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td colspan=3D4 class=3Dxl63 width=3D613 style=3D'border-left:none;width:=
460pt'>&nbsp;</td>
 </tr>
 <tr height=3D60 style=3D'height:45.0pt'>
  <td height=3D60 class=3Dxl61 style=3D'height:45.0pt;border-top:none'>10.3=
.2</td>
  <td class=3Dxl62 width=3D364 style=3D'border-top:none;border-left:none;wi=
dth:273pt'>In
  cases in which deficiencies have been noted, is there a documented current
  status reflecting whether the deficiency has been corrected?</td>
  <td class=3Dxl62 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D64 style=3D'border-top:none;border-left:none;wid=
th:48pt'>&nbsp;</td>
  <td class=3Dxl75 width=3D421 style=3D'border-top:none;border-left:none;wi=
dth:316pt'>&nbsp;</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D364 style=3D'width:273pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D421 style=3D'width:316pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/sheet017.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:x=3D"urn:schemas-microsoft-com:office:excel"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DExcel.Sheet>
<meta name=3DGenerator content=3D"Microsoft Excel 11">
<link id=3DMain-File rel=3DMain-File
href=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagemen=
tAccessControlSystemDevelopment.htm">
<link rel=3DFile-List href=3Dfilelist.xml>
<link rel=3DEdit-Time-Data href=3Deditdata.mso>
<![if IE]>
<base
href=3D"file:///C:\E5382234\2-mht-SecurityPolicyAssetClassificationControlP=
ersonnelManagementAccessControlSystemDevelopment_files\sheet017.htm"
id=3D"webarch_temp_base_tag">
<![endif]>
<link rel=3DStylesheet href=3Dstylesheet.css>
<style>
<!--table
	{mso-displayed-decimal-separator:"\.";
	mso-displayed-thousand-separator:"\,";}
@page
	{mso-footer-data:"&L&\0022Garamond\,Regular\0022Copyright BITS 2004\.";
	margin:1.0in .75in 1.0in .75in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-page-orientation:landscape;}
-->
</style>
<![if !supportTabStrip]><script language=3D"JavaScript">
<!--
function fnUpdateTabs()
 {
  if (parent.window.g_iIEVer>=3D4) {
   if (parent.document.readyState=3D=3D"complete"
    && parent.frames['frTabs'].document.readyState=3D=3D"complete")
   parent.fnSetActiveSheet(16);
  else
   window.setTimeout("fnUpdateTabs();",150);
 }
}

if (window.name!=3D"frSheet")
 window.location.replace("../2-mht-SecurityPolicyAssetClassificationControl=
PersonnelManagementAccessControlSystemDevelopment.htm");
else
 fnUpdateTabs();
//-->
</script>
<![endif]><!--[if gte mso 9]><xml>
 <x:WorksheetOptions>
  <x:Print>
   <x:ValidPrinterInfo/>
   <x:Scale>65</x:Scale>
   <x:HorizontalResolution>600</x:HorizontalResolution>
   <x:VerticalResolution>600</x:VerticalResolution>
  </x:Print>
  <x:Panes>
   <x:Pane>
    <x:Number>3</x:Number>
    <x:ActiveRow>9</x:ActiveRow>
    <x:ActiveCol>1</x:ActiveCol>
   </x:Pane>
  </x:Panes>
  <x:ProtectContents>False</x:ProtectContents>
  <x:ProtectObjects>False</x:ProtectObjects>
  <x:ProtectScenarios>False</x:ProtectScenarios>
 </x:WorksheetOptions>
</xml><![endif]-->
</head>

<body link=3Dblue vlink=3Dpurple>

<table x:str border=3D0 cellpadding=3D0 cellspacing=3D0 width=3D1542 style=
=3D'border-collapse:
 collapse;table-layout:fixed;width:1156pt'>
 <col width=3D64 style=3D'width:48pt'>
 <col width=3D475 style=3D'mso-width-source:userset;mso-width-alt:17371;wid=
th:356pt'>
 <col width=3D64 span=3D4 style=3D'width:48pt'>
 <col width=3D299 style=3D'mso-width-source:userset;mso-width-alt:10934;wid=
th:224pt'>
 <col width=3D64 span=3D7 style=3D'width:48pt'>
 <tr height=3D17 style=3D'mso-height-source:userset;height:12.75pt'>
  <td colspan=3D7 rowspan=3D3 height=3D52 class=3Dxl116 width=3D1094 style=
=3D'border-right:
  1.0pt solid black;border-bottom:1.0pt solid black;height:39.0pt;width:820=
pt'>11.<span
  style=3D'mso-spacerun:yes'>&nbsp; </span>Other</td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D7 style=3D'height:12.75pt;mso-ignore:colspan'><=
/td>
 </tr>
 <tr height=3D18 style=3D'height:13.5pt'>
  <td height=3D18 colspan=3D7 style=3D'height:13.5pt;mso-ignore:colspan'></=
td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td colspan=3D7 height=3D45 class=3Dxl55 width=3D1094 style=3D'border-rig=
ht:1.0pt solid black;
