MIME-Version: 1.0
Content-Type: multipart/related; boundary="----=_NextPart_01C684B8.FAE701D0"

This document is a Single File Web Page, also known as a Web Archive file.  If you are seeing this message, your browser or editor doesn't support Web Archive files.  Please download a browser that supports Web Archive, such as Microsoft Internet Explorer.

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:w=3D"urn:schemas-microsoft-com:office:word"
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DWord.Document>
<meta name=3DGenerator content=3D"Microsoft Word 11">
<meta name=3DOriginator content=3D"Microsoft Word 11">
<link rel=3DFile-List
href=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganiz=
ationalLecturesWWWInternetE-Commerce_files/filelist.xml">
<link rel=3DEdit-Time-Data
href=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganiz=
ationalLecturesWWWInternetE-Commerce_files/editdata.mso">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<title>Microsoft Security Assessment Tool</title>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"place"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"City"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PlaceType"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PlaceName"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"Street"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"address"/>
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>a</o:Author>
  <o:LastAuthor>a</o:LastAuthor>
  <o:Revision>2</o:Revision>
  <o:TotalTime>3</o:TotalTime>
  <o:Created>2006-05-31T17:49:00Z</o:Created>
  <o:LastSaved>2006-05-31T17:49:00Z</o:LastSaved>
  <o:Pages>1</o:Pages>
  <o:Words>23297</o:Words>
  <o:Characters>132794</o:Characters>
  <o:Lines>1106</o:Lines>
  <o:Paragraphs>311</o:Paragraphs>
  <o:CharactersWithSpaces>155780</o:CharactersWithSpaces>
  <o:Version>11.6360</o:Version>
 </o:DocumentProperties>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:Zoom>115</w:Zoom>
  <w:GrammarState>Clean</w:GrammarState>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
 </w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState=3D"false" LatentStyleCount=3D"156">
 </w:LatentStyles>
</xml><![endif]--><!--[if !mso]><object
 classid=3D"clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id=3Dieooui></objec=
t>
<style>
st1\:*{behavior:url(#ieooui) }
</style>
<![endif]-->
<style>
<!--a.SCRIPTLINK
	{cursor:hand;}
A.scriptlink:hover { CURSOR: hand; COLOR: #6666ff; TEXT-DECORATION: underli=
ne }
A.navlink:hover { COLOR: #6666ff; TEXT-DECORATION: underline }
COLOR: #3333ff;
TEXT-DECORATION: none }
=09

 /* Font Definitions */
 @font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;
	mso-font-charset:2;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:0 268435456 0 0 -2147483648 0;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:536871559 0 0 0 415 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-parent:"";
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	mso-believe-normal-left:yes;}
h1
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:1;
	font-size:18.0pt;
	font-family:Arial;
	color:#6487DC;
	font-weight:normal;}
h2
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:2;
	font-size:14.0pt;
	font-family:Arial;
	color:black;
	font-weight:normal;}
h3
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:3;
	font-size:12.0pt;
	font-family:Arial;
	color:#6487DC;
	font-weight:bold;}
h4
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:4;
	font-size:10.0pt;
	font-family:Arial;
	color:black;
	font-weight:normal;
	font-style:italic;}
h5
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:5;
	font-size:14.0pt;
	font-family:Arial;
	color:black;
	font-weight:bold;}
p.MsoCaption, li.MsoCaption, div.MsoCaption
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:8.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{color:blue;
	text-decoration:underline;
	text-underline:single;}
p
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.copy, li.copy, div.copy
	{mso-style-name:copy;
	margin-top:5.25pt;
	margin-right:0in;
	margin-bottom:5.25pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	background:white;
	font-size:8.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";}
p.msatbullet, li.msatbullet, div.msatbullet
	{mso-style-name:msatbullet;
	margin:.1in;
	mso-pagination:widow-orphan;
	background:white;
	font-size:7.0pt;
	font-family:Wingdings;
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Times New Roman";}
p.datatable, li.datatable, div.datatable
	{mso-style-name:datatable;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:0in 0in 0in 0in;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datatablenb, li.datatablenb, div.datatablenb
	{mso-style-name:datatablenb;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datacell, li.datacell, div.datacell
	{mso-style-name:datacell;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datacellnb, li.datacellnb, div.datacellnb
	{mso-style-name:datacellnb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datacellhed1, li.datacellhed1, div.datacellhed1
	{mso-style-name:datacellhed1;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#0148B2;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed2, li.datacellhed2, div.datacellhed2
	{mso-style-name:datacellhed2;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#6487DC;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed3, li.datacellhed3, div.datacellhed3
	{mso-style-name:datacellhed3;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	font-weight:bold;}
p.datacellhed1nb, li.datacellhed1nb, div.datacellhed1nb
	{mso-style-name:datacellhed1nb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#0148B2;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed2nb, li.datacellhed2nb, div.datacellhed2nb
	{mso-style-name:datacellhed2nb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#6487DC;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed3nb, li.datacellhed3nb, div.datacellhed3nb
	{mso-style-name:datacellhed3nb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	font-weight:bold;}
p.header, li.header, div.header
	{mso-style-name:header;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:18.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;}
p.header1, li.header1, div.header1
	{mso-style-name:header1;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:18.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;}
p.header2, li.header2, div.header2
	{mso-style-name:header2;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:14.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;}
p.header3, li.header3, div.header3
	{mso-style-name:header3;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;
	font-weight:bold;}
p.header4, li.header4, div.header4
	{mso-style-name:header4;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:black;
	font-weight:bold;}
p.header5, li.header5, div.header5
	{mso-style-name:header5;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:18.0pt;
	font-family:Verdana;
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Times New Roman";
	color:#6487DC;}
p.buttons, li.buttons, div.buttons
	{mso-style-name:buttons;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
span.msatbullet1
	{mso-style-name:msatbullet1;
	mso-ansi-font-size:7.0pt;
	mso-bidi-font-size:7.0pt;
	font-family:Wingdings;
	mso-ascii-font-family:Wingdings;
	mso-hansi-font-family:Wingdings;
	background:white;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:883639079;
	mso-list-template-ids:-1572183530;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1
	{mso-list-id:1050156527;
	mso-list-template-ids:628907110;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2
	{mso-list-id:1152714431;
	mso-list-template-ids:389463608;}
@list l2:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3
	{mso-list-id:1238322063;
	mso-list-template-ids:-949301402;}
@list l3:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4
	{mso-list-id:2012371759;
	mso-list-template-ids:-988771572;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5
	{mso-list-id:2067794691;
	mso-list-template-ids:891867670;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6
	{mso-list-id:2112507824;
	mso-list-template-ids:-1488300944;}
@list l6:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
-->
</style>
<!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
</style>
<![endif]--><![if mso 9]>
<style>
p.MsoNormal
	{margin-left:19.65pt;}
</style>
<![endif]><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"2050"/>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1"/>
 </o:shapelayout></xml><![endif]-->
</head>

<body bgcolor=3Dwhite lang=3DEN-US link=3Dblue vlink=3Dblue style=3D'tab-in=
terval:.5in;
margin-left:19.65pt;margin-top:16.35pt;margin-right:16.35pt;margin-bottom:1=
6.35pt'>

<div class=3DSection1>

<h5 style=3D'margin-top:16.35pt;margin-right:16.35pt;margin-bottom:0in;
margin-left:0in;margin-bottom:.0001pt'><span style=3D'font-size:72.0pt;
color:red;background:yellow;mso-highlight:yellow'>Free </span><span
style=3D'background:yellow;mso-highlight:yellow'>Management Security Assess=
ment
MSA Executive Analysis Scorecard Prioritized Action</span> <span
style=3D'font-size:8.0pt'><a
href=3D"http://video.google.com/videoplay?docid=3D-417444910876190163&amp;q=
=3Drushinek+Accounting">http://video.google.com/videoplay?docid=3D-41744491=
0876190163&amp;q=3Drushinek+Accounting</a></span>
</h5>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>(888)ITISJo=
b.Net
-<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>Information Technology
Information Systems Job Network specializing in Managemnt Baseline Security
Analysis (MBSA) Vulnerability <span class=3DGramE>Assessment <span
style=3D'mso-spacerun:yes'>&nbsp;</span></span><a
href=3D"http://video.google.com/videoplay?docid=3D-2199987895572940206&amp;=
q=3Drushinek+Accounting">http://video.google.com/videoplay?docid=3D-2199987=
895572940206&amp;q=3Drushinek+Accounting</a>
</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>(888)Nets-E=
xpert.Org
- the Network of Experts Organization providing Expert Witness Testimony and
Computer Litigation Support Services <a href=3D"mailto:email@Nets-Expert.Or=
g">email@Nets-Expert.Org</a>
<a href=3D"http://video.google.com/videoplay?docid=3D5240188564675855151">h=
ttp://video.google.com/videoplay?docid=3D5240188564675855151</a>
</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>(305)6384-3=
97 <a
href=3D"http://video.google.com/videoplay?docid=3D-4470389520639706819&amp;=
q=3Drushinek+Accounting">http://video.google.com/videoplay?docid=3D-4470389=
520639706819&amp;q=3Drushinek+Accounting</a>
</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>Dr. A, &amp=
; S.
Rushinek, Ph.D. U. of Miami Professor, <a href=3D"mailto:eMail@OnAFree.com"=
>eMail@OnAFree.com</a>
, <st1:Street w:st=3D"on"><st1:address tabIndex=3D"0"
 style=3D"BACKGROUND-POSITION: left bottom; BACKGROUND-IMAGE: url(res://iet=
ag.dll/#34/#1001); BACKGROUND-REPEAT: repeat-x"
 w:st=3D"on">1205 Mariposa Ave.</st1:address></st1:Street> #208, Coral Gabl=
es Fl,
33146</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>Accounting =
and
Computer Information Systems Dept., <st1:PlaceName w:st=3D"on">Business</st=
1:PlaceName>
<st1:PlaceType w:st=3D"on">School</st1:PlaceType><span class=3DGramE>,<span
style=3D'mso-spacerun:yes'>&nbsp; </span>417</span> Jenkins Bldg, U of <st1=
:City
w:st=3D"on">Miami</st1:City>, <st1:place w:st=3D"on"><st1:City w:st=3D"on">=
Coral
  Gables</st1:City></st1:place> Fl, 33124</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><o:p>&nbsp;=
</o:p></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Free_Management_Secur=
ity_Assessment_MSA_Executive_Analysis_Scorecard_Prioritized_Action&nbsp;<sp=
an
style=3D'mso-spacerun:yes'>&nbsp; </span><a href=3D"http://www.webjobnet.co=
m/">http://www.webjobnet.com/</a>
<a href=3D"http://www.itisjob.net/">http://www.ITISJob.net</a> <o:p></o:p><=
/span></p>

<div align=3Dcenter>

<table class=3DMsoNormalTable border=3D0 cellpadding=3D0 width=3D"100%"
 style=3D'width:100.0%;mso-cellspacing:1.5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><!--[if g=
te vml 1]><v:shapetype
   id=3D"_x0000_t75" coordsize=3D"21600,21600" o:spt=3D"75" o:preferrelativ=
e=3D"t"
   path=3D"m@4@5l@4@11@9@11@9@5xe" filled=3D"f" stroked=3D"f">
   <v:stroke joinstyle=3D"miter"/>
   <v:formulas>
    <v:f eqn=3D"if lineDrawn pixelLineWidth 0"/>
    <v:f eqn=3D"sum @0 1 0"/>
    <v:f eqn=3D"sum 0 0 @1"/>
    <v:f eqn=3D"prod @2 1 2"/>
    <v:f eqn=3D"prod @3 21600 pixelWidth"/>
    <v:f eqn=3D"prod @3 21600 pixelHeight"/>
    <v:f eqn=3D"sum @0 0 1"/>
    <v:f eqn=3D"prod @6 1 2"/>
    <v:f eqn=3D"prod @7 21600 pixelWidth"/>
    <v:f eqn=3D"sum @8 21600 0"/>
    <v:f eqn=3D"prod @7 21600 pixelHeight"/>
    <v:f eqn=3D"sum @10 21600 0"/>
   </v:formulas>
   <v:path o:extrusionok=3D"f" gradientshapeok=3D"t" o:connecttype=3D"rect"=
/>
   <o:lock v:ext=3D"edit" aspectratio=3D"t"/>
  </v:shapetype><v:shape id=3D"_x0000_i1120" type=3D"#_x0000_t75" alt=3D"" =
style=3D'width:93.75pt;
   height:136.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image001.jpg"
    o:href=3D"http://www.webjobnet.com/srushinek.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D125 height=3D182
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image001.jpg"
  v:shapes=3D"_x0000_i1120"><![endif]><!--[if gte vml 1]><v:shape id=3D"_x0=
000_i1121"
   type=3D"#_x0000_t75" alt=3D"MOL03E.ASF" style=3D'width:120pt;height:90pt=
'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image002.jpg"
    o:href=3D"http://www.webjobnet.com/th_MOL03E.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D160 height=3D120
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image002.jpg"
  alt=3DMOL03E.ASF v:shapes=3D"_x0000_i1121"><![endif]><!--[if gte vml 1]><=
v:shape
   id=3D"_x0000_i1122" type=3D"#_x0000_t75" alt=3D"" style=3D'width:120pt;h=
eight:90pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image003.jpg"
    o:href=3D"http://www.webjobnet.com/th_MOL024-SplitBackgroundPPTandWhite=
Board.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D160 height=3D120
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image003.jpg"
  v:shapes=3D"_x0000_i1122"><![endif]><!--[if gte vml 1]><v:shape id=3D"_x0=
000_i1123"
   type=3D"#_x0000_t75" alt=3D"" style=3D'width:95.25pt;height:136.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image004.jpg"
    o:href=3D"http://www.webjobnet.com/arushinek.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D127 height=3D182
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image004.jpg"
  v:shapes=3D"_x0000_i1123"><![endif]><!--[if gte vml 1]><v:shape id=3D"_x0=
000_i1124"
   type=3D"#_x0000_t75" alt=3D"" style=3D'width:131.25pt;height:120pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image005.gif"
    o:href=3D"http://www.webjobnet.com/pullups_male_md_wht_22041.gif"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D175 height=3D160
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image005.gif"
  v:shapes=3D"_x0000_i1124"><![endif]></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td valign=3Dbottom style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:18.0pt;font-family:Arial;color:black'><!--[if gte vml =
1]><v:shape
   id=3D"_x0000_i1125" type=3D"#_x0000_t75" alt=3D"" style=3D'width:18.75pt=
;height:16.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image006.gif"
    o:href=3D"http://www.webjobnet.com/_phonecall.gif"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D25 height=3D22
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image006.gif"
  v:shapes=3D"_x0000_i1125"><![endif]>(305)Web-Job-Net a Network of Jobs on=
 the
  Web</span></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:18.0pt;font-family:Arial;color:black'><!--[if gte vml =
1]><v:shape
   id=3D"_x0000_i1126" type=3D"#_x0000_t75" alt=3D"" style=3D'width:18.75pt=
;height:16.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image006.gif"
    o:href=3D"http://www.webjobnet.com/_phonecall.gif"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D25 height=3D22
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image006.gif"
  v:shapes=3D"_x0000_i1126"><![endif]>(305)932-5626 a Network of Jobs on th=
e Web</span></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:10.0pt;font-family:Arial;color:black'>&nbsp;</span></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:10.0pt;font-family:Arial;color:black'>e-Mail: <a
  href=3D"mailto:ARsuh@OnTrial.Org"><span style=3D'color:black'>ARsuh@OnTri=
al.Org</span></a>&nbsp;
  The On Trial Expert Witness Testimony &amp; Computer Litigation team</spa=
n></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:10.0pt;font-family:Arial;color:black'>Dr. A. Rush
  (305)668-7425</span></p>
  <p align=3Dcenter style=3D'text-align:center'><o:p>&nbsp;</o:p></p>
  </td>
 </tr>
</table>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"http://www.onafree.com/default.aspx">http://www.onafree.com/default=
.aspx</a>
<span style=3D'mso-spacerun:yes'>&nbsp;</span><a
href=3D"http://www.onafree.com/Quiz%20Engine%20Projects/1Free%20Managemnt%2=
0Baseline%20Security%20Analysis%20(MBSA)%20Vulnerability%20Assessment%20Tru=
stworthy%20Computing%20Scanner.htm">http://www.onafree.com/Quiz%20Engine%20=
Projects/1Free%20Managemnt%20Baseline%20Security%20Analysis%20(MBSA)%20Vuln=
erability%20Assessment%20Trustworthy%20Computing%20Scanner.htm</a>
<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"http://www.onafree.com/Lists/Announcements/DispForm.aspx?ID=3D13&am=
p;Source=3Dhttp%3A%2F%2Fwww%2Eonafree%2Ecom%2Fdefault%2Easpx">http://www.on=
afree.com/Lists/Announcements/DispForm.aspx?ID=3D13&amp;Source=3Dhttp%3A%2F=
%2Fwww%2Eonafree%2Ecom%2Fdefault%2Easpx</a>
<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This report contains =
the
following sections:<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;
mso-bidi-font-family:Arial'>q</span></span><span style=3D'font-size:10.0pt;
font-family:Arial'><a href=3D"#ExecSum">Executive Summary</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Intro">Introduction</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Process">Background: Assessment Process and Scope</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Situation">Situation Analysis</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#ScoreCard">Scorecard</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Improvement">Security Initiatives</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>q</span></span><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"#Detail">Assessment in Detail</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Areas">Areas of Analysis</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#Infrastructure">Infrastructure</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#Applications">Applications</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#Operations">Operations</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#People">People</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>q</span></span><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"#Recommendations">Prioritized Action List</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>q</span></span><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"#Appendices">Appendices</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#QA">Questions and Answers</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Glossary">Glossary</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Interpreting">Interpreting the Graphs</a><o:p></o:p></sp=
an></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>A Microsoft partner c=
an
review this report with you and help with developing a detailed action plan=
 for
implementing the recommendations. If you do not have an existing relationsh=
ip
with a Microsoft partner, you may wish to view a list of Microsoft Partners=
 for
Security Solutions at <a href=3D"http://directory.microsoft.com/mprd/"
target=3D"_new">http://directory.microsoft.com/mprd/</a>.<o:p></o:p></span>=
</p>

<div class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
text-align:center'><span style=3D'font-size:10.0pt;font-family:Arial'>

<hr size=3D2 width=3D"100%" align=3Dcenter>

</span></div>

<p class=3Dcopy>The Microsoft Security Assessment Tool is designed to help =
you
determine the level of risk your computing infrastructure faces and the ste=
ps
you have taken to mitigate that <span class=3DGramE>risk,</span> and to off=
er
suggestions of additional steps you can take to help further reduce your le=
vel
of risk. It is not a replacement for an audit by a professional security
consultant.<br>
<br>
Use of the Microsoft Security Assessment Tool is governed by the terms of t=
he
End-User License Agreement (EULA) which accompanied the software, and this
report is subject to the exclusions, disclaimers, and limitations of liabil=
ity
contained in the EULA.<br>
<br>
This report is for informational purposes only. <span class=3DGramE>Neither
Microsoft Corporation, its suppliers, or</span> partners make any
representation or warranty of any kind, whether express or implied, concern=
ing
the Security Assessment Tool, or the use, accuracy, or reliability of the
results of the Assessment and information contained in this report.</p>

<div class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
text-align:center'><span style=3D'font-size:10.0pt;font-family:Arial'>

<hr size=3D2 width=3D"100%" align=3Dcenter>

</span></div>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><br clear=3Dall style=3D'mso-s=
pecial-character:
line-break'>
<o:p></o:p></span></p>

<h1 style=3D'page-break-before:always'><a name=3DExecSum></a>Executive Summ=
ary</h1>

<h2><a name=3DIntro></a>Introduction</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This Microsoft Securi=
ty
Assessment Tool is designed to assist you with identifying and addressing
security risks in your computing environment. The tool employs a holistic
approach to measuring security strategy by covering topics across people,
process, and technology. Findings are coupled with recommended mitigation
efforts, including links to more information for additional guidance if nee=
ded.
These resources may assist you in learning more about the specific tools and
methods that can help increase the security of your environment.<o:p></o:p>=
</span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This summary section =
is
intended to give IT and senior managers a snapshot of the company's overall
security posture. Detailed findings and recommendations can be found in the
detailed report following.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><br style=3D'mso-special-chara=
cter:
line-break'>
<![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-bre=
ak'>
<![endif]><o:p></o:p></span></p>

<h2><a name=3DProcess></a>Background: Assessment Process and Scope</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The assessment is des=
igned
to identify the business risk of your organization and the security measures
deployed to mitigate risk. Focusing on common issues in this market segment,
the questions have been developed to provide a high-level security risk
assessment of the technology, processes, and people that support the busine=
ss.<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Beginning with a seri=
es of
questions about your company's business model, the tool builds a Business R=
isk
Profile (BRP), measuring the risk of doing business your company must face =
due
to the industry and business model chosen. A second series of questions are
posed to compile a listing of the security measures your company has deploy=
ed
over time. Together, these security measures form layers of defense, provid=
ing
greater protection against security risk and specific vulnerabilities. Each
layer contributes to a combined strategy for defense-in-depth. This sum is
referred to as the Defense-in-Depth Index (DiDI). The BRP and DiDI are then
compared to measure risk distribution across the areas of analysis
(AoAs)&#8212;infrastructure, applications, operations, and people.<o:p></o:=
p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>In addition to measur=
ing
the alignment of security risk and defenses, this tool also measures the
security maturity of your organization. Security maturity refers to the
evolution of strong security and maintainable practices. At the low end, few
security defenses are employed and actions are reactive. At the high end,
established and proven processes allow a company to be more proactive, and
respond more efficiently and consistently when needed.<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Risk management
recommendations are suggested for your environment by taking into considera=
tion
existing technology deployment, current security posture, and defense-in-de=
pth
strategies. Suggestions are designed to move you along a path toward recogn=
ized
best practices.<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This
assessment&#8212;including the questions, measures, and
recommendations&#8212;is designed for midsize organizations that have betwe=
en
50 and 500 desktops in their environment. It is meant to broadly cover area=
s of
potential risk across your environment, rather than provide an in-depth ana=
lysis
of a particular technology or process. As a result, the tool cannot measure=
 the
effectiveness of the security measures employed. To that end, this report
should be used as a preliminary guide to help you focus on specific areas t=
hat
require more rigorous attention, and should not replace a focused assessmen=
t by
trained third-party assessment teams.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<h2><a name=3DSituation></a>Situation Analysis</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This section graphica=
lly
represents the concepts described above for your organization, based on the
answers you provided. As a reminder:<o:p></o:p></span></p>

<ul type=3Dsquare>
 <li class=3DMsoNormal style=3D'mso-list:l0 level1 lfo1;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>BRP is a measure of the r=
isk
     related to the industry and business model of the company <o:p></o:p><=
/span></li>
 <li class=3DMsoNormal style=3D'mso-list:l0 level1 lfo1;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>DiDI is a measure of the
     security defenses used across people, process, and technology to help
     mitigate identified risks to the business <o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l0 level1 lfo1;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Security Maturity is a me=
asure
     of the organization's ability to effectively use the tools available to
     create a maintainable security level across many disciplines <o:p></o:=
p></span></li>
</ul>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>[See <a href=3D"#Appe=
ndices">Appendices</a>
for additional information on these terms and how to interpret the graphs.]=
<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<h2>Results:</h2>

<div align=3Dcenter>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;mso-border-alt:solid =
black .5pt;
   background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Areas of Analysi=
s<o:p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.0=
001pt;
   text-align:center'><b><span style=3D'font-size:9.0pt;font-family:Arial;
   color:white'>Risk-Defense Distribution<o:p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.0=
001pt;
   text-align:center'><b><span style=3D'font-size:9.0pt;font-family:Arial;
   color:white'>Security Maturity<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Infrastructure<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1027" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image007.gif"
  v:shapes=3D"_x0000_i1027"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1028" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image008.gif"
  v:shapes=3D"_x0000_i1028"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p></o:p></span=
></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1029" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image008.gif"
  v:shapes=3D"_x0000_i1029"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1030" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image008.gif"
  v:shapes=3D"_x0000_i1030"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Operations<o:p></o:p></span><=
/p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1031" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image007.gif"
  v:shapes=3D"_x0000_i1031"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1032" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image008.gif"
  v:shapes=3D"_x0000_i1032"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:4;mso-yfti-lastrow:yes;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>People<o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1033" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image007.gif"
  v:shapes=3D"_x0000_i1033"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1034" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod=
-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrgani=
zationalLecturesWWWInternetE-Commerce_files/image007.gif"
  v:shapes=3D"_x0000_i1034"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
</table>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h3>Risk-Defense Distribution</h3>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This chart indicates
differences in the Defense-in-Depth score, organized by Area of Analysis. B=
ased
on your answers to the risk assessment and as depicted in the chart below, =
it
appears that additional focus is needed to shore up security measures in so=
me
areas. This is a strong indicator that your security posture is based on a =
few
standard security solutions. Contacting a security partner that can help you
identify critical areas of risk should be made a priority of your near term
security plans.<o:p></o:p></span></p>

<p align=3Dcenter style=3D'text-align:center'><span style=3D'font-size:10.0=
pt;
font-family:Arial'><!--[if gte vml 1]><v:shape id=3D"_x0000_i1035" type=3D"=
#_x0000_t75"
 alt=3D"" style=3D'width:420pt;height:240pt'>
 <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-c=
astingOrganizationalLecturesWWWInternetE-Commerce_files/image009.png"
  o:href=3D"cid:CHILKAT-CID-929ef4a5-9c66-46bd-8df0-d467ca56a928"/>
</v:shape><![endif]--><![if !vml]><img border=3D0 width=3D560 height=3D320
src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganiza=
tionalLecturesWWWInternetE-Commerce_files/image010.gif"
align=3Dcenter v:shapes=3D"_x0000_i1035"><![endif]><o:p></o:p></span></p>

<p class=3DMsoCaption align=3Dcenter style=3D'text-align:center'><span
style=3D'font-family:Arial'>Figure 1: Comparison of BRP and DiDI<o:p></o:p>=
</span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>In general, it is bes=
t to
have a DiDI rating on par with the BRP rating for the same category. An
imbalance either within a category or across categories&#8212;in either
direction&#8212;may indicate the need to realign your IT investments.<o:p><=
/o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h3>Security Maturity</h3>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Security maturity is
inclusive of controls (both physical and technical), the technical acumen o=
f IT
resources, policy, process, and maintainable practices. Security maturity c=
an
be measured only through the organization's ability to effectively use the
tools available to create a maintainable security level across many
disciplines. A baseline of security maturity should be established and used=
 to
define areas of focus for the organization's security programs. Not all
organizations should strive to reach the optimized level, but all should as=
sess
where they are and determine where they should be, in light of the business
risk they face. For example, a company with a low-risk environment may never
need to advance beyond the upper range of the Baseline level or the lower r=
ange
of the Standardized level. A company with a high-risk environment will like=
ly
push well into the Optimized level. Your Business Risk Profile scores help =
you
gauge your risk.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Security Maturity<o:p></o:p><=
/span></p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>A measure of a company's prac=
tices
  against industry best practices for maintainable security. Each company
  should strive to align its maturity level, and associated security strate=
gy,
  relative to the risks taken in doing business:<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Baseline<o:p></o:p></span></p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Some proactive security measu=
res
  deployed as first-line defenses; operations and incident response still v=
ery
  reactive<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Standardized<o:p></o:p></span=
></p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Multiple layers of defense de=
ployed
  in support of a defined strategy<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;mso-yfti-lastrow:yes'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Optimized<o:p></o:p></span></=
p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Effectively protecting the ri=
ght
  things the right way and ensuring ongoing utilization of best practices<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Based on your answers=
 to
the risk assessment and as depicted in the chart below, your company is doi=
ng
well in that it has a defined security strategy and a practices defense in
depth. You can further enhance your maturity by leveraging your comprehensi=
ve
corporate security policy, IT security policies and procedures for the IT
infrastructure. Use those to define a layered approach to security that fol=
lows
industry best practices, and applies only the necessary amount of protectio=
n to
assets.<o:p></o:p></span></p>

<p align=3Dcenter style=3D'text-align:center'><span style=3D'font-size:10.0=
pt;
font-family:Arial'><!--[if gte vml 1]><v:shape id=3D"_x0000_i1036" type=3D"=
#_x0000_t75"
 alt=3D"" style=3D'width:420pt;height:165pt'>
 <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-c=
astingOrganizationalLecturesWWWInternetE-Commerce_files/image011.png"
  o:href=3D"cid:CHILKAT-CID-e7b77dd2-3392-4b00-bc33-8ec20b29787b"/>
</v:shape><![endif]--><![if !vml]><img border=3D0 width=3D560 height=3D220
src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganiza=
tionalLecturesWWWInternetE-Commerce_files/image012.gif"
align=3Dcenter v:shapes=3D"_x0000_i1036"><![endif]><o:p></o:p></span></p>

<p class=3DMsoCaption align=3Dcenter style=3D'text-align:center'><span
style=3D'font-family:Arial'>Figure 2: Security Maturity<o:p></o:p></span></=
p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h2><a name=3DScoreCard></a>Scorecard</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Based on your answers=
 to
the risk assessment, the following ratings have been applied to your defens=
ive
measures. The <a href=3D"#Detail">Assessment Detail</a> and <a
href=3D"#Recommendations">Prioritized Action List</a> sections of this repo=
rt
include further detail for each, including the findings, best practices, an=
d recommendations.<o:p></o:p></span></p>

<div align=3Dcenter>

<table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td colspan=3D2 style=3D'padding:.75pt .75pt .75pt 3.25pt'>
  <div align=3Dcenter>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
    <td width=3D"10%" nowrap valign=3Dtop style=3D'width:10.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Legend:<o:p></o:p></span></=
p>
    </td>
    <td width=3D"5%" nowrap valign=3Dtop style=3D'width:5.0%;padding:3.25pt=
 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><!--[if gte vml 1]><v:shape=
 id=3D"_x0000_i1037"
     type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1037"><![endif]><o:p></o:p></span></p>
    </td>
    <td width=3D"25%" nowrap valign=3Dtop style=3D'width:25.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Meets best practice<o:p></o=
:p></span></p>
    </td>
    <td width=3D"5%" nowrap valign=3Dtop style=3D'width:5.0%;padding:3.25pt=
 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><!--[if gte vml 1]><v:shape=
 id=3D"_x0000_i1038"
     type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1038"><![endif]><o:p></o:p></span></p>
    </td>
    <td width=3D"25%" nowrap valign=3Dtop style=3D'width:25.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Needs improvement<o:p></o:p=
></span></p>
    </td>
    <td width=3D"5%" nowrap valign=3Dtop style=3D'width:5.0%;padding:3.25pt=
 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><!--[if gte vml 1]><v:shape=
 id=3D"_x0000_i1039"
     type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1039"><![endif]><o:p></o:p></span></p>
    </td>
    <td width=3D"25%" nowrap valign=3Dtop style=3D'width:25.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Severely lacking<o:p></o:p>=
</span></p>
    </td>
   </tr>
  </table>
  </div>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><o:p=
></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1'>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Infrastructure<o:p></o:p></=
span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1040" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1040"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Perimeter Defense<o:p></o:p=
></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1041" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1041"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and Filters<=
o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1042" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1042"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1043" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1043"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desktops<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1044" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1044"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Servers<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1045" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1045"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p></o:p></s=
pan></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1046" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1046"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1047" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1047"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Users<o:p></o=
:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1048" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1048"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detection System =
(IDS)<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1049" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1049"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:p></span><=
/p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1050" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1050"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:p></o:p></=
span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1051" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1051"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:12'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Administrative Users<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1052" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1052"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:13'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Internal Users<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1053" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1053"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:14'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Users<o:p></o=
:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1054" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1054"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:15'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1055" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1055"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:16'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies - Adminis=
trator
    Account<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1056" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1056"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:17'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies - User Ac=
count<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1057" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1057"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:18'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies - Remote-=
Access
    Account<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1058" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1058"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:19'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management and Monitoring<o=
:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1059" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1059"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:20'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Build<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1060" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1060"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:21'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1061" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1061"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:22'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-Party Relationships<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1062" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1062"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:23'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Physical Security<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1063" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1063"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:24;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Operations<o:p></o:p></span=
></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1064" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1064"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Environment<o:p></o:p></spa=
n></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1065" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1065"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and Filters<=
o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1066" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1066"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Administrative Users<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1067" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1067"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management Host<o:p></o:p><=
/span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1068" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1068"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Servers<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1069" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1069"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Network D=
evices<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1070" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1070"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-Party Relationships<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1071" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1071"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o:p></o:p><=
/span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1072" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1072"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1073" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1073"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Protocols &amp; Services<o:=
p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1074" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1074"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Acceptable Use<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1075" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1075"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:12'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>User Account Management<o:p=
></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1076" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1076"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:13'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Requirements<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1077" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1077"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:14'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Governance<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1078" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1078"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:15'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o:p></o:p><=
/span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1079" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1079"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:16'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Patch &amp; Update Manageme=
nt<o:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1080" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1080"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:17'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Network Documentation<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1081" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1081"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:18'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Application Data Flow<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1082" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1082"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:19'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Patch Management<o:p></o:p>=
</span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1083" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1083"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:20'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Virus Signatures<o:p></o:p>=
</span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1084" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1084"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:21'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Change Management and
    Configuration<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1085" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1085"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:22'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup and Recovery<o:p></o=
:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1086" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1086"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:23'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Log Files<o:p></o:p></span>=
</p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1087" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1087"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:24'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Log Files - Rotation<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1088" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1088"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:25'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1089" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1089"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:26'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1090" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1090"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:27'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Restore<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1091" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1091"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:28;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;mso-yfti-lastrow:yes'>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p></o:p></sp=
an></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1092" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1092"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p></o:p></sp=
an></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1093" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1093"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Load-Balancing<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1094" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1094"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1095" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1095"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Application &amp; Data Reco=
very<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1096" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1096"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-party independent sof=
tware
    vendor (ISV)<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1097" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1097"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Internally Developed<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1098" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1098"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Vulnerabilities<o:p></o:p><=
/span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1099" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1099"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Application Design<o:p></o:=
p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1100" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1100"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1101" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1101"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1102" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1102"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Authorization &amp; Access
    Control<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1103" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1103"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:12'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p></span></=
p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1104" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1104"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:13'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<o:p></o:p>=
</span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1105" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1105"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:14'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Data Storage &amp; Communic=
ations<o:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1106" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1106"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:15'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Encryption<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1107" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1107"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:16'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Encryption - Algorithm<o:p>=
</o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1108" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1108"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:17;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>People<o:p></o:p></span></b=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1109" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1109"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Requirements &amp; Assessme=
nts<o:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1110" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1110"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Requirements<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1111" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1111"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Assessments<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1112" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1112"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Awareness<o:p></o:=
p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1113" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1113"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Policy &amp; Procedures<o:p=
></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1114" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1114"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Background Checks<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1115" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1115"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Human Resources Policy<o:p>=
</o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1116" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image013.gif"
    v:shapes=3D"_x0000_i1116"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-Party Relationships<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1117" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image008.gif"
    v:shapes=3D"_x0000_i1117"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Training &amp; Awareness<o:=
p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1118" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1118"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Awareness<o:p></o:=
p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1119" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedP=
od-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrga=
nizationalLecturesWWWInternetE-Commerce_files/image007.gif"
    v:shapes=3D"_x0000_i1119"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
 </tr>
</table>

</div>

<h2><a name=3DImprovement></a>Security Initiatives</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The following areas f=
all
short of best practices and should be addressed to increase the security of
your environment. The <a href=3D"#Detail">Assessment Detail</a> and <a
href=3D"#Recommendations">Prioritized Action List</a> sections of this repo=
rt
include further detail for each, including the findings, best practices, and
recommendations.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;mso-border-alt:solid =
black .5pt;
   background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>High Priority<o:=
p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Medium Priority<=
o:p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Low Priority<o:p=
></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Servers=
<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></o:p=
></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desktop=
s<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Se=
rvers<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp; Da=
ta
  Recovery<o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Virus Signatures<o:p=
></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Protocols &amp; Serv=
ices<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detection =
System
  (IDS)<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Application Data Flo=
w<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Restore=
<o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and F=
ilters<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Governance<o:p></o:p=
></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup<o:p></o:p></s=
pan></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Ne=
twork
  Devices<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<span style=3D'font-size:10.0pt;font-family:Arial;mso-fareast-font-family:"=
Times New Roman";
mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA'=
><br
clear=3Dall style=3D'mso-special-character:line-break;page-break-before:alw=
ays'>
</span>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<h1><a name=3DDetail></a>Assessment in Detail</h1>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This section of the r=
eport
provides the detailed findings for each category, as well as best practices,
recommendations, and references for additional information. Recommendations=
 are
prioritized in the following section.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<h2><a name=3DAreas></a>Areas of Analysis</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The following table l=
ists
the areas that were included for high-level analysis in this security risk
assessment and describes each area's relevance to security. The Assessment
Detail section of this document describes your organization's security post=
ure
(based on answers you gave during the assessment) in each of these areas and
provides industry-recognized best practices and recommendations for achievi=
ng
those practices.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1=
.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Cate=
gory<o:p></o:p></span></b></p>
   </td>
   <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border:solid black 1=
.0pt;
   border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:sol=
id black .5pt;
   background:#0148B2;padding:3.25pt 0in 0in 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Impo=
rtance
   to security<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Busin=
ess
  Risk Profile<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Business Risk Profil=
e<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Understanding how the
  nature of your business affects risk is important in determining where to
  apply resources in order to help mitigate those risks. Recognizing critic=
al
  areas of business risk will help you to optimize allocation of your secur=
ity
  budget. <o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Infra=
structure<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:4;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Perimeter Defense<o:=
p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Perimeter defense
  addresses security at network borders, where your internal network connec=
ts
  to the outside world. This constitutes your first line of defense against
  intruders.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:5;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Rigorous authenticat=
ion
  procedures for users, administrators, and remote users help to ensure that
  outsiders do not gain unauthorized access to the network through the use =
of
  local or remote attacks.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:6;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management &amp;
  Monitoring<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management, monitori=
ng,
  and proper logging are critical to maintaining and analyzing IT environme=
nts.
  These tools are even more important after an attack has occurred and inci=
dent
  analysis is required.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:7;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Workstations<o:p></o=
:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security of indi=
vidual
  workstations is a critical factor in the defense of any environment,
  especially when remote access is allowed. Workstations should have safegu=
ards
  in place to resist common attacks.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:8;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Appli=
cations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:9;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Deployment &amp; Use=
<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>When business-critic=
al
  applications are deployed in production, the security and availability of
  those applications and servers must be ensured. Continued maintenance is
  essential to help ensure that security bugs are patched and that new
  vulnerabilities are not introduced into the environment.<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:10;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Application Design<o=
:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Design that does not
  properly address security mechanisms such as authentication, authorizatio=
n,
  and data validation can allow attackers to exploit security vulnerabiliti=
es
  and thereby gain access to sensitive information.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:11;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Data Storage &amp;
  Communications<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Integrity and
  confidentiality of data is one of the greatest concerns for any business.
  Data loss or theft can hurt an organization's revenue as well as reputati=
on.
  It is important to understand how applications handle business critical d=
ata
  and how that data is protected.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:12;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Opera=
tions<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:13;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Environment<o:p></o:=
p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security of an
  organization is dependent on the operational procedures, processes and
  guidelines that are applied to the environment. They can enhance the secu=
rity
  of an organization by including more than just technology defenses. Accur=
ate
  environment documentation and guidelines are critical to the operation te=
am's
  ability to support and maintain the security of the environment.<o:p></o:=
p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:14;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Corporate security p=
olicy
  refers to individual policies and guidelines that exist to govern the sec=
ure
  and appropriate use of technology and processes within the organization. =
This
  area covers policies to address all types of security, such as user, syst=
em,
  and data.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:15;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Recover=
y<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Data backup and reco=
very
  is essential to maintaining business continuity in the event of a disaste=
r or
  hardware/software failure. Lack of appropriate backup and recovery proced=
ures
  could lead to significant loss of data and productivity.<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:16;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Patch &amp; Update
  Management<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Good management of p=
atches
  and updates is important to securing an organization's IT environment. Th=
e timely
  application of patches and updates is necessary to help protect against k=
nown
  and exploitable vulnerabilities.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:17;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Peopl=
e<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:18;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Requirements and
  Assessments<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security requirements
  should be understood by all decision-makers so that both their technical =
and
  business decisions enhance security rather than conflict with it. Regular
  assessments by a third party can help a company review, evaluate, and
  identify areas for improvement.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:19;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Policies and Procedu=
res<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Clear, practical
  procedures for managing relationships with vendors and partners can help
  limit your company's exposure to risk. Procedures covering employee hiring
  and termination can help protect your company from unscrupulous or
  disgruntled employees.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:20;mso-yfti-lastrow:yes;page-break-inside:avoid=
'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Training and Awarene=
ss<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Employees should be
  trained and made aware of how security applies to their daily job activit=
ies
  so that they do not inadvertently expose their company to greater risks.<=
o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h2><a name=3DAnalysis></a>Assessment Analysis</h2>

<p><a name=3DInfrastructure><span style=3D'font-size:10.0pt;font-family:Ari=
al'>This
section is divided into the four major areas of analysis&#8212;Infrastructu=
re,
Applications, Operations, and People.<o:p></o:p></span></a></p>