  height:33.75pt;width:820pt' x:str=3D"Documents that May Be Requested:  ">=
Documents
  that May Be Requested:<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span=
></td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl55 width=3D64 style=3D'height:33.75pt;border-to=
p:none;
  width:48pt'>&nbsp;</td>
  <td class=3Dxl56 width=3D475 style=3D'border-top:none;width:356pt'>11.1 H=
igh-Level
  Expectation:</td>
  <td class=3Dxl56 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl56 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl56 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl56 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl57 width=3D299 style=3D'border-top:none;width:224pt'>&nbsp;=
</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl40 style=3D'height:27.75pt;border-top:none'>&nb=
sp;</td>
  <td class=3Dxl41 width=3D475 style=3D'border-top:none;width:356pt'>Questi=
ons/Control
  Activities</td>
  <td class=3Dxl41 width=3D64 style=3D'border-top:none;width:48pt'>Domain</=
td>
  <td class=3Dxl41 width=3D64 style=3D'border-top:none;width:48pt'>Yes</td>
  <td class=3Dxl41 width=3D64 style=3D'border-top:none;width:48pt'>No</td>
  <td class=3Dxl41 width=3D64 style=3D'border-top:none;width:48pt'>NA</td>
  <td class=3Dxl43 width=3D299 style=3D'border-top:none;width:224pt'>Testing
  Performed and Results</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl31 style=3D'height:29.25pt;border-top:none'>&nb=
sp;</td>
  <td class=3Dxl42 width=3D475 style=3D'border-top:none;width:356pt'>&nbsp;=
</td>
  <td class=3Dxl42 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl42 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl42 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl42 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl26 style=3D'border-top:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl32 style=3D'height:29.25pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D28 style=3D'mso-height-source:userset;height:21.0pt'>
  <td height=3D28 class=3Dxl32 style=3D'height:21.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D33 style=3D'mso-height-source:userset;height:24.75pt'>
  <td height=3D33 class=3Dxl32 style=3D'height:24.75pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl32 style=3D'height:32.25pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl32 style=3D'height:34.5pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl32 style=3D'height:33.75pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td colspan=3D7 height=3D46 class=3Dxl55 width=3D1094 style=3D'border-rig=
ht:1.0pt solid black;
  height:34.5pt;width:820pt'>&nbsp;</td>
  <td colspan=3D7 class=3Dxl44 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl31 style=3D'height:32.25pt;border-top:none'>&nb=
sp;</td>
  <td class=3Dxl52 width=3D475 style=3D'border-top:none;width:356pt'>&nbsp;=
</td>
  <td class=3Dxl52 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl52 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl52 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl52 width=3D64 style=3D'border-top:none;width:48pt'>&nbsp;</=
td>
  <td class=3Dxl26 style=3D'border-top:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D46 style=3D'mso-height-source:userset;height:34.5pt'>
  <td height=3D46 class=3Dxl32 style=3D'height:34.5pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl32 style=3D'height:33.75pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D37 style=3D'mso-height-source:userset;height:27.75pt'>
  <td height=3D37 class=3Dxl32 style=3D'height:27.75pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D49 style=3D'mso-height-source:userset;height:36.75pt'>
  <td height=3D49 class=3Dxl32 style=3D'height:36.75pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D40 style=3D'mso-height-source:userset;height:30.0pt'>
  <td height=3D40 class=3Dxl32 style=3D'height:30.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D36 style=3D'mso-height-source:userset;height:27.0pt'>
  <td height=3D36 class=3Dxl32 style=3D'height:27.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D39 style=3D'mso-height-source:userset;height:29.25pt'>
  <td height=3D39 class=3Dxl32 style=3D'height:29.25pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D45 style=3D'mso-height-source:userset;height:33.75pt'>
  <td height=3D45 class=3Dxl32 style=3D'height:33.75pt'>&nbsp;</td>
  <td colspan=3D5 class=3Dxl37 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D43 style=3D'mso-height-source:userset;height:32.25pt'>
  <td height=3D43 class=3Dxl46 style=3D'height:32.25pt'>&nbsp;</td>
  <td class=3Dxl51 width=3D475 style=3D'width:356pt'>&nbsp;</td>
  <td class=3Dxl51 width=3D64 style=3D'width:48pt'>&nbsp;</td>
  <td class=3Dxl51 width=3D64 style=3D'width:48pt'>&nbsp;</td>
  <td class=3Dxl51 width=3D64 style=3D'width:48pt'>&nbsp;</td>
  <td class=3Dxl51 width=3D64 style=3D'width:48pt'>&nbsp;</td>
  <td class=3Dxl29>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D86 style=3D'mso-height-source:userset;height:64.5pt'>
  <td colspan=3D7 height=3D86 class=3Dxl105 width=3D1094 style=3D'border-ri=
ght:1.0pt solid black;
  height:64.5pt;width:820pt'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl31 style=3D'height:15.0pt;border-top:none'>&nbs=
p;</td>
  <td class=3Dxl52 width=3D475 style=3D'border-top:none;width:356pt'>&nbsp;=
</td>
  <td class=3Dxl25 style=3D'border-top:none'>&nbsp;</td>
  <td class=3Dxl25 style=3D'border-top:none'>&nbsp;</td>
  <td class=3Dxl25 style=3D'border-top:none'>&nbsp;</td>
  <td class=3Dxl25 style=3D'border-top:none'>&nbsp;</td>
  <td class=3Dxl26 style=3D'border-top:none'>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl37></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl37></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl35></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl37></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl37></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl37></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl37></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D20 style=3D'height:15.0pt'>
  <td height=3D20 class=3Dxl32 style=3D'height:15.0pt'>&nbsp;</td>
  <td class=3Dxl37></td>
  <td colspan=3D4 style=3D'mso-ignore:colspan'></td>
  <td class=3Dxl27>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D21 style=3D'height:15.75pt'>
  <td height=3D21 class=3Dxl46 style=3D'height:15.75pt'>&nbsp;</td>
  <td class=3Dxl51 width=3D475 style=3D'width:356pt'>&nbsp;</td>
  <td class=3Dxl28>&nbsp;</td>
  <td class=3Dxl28>&nbsp;</td>
  <td class=3Dxl28>&nbsp;</td>
  <td class=3Dxl28>&nbsp;</td>
  <td class=3Dxl29>&nbsp;</td>
  <td colspan=3D7 style=3D'mso-ignore:colspan'></td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D14 style=3D'height:12.75pt;mso-ignore:colspan'>=
</td>
 </tr>
 <tr height=3D17 style=3D'height:12.75pt'>
  <td height=3D17 colspan=3D14 style=3D'height:12.75pt;mso-ignore:colspan'>=
</td>
 </tr>
 <![if supportMisalignedColumns]>
 <tr height=3D0 style=3D'display:none'>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D475 style=3D'width:356pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D299 style=3D'width:224pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
  <td width=3D64 style=3D'width:48pt'></td>
 </tr>
 <![endif]>
</table>

</body>

</html>

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/oledata.mso
Content-Transfer-Encoding: base64
Content-Type: application/x-mso

0M8R4KGxGuEAAAAAAAAAAAAAAAAAAAAAPgADAP7/CQAGAAAAAAAAAAAAAAABAAAAAQAAAAAAAAAA
EAAA/v///wAAAAD+////AAAAAAAAAAD/////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
///////////////////////////////////////////////////////////////////////////9
/////v///wMAAAAEAAAABQAAAAYAAAAHAAAACAAAAAkAAAAKAAAACwAAAAwAAAANAAAADgAAAA8A
AAAQAAAAEQAAABIAAAATAAAAFAAAABUAAAAWAAAAFwAAABgAAAAZAAAAGgAAABsAAAAcAAAAHQAA
AB4AAAD+////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
////////////////////////////////////////////////////////////////////////////
/////////////////////////////////////////////////////////////////////////1IA
bwBvAHQAIABFAG4AdAByAHkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAWAAUA//////////8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHCHmBH3s8UB
/v///wAAAAAAAAAATQBCAEQAMAAwADEAOQA2ADUAQgA2AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAABgAAgH///////////////8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAACAAAA9jkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP///////////////wAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA////////