<h3><span style=3D'mso-bookmark:Infrastructure'>Infrastructure</span></h3>

<span style=3D'mso-bookmark:Infrastructure'></span>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Infrastructure securi=
ty
focuses on how the network should function, what business processes (intern=
al
or external) it must support, how hosts are built and deployed, and how the
network will be managed and maintained. Effective infrastructure security c=
an
help provide significant improvements in the areas of network defense, inci=
dent
response, network availability, and fault analysis. By establishing a sound
infrastructure design that is understood and followed, an organization can
identify areas of risk and can design methods of threat mitigation. The
assessment reviews high-level procedures that an organization can follow to
help mitigate infrastructure risk by focusing on the following areas of
infrastructure security: <o:p></o:p></span></p>

<ul type=3Ddisc>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Perimeter
     Defense&#8212;Firewalls, Anti-virus, Remote Access, Segmentation<o:p><=
/o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Authentication&#8212;Pass=
word
     Policies <o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Management &amp;
     Monitoring&#8212;Management Hosts, Log files<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Workstation&#8212;Build
     Configuration<o:p></o:p></span></li>
</ul>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Peri=
meter
   Defense<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules an=
d Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Firewalls are a firs=
t-line
  defense mechanism and should be placed at all network border locations. R=
ules
  implemented on firewalls should be highly restrictive and set on a
  host-by-host and service-by-service basis.<br>
  <br>
  When creating firewall rules and router ACLs (Access Control Lists), focu=
s on
  first protecting access control devices and the network from attack. <br>
  <br>
  <br>
  + Enforce data flow by use of network ACLs and firewall rules. <br>
  + Test firewall rules and router ACLs to determine whether or not existin=
g rules
  contribute to Denial of Service (DoS) attacks.<br>
  + Deploy one or more DMZs as part of a systematic and formal firewall
  development. <br>
  + Place all Internet accessible servers there. Restrict connectivity to a=
nd
  from the DMZs.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  not only have you deployed firewalls at network borders, you have also ta=
ken
  an extra precaution by creating one or more DMZ segments to protect
  Internet-accessible resources.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review firewall poli=
cies
  regularly and prune old or improper rules. Implement rules for controlling
  inbound and outbound access and consider implementing egress filtering to
  prevent unnecessary outbound connections.<br>
  <br>
  Limit internal users' direct access to DMZ segments as it is not likely t=
hey
  would work with the host computers that reside in the DMZ on a regular ba=
sis.
  Limit access from the core network into the DMZ segment to only specific
  hosts or administrative networks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  host-based firewall software is used to protect servers.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue installing
  host-based firewalls on all servers, and consider extending this software=
 to
  all desktops and laptops in the organization also.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Securing Your Netw=
ork<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This article, written=
 for
network administrators and IT professionals, presents an overview of the top
network-level threats and the ways in which you can counter them. The autho=
rs
review security issues and the configuration settings to be applied to rout=
ers,
firewalls and switches.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh15.asp"
target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMC=
h15.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>FAQ About Internet
Firewalls<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This FAQ is appropria=
te for
users who are not IT professionals and who have questions about using and
deploying a firewall.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/security/protect/firewall.asp" target=3D"_=
new">http://www.microsoft.com/security/protect/firewall.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Deploy anti-virus
  solutions throughout the environment on both the server and desktop level=
s.
  Deploy specialized anti-virus solutions for specific tasks such as file
  server scanners, content screening tools, and data upload and download
  scanners. Configure anti-virus solutions to scan for viruses both entering
  and leaving the environment.<br>
  <br>
  Anti-virus solutions should be implemented first on critical file servers=
 and
  then extended to mail, database, and Web servers.<br>
  <br>
  For desktops and laptops an anti-virus solution should be included in the
  default build environment.<br>
  <br>
  If you are using Microsoft Exchange, use the additional anti-virus and
  content filtering-capabilities it offers at the mailbox level.<o:p></o:p>=
</span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  perimeter hosts have anti-virus software installed.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  email servers have anti-virus software installed.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>FAQ About Anti-vir=
us
Software<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This FAQ is appropria=
te for
users who are not IT professionals and who have questions about using antiv=
irus
software.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/security/protect/antivirus.asp" target=3D"=
_new">http://www.microsoft.com/security/protect/antivirus.asp</a><o:p></o:p=
></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desk=
tops<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desk=
tops<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  anti-virus solutions have not been deployed at the desktop level.<o:p></o=
:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider deploying an
  anti-virus solution to all employees' laptops and/or desktops. Add the
  anti-virus client in the default workstation build environment.<o:p></o:p=
></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Serv=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Serv=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  anti-virus solutions have not been deployed at the server level.<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider deploying an
  anti-virus solution to critical file servers initially and then to e-mail,
  database, and web servers. If you are using Microsoft Exchange, consider
  using the additional anti-virus and content-filtering capabilities at the
  mailbox level.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Workstations are a
  critical factor in the defense of any environment, especially if there are
  remote and roaming users that connect to the environment.<br>
  <br>
  Tools such as personal firewalls, anti-virus, and remote-access software
  should be present and properly configured on all workstations. <br>
  <br>
  Implement a policy which requires periodic review of these tools to make =
sure
  their configurations reflect changes in applications and services being u=
sed,
  but at the same time still keep the workstation resistant to attacks.<o:p=
></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  remote access to your organization's network is available<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  not only have you implemented a VPN for remote access, but you have also
  incorporated multifactor authentication as a second line of defense.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Regularly audit the =
access
  list for all the users on the VPN device. Consider managing the VPN device
  from inside the corporate network only.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  employees and/or partners remotely connect to your internal network, but =
no
  VPN technology is currently being used to secure access for these users.<=
o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Deploy VPN for
  remote-user-access connectivity based on IP Security (IPSec), Secure Sock=
ets
  Layer (SSL), and Secure Shell (SSH) technologies.<br>
  <br>
  Deploy site-to-site connectivity based on IPSec technology. Configure net=
work
  access lists and user access lists for restricting access to necessary
  corporate resources.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the VPN is capable of limiting connectivity to <span class=3DGramE>a quar=
antine</span>
  until all necessary security checks have been passed.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best =
Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Use segmentation to
  separate specific extranets from vendor, partner, and customer access.<br>
  <br>
  Each external network segment should allow only specific application traf=
fic
  to be routed to the specific application hosts and ports that are used to
  supply services to customers.<br>
  <br>
  Ensure that network controls are in place to restrict access to only what=
 is
  required for each third-party connection.<br>
  <br>
  Restrict access to and from the network services being provided, and rest=
rict
  access between network segments.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that Internet-facing services are hosted on your organization's network<o=
:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Ensure that firewall=
s,
  segmentation and intrusion-detection systems are in place in order to pro=
tect
  the company's infrastructure from Internet-based attacks.<o:p></o:p></spa=
n></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the network has more than one segment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue using netwo=
rk
  segmentation in order to better manage network traffic and limit access t=
o resources
  based on user requirements.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
s that
  network segmentation is not currently being used in the environment. It is
  important to keep customer-/partner-specific extranet services on their o=
wn
  network segments.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Move extranet access
  servers to a physically separate network segment.<br>
  <br>
  Apply restrictive access controls to allow third-party access to specific
  hosts only, restrict access to only necessary corporate infrastructure, a=
nd
  block connection attempts to remote networks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  hosts are grouped into network segments based on offering similar service=
s.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  hosts are grouped into network segments based on providing only the neces=
sary
  services for the users that connect.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement complex pa=
ssword
  controls for all users of remote access, whether this access is granted
  through the use of dial-up or VPN technologies. A password is considered =
to
  be complex if it meets the following criteria:<br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<br>
  <br>
  Implement an additional factor of authentication for accounts that are
  granted remote access. Also consider implementing advanced controls around
  account management (do not allow sharing of accounts) and account access
  logging.<br>
  <br>
  In the case of remote access, it is especially important to protect the
  environment through the use of strong account management practices, sound
  logging practices, and incident detection capabilities. To further mitiga=
te
  the risks of brute-force password attacks, consider implementing the
  following controls:<br>
  <br>
  <br>
  + Password expiration<br>
  + Account lockout after 7 to 10 failed login attempts<br>
  + System logging<br>
  <br>
  Remote-access services should also take into account systems that will be
  used to access the network or hosts. Also consider implementing controls
  around hosts that are allowed to access the network via remote access.<o:=
p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  employees are not able to remotely connect to the network.<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>By not allowing remo=
te
  access, you reduce your overall risk. However if remote access is planned=
 or
  implemented in the future, be sure to follow best practice when deploying=
 the
  remote-access solution in order to minimize the risk associated with that
  access.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  contractors are not able to remotely connect to the network.<o:p></o:p></=
span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>By not allowing remo=
te
  access, you reduce your overall risk. However if remote access is planned=
 or
  implemented in the future, be sure to follow best practice when deploying=
 the
  remote-access solution in order to minimize the risk associated with that
  access.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  third parties are not able to remotely connect to the network.<o:p></o:p>=
</span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>By not allowing remo=
te
  access, you reduce your overall risk. However if remote access is planned=
 or
  implemented in the future, be sure to follow best practice when deploying=
 the
  remote-access solution in order to minimize the risk associated with that
  access.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Both network- and
  host-based intrusion-detection systems should be deployed to detect and
  notify of attacks against corporate systems.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are using intrusion-detection hardware or software.<o:p></o:p></span>=
</p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using a host-based intrusion-detection system (HIDS)<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider deploying
  host-based intrusion-detection systems, which can help notify administrat=
ors
  that an attack is occurring against your hosts and help the administrators
  respond in a timely manner.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are using a network-based intrusion-detection system (NIDS)<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue the practic=
e of
  deploying a network-based intrusion-detection system. Ensure that the
  signatures are kept current, and investigate intrusion-prevention technol=
ogy
  as it becomes more widely available.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Auditing &amp; Int=
rusion
Detection<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This document provide=
s a
high-level overview of what types of events you should be logging and their
importance in trying to detect an intruder. It also covers different monito=
ring
techniques and detection methods.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/security/prodtech/win2000/secwin2k/09detect.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/security/prodtech/win2000/secwin2k/09detect.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Best practice for wi=
reless
  implementation should include ensuring that the network does not broadcast
  its SSID; that WPA encryption is used; that the network is fundamentally
  treated as untrustworthy.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  wireless connectivity to the network is available<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>In order to minimize=
 the
  risk associated with wireless networks, the implementation should include
  non-broadcast of SSID, WPA encryption, and treating the network as untrus=
ted.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the wireless network is not treated as untrusted.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider <span
  class=3DGramE>migrating</span> your wireless network to an untrusted netw=
ork
  segment and requiring the use of VPN or similar technologies in order to
  better preserve data integrity.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using WEP encryption in your wireless environment.<o:p></o:p>=
</span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>If you are currently=
 using
  no encryption, consider using WPA to prevent wireless network traffic fro=
m being
  'sniffed' and read as clear text.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using WPA encryption in your wireless environment.<o:p></o:p>=
</span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>If you are currently=
 using
  no encryption, consider using WPA to prevent wireless network traffic from
  being 'sniffed' and read as clear text.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you have not disabled broadcasting of the SSID on the access point.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider disabling S=
SID
  broadcast to make it more difficult for a casual user to attempt to conne=
ct
  to your wireless network.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using MAC restrictions in your wireless environment.<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider using WPA
  authentication in addition to MAC filtering in order to prevent unauthori=
zed
  computers from connecting to the network.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response is tha=
t you
  have changed the SSID on the access point from the default.<o:p></o:p></s=
pan></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Changing the default=
 SSID
  is the first step in securing your wireless network. However, this needs =
to
  be combined with further best practices in order to minimize risk. These
  include non-broadcast of SSID, WPA encryption, and treating the network as
  untrusted.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Auth=
entication<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Administrative Us=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>For administrative
  accounts, implement a strict policy that requires the use of complex
  passwords that meet the following criteria:<br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 14 characters<br>
  <br>
  To further mitigate the risk of a password attack, implement the following
  controls:<br>
  <br>
  + Password expiration<br>
  + Account lockout after 7 to 10 failed login attempts<br>
  + System logging<br>
  <br>
  In addition to implementing complex passwords, consider implementing
  multifactor authentication. Implement advanced controls around account
  management (do not allow account sharing) and account-access logging.<o:p=
></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Administrative Us=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
ed
  that currently there is either none or only simple password authentication
  required for administrative access to manage devices and hosts.<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  complex password controls for all administrative accounts and service
  accounts. A password is considered to be complex if it meets the following
  criteria:<br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internal Users<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>For user accounts,
  implement a policy that requires the use of complex passwords that meet t=
he
  following criteria<span class=3DGramE>:</span><br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<br>
  <br>
  To further mitigate the risk of a password attack implement the following
  controls:<br>
  <br>
  <br>
  + Password expiration<br>
  + Account lockout after at least 10 failed login attempts<br>
  + System logging<br>
  <br>
  In addition to complex passwords, consider implementing multifactor
  authentication.<br>
  <br>
  Implement advanced controls around account management (do not allow shari=
ng
  of accounts) and account-access logging.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internal Users<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  multifactor authentication is required for user access to the internal
  network and hosts.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To further mitigate =
the
  risk of access to the environment being gained through low-level user
  accounts, consider implementing the following controls<span class=3DGramE=
>:</span><br>
  <br>
  + Password expiration<br>
  + Account lockout after at least 10 failed login attempts<br>
  + System logging<br>
  <br>
  Ensure that password controls for both local and domain accounts are
  enforced.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement complex pa=
ssword
  controls for all users of remote access, whether this access is granted
  through the use of dial-up or VPN technologies. A password is considered =
to
  be complex if it meets the following criteria:<br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<br>
  <br>
  Implement an additional factor of authentication for accounts that are
  granted remote access. Also consider implementing advanced controls around
  account management (do not allow sharing of accounts) and account access
  logging.<br>
  <br>
  In the case of remote access, it is especially important to protect the
  environment through the use of strong account management practices, sound
  logging practices, and incident detection capabilities. To further mitiga=
te
  the risks of brute-force password attacks, consider implementing the
  following controls:<br>
  <br>
  <br>
  + Password expiration<br>
  + Account lockout after 7 to 10 failed login attempts<br>
  + System logging<br>
  <br>
  Remote-access services should also take into account systems that will be
  used to access the network or hosts. Also consider implementing controls
  around hosts that are allowed to access the network via remote access.<o:=
p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  multifactor authentication is required for users who remotely access your
  internal network and host computers.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To further mitigate =
the
  risks of brute-force password attacks through remote access services,
  consider implementing the following controls:<br>
  <br>
  + Password expiration<br>
  + Account logout<br>
  + System logging<br>
  <br>
  In the case of remote access, it is especially important to protect the
  environment through the use of strong account management practices, sound
  logging practices, and incident detection capabilities.<br>
  <br>
  Remote-access services should also take into account the systems that wil=
l be
  used to access the network or hosts. Consider implementing controls around
  the hosts that are allowed to access the network via remote access.<o:p><=
/o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Typically the restri=
ctions
  around creating passwords for administrators should be greater than those=
 for
  normal accounts.<br>
  <br>
  On Windows systems, administrative accounts (and service accounts) should=
 be
  set with passwords that are 14 characters in length and use alphanumeric =
and
  special characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Administrator Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Administrator Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  administrator accounts have password policies implemented.<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  additional protections around administrative accounts, such as logging and
  monitoring services, around all successful and failed authentications.<br>
  <br>
  Migrate away from clear text protocols.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  User Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  User Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  user accounts have password policies implemented.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  logging thresholds around failed authentications so that alerts can be se=
nt to
  systems administrators.<br>
  <br>
  Consider testing the password policies in place.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Remote-Access Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Remote-Access Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  remote access accounts have password policies implemented.<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  additional security around remote-access accounts through the use of logg=
ing
  and monitoring services on the remote-access device/host.<br>
  <br>
  Consider implementing logging thresholds around failed authentications so
  that alerts can be sent to systems administrators.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Mana=
gement
   and Monitoring<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Build<o:p></o:p><=
/span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Maintain a build pro=
cess
  with all vendor patches and recommended lockdown configuration. Test this
  process regularly.<br>
  <br>
  Use host-hardening procedures to patch and properly configure services and
  applications on each host. Disable all nonessential services and
  applications.<br>
  <br>
  Workstations should be hardened by installing recommended patches, removi=
ng
  all unnecessary services and packages, and auditing file permissions.<br>
  <br>
  Incorporate host-hardening steps into standard workstation build procedur=
es.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your system builds include host-hardening procedures.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  remote control/management software is not used in the environment.<o:p></=
o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue the practic=
e of
  not using remote control/management software.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  disk-encryption software is not used in the environment.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider using disk
  encryption software in order to prevent data compromise in the event of
  machine theft.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat a
  password-protected screen saver is not used in the environment.<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider requiring a=
ll
  users to have a password-protected screen saver with a short time-out per=
iod.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  personal firewalls have not been installed on all of the workstations in =
the
  environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement a policy w=
hich
  calls for periodic review of default firewall settings, so as to allow for
  changes in applications or services being used.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  client-side remote access software has been installed on workstations that
  connect remotely to the internal network.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider using a sin=
gle
  remote-access solution for the environment, if there are multiple types of
  solution deployed.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  modems are not used in the environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue disabling m=
odem
  and dial-up access in order to reduce the risk of having machines able to=
 be
  directly dialed into.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Windows Server 2003
Security Guide<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This guide provides
easy-to-understand advice, tools, and templates to help you secure
Microsoft&reg; Windows Server&#8482; 2003 operating system in many
environments. Network administrators and IT professionals responsible for
installing and configuring servers would likely benefit the most from this
information.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/security/prodtech/win2003/w2003hg/sgch00.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/security/prodtech/win2003/w2003hg/sgch00.asp</a><o:p></o:p></sp=
an></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Gold Cer=
tified
Partners<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The Microsoft&reg; Go=
ld
Certified Partner Program for Security Solutions will help you find special=
ists
in building and deploying IT solutions that help protect user security. Mic=
rosoft
works closely with partners to help ensure they have the highest level of
expertise with Microsoft technologies and solutions.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://directory.microsoft.com/resourcedirectory/Services.aspx"
target=3D"_new">http://directory.microsoft.com/resourcedirectory/Services.a=
spx</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Securing Your Data=
base
Server<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Database architects a=
nd
database administrators will benefit most from this guide, which provides a
proven methodology for securing database servers--Microsoft&reg; SQL
Server&#8482; in particular. The guide reviews the most common threats that
affect database servers, then steps through the process of applying a secure
configuration.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh18.asp"
target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMC=
h18.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>passfilt.dll<o:p><=
/o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Passfilt.dll is a
replacement .dll for Microsoft&reg; Windows NT&reg; 4.0 operating system. U=
sing
passfilt, you can modify the operating system's default parameters to provi=
de
strong password support and administrative account lockout (at the network
level).<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/default.asp?url=3D/library/en-us/=
security/security/strong_password_enforcement_and_passfilt_dll.asp"
target=3D"_new">http://msdn.microsoft.com/library/default.asp?url=3D/librar=
y/en-us/security/security/strong_password_enforcement_and_passfilt_dll.asp<=
/a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party
  Relationships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To help reduce the r=
isk of
  exposure, formal policies and procedures should exist to govern relations=
hips
  with third parties. These policies and procedures help to identify securi=
ty
  issues and the responsibilities of each party in mitigating them. <br>
  <br>
  These policies should include: <br>
  + Level of connectivity and access <br>
  + Data presentation and manipulation <br>
  + Roles and responsibilities (including authority) of each party <br>
  + Management of the relationship&#8212;setup, ongoing, and termination.<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party
  Relationships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  systems are configured by internal staff.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Systems should be
  configured by internal staff following a tested build image.<o:p></o:p></=
span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>All computer systems
  should be secured to prevent easy theft. Servers and networking equipment
  should be secured in locked cabinets in locked rooms with controlled acce=
ss.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
ted
  that physical security controls have been deployed to secure your
  organization's assets.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue use of phys=
ical
  controls, and consider extending them to all computer equipment, if that =
has
  not already been done.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  servers are not in a lockable cabinet or rack.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Having servers in a
  lockable cabinet/rack further protects against unauthorized tampering. If
  possible, consider migrating servers to lockable enclosures.<o:p></o:p></=
span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat an
  alarm system has not been installed to detect and report break-ins<o:p></=
o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider installing =
an
  alarm system in order to detect and report break-ins.<o:p></o:p></span></=
p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  networking equipment is not in a locked room with restricted access.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Networking equipment
  should be secured in a locked room or closet. Plan to <span class=3DGramE=
>migrate</span>
  network equipment to a more secure area.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  workstations are not secured with cable locks<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>In order to prevent =
theft,
  consider securing workstations with cable locks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  laptops are not secured with cable locks<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>In order to prevent =
theft,
  consider securing laptops with cable locks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  sensitive printed materials are not stored in locked file cabinets.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Sensitive documents =
should
  be kept in locked cabinets in order to prevent theft and disclosure of
  sensitive information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  network equipment is also in a lockable cabinet or rack.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Having network equip=
ment
  in a lockable cabinet/rack further protects against unauthorized tamperin=
g.
  Ensure that access to keys/combinations is limited to only those who have=
 a
  business need.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  servers are not in a locked room with restricted access.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Servers should be se=
cured
  in a locked room or closet. Plan to <span class=3DGramE>migrate</span> the
  servers to a more secure area.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Basic Physical Sec=
urity<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This resource provide=
s a
snapshot of the three basic principles of physical security: keeping people
away, keeping people out, and protecting your plumbing.<o:p></o:p></span></=
p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/columns/security/5min/5min-203.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/columns/security/5min/5min-203.asp</a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

</div>

<h3>Applications</h3>

<div>

<p><a name=3DApplications></a><span style=3D'font-size:10.0pt;font-family:A=
rial'>A
thorough understanding of application security requires in-depth knowledge =
of
the basic underlying application architecture as well as a solid understand=
ing
of the application's user base. Only then can you begin identifying the
potential threat vectors.<br>
<br>
Given the limited scope of this self assessment, a complete analysis of
application architecture and thorough understanding of the user base is not
possible. This assessment is meant to help you review applications within y=
our
organization and assess them from a security and availability standpoint. It
examines technologies used within the environment to help enhance
Defense-in-Depth. The assessment reviews the high level procedures an organ=
ization
can follow to help mitigate application risk by focusing on the following a=
reas
of application security:<o:p></o:p></span></p>

<ul type=3Ddisc>
 <li class=3DMsoNormal style=3D'mso-list:l2 level1 lfo3;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Deployment &amp;
     Use&#8212;Mechanisms to enhance availability<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l2 level1 lfo3;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Application Design
     &#8212;Authentication, Access Control, Update Management, Input
     Validation, Logging &amp; Auditing<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l2 level1 lfo3;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Data Storage &amp;
     Communications&#8212;Encryption, Data Transfer, Restrictive Access<o:p=
></o:p></span></li>
</ul>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Appl=
ications<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Load-Balancing<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Load-Balancing<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  load balancers are currently deployed in the environment.<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Periodically audit t=
he
  configuration of your load balancers and run diagnostics on a regular bas=
is
  to make sure they are functioning properly.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  clustering is not deployed in your environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To ensure high
  availability for critical databases and file shares, consider deploying
  clustering mechanisms.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp;=
 Data
  Recovery<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp;=
 Data
  Recovery<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization has line of business applications<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Any Line of Business
  applications should be periodically evaluated for security, backed up
  regularly, fully documented, and <span class=3DGramE>have</span> continge=
ncies
  in place in case they fail.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp;=
 Data
  Recovery<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that regular testing of application and data recovery is not performed.<o=
:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Perform full backups
  regularly. Perform regular tests of the backup and recovery mechanism that
  permits restoration of the application to a normal operating state.<o:p><=
/o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party indep=
endent
  software vendor (ISV)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The third-party
  independent software vendor (ISV) should regularly provide patches and up=
grades
  for their application, and they should explain the purpose of patches and=
 any
  impact you may expect in terms of the functionality, configuration, or
  security of the application being patched. <br>
  <br>
  The third-party ISV should clearly identify critical patches so that they=
 can
  quickly be applied. <br>
  <br>
  The third-party ISV should explain all of the application's security
  mechanisms and provide up-to-date documentation. <br>
  <br>
  The organization should be aware of any configuration requirements necess=
ary
  to ensure the highest level of security.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party indep=
endent
  software vendor (ISV)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  third party vendors have developed one or more of the key applications in
  your environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Ensure that the third
  party who has developed your key software will continue to support that
  software, provide updates in a timely manner, and can provide you with so=
urce
  code in the event that the third party can no longer support the applicat=
ion.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party indep=
endent
  software vendor (ISV)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internally Develo=
ped<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The in-house develop=
ment
  team should regularly provide patches and upgrades for their application,=
 and
  they should explain the purpose of patches and any impact you may expect =
in
  terms of the functionality, configuration, or security of the application
  being patched <br>
  <br>
  The development team should clearly identify critical patches so that the
  organization can quickly apply them. <br>
  <br>
  The development team should explain all of the application's security
  mechanisms and provide up-to-date documentation. <br>
  <br>
  The organization should be aware of any configuration requirements necess=
ary
  to ensure the highest level of security. <br>
  <br>
  Consider contracting with an independent third party to review the
  application's architecture and deployment and identify any security issue=
s of
  concern.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internally Develo=
ped<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization uses custom macros for office applications.<o:p></o:p><=
/span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Using custom macros
  requires that the security settings in Office are downgraded, exposing yo=
ur
  office applications to malicious documents. Consider limiting the ability=
 to
  develop and run custom macros to only those that have a business need.<o:=
p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internally Develo=
ped<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your responses indic=
ate
  that your in-house development team provides you with regular software
  updates and security patches for applications developed by them. <o:p></o=
:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue to work wit=
h the
  development team to address all application and security issues in the
  deployed applications.<br>
  <br>
  When a patch is made available, thoroughly test the patch in a lab
  environment before deploying it into production.<br>
  <br>
  Work with the development team to audit the application configuration to
  ensure maximum security.<br>
  <br>
  Consider contracting with an independent third party to review the
  application's architecture and deployment and identify any security issue=
s of
  concern.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Vulnerabilities<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>All known security
  vulnerabilities should be identified and patched. Regularly monitor vendor
  and third-party security sites for new vulnerability information and
  available patches. <br>
  <br>
  If there are any known security vulnerabilities that do not have available
  patches, determine when a patch will be available and develop an interim
  mitigation plan to address that vulnerability. <br>
  <br>
  Consider using a third party to conduct periodic assessments to evaluate =
the
  application's security design. A third-party assessment may also turn up
  areas where additional security mechanisms are beneficial.<o:p></o:p></sp=
an></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Vulnerabilities<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your responses indic=
ate
  that procedures exist for addressing known security vulnerabilities in
  applications you are currently using.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>These procedures sho=
uld
  include lab testing of the patches as well as application testing after t=
he
  patch has been applied, to identify conflicts that may require the patch =
to
  be rolled back.<br>
  <br>
  Periodically revisit these procedures and verify that they meet current
  application requirements.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Appl=
ication
   Design<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The application shou=
ld
  implement an authentication mechanism whose strength is commensurate with
  requirements governing security of data or access to functionality.
  Applications that rely on passwords should provide for password complexity
  constraints that include character mix (alpha, numeric, and symbols), min=
imum
  length, history maintenance, enforced lifetime, pre-expiration, and
  dictionary checking. <br>
  <br>
  The application should log failed login attempts, excluding the password.
  Each component that provides access to data or functionality should verify
  the existence of proper authentication credentials. <br>
  <br>
  Administrative access to systems should be protected with the strongest f=
orms
  of authentication available. Typically the restrictions around password c=
reation
  for administrators should be greater than those for normal accounts.<br>
  <br>
  In addition to strong passwords with good password policies, for added
  security multifactor authentication should be considered.<o:p></o:p></spa=
n></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your responses indic=
ate
  that multifactor authentication is being used for key applications.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To further mitigate =
the
  risks of brute-force password attacks for external applications, consider
  implementing the following controls:<br>
  <br>
  + Password expiration<br>
  + Account lockout after at least 10 failed login attempts<br>
  + System logging<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The use of strong
  passwords is a basic element of Defense-in-Depth. Strong passwords should=
 be
  8 to 14 characters in length, with alphanumeric and special characters.
  Minimum length, history maintenance, lifetime, and pre-expiration of
  passwords should all be set to provide additional defenses to password
  strength. In general, password expiration should be set to the following:=
<br>
  <br>
  + Maximum length 90 days<br>
  + New accounts must change password at login<br>
  + Password history of 8 passwords (8 days minimum)<br>
  <br>
  Administrative access to systems should be protected with the strongest f=
orms
  of authentication available. Typically, the restrictions around password =
creation
  for administrators should be greater than those for normal accounts&#8212=
;if
  normal accounts require a password length of 8 characters, then
  administrative accounts should have 14-character passwords.<br>
  <br>
  Account lockout, after 10 failed login attempts, should be enabled on all
  user accounts. The controls around account lockout can vary from simply b=
eing
  focused on blocking brute-force password attacks to as complex as requiri=
ng
  administrator intervention to unlock. Consider the following guidelines w=
hen
  implementing controls around account lockout:<br>
  <br>
  + Account lockout after at least 10 failed login attempts for user accoun=
ts<br>
  + Require administrative access to re-enable accounts for critical
  applications and automatically re-enable regular user accounts after 5
  minutes for other applications<br>
  + 30-minute length to cache failures for regular user accounts<o:p></o:p>=
</span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that strong password controls are implemented across key applications.<o:=
p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  logging thresholds around failed authentications so that alerts can be se=
nt
  to systems administrators. Also consider extending the use of strong
  passwords across all applications.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes that
  account lockout controls are not implemented across key applications.<o:p=
></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Think about implemen=
ting
  account lockout (after 10 failed attempts), initially for all critical
  external applications. The controls around account lockout can vary from
  being focused on blocking brute-force password attacks to as complex as
  requiring administrator intervention to unlock the account. Consider the
  following guidelines when implementing controls around account lockout:<b=
r>
  <br>
  + Lockout after 10 failed login attempts<br>
  + Require administrative access to re-enable accounts<br>
  + 30 minute length to cache failures for regular user accounts<o:p></o:p>=
</span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a password-expiration control is not implemented across key
  applications.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  password expiration for all types of accounts for critical applications b=
ased
  on the guidelines mentioned in the Best Practice column. In general, pass=
word
  expiration should be set to the following:<br>
  <br>
  + Maximum length 90 days<br>
  + New accounts must change password at login<br>
  + Password history of 8 passwords (8 days minimum)<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authorization &am=
p;
  Access Control<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Applications should
  implement an authorization mechanism that provides access to sensitive da=
ta
  and functionality only to suitably permitted users or clients.<br>
  <br>
  Role-based access controls should be enforced at the database level as we=
ll
  as at the application interface. <br>
  <br>
  This will protect the database in the event that the client application is
  exploited. <br>
  <br>
  Authorization checks should require prior successful authentication to ha=
ve
  occurred. <br>
  <br>
  All attempts to obtain access without proper authorization should be logg=
ed. <br>
  <br>
  Conduct regular testing of key applications that process sensitive data a=
nd
  of the interfaces available to users from the Internet. Include both
  &quot;black box&quot; and &quot;informed&quot; testing against the
  application. Determine if users can gain access to data from other accoun=
ts. <o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authorization &am=
p;
  Access Control<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that key applications restrict access to sensitive data and functionality
  based on privileges assigned to the account.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider conducting
  focused application testing on key applications that process sensitive da=
ta
  and on the interfaces available to users from the Internet.<br>
  <br>
  Include both 'black box' and 'informed' testing against the application a=
nd
  test for privilege escalation.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Logging should be en=
abled
  across all applications in the environment. Log file data is important for
  incident and trend analysis as well as for auditing purposes. <br>
  <br>
  The applications should log failed and successful authentication attempts,
  changes to application data including user accounts, severe application
  errors, and failed and successful access to resources. <br>
  <br>
  When writing log data, the application should avoid writing sensitive dat=
a to
  log files.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  various events are being logged by applications in the environment. The a=
pplications
  should log all events based on listed best practices.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>For ease of log-file
  management and analysis, consider integrating with a centralized logging
  mechanism. The logging mechanism should retain and archive logs in accord=
ance
  with applicable corporate data retention policies.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  changes to user accounts are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging cha=
nges
  to user accounts in order to detect privilege escalations and unauthorized
  new account creations.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  successful access to resources is not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging
  successful access to resources in order to trace malicious behavior after=
 the
  fact.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  access denied to resources is not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging acc=
ess
  denied to resources in order to be able to detect attempts at privilege
  escalation.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  changes to data are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging cha=
nges
  to data in order to track malicious activity.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  application errors are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging
  application errors in order to be able to troubleshoot and detect any Tro=
jan
  horses or malicious code.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  successful authentications are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging
  successful authentications in order to track user activity.<o:p></o:p></s=
pan></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  failed authentication attempts are logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue logging fai=
led
  authentication attempts.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The application may =
accept
  input at multiple points from external sources, such as users, client app=
lications,
  and data feeds. It should perform validation checks of the syntactic and
  semantic validity of the input. It should also check that input data does=
 not
  violate limitations of underlying or dependent components, particularly
  string length and character set. <br>
  <br>
  All user-supplied fields should be validated at the server side.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that input from data feeds is not validated.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Work with the applic=
ation
  vendor (ISV or internal development team) to implement mechanisms to vali=
date
  all data input.<br>
  <br>
  The validation constraints to input data should accept data that is
  syntactically and semantically correct; the constraints should not rely
  solely on screening of input for invalid characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that all end-user input is validated.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue to audit ea=
ch
  application to ensure that user input is consistently and appropriately
  validated.<br>
  <br>
  The validation constraints to input data should accept data that is
  syntactically and semantically correct; the constraints should not rely
  solely on screening of input for invalid characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that client application input is not validated.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Work with the applic=
ation
  vendor (ISV or internal development team) to implement mechanisms to vali=
date
  all data input.<br>
  <br>
  The validation constraints to input data should accept data that is
  syntactically and semantically correct; the constraints should not rely
  solely on screening of input for invalid characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Data
   Storage &amp; Communications<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Sensitive data shoul=
d be
  encrypted or hashed in the database and file system. The application shou=
ld
  differentiate between data that is sensitive to disclosure and must be
  encrypted, data that is sensitive only to tampering and for which a keyed
  hash value (HMAC) must be generated, and data that can be irreversibly
  transformed (hashed) without loss of functionality (such as passwords). T=
he
  application should store keys used for decryption separately from the
  encrypted data. <br>
  <br>
  Sensitive data should be encrypted prior to transmission to other compone=
nts.
  Verify that intermediate components that handle the data in clear-text fo=
rm,
  prior to transmission or subsequent to receipt, do not present an undue
  threat to the data. The application should take advantage of authenticati=
on
  features available within the transport security mechanism. <br>
  <br>
  Examples of widely accepted strong ciphers are 3DES, AES, RSA, RC4, and
  Blowfish. Use 128-bit keys (1024 bits for RSA) at a minimum.<o:p></o:p></=
span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that key applications in your environment are encrypting sensitive data p=
rior
  to transmission. Your answer indicates that key applications in your
  environment do encrypt sensitive data that is in storage.<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Use industry-standard
  encryption algorithms for all encryption.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption - Algo=
rithm<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The application shou=
ld use
  industry-standard cryptographic algorithms with keys of appropriate sizes=
 and
  cryptographic modes appropriate to the need. <br>
  <br>
  Industry recognized strong ciphers include 3DES, AES, RSA, Blowfish, and =
RC4.
  <br>
  <br>
  A minimum key size of 128 bits (1024 bits for RSA) should be used.<o:p></=
o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption - Algo=
rithm<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are using DES encryption.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider upgrading y=
our
  encryption to 3DES or AES in order to make it much more difficult to break
  through brute-force techniques.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

</div>

<h3>Operations</h3>

<div>

<p><a name=3DOperations></a><span style=3D'font-size:10.0pt;font-family:Ari=
al'>This
area of analysis examines the operational practices, procedures, and guidel=
ines
followed by the organization to help enhance Defence-in-Depth. This assessm=
ent
examines policies and procedures that govern system builds, network
documentation, and the use of technology within the environment. It also
includes supporting activities required to manage the information and
procedures used by the administrators and operations staff within the
environment. By establishing operational practices, procedures, and guideli=
nes
that are understood and followed, an organization can potentially enhance i=
ts
Defense-in-Depth posture. The assessment reviews high level procedures an
organization can follow to help mitigate operations risk by focusing on the=
 following
areas of operations security:<o:p></o:p></span></p>