////////AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAA
AHic7b0JPJRf+z8+YxjbbU267aSQrduuIlkaKWSXfaax71laUPZRGSKJkpAWS3alKGZMTUJF2SIk
S0K2JCn870HP0/fzPJ/fs7ye/+/5f19/7/t13We5z7nOcl/nnOtcM3Om5RXX+5wy/gHEH7AXgUIs
rzAj0L/FIddpFZwIBN16eHllZeVX9MoG/ldhCSZg/R3SiAH20945I0xMMDHDxAIT63oaVdhlh4lj
TQQQXDBxw7QJJh6YNsPEC9MWmECY+GDih0kAJkGYhGAShkkEJlGYxGDaCpM4TNtg2g6TBEySMEnB
tAMmaZhkYJKFSW69HjthF4JJASZFmJRgUoZJ5be2qMP+XTDthmkPTBowaa7K9lqaDaysmCH84CsI
fhf7Eb6wG4A49cep4P8IXgTDX8Y8PU1umOlW40lrjzG/p4WETbm+VTxFohCIv0wkSMRhhDfC5V8q
83ewIOiQv7fnn83Hs+4qICwQOMTRf7sO7PAsSGsKrU3/bPm0flodPAha+3Xh/vdB+MP9cBTh+S+X
z/1vtJ9WX/d1P20c0CH+OmY28P8vINeW8f+B6Rjhf1r+kLDkoFjWZP+PY5+2Bhh54AP8Av1cg0St
/QKcRU088EHBAS6rS4qROS1Kzw+/upjQ/PLrj+XVEXO7yo/9s3WgX5dpWh3+6YpvYBXc8ETEAvee
HfwSfgkCvK7um4FnBdr6ikYYw/NTADxD4eA5ck1YOBG6B0HE4YMohClMPgeY6f+WrwZCe9/sSs7q
msuL0INnV1eYQzDMg7bWmMD+AJjcVu/+8GwkCi8Vfqsr0O8wgXUCJGIWdmml0lao4zAnbzilP+yK
IrQRzvAVAPsD4YumXXAgBCQiOGL2sYIxP1f4YuZW+GOmhXfGVCJk9B4xrnOltQH2A7RZe30MIOhF
19y/plgH3DY6+rX5/Zef/jc/TV+CxXfaezUxepqm86Do1zj80o9/rQ8iCOQ0TYc5imCcpuk6aDT/
3LXuNsUS15pzUxq2Eyc+rCCKVdbSCwNrxe9DCM/Qloo1yV5BREREIL7ROgN+XdMtq93CNM20Xhit
QhwI1LTvaqXop6VWC2ee5vytS2mMaESHYFnNh/hLI+inacpdOf1aPI0XbZhuQrBO0xRCeu217uGc
/uvb5pr+NfRouXVWxWktN5L2ANYTzeHctMmkDkmradMqC1o/MyHoUTTVUguFXM3/V06/up/uN6Hy
h1lmw5X8q3DQr73Cv/hW9iHXc9PyMtVvRv4KM/zWdrpfHUFL5E+rxb41Bvq8SbSJkA6NYqBnoEPR
oxD/E78qZoHwgEcCTdpE4XHhgjgBu2ar6zcOQet0FZgPHYKBAUmHZETTMfwSuN/7P4J2M4e1LB9Y
DvxWx5SSxGrprGh6Ohr+tHRtWNI91sfhrvUa09OjUEgkEyruD7N41rqrvz7SfFZHlzOCpm3TI2aY
iLCgtsB53FeZV7xRJ9DoV9/8Xvbq6ECgOJF/E/srRuyPFd7Av4BbaBJjJaISFowA6D/PnfY2zWAN
kfsP8VywLLusz5w4WIp1EfLw3RCWL5qUBMLxp/6pNBvYwAY2sIENbGADG/jfhTWrowsCD2+uTFZt
wd7/Un5eBBJJ0zFpW8Q/s79ARcardt9f7u/P6Nbtvybreia0ev3zAP8N+ydtu7Jt3W+9at1wRujB
Lh4RvLq7+6MV4v8EfrgFtC0mbav3z5bPBlOz9pqfAd4L0kr1Wd2nnUIYwKW7/sXiEgTr2n6rO8s/
g9R6+5n+hfLlabf1PenELTLCBrFqweGuW4tae7Ju32BHHPU86vnF+ov13/JhpuddbUeyJnKV/saQ
+AesrHD8Q/8vOKzep9dD03/w/5n7y6pPgyjyH7s0I4vsuvsrng61xktvPfyP3Aq6v+8+o1vbfT1f
D/8zLk0qZ+Hy52DeI7BY0d78Z7q1T9X+iF/trviTbk+mW/tk7c/q9/m3ev7O75er9z/G6VrYCPnX
+Gd0f9+l8Wf5O3z+GH72J/WmR659wsi97v6j917xJ/X4I/8/a+e/i1/8frVHfV2OsEGDC1+mapF/
lLfH6/3yZ+3+74CJ7b9dgw38V0G/ZqylzfUL/+26bOD/dbChVj9jtmRC+hyA3z3dr3V+6b9dsQ38
38aaCf+38b+8/N+u0gb+b4IO3roJIkRKScaiMImVSolvhUk8KWnbNpi2l8JJfIWnb6vAu5w/fk55
zsRYn42Fn6bPsBkc0DODFQkbeC0hrX63R0A0nfa1LHo3bSN4d1B2NjV97jYcRpsYWuxHrG5Tbr3N
6oV9zP4HbAIRiB4+BKKGDnltP24P7UthBnraFievfc40ulj06PJ1A7eYN0W7fast2zjfBTWFSqvQ
qxWamvp/UPWtuP0kwdPijXm2awRFSFC7NDO7zvr1651DhOaKvrNTex5q29qGIDzEYtyvy96qfdgd
LXAOFwGiz/5HbqO80OIm70dZ2EFeiDBZei4VByoALYvH3iWEkkCROCNZgOL+PfhdQgZJ3THl0zNS
emLWIIAygoDcHM1JqiZW9ll0TC3sM8I+ElJtrXzW+4CZSDG+a5SWXPDd4q7PQwbivVOClaXOJFAg
B2InIKuZifPZsTsc2J7e8IiSa5PDauRaByRSnVVuo3kOBG4C9X90OKtYOXPtVvOlEy9UYvJizlo0
i2bIzcl9FEoa5XCUxLNQ36l7eqixnzp2EUTnaR3PDLNSaR19IDs6y0N8evj62NmASx5lHJevF6oD
U0+ylW7ivAtqC5tjFMIUiNcbWjvqmezxalFcPoFWioes2XJnh0SNvkMSig7nbkBoxfhwRQUiPxis
vdXjkwxW4/xjUfnTDNG1d2UtY+n0VDRFavkxLSFMmETdMrro2RCVRpbWr5ulR3o4G4ccFzmDEvLp
xrcm9qnqOPo8wwXhGOslH4+zkg447bjADwYSEoLiU83oMemVoUF8aDZxoUULB0lVfPXhRTMw9+AX
/4wokDiX2tPRMtpKJ1QsGMe1o1/67W5lBTC9FKWUX7BN+fYx16CJdmib++mDmACbqunHKMrHVs0m
l69vL5REcj2McLvTd5J3t4EcKG7qteene7xp1624a8s6YPT4ArZcc+ImL5B3Ut/nrreOWLjU7RUd
0PGhP//eiZsAypkcMXlTvKpDhf/xc2HPyAv1TP37i88UGcUKH7dlRdv3HvnEdbDooV1ThEIYH/Fc
V5GQZ+/naXEE/oW0imyex9lhU3AAr8xZ8zW1v7tHDjQZT2yemGx44x6gtdXANsR6+iZm6ihHikAJ
a/tX795Ki61VL0+/VGDyBK7cuxhTnL2N+KIm21rG1C1w6+63IMGlQeFQCJvQwf16xvNd96nTxcrE
HdzAS+f8gmN3o5AOTvtvIqGtBjo1r6HLTMRzx6/sLVclam959111k3xsKoN4l9Et3F2uOyErC378
F0gRHTfZUgV47J1ztsXBclbTkPmFCyy986gVamd2xB/q8kYT9x5/nRTbGD3OgF+Ix0VQRYlEc828
LST/XpXjKH0/dTrUYooJWfsKWpJJXLF/J4rKOV7+CXTeTY8/8IPnNSs25hs9e9/BzOG3EPHw0wRC
JNeEYi0LRkQDAaCCmKhKDrlJilg9x2R1enH7kX0WKbjsTZeFNqn35Bv6rrxrbEmjML3tZdclTYcx
UQXfppmgidNelvrY5gH7JjHQ1RAaPXEgjZy+NS4RusJBscg/GfaxCRez+4HC4t6nXKBu9UGkCwns
abkuDi0eEIUUgFw8NPfyA7l4ZxxXtT++c863U/4egsrdw2eZRVC4l6PJiJV1DNZ+YnIMSXTrLowI
wAo+jOW4Vxs4R/rad8qcTrdzh8nxyi4ZrGHroRBD0llGq9xum+4qV1J6HR0V9JlYkjwGUGZT5B+w
DvVZhmxaGYboQgl5hfEfTZiB3sxL80W7oEQNaSbygWtP4rDpdjMHmC8pE0u9Bm7dGsPpTdqk2n2F
DG81PG41q+PBYBkebB/49P764H6IcNOuUhEbk5ZbGKcg+RJX8tEFvJwVRHYQrTIRkKFYsxOxudeQ
gycgt8p8J/sj+6G5yfpaFUaMCR9Ed5VbrWtcDKz2k3t0ro6JmrTbMw47WnsPannAhMmKat3zVTZq
5qcjdNViUBWi9Q76Xk1z4Tj2SYVhHJY40yvmgMIbLe7ao9qEtUDzd5Km65mkY10qAKq9daEX1tAA