<ul type=3Ddisc>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Environment&#8212;System =
Build,
     Network Documentation, Application Data Flow, Application Architecture=
<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Security Policy&#8212;Pro=
tocols
     &amp; Services, Acceptable Use, User Account Management <o:p></o:p></s=
pan></li>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Patch &amp; Update
     Management&#8212;Patch Management, Virus Signatures<o:p></o:p></span><=
/li>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Backup &amp;
     Recovery&#8212;Backup, Storage, Testing<o:p></o:p></span></li>
</ul>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Envi=
ronment<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Firewalls are a firs=
t-line
  defense mechanism and should be placed at all network border locations. R=
ules
  implemented on firewalls should be highly restrictive and set on a
  host-by-host and service-by-service basis.<br>
  <br>
  When creating firewall rules and router ACLs (Access Control Lists), focu=
s on
  first protecting access control devices and the network from attack. <br>
  <br>
  <br>
  + Enforce data flow by use of network ACLs and firewall rules. <br>
  + Test firewall rules and router ACLs to determine whether or not existing
  rules contribute to Denial of Service (DoS) attacks.<br>
  + Deploy one or more DMZs as part of a systematic and formal firewall
  development. <br>
  + Place all Internet accessible servers there. Restrict connectivity to a=
nd
  from the DMZs.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the firewall is tested regularly to ensure proper performance.<o:p></o:p>=
</span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue regular tes=
ting
  of your firewall. Ensure that functionality is working as expected not on=
ly
  from external traffic, but that the firewall is also behaving as expected
  towards internal traffic.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Securing Your Netw=
ork<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This article, written=
 for
network administrators and IT professionals, presents an overview of the top
network-level threats and the ways in which you can counter them. The autho=
rs
review security issues and the configuration settings to be applied to rout=
ers,
firewalls and switches.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh15.asp"
target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMC=
h15.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>FAQ About Internet
Firewalls<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This FAQ is appropria=
te for
users who are not IT professionals and who have questions about using and
deploying a firewall.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/security/protect/firewall.asp" target=3D"_=
new">http://www.microsoft.com/security/protect/firewall.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Administrative Us=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>For administrative a=
ccounts,
  implement a strict policy that requires the use of complex passwords that
  meet the following criteria:<br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 14 characters<br>
  <br>
  To further mitigate the risk of a password attack, implement the following
  controls:<br>
  <br>
  + Password expiration<br>
  + Account lockout after 7 to 10 failed login attempts<br>
  + System logging<br>
  <br>
  In addition to implementing complex passwords, consider implementing
  multifactor authentication. Implement advanced controls around account
  management (do not allow account sharing) and account-access logging.<o:p=
></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Administrative Us=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  separate logins are used for secure administration of systems and devices
  within the environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue requiring
  separate accounts for administrative/management activity, and ensure that
  administrative credentials are changed frequently.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Administrative Us=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  users have been granted administrative access to their workstations.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider removing
  administrative access for users, in order to limit the ability to modify =
the
  secure build.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>When management pack=
ages
  are used, the administrative consoles should be hardened and physically
  secured.<br>
  <br>
  Harden the management workstations used to manage the network servers and
  devices.<br>
  <br>
  Use SSH or VPN connections to protect clear-text protocols.<br>
  <br>
  Management workstations should be dedicated to specific network and host
  administrators.<br>
  <br>
  Test all management systems that utilize SNMP to ensure that they are pat=
ched
  to the latest version and do not use default community strings.<br>
  <br>
  Shared systems do not store any management-specific data. Shared workstat=
ions
  are not used to administer network devices or hosts.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host -
  Servers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host -
  Servers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  a dedicated management computer does not exist for servers.<o:p></o:p></s=
pan></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider deploying a
  separate management workstation to administer the servers on the network.=
<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host -
  Network Devices<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host -
  Network Devices<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that a
  dedicated management computer for administering network devices has been
  deployed.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Test all management
  systems that utilize SNMP to ensure that they are patched to the latest
  version and do not use default community settings.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party Relat=
ionships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To help reduce the r=
isk of
  exposure, formal policies and procedures should exist to govern relations=
hips
  with third parties. These policies and procedures help to identify securi=
ty
  issues and the responsibilities of each party in mitigating them. <br>
  <br>
  These policies should include: <br>
  + Level of connectivity and access <br>
  + Data presentation and manipulation <br>
  + Roles and responsibilities (including authority) of each party <br>
  + Management of the relationship&#8212;setup, ongoing, and termination.<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party
  Relationships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization manages the computing environment itself.<o:p></o:p></s=
pan></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Based on business ne=
eds,
  either self management or outsourcing can be viable solutions. If the
  management is outsourced, security requirements should be addressed in the
  contract, and service-level agreements (SLAs) used to enforce compliance =
with
  those requirements.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Secu=
rity
   Policy<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the build processes for infrastructure devices have been documented.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue using a
  documented build process for infrastructure devices, and ensure that the
  build is kept current as new patches are released.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the build processes for servers have been documented.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement a document=
ed
  build process for servers, and ensure that the build is kept current as n=
ew
  patches are released.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the build processes for workstations and laptops have been documented.<o:=
p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement a document=
ed
  build process for workstations and laptops, and ensure that the build is =
kept
  current as new patches are released.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Windows Server 2003
Security Guide<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This guide provides
easy-to-understand advice, tools, and templates to help you secure
Microsoft&reg; Windows Server&#8482; 2003 operating system in many
environments. Network administrators and IT professionals responsible for
installing and configuring servers would likely benefit the most from this
information.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/security/prodtech/win2003/w2003hg/sgch00.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/security/prodtech/win2003/w2003hg/sgch00.asp</a><o:p></o:p></sp=
an></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Gold Cer=
tified
Partners<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The Microsoft&reg; Go=
ld
Certified Partner Program for Security Solutions will help you find special=
ists
in building and deploying IT solutions that help protect user security. Mic=
rosoft
works closely with partners to help ensure they have the highest level of
expertise with Microsoft technologies and solutions.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://directory.microsoft.com/resourcedirectory/Services.aspx"
target=3D"_new">http://directory.microsoft.com/resourcedirectory/Services.a=
spx</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Securing Your Data=
base
Server<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Database architects a=
nd
database administrators will benefit most from this guide, which provides a
proven methodology for securing database servers--Microsoft&reg; SQL
Server&#8482; in particular. The guide reviews the most common threats that
affect database servers, then steps through the process of applying a secure
configuration.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh18.asp"
target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMC=
h18.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>passfilt.dll<o:p><=
/o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Passfilt.dll is a
replacement .dll for Microsoft&reg; Windows NT&reg; 4.0 operating system. U=
sing
passfilt, you can modify the operating system's default parameters to provi=
de
strong password support and administrative account lockout (at the network
level).<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/default.asp?url=3D/library/en-us/=
security/security/strong_password_enforcement_and_passfilt_dll.asp"
target=3D"_new">http://msdn.microsoft.com/library/default.asp?url=3D/librar=
y/en-us/security/security/strong_password_enforcement_and_passfilt_dll.asp<=
/a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Protocols &amp;
  Services<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Clearly document the
  standards and practices regarding which protocols and services are allowe=
d by
  the organization. Access-control lists should be verified to ensure that =
all
  services allowed have a business need for the level of access granted.
  Identify specific IP addresses/ranges wherever possible. Servers should h=
ave
  their services limited to only those required by the business need. Speci=
fics
  for protocol version and minimum encryption strength should also be state=
d in
  these guidelines. Enforce accepted protocol usage through the use of
  perimeter devices (routers, gateways, firewalls, etc.), strong
  authentication, and encrypted communications. <o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Protocols &amp;
  Services<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that you have documented guidelines that govern which protocols and servi=
ces
  are allowed on the corporate network.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Audit the documentat=
ion
  for allowed protocols and services and check that it conforms to the
  configured ACLs and firewall rules on the respective devices.<br>
  <br>
  Publish this information on the corporate intranet, and implement policies
  that govern making changes to the guidelines.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Acceptable Use<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>An Acceptable Use po=
licy
  exists to govern the appropriate use of corporate networks, applications,
  data, and systems. The policy should also cover digital media, printed me=
dia,
  and other intellectual property.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Acceptable Use<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a corporate acceptable use policy exists at your organization.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>All employees and
  customers who use any corporate resources should be familiar with these
  policies. Make the policies available on the corporate intranet and consi=
der
  introducing them as part of new employee orientation.<o:p></o:p></span></=
p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>User Account Mana=
gement<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Individual user acco=
unts
  should be created for all persons needing access to IT resources. Accounts
  should not be shared among users. By default, accounts should be created =
with
  the minimum required privileges enabled. Network and server administrators
  should have privileged (administrator) as well unprivileged accounts.
  Password strength should be enforced and regularly audited and all account
  modifications should be logged. As an individual's role changes, all acco=
unt
  privileges should be reviewed and modified as necessary. When employment =
is
  terminated, all accounts should be disabled or removed.<o:p></o:p></span>=
</p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>User Account Mana=
gement<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that policies governing individual user account management are being used
  within the environment. <o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>It is important to m=
anage
  individual user accounts through a list of policies mentioned in the best
  practice section.<br>
  <br>
  For a Windows-based environment, consider implementing user account
  management through Active Directory and periodically test password streng=
th
  on these accounts. A variety of shareware, freeware, and third-party tools
  can be used for this.<br>
  <br>
  Develop auditing practices and alerts for Microsoft Operations Manager (M=
OM)
  to track account privilege changes on Windows 2000 based servers.<o:p></o=
:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>User Account Mana=
gement<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  user accounts are not shared.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>User Account Mana=
gement<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  administrators do not have both privileged and unprivileged accounts.<o:p=
></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Administrators shoul=
d be
  required to use unprivileged accounts for regular work, and only use
  privileged accounts when needed.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>User Account Mana=
gement<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  accounts are not disabled when users leave your organization.<o:p></o:p><=
/span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To protect against
  malicious ex-employees, all accounts should be immediately disabled on ex=
it.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>User Account Mana=
gement<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  password strength is not enforced.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Policy should define=
 a
  minimum password strength, which should then be enforced by the authentic=
ation
  mechanism.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The organization
  identifies individuals with subject-matter expertise in security to be
  involved in all security-related discussions and decisions. The organizat=
ion
  identifies what it needs to protect based on the value of the asset, as w=
ell
  as the level of security needed to protect it. All threat vectors are
  included in the analysis. The resulting strategy balances cost and benefi=
t of
  the protections, and may include transfer or acceptance of risk as an opt=
ion.
  Security requirements, derived from both business and technical
  representatives, are documented and published for all parties to review a=
nd
  address in future designs. Differences between classes of applications and
  data may result in different end requirements being identified.<o:p></o:p=
></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization has a model for assigning criticality levels to each
  component of the computing environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue to assign l=
evels
  of criticality to components, and be sure to update the model as new
  equipment is added.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Governance<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party audits s=
hould
  be performed regularly to ensure compliance with all current legal and ci=
vil
  governance requirements (e.g., HIPAA for healthcare; Sarbanes-Oxley for
  SEC-regulated firms).<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Governance<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization has policies to govern the computing environment.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue developing =
and
  implementing policies for governance of the computing environment, in
  accordance with applicable standards (ISO17799, CoBIT, HIPAA, SOX, etc.)<=
o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security policies sh=
ould
  be defined with input from management, IT, and HR; empowered by the corpo=
rate
  executives; and frequently updated to reflect current best practice (such=
 as
  CoBIT).<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat an
  information security policy exists to govern the security-related activit=
y of
  the organization.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue usage of the
  information security policy, but periodically review and update the polic=
y to
  reflect current technologies and environment changes.<o:p></o:p></span></=
p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the policy was developed with IT alone.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Policies should be
  developed both by IT and business representatives in order to account for
  legal, technical, and business requirements.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Operatio=
ns
Framework (MOF) Process Model for Operations<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This white paper desc=
ribes
the Microsoft&reg; Operations Framework (MOF) process model, which provides
technical guidance for organizations working to achieve reliability,
availability, supportability, and manageability of their IT solutions. This
paper is intended for IT managers responsible for defining consistent polic=
ies,
procedures, standards, and best practices across an organization.<o:p></o:p=
></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/itsolutions/tandp/opex/mofrl/mofpm.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/itsolutions/tandp/opex/mofrl/mofpm.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Operatio=
ns
Framework (MOF) - Team Model<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This white paper prov=
ides
guidance on how to structure IT teams to help achieve greater efficiency and
synergy. This document is intended for IT and Operations managers as an out=
line
of best practices for organizational structure and process ownership.<o:p><=
/o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/itsolutions/cits/mo/mof/moftml.msp=
x"
target=3D"_new">http://www.microsoft.com/technet/itsolutions/cits/mo/mof/mo=
ftml.mspx</a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Patch
   &amp; Update Management<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Network Documenta=
tion<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Current and accurate
  physical and logical diagrams of the external and internal networks should
  always be available. <br>
  <br>
  Any changes made to the environment should be reflected in the correspond=
ing
  diagrams in a timely manner. <br>
  <br>
  Access to the latest diagrams should be restricted to the IT operations t=
eam.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Network Documenta=
tion<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
s that
  logical network diagrams exist for your environment and they are kept
  up-to-date.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review the policy th=
at
  governs updates to the network diagrams.<br>
  <br>
  If change control policy exists for the environment, include updates to t=
he
  diagram as a formal step in the change control policy.<br>
  <br>
  Make certain the latest diagrams are only available to restricted personn=
el,
  primarily the IT operations and security team.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application Data =
Flow<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Application architec=
ture
  diagrams should depict major components and data flows that map the flow =
of
  critical data through the environment, including the systems through which
  the data passes and how the data is manipulated. <br>
  <br>
  As changes are made to the application or the environment that hosts the
  application, the diagrams should be updated in a timely manner.<o:p></o:p=
></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application Data =
Flow<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that application architecture and data-flow diagrams exist for external
  applications only. They do not exist for any of the internal applications=
 in
  your environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Work with the applic=
ation
  architecture team and the respective business owners to develop architect=
ure
  and data flow diagrams for internal applications. Update these diagrams i=
n a
  timely manner, when changes are made to the environment or to the applica=
tion
  itself.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><span class=3DGramE><b><span style=3D'font-size:10.0pt;font-family:Arial=
'>Building
Secure ASP.NET Applications: Authentication, Authorization and Secure
communication.</span></b></span><b><span style=3D'font-size:10.0pt;font-fam=
ily:
Arial'> <o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This guide provides
information to help you design and build secure Microsoft&reg; ASP.NET
applications for Windows&reg; 2000 operating system and version 1.0 of the
Microsoft .NET Framework. It describes how to use various features to enhan=
ce
security in building application level authentication and authorization
communication mechanisms within and across the tiers of .NET applications.<=
o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/default.asp?url=3D/library/en-us/=
dnnetsec/html/secnetlpMSDN.asp"
target=3D"_new">http://msdn.microsoft.com/library/default.asp?url=3D/librar=
y/en-us/dnnetsec/html/secnetlpMSDN.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Improving Web
Application Security<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This guide gives you a
solid foundation for designing, building, and configuring secure Microsoft&=
reg;
ASP.NET Web applications. Whether you are maintaining applications or build=
ing
new ones, you can apply the principles here to help make sure your Web
applications are hack-resistant.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/ThreatCounter=
.asp"
target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/Threa=
tCounter.asp</a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Patch Management<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security patches and
  configuration changes should be deployed in a timely fashion (defined by
  corporate security policy) from when they become available. Whether devel=
oped
  internally or supplied by a third-party, patches and updates should be th=
oroughly
  tested in a lab environment before being rolled into production.
  Additionally, each system should be tested after the patch has been appli=
ed
  to identify conflicts which are unique to that system and may require
  rollback of the patch. <br>
  <br>
  Systems should be categorized to allow for scheduling based on
  groupings&#8212;critical systems and those exposed to higher traffic shou=
ld
  be patched first.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Patch Management<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a patch &amp; update policy exists only for applications and not for
  operating systems<span class=3DGramE>..</span><o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>While having a patch=
 &amp;
  update policy for applications is important, it is critical to enforce a
  similar policy for operating systems as well.<br>
  <br>
  Develop a patch update policy for operating systems, based on the informa=
tion
  in the best practice section. Patch external and Internet <span class=3DG=
ramE>servers</span>
  first, then critical internal servers and finally non-critical servers.<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Patch Management<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  patches and updates are tested before being applied to all systems.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue testing all
  patches and updates before they are deployed into the production environm=
ent.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Patch Management<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Deploy automated pat=
ch
  management for servers to ensure that patches are applied in a timely man=
ner.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Patch Management<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  automated patch management is used on workstations and laptops.<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Guide to
Security Patch Management<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This guide should be =
read
by system administrators responsible for maintaining multiple Microsoft&reg;
Windows&reg;-based computers within an organization. It provides essential
security patch management advice and the recommended processes, tools, and
techniques for implementing it<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/security/topics/patch/secpatch/Part_I/P1CH3.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/security/topics/patch/secpatch/Part_I/P1CH3.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Virus Signatures<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Regularly monitor re=
levant
  vendors' sites for virus signature updates and download updates to a
  quarantined area for testing in a lab environment. Verify that the update=
s do
  not cause any conflicts with deployed operating systems or applications
  before rolling out to production. <br>
  <br>
  Auto-update features for anti-virus solutions should be disabled on all
  systems to prevent potentially damaging files from being deployed before =
they
  are tested.<br>
  <br>
  For anti-virus applications, consider deploying a central console that wi=
ll
  facilitate reporting on which systems are out-of-date or have software
  features disabled.<br>
  <br>
  In the case of remote users who do not regularly connect to the corporate
  network, consider using an auto update feature.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Virus Signatures<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
s that
  policies for virus signature updates do exist in your environment.<o:p></=
o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Regularly monitor re=
levant
  vendor and security sites for warnings on recent attacks and new virus
  outbreaks. Periodically audit remote users to ensure they are updating th=
eir
  systems.<br>
  <br>
  Continue based on the listed best practices.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Change Management=
 and
  Configuration<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Any changes to the
  production environment should first be tested for security and compatibil=
ity
  before being released into production, and full documentation should be k=
ept
  of the configuration of all production systems.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Change Management=
 and
  Configuration<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization has a change and configuration management process.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue using a for=
mal
  change and configuration management process to test and document all upda=
tes
  before deployment.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Change Management=
 and
  Configuration<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Change Management=
 and
  Configuration<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  changes to configurations are tested before deployment to production syst=
ems.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue the practic=
e of
  testing all configuration changes before deployment to production systems=
.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Change Management=
 and
  Configuration<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  configuration compliance is checked and enforced centrally.<o:p></o:p></s=
pan></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue the practic=
e of
  checking for and enforcing compliance through a central management system=
.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Back=
up and
   Recovery<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files<o:p></o=
:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Log files are config=
ured
  to allow for recording all planned activity without overwriting entries. =
An
  automated process should be set up to rotate log files on a daily basis a=
nd
  offload the logs to a secure server within the management network.<br>
  <br>
  Access to log files and configuration settings should be restricted to
  prevent modification and deletion.<br>
  <br>
  Log files should be reviewed regularly to ensure that suspicious or anoma=
lous
  activity is identified. Review should include systems operation, maintena=
nce,
  and security. Event correlation software and trend analysis should be use=
d to
  enhance review capability.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files<o:p></o=
:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  logs are not written to a centralized log server.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging to a
  centralized log server in order to preserve data in case a production ser=
ver
  is compromised.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files<o:p></o=
:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  log files are rotated in your environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider storing the=
 log
  files in a database so that the security team can perform trend analysis =
and
  have access to protected logs in the event an incident occurs.<o:p></o:p>=
</span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files<o:p></o=
:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  access to log files is not protected in your environment.<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider protecting =
all
  operating system log files and application log files on the servers in the
  DMZ and core networks by limiting file access permissions.<o:p></o:p></sp=
an></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files<o:p></o=
:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  log files are not reviewed regularly in your environment.<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security team sh=
ould
  review the log files every day to look for suspicious or anomalous
  activities. Consider having the log files from the DMZ and core network
  servers monitored by MOM (Microsoft Operations Manager). In the event of
  critical log-file entries being generated, MOM will send alerts to the
  appropriate members of the team.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files - Rotat=
ion<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files - Rotat=
ion<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  log files are reviewed regularly in your environment.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider having the =
log
  files from the DMZ and core network servers monitored by MOM (Microsoft
  Operations Manager). In the event of critical log-file entries being
  generated, MOM will send alerts to the appropriate members of the team.<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Log Files - Rotat=
ion<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  log files are reviewed daily.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security team sh=
ould
  review the log files every day to look for suspicious or anomalous
  activities. Consider having the log files from the DMZ and core network
  servers monitored by MOM (Microsoft Operations Manager). In the event of
  critical log-file entries being generated, MOM will send alerts to the
  appropriate members of the team.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup<o:p></o:p>=
</span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Full backups should =
be
  performed at regular intervals. If feasible, partial intermediary backups
  should be made between full backups. The backup strategy should address t=
he
  worst-case scenario of a complete system and application restore. For
  critical applications, the restore process should result in a fully
  functioning application in minimal time.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup<o:p></o:p>=
</span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
s that
  critical assets in your environment are being backed up on a regular basi=
s.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Audit the backup
  mechanisms and ensure that all critical assets are being backed up regula=
rly.
  Periodically test the restore functionality to verify recoverability from=
 the
  backup media.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Detailed policies sh=
ould
  exist to govern the storage and handling of backup media. These policies
  should address issues such as: <br>
  + Onsite/Offsite Storage <br>
  + Media Rotation <br>
  + Security Controls <br>
  + Personnel Access Controls <br>
  <br>
  Removable backup media should be stored in locked, fire-proof cabinets and
  only authorized personnel should have access to these cabinets. <br>
  <br>
  Offsite storage locations should be used to offer greater recoverability =
in
  the event of disaster.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a policy which addresses the storage and handling of backup media do=
es
  exist in your environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>While just having a =
policy
  in place to govern the handling and storage of backup media is a great fi=
rst
  step, it is important to have this policy be thorough and well defined.
  Regularly audit the policy to ensure that it meets all of the criteria ou=
tlined
  in the best practice section.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  backups are placed in offsite storage.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  backups are not stored in locked fireproof cabinets.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup media should =
be
  kept in a locked, fireproof cabinet offsite, have its access restricted o=
nly
  to necessary personnel, and rotated and replaced in accordance with
  manufacturer's recommendations.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  access to backup media is not restricted.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup media should =
be
  kept in a locked, fireproof cabinet offsite, have its access restricted o=
nly
  to necessary personnel, and rotated and replaced in accordance with
  manufacturer's recommendations.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  backup media rotation and replacement is not defined by policy.<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup media should =
be
  kept in a locked, fireproof cabinet offsite, have its access restricted o=
nly
  to necessary personnel, and rotated and replaced in accordance with
  manufacturer's recommendations.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Rest=
ore<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup and restore
  procedures should be tested regularly to identify faulty media and improve
  the chance of a successful restore in the event of an outage.<br>
  <br>
  Detailed procedures for restoring different systems, including applicatio=
ns,
  should be well-documented. <br>
  <br>
  Audit <span class=3DGramE>all the</span> backup and restore documents to =
ensure
  all the critical systems necessary for business continuity are covered.<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Rest=
ore<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
d that
  a well-documented policy exists for backup &amp; restore procedures.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Audit <span class=3D=
GramE>all
  the</span> backup and restore documents to ensure all the critical systems
  necessary for business continuity are covered. Test backup and recovery
  process on a regular basis to ensure that all hardware and software
  components are functioning as expected.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Backup and Restore
Solution<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This resource provides
guidance on the importance of backup and recovery services in Microsoft&reg;
Windows&reg; operating systems.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/security/topics/disasterrecovery/s=
ecmod200.mspx"
target=3D"_new">http://www.microsoft.com/technet/security/topics/disasterre=
covery/secmod200.mspx</a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

</div>

<h3>People</h3>

<div>

<p><a name=3DPeople></a><span style=3D'font-size:10.0pt;font-family:Arial'>=
Security
efforts in an organization often overlook organizational aspects that are
critical to helping the organization maintain overall security. This sectio=
n of
the assessment reviews those processes within the enterprise governing
corporate security policies, Human Resources processes, and employee securi=
ty
awareness and training. The People Area of Analysis also focuses on dealing
with security as it relates to day-to-day operational assignments and role
definitions. The assessment reviews high- level procedures an organization =
can
follow to help mitigate people risk by focusing on the following areas of
people security: <o:p></o:p></span></p>

<ul type=3Ddisc>
 <li class=3DMsoNormal style=3D'mso-list:l3 level1 lfo5;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Requirements and
     Assessments&#8212;Planning, Third-Party Assessments<o:p></o:p></span><=
/li>
 <li class=3DMsoNormal style=3D'mso-list:l3 level1 lfo5;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Policy and Procedures&#82=
12;HR
     Policy, Third-Party Relationships<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l3 level1 lfo5;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Training and Awareness&#8=
212;Security
     Awareness<o:p></o:p></span></li>
</ul>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Requ=
irements
   &amp; Assessments<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The organization
  identifies individuals with subject-matter expertise in security to be
  involved in all security-related discussions and decisions. The organizat=
ion
  identifies what it needs to protect based on the value of the asset, as w=
ell
  as the level of security needed to protect it. All threat vectors are
  included in the analysis. The resulting strategy balances cost and benefi=
t of
  the protections, and may include transfer or acceptance of risk as an opt=
ion.
  Security requirements, derived from both business and technical
  representatives, are documented and published for all parties to review a=
nd
  address in future designs. Differences between classes of applications and
  data may result in different end requirements being identified.<o:p></o:p=
></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the security team is involved at the planning and design level of the
  technology lifecycle.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the security team is not involved at the deployment level of the technolo=
gy
  lifecycle.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security team sh=
ould
  be involved at all stages of the technology lifecycle, for all projects.<=
o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the security team is not involved at the testing level of the technology
  lifecycle.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security team sh=
ould
  be involved at all stages of the technology lifecycle, for all projects.<=
o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the security team is not involved at the implementation level of the
  technology lifecycle.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security team sh=
ould
  be involved at all stages of the technology lifecycle, for all projects.<=
o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Requirem=
ents<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party assessme=
nts
  should be conducted to gain a valuable and objective view of an
  organization's security posture.<br>
  <br>
  Third-party assessments might also prove beneficial in meeting regulatory,
  customer, partner, and vendor requirements. <br>
  <br>
  Assessments should cover infrastructure, applications, policies, and audit
  procedures. These assessments should focus not solely on identifying
  vulnerabilities, but also on auditing for nonsecure configurations and
  extraneous access privileges. Security policies and procedures should be
  reviewed and evaluated for gaps. <o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security assessments
  should cover infrastructure, applications, policies, and audits.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security assessments
  should cover infrastructure, applications, policies, and audits.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security assessments
  should cover infrastructure, applications, policies, and audits.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security assessments
  should cover infrastructure, applications, policies, and audits.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  security assessments for your organization are performed by internal staf=
f<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue performing
  frequent security audits by internal staff, but augment these audits with
  input from a trusted third party.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  assessments are performed annually.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  security assessments are performed on infrastructure components.<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security assessments
  should cover infrastructure, applications, policies, and audits.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security assessments
  should cover infrastructure, applications, policies, and audits.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Assessme=
nts<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security assessments
  should cover infrastructure, applications, policies, and audits.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A security awareness
  program helps employees contribute to a company's overall security postur=
e by
  keeping them up-to-date on security risks. Knowledgeable employees are yo=
ur
  best source for reporting security issues.<br>
  <br>
  An effective awareness program should take into account all aspects of
  security&#8212;including application, network, and physical&#8212;while
  providing clear guidelines for what employees should do if they witness
  things that appear to jeopardize the security of any of these elements. <=
br>
  <br>
  Implement policies that regulate employee usage of company resources. <br>
  <br>
  Awareness programs should be a part of new employee orientation. Updates =
and
  refresher courses should be conducted regularly to ensure all employees a=
re
  aware of the most current practices and risks. <br>
  <br>
  Periodic testing should be implemented to ensure employees have absorbed =
the
  material.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you have an individual or group responsibility for security at your
  organization.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue ensuring th=
at
  your company has a person or team responsible for security, and require t=
hat
  this team be consulted before making changes to the computing environment=
.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization security team is involved in defining requirements for =
new
  and existing technologies.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue consulting =
with
  the security team before making changes to the computing environment. The
  security team should be involved in any discussions at the earliest stage=
s of
  planning.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Learning=
 Web
site Security Resources<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft&reg; Learni=
ng is
a central source for integrated learning solutions. It provides training,
books, skills assessments, certifications, and online reference materials to
help users maximize the power of Microsoft technology.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/learning/centers/security.asp" target=3D"_=
new">http://www.microsoft.com/learning/centers/security.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Poli=
cy
   &amp; Procedures<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Background Checks=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Background checks sh=
ould
  be performed to identify any potential issues, thus reducing the risk
  exposure to the organization and to other employees. This step also helps
  identify any potential issues and gaps in the candidate's resume. <br>
  <br>
  The hiring process should include a review of the candidate's employment =
and
  legal history. <br>
  <br>
  A candidate's skills should be evaluated against detailed job descriptions
  and task requirements to understand strengths and weaknesses.<o:p></o:p><=
/span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Background Checks=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
s that
  background checks are being performed for all employees.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Excellent, continue =
this
  policy. Ensure that the background check includes a review of the candida=
te's
  employment, education, and legal history.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Human Resources P=
olicy<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Formal exit procedur=
es
  ensure that all the necessary steps are undertaken when an employment
  contract is terminated. <br>
  <br>
  These procedures should exist to handle both friendly and unfriendly empl=
oyee
  exits. <br>
  <br>
  These procedures should include: <br>
  + Notification to all departments&#8212;Human Resources, IT, Physical
  Security, Help Desk, Finance, etc. <br>
  + Escorting the employee from the premises <br>
  + Termination of all accounts and network access <br>
  + Collection of company property&#8212;laptop, PDA, electronic media,
  confidential documents, etc.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Human Resources P=
olicy<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a friendly employee exit policy does not exist within your organizat=
ion.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Immediately begin wo=
rk
  with the HR department to develop procedures for friendly employee exits.=
<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Human Resources P=
olicy<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a formal hostile-employee exit policy exists within your organizatio=
n.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Regularly review exi=
sting
  hostile employee exit procedures and update for gaps based on past
  terminations.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party
  Relationships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To help reduce the r=
isk of
  exposure, formal policies and procedures should exist to govern relations=
hips
  with third parties. These policies and procedures help to identify securi=
ty
  issues and the responsibilities of each party in mitigating them. <br>
  <br>
  These policies should include: <br>
  + Level of connectivity and access <br>
  + Data presentation and manipulation <br>
  + Roles and responsibilities (including authority) of each party <br>
  + Management of the relationship&#8212;setup, ongoing, and termination.<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party
  Relationships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
s that
  policies do exist which govern third-party relationships.<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Audit all <span
  class=3DGramE>the polices</span> and procedures for existing third-party
  relationships. Revisit these policies as the business evolves to ensure t=
hey
  are still aligned and properly represent the position of your company.<o:=
p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Trai=
ning
   &amp; Awareness<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A security awareness
  program helps employees contribute to a company's overall security postur=
e by
  keeping them up-to-date on security risks. Knowledgeable employees are yo=
ur
  best source for reporting security issues.<br>
  <br>
  An effective awareness program should take into account all aspects of
  security&#8212;including application, network, and physical&#8212;while
  providing clear guidelines for what employees should do if they witness
  things that appear to jeopardize the security of any of these elements. <=
br>
  <br>
  Implement policies that regulate employee usage of company resources. <br>
  <br>
  Awareness programs should be a part of new employee orientation. Updates =
and
  refresher courses should be conducted regularly to ensure all employees a=
re
  aware of the most current practices and risks. <br>
  <br>
  Periodic testing should be implemented to ensure employees have absorbed =
the
  material.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a security awareness program does exist at your organization.<o:p></=
o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>All employees should
  participate in security awareness training. Security awareness should be
  mandatory as part of new employee orientation.<br>
  <br>
  Knowledgeable employees are your best source for reporting security issue=
s.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  less than 25% of all employees have participated in a security awareness
  program.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>All employees should
  participate in security awareness training. Security awareness should be
  mandatory as part of new employee orientation.<br>
  <br>
  Knowledgeable employees are your best source for reporting security issue=
s.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat awareness
  training does not cover computer security, including the use of personal
  firewalls and encryption.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security awareness
  training should cover all aspects of security, including security policies
  and controls, reporting suspicious activity, privacy, e-mail security,
  Internet security, and computer security.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  awareness training does not cover Internet security, including Web surfing
  and downloads.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security awareness
  training should cover all aspects of security, including security policies
  and controls, reporting suspicious activity, privacy, e-mail security,
  Internet security, and computer security.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  awareness training covers privacy issues.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  awareness training does not cover reporting suspicious activity.<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security awareness
  training should cover all aspects of security, including security policies
  and controls, reporting suspicious activity, privacy, e-mail security,
  Internet security, and computer security.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  awareness training does not cover your organization's security policies a=
nd
  controls.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security awareness
  training should cover all aspects of security, including security policies
  and controls, reporting suspicious activity, privacy, e-mail security,
  Internet security, and computer security.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  awareness training does not cover email security, including spam and
  attachment handling.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security awareness
  training should cover all aspects of security, including security policies
  and controls, reporting suspicious activity, privacy, e-mail security,
  Internet security, and computer security.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  training is provided bi-annually or less.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security training sh=
ould
  be provided for all employees on a quarterly basis.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  applications security training is not offered to employees based on their
  role in the organization.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Role based, subject =
matter
  related training should be offered to all employees in the organization. =
This
  training should be more thorough than that given to general employees, and
  refreshed frequently.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  incident readiness and response training is not offered to employees base=
d on
  their role in the organization.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Role based, subject =
matter
  related training should be offered to all employees in the organization. =
This
  training should be more thorough than that given to general employees, and
  refreshed frequently.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  infrastructure security training is not offered to employees based on the=
ir
  role in the organization.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Role based, subject =
matter
  related training should be offered to all employees in the organization. =
This
  training should be more thorough than that given to general employees, and
  refreshed frequently.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Awarenes=
s<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  operations security training is not offered to employees based on their r=
ole
  in the organization.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Role based, subject =
matter
  related training should be offered to all employees in the organization. =
This
  training should be more thorough than that given to general employees, and
  refreshed frequently.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Learning=
 Web
site Security Resources<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft&reg; Learni=
ng is
a central source for integrated learning solutions. It provides training,
books, skills assessments, certifications, and online reference materials to
help users maximize the power of Microsoft technology.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/learning/centers/security.asp" target=3D"_=
new">http://www.microsoft.com/learning/centers/security.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

</div>

<b><span style=3D'font-size:12.0pt;font-family:Arial;mso-fareast-font-famil=
y:
"Times New Roman";color:#6487DC;mso-ansi-language:EN-US;mso-fareast-languag=
e:
EN-US;mso-bidi-language:AR-SA'><br clear=3Dall style=3D'page-break-before:a=
lways'>
</span></b>

<h3>&nbsp;</h3>

<h1><a name=3DRecommendations></a>Prioritized Action List</h1>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The following list
prioritizes the recommendations made above in the <a href=3D"#Detail">Asses=
sment
Detail</a> section. For more information on any of these items, refer to the
matching entry in that section.<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>A Microsoft security
partner can help with building a security program that encompasses these ac=
tions.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
   <td width=3D"100%" colspan=3D2 valign=3Dtop style=3D'width:100.0%;border=
:solid black 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Prioritized Acti=
on
   List<o:p></o:p></span></b></p>
   </td>
  </tr>
  <tr style=3D'mso-yfti-irow:1'>
   <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1=
.0pt;
   border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid=
 black .5pt;
   background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Analysis Topic<o=
:p></o:p></span></b></p>
   </td>
   <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;bord=
er-left:
   none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
   mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
   mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recommendation<o=
:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:2'>
  <td width=3D"100%" colspan=3D2 valign=3Dtop style=3D'width:100.0%;border:=
solid black 1.0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>High Priority<o:p=
></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Infrastructure<=
o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Perimeter
  Defense<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Anti-vi=
rus -
  Servers<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Consid=
er
  deploying an anti-virus solution to critical file servers initially and t=
hen
  to e-mail, database, and web servers. If you are using Microsoft Exchange,
  consider using the additional anti-virus and content-filtering capabiliti=
es
  at the mailbox level.<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:4'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Applications<o:=
p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Applicatio=
ns<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Cluster=
ing<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>To ens=
ure
  high availability for critical databases and file shares, consider deploy=
ing
  clustering mechanisms.<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:5'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Infrastructure<=
o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Perimeter
  Defense<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Anti-vi=
rus -
  Desktops<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Consid=
er
  deploying an anti-virus solution to all employees' laptops and/or desktop=
s.
  Add the anti-virus client in the default workstation build environment.<b=
r>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:6'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Environmen=
t<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Managem=
ent
  Host - Servers<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Consid=
er
  deploying a separate management workstation to administer the servers on =
the
  network.<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:7'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Applications<o:=
p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Applicatio=
ns<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Applica=
tion
  &amp; Data Recovery<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Perfor=
m full
  backups regularly. Perform regular tests of the backup and recovery mecha=
nism
  that permits restoration of the application to a normal operating state.<=
br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:8'>
  <td width=3D"100%" colspan=3D2 valign=3Dtop style=3D'width:100.0%;border:=
solid black 1.0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>Medium Priority<o=
:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:9'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Patch &amp;
  Update Management<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Virus
  Signatures<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Regula=
rly
  monitor relevant vendor and security sites for warnings on recent attacks=
 and
  new virus outbreaks. Periodically audit remote users to ensure they are
  updating their systems.<br>
  <br>
  Continue based on the listed best practices.<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:10'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Security P=
olicy<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Protoco=
ls
  &amp; Services<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Audit =
the
  documentation for allowed protocols and services and check that it confor=
ms
  to the configured ACLs and firewall rules on the respective devices.<br>
  <br>
  Publish this information on the corporate intranet, and implement policies
  that govern making changes to the guidelines.<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:11'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Infrastructure<=
o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Perimeter
  Defense<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory:
  Intrusion-Detection System (IDS)<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'><br>
  <br>
  For additional information<span class=3DGramE>:</span><br>
  <br>
  This document provides a high-level overview of what types of events you
  should be logging and their importance in trying to detect an intruder. It
  also covers different monitoring techniques and detection methods.<br>
  <a
  href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/tech=
net/security/prodtech/win2000/secwin2k/09detect.asp"
  target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/security/prodtech/win2000/secwin2k/09detect.asp</a><o:p></o:p><=
/span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:12'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Patch &amp;
  Update Management<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Applica=
tion
  Data Flow<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'><br>
  <br>
  For additional information<span class=3DGramE>:</span><br>
  <br>
  This guide provides information to help you design and build secure
  Microsoft&reg; ASP.NET applications for Windows&reg; 2000 operating system
  and version 1.0 of the Microsoft .NET Framework. It describes how to use
  various features to enhance security in building application level
  authentication and authorization communication mechanisms within and acro=
ss
  the tiers of .NET applications.<br>
  <a
  href=3D"http://msdn.microsoft.com/library/default.asp?url=3D/library/en-u=
s/dnnetsec/html/secnetlpMSDN.asp"
  target=3D"_new">http://msdn.microsoft.com/library/default.asp?url=3D/libr=
ary/en-us/dnnetsec/html/secnetlpMSDN.asp</a><br>
  <br>
  This guide gives you a solid foundation for designing, building, and
  configuring secure Microsoft&reg; ASP.NET Web applications. Whether you a=
re
  maintaining applications or building new ones, you can apply the principl=
es
  here to help make sure your Web applications are hack-resistant.<br>
  <a
  href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/ThreatCount=
er.asp"
  target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/Thr=
eatCounter.asp</a><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:13'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Backup and
  Recovery<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Backup =
&amp;
  Restore<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Audit =
<span
  class=3DGramE>all the</span> backup and restore documents to ensure all t=
he
  critical systems necessary for business continuity are covered. Test back=
up
  and recovery process on a regular basis to ensure that all hardware and
  software components are functioning as expected.<br>
  <br>
  For additional information:<br>
  <br>
  This resource provides guidance on the importance of backup and recovery
  services in Microsoft&reg; Windows&reg; operating systems.<br>
  <a
  href=3D"http://www.microsoft.com/technet/security/topics/disasterrecovery=
/secmod200.mspx"
  target=3D"_new">http://www.microsoft.com/technet/security/topics/disaster=
recovery/secmod200.mspx</a><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:14'>
  <td width=3D"100%" colspan=3D2 valign=3Dtop style=3D'width:100.0%;border:=
solid black 1.0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>Low Priority<o:p>=
</o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:15'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Infrastructure<=
o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Perimeter
  Defense<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Firewall
  Rules and Filters<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'><br>
  <br>
  For additional information<span class=3DGramE>:</span><br>
  <br>
  This article, written for network administrators and IT professionals, pr=
esents
  an overview of the top network-level threats and the ways in which you can
  counter them. The authors review security issues and the configuration
  settings to be applied to routers, firewalls and switches.<br>
  <a href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh15=
.asp"
  target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/THC=
MCh15.asp</a><br>
  <br>
  This FAQ is appropriate for users who are not IT professionals and who ha=
ve
  questions about using and deploying a firewall.<br>
  <a href=3D"http://www.microsoft.com/security/protect/firewall.asp" target=
=3D"_new">http://www.microsoft.com/security/protect/firewall.asp</a><o:p></=
o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:16'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Security P=
olicy<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Governa=
nce<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Contin=
ue
  developing and implementing policies for governance of the computing
  environment, in accordance with applicable standards (ISO17799, CoBIT, HI=
PAA,
  SOX, etc.)<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:17'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Environmen=
t<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Managem=
ent
  Host<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'><br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:18'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Backup and
  Recovery<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Backup<=
o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Audit =
the
  backup mechanisms and ensure that all critical assets are being backed up
  regularly. Periodically test the restore functionality to verify
  recoverability from the backup media.<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:19;mso-yfti-lastrow:yes'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>AoA: Operations<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Category: Environmen=
t<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Subcategory: Managem=
ent
  Host - Network Devices<o:p></o:p></span></p>
  </td>
  <td width=3D"66%" valign=3Dtop style=3D'width:66.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bott=
om:12.0pt;
  margin-left:0in'><span style=3D'font-size:9.0pt;font-family:Arial'>Test a=
ll
  management systems that utilize SNMP to ensure that they are patched to t=
he
  latest version and do not use default community settings.<br>
  <br style=3D'mso-special-character:line-break'>
  <![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-b=
reak'>
  <![endif]><o:p></o:p></span></p>
  </td>
 </tr>
</table>