LAy0aMLK9gOYghw3MDsQe+npYCcJfOPLro8d3ZcrKywiH6lws0nAxz4WalOQj6/2ZcXDkrGAgRaD
6CGRKIWCpf2+Dihxe9aip7V9fOg8Xozdhw4fnAYHOS/+2c7I5ESqVrtdgpMYsTpvvBYiaNFTr21i
S4CZR9bd4JzjBs0TU+a7KQDKgilXXhiuwSEscdfTt+OpafWjw8s3Tv6shTrgPEmbAaEohZvcekq9
HISvqigKSSQWuu2HEt8ZraJWzI8556ZGwBm9kY/NMa+MpL9UHDHwQo3piH7achDYxAU2nYgsGwpe
kVnGgtme4Pav1QrAIbhEFvySPGRmviRlSZHio/XnTE2QFi/Gs0/8lhloWVW0hSzl+DISF3FGljiw
GcKk3mhWICATHwtinEz5KaWzLQwncgCV3D0A6gm0z5okZVSXD1LtB/gpCAcE3gXElESaKrUFcxGL
K6UIyMV8yMxvT8pRUJSAlCbQHiCJcxlqMesrVJ4whtz1hQGippFaorOBwe8J2EvhftHrj7RttpBA
RxQeC1opAKjzONCkWS2itTMMSMIduTIaVYOF1xx+y4s/dVa5yUe0QoA4AblaVggX8TwzP4CaCwGX
r37YtRr319tiDuRKwLkdBZPO4fZJEJBXHJF4V1Dvqj+39Wqrfr8FsRGtm19hQQva05I4BYW/lLF6
69bPPh//O/vsLCBXRu786vpL2nSPVrnRrSDDp9hfi7IkZWHx3hJIsH7Zi2sGKM/ndMCqM6mBr+a+
ejEpAW3fIme+yrzW0ifgVou/iX0X8iLz4bQ/M7x0HyaYamxthvZ9jT/3LiSH8lCZUizClisnC5d2
RooYiwPlLJ+2U9y/sH5/CC1OoXLnhJf1KVKPd+HA7BCQoRjmMI7T2J9Yf+OMKrH4bt5i8DNWlmoA
Y2fFQ0EoAJwURDtFSmpIEYwdXvIGY2dOKhCH4YX5m2Csbn075Lu8vb924axmuAaxOE+KgHO5wcpu
a2rgu+ywUKvR9CpWLN47/nwBwdSsZBx76WvRU1hOGXK99XL5MXaTbxmgRjq2VXHAXLmTl3cUxMe6
bakfPXh+8RPUffFGAY5+E2c1AmN0x5o9d8UROr9oRUAWxJq2uTkw5Ta8MgO9jMS2kI6Ybc6xYM0d
navhxtgl5fNiWoVaUqGD52Vjy8I2gSHvqodCXMFsW3B/ezU35nmvwQ4g9Yac1KAtyPDwjDTxzsv2
kY87YnOirnDXFceactJb1EsJKD+kw5RUpA7lsE7SfeJDuy+cgbqjNGhT1JJJmNjeEkKyCHdq/egh
1q4gBsDBlRwpE2tqWeiFG+p/sHwEDFmKisLA0sqCu3tr/oQDIF4zXhjD1SXUshkyvB/mx4rLy+jg
riqOa3Ud2RFjujnCkU6XI3jzAzvG3One2ELc0IgzmK0D5nbZqb+dYwFdgyT7+3XAclufc3ZqEclv
38MdVMcGKFWnTPkLERWriiNzWHsvdTZsrj87ZbQYzEd89AgezehcecRjNNWd3FBt3IhtWLpVYtmP
wHQ8t0fjCwrfbIfe31f5hrAiu8c/qmZC9+X7NDaYofF3Z8YkIMVGuLcUQV1vtyNppNLJtqt3fywo
gm9dfRzoKInPMq5dTsRFnMc27CF/aOeZQoqfBuKxsqmW1WjM1OsDIzujFD5e90uE63ToxV4VeLgy
UXnepg13HMIR5Yk3I7eC5WYuezWnUOLBnjxkzprGuswwNuCjsY+5wCtTOt35u0+9MpzoKWzab56V
0VPNht98kQbnF04mMsPTRKRpzxV7egqrdkqnATNgemfWr76PCfMOw0w802/ed8aRIXenpgoLtkEi
Vy7o0yk+wMF7Mt8UgS8OpAW2tpzN6oK7BYF/d8KiMsua7K+vHa1iLh2RLCHwej90lrPy3P1T36GO
xUV7+ujz1TfuHN9L3HXqMkMwF6DYcvbK8ziFbWR08GbAofiWfx4Z2vcWCvKaO73V5OhJSf/sW+U4
kPJ0rwM6GlDeGqckgCk5keokZU3ORiX4MwTgsnv9Zt9t43GP0U2wB1H8gSduB20m7uvnf2QMoqU2
EU7Xn473MMxYRCRgA6rfy3vea7nThKWvTjHJTWak+Fxm7YWHYvYe5qcONpBGRv/7zfEOc0W2m3bf
C8RyhjWFwQ/zGNjsJQHUJYLCkADrp93gzS9GeYFs5AOjy6wopgTkyqezj7ipS9ZWx5T2bPVpr3/w
w9PQjDwZM3eTl9rb+cmM5fthRzi7BevgZOFe6a85LEHOR6vf3zyoUcOJGZ2MAdgLcCZUnWpOTCnG
wt+EbXBExNeE5bhkW7Aj7M9Cvh7TXT5hYVuNJZjSR0O8r1MhatJKzM6vEIs9PB5L94jZtjxKLr4O
HR/ncBRIrcx+mDtY+yJKoFMGFyOQcPnAwS3vTu3o/VIkin7MQ22hH9pDgfYxvEm359e7eEkLXkbO
ah+SeJp4v0y1J+sQjt7ORMtMOqT/ZpX3cOeEGTjA21Zh/WX+hsWZ/hA54k+BzqtpYbdmf3TAA1GN
f3Witmxq1nvDWc2LObPPscrYOiews54pziEzpdTXRyvnfleGF5a+ZlMndvhDnotlDYiZT7nZyJB6
woWRfwul4cxPeE5Nbfoy1Vjr95gf4743zy6y+8LjicbgEU+QHEc0Lu8+HLd/08NqQWpLS4CsVXho
2ZMaWF2LaukwtgLwLD0sYwHgFfNYWA0A0deP+dyW6aSAHuDLIlsFwFs7EJUwDqt21nssV0N+H0ri
uPh/jF/TCyIfl27DGg5jHNQiuB7YVBhdpuyruHL9HQLz3rXoHrcCYLILmDCuz5ftRWBEme4JScdF
Ein57vryMdrfJI9vMWFHodJVXyXvIWX/SFGTZHbwT3NRqQioitDuzzpiII0FqBaubcGs4Fx+69sd
o1FFevdBtPvP21DDg6ZyGyRKvrb55E9hqMGuk3eTBSnCWFpJuI4ZUL/1KbCGDnMq+9gm8PnTZWls
9osjirk1JFFbtvF38HTBD542H+13wJp0Mk8WRyrwm/tc5qiK1L7GLzRRHGn606GrhyRqnMA+30GK
2Ce+c6yaA1DPP0exQaHoEqbQFJFB7TQQPaHJJL5TuI4DCCexcrixAU/sRshfoUfInRrXVCCopWH2
PQZ6ZD4IARBo9PFWHRI4QWLVbZEGB9UIA7H8mW+DeTCXo6uikC+ViBW4fRrXh98XYR/koI8URSET
TDLMl+EQilLnzwF3yMf+EzEDc5KcwZbkCCW5wpBvUQP2kvq4fd/m2HDqRlJ6DsCgHmhzwlMtGtef
JUhoDfcCjcOjej5F1Rh62VxInkRTao13P37MTiju/RaD+yaZ2efIiGoZ4TmjBuZYfwapIhyon27g
nfqI6b3XTUaPQ3cP5LZnrBiCHf5pxwrY0UkJkjzVIsAjY+OY5MGBJex7n0fMN/ioOJCzfvjkSS0Q
jL7OJH7nzLdo7ToVc8Zc/32DBAhD0LaJfVDGjSnZNGJ48IEYQFSeUyWQobsCnS+9c1kn3zXfp/px
UNre64G7orNPxGg/TUiFmt90TLFEnxdYOQK2uGs0S8DTi+85XBJzIOGZHzPeW6Nk2R6kylMiJvX0
GVOhbHyj1LfLkGEuGcpuxYKS9RFJ23O7QutbBiIT2WFlcXFiLxeGEP8tJmfqQ3DcEWYUAaVo/2gH
8TpuwVeBKEkpVZameOrKAT5SbonTRrjRST2fhRTcqLzpquPlsFQci8Oc6A7KORHbuofAh6aULpkR
LlAa8t474AwTB2zBJ9k2R07E5hhWzX4TYdNl4C/6uaRPMYnEyIQrETdh04/V+QG6+x2Kfn53o4Ag
oRVbEyyIodIn9NSDryJxaO06JeI5mimjX5XSVdllCbeAJHodFxdsBx4mIMf4CFwURCabOL66/zQO
+EgCz9ATWwvoKFjwIIBSXlXfbGGmBhBVBEnTVwHU03Vlb8nXZiWbddLMCkQ3ZKWIdCTgAICyqrS5
O9PSPYE0xmcZYUaJwd9z+anN0Nmb/QLUeoh4Zi+x2W/MF1b+Vk0snDRtClapMunW+K8qcnPm2DmA
MmoPql3jafqLdnnpq6bSDliLXa30es4W9OC0d9297Ki/0UXhWzg7UdVBdDVZIU750zZbASKlcBu0
lhO+FTHIK9LcXiFqK6xlosc6oOqwL7AaK08k0vHRVNBJ9tzU8JUZaFEJ924mtGiV6y61CwdXPZrg