<span style=3D'font-size:10.0pt;font-family:Arial;mso-fareast-font-family:"=
Times New Roman";
mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA'=
><br
clear=3Dall style=3D'page-break-before:always'>
<br clear=3Dall style=3D'mso-special-character:line-break;page-break-before=
:always'>
</span>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<h1><a name=3DAppendices></a>Appendices</h1>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h2><a name=3DQA></a>Questions and Answers</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The following answers=
 were
provided for input into this assessment.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;mso-border-alt:solid =
black .5pt;
   background:#0148B2;padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Assessment Quest=
ion<o:p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#0148B2;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Your Answer<o:p>=
</o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>Business Risk Pro=
file<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Number of desktops and laptop=
s in
  use at your company:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>More than 500<o:p></o:p></spa=
n></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Number of servers in use at y=
our
  company:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>More than 25 servers<o:p></o:=
p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:4;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company maintain a
  full-time connection to the Internet?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:5;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do customers and vendors acce=
ss
  your network or internal systems via the Internet?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:6;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company host applic=
ation
  services, such as a portal or a Web site, for external customers or partn=
ers?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:7;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization deploy
  services that are used by both external and internal clients in the same
  network segment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:8;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do external partners or custo=
mers
  connect directly to your company's internal, back-end systems for the
  purposes of data access, record updates, or other information manipulatio=
n?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:9;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Has your organization deploye=
d the
  same back-end infrastructure components, such as databases, to support bo=
th
  external applications and internal corporate services?<o:p></o:p></span><=
/p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:10;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization allow
  employees or contractors to connect remotely to the internal corporate
  network?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:11;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization allow
  employees to deploy non-production systems, such as personal Web servers =
or
  computers housing &quot;pet projects,&quot; on the general corporate netw=
ork?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:12;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Aside from backup tapes/media=
, does
  your organization allow confidential or proprietary data off-site for
  processing?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:13;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Would a systems security comp=
romise
  in your environment significantly impact your company's ability to conduct
  business?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:14;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company share office
  space with other organizations?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:15;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company develop
  applications?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:16;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization allow
  software developers to connect remotely to corporate development resource=
s or
  remotely develop application code?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:17;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company develop and
  market software products for customers, partners, or a broad market?<o:p>=
</o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:18;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization allow
  developers to run development or test systems in remote or unprotected
  locations?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:19;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your IT staff act as the
  custodian (as opposed to developer) of line of business applications?<o:p=
></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:20;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do your business processes re=
quire
  data that is stored, processed, or distributed by a third party?<o:p></o:=
p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:21;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company store or pr=
ocess
  customer data in an environment that is shared with corporate resources?<=
o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:22;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do you rely on third-party so=
ftware
  development partners to support business-service offerings?<o:p></o:p></s=
pan></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:23;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company generate re=
venue
  based on service offerings that require data processing or data mining?<o=
:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:24;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization consid=
er the
  data processed by your company's application services sensitive or critic=
al
  to your customers' business operations?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:25;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company make its cr=
itical
  business applications available through Internet-based connections?<o:p><=
/o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:26;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Who are the target users of t=
he key
  applications within your environment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Internal employees<o:p></o:p>=
</span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:27;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>How is access to key applicat=
ions
  made available to users?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>From within the internal netw=
ork
  only<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:28;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your corporate network c=
onnect
  to customer, partner, or third-party networks via network links, whether
  public or private?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:29;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company generate re=
venue
  from services based on the storage or electronic distribution of data, su=
ch
  as media files or documentation?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:30;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Has your organization gone th=
rough
  a &quot;rip and replace&quot; change of any major technology component in=
 the
  last 6 months?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:31;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company rely on rec=
eiving
  data feeds or processed data from partners, vendors, or other third parti=
es?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:32;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Would an incident that affect=
ed
  customer applications or infrastructure, such as a site outage or a hardw=
are
  or application failure, impact revenue?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:33;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company store sensi=
tive
  or critical customer data?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:34;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do customer infrastructure
  components or applications rely on access to resources within your
  environment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:35;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company share infra=
structure
  and application components among multiple customers?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:36;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do you consider information
  technology to be a requirement for your company?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:37;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do all of the employees in yo=
ur
  company use computers for business?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:38;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company outsource
  maintenance or ownership of any portion of its infrastructure?<o:p></o:p>=
</span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:39;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company have a mid-=
 or
  long-term plan for the selection and deployment of new technology compone=
nts?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:40;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do you consider your organiza=
tion
  to be an early adopter of new technology?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:41;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization select=
 and
  deploy new technologies based on existing partnerships and licensing
  agreements?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:42;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization limit
  technology choices to technologies known by the current IT staff?<o:p></o=
:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:43;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company expand its
  network through acquisition of new companies and their existing environme=
nts?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:44;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization allow
  employees to download sensitive customer or corporate data to their
  workstations?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:45;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization restri=
ct
  access to information by users based on their role?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:46;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization deploy=
 new
  services or applications before assessing them for possible security issu=
es?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:47;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization change
  credentials for privileged accounts on a regular basis?<o:p></o:p></span>=
</p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:48;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization change
  credentials for privileged accounts after termination of personnel with
  privileged access?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:49;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Choose the option that best
  describes your company's industry segment:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>IT Services<o:p></o:p></span>=
</p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:50;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Choose the size of your organ=
ization:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>More than 500 employees<o:p><=
/o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:51;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company have more t=
han
  one location?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:52;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is your company in a highly
  competitive or research-focused industry in which intellectual property t=
heft
  or espionage is a significant concern?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:53;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Are the technologists in your
  company subject to high turnover or attrition?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:54;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company have signif=
icant
  product or brand recognition?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:55;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company use down ve=
rsion
  or legacy software (software that is no longer supported by the vendor)?<=
o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:56;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization acquire
  software from a reputable vendor or source?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:57;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>Infrastructure<o:=
p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:58;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization use
  firewalls or other network-level access controls at network borders to
  protect corporate resources?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:59;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization deploy=
 these
  controls at each office location?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:60;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization use a
  neutral zone (commonly referred to as a demilitarized zone or DMZ) that
  separates internal and external networks to host services?<o:p></o:p></sp=
an></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:61;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization use
  host-based firewall software to help protect servers?<o:p></o:p></span></=
p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:62;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Are anti-virus solutions
  implemented in the environment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:63;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Please select the systems tha=
t have
  anti-virus solutions deployed:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Perimeter hosts (gateways, pr=
oxies,
  relays, etc.)<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:64;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Please select the systems tha=
t have
  anti-virus solutions deployed:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>E-mail servers<o:p></o:p></sp=
an></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:65;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is remote access to the compa=
ny's
  network available?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:66;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is multi-factor authentication
  (tokens, smart cards, etc.) required for remote users?<o:p></o:p></span><=
/p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:67;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is virtual private network (V=
PN)
  technology being used to provide secure connectivity to corporate resourc=
es
  for these remote users?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:68;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is the VPN capable of limiting
  connectivity to a quarantine network until the client has passed all
  necessary security checks? <o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:69;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization host
  Internet-facing services on the company's network? <o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:70;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the network have more th=
an one
  segment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:71;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is network segmentation used =
to
  separate external customer and extranet services from corporate resources=
?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>No<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:72;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization group =
hosts
  into network segments based on similar roles or services provided? <o:p><=
/o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:73;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization group =
hosts
  into network segments based on providing only the services necessary for =
the
  users that connect? <o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:74;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization use
  intrusion-detection hardware or software to help identify attacks?<o:p></=
o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:75;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the type(s) of
  intrusion-detection systems (IDSes) used:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Network-based IDS (NIDS)<o:p>=
</o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:76;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is wireless connectivity to t=
he
  network available?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:77;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following securi=
ty
  controls are used to regulate connections to the wireless network? <o:p><=
/o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Changing the default/preset n=
etwork
  name (also known as Service Set Identifier, or SSID) on the access point<=
o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:78;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Indicate the authentication o=
ption
  used for administrative access to manage devices and hosts:<o:p></o:p></s=
pan></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Simple password<o:p></o:p></s=
pan></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:79;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Indicate the authentication o=
ption
  used for internal network and host access by internal users:<o:p></o:p></=
span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Multifactor authentication<o:=
p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:80;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Indicate the authentication o=
ption
  used for remote access by users:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Multifactor authentication<o:=
p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:81;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do controls exist to enforce
  password policies on various types of accounts?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:82;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is account lockout enabled to=
 block
  access to accounts after a set number of failed login attempts?<o:p></o:p=
></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:83;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the accounts for which
  controls exist to enforce password policies:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Administrator<o:p></o:p></spa=
n></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:84;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the accounts for which=
 controls
  exist to enforce password policies:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>User<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:85;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the accounts for which
  controls exist to enforce password policies:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p></o:p></spa=
n></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:86;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following are bu=
ilt
  based on either an image or a formal documented configuration?<o:p></o:p>=
</span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Servers<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:87;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does this configuration inclu=
de
  &quot;host hardening&quot; procedures?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:88;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following soluti=
ons
  have been installed on employee workstations and laptops?<o:p></o:p></spa=
n></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Personal firewall software<o:=
p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:89;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following soluti=
ons
  have been installed on employee workstations and laptops?<o:p></o:p></spa=
n></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Spyware detection and removal
  software<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:90;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company configure i=
ts
  systems itself or is this done by the hardware supplier/reseller?<o:p></o=
:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Configured by internal staff<=
o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:91;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Have physical security contro=
ls
  been deployed to secure the company's assets?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:92;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following securi=
ty
  controls are used?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Networking equipment is also =
in a
  lockable cabinet/rack<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:93;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>Applications<o:p>=
</o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:94;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>What mechanisms are in place =
to
  ensure high availability of applications? Select all the mechanisms that =
are
  deployed from the list below:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Load balancing<o:p></o:p></sp=
an></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:95;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your company have line of
  business (LOB) applications?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:96;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Have third-party vendors deve=
loped
  any of the key applications deployed in your environment?<o:p></o:p></spa=
n></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:97;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the third-party vendor p=
rovide
  regular software upgrades, security patches, and documentation on security
  mechanisms? (is it still supported)<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:98;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do you use custom macros for =
Office
  applications (such as Word, Excel, or Access)?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:99;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Has an in-house team develope=
d any
  of the key applications deployed in your environment?<o:p></o:p></span></=
p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:100;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the in-house development=
 team
  provide regular software upgrades, security patches, and documentation on
  security mechanisms?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:101;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization know of
  security vulnerabilities that currently exist in any of the applications
  being used in the environment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:102;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization have
  procedures in place to address these security vulnerabilities?<o:p></o:p>=
</span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:103;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the most common
  authentication method used for key applications from the list below:<o:p>=
</o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Multifactor authentication<o:=
p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:104;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do controls exist to enforce
  password policies in key applications?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:105;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the password controls =
that
  are enforced across key applications: <o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Complex Passwords<o:p></o:p><=
/span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:106;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do key applications in your
  environment have mechanisms enabled to restrict access to sensitive data =
and
  functionality?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:107;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do key applications in your
  environment record messages in log files for analysis and auditing purpos=
es? <o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:108;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the type of events tha=
t are
  logged:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Failed Authentication Attempt=
s<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:109;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is input data validated by the
  deployed applications? <o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:110;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the application inputs=
 from
  the list below for which validation is done:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>End Users<o:p></o:p></span></=
p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:111;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do key applications encrypt
  sensitive and business critical data that they process?<o:p></o:p></span>=
</p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:112;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the different stages w=
here
  encryption is used:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Transmission and Storage<o:p>=
</o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:113;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following encryp=
tion
  algorithms are used?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Data Encryption Standard (DES=
)<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:114;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>Operations<o:p></=
o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:115;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is the firewall tested regula=
rly to
  ensure it performs as expected?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:116;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Are separate login accounts u=
sed
  for normal activity vs. administrative/management activity?<o:p></o:p></s=
pan></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:117;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization grant u=
sers
  administrative access to their workstations and/or laptops?<o:p></o:p></s=
pan></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:118;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization use ded=
icated
  management hosts for secure administration of systems and devices within =
the
  environment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:119;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the systems for which
  dedicated management hosts exist:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Network devices<o:p></o:p></s=
pan></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:120;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the company manage the
  environment itself, or outsource?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>The company manages the envir=
onment<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:121;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does a documented process exi=
st for
  host builds? If yes, which types? (For what host types does a documented
  build process exist?)<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Infrastructure devices<o:p></=
o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:122;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do documented guidelines exis=
t that
  govern which protocols and services are allowed on the corporate network?
  Select the option that applies.<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Guidelines exist and they are
  documented<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:123;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does a corporate acceptable u=
se
  policy exist?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:124;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do policies exist for individ=
ual
  user account management?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:125;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select which of the following
  policies are being applied towards individual user account management:<o:=
p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Individual user accounts (acc=
ounts
  are not shared)<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:126;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does a model exist for assign=
ing
  criticality levels to each component of the computing environment?<o:p></=
o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:127;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do policies exist to govern t=
he
  computing environment?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:128;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does an information security =
policy
  exist to govern the security-related activity of the organization?<o:p></=
o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:129;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Please select who developed t=
he
  policy:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>IT alone<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:130;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do accurate logical diagrams =
and
  supporting configuration documentation exist for the network infrastructu=
re
  and hosts?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:131;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do accurate application archi=
tecture
  and data flow diagrams exist for key applications?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:132;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>For which types of applicatio=
ns do
  diagrams exist:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>External applications only<o:=
p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:133;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3DGramE><span style=3D'font-size:9.0pt;font-family:Arial'>Does</spa=
n></span><span
  style=3D'font-size:9.0pt;font-family:Arial'> an established patch and upd=
ate
  policy and process exist?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:134;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the components for whi=
ch
  these exist:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:135;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization test pa=
tches
  and updates before deploying them?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:136;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Indicate which of the followi=
ng are
  used to deploy and manage patches:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Windows Automatic Update<o:p>=
</o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:137;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>On which host types is automa=
ted
  patch management used?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Workstations and laptops<o:p>=
</o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:138;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does an established policy ex=
ist to
  govern the updating of signature-based detection products? <o:p></o:p></s=
pan></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></o:p></span><=
/p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:139;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does a change and configurati=
on
  management process exist?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:140;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization have
  configurations documented for reference?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:141;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization test ch=
anges
  to configurations before deploying to production systems?<o:p></o:p></spa=
n></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:142;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is configuration compliance c=
hecked
  and enforced centrally (e.g., through Active Directory Group Policy)?<o:p=
></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:143;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is logging enabled in the
  environment to record events on hosts and devices?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:144;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization take me=
asures
  to protect the information contained within logs?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Operating system and applicat=
ions
  are configured to not overwrite events<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:145;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization review =
log
  files regularly?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:146;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>How often are log files revie=
wed?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Daily<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:147;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is critical and sensitive data
  backed up on a regular basis?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:148;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do policies and procedures ex=
ist
  for storage and handling of backup media?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:149;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following polici=
es and
  procedures are followed:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Offsite storage<o:p></o:p></s=
pan></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:150;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do policies exist for regular
  testing of backup and restore procedures? Are these policies documented?<=
o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes, and they are documented<=
o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:151;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
  style=3D'font-size:9.0pt;font-family:Arial;color:white'>People<o:p></o:p>=
</span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:152;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does this individual or team =
have
  security subject matter expertise?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:153;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>At what stages of the technol=
ogy
  lifecycle is this security team or individual involved?<o:p></o:p></span>=
</p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Planning and Design<o:p></o:p=
></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:154;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Are roles and responsibilities
  defined for each individual involved in information security?<o:p></o:p><=
/span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:155;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization perform
  security assessments of the environment through independent third-parties=
?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:156;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does your organization perform
  security assessments of the environment internally?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:157;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>How often are these assessmen=
ts
  performed?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Annually<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:158;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the areas of analysis =
that
  are being covered by these assessments:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Infrastructure<o:p></o:p></sp=
an></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:159;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Do you have an individual or =
group
  in your company that is responsible for security?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:160;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is this individual or group
  involved in defining security requirements for new and existing technolog=
ies?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:161;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does the organization perform
  background checks as a component of the hiring process?<o:p></o:p></span>=
</p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:162;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Please select the option that=
 is
  most appropriate:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Background checks are perform=
ed for
  all positions<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:163;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does a formal employee exit p=
rocess
  exist?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:164;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Select the options for which a
  formal employee exit policy exists:<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Hostile exits<o:p></o:p></spa=
n></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:165;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does a formal policy exist to
  govern third-party relationships?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:166;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Does a security awareness pro=
gram
  exist at your company?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Yes<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:167;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>What <span class=3DGramE>perc=
entage
  of employees have</span> participated in the security awareness program?<=
o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Less than 25%<o:p></o:p></spa=
n></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:168;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Which of the following topics=
 does
  the awareness training cover?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Privacy<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:169;page-break-inside:avoid'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>How frequently is training of=
fered?<o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Bi-annually or less<o:p></o:p=
></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:170;mso-yfti-lastrow:yes;page-break-inside:avoi=
d'>
  <td valign=3Dtop style=3D'border:solid black 1.0pt;border-top:none;mso-bo=
rder-top-alt:
  solid black .5pt;mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3=
.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Is subject-matter-related tra=
ining
  offered to employees based on their roles in the organization?<o:p></o:p>=
</span></p>
  </td>
  <td valign=3Dtop style=3D'border-top:none;border-left:none;border-bottom:=
solid black 1.0pt;
  border-right:solid black 1.0pt;mso-border-top-alt:solid black .5pt;
  mso-border-left-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>I don't know<o:p></o:p></span=
></p>
  </td>
 </tr>
</table>

<h2><a name=3DGlossary></a>Glossary</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The glossary addresses
standard security industry terms and concepts included in this report.
Additional terms outside of this report may also be included.<o:p></o:p></s=
pan></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1=
.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Term=
<o:p></o:p></span></b></p>
   </td>
   <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border:solid black 1=
.0pt;
   border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:sol=
id black .5pt;
   background:#0148B2;padding:3.25pt 0in 0in 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Defi=
nition<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A software program t=
hat
  provides functionality to an end user. Requires an operating system to ru=
n.
  Examples include word processor, spreadsheet, and database programs.<o:p>=
</o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus (AV)<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Software and hardware
  technologies that protect the computing environment from malicious softwa=
re.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Business Risk Pro=
file
  (BRP)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A measurement of the=
 risk
  to which an organization is exposed, based on the business environment and
  industry in which it competes. <o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:4;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Defense-in-Depth =
Index
  (DiDI)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A measurement of the
  security defenses used across people, process, and technology to help mit=
igate
  the risks identified for a business.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:5;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Demilitarized Zone
  (DMZ)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A portion of the net=
work
  that is separated from the internal network by a firewall and also connec=
ted
  to the Internet via another firewall.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:6;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A hardware or softwa=
re
  device that provides protection to hosts from unauthorized access over the
  network.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:7;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Multifactor
  authentication<o:p></o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Authentication that
  requires a combination of at least two of the following: something you kn=
ow;
  something you have; or something you are. For example, the debit card from
  your bank is two-factor authentication: It requires something you have (t=
he
  card itself) and something you know (the PIN number). Requiring someone to
  type in multiple passwords for authentication is only single-factor
  authentication, because it is merely 'something you know.' Generally, the
  more factors, the more secure the authentication. Thus, a system that
  requires an ID card (something you have), a PIN (something you know), and=
 a
  fingerprint scanner (something you are) is more secure than one that requ=
ires
  only a username/password (single factor) or ID card and PIN.<o:p></o:p></=
span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:8;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Operations<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The policies, proces=
ses,
  procedures, and practices related to the protection and maintenance of the
  organization.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:9;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>People<o:p></o:p>=
</span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The members of the
  organization and the policies, processes, procedures, and practices relat=
ed
  to protecting them and the organization.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:10;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Public Key
  Infrastructure (PKI)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>An integrated set of
  technologies that are required to provide Public Key encryption and digit=
al
  signatures. Uses a combination of public- and private-key encryption to
  provide key management, data integrity, and data confidentiality.<o:p></o=
:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:11;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Process<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>A documented series =
of
  sequential tasks used to perform a business function.<o:p></o:p></span></=
p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:12;mso-yfti-lastrow:yes;page-break-inside:avoid=
'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Security Maturity=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security maturity is
  inclusive of controls (both physical and technical), the technical acumen=
 of
  IT resources, policy, process, and maintainable practices. Security matur=
ity
  can be measured only through the organization's ability to effectively use
  the tools available to create a maintainable security level across many
  disciplines. A baseline of security maturity should be established and us=
ed
  to define areas of focus for the organization's security programs. Not all
  organizations should strive to reach the optimized level, but all should
  assess where they are and determine where they should be, in light of the
  business risk they face. For example, a company with a low-risk environme=
nt
  may never need to advance beyond the upper range of the Baseline level or=
 the
  lower range of the Standardized level. A company with a high-risk environ=
ment
  will likely push well into the Optimized level. Your Business Risk Profile
  scores help you gauge your risk.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h2><a name=3DInterpreting></a>Interpreting the Graphs</h2>

<h3>BRP vs. DiDI</h3>

<ul type=3Dsquare>
 <li class=3DMsoNormal style=3D'mso-list:l4 level1 lfo6;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>BRP ranges from 0 to 100,=
 where
     a higher score implies a greater amount of potential business risk for
     that specific AoA. It is important to note that a score of zero is not
     possible here; conducting business in and of itself implies some level=
 of
     risk. It is also important to understand that there are some aspects of
     running a business that have no direct mitigation strategy. <o:p></o:p=
></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l4 level1 lfo6;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>DiDI also ranges from 0 t=
o 100.
     A high score indicates an environment where a greater number of measur=
es
     have been taken to deploy defense-in-depth strategies in a particular =
AoA.
     The DiDI score does not reflect overall security efficacy or even
     resources spent on <span class=3DGramE>security,</span> rather it is a
     reflection of the overall strategy used to defend the environment. <o:=
p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l4 level1 lfo6;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Intuitively, it may seem =
like a
     low BRP score and a high DiDI score are a good outcome, but this is not
     always the case. The scope of this self-assessment does not allow for =
all
     factors to be taken into consideration. Significant disparity between =
BRP
     and DiDI scores in a particular AoA suggests that further examination =
of
     this AoA is recommended. When analyzing your results it is important to
     consider the individual scores, both BRP and DiDI, in relation to one
     another. A stable environment will likely be represented by relatively
     equal scores across all areas. Disparities between DiDI scores are a
     strong indicator that overall security strategy is focused on a single
     mitigation technique. If the security strategy does not balance people,
     process, and technology aspects, the environment will likely be more v=
ulnerable
     to attack. <o:p></o:p></span></li>
</ul>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<h3>Security Maturity</h3>

<ul type=3Dsquare>
 <li class=3DMsoNormal style=3D'mso-list:l5 level1 lfo7;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Security maturity for eac=
h Area
     of Analysis (AoA) ranges from 0 to 100, where a higher score implies a
     greater level of security maturity within the organization. The concep=
t of
     security maturity is holistic though and the rating blends the scores =
from
     all areas to determine overall placement (Baseline, Standardized, and
     Optimized). This overall score ranges from 0 to 400. It is important to
     note that a score of zero or a score of 100 in any area is unlikely; m=
ost
     organizations utilize some levels of protection and are likely to be at
     least at baseline level. Few organizations have such a significant lev=
el
     of risk as to require them to invest heavily in security strategies and
     programs. <o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l5 level1 lfo7;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Security maturity is incl=
usive of
     controls (both physical and technical), technical acumen of IT resourc=
es,
     policy, process, and maintainable practices. Security maturity can onl=
y be
     measured through the organizations ability to effectively use the tools
     available to create a maintainable security level across many discipli=
nes.
     A baseline of security maturity should be established and used to defi=
ne
     areas of focus for the organization's security programs. Not all
     organizations should strive to reach the optimized level, but all shou=
ld assess
     where they are and determine where they should be compared to business
     risk. <o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l5 level1 lfo7;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>The stacked graph shows t=
he
     cumulative maturity score based on four areas: Infrastructure,
     Applications, Operations, and People. The sum of the scores from these
     areas determines whether the ranking is Baseline, Standardized, or
     Optimized. To achieve the highest score, an organization needs to have=
 a
     balanced approach to their security programs, which encompasses a
     multilayered and proactive response to security. By comparing the rela=
tive
     size of the four analyzed areas, you can determine if your company's
     security controls are more mature in one area than another, and plan f=
or
     mitigation appropriately. <o:p></o:p></span></li>
</ul>

</div>

</body>

</html>

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image001.jpg
Content-Transfer-Encoding: base64
Content-Type: image/jpeg

/9j/4AAQSkZJRgABAgAAZABkAAD/7AARRHVja3kAAQAEAAAAPAAA/+4ADkFkb2JlAGTAAAAAAf/b
AIQABgQEBAUEBgUFBgkGBQYJCwgGBggLDAoKCwoKDBAMDAwMDAwQDA4PEA8ODBMTFBQTExwbGxsc
Hx8fHx8fHx8fHwEHBwcNDA0YEBAYGhURFRofHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8f
Hx8fHx8fHx8fHx8fHx8fHx8f/8AAEQgAtgB9AwERAAIRAQMRAf/EAKMAAAEFAQEBAAAAAAAAAAAA
AAABAgQFBgMHCAEAAgMBAQEAAAAAAAAAAAAAAAECAwQFBgcQAAEDAgQDBgQEAwcFAAAAAAEAAgMR
BCExEgVBEwZRYXGBIgeRoTIU0UJSI7FysvDB4WKSMxaCokOjFREAAgIBAwMCAwUHBQEAAAAAAAER
AgMhEgQxQQVRE3EiMmGRocFygbHRQiM0BuFiMxQkFf/aAAwDAQACEQMRAD8A8YAXpkjlSLROAFon
ApCicBItEQKQokAhoBUmgGZSbSGcBeW7vpdXwxVD5FPUlsYffWweGOeGk5VSXLo31DYzsx8b8WuD
qdmKvrer6Mi0x1FOBSFEoCQoiAkKIgJFpgnApDQltDcNATRIWiYhUCBAHKe5iiwdUuOTWipVObkU
x9XqSpRvoV8rtwfLRnMZqxZXAHuXIycuzcpmmuNEU3IjneJHmV/0tAyrxJVLy2esk9iLPbJLV2tt
wQ01yp50NclTZskkjpcOllk/biDowKuk0GhGQaygr80SNIkSQQQxtfLC6MnJzPwGSdMlq9GK1Ux7
G8xnMYPRkMa/Ndbi82flt1MuXC1qhq6ZQCAFARANi0TgjIUQEnOiiWCpiFonApOdxKIYnSEVoMB3
qvLk2VbHVSylhuWm5ElyS7GukV+PcF5vJZ2cs31rCOe77o6X9uIFkHGlQPHNQSJlbbmryAQKAnHM
071MRPY6J0Rd9ThnHlgogWuzXcEBAmcXtfWjuw9+LVGyJIvp52OtwIzqYaBzsDTsoKlVokx1qx7m
BzAHt4u9IJ7yAiRQcb225UlQKNdkOw9i9DwOT7ldr+pHPz49rnsR6LoQUSFEQKRUACBDAoosYtEx
SLRSIyV+7vpEIwaF5xpnTsXM8jkhJepp49ZckWzs3TyENAD6Vc9xoGMH9s1xWzaQt1ijLC6INFux
2gSitHkZ6K5gJoGQNDWnUyhxpQ5ghSESLdj3YQmjjxNRkkBMgttEgZJcMY8ZA1cMe9tUmMtLG4s7
d5ZcuILCC141FpB7NQA8lFoaZoWwQxQRyxMbIDgdIoA0jvPyKgMqLq5ljpzKvja4hkgxpji13HwK
0cfLsurFWSkqDqvVHKBIYIAEAMCgixjlIixQmRZUXrjLuQYBXlgYcO1cDyF5yP7DocdRUa1w5joX
apPzXDm4NJ/K3FYS8k7jtcj4WSui9DMImjIHwpkP4qKY4M/JC8XDGECpGPn4qyRQObDLzdLTR5OH
AEoEdrGWaOcyGNj3Cpc2Q5gZpMZ3vZ+ZcRzRcxsZ9VC/UWnI01ApIINLYQ7he2sTSI9FK10lpLRw
7KqDGJujLZlg5v54i0iU0LqHgQO9FRsjWMwmtWPB1ZivbQ0XqOHfdiTOVmrFmdloIAmIEAc6qqS6
BQVIjA4FNEWinvHgTz8unMcWs8zgvPc1zlZ0MK+VEjabR09yyCL9VNZ7sXu+GSxWehfVSzZw7PHu
FxyGAujjAaRU4/FUO0GmuPcyxufbWB9oJnMBfTCla07iqvfhmv8A6aaMpuHSEIa1sLqSNdQ1z76q
+uUx5MEMgHpO4a5tAHGoBNaHxU/cKdhIs+ngWGGU1IcQCBiO+hCja/clSk6F/a7b9rZP5rg5jBUR
4ljmjs7O8ITkLVgy9YBezDlcuKRrsCaijsvEDgrCk57SC2yDcBpc8YdxovR+P/4l8Tn8j6yYtpQC
YgQBxCoRoY4FSFAoKkRgqXv0X8rnN9Mbg8/ivO8xf1LG/D9KLPp1wgcbhzsCSD20kcBVYchoxnqn
SdtE+4llZpcAak5jyWTKzpcap6NZW1uYhG5ocHZCnBZjaVe8+3FlfuMls7kyuPZgpVs0RaT6nn3U
ft51faTNNrbmbGjZG+oHFX0zJdTNl4it9LMxuTuqrCRsb7IxzxkBznRkh4y9Q/vV1clWZb8bJVnP
foOrJbdxktJIISzXqYCWVpjRydL1FkwXXVGBE9xbvLXvNW5Z1B81oMbNDt2n7KJzaesajTKpzXpO
FWMaObnc2ZJWopBMAQBHCzmkcFIixwUkRZG3OxnNq2+FGwNfynmtC4kVoBxpxXH8nau5LvBr49Lb
XbsV0dy/mttoBV0rdDWgVxrh81y7Gmi1PdOjLZ9rtcIk9LiBq7gM6rn5Op2cShHoW2GGXS5tH+Br
gqGi9WLuHSAc8B9IKaQM6MJL6k0CaBheO2yOAvuzA0U+qXTXDxU9pXu1KR269P38UtnBJDKCC10Q
pjUcAlEA1J8t+4WyTbZ1Pf2UQq6M62ChOpjvVGR/BdDDaanJ5FIsWu7bDLsV03bpa62wxSEOFHAy
xh5BHbUr0vjsm/CmcrmY9mRohLaZQTAEARws6NI4KSIscFIiyXc2xuNhe+o02rZnHVkDVhr44rz3
klGdP1R2eJ83Ha9Gdvazpxt39xul0NXLIZbtp/1E/NYczgs41ZlnpNzbWIAduFxJFatA0xR4ai7I
UGZWZv0N1UcttsRd7ubLa33trPVrWGSWOOpcSAGgZ5Y9iaq36Gd5VPc1thu17t13Ft95cPmuS8tf
zQBI3uJBxHestzpY1pqay/eWWmvWQC0n05jBQbGjy3cbQR38crIH3Uc7XvDp5ZX+oAkAhmWoinct
OJz3MnJTq+kmz2mZsszLKba4rORjA4zwgOblWmr6q+Khdw+pNVttk8v93dqth1t0/ePkEMdy5lvc
yUBAa2UGpBwOBWjBb5WZORSbVKb3E3A7h1tvFx+UXDomfyxUjb8mr1vj6bcFV9n7zg8205bfEzq2
mUEACQEcFZ0aRwU0RY4FNEWXWy2Ld126/wBp5nLmnDXxHtpg4fMLjeXo/luu2h1vGXTVqPuaXouz
O3baLdx9esh5y9QwNB2YLh3tJ08ePaoN0zZIb+NlC1ssVHNJyr3hZHdpmlV7k6wsH2c3O0sbNiOY
0Y0y7K/NHuMs21esFXubJH7zbzPpRrwGnSASa4k0QnI41NyZ9TQKkNLS0eCiR2lcdnhhJfDK8l2J
bhSvxCJgtlsl21tLC18jxQ8EtX1KrpGa3fpjZN2umbvvL3fa7HqumxtoGuc31guJ4DTktGGX8q6s
y5EvqfY8K3C6N5f3N2RpNxK+XT2a3F1PmveYqbaqvojyWW+6zfqyOrCAIATiokiOCs6LxwKkhDqq
RGCTt16bO+guRJyxG9pc/Oja+rDwVPJqrY7LroW4LOt00buw3azu7+4jt7hs3LcHtLSCNByIpwwX
jqzGp6ir+03ewT6mYuzWfIaMaNLSKOAyvqQ0VoFWWGKivXbnftnceVE2Z8bIzgRoNKnxV1VCFbqb
lltptWO5jdTQNIrUmqi1oK1zldX/ANtIznxh0TqDmt4OPAqDJ0UrQkm7hdbktPpIzQ2QtU8l9yet
XRwT9PWlWmSgvn40c0kPA8cB5Lv+H4Tdllt9PY4PkuSknRde55hVenk4UCoAExCJDI4Kyo0QOqpI
UCgqQoDAimYOFEPoCRP6RsYto3aOZtQbg8qYcKOxb51XleRZNuOh6nj8N46J2+ruet7X9yyQco4O
/KuZkZtpoXe776dqsgb4mNrxQvIJA7zTJQpVvoSbXX0MyYdh3B0cwujGXmsc4a5oONMDTFXJtaEk
t3Q19ncWUcLWS3ouchpYC/LIUAJSgi6s6XW62cl4NndDM64laH8rQ5ulhycf0pOriSNbTMPoPhtZ
YBKyWQuijcA17hQ6aajXwVPcLWlHz/1Heuv98vr2h0TTPLCQfpBo35Be84aVMVaz0R5Dl1s8lm0+
voV1Vqky7QqmKBVIiCQyGCsiNQ4FSTFA9tSQAKk5AYlNtJSwVW3C1ZP2+wkfcAyDS1nqp38FyOb5
Gux1p1fc9F4nw13lVsihV1j9xZTW72xuMf1g62H/ADDELh1semzcZ7WkbjpPfo5DbyE4toXN8cx8
VTlrBzFWVJvd+Zb7nC6MsD2uYCWkChqFTV6yKnymb2S8u9o5Nm21ZLYwO/bidgQNWo6XGqvbkd+J
W2tXtNd/yi8fbSR2G3xW8r3F/Me4ODXOFNQa0CpTSZR/1dfmsc9ksJWz3G4XRD727dWSU50/DDBV
2sXXhLbXoU3uD1A2zsTaQOpc3ALcDiGnBx+GChRSzXwON7l5f01PK9IV6PQuiYmhvYE9z9SPs19E
IYYzm0HyUlksujZC3FxvrWv3IYbO2OcTfgFdXl5V0tb7zNfxPGt1x1+4i/8Ax4OeHY8umLK8fwW7
/wCvk9uP5/X7P4nGf+LYPf3a+3H0/b/DqZgFdtHiDva20tzII4hU8TwA71DNnrirNjTxOHkz320X
+ho7LbIbZv6pOLzmvOcrm3yv0Xoe+8d4bHx1629TtDEA+R/Fx+QwCyNm/Bih2fqzo5qRbeglmJop
/wBh2l5q5nYTm5vnmpNytTicrC8dty6M2fT3VpllFtcemRtNIdh5Km2ODK0nqjZw8l0jZWN1sfmB
wKgpEloXVvCBC6jBhwyqrUtCqz1OVzM5rTFG4NeRn+lvEqpiZ4zv9793u9zKHFzA8sjLs9LcP8VZ
RQj1XEx7MaRXqZpEQAJgCQAgDM2WyXM1HS/tR9/1HyXoc/kaU0r8z/A+d8HwGbK5v8lfx+4v7a1h
t4wyJtBx7T4rh5s1sjmzPbcPhY8FdtEd6Ko2wAFKhMKqAKiwsgjIbIx/6HB1R3IM2bDvo0bCXp6K
djZmt0vwNRgVTvaPOzBc7MNytm6CRKzLS8kEU70SRtdGkt5L5zSaNiac/UXfKiclTyI67PbMu99t
LaR1Ypp2NkJzcAdRHnRSxLddIqy3ijfc8Z3oU3i/AAAFzNQDL/cKsPY8WfarPoiIg0AgQJjBACoA
YAkVKoqCaQIJCE0I78EyLcNC8EiQJIij1rpJse69JQ3zKc6xf9nfNzOArDIf5m+k94UMtNNy/aeX
51Pbzuva2q/NEuK1ayQ40ae3FUJmWx3+lpa01JywTkhBa9J7c6XqTbrj/wANpI+SQj9ZicGj4OJ+
C08VTaTPy7RSO54bv8Tot93GN2bLqYHykKZ7fiOcVX/tRBCDQBQABAAc0ACAECBJC0QMEwGvFW+G
I8kEbqUOSJCJCPQ/ZXdoYOppdnuiPtN6hdbkONBzW+qPzOIHirccTD6M4nnsDthV11o5PQb7pvcL
aZ8UcTp2tPpe2lS3hWpzWXJxr1eilHn8fKpZauGPtOmbuVp54+21CheSHOA7gCQpU4tn10I35dV0
1LXZNz26Lqa36bsIi77a1lu7iatQMQxor+Z7nPqSt2Pantr2MeVWa327nz71k0N6s3doy+7l/qKz
W6s9741/+en6SmOaRtBAAgYHNIixEDFCYAgYJiBAxAkRQpQNnW0uZbW6huoTSWCRssZ7HMIcPmEE
b0VqtPufU93eO3DZrXdrN+gXMMdzgAfS9ocR5VWzI3slHzb2lTK6W7OCjlknLmiSR8jDiS4gD4Ci
5t8tn3OhTDVdjh7exNuOsuoL8DCJkVkx3CgHMcB5kLVw1o2Uc9wqr9p4j1uKdYbyOy7l/qKhbq/i
e08Z/b0/SUuaRvEQIRIAQIEDFTGgTAEACAGt/N3FIhXv8RyCYIEe++yW/t3LpSXaJ3ap9reWtBxJ
gmq5v+l2oLVgtpB4n/IONszb10v+9FpfwfbzOgd9IOFezOq5+am20FfHyb6ydvaSDVs91dkeq7up
pK9o1lg+TVu4iihj8g/6seiPBuvGhvWu9t7LyYf95VFur+J7jxn9vT9KKJI3iVQIEAIkIEAKmSQI
AEACAGMqHPrxdUeFAhlNNG59fyHoLQQM2vtBv42jrW1ZK/Ra7gDaT1NBWT/bJ8JAFZitFjkea43u
8dx1rr/H8D3DrC25dpLdtA/aY/X4BpIKlzMc1n0PHcHJF9vqd/b+1Fl0xaMpTTExzh3u9R+ZV+Gs
URTyb7sln9p83dbvL+sd6eczezn/ANhWO3Vn0Dxq/wDPT9KKRI3CIEASAOKBdxOKCM6ig4IJVegp
TGCQwQAJiGvNKAfU7AJJELuNF1YoFBRBNIfHI+ORskZLXsIcxwzBBqCgLJNQz6k6e3W36r6PtbyQ
B/3kBiu2jhK0aJB8cVvo1auvc+bc3A8GZ1X8r0/IvdngbHZRwjLTo8xgpxBkmdT5X62iMXWG8xnA
tvJq/wCsrn26s+j+Mc8en6UUiRuBAgSGJxQQ7jNbeZTjWnyqiCnet/4fmNtH8y2ifxc0E/BO2jDi
33Y6v7DqkaBUDBAAmAxravLz4N7ggrrXV2+4ekWAgD2P2A6iAO5dPzOweBeWgOOLaNlA8RpPktPH
trB5X/JONpXKvg/yPXYJnRXBjGT/ANxvlQOH8FrZ5JHzF7jlruvd+Lcjey/1Lm3+p/E+j+K/tqfA
ziR0ASARAAkROAB5x8QfkVPsYFPuftGbZX7KOuQrpPa2uBRk6kvHT7KklcVA2LqKmTBACGtDRAn0
AIBdBUDBAGl9uJN5j602yTaIjPdtkq6KrQHRUPNDi4tbTRXMqeOdyg5/lVR8eyu4Ufj2PpoyzPvL
cCDlTsfg5rmujewj16cdQw/UF0EfOWfK3Vlf+UbtXP7uatf5yudf6mfRvFf21PgVKR0ASARIQx5c
G+kVKaKcraWiGY6u9SM0vcf/2c==

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image002.jpg
Content-Transfer-Encoding: base64
Content-Type: image/jpeg

/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAYEBQYFBAYGBQYHBwYIChAKCgkJChQODwwQFxQYGBcU
FhYaHSUfGhsjHBYWICwgIyYnKSopGR8tMC0oMCUoKSj/2wBDAQcHBwoIChMKChMoGhYaKCgoKCgo
KCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCj/wAARCAB4AKADASIA
AhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQA
AAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3
ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWm
p6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEA
AwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSEx
BhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElK
U1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3
uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD1S0+D
3guBXWTTJrjc2QZbuUkD04ata2+Gvg62Efl+HNNZo+jSRbz/AOPZrr6UDFeRLF15O7mwjSh2MKPw
l4djYNHoOkKynIK2UYx+laX9l6eOlhaD6Qr/AIVdpAM1k6k3u2y1FdERxxJGgWNVVRjAAx2x/SpC
cUEYqK5kMce5V3NkBVzjJNQ2Owy5uYrYoJWO587VAyzfQVEs105+W0Ea/wDTaUA/+OhqQothbtKy
yXN05C5AAZ27D0Aq2HAhEkv7sYy24j5ePWknpcadyEXEiDM8O1P78b7x+PSrBGa5nX/Heg6DMseo
XZUnPKLu5BIx+lR6N478N6tA6WGpw+cyt5UUwMTNx0G4DNNDOktCJEM3XzfmB9u1T0KgVQqjAAwB
7U4DNAm7FPUolmjijfO1n2nHurCmLp8YiZZZJpndgxkZ8NkdPu49aeS813GDGypFkncOrEY4/Amp
p5o4ELzOqIOrMcVavF3Em1sAVVZ2VQGc7mIHU4A/pSlM96qXOp29vA0ziURL1d18sfm+BVIeI7Uk
kRy7cZyCrfyJ/nRa4jZIxSVlWHiGxv4ne1ZnEeN4XDFM/wB7aSB+NXvOkZQ0cPykZy7gD9M0WAnq
rfs0VpKynBC8e2eP60sv2xlAiNvC3curSD8vlqCayurlWS5vz5bDBWKFVz+LbqNgNFacBmgDNOqC
xMV554j+JMui6tdWb6DM8cLKFkaUxmQM5QEApg5YcEEgjvnivRQM1514k+Gh1vXrm9udXdbefHye
UWlTD7wquW27Q3ONn681pS5L+/sJlU/FK5R4Fbw1cyPNbm5jS3mMrMo8jkAJ0IuEI9gc46VvReNN
KutCgv7mezilUO8tot0kjKQjjZuHGTwMepxXMTfCJ7mO1kutXilvLNdlsWtHaFEKxKQVaUsTiFAD
uGBng5refwT4a03wzNDqtpYyy7ZGlv3t0ExZmZtwYgkEE8ZJ6DrW0/Y6WFGLbOePju4s7pLRdCgs
Z5MXETJOpXylIjYgbF3HJJUHGST04zmah45uJdLuL19InYTWjtZS/b0dZUW3SVmAwACDIp5A6cZz
Xl/jTV3udRkSK/huookMMTJC4OzzVk7yHBBXjHHJ46Vj313q90Jr2/FtEZ4VjMMcW1QBGiblXdhc
7Mkc9fatoqnFXRSUuhpeIba7tL+R7h5iouBbyyTIVJfJyyA/fXCk8HI4yORVOJXna/a32eVagt5p
Gwth8DavPO1ZHxnohqrDe3l/Le3NwLYyXd2JipiYhRubcq/NkAhwDzn5F54rTj+2WRVoTYq1zKGk
hkt1k4YMAm5izABHkGVIPzZJOAKL0hWmdv8ADTx1qVhqdrBruqTNYmKOUNIzSja6K2zkE/xdRjoa
9T1X4jW6XCx6BaJq6CHzpHScx+WCzLyNh4Gw5PuMZ5x5jovgC/v9LjD3NplLUW6bIXzuEYRXOZCO
MA4GKxNZtNY8I3MykorPEI5ZWjkVWAZiMBXXjD4IJOcDpWCjTlPTVA0+p6ZL8WZJrO2ng0Z4YLhY
2SWSfJPmKhjAAQgE+Yuc9MEgNg4XT/iLHNpWqXn2EJe2IhEh87zAPNLAbnK542MSFzgZ6Vg+BvCe
k+I9Atja38cf2Ft0yC2PnKqJEIRu38lfKJyRzvYYGTnbh+G+p6ZHo8zamb82s0XnWYjk2SBX3L87
yMygF5ASdw2sRgd7tR6E6rc617m9tNGg1S50JReeWjTJqF4pkiZsDarIjrgFiONo46c1zY+Kr+eI
4tAMmPkdYrxCUkAhyOVC7czD5t3IGe9bl7Zaxc6zeWl/r1q0U1skcNrFYFUSYkurE+YSQBA/GRnf
7c8vdfDI6bDFNFqmmQ6dZQNEkFxpZnGD5YJP7wA5MYwuDjIHOBSgqavziZr/APCSXmp3ti0nhUi7
bybiJ0voZC0DEt5isvBGIyeoJ49a74weXukt/lkP3gOjfh61zOg6DqVuNGvrma3N1a6dHby25i8t
TIqvjBUkKBvIwFPSrsy+IJILFLWewtEkCoxaFp3jGwktuLKOSAMbe/espcr+EZvRuJI1dfusOKSV
ljQvIyIi9WZsAVkR6MXZlvdR1C4YHJKzGAc9eItv65qymhaVFgrp1oX/ALzxBj+ZqEBp024ZooXd
MFlUkKe+BmpE71DfjNpN/uN/KoKK9ta3ZUm6vWMpwWEMaqgPtkE/mfyp0WlW8ZJ33TZ6h7qVh+RY
ir1FAFCLTNPtIyIbK1ijxkhIVAHfsPrXg3xE8Rr4gv7iKxzHYwAxoq/LvPr+NfQF/C1xY3EKNteS
NkVvQkYH86+SNeiv9B1S5tr6Nra53HAkGM+hB71pCF3c1gzPezjVGwQrK2ffrUV0wmtyAv7pQArH
lj6nNYuoarKCBI4Cj+ItUNlqck0hYOWjU4XPr61v7NoammdFaWarsZk2Ig+VT2HqavaDKmo6rGlw
xKkNt9zx/hWMuoeZa+dzjIGSepo0edrPWPNkPEaBc+pIFZVY6FXPqfwcANPBAxnH8qvao2m3r/2f
dtbtNKCoiYZPT0rK8HSn+zLNcYZolZh6HGf61Bqd7b6XqUJsoY5HmkxM+35mJPUt2xn8a4k7Xkby
VzkvDGht4Z+IGs6fZxyCzmsZHjUNkAMucdRnlTXsn2pLq2VoXljEihklVN2AQCD0IrDbT2urs3UU
0cTTRCCchMu0YJOVPY4JH457VdfThHOsTyXZsScJHFIyrHwBtO0hiP09a2jJSOOUWnZkFvLZpqMU
KXaBIHaSd5JRulmZcAZ74ViSO3y8VflXTDdJc3L2vnryjNIOD0yATgH3q/b28dvCkUCJHGowqIu1
R9AOlQ3F00PyxW808h6KoAH4sSBWl7mbt0GzXMMkZEU0bs3yfKwOM/8A6jRLdqGVEVnmYEom0rux
16jpzUMMF453zvHE7feKDccdgM8Ljn1zVq3t44AdgOW6sxyzfUnrSi7bisMt1ZEO7aXY7mbPU1Jg
9zmnF0V1QsodvuqSMnHXFMnhMqhfNkj5zlMA/wAqsErKxYAxUd1/qSPUgfmQKlpk/wDq8+hB/Wsi
h9FFFMArz747aQup/DLWnjjjNzbQ+ermNWYKrBnAJHHyg9K7e+1KxsDGL68trYy5EYmlVN+OuMnn
qK5L4k+KP7L8LXb6PcW8t87CBdsikx7uN2PatKbtIaVz4jWzurwlo42kC9WxwK1Y9NFppjTyzMSx
BKocACulvbpYQIsBWBycVhNL9rSSFTlVfI9663J9C1CxIWEEUAYE7fm2joDWjpELzt5jfMTh2Pua
zpbZ7S8EeoRvAcKxDLk7WAII9etbunavaWNvPCkRuYTMh87OzcoIJGDzzisK0W46GsOW/vH09oNm
p063KZXMYBx9BVgaNGEkVQTv5JznmqPh++F7pNndxRyRJNEsgSQYYZ9a2Y5mzg85rx4zd7HdOLWw
9pEtlRGPAXP5VNpFxPqVpKywy2Q34VpEUsy+oGTj8fyqC/urW1tXuL54o4Y+S8hAA98mp9B1JblJ
mKJFbhFmjfzAwZCXGeOn3DXXTRyV37pet7KaJSH1K7mJ7usQ/wDQUFQT6JbTtuln1HPfZfzxj8kc
D9K0YJUngjljJKSKGUkEHBGRweRUWoTi1sbi5baRDG0hDHAwBnr26VscZmr4asV6T6v+OrXR/wDa
lWG0yUGPyNUvoQvUAxvuHHBLox7VP9uQ2M9yikrF5vB4yUYg/qtUtT1Jk0tL6zntY4A43zTAunl5
IyNpHU45z0OcHpRcWxa1CNChn2L58Q3o2OQAQSM9sgYq1TJpQluXKEjaCR7UyycyWUDN1KAn8qd7
iLVMm/1T/Q1XFyEupY3fPcDHQAc/zqWKXzrUSY27lJxnNTuUVNdaVbNPs8ZkkMijYJjEWHXG4Akd
PxrNfSbu5x/aMVtOByEL70H4SKx7diKvXGqWMs5givIHlhb96sbhzEQRndjO3g96r6dc2rhki8St
eOuAx8y3JB99iACkIR9MuHkSQW21l7Jqc0Sn6qqgH8RUOuae2p6RdWl9DJsuF27zKHVDkbSAMd/a
tCe9s7Zd1xrKRL/ekkiUfqKoRavpV5cCO08Q2l9I5QC2juIXP31+YBRu/XFWUmfHni7T59L1ie0u
V/fQyFJPYg1iWjSQTb4skq3pxxzX0J8Rfg3q2tXMtxpd3atI7M5E7MrSHJI524z25rwvWdE1Dw9q
8ljq0Btb2HrG3OQehBHBHuK6k4yVkaKTTuj1jwT458J6pHbWviTRrVL5I/KErW6Spj/gQJA9ua7x
bXwxqLRmysbWRIlCj/Rwgj5zgAAelfMZ3mdZbeM71OcoOK91+GFwdS0jcqkOpw4PqK87EUlDZnfR
q87uz0+2nQjaCTV5WHOeK5dUmjYjd+lWknlRcHJ+lcajY2lKLLevaeuptGZQskUfPlOgdGPqVPWs
nQvC12yu+ma1cWc1mFiihlj+0xFBu+9G2DyCR8rDv1rRh1BoyomKpv6bmC/zqW2v7WHWoLe4gVWc
hladDsb0KOMjI9/Wu+hd6Hn4mcLWT1PEvBXj/wAT3fjuCKG/uVtbm6xLahGljjiB5Cp8xGFHavpX
W5Fm0VwoO25McIBBBxIyryDz/FVG9gW31Nr37NYR3ESkfbbiNTIkZ6/MOccDqQOKWLWYZ132a3Wo
Z+4YI90f/fQwh/77rqcXJ3SOO6My9s7lL2xs5xNPawW5knY24MUjZIPUHBO/OAf4T7U9NPvL3R/s
11aB5Ek86Jt4DJuO/CtjjGdu4HPXgVsQz6pJzHZ2Uf8Asm7J2/gsR/nQ6amsSvLfWsaLzIy2smNo
64LSYH1IP0qvZNauwK99DFfw3fXupR3F7fgRROypGNw2xjgbWGCCdoJxjOfatrT7SWxlmEe2S3Ll
iTM7v34xg9BioFubK5A3XV/K694zOufqqBRTHa2LiRbC9eYco11FKwB9tzHH4VcsOuo+Vrc07a2k
VlLEY2hSe5IUjNQyw2txvnkSN7VFLb5DlBx/CDx+NWBavMxN5IHXtEgwg+v978a574q3Jt/BN6qN
ta4eO3H/AAJwD+mawoUfbVI011ZdOHtJqPcv3GsafObIafeWM0lxGJLdBcKBKN6dMZ4+gq0usL9u
aze0mW5Ch/L82EsR6hQ+7H4V4veadqmhaVbwS+Qq3226jIGZV8uAEHOMrtZQeP79Eus3kaxXf7g3
DXL3wuTETLvDOoTcDwpSIj6NjtXq/wBkXfuyuj0P7Ob1jK6PXJ/FmnxZxskOM7VurcH/AMekFWba
/XV9Lhu4YXijeSJo2Z433rvU5BRmGOPWvJNLt5tU0Cx03UIbGytZYoXhufsZzMTGJCDNuxkgenau
m+HeqTn4cSXqzKZrKN5zCwBySnmgZGMff96wnl7jHmi762Mq2EVOHMnrfb/gnoQ1Cye+Nmt5bm8U
BjAJBvA9dvWvE/2oPCLXmk2XiO2Vmntn+zzqOf3bchvwI/8AHq2jdyWmmw2JtoWuLEGVb5WPmNeQ
xrNNknqHyw9sHrkY3W8ZDU9OuVvNGJ0x3WJ5nl+UBmKDA2/NgqScdhWscBOnJWI+rTesNvkfIWnW
N95h/czGNV3FwuBXsPwidNJtLuW6mWNTIAzu2B0B6mnWPgSfTfEx09rl5bm3mWM5lJQkQiQnJ9Rn
irEEg+wWsNvaBFkPmK3mdcxM/Tb/AHTnr6VjWwEqllsr66HqYbBKTvD9P8z11oo5RvTj0NMs5rO5
88QTQzPDw6o4JU89fyP5VzMPiNIIECwxvBGuGPngSFVYIzKmOQCfWo/BxknudS8pS80qbhtHUGWZ
sn8DXJTy2XJOdTS23mY1aD5HKRjQX73XinUluZF8sXKxRiX7h4Hy88A5J54610+rXdxoNxZGfYf3
u61UkszJwHj3dCeeh68Vztpp/wBo+yXVl+8a8jhF4rHiX7USUG31UbT+JrSPjS6m063t73TYru1h
jEV2z7gXkEaHeGHCH5umDnP59ry9rbU4pZfUraUdfmjqb3UbS3uILxLCJ7B4Vmt7qWWRoo8jOFRU
bYfyzx6VDbeKYdRvI7S31FTPKSFWKyKliASfnmYjop6gVy13qD6dpGo+RGgs54niCx3vmCB2UsVH
UnjqG74IxzVHSsw+H9QbzUS7juoWtwQQzMilmI9RtkPH+NddLCKSvPQ3pZdN0XKbs7pK1meh6TOm
t2kv9lXbXTRgCRpr+4ABOcfKFXPQ9Kfc6bb6YIp76SytIA4zLHHI0gY8AK7MdvJ9K82svGV94ato
rGyj0a3ZrC2ke71O+kit7dEW1hUN5cZPzPcrydqqMknFaM+k+NvHFnputWkfheTTprYSWxXU7wB9
xVg5D2+4cAjGAeaxnhZKpyc9l6HDKlGNTknJpf12R6eYbSZTG095ICcEfaJufyNVr6ay0mUJa2lw
ZnGS6W0kuB25/OuX1CHxRomlXmpalp2lJaWUElzNIfFN+wRFUszYFsWOACcDJ9KyfBfiTU9Zvbq3
RdDljihSeK50+4nuYZg008JwzqnR7Z+QCGBBBIrjlQcVebdjmUF1Z7FXC/GRN/hGNsZCXcZP4hh/
Wu66VzvxBsX1LwdqUESl5UVZ0UDJJRg+Px24oy+ap4mEn3Oqg7VI37nlni3WJdQNvbpBLGbSKSxy
EBVo9kbvnqQV2xsDxwDmsn7LNdIpgEyQwRzK7snycPKgXP1kQ16j4a8PWeueGdMu7yS7hlntY47q
OKUos+wbfnHfpj6V0EnhbTn1Brw/aArSpO9ssmIXkUAK5X1wB+Qr3KeNp0lyU1a1z0I46nSXIlse
MxC3NskmkWl5Z2b20cjrLIZAFaWBoircY4aUY56Gjwhpuo3vhe/GnwXskLW8MYMM5WNX8v8Aeb13
Dd8hTsehr1TxBoOnaPo95fL9pe3tUluIrLzP3KuQx+VcccsTjtmm/CS0js/B8KRkHe5Y8Y4ACKfx
CitnWh9XcYrqivryjTdVRvqt/vOPv3muLCa/gt5H06XzdRjuyQUdbi2Ecag+u6Qj8PeuavJ5JGsl
jLGFbPYFXjIYhsfm/wClexv4Zs4Z0zLcNYwuZ47HcBCpzkkDHQHnHT0rN/4VvosMkTrNqG4Dy1Jm
BAHGARjplV/KiliqUJc0kZ0sZSjBxZxerW8sni7VbqKZkmaeXeSpG1Y7SJuQDx98isd7YtoVndPv
ZYEECDbzsSxH5DLfrXrEHhewn1i9vX8/ddxmR0EnyZlTY/HY4QVRPgbT3tbe2iuLwW8cjHJm+Y5Q
Jg+owpXH0qPrdLl5GvwFRxcKct7f1sedCC2drgNBM12baW58xSFjjA4+7jnOQCfU1p+HNebQrVoL
exN0brTYJXIlCMgJHOCDk/6QnHHSu0h8C2c5a3u571EgLGJIpQE2OSW7Z5Ocg56U/T/h5o0EsMqS
Xwa2IRAbjIKqUKqR3A8tOPaspVaTjyLa501sdQqp87v5anHeHbK6g0axuVh32Pk2dw9xuwqG1iKs
h753xgfj7VzM2nyto+r7mQFrSa544yysiHPuArfnXseuaLploZLiSW7EdxMHNikx8qeUkfwe5xnH
HeszW/Da2djrE2jvMNTMLzCPO9X3EsyqjAjDHP44ohXp8+q1f9anNSxkUuVOzdv6/E838S6Vc6VB
qAvmKrNM6Ku9WJCrJhzg8ZEg6+lR2ZWCGyuLqTfYrebpEGQQhjt45Mn/AHWNb+ieFrfUrsW6XUl1
p+0mSYRPHt4VY4zuAweG5HTNd/p/g/QrRZYktHIubdonWWRiShwG4zgdFzitJYiFNLm19DuxGY06
dP2V7yv28rdTwT4jW5g8VamF/s0wi1REOpjFmQuracv77/plwN3+zmug+GPwnvNW+Hvh3UE+IfjW
xW5sYpRbWmoskUIKg7UXsB6U34vWkWnSRWEKaYqQRSbTqhJtSranpLjzyf8AlmN2G/2c074Y/GSz
0f4e+HdOfwd41u2tbGKEz2mlrJFIVUDcjbxke+K4pSU3dHg4ir7ao5+n4KxY+IHwkvNN8B+JL5/i
L44vFtdNuZjbXOpM8UwWJjsde6nGCPQ1L8CLCC8vL15105jFZDaNLP8AofOqar/qf+mXHy/7OKi+
IHxns9U8B+JNPTwZ44tmu9NuYBNc6WqRRl4mXc7eYcKM5JxwKvfs/f6/Uv8AkG/8eS/8gv8A49P+
Qpqv+o/6Zf3f9nFc+J/hsxSuz0b/AITnwl/0NOgf+DKH/wCKpf8AhOfCXbxVoH/gxh/+KoorkVKJ
VxR468JdvFOgf+DGH/4qpF8d+ESAP+Ep0HPtqMP/AMVRRXTQVmSyNvHPhNp4/wDiqdA2jc3/ACEY
c56f3vc1Tm8a+Fo7mS8i8U6B8rbZF/tKH5kAH+1wRnNFFdL2JkXG8d+E2UsvijQCyHOP7Sh6f99e
lNTxt4RaB4T4r0HA4BGpQk47H71FFKK0CI+38d+E2jVpfFHh8S4w2NRhPI6/xVSXxl4VgF3t8U+H
gGm3jOpQ8EgHn5vUfrRRRIIu7Kr/ABP8MNdgw63pJEeUmjfUIUYZIwRlsHHPGe9aVn8Q/Bkwdo/F
WiDJyQ99EpHHu3tRRUJu5q0iuvjPwnNqcs0ninw9tjcIgOoQk8Lk4+b1b9KsXXjbwm2TF4r8PLIB
kFtRh4P/AH107UUUJWZDVxbXx74TMeyfxLoMcg+8h1KE4z77uaQ+OPCjoVPirw+syncp/tGE4J/4
F9RRRTRKPPPG7+GvE3iO2uk8W+EPs72jJJa6iyXUMn763k+YJPH0a3i4JIYEgjHXQ0TXBoekWel6
X8Q/h3BY2kSwwRfZnbYijAGWviT+Joorl55J2TKjsLrHiJtW0u70y/8AiJ8Op7O9he2ni+zMu+N1
KsMi+BHBPTmm+ApvDHha8v5m8YeDDFcQxQRW2nSJawwKs1xM2FaeTq9y/AICgAAYooqHKU04yY7H
/9n=

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image003.jpg
Content-Transfer-Encoding: base64
Content-Type: image/jpeg

/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAYEBQYFBAYGBQYHBwYIChAKCgkJChQODwwQFxQYGBcU
FhYaHSUfGhsjHBYWICwgIyYnKSopGR8tMC0oMCUoKSj/2wBDAQcHBwoIChMKChMoGhYaKCgoKCgo
KCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCj/wAARCAB4AKADASIA
AhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQA
AAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3
ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWm
p6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEA
AwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSEx
BhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElK
U1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3
uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD0K50+
3mBDRjn0rA1Pw7HyUC/hWsNWhdOgGfSqtxqqbgGY8V8ym1sdBxGpaW0LZxWKyYYjNdxqF5BNGea5
K/CGbgVqncLFPFGKcqjuM0uKoQzFGKcVz3oKehP480ARkZqBhVg7h/tVXZgMbgR9aaAzLsZbPpWx
+zyoPxyGQzf6NN904P3BWNqM0cUmyV0Rj0DMBmtX4BOF+OEeWkUG2m5QZI/dZ9DXbQ+IxrfCfYMa
kTXZ+zmPdj95uzv/AA7Y/rXnviZf+JxL9F/9BFegIu29utgu2dlH+sbMfGPu+nWuG8Toy6zKHABw
vTn+EVpXWhhD4jBxVCcYnk+tahGKzbhf378965DYpyD5cetSWiEwjFNlGMVZtV/cHn1/lSjpJmlM
DHjqw/OkMXqQPxH+NVwM1o6ZDZSxzC8fY4KmM7yvc56dew/Gso123ZI0bsrnniXcozg1I9w74z2r
ODY7UBsdqkRZldjjmq7Co5b+zjk8uW6gjkHVHkUN+Wc1IZFHU8ewyfyFACBc96RvlaQENhFDE47c
/wCFS2C/vfm3BVZjgqRnc2e/T0/GtS0hijVdyAkRqmWxzjPv70DsZn2dqhMRHU10DbC8nyIqsMAk
4YcVmzWSxBWRQQARhm/wWkmIyiQfunI5H5HH9K898SeJrqXUlstHl2lOGYYKn2/Ct34hj+y/Dkxt
GdfMZIcs5YqvJIBJPpXB+EmiRJpJAMgj5iCRz9K7KMEouowS5nYtnwvfzs1z9pV52OTlTya9A+Aq
XOlfFXS31GZLWeWOVEuJACozGR0JGecDr3rJ0i+t3Tc8wEhYg7o2KKuD8xbkk+238a39Cin1TW9K
j0yS2i1JbyKS3WV252sDk8Y24BzyKcK83LllsXWpU+RtM+wYLgPrE8P28u6x5NsYwAnCcg456+p+
92rj/Fw/4ntx9F/9BFdXpGpjUbuR4Lize2KZEat+/VuAQ69sHP6Vy/i9f+J3L/uqf0rpr/BfzOCG
pgYrMuv+PhvoK1iM1m3S/wCkN9B/KuI1KMoxirNoMQ49Qf5VBKM4qxaDMI/KhdfQ0plQDNSJ3pAM
1KorgNkrnmpiB/ib86MVNt96UDFbkESjFJUxGaZQAyRykbOOopYb4y/Lh489c8Eeo/lUVwMBfd1H
/jwps8Qdg4aRHCldyEdDjIOfoOnpTBGgkoZcxsCp7jmq818VzhSSCABzyT9KzpNMhMYRAw4CEA4X
bkk/KOO5qV7DdKzpPLGCDgLggE5z1B9f060WAxPiNax3GiIzhTiZQccnkH06f/WryqyZrS7JV8Lt
5UjIOe1ereMFdPD1zFmQmfHzDk5yuP0B/OvJLlpyqySEu23DZHINd2G1jYTZ0UurItmREAHY42gZ
zXY/C3xIbXxVpMd5BuzcIoZcAlWYKwx9DXldu00jL5A3MTjjnFd14O0yW98Q6KJZjJB9rUOVTDBA
wLn/AL5Bq3SjHcbqtxaPuzRbI2LRQG0T5I2zcqQNzHYT8nYE578be9cz4vGNbk/3F/lXSWHltrTu
kGo7jCP3spxEw2p0UnIP4DndXN+L/wDkMH/rmv8AWrr/AAHHDcxSM1m3X+vI9h/KtTFZ90MTH6D+
VcJqZs38NTWR/dH2OKZOMbafZnMZ+ppwfv2NKZoQu65wzDP904qZWPq//fVV0TOeR+JA/nUyY5+d
P++hWvu9EaHlIGaCMU6kzXEIaRmmkYqTFNoArTrwnP8AGv8AMVV3BbwRjMgPzEsemdx4H/Ae9aLL
0+tVJ7NJMBiNxjCEnjgHr+tMB/nKPN3HaI22knvwD/WqM1+2CIY/xYf0qmkMe+ZYSVh5KqDwD6ih
H3orEYyM49+f8DVqNhMytcnnvF2SMy9uR8uTwP1NcxqNsm54ruP9+FyrqcZ+tdmAbm7tedqvGZVB
H8QIGD+Bpt9psVwhBTGOoxyp+tbRlyitY83trNorkEMY1AyWHpXb/CW9ki8daXIAsscDO6xyjcrf
IxGR9B+tV5NDKmUCH7TasHYBGCyKMEkqxyCBg8flXY+CLG3ttU0+8sgQkywrnsyhQuD+FaOpzIUr
dD6s8OalNqBt5JLh8yw7mga3bg7UwfMAC+pxj+PtisfxiP8AibA/9Mx/M1F4d1uW21O0srq6byDG
FG+JE4AwBlVAPTtnt07yeMf+Qsv/AFyH8zWtZ3pnPB3aMUDFUbsZmNXgc1VvF/e9e1cZoZU4woNN
szg/U5qW5G38KiibrxUxepcDYtRZmKEOWWVxncO3zdSd2BwP7tW7SGyOWe5ZyFJ2/dx8pOeh78Vi
L3q7YNGJW8wL9w7cjPP0xXow1VzGSPLKQsB1NK4IwqnBbv6UxVC/dFeSdQ/IPQ5pCM0VUnfyZGkx
kHah9upz+tCGyw1Ub+U7DEhwx6n2qGe9KRq4BRNhZizdOQMfz/KqY1OyJDG5j/efdYnAb6U0hFlI
giYXgBcYrNJZYUccKSwP15P+NaiOshYKwO04OKz5WWKPy2PVmOfoDVJgU9OuEDQF2yknmR5HbD5H
8xW5GAGBHPc4/i964/T232cCdMyySg+y/L/MiukhuVSAs7ZAqpoEXbixV1DxKM/xL2an+AWEWpC3
dlVYb0OhZcgIxDAY+u78qj0W/OoGRlidYlON7AjJ9uKu6KGtvGEG6NfLuiiliON6MePxDN+VEHd2
FUg46M9eiYpdW7IzNHtPEQHljqeh5X/9dV9Y19YtVtoL922PHtjlPO3k4B/PrUUcaRSpsjKcfK6S
f+yn1rivF87LfQRSEncrBSfY5/rXS9VY5orW56ahzmoblf3n4CvMNI8Z3el6daxT7JNg8vaQBkD3
xxV3WviTBDa+dbWjFlUFwzZ5z0HT8z+VYuEuxozpvEWo2+lafPeXjbYox26k9gKoaFfDUdLgvvLM
SzLu+Y9B2rz2z1u58fzvNewQW1tAxENtuYtg92Jxk8ego1DRL1Z0KO8FmBsWRV3KrD3JA9KhxafK
zenFcurPXF71sG8tSyMsat+6G5REqjIOe3tmuU0J5v7EsXdlUvErYRiR9enfrV/z5O7Gt4YiytYx
nSd7I8+k6qfTP8qQnNG7d2qIgjocVxm1xpeOZpMckHa5BI5qB4k8zeA28/xF2J/nUZkYSExozgMQ
doGCMn1PNcnrnjR9L1KS2l0uQxqTsczAM49duOme+a3oYepiJctNXZEpKO5N4lvmtLqCGL78mMr6
cmnWd9HOfLlVVmIzhlzu9xXI674kee6t5J9O8qRY94HnbsqwDKfu+lOh1iNbZZXeJpFG4xiUZzjp
XbUwFenCLlHf5kqpFncLJa2yG5m8uKNBnd0H6Vz1/wCI4L+MiG0n2nIV3YLgn2wa4a/1W71C5Z5X
JjDZWLdwtLHqLZ3eVn0+b/61a/2VXSu4/kNVIdTtIvM061gQyr5rJJ8hXPlhmVhn8v1rZ06VINPd
5HkSd+jMMj2rhb3XJtSmMnkYeKIZ+fOQp69PetFdfljGngRFFn+8sjZVRnAOe/r0rmrZdiovllHX
5dr/AJHTSq0k20zvNPmu4Y/MZI7m3zyY/vADvitGeYwLZ6khDxwSJcKe+0H5v/Hdw/GuS0bWEurS
K4tklsbhwW8pfmjcAkcZGO3t1q7r/id7KT7NFpguZRbtczMswjVU3YyBg5rkpYas63sorVF15wcO
Y9jtdXWYbZDE+0nBjBU4/wB01nald6cbgvcwxTbQHTeuS2QTx6V4xZfEeO2gWL+zSIFDLEy3A3cD
5QVxkDkD/HFN1Txjd6jbXN1Igt1gCRlIrhZGdj0AcDA7547V6awWIpytONr+h5smnsegXx065upL
p9PmVYUG2NY8AZJyT2OQP1qM39sNJvbVbYQrsyAeCCGHOARiuafVdXs9BlkmitvLihIKg8+o556E
mubk8VQ3d1GsVo81wQpMlxdxxRZK/MrKyYwDkZ3c4rWlhp14t0ldf5EMPClrf3nieKDTLqOKQyNJ
znYVyMjj2r3KHSJfK8k3IbrtEEIjycgjPXPT+dcn4e1edNQ+zy6To2jxCyi1A3V3qRSAJJLFEDmO
KTH7yZRk4AAJJAr03QvDfivWtJs9U0uDw1PZXcSzwS/2ncLuU8g4a1BH4iuGtRquS5Vp6o6IS7lf
Rba70+0hiaIzNH0Eke8Adl5HIrUDTu2TaJwMf6quk1STxHo+k3mo6l4d8KR2dnC9xcS/2rKdqIpZ
mwtiScAHgZNR+A/EFp4mv76A6VowgggjuIrrTrxrqKYNNcQkAtDH0e2fkAggggkUvqs11InU62PE
ycVEXx2rn9b1280+9NvFoOpXWFDF44mK8+4BrEm8avDgXejanCx6Bouv54rnjRnJXSNrnbO+McVx
Wr+EE1HVZLq5v5zHIS3l7QWU+zHOB7YrW0rWY9VgE1vbXKpnHzqB/WrbxyHGI3/KtKFWrhpc0HZg
0pbnEz+EC/zT6lLJcqFVJDGNoQDAG3PPA65pLrwvEtoEtShYA7jKo3MTnndjjr+ldg8Mpx+7aqzx
SDGUaumWOrzVpS/Qj2cUebyeHbuFGaUbVznIwcfrRFpOFS4W4iKtuB3cY4wOK63xDa3s1tH9l3Kq
tmRVXJI9v8965j+w2nDiG5+cD7rHB/Wuj6/XqRtKen/D/wCYnTiiSz0WVoiyXCJ5yGMsy4z8wJPX
2xWgPCzXMKmbUVZljEaMI+AAfc88cVkwaO0MiG4iu5Exn5Uz16EVsWWnwhChtL+QjoOFA/CiWOxE
XzKevewuSPY0tE0S6sBJHbaxhGjZVCxD5GPRup/KtC98LzambV31KRZ1g+zzyCMfvUznGM8frVO2
s9OjX/TLN7dO7tIMD/x6tDRtQsYAklnqSG1kHCSSHKn6HmuR4qqqntU9fRF8qasymngG1a4SCa72
xR+ZIAkOHYEYA3Z/h+XqDnnpmut+H/wv0pL+KbWdQlurOzb7TNbLEqC5IBVMNvBXaWz3z04qmL6D
+0o7gzDCQSRsFOTklSM/l+tdJZ6pcRWolsLueEv1aGVkJHviq/tPEtWcromVKLWh0nif4b6RPfeI
mj1R4NPayEKWhhLC1lJX97vMg3Dg/KcDnrWHqPwI03UfEa3ei64NMguo1mispdLW4EfyjdkNJyCQ
xxt4zjtUcetau7jOraiMel1J/jWrBq+pqn/ISviT1JuX/wAa0pZpOinGm7JmToze7GfEDQ00eDR9
k+mzFNEgsnfVIBFaSPFqmnEyTgEgRN5nzDsoPJrX+GPwnvNW+Hvh3UE+IfjWxW5sYpRbWmoskUIK
g7UXsB6Vyvii/uL2Q/abiym2WS7f7YctaDOqaZ/rsn/VcfN/s5rqvhj8ZLPR/h74d05/B3jW7a1s
YoTPaaWskUhVQNyNvGR74rWjP2kFIpR5VYsfED4SXmm+A/El8/xF8cXi2um3MxtrnUmeKYLEx2Ov
dTjBHoaX4J3f2Nr+Qw2coNoi40ZQbUf8TTVf9Tkj91/d/wBnFJ8QPjPZ6p4D8SaengzxxbNd6bcw
Ca50tUijLxMu528w4UZyTjgVyng2V45GCnS8GybI01FazP8AxNNT/wBRkH91/d/2cUq81Cm5MHHm
VjhPFumaRpetSQ2Gr6bNbuokUwXquFz2zn2rE32Q6ahAPpdj/GiivLhDmV2zpQnn2y/8xNPwu1/x
pftMfbVU/wDAof40UVXs13GJ9tVfu6uv/gWP8aibUm7aun4zj/GiiqVNCIrrVmhgeQaiHKqTtWRT
mvPZbueS4edpG8xjuJBxzRRXZhopJmUyzHrWoxACO7mUDoM1J/wkGq/8/wBL+lFFdHJHsQU5Luab
LTSO7A5BLE4qzFrF/FAsMdwEjUYC7F/wooo5UA+zuSWke4mmwozsjcJuzx1q/PJM088MOsSrbpId
qtMfz6iiisZLUpCIb1c7dak/Cdh/7NUy3upLnbr0wz/0+P8A40UVne4Gv4f8S3+kXk8102la1FNC
IHttWkkmhKiaKYfKHXPzwpkEkEZBBBr0TRf2g/FehaRZ6Xpmn+EoLG0iWGCLZcPsRRgDJmJP4mii
qjNpWQDtW/aH8X6vpV7puoaf4SmsryF7eePZcLvjdSrDImBGQTyDmvP9V8bavc3kc2nnS9DiSHyF
ttJd4oQvnSzH5WZsfPPJgAgAEAAAUUUOTkrSK5Uf/9k=

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image004.jpg
Content-Transfer-Encoding: base64
Content-Type: image/jpeg

/9j/4AAQSkZJRgABAgAAZABkAAD/7AARRHVja3kAAQAEAAAAPAAA/+4ADkFkb2JlAGTAAAAAAf/b
AIQABgQEBAUEBgUFBgkGBQYJCwgGBggLDAoKCwoKDBAMDAwMDAwQDA4PEA8ODBMTFBQTExwbGxsc
Hx8fHx8fHx8fHwEHBwcNDA0YEBAYGhURFRofHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8fHx8f
Hx8fHx8fHx8fHx8fHx8fHx8f/8AAEQgAtgB/AwERAAIRAQMRAf/EAJ4AAAEEAwEAAAAAAAAAAAAA
AAABAwQFAgYHCAEAAgMBAQEAAAAAAAAAAAAAAAIBAwQFBgcQAAIBAwIEBAMFBgQGAwAAAAECAwAR
BCEFMUESBlFhIhNxkTKBoUIUB7HB0VJiI+FygpKiM1MkFghjcxURAAICAQMDAwMCBgMAAAAAAAAB
AgMRITEEQRIFUTITYZEioUKBscHRFBVx4VL/2gAMAwEAAhEDEQA/AOWBK9lg8VkyC1IuRempIyLa
gBaACggKACgBaACgBKACgAtQSIRUBkwKGjAyZgU1pcDZH7U5UFAC0AJQAtACUAFABQAXFQAXFSAt
ACUAFAC0AJagBLUE5MqCAoAKACgAoAwkljjF3YDwqq26NazJ4LK6pTeIrJEk3L19MSdR5Xrl2eXS
9sfudOvxT/cxqTMyA1mYBh9Q4KK59nkbZdTfDx9UehNxMzbYrGaRy3M6AXrJK+x9TVGmCJjbhgSK
VWRWA/CwBBHxsKI3TXVhKqL3RDeWBZrwuWhIuQw1Wu3wednSTOPzeFjWKHQQRcG4PA12EzkNBUkC
0AFABQAGgBKAFoASgCBl7iVJSLjzeuJy/J4fbX9/7HZ4vjdO6z7f3ISJJJJdmPU34jqT8K405tvL
eTrxgksItMbBgi1lcAEjqtqaqbHSHZdkyZdcYLElrmRrFj8L1HcP2voVOXiOr9CL1MBdnv1E/Kmi
xJIiy4uVCOtlZVFrk3/fTJoXBlFnzwyLJG2lrMp9QI8DepRBd4bxZI6oiI2v6ohqpPiK38XnyreH
7THyeDGxZWkh9kZGKsLMOIr0kZKSytjzsouLw9xKYUWgAoAKACgAoAbmY9PSPqI0rleU5LhHtW8v
5HU8Zx1OXc9o/wAyumx4oh1v6vK9hfxNedR32RWmkOoOngDYCjAFzswEjKZXQIv03AuT5czSSGiX
ufLlFBBAvthhfr6epj42T95pCzVmvZeD7V+lXjJNmkZQpJPIAammTFcSKu1ZJUyZDoIuV2+zlTdy
FUWyDl4EiSejpdR/KwNh86aMhZQJG35C47sjXsbEMuvColqTHQ2XcVjK4+RGQyTJqQeYrueH5GU4
PocbzFCTU11Ildw4gUAFABQAUAFADGpmZxy9K+HDU15XyFnfdL6afY9RwK+2pfXX7lfmIGa/WOkH
VuNYjXuRyxVCraoPp5UBgajyZI3BQlSOFqMBk3HY58oYQnmn69PoLqdPHjpVTRdFsJ5M/NIb2fai
jB9t7W489bH7aNCdWQMfZ8nKmAk6jGTopN2b+ApZWYLauO5Gx4/6dSTRxSBGBX1dN7dXj8Kzf5Rv
/wBejX9+7RyMDPEUpEfVdotSb316RetFd3cjDfxexmMkEmHhQRy39pZLI55dQ4aV0PHWqNybOb5K
lulpC1688iFABQQFBIlAC3sL0AQ8jIjGLx9PC3C99TXiptt59T2UEksFrsPbU+5QicRf2xpGvAfG
s07MG6ijuWWSs3sHuCdh0wpHEg0seo2/jSK6KLJcScn0Rrud2/LhTGLLIikGnruo/YatVudimXG7
XhiYnXG4WPILPwARj/hahsRV+h0DtXtTufeERMXFeSI/XkS+mMC/8zfV9lUytSNVdD/cdS2D9L4M
BQ2Q4lySPW6i4Hkt6yz7pG2E4x2NhfZoMePpVdP5ja9VOGB1bk5x+p/bhm2yXJiH93GPuKw428qe
iXbL/ki9d8Pqjkm67qhhmx5LEdKFSOPUD1Dh8K6dWkkzj3vKaMVNwD4i/wA690nk8G0LUgLQQJQS
JQAHhQBWLCctlUAhPcChR4k6mvFWPVnsq1nCO29vYUGPt0CxqLdIrBM7de2DYsQKHuQCLisk2aoo
nTbHtOcP+6xY5eVmUNxqtMlkrbOzO2cSQSx7ZjqwNwfbUgH7asTfVlbx0Nqx0ijWyqAOVuFPEolk
zeYICQt/IUzkCiRpm62txqtvIy0KPeMOObFyIJACkiMpB8KQsTPKXc+HJg78+OAegSkIeRs3D767
PG1w1ucPl6NroWIvbXQ869weIFoAKCBDQSFABQAuDEkUxI/HKrAfEG/7K8t5Wnssb6S1PT+Lt760
n+3Q63tIePAhBv8ASCPtrizPSwL/AG49ZAtq/wC6sk0aky9wVK9UbfUvPy5VXgG8l5ihWWwPLhTx
K5EqMW56UyEY8YlI8zTOIncRZIwtyTYg8aXtJyV+RH1RyAcSCB8qjA2TzH3dCMjdx16iHImZviLC
33V3/D1d9iz01OD5uzsi8ddCDevXnjwoICgAoAKCR/Ax0yM2CB2KJI6q7AXIUnUgfCqb7fjrlL0W
S/i0/LbGH/ppE7uLZBiSQ5O2TB8V7PC0mnVbgOVeTu50r0lNar0PYf62PHeYPR9Gb5HuyJiwBYnM
jKAkf0km3jwt51znqzqZwsleN57ifOVIJAjDQRxj0/7jcn5VE4x6kRlLJa/+Sd3YsZbJMsZvbqWC
OQW+OlVqEGM5TRcYndm6exHlRb/CIX9M6yYcavCxNgWvJ0lP6uXhTTrjFaaixlKT10RaHfdyiwGy
I+5cPLkt6caGKBnP2BmNVLOPaW4TeO4g5/enekWPEYryynWSOCBD0KeAd2uvV42FMpxF+J/X9C02
Dcs/cIJW7ibLgVbNEYTFYgeKqv7asi6nuVT+Re0yz+4IsTElzMWSSaGGRV9jJQCR1JAIDJbpOvGx
pJducIaKnjLOc9rdpbb3Pv27z7gZUgwpnaPEFg8glZiCbG4sRY1tp5k6I/h7n1Ml3DhfL89l02/7
NR7sw9qwu4MvF2oucOFgoEhBZXA9a3HHpa4r1/AtsnTGVnuZ43yNVdd0o1+1FTWwxBQQFACUEj+B
kDHzIpm+lT6vIEWJ+y9Z+VU7KpQW7Rq4N6qujN7RZs2/5mLibJtmAP7kgCO7DhYm4I+N68NGLUmn
uj6DyJJwTWqeMF1g7BFibozR5Us2PkYxaHHkIMcJDIP7fxvrUTszqVwq7Zbtjb4ee+4KFnOHCNB0
2BYjz5VXOaxrqXwg84zgt8bbciLEynzc2fI6wTjD32Htta11t1aacDVbvg1jBMONNSy5Nmnj8+y5
nvxpkQs6xTagAdfp4Hj1fCrljGhXZnOPU6rj9mdtSdsmXF2jDh3HGVZ4544kV+uIiQi4H4um1ZoW
SejZbZXGLykvsV+6R5u44vvSJLjLMxIx7kELydQtrqw4UrXZItrxOGHoJt/brQbb7eFueYs2nR/c
fS3Iq11I+NNZan0K66u3R5ZNzNvlx+2c2TJcS5HsOVktYkkaaeNLXrJBOXoarsOdD22e5N7MbGfK
gV45uoteZjZF8AvU3VXS41TusjX0z+hz+TNUVSt6/wBTmDO7szuSzsSzMeJJ1Jr3iWD5/JtvLEqR
QoAKACgAoJLSaSObG26brVni/syRcSvST0m3mK8h5Khwvk8aS1PaeP5UbONCOfyjo/6HQdtysaaL
BmlcRRkGN5OksFDC1zbWwZRe3KuVjXDOu84yi3wIcSeIt7say31UFXFhpyP31lsjI0VziG4DFghY
GZEPAWIX5VUos0KaxqzXI9uR5VIskQfr6DoWI/ER+yr+/oV9mXk6T2e0pxZQ1iLa+YIqpb6BatEE
QxMCQbVluv5YDrwJ5dF9sn/klzwePgPFbUz10K4ppZRYrHtyKT76eQV1I+41HxMV2FRvrpl4v5OA
M/u6O4BEaAEG5c2DH+lb38qdLt1ZU3nY5l3nvmLHsebtMJXryNwWyAepYMWPpW/xYivQ+Cpbsc+i
X6s4Xnr0qlDq3+iNAr1h5AKCBaAEoAKACgByDoLMrXuwFiDa1uNcXzMcwi/qdrw0sSkja9u3Mpgw
oxsOo2v4V5icdT19U/xNy2bcMDMj6JkSRha3UAfLnWOxNG2tKRC7w3qDacP/ALGGJMqTRCFUG3jo
KSqDm9diyyca456ldtXc/bb4+M0mQFn0Mivpdreqx4Ve6GmVR5cWtzqvbGdgyYqSQsLMPqHAiqI6
Me3LGt237YZGkwXnBlBJ9FmMbLr6v4USSaFhlPKHtn3aEQMswj6o7A2A1HiPKojJrcJxTehSdy9w
tHlDHLXvYrbUi99Tw+FNHUTCRxDf8kz7lI5NyzuwPkTyr13gk1n+B4/z0k2v4kCvQnnQoICgANAB
QAUANtNFHPCHNixsR/SdDXK8rJfHjqdXxUH8mehaQSGEdDN1W08R0jhqa8vJHqa5YLHb9ybFvkdd
igJ0F+ojgKpnDOhrptcdSn3Tepch5DIjTuVN5OIW4uunK3CrIQSRnsulNkGHbRMATjOyMAwZr2uP
qt48RTOSK41tvY3fZZdzxsMY22Gb24h60jLG32AG1ZZ4b1OpWnGOFsJlLu+1xiWfFfHklkPQjKep
gfqIHHp11NNhMqUnnTVl12rvj5ggjd7SoxWQLz8qz3V41LqbMr6lTuu6TzTZs1+pELRxEDWw1uPl
V9cNEVW2as0kye4evXXWx89a9n4qrtqz6nhfKW91uPQK6ZzQoAWggKAEoJEkkSNC7myiknNRWXsN
CDk8Lco8jKLzmQ8+A8B4V5jkXOyTkz1HHpVcFFFtBuEU8IEY6QzWcX5Aa2+VYZRNkZaYJ+1bjBO7
QzL0gDpA8b8taqnFmim1bM3Dt/bNtbb5pV6TJJ9CHX0rxv8A5qyXN5Ojxklqi97dxRiyhsWUIr3H
5eVQ8N2tyOqn08jVMptb6mz4ITWY6HTU3DNdLYuPjYvvRFXyPq1F9QAF1HnTqfojH/ipe57FRi7Z
jY2Rk7hMPzOTLrJlzC7yMRp8EHIAWqpybepolGMViOhx6DIx9v3XM9m6kSOb6hfVcCwrYotxWTE5
qMmVu770Hj/LBrSKL6aak6k+Nquqr1MfIvysGuHONyXW5OpN69NV5BRio9ux5m3gOUnLu3HIsuJy
FPpY8AefwNbaeZCbxszFdw5wWd0PVrMgtABQBGzMwQLYayHgPD41i5fLVSwvcbeJw3a8v2lRLkzT
Sj3HJ8F5VwreROx/kzvVUQrX4ojzg8RVDLkMxZksEgKnS+o4cdKrGwW+LMZ2RQl/csVINuGhuRwo
wK2dAwJ3w8RR0gXRWbpGpUgWUVlsrydDj34H8fuUxTOIka2hAP0jyvVEqU9zbDktPQu8H9RNzhAi
YdaG3QFA0Jv40jqxsWK5yeWT8vu7NCLHJI3XMo6RpezDTlxtVcK22NOSijm++xS4xkkIb1EsLj6u
m504104Q0OHdZ+TNbmaUydUv1dNtDfjqNRWmuGDNKQ3erisxPC3I+FGQJuFkmRTG5u6c/EV3ODye
9dr9yOHzuN2PuXtZLreYCPl5YhHSusp4Dw8zWLl8tVLC9xt4nEdry/aVftySNdySWPzrgSbk8vc7
8UorC2CXH6SLD6TcmlcRlLI3LETwFK0MmQJ4bceNI0OmSu38phlphswTra8DnXpfw/1UmcA1k3vb
Z8rMy4saQGJ+q7u3NACDb/bc1LjkWMsMvWwsGObpYWiVG6V1uSouDceNZ5xN9Vi6mGKOshhGIoy3
o5kEEXc8eGlV9hf85tP/AOVhywjI6vTGOknmWBJYcuQp4V4KruRk573pHk4uPhe8jqsyGbHZuDIz
FWYeIuLCtkY6HNk9TUVPVduJ51cithbXyqSA0oAbSUxZKuPifs4/dT02OE1JCXVqcHFl3cdN+Vr/
AGV6fK3PMYecFRZmYltWOpNeWlJyeXueqjFRWFsh6OG2trmlBsApY25HQ0EGBhJHSeWnyqGiUyJN
jg3HE0jRYmQJcKQMGU9LA3BHEEc6rcR0zun6f9sYHefb8OZFKE3HFvDlIOKORxt/K41H+FMo6CuX
qXG5fpn3Nt2O6rjHMxDduuH61JFvp1uPGkcRotGsYnbW7rJ7JhkaNm9SGy9Nv8xB4VXJpbl0a5PY
3PZ+y8vcpoMCb+zHM+uPGxJ4Wu8nMBeQFUO7ufbE1R4yiu6ZG/8AZ3Z8fCj7Y9iPogjinw1AFgFj
CMg/bXRh6HMs1eTgdmiexPmp8RTCvUdBBHUOHOmEA1IEbJJVo3H4WAPwOhpGMi1hlEmI6fjRCD8u
Ndym9Toa/dGLOHdS4Xp/tlJfzI6IeJFcbB2mzO9za1QwQ6sduNCIZiAPesQbMNPiKA6BJEB9K28a
HEFIjGC5uaTtH7jcP0v7vl7T7liyzdtuyLQ7hEOcZOjj+qM+ofKpUSHI9k4MmPkY8csbLJG6hkdd
QysLgg+BFVsujqY5OybXlf8APxo5D/MVF/nxpWk9x1pscs/Xfadt2ztOB8ZJIlyMlY5khdlLAIzr
dr3Ch1BNuOlUuuMdUtTXV3Wvtb0ORnfs/uD9P922bcsyTNydnMW4beci7yxIrGORFc+ooVcEXOlq
trehmvglJo506LIvSfip8DWnGTHnA0gZWKkW8aEDMyAeHzqSERcsExtbj/CkkPEdE3QgkGgZCf8A
h1FWxscdV1RVKtS0fRkm5vYcBxpRxxUFrjgeVGBcjnK3hwqAMJbhQw4qb/YKGCHmTmTanaETGiq8
h86XQbUBfjyoA9Ef+vPfUubgydsZsvVl4CmTALHV8e/qS/jGTp5HyquaLYM7eklwKrL0ziH64b7L
uXcEHbmKA6YUQecC1/dlHVxJ0AQLVUnl4Otwa4Rj8kjk25ZeTh7qcV4BAcvDmw5TxBDBZF4f/Xpr
TQeuDHy6VH8ovKkabKvTJIo/C1x8DrWpHMZjYML8/wB9MKN6g+R4mgkjZQIH7arkPEaBY4ieSuv3
GozoTjUtlW3wNWIrZmgA9PI1K9BH6hrfhqKgYxcCxB4GgDKE9USk8eB+I0qVsRLcUAk2A+VBAjJ0
rY8TUEln2v3Bndv77hbvhm2ThSB1U8GHBkbydSQagZPGp6/XvLbpOzP/ACnFBmxGxTkxxjVi1re2
fMP6TVTRoTPKEm9dx4HcGRvOfMMg7jI8rZB0uXe5ta1uk8gdKpcWtTVVYm+yXtLibIyM11ypIVnm
yGVY2JCDQjnyHiaVS1OnyqYfF2xftNd7/wC0MztPufK2vIcSx6SY0w4PE2qn91a4nnpI19dG8jTo
qZgbqxqQGcsAxk+GtJIeAxAOrFcfylj9lqhbDPct1HTx+nnVhTkUj7bc6AFJ5/OpZCMDc/EUowuM
wBkQ62Nx9oqIhIcJbjy8BpTEZMSBe3E0EDZFjbnSjHZv0C7tVzmdm7hJ1Q5qtNtqOdDL0kSwi/8A
1E9Q8xSMtg86Gm/qLg5W0Nk7Yy+5iYeUMiFHGjIQQPu4jxFVzRamSNrRt9hyZVIxTBCojVQLaDT+
Ucv4VRudhXqutRxnJbfrGBu3Z3Z/caLd3w/ymRJ/8kHoYH/UprVW8o498e2TRyYcARVqMzFlPBgL
jn41LISG5VDRsPHhUME9SNALY8g8Q37KSOxbLcuD01czOHIUowC2vhUkGBC340rGRjD1fmT08OgX
+ZtULcJbD5A5m1MKYm3VpUAYyWtrxoYImbCd0G94B2gOd1E8X5ER/WZuoe3b/VSsdb6HQf11my8i
SGfIxxhZkyRNuWIGRzBMNJl6kLKyk2N1J+d6rs2NEdzXkgwlhDbPkSuxhP5tI1ksEv8AiJUVl0O1
x3lfmsehvh/JT/obnRbzbExo5Q+xZD+sST2/uIgTrYDqB1IA1rRVk5nLS7nqcOH38xV5gMjboN/s
pmQhs2sfhrQBHht7b+FzSIsZ/9k=