XmAwsT82fBfxexzJHUTfdAGT5g1BPvNqR47c7GsvShczcBBwIFSCeC3AD8DHc7KHd6TjTAz8mMU/
dm+GeyAQN3TyZCC422L3I2XLxDg1QtnPMPD7zny4wg+hi8xZVXE5Owu0hODe8x7/SG7YMTMMzX7c
+3LUUoU440YCX8UkW8quNq8JNyQp1DppCtp8nl99E8eLzLUKcEAVoXVEQnMzxuqrL5DrRuvfSnKE
CKyyNZ6/i7XKL4lLdjAJZCEuPyNBOa/h3OyKNLV3iD3KdpAMDBqCz4Myzuwmqmzpvt1JaRAas5W9
owOZMciANvtXO+6xMGay5kDPAd/C8PZ6TqfwBg261Z75Fqtg68pR3zD+amdE6/AtQeNIhRVBUOKT
NuhzPHknIfnK/RVx7NAu1wufIaIS1nD7cu8WDD74rBi4A8+NSbMcYoBmD8Jyl6zid0eY+uBOYxgp
FEl85O7vCmJSPm+iqCMJB1J3efvDcRTlt1YXyA2Cno8QmL7M7nRG8YH5RSWsd2LwyEcF8EoqPD+n
fQIdDz/DVp566YAUlzlGge7GSJKO+HKI35H6wWUGYm68uQRVa3ycZKGco3rhGmKu0NLdyc14FanQ
K4wx1hilz9YGzzH5NhrcDGYgCvZPMDIAgwCIf3mPFn63vWL3wmkmzKTs2Zr60UxnMZDZ7jQXcZkF
5MvvDbGq5/ToNvwoH5l8/GVIzylzTkyavHxPzSHszaYAQjQflRnqEMQeaWCAXrN1D90uiC4bqpRZ
DS4tj96X1QZbL9ahiJUnHntVsBMOpC3ZvlOBqq85W90QJeb140cs81lhlVz6OzyqWLB6XrsvWX7m
B/Prj1MSs4LIu6Bu+4/Fkcljxvevt/vOR0E3bi8q0iI8+0NLLmuDpuZbDdLGYYbcp8fH9lgw5EII
Fejg3q7JH3MNLy6mnpkpCSLgvhtsEdR8zoIvrsBWPrQpl298rnUdB16IyYy66kAvLsyYsMzFQTnL
o+l6yWVLADNxIf/QwiYC167nBGJFi/wQN9iKwW9PvMOG9yRuZazd+eWzIlgGKB3T4CMMSy7rgLhn
h0I7mrBPbO9FloIErkk71rjjxdFcgce+fRrwpTjxEuWd70y8/fBFBxwQlLGMZSLqN7SkazA+1mEn
pSsWjBz4yPRD3XRSD9ZWXtY2q/hPtkP1nc/3la1uLs+TmO4llbudHqo+zk+8cQ//wbh4qI+JyNlR
/tzncuD2rOH50wURXJ7akuUsqsTWqJlstoRzStCHd7Cq8mjieaYC6NNsYvBYPqb1IvMTyw8OlQpg
pMyjloqP2iD1Dj8YJITpFqYgnmJbtti3ChTVzLnxw+KeeKqM/YI/nZ81D0bgWKJszOVI09dji3st
ydmKsY6PK3GAKlA+V7sAOrFE7/a8wbK8mSdW+yn3rPQO5qxEMrS3nTzNkaGh8FNCij3avZyq8+w6
g9LTA3xZ5Rz7HnErum/jRxKQ5bg5dmClkt2OZfwouHyyQ/5G+yGSu27x8OK9TyAwvUPt0FxSYoD4
MV9J7IPhtLB4c1bfFeHt3zWyAipO3htlcrMtkFooC7GyPzP2ROqqnT8TevFSxrMSzPgPnaFD5FLk
y6GOSxh8UVgUerHNZUSsQGxWfkQt2FcJSGLA59zVkHp2fiyQiapTw73ZMmFU+3I5ttlZ9Y23XhlB
xeR+QOquQ/Vm7MTEhjSkrqng4BHKmBF1Vrvl+RfxIoA3sqd4H/npkYowmbq4ON2k08kubdm3Zm0g
6s2Eq9I2cqamxgPZppOnLO1QBFzqZin12+V7xaaQvsZPAzh0qtFBuolQw/VUM2uLTGTF/f02DlmK
rMVFyHqmYInixsVnX/c5njAZSE7bYRNN+kqAFg1BH9NgwSf7T/Wmq29yKUdz7BYhZUcdOxjbOyh2
MTelpuDAYbHbAIoeIhiCF3Tbd+h82h95qtPAhw0AOseTGq+SyGpJWQ+/Kbl9HTvHrydx/Wx4RU17
+ZnUyqTQAKLzJDGaq2SfepAModW1Y9uHjqdQ/feDOA1FGe7AcVvQQV2Egthcf9K5Q3ysIxW64bKF
LCVSWSNAVL1asrMuf/nhH+wr/2tvF6EA69yV5BC39WVbHuiQ+P9Cvf7zt+yD4HiJ4BsjgQahrkl3
j6v6xbqmCUZfePt6lAsUuamyhxy+rRzOqrt8/Mf4imbWit3E9/GP4QTS0eWf25U+qy5fGI6UH9G6
aZpa0x6+3DcfVJmWpTycY2vRxzhhHv4y6+2dpZLwzVrXw08VyG1F3q0sju+4fPtVZqai52u1gmmD
TgoUW+DzSavNqcd2niPlUKcX1/xuBzn1xgqFtiNXZD/z2irf9m5e0P05ZqHAUfdg6U5QX9m2zg/h
bqAbOf0ihMFNRUcpuJLTDc84xPI+XmqIzlE8sY24XYR6V/UzQ/ruOX7qm4AZNlUtVRMRAjGyNToH
Is4svXEGCM1qXnWhD4s67fQGpn7cTiytbL9nJwiO7Wt0qiheyCuaH/HiyNJq7o833qP9TYwFbGsV
uMuPOihFar9TZjksUiTt3R6e/hrDZrvUij8WiozvVtwFUV9xoxmp5SJtpsu29xR8ht40ogpQWPRp
KumcmNlOz6aYbXJgYF6nXVVUHEeQn5ll+hPy8q3TFsWPCpeoo1sv5ocwHaoglGXeyjXsHR8Ln/Cw
uNcmUni79n3Z0+qEsWmxrR7Wu1TUTFbc8OR9htkuFdCZ7NDDlrHBTTcVitEEXwyx1cYCazIZ73C6
MOz7Ow0l4HvFF9wBRk0wi1m48SF7Aerj/Yf0pTapvWfnO6OQX53uamafOqScf2lre3bhdCJwAyKo
fboV5CSo4OLROy+vTOy7X7p0KxHDSf3wvXyXdEACI3biTgG82M3cEdh1ZreoXTLfntoTPadnQi3u
dQvdxAGN0qQWN2krRuyCW76Hjxsbys+1HDuR08wfUZYVHb3b4+v27MRvR8+bby9RBVwMWo7j5pBg
7qwg7m5X8BURNGHs8gGwsD2SHjexa0LG33fm4yjZRA5JalkisOnacENnmhxUiabwslq994iQACHg
4PeCLzu/Qmg6Qq3Wu3CdwzKPPw3XISg9akcgPdYX0PFMBL6M7uAmlvueKWPO1iwEITebIuYDpIX4
4etseFVIOCDwzs83GH0H7YeHSSa60uL32dmJNqfooKBtRwXvxTkYTvSNGY35r1hdkQN5GxHAsaVn
uAYzZWB4K6lFhc/lCjfh/Bc8ZMEe0/p8EdQ3hxW9Osur5ti7vEAv1wsucDenoAs/X3lhhsQj0QDs
hKMNNLLiSknKVwE+937xk2azOLUo8h1afhHwKnam+HyKvHQJG7DpfV6yKiMBzE+y4qNWMBGUvSnu
ObsLbFqhoE3FqC2MVFQAI/YsdzlWVgHslrSRoJzsIB2xEAKI4SaEGUx71EyWRTQT1FabC10a0sxm
GPxENpHnB+NVc4URB8Dw1LrSIEZCcXTkTH+7ZRy0zOdw2vp0PCFnzwmhB9hUrUCt5pKt4PxhlG5X
OhuQ+rbSkR3IR36+jft52PImG6pgunjSWwVokF8JxlaOdDJDFjy5zybYiJ/sQY526/cH+o+SwSYs
cIgX8NrDrPvs4cVGPfJo2/042SUQ8ODAHeEa/nETTU5lHRF20Dxagb0rSTEZ/rQnDIVvg6y+x6Eo
/BkuIFaFTZft51tI9HsNv4s51EGV9j/RSZiJ78MPlwoWxA10a9Lnmr8Qd/7hQzE5TA8AJVEPhr99
gm7WjM2jsAsVQCIZZAYPMxJKb2BlmcFXguDj4SAVYCqfiEJ9cyOZ5BZih17w05+21q04Be0d1NM7
xQKYxueESjPaumgyUEJepxFyJi+RG2pQuVtiBcDPb7jqFxqicZnvj4GDSJDjxgFCMoMum40thGEl
hL0rwDbvAE9uj8MFLcgwEkLap3pBBGIzH+27AGN4bNcrr+NvIYzsXlbCATwxrI8Tl/a12HCEfGQW
e+SZYd/tvXezRuhTjrnuBTQzPJ7QswOpaFzeCBc2TB1ybktlHrSWAJQvMugmKPCSSoW/dkNzyhqs
BGK1LLjp2pOpsWOFUbgXjpzlONFGTuAobzRjbrtHlWaIOgXe+3Y+hEipgqBiSwRjTxFKV1XmFDRi
D1oxccYqxOFOdjAQ44yZN+PAWMg5njNSLCMV1iV4iW+zvjvfvtiIq4szrlm6N3poK7Mum683ZGt+
AE18GztzSldZ93R/VrnN82iFt1LiEOl8RKuNFhtg+pEf9EIZmbMDu6ZZIGF5oHVOBtQVpIqzUl8f