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image005.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODdhrwCgAOfYAAAAADMAAGYAAJkAAMwAAP8AAAAzADMzAGYzAJkzAMwzAP8zAABmADNmAGZm
AJlmAMxmAP9mAACZADOZAGaZAJmZAMyZAP+ZAADMADPMAGbMAJnMAMzMAP/MAAD/ADP/AGb/AJn/
AMz/AP//AAAAMzMAM2YAM5kAM8wAM/8AMwAzMzMzM2YzM5kzM8wzM/8zMwBmMzNmM2ZmM5lmM8xm
M/9mMwCZMzOZM2aZM5mZM8yZM/+ZMwDMMzPMM2bMM5nMM8zMM//MMwD/MzP/M2b/M5n/M8z/M///
MwAAZjMAZmYAZpkAZswAZv8AZgAzZjMzZmYzZpkzZswzZv8zZgBmZjNmZmZmZplmZsxmZv9mZgCZ
ZjOZZmaZZpmZZsyZZv+ZZgDMZjPMZmbMZpnMZszMZv/MZgD/ZjP/Zmb/Zpn/Zsz/Zv//ZgAAmTMA
mWYAmZkAmcwAmf8AmQAzmTMzmWYzmZkzmcwzmf8zmQBmmTNmmWZmmZlmmcxmmf9mmQCZmTOZmWaZ
mZmZmcyZmf+ZmQDMmTPMmWbMmZnMmczMmf/MmQD/mTP/mWb/mZn/mcz/mf//mQAAzDMAzGYAzJkA
zMwAzP8AzAAzzDMzzGYzzJkzzMwzzP8zzABmzDNmzGZmzJlmzMxmzP9mzACZzDOZzGaZzJmZzMyZ
zP+ZzADMzDPMzGbMzJnMzMzMzP/MzAD/zDP/zGb/zJn/zMz/zP//zAAA/zMA/2YA/5kA/8wA//8A
/wAz/zMz/2Yz/5kz/8wz//8z/wBm/zNm/2Zm/5lm/8xm//9m/wCZ/zOZ/2aZ/5mZ/8yZ//+Z/wDM
/zPM/2bM/5nM/8zM///M/wD//zP//2b//5n//8z//////////ykyIjUlIyggMAwcHxkiEiUVExgQ
IAoaHRcgECMTERYOHhoqLScwIDMjISYeLg8fIhwlFSgYFhsTIwcXGhQdDSAQDhMLGxcnKiQtHTAg
HiMbKwMTFhAZCRwMCg8HFw0dIBojEyYWFBkRIR0tMCozIzYmJCkhMSH/C05FVFNDQVBFMi4wAwEA
AAAh+QQJFADYACwAAAAArwCgAAAI/gCxCRxIsKDBgwgTKlzIsKHDhxAjSpxIsaLFixgzatzIsaPH
jyBDihxJsqTJkyhTqlzJsqXLlzBjypxJs6bNmzhz6tzJs6fPn0CDCh1KtKjRo0iTKl3KtKnTp1Cj
Sp1KtarVq1izat3KtavXr2DDih1LtqzZs2jTql3Ltq3bt3Djyp1Lt67du3jz6t3Lt6/fv4ADCx5M
uLDhw4gTK17MuLHjx5AjS55MeWUgK1cCBWLFqrLEQINCD7KyIpDnh6yuiF4tSPPphaysCFodWrWg
FQECsDD9mqBm2rQ1CwggQICVyKz21FECIHNmQbOB057Nonjxzo/r4NpuRbPm6Ky9/ge6wsKKlQAA
0gNYgZ1xoEm4KCl5QwnXpDdKVqwoX767ePCitWbeCt0pFsgbuChR33aUQDEbaNJFCJwgV2TmWmGB
bFfCdttFMQiFAAYo3ojjmfdfaxa295cV2yG4nRvjQbjaFbgNN1xu6RFnnQAAjBjeZn6xogSHC5ag
Gmss4KbjjsXlxuRw2LESSJJXQFdhaXxZsSCRVrC2X2dO7rikjdblFoAV7cVWmiBJEqhiXUJyyCVr
xwl03phjiinAChW+iU2Mt1nBgp9yaSknh0pENyVBrKTHZJ5lBjBbZgNdM9B45LGAV5yHMqgEFPpZ
SpAVAOQJaZMsQLcbQpoRGpcV/vB1yuEbVohaUI1l3qinpBVWOWhgG8q6XX4JxRZmk2HiiN6kH7L3
14HCJsibQoE8qSx66jUXYADT7mWorEqYJqWrArFyrbJX6LYeeUh2mxcUwoZr5wqCoFlsIPphi2O6
5KlK26p7uSErreWywAJ59iqUXoVs+pfqpEeKBvCmsR6qRJRTVjnIxAY1uoKIUo4nWoX/uksXi51S
0i0rbFbZMEKNsrBad9cEAqDBtFF615CdvvHmlAanSiOhU344SK8a11ZbqjOS2xYrLh7qc8f0Vlml
mwZhdrBmH4cGsdf0zmjyWxm2qMTZ9I0tZcQf0ljgQIJecU3N0clMY3R3r1ae/tNpaYfLG1FP4gYU
90LHGo1AskJvIDWPfPRlYId4BQAJv6Ud4IdOAoDTUh4c4IdJdkev50aPdk2XR7MJHI3lwQU4z4f2
yJCU+03Y5oSbydw26YZvfLCzbeEX79gwxz0dziPvhnpoqQKA95EH38a3WPMNHxG+bNeW9NHbb3yb
pNoz/6EK04NlRdRSE69QbEwf3j5wH6erbepGX+HEE+V7xWnP6sPGp3SZupnuDIYHJwhtZE4QBfDS
Arv0WYQ0IUrelQCQpLatwBiicMJ+KqQCUWBwgWeB18DqZJGMdQ9sosjgkSqEB2O4EA8wdKELRUG+
tARiS3J6Q/8gwjXdscYJ/hh8At6AKMMiypCG+dMK1Aa2Q4nEJmK+aqECDRaAFhrxisZwQhKz0sBZ
NXEiT9QeC6woCili0YNFpCFaUOZAkDxxUmPEYhrRWEQ8fFEr7+HfSGKDGRpZUY5/NKIWzbI/Dk2C
hHu8jBXoaMQUAvKOWWGjnBBpkkAEUo5XXMFZ8ngoTarEkkdkpByrgJYu4oJwllGBE1YpSiziYYtX
2UOnULkSKVmBiJiUISXFwoqKDQsmgehgLl3oBLT4jUMliAkrSJDAXL5yk4dKpksCUQU8pNAJwpTj
LsOyRESxJDZOICMay+hIIz7TLLLkEIxSgq9mptGazoSlVThpH0hiRHHu/rxiBuGJxRqepYHb/Egw
WzlMY/zRjmgxxZbcIE+JWOGSrqRjGS9JSmMSyZ4TWWRBidlCPKgAoqIIKFhuOKuGPgSiziQNQbOI
UasUsg4iQak+sYkmVjyBoApEC0m3M4mWPgSX+iygCkqTppticZCEbCAtPVKFIxbQCSQgkPpY0VR9
ivQre9jSxUByQRnCsKKzo8JRTToVVgiMpz5tiEbrmD9W5EGfYC2LJJfKEVDWEZKsAOoLySqVbiaI
r8W6pBPsmVdRxpUsK1iQDkFySRLAkhXZfGFaywo7um6kqjO8arFWwEg8EFWuC1ICSDBrULI+tJFU
mOxTONXTj3TVhSq4/ggoAymKKgCWKdA65UfWagxPVkRxJLikKKhw26WIcGodsWtv76kCOSIVLGbd
jmXv+UfNOsStBEVoWPYAn8V2hIjavWcVsmvdqrD2DXVQbUGaW1qO3LKVCgSSVwLRQN9ihL2HzUgw
+fnOKnSnuEM5HzIvS0yQtJO/70ztVmD1S41U9ZwGtsITEOzV8jolq/FR70CqKgoNN0RK+fSqh4WC
4a1ahBV6qC5KlKtLrmSVEhZGyGmL+NySsIIKjKRCV7KK3OuN16opwScai9kVeImWh9XEZIzrqh8C
6Q9wX5RSDDEZ0sfQt3w3bqVQzVO5xuCVa02Wam/GTOYym/nMaE6zDZrXzOY2u/nNcH5NQAAAIfkE
CRQA2AAsFQA/AGkAUwAACP4AsQkcSLCgQYGBrFwJFIgVq4MQI0qcSLGixYqBBmkcZGVFoIsgQ4oc
KZHVlY0oBTEkybKlS4OsrAhCqfGkoBUBArD4+LKnz4kMadJkKCCAAAFWfiolyWpPHSUAFi4UNFMo
zZksjh59uLSrxTq4wlphyLBqSrKBrrCwYiUAgLcAVnD1SvdgoEm4KCl5QwnXpDdKVqxYu3YsWrMb
VbJdMbauY2yB3uBS0jcsJSgzM1rdLFTQlYUrHysNFLZE2LBRBnlGnBit67RsD6sEPVc0SythJYd1
k1Yzyis4ixbN+daoVgEAXJ9taHskKyWnK5c4mZIFTuPHj+bMXpQrq0DWr/5Q/eyxOUgrlaNbSTn4
4fbj2IVrzRnAytyYHgVZZ1zbPMTnp6mXUlICtRVffPAJsMJn/UE2FWMsNOgfQegFeJoSVYFHECtv
ZYfgfAHMtNBA1wyUllosTBgRgBZapgQUgpVIIQAIfqgdC1TtBBFDEqqIjRV4tXjaG1bIWFBw8w2X
YIifiRehjyCZJmRYga1oIHzvEeeWiKrJBSVGugmpBE8SBcKdlm7BFVViAZD5JUQVivnRdz0KxAqa
Wl6hU1xqVefmmwVBMeWYBa4giH0rBiJYmsTpqVaONOkIqEFuCEmknSywoBaiEr31mX6G4SgidRtJ
OqmdQVqohHfgiTeIqf4wxdXad2lt9Fmkf76JW4uUuMmKfuKB+h8ALKA01jWBIJYpTSOeCl2Lb/QH
XqY4AicheKoN0qSrNdWE4291msdKmAFGC5Oh4onHn0EKacrQColpS91NiDX7JWm5KaEvX7li8x2p
qgHX2EBWaHoNslUVC1xVC6O0VriPgYXLG2FO4gYUiVKVEnDMsWJoIMjaqm1CGtHLLACcTggWxRZO
AkC432kar36MKQpsyRoVuZ62+gkF3FoqUvyshclR9N1gne3XWUPFBiyzaglr6qV5gA3a738FA6za
srbutLNGOALAMHWa3gSxUntZHZKiWstr1qcO3xRiTWSrpsLZPllBbv65V5dUMGuefWsVvHquyXO2
VzjxBN4vsQht3xN53La2mSrbdKZ4OFGtrU6IMvVjQ1v4BuQUdcRa1+QRC69nKxgjihODfaaCKK5/
XpeglhLYUqvcsifK69R9hocxxONhPPHEi3L3Y4Gkx7dP7zadkhOuP8Ew9chnj7zyjDO1d26kixQT
qU4O73mmAQyv/frGONH9SKEPGb5zCtHNgvqimM8+7dkr79iuopsfUxQiovuxr3/8yx4eBDiSuzzu
MTFRCHDUd0AKas99dHHcaSahOwgmxAoJ1N7vKshAkQAwQB1sTiAseMD1raAuDrTQC1W0wu2F8IBV
cEz8cIExHwVCBf5OCOIN2YeH94VkDy3qoY++YwXstRB5KVQKK1JFpUn9cIjrc4JjJHaaEpyKFSTo
3BOLCEMLefFNgagCHn7nhNm1MIo/GVeAlAClmDgBf/zL3wi1R0a6IPE0vJmQosTYvzWO0YggiaFf
SugSjxFyfa8zJPuWV5fQwdErV3xiBZG3QMeYIj1uQKQJWUjEBOaPhTncYnQYaUIssu+OxsCDCkgp
iktCLz3mqgspx9gRVzqBlRfRYB0cs0tIttE+rHgCFj3nmOZtEJgWcSIkM6cCj9xHma8UpUU0qMSu
VGF7mXMCCWq2om9C0pY92UN6VkWX1nESD6k0GhWyWRdWVCosk/6AZulu2Eej5QGS8fTKCbs5GhZ2
cpvSLJ42KyJHKi20JCz8JUhY8UjiBbQrK6jM6OjCQhIYkRVu5KQ+jTY0gv7EnMlD54pWEEI8WFOg
laGjV1Aay4VagYWioMJI//OsfHrFncRTgUtqaEFRVOGhdtGNSXsCQuTNkCUeIwFOqYBUg+AulwV1
auNUcEAMxvGeS20kBVW6zTxg8aA+2QNeNroU7KG1kVU4K1mD2dM31GGnBOFqTZXSxCF6jjkvCUTo
nvoSvV60Jz+UZCGrMJaH6q2LJyWeFjG5gjsuEw86vU2QZNoTc/YTk1Z4gmIVOFeIqDMveBWIOUWR
WqMFoqLF02PnadnZElboYaz+qaH2SmtaSlCCtwe56QWrOlEqhJAKLlEnVhMZ13NOyJH8m2xLBMVZ
i6SxmMYA7k8UJRjtHmRcbI3cCrHrOu+eyiCCxRsrjLs+arIlZedlCQNpJZj6Diy+AQEAIfkECRQA
2AAsFQA/AGkAUwAACP4AsQkcSLCgQYGBrFwJFIgVq4MQI0qcSLGixYqBBmkcZGVFoIsgQ4ocKZHV
lY0oBTEkybKlS4OsrAhCqfGkoBUBArD4+LKnz4kMadJkKCCAAAFWfiolyWpPHSUAFi4UNFMozZks
jh59uLSrxTq4wlphyLBqSrKBrrCwYiUAgLcAVnD1SvdgoEm4KCl5QwnXpDdKVqxYu3YsWrMbVbJd
MbauY2yB3uBS0jcsJSgzM1rdLFTQlYUrHysNFLZE2LBRBnlGnBit67RsD6sEPVc0SythJYd1k1Yz
yis4ixbN+daoVgEAXJ9taHskKyWnK5c4mZIFTuPHj+bMXpQrq0DWr/5Q/eyxOUgrlaNbSTn44fbj
2IVrzRnAytyYHgVZZ1zbPMTnp6mXUlICtRVffPAJsMJn/UE2FWMsNOgfQegFeJoSVYFHECtvZYfg
fAHMtNBA1wyUllosTBgRgBZapgQUgpVIIQAIfqgdC1TtBBFDEqqIjRV4tXjaG1bIWFBw8w2XYIif
iRehjyCZJmRYga1oIHzvEeeWiKrJBSVGugmpBE8SBcKdlm7BFVViAZD5JUQVivnRdz0KxAqaWl6h
U1xqVefmmwVBMeWYBa4giH0rBiJYmsTpqVaONOkIqEFuCEmknSywoBaiEr31mX6G4SgidRtJOqmd
QVqohHfgiTeIqf4wxdXad2lt9Fmkf76JW4uUuMmKfuKB+h8ALKA01jWBIJYpTSOeCl2Lb/QHXqY4
AicheKoN0qSrNdWE4291msdKmAFGC5Oh4onHn0EKacrQColpS91NiDX7JWm5KaEvX7li8x2pqgHX
2EBWaHoNslUVC1xVC6O0VriPgYXLG2FO4gYUiVKVEnDMsWJoIMjaqm1CGtHLLACcTggWxRZOAkC4
32kar36MKQpsyRoVuZ62+gkF3FoqUvyshclR9N1gne3XWUPFBiyzaglr6qV5gA3a738FA6zasrbu
tLNGOALAMHWa3gSxUntZHZKiWstr1qcO3xRiTWSrpsLZPllBbv65V5dUMGuefWsVvHquyXO2Vzjx
BN4vsQht3xN53La2mSrbdKZ4OFGtrU6IMvVjQ1v4BuQUdcRa1+QRC69nKxgjihODfaaCKK5/Xpeg
lhLYUqvcsifK69R9hocxxONhPPHEi3L3Y4Gkx7dP7zadkhOuP8Ew9chnj7zyjDO1d26kixQTqU4O
73mmAQyv/frGONH9SKEPGb5zCtHNgvqimM8+7dkr79iuopsfUxQiovuxr3/8yx4eBDiSuzzuMTFR
CHDUd0AKas99dHHcaSahOwgmxAoJ1N7vKshAkQAwQB1sTiAseMD1raAuDrTQC1W0wu2F8IBVcEz8
cIExHwVCBf5OCOIN2YeH94VkDy3qoY++YwXstRB5KVQKK1JFpUn9cIjrc4JjJHaaEpyKFSTo3BOL
CEMLefFNgagCHn7nhNm1MIo/GVeAlAClmDgBf/zL3wi1R0a6IPE0vJmQosTYvzWO0YggiaFfSugS
jxFyfa8zJPuWV5fQwdErV3xiBZG3QMeYIj1uQKQJWUjEBOaPhTncYnQYaUIssu+OxsCDCkgpiktC
Lz3mqgspx9gRVzqBlRfRYB0cs0tIttE+rHgCFj3nmOZtEJgWcSIkM6cCj9xHma8UpUU0qMSuVGF7
mXMCCWq2om9C0pY92UN6VkWX1nESD6k0GhWyWRdWVCosk/6AZulu2Eej5QGS8fTKCbs5GhZ2cpvS
LJ42KyJHKi20JCz8JUhY8UjiBbQrK6jM6OjCQhIYkRVu5KQ+jTY0gv7EnMlD54pWEEI8WFOglaGj
V1Aay4VagYWioMJI//OsfHrFncRTgUtqaEFRVOGhdtGNSXsCQuTNkCUeIwFOqYBUg+AulwV1auNU
cEAMxvGeS20kBVW6zTxg8aA+2QNeNroU7KG1kVU4K1mD2dM31GGnBOFqTZXSxCF6jjkvCUTonvoS
vV60Jz+UZCGrMJaH6q2LJyWeFjG5gjsuEw86vU2QZNoTc/YTk1Z4gmIVOFeIqDMveBWIOUWRWqMF
oqLF02PnadnZElboYaz+qaH2SmtaSlCCtwe56QWrOlEqhJAKLlEnVhMZ13NOyJH8m2xLBMVZi6Sx
mMYA7k8UJRjtHmRcbI3cCrHrOu+eyiCCxRsrjLs+arIlZedlCQNpJZj6Diy+AQEAIfkECRQA2AAs
JAAEAFoAjgAACP4AsQkcSLCgwYMHA7FCyLChw4cQIzpcAWChxIsYM2oMBOBKII0gQ4okyIrFihUj
U6qUGMjKio8rY8okuYKFlZk4ZdZEmbPnyCuDbvocunHQFaJIMVqBmbSpw0BMnUo1eEXo1KsCWQmy
inWqlaBdsQLlGjZpIEFgyzoNNEhQVLVDWQGFCtfsoKAW6w5lm1bvUKCD3vqdebat4MEx+V7Ji5jw
3cONVQKGHHnkirtkK6vkm1nzSLZbPctk21L0SlakO5vOyJfu6s+PKb+O2Fr2bISsrOiefLjlUsa3
A73BhetNR7fA5aI1fJtgHeKU3FwRdGUFaqhQl99tC8B2Y1bD3/6UeEM+CuDt6LcLWu9d5h4oUNof
3EO8BCXi0N/sSZ9+Pd6mwxGnhGoNBeKGgPjhQokSUNQ0HX93rScIAEsRFUiCxRGYkBL4cUicdIa1
dUVVD6YXyAoBAMBTT1ZgiMskGhIUiIcYKrHCbtqpN910aAnCggBAsuATFC6+GCM2MxZJCQsQQrjV
CiOiCGQAPrVY5BsaskJjjec12eRWAAQQgHysJXggfm9ApmWRH3ZZlW4u1WRSiegJcmNPgdyHYIJK
ACcQFHoqyWSELIyImphTCkBhjhGy4mdK4KHpYp8FCccmmlBYURVaH1mBKJCgplhofwrNdGZxAeJH
CRQFPXcpcf7iMbncTRwFAOqtiAZQ6HJbkQmRq8VtCd0eA9H36huZWjEoZtiwEiauod4qgK5zlaoS
sAMGit8kH1nK5hsvDSTXdh5hE6atiU6J7pRQaUqdtSIZiwsUrJyaYJr2JrigYIGc1+2n6a4b6kL9
tsWCrwnpidIe2nZ4Kb0ILcvCQgDgui66tgJAYVZWcApvRpHigtKaGL7RMH5uPCpQwcwFAjDAodrk
Wm6AlQuSh0JZoW1025I3CXGylbQdT1dAK+20FRnUUltugeQqTCQLeJ94JShh9SSU2LbCcuWygiLG
n6Kr20GoUVdhRsYyFcjPCipBSQn5upHmU4DZyfG5SIuZov4ALz2qVVUHs3YfVx6SBwDb+pZgm9fb
TTyQbhSJ6SkALKTo6KPXiLgYRpayKu6BShzOZncPXRYhV1Z4TRGUKKreUElX2IRRpEpUavilSTvU
8XaZOepSSy3lpnJWJ2rEIaUEWfGGsKoCABHLRg2/EGrDq0QkLnW8pfy3K06EXnvVp3T9i54PlGqN
3VeqkOraHaWWlR+ShHiNzheE2kka53+e+2VdiF8dMjoZcaBQP3GdSGOFugIC1YMwnIRsXjI6H5qq
QxON0Sl/6DkSUlJFrIF4q2SDcNzKKKcj7gCAVzYLi7zKhyQBRsEoVhFahEYEFAWabixqCRnykDQ/
6NwwL/7LCiFUajgqoFhHLa6a28okiAs3BGJQm8PGqDBzjaX0aFkp7EqeiGOVD+KHVbtLi7taURVW
XKMwIVRP+rBypi4y8SbjastNOrYUTXkEPaa7yxHLQiRKuLFkMOGLHOl4RkaFcH8NJEwTmfJAAUGt
fVCqo3qMYrAM5lA8BZFgCZKHHhawgDroAcqg8tiXrngNOOejRPfQ2JY8UodHALgLnaI4mPMpkWOd
NKRJrsjAxmxphwIJYyXVsxSWkTKRRAEWBJXWyRr+porL2dp2kDmU8S3TfuexU48WM0VtTrMx1lRN
HFtpyBAGURDhu4q8cEEgxkVImukxSXo0KBUrIE5D0P7zUXqiFE9q5uSDMYKniNQ4oR5FqIB1eSAL
yRZET3pSmh2J0F1I5xcavSF8BUPLFUQhipNM9IZ6TJ1fgOXHh3TslXgwhgoAswInaPQuhaJnUpS5
RoPkxihXcIIx8MA1JzxBQjgVIVzWuVDciPIJO62ZCvBwGaC8UqYWSlBREdIvQQTAGKL4Sgh1iodP
SrSmWPHfAFkSu5SK4gkUEYUxjOEELKpALwq9yIl0utad1pWtciIBHvwpk1RN9XUquKtgseoEJ3AU
qkMB1l8bYoXBOnatYFXnF1mT0scKVgXpNMtkZ0dXx6q1rntNaIAWy9jPClYUla1rZKcyWo2wIrB3
Rf5tauvqBL6uxFi124gKVGBYy2J1tWu5T243MlvL4iGzRInULTMCW9+uFRB1cRXENGKF4j7WD3Ux
FiWWK5HXOnetorBtSj44XM511rfQhQuNyouRFZjWuHXZ4jVBpoL3Oja0lxxrSF5r39MiticMmy99
6+vbKuhlOG4QCSsM29+7Hje+20VupaqAB7VytMHP1ctzoJobJ1SWo+AF8WAfDJcLsZchc7UvajG8
VhLDZXkP8VpvPethDGNWL/B5CoG/K9jU4rfE1avudytcV9kK1sCmsQKLBevhnS51sFk1jXV9iweX
YLi2opkylJ2ggtSx4gkN7qhozntaPHC5b+ICs/5jnSBhrFShyGZ2AgluRBlWvBnK/5XKChyMByTH
mAprbrNX7Otih7AiD1D2c2MCUdwfx5jMOxW0U1hRXCx3d8Z1VTRiiksCQfPXweLNyZ3Bm2evvZep
H6vLqCMdEiHHlgqhXsme6/pWkTDarkWugqRZZFrgxngFej0tFXaNk1tDFlLNZTKxZULpuubZpnlo
sKO7Qtdp77cK0n52TGBb6JRYAdNFRjNWYKvpzSy1v6itwm+kcmcn4KmlRIYyHmDdlDt3mzBWeEK8
e6zti9w5vElBDbhbHGuy6SG1/absYBPO2Eov27VUeC8V/oltPE9Fxp9192gobFmGb+Qkd1IJahnw
oGVSN4chrIj4iLkMp4cj5jogP8nZ/BIQACH5BAkUANgALDYADgBUAIQAAAj+ALEJHEiwoMGDCBMq
XMiQIKtADSNKnEjRYKAVKypq3MhRICsAKyB2HElS4UUrIkuqXHkRAKuVMEuuuJIxps2NgWimvMkz
4pVBNXsKXfjwysuhSBEGGiQoqVOHgQS1EhpoD5SrO4cGsiKoacyHgeq4mYSrLC5KWW+yuiKIKUxW
VlYoIWu2Li5NQosOYnp0JFwoc+0KxvWmb8ycbQcZHVk18ODHb9KWjLpXsWGKgaC4ofS47hsAnM2+
sWKT8t7FFFntqfMm9Nk3bursmT07LspAb+pSIg3TtKBAlxnCdWOXEhTgRHPX5a3St+SFgZQMNhWR
lfS6QUluPR0ceh3XniX+4rabveND7hLhKgH/+s0bKOLpmoWvfekgFt0RsoKivOybEoEEWNEKgtGX
HnIDmXbFcyZdBcUeDDZUQoETBVKCe3Vg81BigjD3VEHX1VVCQw/xJ6IVlXX44UGs9GeWEgY9ZMVV
byixXnEl/MSUhysmKN+LBEWnRGuQuQfAFSzsZUV+HwYymBIP7UFkZ7jceBYUgrCwZI8H7aGbezW6
SGVxLCzI5UFQmOUGAFaOSeUkUTH5YZpViummWZTUaOOQUVh2JkFp2gimez9SSUmONP12BQBt/YYg
l3tQAkAJe9p44Z1K6JglW4Ekuddvv7Ui5017KEGcYEO6WUJlKQqyIKv+KY56mJ0viubGnm4o54aO
sCqWGKwRxmQKe3YRNxqCMlphIwD29corq14hxQqxdr0BZ0KslMkCRgBwxeqz6A3FyqmdUaIEjwah
yNQV7DKb4rPsBkvSfm4qscKozTIFUVwc/rqUvCNBQW1d9srK628aAhDAComx9amKPY1H5bkReToI
aR8FEIAAASQ2k74Ab2SdoSW41FBOn5JmRQAACOByAJ8m6WoAIVdEJ2QrsBCyt4oBp7DLLnf78CAa
C3BTIIV6xi66Ca1Q2b2B/Aw0xxyuwDHNX9GKyyRQ7FWeSbxmFMjGU7ts8RVA1xxRJo+5ka2SEvGM
8MpTkx1A2BurzZD+l0++5CnTCDmN3hVkv/xyx6e1/Jadxr20FtwCWQEASCtsmWDYAqFd9+EseAy4
RvQWC8VRpvHGCreTT44gwykLFAjQhV8tgKdXfF5RIOwBGGRlvMmNJAuqX1SZmdiMbTjsQOtoO0Uu
Nl4Qr6R12itTk3+8FwsJSl147G3hV5IVru0WI/TYzNT5uo2mzqqHVste9su/LU9iiMYdlG9IbDns
6k+LAmAxwgOxwqKKtjmOoehrFQHffLqjLq91LkACDElU+vcrHm1FYS2r28YWtBW9FaRFonlOAwVx
JOBsBT8Bapfg9GWRFbCsbCy7GzZQIj+F3AwXBrLI8JxGQyRd4xr+USEhr54ztte9UADM6paGaCIr
pbjmWgjhFbvQty4rqKtMTLmYfkKCQY4BQEMiiRfoXASlhFiMddOrTOdcNQgGBQgkY4uLRzKnxYrw
rSyTsF2z/verFMnMVXKCC0poxiMUoUY8/aHEvRSCRospBotqrKBwSMOsrCBGbzcsIyMTkySH+dFV
jqwhRARkkE5WqD+RYcgKZRYAFrgSeN2DFsDkxBUANiREXGvICpX3QyDqyJHeY0xUQiYx56lSjacJ
EMoU86waMiSFV4iIFV7UxPIND1q/ciTxGOMqyylkZFWq2dn6yKpQNqeNKHkmZ8QnEZkxE1agPJgH
9aOzQyakDmX+0SSJkpSknEGrTJ70k0pqF4hrJGdrastWllaABzzkbFvmk+VbQLK3fFZEWwAwBh62
lb8VhmtF13EmQbSFB2Mc6SdCBBaXJFaHag6EXSswhijOJ4gVAABWOuPSNM2iNyuwoKROaJgrP+W1
M91MCXoLBAmMYQwnnOYKKkBpZb7IJeUg9XYl1Si7rkACJ/DvNAhMirHmaQVRMLWpK3gCHryqGK+F
VVy5yeFEqnBWjZ7Vqw5b2krd41KHZJWpZmWqVz22zQ95Sa7iCWxdmYoHHbElmCtyzzzLt9i6ikJT
91mpufpKkBUotrIq4NBkR7ICN4zWCiT4rGUfWgXOqoQVriX+CF1Va1k8iAIQfxqJE2pbWY3GNrce
2W1tVZsH4HIkEH/tLWNHC9xA0LayTjAuR6ygXMuKVLoFoW51l4tdjZR1u03trneT29vritd1wq2u
ec+LDRWAtwrspQhdt4uH32IXEOAVBXOBy4r0Vhe+8SWRf5Vb3wCbpAq2lakonstU3Br4g1ZwQlYX
DFgKV7bADy7eCpygWlEkuLoYDvDpOKxcUUiYwSqwL1ICoQIG0/eseNhvT6xA3t5+WKYNXSyAz/td
8Aq2pHhQQY1FsV6k1Ji+cWGwE2QckyNX1sQqWBIrnvBcUbz1TAOurRNUEJK+TPm5TlCxTeaLYyc4
gQSVYxD8K8hsXfHGFMZ42DFRqNDbMHe3xzCuJivy8GQ5N5e8MU5PlkPMX/IueSL9Va2fc0teEnCW
FS2ua6Cly2Yig86zku4ycNlMaIrQeLGioAKTOfJmpqqAMUC2bGvPhOcrk2gFJCBvqMWMk7+6mkTu
rTOtK8KKvxY5Rnl47qQ/JNxh+6UKwv41R3Ld6ZFEmLZWftRQcr1o7QgZ2nFGya4TMt/oHm3DN66t
qHky32b3xgpqTfZN5qvfpDyExIs19rz04Osm1VjZ6TL0tqtDhc9SYTLIfjK+Lw1vbx8XwepdKUYq
JzLkOhmwA/8TK/p94S1b0ZsZZlGAFo6RdGacIAEBACH5BAkUANgALDsAAgBhAJAAAAj+ALEJHEiw
YMFAUAwqXMiwocOHECMWhDLJisSLGDNqZAgFlxJWG0OKHKmwDi6PIEmqXHkxECVclKCkZEmzpkEl
J2POtMmTZSCcMGX2HLrSypucQokqDVniJEyLS6NiDDTJ6ZtAUrNGdOMUVwmtYBvu6foGatizAwO5
eXMUJdq3A1nhjAm3rlpcV+vC3fOyjt63ck/u+YvWysu8hMEGxpUwMVgrJys61hqorZudk5VyPdk4
81KTkbF6VtrR6millbsOPj20qVXMrH26Puk3tk21L08itk2zrdMVvGsCddo5uMrhnI2znH0SuHKV
zHE5fz4SOS6z1Dem7oo9e8bSTin+dfd+0bdu0eSnmseLPr1E8Fbbu3+4mOz8lus9TrViBTZvyF2d
5AZDrARi4IF1sPXGR9RZR1taCCkh4YQSvpEbcYH4N1p9lCy4YAlKVBXgiDkpqAQLV1yRISsaErbd
GyBaSOKMuq31BgAssDDIjjsKoiJ/QAbSX0QFtihSZZSESOOSkYW3xxU8RikljypmyFAgKa4AwHQs
GaUEACWEqUR+TAb4ho9ApsmfioJE6aOKKRV4xQorWHGFIFbW9FMJF+KlRJ9lBqiEIJgVeCCQKvLo
o4FtDmJFnVbI16WDApI5IiUlQKFEFHVMciah9AmZZiCCtNIKnkSxQtGSlAaIaZv+KA5yhRJQ5umZ
qoCOCJSCCnZFK49Y+qjjIAbeCkWuusZ0oJB0uvGSEoFIKYggVjSKpqSAHVtmkkkVVGAJblgx5SCC
DOumIHrhum0JABhpBQsAiDulj/MaGZW2TE4Sr71YkssCnY3ueOeU2GZlWJlutBuRjm/OCSWP5gL7
lkv5mgBAwQax8jC5VZrbr6JDhkXVkpPQqqJE8pK7AkhWBGBuyrKerJiIJC54J6pErgAxVi0H4HKP
D08LqlasWArju+SO19DH1GJjBQA+CyDAwwP7q1irSqzcLwsYK6TzjiywCHUAUgsAQJuCACDwFUTD
59QkJYhW7SBhS/Sxo9gEAnX+2VIPSyqxF2fFl6vQEjQsC3HxZ6B/X8vKc9R8B9DonSz4LNV2ORVO
0N90D6QlAPGuYGveGyOOzQpk8913j6kH0PVKP3VVEWwpQxUIw/+CvvJA5jaNzd5lp372jlaU/TpJ
qsqOrcY8WnT7lFdsyXLpILGiutRk/0wuAFLbSxK+Ty3EOd4oshAw66GDLJD1wacugM/R0h0A20RZ
QTNjDMHM37QDv7k96BuTGTYg9z7skW1YafPekczzhhb1bgUoMtCdroC06G0pSqYTyN581rrUxU9p
LKlPchgSwLNlCEtXuAYrxGXBALYHde9rXeTaBEKVJM9XLRrfCu6EKCtcw0D+dLsgj7jkNHgRUHVQ
uoICNXIwp2hOfIpqHJVYJC54BUyAAgmElgLAveu9b1o1PNJmTvLEhaQsReO6gvn8pT6DPIqLqktd
nfBmE+SU0YxUC9j5qASladXNawEoXvAKuMJy2WRwZDye0yBGrrVVbUdfg1IN6RS9qPkMXthgBYqW
SKQx3jF/jETjuei2MZzhcYdku5gWBbICU6pkLIlEGSMFUacUqTGJG6ObkVaoRJ9BJSU6CyNGihZL
IpWOeD+UINjcJMy8WSRe8hFXMyUCy7K05IoCi9TzOIZBBT6zWASpFhZDMjK6XARmuaTXMtv4EJ4p
pECuDAloGHSRPgpsXNz+hBgn16cQcSnSIduZZkGgpKM5Qa9cehRoO6f1PafU5iI6ypETRPEEa6FI
lGDb59LupFGD+KaBGJkgCUQhChJsCYARc5xPqnSk3EyiDhpNEQvwYAwVqLFNc9qjQiGCwn+KTzc7
HUiKnGAMPMRKVsOLkhJpgiUWBLUgmcDFJFaTkUeJwhhPoBIEpeXTiPQ0JEUzJxNpKgqqRQ9tELOJ
nUhFziR1dCBENYYxCnqFJ2RVVtm0CSt2+FaBWOipabmqXJ2AoieIgmEPEx1PRjcVSlwmJHGVqyjw
INiCCkxhjmEFiLp6EJrK9bOfvdmOApmZIolkBYIFrWRFmSLA2qYKqgX+LR6CFsH7GAS1sZXssAhq
W2+pQAWpVe0ZXRubQHg2t0W15e566znVHvezeHACHogbGxXENriffQJzCcKKyCJXrnjgrHGM+93P
ioK6sbECdnPrhL7+57m5Pe92D+Jd9ro3ONYtrxPmaxDYlhcP9+UNIMprDFGIVzndJbAxqsDfuNQ3
twDmbyCqQNkCk/S7Bz7NCqUrWcGSdL1Fta0WJ6rayYIYugFO1wpIHF/pnlgFKYZLIICr4NgeN7zk
sQJ8IZzaycKXwdlRb42NwWE8qGDH8qXOjv9rVeQ6IcNwWfJ1naCC/rDCsPElIm8ebN7oqkB0M7ky
iNv7HP8WOLpOIEH+nTDGCjODNsnGWYFs8QBk+lDBvsoRsmyXyIo8XLfOvCGvbH2aYOfGWCqsgO+T
L9Jd7ALaNvAlgUZZQWPoQjksboYzo3ELXTC/ds8h0XGJqXDpqMj5syoYCXmfK4oqHJonejaGloe5
AhLAVxRUeLWejjvrYeY3tmQu7XHRu748gBjHmYkrspFXhWMT2yb5jXCXWPxmTxMmv49WyYwrXGI6
R0rXGvHvfhe7Ym53m9Rv8a+0eyKkJ5hbts8Ot2RLTaRAUNvSitHDsCmz43hHRNSgDTaiqRBcKlyu
2df1d85YPG6iTFjKxlC43ehUp6EUCA8QL7DEM0twG1MZSOCejKEJKE6nSDV4IAEBACH5BAkUANgA
LDsAAgBhAJAAAAj+ALEJHEiwYMFAUAwqXMiwocOHECMWhDLJisSLGDNqZAgFlxJWG0OKHKmwDi6P
IEmqXHkxECVclKCkZEmzpkElJ2POtMmTZSCcMGX2HLrSypucQokqDVniJEyLS6NiDDTJ6ZtAUrNG
dOMUVwmtYBvu6foGatizAwO5eXMUJdq3A1nhjAm3rlpcV+vC3fOyjt63ck/u+YvWysu8hMEGxpUw
MVgrJys61hqorZudk5VyPdk481KTkbF6VtrR6millbsOPj20qVXMrH26Puk3tk21L08itk2zrdMV
vGsCddo5uMrhnI2znH0SuHKVzHE5fz4SOS6z1Dem7oo9e8bSTin+dfd+0bdu0eSnmseLPr1E8Fbb
u3+4mOz8lus9TrViBTZvyF2d5AZDrARi4IF1sPXGR9RZR1taCCkh4YQSvpEbcYH4N1p9lCy4YAlK
VBXgiDkpqAQLV1yRISsaErbdGyBaSOKMuq31BgAssDDIjjsKoiJ/QAbSX0QFtihSZZSESOOSkYW3
xxU8RikljypmyFAgKa4AwHQsGaUEACWEqUR+TAb4ho9ApsmfioJE6aOKKRV4xQorWHGFIFbW9FMJ
F+KlRJ9lBqiEIJgVeCCQKvLoo4FtDmJFnVbI16WDApI5IiUlQKFEFHVMciah9AmZZiCCtNIKnkSx
QtGSlAaIaZv+KA5yhRJQ5umZqoCOCJSCCnZFK49Y+qjjIAbeCkWuusZ0oJB0uvGSEoFIKYggVjSK
pqSAHVtmkkkVVGAJblgx5SCCDOumIHrhum0JABhpBQsAiDulj/MaGZW2TE4Sr71YkssCnY3ueOeU
2GZlWJlutBuRjm/OCSWP5gL7lkv5mgBAwQax8jC5VZrbr6JDhkXVkpPQqqJE8pK7AkhWBGBuyrKe
rJiIJC54J6pErgAxVi0H4HKPD08LqlasWArju+SO19DH1GJjBQA+CyDAwwP7q1irSqzcLwsYK6Tz
jiywCHUAUgsAQJuCACDwFUTD59QkJYhW7SBhS/Sxo9gEAnX+2VIPSyqxF2fFl6vQEjQsC3HxZ6B/
X8vKc9R8B9DonSz4LNV2ORVO0N90D6QlAPGuYGveGyOOzQpk8913j6kH0PVKP3VVEWwpQxUIw/+C
vvJA5jaNzd5lp372jlaU/TpJqsqOrcY8WnT7lFdsyXLpILGiutRk/0wuAFLbSxK+Ty3EOd4oshAw
66GDLJD1wacugM/R0h0A20RZQTNjDMHM37QDv7k96BuTGTYg9z7skW1YafPekczzhhb1bgUoMtCd
roC06G0pSqYTyN581rrUxU9pLKlPchgSwLNlCEtXuAYrxGXBALYHde9rXeTaBEKVJM9XLRrfCu6E
KCtcw0D+dLsgj7jkNHgRUHVQuoICNXIwp2hOfIpqHJVYJC54BUyAAgmElgLAveu9b1o1PNJmTvLE
haQsReO6gvn8pT6DPIqLqktdnfBmE+SU0YxUC9j5qASladXNawEoXvAKuMJy2WRwZDye0yBGrrVV
bUdfg1IN6RS9qPkMXthgBYqWSKQx3jF/jETjuei2MZzhcYdku5gWBbICU6pkLIlEGSMFUacUqTGJ
G6ObkVaoRJ9BJSU6CyNGihZLIpWOeD+UINjcJMy8WSRe8hFXMyUCy7K05IoCi9TzOIZBBT6zWASp
FhZDMjK6XARmuaTXMtv4EJ4ppECuDAloGHSRPgpsXNz+hBgn16cQcSnSIduZZkGgpKM5Qa9cehRo
O6f1PafU5iI6ypETRPEEa6FIlGDb59LupFGD+KaBGJkgCUQhChJsCYARc5xPqnSk3EyiDhpNEQvw
YAwVqLFNc9qjQiGCwn+KTzc7HUiKnGAMPMRKVsOLkhJpgiUWBLUgmcDFJFaTkUeJwhhPoBIEpeXT
iPQ0JEUzJxNpKgqqRQ9tELOJnUhFziR1dCBENYYxCnqFJ2RVVtm0CSt2+FaBWOipabmqXJ2AoieI
gmEPEx1PRjcVSlwmJHGVqyjwINiCCkxhjmEFiLp6EJrK9bOfvdmOApmZIolkBYIFrWRFmSLA2qYK
qgX+LR6CFsH7GAS1sZXssAhqW2+pQAWpVe0ZXRubQHg2t0W15e566znVHvezeHACHogbGxXENrif
fQJzCcKKyCJXrnjgrHGM+93PioK6sbECdnPrhL7+57m5Pe92D+Jd9ro3ONYtrxPmaxDYlhcP9+UN
IMprDFGIVzndJbAxqsDfuNQ3twDmbyCqQNkCk/S7Bz7NCqUrWcGSdL1Fta0WJ6rayYIYugFO1wpI
HF/pnlgFKYZLIICr4NgeN7zksQJ8IZzaycKXwdlRb42NwWE8qGDH8qXOjv9rVeQ6IcNwWfJ1naCC
/rDCsPElIm8ebN7oqkB0M7kyiNv7HP8WOLpOIEH+nTDGCjODNsnGWYFs8QBk+lDBvsoRsmyXyIo8
XLfOvCGvbH2aYOfGWCqsgO+TL9Jd7ALaNvAlgUZZQWPoQjksboYzo3ELXTC/ds8h0XGJqXDpqMj5
syoYCXmfK4oqHJonejaGloe5AhLAVxRUeLWejjvrYeY3tmQu7XHRu748gBjHmYkrspFXhWMT2yb5
jXCXWPxmTxMmv49WyYwrXGI6R0rXGvHvfhe7Ym53m9Rv8a+0eyKkJ5hbts8Ot2RLTaRAUNvSitHD
sCmz43hHRNSgDTaiqRBcKlyu2df1d85YPG6iTFjKxlC43ehUp6EUCA8QL7DEM0twG1MZSOCejKEJ
KE6nSDV4IAEBACH5BAkUANgALDYADgBUAIQAAAj+ALEJHEiwoMGDCBMqXMiQIKtADSNKnEjRYKAV
Kypq3MhRICsAKyB2HElS4UUrIkuqXHkRAKuVMEuuuJIxps2NgWimvMkz4pVBNXsKXfjwysuhSBEG
GiQoqVOHgQS1EhpoD5SrO4cGsiKoacyHgeq4mYSrLC5KWW+yuiKIKUxWVlYoIWu2Li5NQosOYnp0
JFwoc+0KxvWmb8ycbQcZHVk18ODHb9KWjLpXsWGKgaC4ofS47hsAnM2+sWKT8t7FFFntqfMm9Nk3
bursmT07LspAb+pSIg3TtKBAlxnCdWOXEhTgRHPX5a3St+SFgZQMNhWRlfS6QUluPR0ceh3XniX+
4rabveND7hLhKgH/+s0bKOLpmoWvfekgFt0RsoKivOybEoEEWNEKgtGXHnIDmXbFcyZdBcUeDDZU
QoETBVKCe3Vg81BigjD3VEHX1VVCQw/xJ6IVlXX44UGs9GeWEgY9ZMVVbyixXnEl/MSUhysmKN+L
BEWnRGuQuQfAFSzsZUV+HwYymBIP7UFkZ7jceBYUgrCwZI8H7aGbezW6SGVxLCzI5UFQmOUGAFaO
SeUkUTH5YZpViummWZTUaOOQUVh2JkFp2gimez9SSUmONP12BQBt/YYgl3tQAkAJe9p44Z1K6Jgl
W4Ekuddvv7Ui5017KEGcYEO6WUJlKQqyIKv+KY56mJ0viubGnm4o54aOsCqWGKwRxmQKe3YRNxqC
MlphIwD29corq14hxQqxdr0BZ0KslMkCRgBwxeqz6A3FyqmdUaIEjwahyNQV7DKb4rPsBkvSfm4q
scKozTIFUVwc/rqUvCNBQW1d9srK628aAhDAComx9amKPY1H5bkReToIaR8FEIAAASQ2k74Ab2Sd
oSW41FBOn5JmRQAACOByAJ8m6WoAIVdEJ2QrsBCyt4oBp7DLLnf78CAaC3BTIIV6xi66Ca1Q2b2B
/Aw0xxyuwDHNX9GKyyRQ7FWeSbxmFMjGU7ts8RVA1xxRJo+5ka2SEvGM8MpTkx1A2BurzZD+l0++
5CnTCDmN3hVkv/xyx6e1/Jadxr20FtwCWQEASCtsmWDYAqFd9+EseAy4RvQWC8VRpvHGCreTT44g
wykLFAjQhV8tgKdXfF5RIOwBGGRlvMmNJAuqX1SZmdiMbTjsQOtoO0UuNl4Qr6R12itTk3+8FwsJ
Sl147G3hV5IVru0WI/TYzNT5uo2mzqqHVste9su/LU9iiMYdlG9IbDns6k+LAmAxwgOxwqKKtjmO
oehrFQHffLqjLq91LkACDElU+vcrHm1FYS2r28YWtBW9FaRFonlOAwVxJOBsBT8Bapfg9GWRFbCs
bCy7GzZQIj+F3AwXBrLI8JxGQyRd4xr+USEhr54ztte9UADM6paGaCIrpbjmWgjhFbvQty4rqKtM
TLmYfkKCQY4BQEMiiRfoXASlhFiMddOrTOdcNQgGBQgkY4uLRzKnxYrwrSyTsF2z/verFMnMVXKC
C0poxiMUoUY8/aHEvRSCRospBotqrKBwSMOsrCBGbzcsIyMTkySH+dFVjqwhRARkkE5WqD+RYcgK
ZRYAFrgSeN2DFsDkxBUANiREXGvICpX3QyDqyJHeY0xUQiYx56lSjacJEMoU86waMiSFV4iIFV7U
xPIND1q/ciTxGOMqyylkZFWq2dn6yKpQNqeNKHkmZ8QnEZkxE1agPJgH9aOzQyakDmX+0SSJkpSk
nEGrTJ70k0pqF4hrJGdrastWllaABzzkbFvmk+VbQLK3fFZEWwAwBh62lb8VhmtF13EmQbSFB2Mc
6SdCBBaXJFaHag6EXSswhijOJ4gVAABWOuPSNM2iNyuwoKROaJgrP+W1M91MCXoLBAmMYQwnnOYK
KkBpZb7IJeUg9XYl1Si7rkACJ/DvNAhMirHmaQVRMLWpK3gCHryqGK+FVVy5yeFEqnBWjZ7Vqw5b
2krd41KHZJWpZmWqVz22zQ95Sa7iCWxdmYoHHbElmCtyzzzLt9i6ikJT91mpufpKkBUotrIq4NBk
R7ICN4zWCiT4rGUfWgXOqoQVriX+CF1Va1k8iAIQfxqJE2pbWY3GNrce2W1tVZsH4HIkEH/tLWNH
C9xA0LayTjAuR6ygXMuKVLoFoW51l4tdjZR1u03trneT29vritd1wq2uec+LDRWAtwrspQhdt4uH
32IXEOAVBXOBy4r0Vhe+8SWRf5Vb3wCbpAq2lakonstU3Br4g1ZwQlYXDFgKV7bADy7eCpygWlEk
uLoYDvDpOKxcUUiYwSqwL1ICoQIG0/eseNhvT6xA3t5+WKYNXSyAz/td8Aq2pHhQQY1FsV6k1Ji+
cWGwE2QckyNX1sQqWBIrnvBcUbz1TAOurRNUEJK+TPm5TlCxTeaLYyc4gQSVYxD8K8hsXfHGFMZ4
2DFRqNDbMHe3xzCuJivy8GQ5N5e8MU5PlkPMX/IueSL9Va2fc0teEnCWFS2ua6Cly2Yig86zku4y
cNlMaIrQeLGioAKTOfJmpqqAMUC2bGvPhOcrk2gFJCBvqMWMk7+6mkTurTOtK8KKvxY5Rnl47qQ/
JNxh+6UKwv41R3Ld6ZFEmLZWftRQcr1o7QgZ2nFGya4TMt/oHm3DN66tqHky32b3xgpqTfZN5qvf
pDyExIs19rz04Osm1VjZ6TL0tqtDhc9SYTLIfjK+Lw1vbx8XwepdKUYqJzLkOhmwA/8TK/p94S1b
0ZsZZlGAFo6RdGacIAEBACH5BAkUANgALCQABABaAI4AAAj+ALEJHEiwoMGDBwOxQsiwocOHECM6
XAFgocSLGDNqDATgSiCNIEOKJMiKxYoVI1OqlBjIyoqPK2PKJLmChZWZOGXWRJmz58grg276HLpx
0BWiSDFagZm0qcNATJ1KNXhF6NSrAlkJsop1qpWgXbEC5Ro2aSBBYMs6DTRIUFS1Q1kBhQrX7KCg
FusOZZtW71Cgg976nXm2reDBMfleyYuY8N3DjVUChhx55Iq7ZCur5JtZ80i2Wz3LZNtS9EpWpDub
zsiX7urPjym/jtha9myErKzonny45VLGtwO9wYXrTUe3wOWiNXybYB3ilNxcEXRlBWqoUJffbQvA
dmNWw9/+lHhDPgrg7ei3C1rvXeYeKFDaH9xDvAQl4tDf7Emffj3epsMRp4RqDQXihoD44UKJElDU
NB1/d60nCABLERVIgsURmJAS+HFInHSGtXVFVQ+mF8gKAQDAU09WYIjLJBoSFIiHGCqxwm7aqTfd
dGgJwoIAQLLgExQuvhgjNjMWSQkLEEK41QojoghkAD61WOQbGrJCY43nNdnkVgAEEIB8rCV4IH5v
QKZlkR92WZVuLtVkUonoCXJjT4Hch2CCSgAnEBR6KslkhCyMiJqYUwpAYY4RsuJnSuCh6WKfBQnH
JppQWFEVWh9ZgSiQoKZYaH8KzXRmcQHiRwkUBT13KXH+4jG53E0cBQDqrYgGUOhyW5EJkavFbQnd
HgPR9+obmVoxKGbYsBImrqHeKoCuc5WqErADBorfJB9ZyuYbLw0k13YeYROmrYlOie6UUGlKnbUi
GYsLFKycmmCa9ia4oGCBnNftp+muG+pC/bbFgq8J6YnSHtp2eCm9CC3LwkIA4LouurYCQGFWVnAK
b0aR4oLSmhi+0TB+bjwqUMHMBQIwwKHa5FpugJULkodCWaFtdNuSNwlxspW0HU9XQCvttBUZ1FJb
boHkKkwkC3ifeCUoYfUklNi2wnLlsoIixp+iq9tBqFFXYUbGMhXIzwoqQUkJ+bqR5lOA2cnxuUiL
maL+AC89qlVVB7N2H1cekgcA2/qWYJvX2008kG4UiekpACyk6Oij14i4GEaWsirugUoczmZ3D10W
IVdWeE0RlCiq3lBJV9iEUaRKVGr4pUk71PF2mTnqUkst5aZyVidqxCGlBFnxhrCqAgARy0YNvxBq
w6tEJC51vKX8tytOhF571ad0/YueD5Rqjd1XqpDq2h2llpUfkoR4jc4XhNpJGud/nvtlXYhfHTI6
GXGgUD9xnUhjhboCAtWDMJyEbF4yOh+aqkMTjdEpf+g5ElJSRayBeKtkg3DcyiinI+4AgFc2C4u8
yockAUbBKFYRWoRGBBQFmm4sagkZ8pA0P+jcMC/+ywohVGo4KqBYRy2umtvKJIgLNwRiUJvDxqgw
c42l9GhZKexKnohjlQ/ih1W7S4u7WlEVVlyjMCFUT/qwcqYuMvEm42rLTTq2FE15BD2mu8sRy0Ik
SrixZDDhixzpeEZGhXB/DSRME5nyQAFBrX1QqqN6jGKwDOZQPAWRYAmShx4WsIA66AHKoPLYl654
DTjno0T30NiWPFKHRwC4C52iOJjzKZFjnTSkSa7IwMZsaYcCCWMl1bMUlpEykUQBFgSV1ska/qaK
y9nadpA5lPEt037nsVOPFjNFbU6zMdZUTRxbacgQBlEQ4buKvHBBIMZFSJrpMUl6NCgVKyBOQ9D+
81F6ohRPaubkgzGCp4jUOKEeRaiAdXkgC8kWRE96UpodidBdSOcXGr0hfAVDyxVEIYqTTPSGekyd
X4Dlx4d07JV4MIYKALMCJ2j0LoWiZ1KUuUaD5MYoV3CCMfDANSc8QUI4FSFc1rlQ3IjyCTutmQrw
cBmgvFKmFkpQURHSL0EEwBii+EoIdYqHT0q0pljx3wBZEruUiuIJFBGFMYzhBCyqQC8KvciJdLrW
ndaVrXIiAR78KZNUTfV1KrirYLHqBCdwFKpDAdZfG2KFwTp2rWBV5xdZk9LHClYF6TTLZGdHV8eq
ta57TWiAFsvYzwpWFJWta2SnMlqNsCKwd0X+bWrr6gS+rsRYtduIClRgWMtidbVruU9uNzJby+Ih
s0SJ1C0zAlvfrhUQdXEVxDRiheI+1g91MRYlliuR1zp3raKwbUo+OFzOdda30IULjcqLkRWY1rh1
2eI1QaaC9zo2tJcca0hea9/TIrYnDJsvfevr2yroZThuEAkrDNvfux43vttFbqWqgAe1crTBz9XL
c6CaGydUlqPgBfFgHwyXC7GXIXO1L2oxvFYSw2V5D/Fabz3rYQxjVi/weQqBvyvY1OK3xNWr7ncr
XFfZCtbAprECiwXr4Z0udbBZNY11fYsHl2C4tqKZMpSdoILUseIJDe6oaM57WjxwuW/iArP+Y50g
YaxUochmdgIJbkQZVrwZyv+VygocjAckx5gKa26zV+zrYoewIg9Q9nNjAlHcH8eYzDsVtFNYUVws
d3fGdVU0YopLAkHz18HizcmdwZtnr72XqR+ry6gjHRIhx5YKoV7Jnuv6VpEw2q5FroKkWWRa4MZ4
BXo9LRV2jZNbQxZSzWUysWVC6brm2aZ5aLCju0LXae+3CtJ+dkxgW+iUWAHTRUYzVmCr6c0stb+o
rcJvpHJnJ+CppUSGMh5g3ZQ7d5swVnhCvHus7YvcObxJQQ24Wxxrsukhtf2m7GATzthKL9u1VHgv
Ff6JbTxPRcafdfdoKGxZhm/kJHdSCWoZ8KBlUjeHIayI+Ii5DKeHI+Y6ID/J2fwSEAA7

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image006.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODdhGQAWAMYHANDg/wAAAGZmZpmZmdLMmXBgIJCAUP///6CwwD1BQczMzLDA0EBAQBAQAKaN
KTMzMxAQEODg4DMzAMzMmcSvVkAwECAgIKCgoIV9U1BQUHCAgNDQ0M/Dfo55JNDg4BAAAHBwcLCw
sICAgODgwCAQAGBgQNDQwNDg0CAgAKCggMDQ0CAgEMDQwLDAwHBgEHF5gMDAoLzArMDA0NDQoNDQ
kNDQsKCQUFBAEDUtDdDgwJCgkJGViYCAYO7dh7CgMLC2qeDgoODgkGBQEFpgYVBQMFBAIMDQ4E9D
E2BwcOTbnbCgYODo24mRk4+TiMu/fsmzV52ZcpuQWZSeooiJeYiAVDs4Jz81ELK+w7u5k4B/aoBz
OX1zRH1wOOXitq2gXaKdc6q0tOjUeHRvTnBfHNPKjJ+qscvNsDQvGaONNP///wAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACH/
C05FVFNDQVBFMi4wAwEAAAAh+QQFCABpACwAAAAAGQAWAEAH8YAHAIKEg4aFiIeEJQGNOiNAJ4NA
IzONjVKKhzMrjREbQxYhBxkBDYkHqBFOSlEGBlE2NB6HmoUGjRAiEREXFo0qqKi1w4jFxMiEhDkF
nUMMGQzSGdFnEDhQxoMpGYY+EJcBKzCpTQEttoMz4BARLA+6pAEQwpud8xkiTKG5wwD/AAMKHEiw
oMGCB2JouRfOlJUvtApSaNAI3cANXC5tIChmHhMAXVBUKNChQgkAF+5pOAhACUNw4lSw/DcDRaML
BzawiBCCQQAcM7FQfHDgArgMB0QE+BCUYoAhEVJFYPKrwUwPCBC00IpgQVauM8MSDAQAIfkEBQgA
aQAsAgADABMAEQBAB7mAaYKDEScHg4iJghFcDYIQFogpEBlpAJeYmZqZaSgBnxeKKkwMaWcxAIM0
iCKCpSBppYMcN58MjogNRFibmT0rgzdNTw2fASq5gq1pIYIPsYozgxksg0MQ0Ig1KSUVDQ0VRBhY
MYaJjZ8tBwAhGmkQnx8lHqknJGkZIakzHoRhQoIapAJwKM0IB4nOsIACL0BBQSUGNWP2TFC/RLgO
XIgES1AlRdjSbNgAgkE1V4rS4BI0BMTHbGkCAQAh+QQFCABpACwCAAMAEwAKAEAHcoAAgoOEBzkn
B2mKi0oQSIuQkIRpI2goFiIqhIJdRAGfaYQzXDcNn6cMpgFZigWokYqbAIoHAAcRNTRKBTc4DQ1E
WTGLABFPOJ8QDEhlRgcsQqYWoT4fAQ0YsKEsIQwBC2lcn0M12iq1tWkHByrasIlpgQA7

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image007.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODlhCgAKAPcAAAAAAIAAAACAAICAAAAAgIAAgACAgICAgMDAwP8AAAD/AP//AAAA//8A/wD/
/////wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMwAAZgAAmQAAzAAA/wAzAAAzMwAzZgAzmQAzzAAz/wBm
AABmMwBmZgBmmQBmzABm/wCZAACZMwCZZgCZmQCZzACZ/wDMAADMMwDMZgDMmQDMzADM/wD/AAD/
MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMzADMzMzMzZjMzmTMzzDMz/zNmADNmMzNm
ZjNmmTNmzDNm/zOZADOZMzOZZjOZmTOZzDOZ/zPMADPMMzPMZjPMmTPMzDPM/zP/ADP/MzP/ZjP/
mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2YzAGYzM2YzZmYzmWYzzGYz/2ZmAGZmM2ZmZmZmmWZm
zGZm/2aZAGaZM2aZZmaZmWaZzGaZ/2bMAGbMM2bMZmbMmWbMzGbM/2b/AGb/M2b/Zmb/mWb/zGb/
/5kAAJkAM5kAZpkAmZkAzJkA/5kzAJkzM5kzZpkzmZkzzJkz/5lmAJlmM5lmZplmmZlmzJlm/5mZ
AJmZM5mZZpmZmZmZzJmZ/5nMAJnMM5nMZpnMmZnMzJnM/5n/AJn/M5n/Zpn/mZn/zJn//8wAAMwA
M8wAZswAmcwAzMwA/8wzAMwzM8wzZswzmcwzzMwz/8xmAMxmM8xmZsxmmcxmzMxm/8yZAMyZM8yZ
ZsyZmcyZzMyZ/8zMAMzMM8zMZszMmczMzMzM/8z/AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8A
mf8AzP8A//8zAP8zM/8zZv8zmf8zzP8z//9mAP9mM/9mZv9mmf9mzP9m//+ZAP+ZM/+ZZv+Zmf+Z
zP+Z///MAP/MM//MZv/Mmf/MzP/M////AP//M///Zv//mf//zP///ywAAAAACgAKAAAIIgD/CRxI
cCCug7gKIkRocCHDfw4fRjwocGLCig4VPizIMSAAOy==

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image008.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODlhCgAKAPcAAAAAAIAAAACAAICAAAAAgIAAgACAgICAgMDAwP8AAAD/AP//AAAA//8A/wD/
/////wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMwAAZgAAmQAAzAAA/wAzAAAzMwAzZgAzmQAzzAAz/wBm
AABmMwBmZgBmmQBmzABm/wCZAACZMwCZZgCZmQCZzACZ/wDMAADMMwDMZgDMmQDMzADM/wD/AAD/
MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMzADMzMzMzZjMzmTMzzDMz/zNmADNmMzNm
ZjNmmTNmzDNm/zOZADOZMzOZZjOZmTOZzDOZ/zPMADPMMzPMZjPMmTPMzDPM/zP/ADP/MzP/ZjP/
mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2YzAGYzM2YzZmYzmWYzzGYz/2ZmAGZmM2ZmZmZmmWZm
zGZm/2aZAGaZM2aZZmaZmWaZzGaZ/2bMAGbMM2bMZmbMmWbMzGbM/2b/AGb/M2b/Zmb/mWb/zGb/
/5kAAJkAM5kAZpkAmZkAzJkA/5kzAJkzM5kzZpkzmZkzzJkz/5lmAJlmM5lmZplmmZlmzJlm/5mZ
AJmZM5mZZpmZmZmZzJmZ/5nMAJnMM5nMZpnMmZnMzJnM/5n/AJn/M5n/Zpn/mZn/zJn//8wAAMwA
M8wAZswAmcwAzMwA/8wzAMwzM8wzZswzmcwzzMwz/8xmAMxmM8xmZsxmmcxmzMxm/8yZAMyZM8yZ
ZsyZmcyZzMyZ/8zMAMzMM8zMZszMmczMzMzM/8z/AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8A
mf8AzP8A//8zAP8zM/8zZv8zmf8zzP8z//9mAP9mM/9mZv9mmf9mzP9m//+ZAP+ZM/+ZZv+Zmf+Z
zP+Z///MAP/MM//MZv/Mmf/MzP/M////AP//M///Zv//mf//zP///ywAAAAACgAKAAAIIgD/CRxI
cCC9g/QKIkRocCHDfw4fRjwocGLCig4VPizIMSAAOy==

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image009.png
Content-Transfer-Encoding: base64
Content-Type: image/png