YdNE4lVRanTUnSlVT4Uue4OHr+W4U9LtUimEspXzZM5Iaj5k5VWvxqa7xBPnNY9rRoIjUZQrabvg
HnDBhvUJHX2yVCwcyg9218q/UVfpltKFZNWGY4gvF3eR7745MVdLj+GwFqcw1bfo7ucFTmUgoN1b
qGZ0uU3RCkfML6rFtd2le0qlt9gDfD4tSPU1SNMa8+hkGmTzHCRxvsALol21GNHVOyQpXhU/5Lrf
lyrG7WGhXN1d+wLsCFaB+NNZaMlyIxWCrFpWiiUeDpNHfS5pgym9LT8gSKfrQmwxDklkuH0FBVwz
9aFwmm4hnayG9NpSGQe/KXFQvdXmhIFr8Q+to2NwLGYveyCrvGBe4JgXI/kcB/5CNQ/wQROZN2sn
QZRc0CWnixJ7ny0Z/rBF4CvuZr1XJOqAhRyoZ15VdfMZDx81Db3A8BGQviHQVQ6vI65xuN0ZUap4
r6uXcgzBnsPmP3w4n0aWqcEvuS8Qd+Rx30jkm5jK9MrossygzvNTZ6+U9o/ZdsKTV99491RVIztx
6WBjVJkrpTTksVy08PRmaJq8bHXjU+hF7TQPL1xxwqYghg9A61Z1yLD1B0JbjHji6IXCzaGaknRf
sZUnx3j1sg+f9NkhQ7fZNC2yzMlUnljVLKCSvIcRjR6aTOju2aRbrqljK4NLr6oG4VXjXYGgKlGT
vt1Fjh52XkSVDVFAw8Kp+hbxWZ1bUPNJdK1bOiO+bkcwNt1x2QEcO4h9xBWq8UIe8LkfXvVR0zta
fZzxp3dqrDLRsmrvKWg+fl+apjl0X2YHK/UaBz72wNvImZkY62f0xFvcVCVEtPB8SiRGkHp8eyYb
Pr6oRTM06B1hJjJ+8zYceKimZqpAXVYOyNUGQzs9q1+dfnac+SO5Re3hpLATHkDvJfbSpV2JSA47
u81+Z1SZvgM/te+jITtRbswMajaJuJw/e929OXrgEehB2Te0BzB35wOWpBUpUnFlsdnHQLuKgN3E
t4QciYnv0HV/qet8kFWDp+OmplMsKzwDxYQyxnn/QFmcsoMwcdIjh0g+4g1ieg4XXmIjqF4hDKhL
ijkbng7bu/8LGDfTHFvW7+NSD5XMc0F3y85/ftQmceygztGRxCAH2xfwOy1BY75tw4Y5GrCgW3Pa
yVBV9Daik5VO4GE7FrxUdJmRbxtmXpsnvem7vNx9GyhEcj8PlTMS50CXtTSBPbO5HuQjmIoRi04Z
khYAbSdWytUbysoOfmfI3nVPANynEMm7rpST7uJ1T3kZqR9fXIsqU3aMTIWoUoD6WBbUnOe0g5gP
UO/fjlfdOn9lcFZe6GRTpNjtTpJpEQFnGeQpHDESjwNe6NNRPz7PxXJae8oB3ZrchGD9/oKYPqZt
SLx8jILqVONZQb1juLDF+QuvY0HiLSYqT3SkblFWDhsFYuZDbwsTI+afCsSmM0ryU7Wktvx0bSIl
SfU/1ry/rMt7qFoyS5CU2f36pyYzfo5gJQse9WkwA6ff7aDPVYsOQhOqNe/Gco0bYR7ssrlaF82z
jRi+eaULqv68cgvCns8W9JrDEqeDzLKueZaaWp9qjBHrQybUk36Q733fuQ1IwTzefYaOeIeRsu2U
9bArOUkq2Pehvhz+RtPmfAcwPFnrqbjRoBJRSOsYNddgsL5LzrIeGhd8yQ58fXTU92yKOZu71xQV
QZzxkGEl7GrwAFmZB8W4g8sTjT0UGSnQ+foFF0lTCMs/71zMYmrIQNTMZdRV6fiQLGG/jAQlElh1
iZ+m7plXeFXgAHlgSb7M5pjBD3xiHP8ZRcjWw7jzBj/hK91VlTeCna9MPFw/wa9GgAdFeQrNHfT1
bLXjIIT4TJ17psuudSX0nfZNJDhbENp9kZIQAljw3GAvicE9Vv8Cafkjt6ZiNC3SoA5xyFWE8E63
vqVndzI1LicsDXqPtl+onRLJhaBHlTpG9lcP+nRCN29xfAn3Y27mAdS76scmyGCzi5cEpUHZlftK
g4oEboLPHqxgQLEA9S3JV6pvSWANAcpPLRGC9E42VD0+mKHw693X0Du7PVzXEhplmHUzx+nQtZd2
o7GjiUZGW6pKz2eg2hU9wPmE25EKeSxj0zVb7OYq6GhZn7owU0w8tjtzUGssq4MOC/EzUAS1vXyY
vJgNr2AOv0q+TE9UM7cSIhpf3vrNHZyW2i/EEa5pcgqhApz6Tq4U8Bh4Id1rE6etHu0XaowEC/wc
Xtjf6o0eSOuqtgv+6NYFGd651csnCFbvC57Djdz0xUmw6QrpMuNVH37bVsGIrypwik1iZ5utgi40
6RuParG/Gm/v3POpdkH3Wv/RpS4xAUJgTX5hroidrISze7uTJ9lks/tLiWMffd1lxw/+6DkZUmRn
s/30yQw1WRc1LAUacZYpzBp43mLy00lQa1iNcnIR8pdPsDxY4neqr73WOKSw8IuJcFV3FBNprj3n
cYYDODvvW/pMZiiJ3j4ytMDmhFlATF9MplI9aUuMi0yhnbaCS4AVdMbmxTnpnsmrQXX5YnKOwfyW
AYVMeVoWPbcL73ZmZAahCtS8j989RXwdy6H+Lj6dm6Xf8yTTVPA5JX5woKXR/HBq1VmDj9Kyb9/F
jOgteT3e3x1RUq7R3ld4r+qrVNaV8dsCdgzWp6nY9pSMdgsrFQ5Hw2Qffg7qGZ6g6TeFzpnD/QgH
KfCIbGjoi6BnSl2X74e/YDPJHQO+v5DU5D1ZNuAw5WV51YfStTAeOXnrEd/FxyGFuKSH+ql2Dwlq
71kwhXvumkqOV4bboUeNsR9ydxi7nBmNrCbfr0wwTL8uz0iYe3Ozrf2TN6jU5v6EL1GYqD3MXl/q
6YwFV7olX7o9PXeBncjACnofqg8o/KIAcKOffGE7dgXgBZZaRSIiA0djWHdf9TjbtI0dr3o8GtrL
Ni6hyqSLOBldh6QeXY5RF5c7IduYppLDKdqeX9YnleNCd377teOx4mMeNx1njcZXbqdoTMf1O/A2
ZnVxms7pBuN4eSPpQC2nv2d8/y/fgg6BrWk/60yq4mY6t1zOYM3VevBTN9nqCGu0LS9lsaP9HLyt
NwQT6o63bfFUkSm/ywOMN52TbJR122IX73J/Sxl5IsEmu3EmtAXxXCX4tsQD9gTHRzKlr5sn+N4Y
mz3/YdIeYkOoUE59J2wrfueZbB/7V30uIFRI1C6QjrD8vvSe6c1w+msTOn2boKvZ+XeOHLwwvwep
G96/FYi2tZZkQF1+oXQ1al76FXEfpVSuoarlpjKpb08Rb0W5wLGXn7q5rbgwhzYfvC5PNvdhh9qH
IaIbSK3lHgbdleeHxRlfZztmnJ49kRErFVrX+IXdfVvvuy2X3llJOLFivZ9VZBg8QPUqP7+n/WJ2
1jXY49hcvuxRhtbYbbe2DF5dKnydnsFUU+9T3nr9vsOPo1cCkcRe7dmkhJzNdU8utj1mxPf3pbjs
DEi1On/JMT05Anf5yC3s2VsfthR49KQhN6Pz7wfcKhk5/cWwPWPBJD8pYkA+cgfHE/ABPzm05JpT
4+bwO47gaQn2Onupa9XGEmWlY/dFLoPtLKQua0jyVb8J+qHFuA4l2zo7Jevhl7p7c4akFhmqPtZk
/2RhKyv44EmeGUBNIXAdWThMOsJHkAqTEUfgJeKTvaRTbr7HZy8b9141hYY865UGloz3kdLtCgyr
3/Qs5freH8Peda6QGRdwz7hUtQ1ob4/Bcfbbm/cb9c2/KqpSY8LXVUjUGmRFzdzE0RuXx81FRpRR
saN+zLJcoB5QXqJhyxxdnW4OLRvxmQSnR0Nz1R+UdwzLvZXNe7Wda0u6TVBN8Ak2as7THub4sD3d
OE6RHnZKei4UcuPg7qjsnfqWqsy6RXcEIrVjisOVnioSa0iidDJLKg7VPmYuKVCb2TJcysn0qBmn
w4QcK/3jWBPT28s8HMeCJXEa81pHobPCE/0JujzEmfBW3YA9xFh/xQW+tgCQwgUe9QPQ7VX8cZNo
XQ7iJusTdFStEfJ0U5iO+bDHwh0p4MYHZrA7gi167FZGCLiyLVAPZ/L50pSUe/qnAYNVq1UaCXJ6
MDfOEzfzSlGfB92O/5EYJR9TRgesjGxjH3Ti/3ktsygErEtjxVUuloDAt9DIV0IESCRWO9agNje7
3/nbqWyvdvRF6H1Kq54eZ1xr/oX0p9iW6NoTcdqx+szg7HJYAoVJo20070VWiBMfoSMWeh+YNgxR
d0Zps0dd56B8IUUNfDYiJd2x5EHviuKNLOtDobmEt2MbuEYCcWH0I1wGIEf4Kw+IgIeeMB7AQ1Yh
B5RYop9IPlMSXr6uTqzzRPFBhh5lUjExYs98D8cqSGI5Q0F0Hjdhagvcxx/pAb47may5KoNGl5/k
0jUeESKS1dpF4C3blTe4pF2eOPeP9uDeWZj3YIcUkfTAiZM6d5YsevhqSWRrdag5XM1IbeEzyOiJ
4HEs520E+lj4lSgxdIxxrMLeianrAoerzEavuAEUuLiswl1MeJkxe9CBHp1ZyI7m6hKJFtNpqcAl
kZ+wR/va5kIdCGKqP0JLz4lddy7jGKjLR8yJfpS3nCBYcUYCK4sElVT2z3ACx+6EyhPdmDDuIcH0
VFRdvS8l/WzKhChRM0ZLAP24hKOZM5Fcenu/ElGUmMzUz17fhbpnjpvLURjau8Cvs5l4XWpQlHj6
+ud86Mwz3KXYQTGQo9ohatOFaTFm/F4BqqpN4vXT5UZ7bpSkBIBsSxKvceCUJGXhLDnbSYaJ4j6T
8ymN0uUkd5KLqCm488wjdQXAnMqKm5iyucaM7ys07M1r4qt/UjzLpNxiIBJTVuccqAosks8JouRi
tfsyNEa/p+rjvHfOwYlZag0lszJMysy+J3QfNFbZw4JnVX75yCszqhXuDUHTooexksIMgnFlmVU7
Y7Rf+rvRvggxVIOBs/t1wtkNSdkjTe0kUUkebV2zQL/yOqGAvYA0U17sjLUPApfk5/KVaXBg8kVk
600sj6YefxVdfpXINsCz9l0TzqRiqfrO2eqXMQree5N0Mz/Wi/4YzYXuu363AHtcPyAfRmm/MMi7
kqU93zrNGyREzPF4FdZR7ZdY7/5YE0B9ucaA3wdeZx1ZTn5QT08s+36AJHWVeilKOyHK0gh/o08H
BT7pkeKDbo8sGYJTRz9S+gMVgbHLzLy4vOgZPvdtEg9SDU/bOzFRTmD1wFo/DzBLu70qRvtx7GVm
fAJ5Ie0L9mwOGHBfkoJ4TE94mJzjWJYUKg4tjkzhocY+6ZNCwJjYPE9sjr54vqt2PXi17kcilJeR
8nwurC1sx2NpPZDa9fOjOlGfkBvyxXFnwMmfQWBbbHZVMr7IA9y0y5nZb2vwcp8AKdvp0Wvcju8H
dEbOktJfxSgoAA3ziuAc4kY3JiTb2v+LgwnUoQ4sGmhzEqTiBE8lQ8K1KfUzuyyo29jUISaOuQj0
d1ULWHx7z1Oy3Z6GMxB3wI+WceAP9pkLeziU0dFhz/X5QLvwfmsSqLfrY31La869TP59bT0foLOn
Pe3gyaHOnzdGzPsixUTkskNSjEJMI5ia1XH8aMGjc63P8/PGMNa7PaZC85S5wBwVLB0UgkvhF97S
s1XcJJw1VWyHArzceJBOyzV9M6w7cbC2K1v+RqS/AxnEQ3RTAZ2U6W9SYF9upjowNqJ3OOSGBGZM
+8N1+Llo1rP0W/nCMW8h4DvHscss4BPxVFHg8flreAv5BANlw5CeffeCxlQcZ7lDpFi3AWVpZ3RF
wfSC+d2AuMbL9+1G30VPnITyZgQeJpxc0XHSaxs7zY/e1YrZpVPHmEQYmNocfA6oPhn6AWq4d8wy
W/v6q9kdgveKcz0sPMCiUuEj/Wm1YR1MwMAe08sxAxe0nivyEmaI5JNM0WfEArrRvTee87rc6N7E
J4fB0WP2RUN9d99dPg5aHJbzo7rRYeL32IOapmebdeqWxSWjkj8blHib6jqX17EFS0QKHeLB6H9r
mw0T0dw5lDQyVJ8Ul8XCPLSw5W1FgU2ec2k2bsFXo/1oTqTAQku1HpqgH97rdtC8l2j/qmeKTb/G
lR9Twq7VDsbHJ+/NihuRgxI9dnONbeUfshFyV2wIbIuxiMk62hVT7ZHsBSw+O1VaIsuAT31zM+9r
wv4kYbCqF6Me3jr+5Up2LIi2e1ooFpRKFnu1eWZqtGqup9Jxd9fnTD/ubI6FRBaKKDav0rm/2snW
AnE3TFTIqVlDOdxD+suxjMTK6paKLswV3Fy8Ba+I421yfoXV4MQ+ePig2lViXaW8UvRCFTMKFg+n
8w7rkzyx0j9EvfYshA5/29XwSVUZ+By9e48mKP70fpzgzei2mRfRA1tcFTtJoo8mUC6xuKDyFXGn
4SseQzrm2I9uUrlO/MuFNYG9Hz/HMcfvqu4bGRCz0hY5MyB5zznR7X2gVHnct0XPh9mLBV4TVfRD
eftFNGLyM3VWrneFcygAJnkXFsSf/teV0j+9ta2ED/jSYTYbDerTfsdlsN9Yr1gHG/Xv/AZseQWx
+jPQP4L248D3sVmz3w+7cxYmMyFkJCve0s7l8EauHRBBe34WsXbCQRJi7UyNa4i10xTzEGvHLj5B
rJ2LQTumknY+xRBi7TxxWmbaeXQAcu0X8VLrv5xXRq6djbFv/Zf/hsi1c8Yt1su0R66dM+68fmjt
EP3aWeJrP7AP/Bs/rQwLlwCXQJyorryooYevc6DLKYTzX9PBz2h+2tnmxn4BPjhveWe/IITHP8pL
K1sRsZaXVp8/nHGrLk87QPW3vlz1R+lO004F+N2PQvz1bFDE33E3sIENbGADG9jABjawgQ1sYAMb
+E+B4W9OvvzXzqNUh3fD/+r5m2q0G+c/SvXP418t/z+N/83l/5n9Z/UvONpftF+TF+BMSWNCyMh+
L9aD4xj+EAchEYgJxJr95tf/StFsNv6INRtQBGLtbFiarYj2X3E0WxHtf4HSEWt2l2zEmijQbEY0
Wwrt0CHa/8c9QKzZgkjrvF8g/qfNh8Zbx8DCHOER5P27HeWP9hRPTqbVchDr5f09V5jzt/82BNb/
2FB4veIWcAEuf2G9Wu9f/EXXI1XX67Z3PUzz0+xaTiYGek76lgZ6f6k57dBXY5hCEcqIXXBIGYGB
L1X4kkOoIHTgSwn2KcCX3qpPG45Vg1PJIXRXn+2Cw7T0CnB4P/xECXH6z17sBjawgQ1sYAMb2MAG
NrCBDWxgA7/h/wFdkyPqAAAAAAAAAAAAAA==

------=_NextPart_01C5B3D5.8A1E1380
Content-Location: file:///C:/E5382234/2-mht-SecurityPolicyAssetClassificationControlPersonnelManagementAccessControlSystemDevelopment_files/filelist.xml
Content-Transfer-Encoding: quoted-printable
Content-Type: text/xml; charset="utf-8"

<xml xmlns:o=3D"urn:schemas-microsoft-com:office:office">
 <o:MainFile
  HRef=3D"../2-mht-SecurityPolicyAssetClassificationControlPersonnelManagem=
entAccessControlSystemDevelopment.htm"/>
 <o:File HRef=3D"stylesheet.css"/>
 <o:File HRef=3D"tabstrip.htm"/>
 <o:File HRef=3D"sheet001.htm"/>
 <o:File HRef=3D"image001.emz"/>
 <o:File HRef=3D"image002.gif"/>
 <o:File HRef=3D"sheet002.htm"/>
 <o:File HRef=3D"sheet003.htm"/>
 <o:File HRef=3D"sheet004.htm"/>
 <o:File HRef=3D"sheet005.htm"/>
 <o:File HRef=3D"sheet006.htm"/>
 <o:File HRef=3D"sheet007.htm"/>
 <o:File HRef=3D"sheet008.htm"/>
 <o:File HRef=3D"sheet009.htm"/>
 <o:File HRef=3D"sheet010.htm"/>
 <o:File HRef=3D"sheet011.htm"/>
 <o:File HRef=3D"sheet012.htm"/>
 <o:File HRef=3D"sheet013.htm"/>
 <o:File HRef=3D"sheet014.htm"/>
 <o:File HRef=3D"sheet015.htm"/>
 <o:File HRef=3D"sheet016.htm"/>
 <o:File HRef=3D"sheet017.htm"/>
 <o:File HRef=3D"oledata.mso"/>
 <o:File HRef=3D"filelist.xml"/>
</xml>
------=_NextPart_01C5B3D5.8A1E1380--