iVBORw0KGgoAAAANSUhEUgAAAjAAAAFACAYAAACiO0YzAAAAAXNSR0IArs4c6QAAAARnQU1BAACx
jwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAAJr9JREFU
eF7t3cHLJMmZ3/EW6LiWQbB3HSzRXjAIsxiDZXiPveA1LWQfFrNCI600st0YMRrYYc0yF8stYcFc
5mB8GWOx6DhId6mNTzKWT3NodNFchP4B6aRL+c1XzlFOdmZlZGZE1hORn4Jipt+KiIz4/p6I55eR
WVmfuNy/HnkhgAACCCCAAAI1EegMjBcCCCCAAAIIIFATgUc1dVZfEUAAAQQQQACBh6tHMCCAAAII
IIAAArURYGBqU0x/EUAAAQQQQMAOjBhAAAEEEEAAgfoI2IGpTzM9RgABBBBA4PQEGJjThwAACCCA
AAII1EeAgalPMz1GAAEEEEDg9AQYmNOHAAAIIIAAAgjUR4CBqU8zPUYAAQQQQOD0BBiY04cAAAgg
gAACCNRHgIGpTzM9RgABBBBA4PQEGJjTh8C5ANz/Tln346WT7zGJrtya19ryXdtr+rO2L1v6s+YY
e8uuHXuJ8YzbPOIYe7mpjwACvyewboVGDYHKCVxLUHuT15b6JfqzpR+3kLXE2Ifj2MJhS529xvcW
7B0TgRYIMDAtqGgMyQSWEtTS59cOtKXuUp2lz6f6s6VOMsCMBZf6ufT5Ule21N9Sh4FZUsLnCJQh
wMCU4arVoASWEtTw86my48seKWf8e3calvox7sOwj3OfzSXduboP27WjS29z5qkvtxQCS1r0x+zb
WeIw1m48lv7zYf/GbY7LzB0zhd+wrbWsUvqxxNfnCLROgIFpXWHj+xiBpaR5zcAsJbOlz7fulswl
2bnEntKPqTavHWdrm9fCb0mLJQOz1Ke1YxyatGvGdMtx5wzPNQ2XdDe1ETg7AQbm7BFwsvGv2Q1Z
m0DWlh8n6DkprpmqqQSY2o+ldpc+v5bkr+2apHy2Z1w5jV1KP9YarbkYXOKdYvhONp0N9+QEGJiT
B8DZhj+8rDD+/7VnydfKpyablHJLiW1tAs2RlJdYpZiUvWNfqp9i5FLKLPFd+rzEMc42b40XgSkC
DIy4OBWBpe3/pV2Fa6anb7svkwJ2KQlPJcc5E3Zt52FtnfFx+38P2xmzWjpGqumZ02BOu2t9StFz
qcySQVn6nIFJmQnKILCeAAOznpkaFRNI2b5P2T2Y28WY2y2ZMz5bDMwS/tSEuZS4l/qWsjN0ra9L
7S8Zg8kzssGze1I4pJRJ6cc1FiWOsRQDPkfgDAQYmDOobIwfEShtYJZMwdpdiBzJL2XMa3am5szb
kqEoNfbUHZuUMeZgtaRZjmOY0ggg4EF2YuBkBK6d9W9JPEu7EEu7DGv6M7cztNTv8Q5Cyr/X7jqk
tplq8LaajTU7IXN9XuI59XmO4y6xWYqlk01lw0XAk3jFwLkILCWBFEMyvBy0lHSmkuS4zrC9uban
di/6sqk7G9faTjUMS/1b+nzP2Of6eE2PIaPUMfaazfGd+nwcN0vHXTpGSl/PNXONFoFXCbiEJCoQ
QAABBBBAoDoCDEx1kukwAggggAACCDAwYgABBBBAAAEEqiPAwFQnmQ4jgAACCCCAAAMjBhBAAAEE
EECgOgIMTHWS6TACCCCAAAIIMDBiAAEEEEAAAQSqI8DAVCeZDiOAAAIIIIAAAyMGEEAAAQQQQKA6
AgxMdZLpMAIIIIAAAggwMGIAAQQQQAABBKojwMBUJ5kOI4AAAggggAADIwYQQAABBBBAoDoCDEx1
kukwAggggAACCDAwYgABBBBAAAEEqiPAwFQnmQ4jgAACCCCAAAMjBhBAAAEEEECgOgIMTHWS6TAC
CCCAAAIIMDBiAAEEEEAAAQSqI8DAVCeZDiOAAAIIIIAAAyMGEEAAAQQQQKA6AgxMdZLpMAIIIIAA
AggwMGIAAQQQQAABBKojwMBUJ5kOI4AAAggggECVBubTn/705dGjR94YiAExIAbEgBioJAY+//nP
Z3VdVRqYzrx4IYAAAggggEA9BHLn7iqdQG4I9civpwgggAACCNRJIHfuZmDqjAO9RgABBBBAoCoC
DMy9XLkhVBUBOosAAggggECFBHLnbjswFQaBLiOAAAIIIFAbAQbGDkxtMau/CCCAAAIIZL96YgdG
UCGAAAIIIIBAcQJ2YOzAFA8yB0AAAQQQQCA3AQaGgckdU9pDAAEEEECgOAEGhoEpHmQOgAACCCCA
QG4CDAwDkzumtIcAAggggEBxAgwMA1M8yBwAAQQQQACB3ASqNjBTnR/+KOMQ1tzfuzK5IeQWSXsI
IIAAAggg8HECuXP3YV+j7g3J2KRM/Xs8yKV/CxIEEEAAAQQQiE2gSgPTd3rJiKwtF1sqvUMAAQQQ
QACBnkCVBmau83OG5prReeuttx4uId3d3XljIAbEgBgQA2Kgkhg4vYF5+fLlg4F58eKFNwZiQAyI
ATEgBiqJgdMbGDfx2o5EAAEEEECgPgIMzL1muSHUFwZ6jAACCCCAQF0Ecufuw76FNLdz4mvUdQWg
3iKAAAIIILCFQNUGZsuAp+rkhpCrX9pBAAEEEEAAgWkCuXP3oTswuUTNDSFXv7SDAAIIIIAAAgzM
bAwwMKYHAggggAACdRHInbvtwNSlv94igAACCCBQJQEG5l623BCqjASdRgABBBBAoCICuXO3HZiK
xNdVBBBAAAEEaiXAwNiBqTV29RsBBBBA4MQEGBgG5sThb+gIIIAAArUSaM7AeJBdraGo3wgggAAC
CKQTaMrAbPk16g5Vbgjp+JVEAAEEEEAAgS0Ecufum97Ey8BsCQF1EEAAAQQQqI/A6Q3Me++997AD
8/bbb3tjIAbEgBgQA2KgkhhoysD0l4PG98HM7cx05RkYxo15FQNiQAyIgfpioDkDM9wE6wd3zcC4
B6a+bUM9RgABBBBAoCkD4x4YAY0AAggggMA5CDRlYMaXkMa7Mf2lpbG0uSGcI3SMEgEEEEAAgdsR
yJ27b/otpK0Yc0PY2g/1EECgPIHf/va3lx/+8IdVvX/yk5+UB+MICFRGIHfuZmAqCwDdReBsBDrz
8oW/+PLl8WvPqnk/ffr0bDIZLwKLBBiYe0S5ISxSVwABBG5GoDMwnXn5xBvfq+bNwNwsXBw4MIHc
udsOTGCxdQ0BBC4Pl44YGJGAQP0EGBg7MPVHsREgsIIAA7MClqIIBCbAwDAwgcNT1xDIT4CByc9U
iwjcggADw8DcIu4cE4GbEWBgbobegRHISoCBYWCyBpTGEIhOgIGJrpD+IZBGgIFhYNIiRSkEGiHA
wDQipGGcnkBzBmb8Q469wnN/7z7PDeH0UQUAAoEJMDCBxdE1BFYQyJ27b/o1ar+FtEJ5RRE4KQEG
5qTCG3ZzBE5vYF6+fPmwA/PixQtvDMTACWLg+fPnVT4HxhpljRYDH4+BpgxMfzlo/KONczszXfm3
3nrrwcDc3d15YyAGThADT548qdLAWKOs0WLg4zHQlIFxCam5HUIDQiA7AZeQsiPVIAI3IcDAuIn3
JoHnoAjcigADcyvyjotAXgIMDAOTN6K0hkBwAgxMcIF0D4FEAk0ZmLl7YK79vf8skZdiCCBQOQEG
pnIBdR+B/0+gOQOzRdncELb0oUSdn/3sZ5enT59W9f76v/v3JVBoE4GPCDAwggGBNgjkzt03fQ7M
VklyQ9jaj9z1LNS5iWqvBQLmRQsqGgMC+R9Cy8AEiioLdSAxdCUMAfMijBQ6gsAuArk3HxiYXXLk
rWyhzstTa20QMC/a0NEoEGBg7mMgN4QoYWWhjqKEfkQiYF5EUkNfENhOIHfutgOzXYvsNS3U2ZFq
sAEC5kUDIhoCAgU2HxiYQGFloQ4khq6EIWBehJFCRxDYRcAOTAEXt0uRjJUt1BlhaqoZAuZFM1Ia
yMkJNGVg+h9xHP6313fqb8PPWowDC3WLqhrTXgLmxV6C6iMQg0BTBmaIdDiwa79G3dXJDSGGtJeL
hTqKEvoRiYB5EUkNfUFgO4HcuTvMPTCpBubDDz98MDAvXrxo7v38+fPL49eeXT7xxveqeXdPDm5R
C2OKM7/MizhamBe02BMDTRqYNTsuX/nKVx4MzN3dXXPvJ0+eVGlgWtTCmOLML/MijhbmBS32xMDp
DYxLSLF2Z7odGC8EShJwCakkXW0jcByB5gzM1IDW7Mgch778kSzU5Rk7Qn0EzIv6NNNjBKYIMDBu
4g11f4wdGAtVaQIMTGnC69r/4IMPLjW9f/WrX60boNLFCJzCwPSXifqvUo9p5oZQTK2VDVuoVwJT
/BQEzIs4Mv/4xz++/Mu/+DeXf/HVb1Tz/tK/+tdxAJ68J7lzd5hvIa3RNTeENccuWdZCXZKutmsl
YF7EUY4WcbSosSe5czcDEygKLA6BxNCVMATMizBSeFZVHCmq7AkDcy9bbghRIsFCHUUJ/YhEwLyI
owYt4mhRY09y5247MIGiwOIQSAxdCUPAvAgjhR2YOFJU2RMGxg6MbyFVOXV1eisBBmYrufz1aJGf
6ZlaZGAYGAbmTDPeWJ31B4oBBiaQGBV2hYFhYBiYCieuLm8nIGluZ5e7Ji1yEz1XewwMA8PAnGvO
n360kmacEKBFHC1q7ElzBqZ/WN3Uzwd4kF2s3z2a+pVsT+KtcRmpq8+SZhy9aBFHixp70pSBmfvN
I7+FFN+49GaGgalxGamrz5JmHL1oEUeLGnvStIHpBWFgGJgaJ6c+lyEgaZbhuqVVWmyhps5cbt9L
5qbPgRlePhqalmsGpjvjH9dr5d+PHz++PH7tWah7XKYuGw3/1rIercRV7eMwLx6FWfNoEUeLWuf1
XtMyrH9zA/Oxzjz6fXfswNiByRnk2qqbgLP+OPrRIo4WNfak6UtI/eAYGAamxsmpz2UISJpluG5p
lRZbqKnT7CUkOzB/IGBxMNEReJWAeREnKmgRR4sae9LUDkx/uWjq69JzX6+eusRUo5BTfbY4tKKk
ceQkUOu86O4Pq+n9g7/774uy1arF4sAUOIRAcwZmC7XcELb0oUQdi0MJqtqsnUCt8+Jvf/q5Sy3v
Z+/+k8v33/nuYqjUqsXiwBQ4hEDu3H3Tm3i3EssNYWs/ctezOOQmqr0WCNQ6L2oxL10/GZgWZkr8
MeTO3QxMIM1rXagDIdSVBgnUOi8YmBhfRvCwzTiLAgNzr0VuCFHkrXWhjsJPP9okUOu8YGAYmDZn
5PZR5c7ddmC2a5G9Zq0LdXYQARr85S9/eXn27Terev/n//L9AOTyd6HWecHAMDD5Z0PdLTIwdmBC
Pam31e3ZLmn+47/8xuWP/+1/rObdshY1PqGagWFg6rYb+XvPwDAwDEz+efVKi7We9R+A5vBD1KoF
A8PAHD5Zgh+QgWFgGJgDJmmtSfMANIcfolYtGBgG5vDJEvyAzRmYaz/oOPWAu06f3BCiaF7rQh2F
X85+0CInzX1t1aoFA8PA7Iv89mrnzt03v4l3akB+CynGxF/6Jeruc/ddxNGKFrG0YGBi6NHqvKjR
3jRlYOYGw8DEmPgMzLNQl+uW9Gh1obYDU/6Jvh5kV6MdqK/PzRmYqd88umZgvvnNbz5cQrq7u2vu
/eTJk0uN37agRQzD2RkYWsTRorYdmD9/+meL8WONai/vHLlmNGVgxv6xH9w1A/Py5csHA/PixYvm
3s+fP6/SwNAiTtKkRRwtajMwf/03315cU61R7eWdI9eM0xsYN/HGWKD7yxkuW8TRgxaxtKjNwPgx
x/ouydTW46YMzNxOi3tg4izE7rugxa0XSffAuAdmaR269nmrxv7W83LL8ZsyMP1uytTXpafujemB
5YawRYgSdWpdqEuwuHWbtLi1An84fq1a2IGJYf4ZmDhzOXfuvvnXqLegzQ1hSx9K1Kl1oS7B4tZt
0uLWCjAwRxog30KKE+8t9yR37mZgAkWLpBlHDFrQYu9liyMNyN5jMTBx4r3lnjAw9+rmhhAlYCTN
KEpcLrSgBQPzagyYF3HmRY09yZ277cAEigKLQxwxaEELBoaBiTML2ugJA2MHJtTTYVu9QY6BibNg
1qrF3ss6R9Z3CSlOvLfcEwaGgWFgDpjhtSbNA9AcfohatTjSgOw9FgNzeFif8oAMDAMTzsB88MEH
l5rev/vd7xYXj1qT5uLAKixQqxZ7TcWR9RmYCidGhV1mYBiYcAbmr771pUst77/8qy9d/ut/e3dx
6teaNBcHVmGBWrU40oDsPRYDU+HEqLDLzRqYqafvTj3grtMsN4QocWCh9sTRvTeORonlnP0wL8yL
vfPizbf+w6Wm9//5v/875xQK01bu3B3iW0hjo+KnBGI8wTJl0ehu4t179ndkfWeaYday5I4wMAxM
ylo0V6Zbo974H5+v5v2N//TPLym/S5U8gQIVbM7ATP0CNQPDwJQyNa0bmJrOMru+/s//9dPF5ZWB
YWD2GphS60mJdlPXqMWJE7DA6Q3Me++993AJ6e23327u/frrr18ev/Ys1D0uSwtHjTswX/36lxdj
p1YtajvTbFmLEsmtVJtd0qRFeaOYol+qFjXmwKYMzHAwc/8/vufl/fffZ2DeiLNDw8DQImVRniqT
ulDXaia3crlFPVrEMC+d9qlaMDD398Pecpdp+IvTw/tgXEKKkxRb3IFJub7sskX5BT11q5wWtFha
h659XuNJVsoadcvcvfXYTe3ADCGk7sD4FlIsc9Pq4iBpSpqS5qtpyryIMy+2mohb1juFgelNiq9R
xzIrUws6AxNHI1rQYuvlJ7th5Y1JqjapWtzSiGw9drMGZg2Q3BDWHLtkWWc35ReR1MWBFrSwA2MH
JtV05CyXukaVzEWl2s6du296D8xWSLkhbO1H7nqSpqQpaUqaOZNhalupSdMaFWeNyp1/jmgvd+5m
YI5QLfEYFoc4iwMtaMFMMpOpBjBnuVQzmZhWQhVjYO7lyA0hisKSpqQpaUqaOZNhalupSdMaFWeN
ipK31vQjd+62A7OGfuGyFoc4iwMtaMFMMpOpBjBnuVQzWTgdFWmegbEDE+pJvb754psvWxfv1IWa
mWQmmckifuLwRhkYBoaBuX9apaT5qnFiJplJ8+I88+Jw95HhgAwMA8PAMDCTMcDAMDAMDAOTwWcU
a6I5AzP8OYEhtbm/d2VyQyim1sqGbZVv31lJXbhdtijPmBbfuzCTzGTqPBiXS12jVqaXEMVz5+6b
3sQ795tHfgspzuRfuvZsoY6jFS1oUTppOskqfwLAwKR7rZsamHE3e+PCwMRZiBkYWmxNikv1Uhdq
STNO0qRFHC3S03yckk3twPRYx795dM3AvP/++w+XkGr8KfGlPr/++uuXx689C3WPS4sG5qtf//Ji
/NDimIWaFuU5LxnJ7vPOTNKiLi2W8knEz5s0MEMjM3WPy3DQ77zzDgPzRpxdgRovW1io61qomcny
ejEw5RmnGMk1ZjKiQVnq0+kNjJt445iXbnemRgPz/Xe+u7inaqu8/ILuElJ5xmuSpnkRQ4/UebG4
iAUs0JSBcRPvxyNM0iy/gKQuDrSgxdLl02ufM/ZxTrRa1SKgP1nsUlMGpt9NGd8Dc+3vdmDiLAx2
YGiReoY/VY6ZLG8SU/WhRX1aLLqFgAWaMzBbGOeGsKUPJeo46y+/iFioyzOWNF1a3bN7lbuuHZgS
2Wpbm7lzd6ivUaciyQ0h9bilyzEw5ZMrA1OeMQPDwOQ2IXvaY2BKZ6709nPnbgYmnX3xkgxM+eTK
wJRnzMAwMHsMR+66DEzx1JV8AAbmHlVuCMn0CxdkYMonVwamPGMGhoHJbUL2tMfAFE5cK5rPnbvt
wKyAX7ooA1M+uTIw5RkzMAzMHsORuy4DUzpzpbfPwNiBCfWk3lYXB2ayvNFhJsszZibbNZPptiFO
SQaGgWFg7h99nrowb/2lVwZmO+NUbRiY8oxpwcDEsS/5b/9wCSmQupJm+QVd0izPWNJsN2lao8rP
n9Q1KlDqSu6KHRg7MHZg7MBMxoDLeXEeLEgLWqQa+a27xMmuIVDB5gxM/xTeqZ8VmHpCb6dFbghR
9HV2E+fshha02HMzKQPDwDAwr2bW3Ln7ppeQ/BbSxwWWNCVNSfPVRc+8MC/Miyin2fv60ZSBGaPo
BzdnbLryH3744cMOzIsXL5p7P3/+/PL4tWehLhEtLRw1nmn+9d98ezF2aHFM0qRFec4pOwHdfRe0
qEuLGnPg6Q3Mt771rQcDc3d319z7yZMnDMyO+1tSF+o/f/pni7FDi/KLeZc0aVGes3nxdPO3FlPY
5S6TOi9qzIHNGpjhwK7twLgHJs61Zb9GTYs9i3fqty1cQipvcmhRnnHqXEnVYt/FnNvUbtLArDUs
uSHcRkrX+lMndM5yqYuDpFl+QadFecapc4cW9WkRJW+t6Ufu3H3Tm3jndlPWGpo1ACOXlTTLLyIW
6vKMJU3PgVm6d+7Iz2u8T+/773w3cqra3LemDMzwK9Tjr0zPfb3aJSSXLVIT5FQ5BoaBOSJ5tpo0
nWSVnz+pa9RmF3HDik0ZmK0cc0PY2o/c9SwOcRYHWtBij9FhYOKcaLWqRe78c0R7uXP3zS8hbYGW
G8KWPpSoI2lKmpKme8P27DBurZt61m+NirNGlchBpdvMnbsZmNKKrWjf4hBncaAFLZhJZnKrIdxT
L9VMrkgtYYoyMPdS5IYQRV1JU9KUNCXNPclva93UpGmNirNGRclba/qRO3fbgVlDv3BZi0OcxYEW
tGAmmcmthnBPvVQzWTgdFWmegbEDE+qnBlq9QY6BYWAYGAZmjxHZWpeBSfdOdmDSWRUvKWlKmpKm
pLk18e2pl5o0rVFx1qjiCanAAezA2IGxA7Pj95Is1OUX4NRESgta7DHsqXVb3SUu4C+KN9mkgZka
lAfZxXmOwrWFotXFwZlm+eTKwJRnzEy2+1Tk4m6jwAGaMzDjJ/B2zPyUQB3mxY85xtKJmYyjBy1o
kWoex+VSjX0Bf1G8yaYMTD+YtYYlN4TiqiUewFl/+TPS1MWBFrRIvUQxVY6BYWAYmFcTX+7cHeIm
3jUG5u7u7mGHpsX348ePL49fexbqHpelRbzGhfqf/rM/XYwfWhxjYGhRnnNKIu2MPS3q0qLWHJh4
Pp9UrDoDM3WJKWmkFRRy1l9+AbEDU55xSsLsytCCFksnSDk+r/Eky69RpyVsBiaN0yGlGJjyC7qk
WZ4xA9PujaPWqPLzJ3WNOiQpZT7I6S8h2YGJc23ZTby0SDUrU+VSF2pJM07SpEUcLTJ7i0OaO4WB
6U3K1DeUGBhJU9KcjoFWt8olzThJkxZxtDjEcWQ+SJMGZi2j3BDWHr9UeYtDnMWBFrTYc/8FMxnn
RKtVLUrloZLt5s7dIe6BWQssN4S1xy9VXtKUNCXNV2eXeWFemBelss6x7ebO3QzMsfpdPZqF2kJt
oWZg9lwi3VrX/Ujl155UbVK1CJS6krvCwNyjyg0hmX7hggxM+UUkdXGgBS2YSWYy1XTkLJe6RhVO
R0Waz5277cAUkWlbo5KmpClpSpo5k2FqW6lJ0xoVZ43almVuW4uBsQMT6km9rd4gZ6GOs1DTghaM
/W2NR66jMzAMDANz/xTX1DPLrT+UJmluZ5yqjbP+8oxp0e5DBXOZiiPbYWAYGAaGgZmMAbthvrqb
algY+zjmcasWRxqPXMc6jYEZ/lDVGF5uCLnE2duOs/7yi4qz/vKMU5MoLWix59JQat1Wjf3efHOL
+rlzd8ibeNf8OvUtRCh1TAam/IIuaZZnzMC0e9nCGlV+/qSuUaXyUMl2GRiXkFxCcgnJJaQ34lwu
mtoJaPWsn4FhYPYYnNMbmLu7u4fnwHhjIAbEgBgQA2Kgnhj45Cc/ucf/vFK3yktIn/nMZ7JC0Nh2
ArTYzi53TVrkJrq9PVpsZ5e7Ji1yE43TXpUGJg4+PUEAAQQQQACBWxBgYG5B3TERQAABBBBAYBeB
kAamG9G1r1HvGnFjlVNvikott4QnVzu9xkvHa+HzHMz6Nra2Nay3tY0WtOjHcPT6gv/26Bnf47K9
pema5kNuose1F9bAHIeg7iOlTL6UMqkUoraV2v+jy+01HsOEu6fvOXXb048IdZce01Cij/hvp1pa
L9ps1+bWNRmYWyuw8/jDBDl1Vjn+21RCnTsbnarb/224gzKXpMdnneO6U22NE/aa/u5EWaT6Epsh
gzHTqbP2a0zndhfmYqA/3lQfUmOiCLSCjc4lq7FOYybXWA11myqH/z5BrxmYNXE6XiunTg7m2ts3
ArVLEWBgSpE9qN2lBDm3uM6d2S+1N5VAc7U1RJay2IzHdhDyVYe5xnPOoFwzLmv0mTKZc3/b8/dV
QG5cOMXALBnHFKM5Z8T3cL6WyG+Mtejh58a95e8pc2tuPSs6SI1vIsDAbMIWp9JSQpsyMOPeD886
rhmUpbZSF5S5M585AzP++1x/46jy+54snTmmjncq6c0l4r7s0ln/tf4t9fvasaNpMBXrU31cmkfj
mJsrj3/+CFhan67F+hrDOKdx/hFpMRcBBiYXyRu1s7TwbjUdU8l1a1tLZ71bk+mNkCcf9tqCmGr2
xvpeS5ypHJdiJuVMv1YTsxSLqbpMmXD8k6fGqoJLmi2Z1NR4rzWmV8FsrDADU7mgS5NzjenoE+7a
hXhqMd/TVkrduQQSRc6lRXc4xvFZ4rBuqoGZioM5jksxk5rEa13wrxm0a7pMmfrUtq5pOo7l1vmv
naNLc2kNv5S5FX1tWcuv5fIMTOXqLiWjJQPTf34tAY4n/bVdgGtJcyo5LLU9tXj17UROoEuL7pDh
3KK6lPTmOExpsFaXaztwYx1rnELX2I3nxDChzRmcMa/xHMF/e5Rcm+dLc2DN3BrqHnlt2U6yvZoM
THuaGlEFBJYMTgVDaLKLEleTsj4MirbtacvAtKepEVVAgIGJKZIkF1OXHL2ibQ6KsdpgYGLpoTcI
IIAAAgggkECAgUmApAgCCCCAAAIIxCLAwMTSQ28QQAABBBBAIIEAA5MASREEEEAAAQQQiEWAgYml
h94ggAACCCCAQAIBBiYBkiIIIIAAAgggEIsAAxNLD71BAAEEEEAAgQQCDEwCJEUQQAABBBBAIBYB
BiaWHnqDAAIIIIAAAgkEGJgESIoggAACCCCAQCwCDEwsPfQGAQQQQAABBBIIMDAJkBRBAAEEEEAA
gVgEGJhYeugNAggggAACCCQQYGASICmCAAIIIIAAArEIMDCx9NAbBBBAAAEEEEggwMAkQFIEAQQQ
QAABBGIRYGBi6aE3CCCAAAIIIJBAgIFJgKQIAggggAACCMQiwMDE0kNvEEAAAQQQQCCBAAOTAEkR
BBBAAAEEEIhFgIGJpYfeIIAAAggggEACAQYmAZIiCCCAAAIIIBCLAAMTSw+9QQABBBBAAIEEAgxM
AiRFEEAAAQQQQCAWAQYmlh56gwACCCCAAAIJBBiYBEiKIIAAAggggEAsAgxMLD2a7s0/+Id/cnn0
6FG2d9eeFwI1E/iTf/S5bPOhm1tde14InIUAA3MWpQOMs1tgP/HG97K9u/a8EKiZQBfDf/vTz2V7
mxM1R4O+ryUgA6wlpvxmAgzMZnQqNkqAgWlUWMM6hAADcwhmB+kIMDDiAIGPE2BgRAQC2wkwMNvZ
qbmSAAOzEpjizRNgYJqX2AALEmBgCsLV9Ktnm+6BERUI/IEAAyMaENhOgIHZzk7NlQTswKwEpnjz
BBiY5iU2wIIEGJiCcDVtB0YMIHCNAAMjPhDYToCB2c5OzZUEjtiBeffddy9f+MIXHt5f+9rXLt/5
zncuv/nNbz7q6Re/+MVXPn/x4sVHn3d1+vpvvvnmQ/1f/OIXK0eqOAJpBI4wMMM50cf0r3/96486
2MV3F/fdaxj/Xex3dYevYdm0ESqFQDkCDEw5tloeETjCwHSLbmdAfv7znz+8uwW7+3f/+uxnP3v5
wQ9+8NHn3f93f+sX9K5sV6ev37U3/JyoCOQkcISBmZoTXUz/6Ec/ehhKZ/B7ozKM/87Yd4ZmGP/d
vBjOp5wstIXAWgIMzFpiym8mcKSBGXayW4CHBqZbhIevbkHuFvnuNfz/vkxviDYPXEUEZggcaWCG
XejMS29Exgamnwt9+c7Q9zs0DIxQjkSAgYmkRuN9OdLADHdgustGcwam2xLvDE5/mWhsYLrFffh5
4xIZ3sEEbmVgumH2xn5oSqYM/PBzBubgAHG4qwQYGAFyGIGjDEy3MHdnkf3W+djAdJ8P3/1Wer8D
033W1ene3f93Z6BeCJQgcGsD0xn3FAMzZXZK8NAmAmsIMDBraCm7i8BRBmZ8jb7b/u6v8XcL8fAS
UvfZ0KBMnYHuGrTKCFwhcGsD03VtycB098L0c8oOjHCORICBiaRG432JaGCGW+n9Dsz4HoDGZTG8
GxK4lYHpjPvUfS1Tl1C7v3U3u4/Nzg2xOTQCDwQYGIFwGIGjDEy3y9J/Fbr/bz/I8Q5M9/fuUlG/
QNuBOSwcHKhbgA/4Ner+m3TDOTG8rDregRnOn/ElVDswwjYSAQYmkhqN9+UIA9PddNvfwNv9d/wM
l/E3kDrkXZ2+XPff4XNjGpfE8G5M4AgDM54Tw2fA9MMfxv9w/kzh8VykGweNw39EgIERDIcROMLA
HDYYB0IgA4EjDEyGbmoCgZAEGJiQsrTZKQamTV2NajsBBmY7OzURYGDEwGEEGJjDUDtQJQQYmEqE
0s2QBBiYkLK02ak/+tSnHm5azPXu2vNCoGYCn/r7fy/bfOjmVdeeFwJnIcDAnEVp40QAAQQQQKAh
AgxMQ2IaCgIIIIAAAmchwMCcRWnjRAABBBBAoCECDExDYhoKAggggAACZyHAwJxFaeNEAAEEEECg
IQIMTENiGgoCCCCAAAJnIcDAnEVp40QAAQQQQKAhAgxMQ2IaCgIIIIAAAmchwMCcRWnjRAABBBBA
oCECDExDYhoKAggggAACZyHAwJxFaeNEAAEEEECgIQIMTENiGgoCCCCAAAJnIcDAnEVp40QAAQQQ
QKAhAgxMQ2IaCgIIIIAAAmchwMCcRWnjRAABBBBAoCECDExDYhoKAggggAACZyHAwJxFaeNEAAEE
EECgIQIMTENiGgoCCCCAAAJnIcDAnEVp40QAAQQQQKAhAgxMQ2IaCgIIIIAAAmchwMCcRWnjRAAB
BBBAoCECDExDYhoKAggggAACZyHAwJxFaeNEAAEEEECgIQIMTENiGgoCCCCAAAJnIcDAnEVp40QA
AQQQQKAhAgxMQ2IaCgIIIIAAAmchwMCcRWnjRAABBBBAoCECDExDYhoKAggggAACZyHAwJxFaeNE
AAEEEECgIQIMTENiGgoCCCCAAAJnIcDAnEVp40QAAQQQQKAhAgxMQ2IaCgIIIIAAAmch8P8AiSr/
Yj+gcLQAAAAASUVORK5CYIJ=

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image010.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODdhMAJAAXcAACH+GlNvZnR3YXJlOiBNaWNyb3NvZnQgT2ZmaWNlACwAAAAAMAJAAYYAAAAS
EhIEBAQMDg4ODw0VaXsBcokwMDAoKCg4OzQgICAkKSoqLSY8PDwlJSU8WV4yXWYoYWxAQEBQUFBI
SEhOWVtTVFVNUElRUVFdZFNMYmZkcFNiZV54eHh/f39lamtgYGBsc3RoaGh3enN0eG5nZ2dwcHBj
Y2N0dHRslDZmhD19viZyojCfn5+Hh4eMj4iGi4yYmpSPj4+UlJSFhYW/v7+np6e9vb2ysrKjpaCv
r6+jo6OxsbHAwr7X19fIyMjf39/T09Pe3t7LzcnZ2dnMzMz+/v709PTk5OT6+vrz8/Pm5uYBAgMB
AgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMB
AgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMB
AgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMH/4BGgoOEhYaHiImKi4yNjo+Q
kZKTlJWWl5iZmpucnZ6foKGio6SlpqeoqaqrrK2ur7CxsrO0tba3uLm6u7y9vr/AwcLDxMXGx8jJ
ysvMzc7P0NHS09TV1tfY2drb3N3e3+Dh4uPk5ebn6Onq6+zt7u/w8fLz9PX29/j51wD8/QCE/xQF
FOiP3yODpgoiHDQw0sCGkCDqm0iRk0SJiTAWuthIYyiOBxl5PDSyosmTkjCWZCiSZEtUKkMuWgkQ
pc2bk2IaaeiPZc2NiHgu7CmoX02jDJEm1ci0KECkPf8ZfLhz4c6jRiEqvboVp1d7Oqn65Omy7FWn
aNM+FEtWrVmgZ//jnl3rs2rdtmLdFs37ta88kHF1yv1pKKBWvWN/Ck5bFy7fu4QPyzUMWTFhv5jd
KWw7GK3HpoMpM55ruTDcy6U7B47sOPVj0aMzy0bHmTFRrp+D7i2oVqHtpWt5n24NvDJiz64bk1Y+
uzk5ybE9iyYKGrTqyWVXVte92jjyxMeXR3dO3hv067Cts06eWjXs2IK3/x79Pr3y+uXzhwPMF7/p
4d1hd5x/AaImoID9JWUcQgkOqN+D3YT11FAAViXcRlZplWFkXXUFXIcTBnegVFZZONdUGNZGE4Qs
tujiizDGKOOMNNZo44045qjjjjz26OOPQAYp5JBEFmnkkUgmqeT/kkw26eSTUEYp5ZRUVmnllVhm
qeWWXHbp5ZdghinmmGSWaeaZaKap5ppstunmm3DGKeecdGYTwGZ45qnnnnz26eefgAYq6KCEFmro
oYgmquiijDbq6KODHgDMinVWWgqlsWBq6aafaPqKp5yGmgmorZAq6qk5TYrqqqOYuoqrrMaakaqy
1qoJrKngaqutup7S666x/nopsMSm+ouwxYqKbKvJNtuRK0KJyJyz1E6bUF5SeVfttteRkq1b2HIr
brfDgutTBwBIoO667Lbr7rvwxivvvPTWa++9+Oar77789uvvvwAHLPDABBdscMHLRgSZWD4AUMPD
EEcs8cQUV2zx/8UYZ6zxxhx37PHHIIcs8sgkl2zyySinrPLKKics02rhjruty46EG7PM1NL87FI8
W4vzrjp7EvTPaA5tEdHOGr2J0kiPyfSoTSf7NCZTR+1l1ZZgbfWWWlPS9dZYfp0S2EDPotRWYpNN
Zdrmhqc2qmzDrO3bp8ZNlVgtAODB3nz37fffgAcu+OCEF2744YgnrvjijDfu+OOQRy755JRXbvnl
lsdt4bdn5Y3556CHLvropJdu+umop6664ZqzdDPdcMty99ywc6r52RvWHvuxPx9hw+/ABy/88MQX
X/wNXbb+ksw2PBDB89BHL/301FdP/QTJ08p8BAZ07/334Icv/v/44mPPpfIz/WwD9+S37/775nOt
/bjrv2///d/HryX6AqnPPv4AbJ/+ssS/WeGsfgFMYPmyx7sD/k+BEDTAAMM2P3EhMIIQnOCVbjeU
3G0PgxHUoJXs5jraVeuCIAygCKtEQqcwzGEsi6EMZ0jDGtowYy54YArxN4Eb+vCHQPQhB+1jBHQd
7IhITKISl8jEelFAhzu03wSaSMUqWpGKLeSKCamFwihKkYGwmJ3bttVFL7pvhWuTXQnHeEIompF8
aJzSEHs2Hi668Y0LPF8FYfGDCfjxj4AMpCAHSUhCfgBGZcRjHuXXwFkkUpHgi6NzHglJ70kySgXk
jiPvWMnuXXL/NpTs5CeflMm3xCKUlRxlZlAJSVU2qZT/2WQn4YhITooSjL1QHisV6Uq/7BKPvVwS
LCv0il++MZhfMaYZkZmkYRqomLZMZS1nOT5mIslu1PGgLJTpRWvehJtR9KaRlEdEcq0CnDsUJ0rQ
mUJ1EomcegECDINosRxSs3z0zKc+Q2bPe0ZynwANqEAp1rqYgSBdV5TXE/0ZyYQ69KH8WihDLQnR
ilr0ou8q6IJqwU4QutMkHcXgR4V0u/WYUxUhDeE0J+pJXH7KpLqMZitXytKRaiIIOM2pTnfK0576
1KdIEEdJJ/RMV6Q0gzSdqE0xgYMKaOCpUI2qVKdK1apS1QJC/90jNFna0hcdVYFLvcRXExjWYTjT
Z6wYqwqTytCyVkKtAHRrMM5ax7TKlJds9adcJwFXHma1kdu8KzDzes+9SqKv9zOsL+h60lQg9ote
FewxOSrZZf51sZTlqgQJS03FQuKx8LtsLjPLVc/KA7RnJG1NRcuLmGrWtPFArQBVq1TWQquDtTll
ZbvJ2VnCthGypeV+1OjCLdr1tb29JS2CW03bsgI6j4EFcxfZoumG77eMsG4knfsqqPhkApAyFAJ2
G87wmve86PXTeF+bXkCtt7Ttja+hiKtFNrZCu/lLrjSXS950clcVYiyQbpEbWQLLsrT/zdUaBSzd
/rZTvzPlr/+BvzHH3RT1vg72KIR5WcgOe/jDfswBIvBryQTbwrUILnBpV8DiFrv4xTCOsYxjnIIX
jDjDIjVxLVC8WhXXdMZADrKQV1DjG0/YPFo1Ko5V6mOlDvnJUCayjQ9B4q6Cg7E8rm2T2xrlLgO5
yFReMlKHC9gBp3gWQgiBmtfM5ja7+c1whjMMaMtlL9v5xWA2RJU3S2bMSvjM24RAAQZN6EIb+tCI
TjSisbuIPU/gzpBmcZ4L4Wgd0yLLbaWzXjVd2EhDetKEqHSfR/vnHh/Y1IF9rafvDOpBiPrKZoOK
Ns2Malpr+dROXrWXWy2IV1PYbDDldGeF7Vtii1LXu56ynsX/DFZLl2ujpb51qgFt6zojG8q8NoKv
kZwp76JFBAjFqAQkWlNxq4vcSjX3uJlN1mtHOQUXgBe626ruh6KPcwFp2EAh1s+a7vth/Vbqv2sQ
cGu7W8gpGEHFCq7Xgevz3gHC9KajnWmK6/XgT872tiNEX3yj9ZzsXqvFC2vsVGJ8yBoPeVydfSnc
Xvi41G7wkWW+4pMHOeUz5waWSx5hXFfc5xe3+ZeVTWmV+3XUreU5Xkc+bKb7VuhDN3LMdZ5kDOdc
yVe3es2hTmOih9roiWV5ppQ+WKcrF+id5nrXpV5rjpeZ5m3f6tSxvnW1uxjnc9fGzs2+X7Q33e9P
tzueve5q/7BDFtZvl3tNf8r4xjsep0lgu7SrHXTBtxjvcd/G3gEvyg14/vOgD73oR0/60WcgBpL/
+bR/bPnLE77Xhg8t0sNIx8aiwtGtd33qJ855k+deyrsvLAmGT/ziG//4yE9+8oew40uXU+Jpzz3m
Jw/3XEv/9dqO/RlZwP3ue//74A+/+MOvAuyXCtjPJ/sxfw/8ML9W+fCPv/yH34Pgd5b90ze45bN9
fjUS0XOrEzgloH0ChH8cIIAECEfjt4AM2IAsoAIHCDgDqGq/lwIR+DcTWHf7d4EB6DctREQ6oDcd
iIEJWE0GiIAUKH0c2DcZyHoqiIIaKHgWOIJ/g01ZYVwgl/+CrZd/lbeD2Id7FfiDJVg++Gd+z9V8
Ead+y1SE9hd419eExxaEUOh7T3hpSGgiH4dSQ3hdTOh+MWh3PBh9PjiFrdSFwJZ4dOeCY+iFarh/
QqiDbkiGvGSG9EVqvVeGUsiG1reGywaHMviGX6h2/HeEaKh1bfiHcghMdPh1fgiGgHiIjniFdrh6
exiHeqh/iHiJPWiJfRiIXDeIr1J1MAeJgviIlZiJnUiKn2iKmBiJVliIo3iKrpiKsliKibh+eUiL
rWiLr+hndziHuVh0jciLuriJqCiMngh1oAhgopiDySh0YXh/wciIz2hz0eiEfFiHn+JyWehYWxhJ
i1h4w7j/ire4hNMojtV4csuoYGNXXPYVi7tIjpoohpyIjKqojKxojLOojWP3OpRHj8dIjfcIjfkI
kPsokLUoj2coOyAogjTINy2YkMq4ghD5jflzghJokZaEkSQ4jhP5kH0DcWIhAw4JkhEZjx+ZkR4J
jRS5Nyepj4LYkh7wkgYZkyDJNyKJg1q4ktZYkNJYhcVYkwppjxJJkJIILQsWXYpXlD1Zjt0UjrDH
k+rok9hYj+3YbdJSV844kE05jz+ZjQiJkkbplVUZkLQHi1vJlFPplOEEldknlRh3jVEIlPyoC9D3
lVaJjly5lmQ5l2Cpl2oZl0YYimi5k+komGyZTm4JhHQZ/5YwOZRXOYn/iJdmGZWHeXBySYV/aZl7
iZi9KJnVJ5ZdGZSUeZCAKZp8SZplaZovVZjeCJeYSZV+mZecGZixmZjt5Jb954uUiJqeqZqzWZlv
eZnulpl42JhnyZuTuZrESJS+eZt9qZm0OZydCZ0LCZpL+ZzFKZvSKZyMuZnUaZvbeZS3lZW2dwrf
OZ3p6Z0a6UmL2Z4SpJuEmJwep5WGWZ3jGZ3HCZ7ryZrhqZ3Xto4wcWLdIU8Dx3BCqYwKRzEIWpqC
uKAT06DM+YkQKjESGpxgWKEClZNoYQLhhlHz9pjKGG/vEqIJCo0k6i4m6qCfmKLtsqITOqLqBk9J
yHf7qf+e8Plo51ibAIpsxgmMyNmaHaeTr0mcAcqdN8qesJmfwNmd/rmbyVmjv6iIO/qfIjqWTZqk
/tmfzRmZ5ckgsxaaVzqazjmmqVmmJ0qmjpmmZ+qlu3CXMYqlaMqi+IibHvWeS3qk5GmXSviUVcql
kHmaZvqbcxqnahqlSWejQMqfOYqnRuqjSLqo0wmliTqluBikVsqmhLqmdCqnnGqobYqob9qnbfmn
jWqqeQqpdipS8kmYyimmmmqdhYqhXSqoscqks+qktSqk2JmG4qmn+impSvqouvajVIqplDqqinqs
jJqqxRqpzIqjzrpqAuorn4k2pKqYqEqs1Aqtl9qs3Or/adWaELEGbZZqjpgKqHUarNE6rPgJrNeJ
lDcDp7QaqDw6qLL6qfW6rlkqrE86n1cpFhIgX+p1qtKXAHjyXu/qowi7GQr7qwybsAa7gw1LsHvS
i/4Iq516qPd6q/Caq1q6q5m6saHKq/RJpLc3sdIarpFmrN+6sgv7rHu6mxmbnfiKq/qqq/Y6sqC6
qbZKsj5rsryKrcv6su4KsTLLrka7pSornMnKp0WLruAas926qiHkqFQrroPJjK6ZstOqtVabQViL
tFWrtFI7qQBbqb15sx+bsyG7s+rqqT/bs/kqqlB7rn6ark3LtF/bst56tk6btsqKt6Wqt337aX+b
t1NL/7Zg+5lqu5z7KrcdC7R1O7l0i7NzG7kci5Rdi557K7Jxu7mhW7I8q7mk+7S5QK86y68g66+g
+7lwC7us66axllsae7ltm7mrK7mlu7uiK7u8i7ona59FmrV+G7ZgNbY9mrT92q7/6qpXqJS+urxl
27xL+7qHy2qJW7jgKbxCGhADa7HiO77kW77me77om77q2ygCgAt5oQDiAL/hIL/gQL/fYL8vIr26
s78KQ7z8+79BUSLCkBv9W8AEGhI08R6tJcDGwlgz4SE1UynqEcEO4b7nSSkOzGBj0wz62z91QiJg
mi2G4XI3WJ9ZgSLFNcJP43EMYhf1hTsgfCIqbJ7sWP9C3PgtJ4zDIUzD0WthPkwi0pHB+dsdI9w2
L2wfYnQ35eQtgUEZLSzCSUkaAVafXOs6TmzFbcPCUWzB7lhfuJHC3eg0RGwbsgYecpMcwcHAnWLG
Wsw5xXHFXVzElMrCUREiUrzFaly7M6zFKXwbbWLCiIEXgRwaRlw1wjHFWgRddxzHL8csR7FggwzH
Xmy7jqvIsyPEMQLIRMzHbMHJeyGlonAYT3zFnIzDZzzJNPvJqNzJi7zKYQy9pwzEifzKYaLJQiHD
n3zLKqzKKBIt5PrIo+yOuPPFu7zJYnM2LoyFumwXxdzJpXQRN+zCxQzAXEzLz4DJdUnNkonNtwIW
2vz/zeAczuI8zuRczuZ8zuiczuq8zuzczu78zvAcz/I8z/Rcz/Z8z/icz/q8z/zcz/78zwAd0AI9
0ARd0AZ90Aid0Aq90Azd0A790LiwAIOyAEjCAIPCABBdCQCgQNysDgBgZx2tzRudQCFNGyCd0V7D
0dd00iidEip9JB/tZSUNwCMdQDNtDjHdZTfNvzUNQDv9HCzd0hHx0uMU1EJdM0RtBDPQAA1wAjSg
BIKAAUzt1DUgCCfA1ChAA0TgIjkdZQ2x1A2Q1UsgCERwAkZw1Q1AAzMwCGXN0D2NPw1BAw1QBEWA
Ag0gCA6wA3S9Aw4w1mFN1zTQ1y3S1VAW13Nd1w7A/wNGoARr/dc1cAKCXQR3vdBvfT+GPQgOgNdF
MAhpbQSdLQhzPdhGLdeDwAN3zdieTQODgAJmLdlundRyTdcogAGaTdYOsNWfrQS3LdoyTQikjdlG
4NqfHdx37dqUDdsOQANyTdtG4ADO7dyK7dkOgAEY4AAowNWjPdl4TQTCrdqCUASZbdwKXdn2c9lW
vdYOsNlnfd2pLSOE/WTmjdfE3d6CUAPFrd0JTd7vE98ngN7q3dyg7d0w8t5Dxt+tfde53QA7MN/H
TdK+7QBMzdS1HdULPtz5O9oQztTMLdwZbt3fjd8Ird/u0xBKQNdFsNXfTQhKsNVEANWZbNQlTtdj
zX/WRsDddF0IKD7eSf1ORn3UIrHjQ0LgQvbTuiPi7UPkQtXjPq4IAzAoA4AkBDAoBLDkVF7lVn7l
WJ7lWr7lXN7lXv7lYB7mYj7mZF7mZn7maJ7mar7mbN7mbv7mcB7ncj7ndF7ndn7neJ7ner7nfN7n
fv7ngB7ogj7ohF7o6BAIADs=

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image011.png
Content-Transfer-Encoding: base64
Content-Type: image/png

iVBORw0KGgoAAAANSUhEUgAAAjAAAADcCAYAAABu6Ju/AAAAAXNSR0IArs4c6QAAAARnQU1BAACx
jwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAAHOVJREFU
eF7tnTuvXcUVx697CDQpaBBFrKBEJE4R5SEKowjFAjtcwE+FRxKTIBEgtgJ5oEQuIpQUFClAiUQa
sBAVQjR00c0HQKKgoqTxF+AD7LAuWtIwmv2cWfPavyMd+d5z9qxZ81v/mfnvOcf2ieGLxwEPCEAA
AhCAAAQg0BIBMTA8IAABCEAAAhCAQEsEDlpKllwhAAEIQAACEIDA8adHYIAABCAAAQhAAAKtEcDA
tFYx8oUABCAAAQhAgBMYNAABCEAAAhCAQHsEOIFpr2ZkDAEIQAACENg9AQzM7iUAAAhAAAIQgEB7
BDAw7dWMjCEAAQhAAAK7J4CB2b0EAAABCEAAAhBojwAGpr2akTEEIAABCEBg9wQwMLuXAAAgAAEI
QAAC7RHAwLRXMzKGAAQgAAEI7J4ABmb3EgBACQJf/H9p8p+ofuVZIo9Qn5JXqsfSWEuvS5WXxCnR
Z8r8iQWBvRNIt1LtnSTjh8BCAmMbZ60bakxeatKm0Cy5xm8fk9NYLhYxF0qCyyAAgQ0EMDAboNEE
AlsJzG2Sc+9v7TemXUxOS8zJkmswMDEVpC0E+iSAgemzroyqUgJbzID7UdPU6UHICIT6c1/Tn922
/vtLPuqaO1Xa8v5Yv6HXS4+zUrmRFgS6JoCB6bq8DK5GAmtMjH/t3EYt4w0ZFJdDyKCMvb8knn9N
KNZaAzM3zrVclpi7OW5T46xRZ+QEgd4JYGB6rzDjq5LA0lOVUPJLNlptt9YIhDbpuf6mDNlU27H3
5szOXI6hsc9xWGLU1hjPKkVHUhDojAAGprOCMpz2CIyZmS0buT/6uY177v0lZiG1gQmNwT9B2XIC
M8dmLiYGpr25RcZ9E8DA9F1fRtcYgdDHO/53PuZOREIf4Yy9ltPAuGZoiVmYMi1z7becqMzFxMA0
NplIt3sCGJjuS8wAWyKwxpyETkfmThlSbOxTRmSufx3flFnYcvI0Z8Tm3h9jOZZvS5oiVwj0SgAD
02tlGVeVBObu4pcYmCXX6ODnNu6592M39jGjgoGpUp4kBYGmCGBgmioXyfZAYMkJw5gBWWs4QkZh
zgDNfZQScwIzZ4im3p/Ku/Q4e9AlY4BAawQwMK1VjHy7IDD1vZbQxzD+90HWXOP25RuEpYYo1P/c
adISszJl1ObyDn1Hxn1ti1HbOs4uRMkgINAYAQxMYwUjXQjUQmCJgakl15g89jLOGEa0hUAJAhiY
EtTpEwIdENjLxr6XcXYgSYawMwIYmJ0VnOFCIJbA3MdZsfFrab+XcdbCmzwgsJYABmYtMa6HAAQg
AAEIQKA4AQxM8RKQAAQgAAEIQAACawlgYNYS43oIQAACEIAABIoTwMAULwEJQAACEIAABCCwlgAG
Zi0xrocABCAAAQhAoDgBDEzxEpAABCAAAQhAAAJrCWBg1hLjeghAAAIQgAAEihPAwBQvAQlAAAIQ
gAAEILCWAAZmLTGuhwAEIAABCECgOAEMTPESkAAEIAABCEAAAmsJYGDWEuN6CEAAAhCAAASKE8DA
FC8BCUAAAhCAAAQgsJYABmYtMa6HAAQgAAEIQKA4AQxM8RKQAAQgAAEIQAACawlgYNYS43oIQAAC
EIAABIoTwMAULwEJQAACEIAABCCwlgAGZi0xrocABCAAAQhAoDgBDEzxEpAABCAAAQhAAAJrCWBg
1hLjeghAAAIQgAAEihPAwBQvAQlAAAIQgAAEILCWAAZmLTGuhwAEIAABCECgOIHmDMyZM2eGo6Oj
4uBIAAJKQPSIJtFDTQTQZE3VIBchYKHJ5gzMwcHBcOPGDRQBgWoIiB7RZDXlIJEvCKBJZFAbAQtN
YmBqqzL5NEfAYmI2B4GEqyKAJqsqB8kYmWoMDNKCQCQBNotIgDRPTgBNJkdKwEgCFprEwEQWheYQ
sJiYUIVADAE0GUOPthYELDSJgbGoFDF3RcBiYu4KIINNTgBNJkdKwEgCFprEwEQWheYQsJiYUIVA
DAE0GUOPthYELDSJgbGoFDF3RcBiYu4KIINNTgBNJkdKwEgCFprEwEQWheYQsJiYUIVADAE0GUOP
thYELDSJgbGoFDF3RcBiYu4KIINNTgBNJkdKwEgCFprEwEQWheYQsJiYUIVADAE0GUOPthYELDSJ
gbGoFDF3RcBiYu4KIINNTgBNJkdKwEgCFprEwEQWheYQsJiYUIVADAE0GUOPthYELDSJgbGoFDF3
RcBiYu4KIINNTgBNJkdKwEgCFprEwEQWheYQsJiYUIVADAE0GUOPthYELDSJgbGoFDF3RcBiYu4K
IINNTgBNJkdKwEgCFprEwEQWheYQsJiYUIVADAE0GUOPthYELDSJgbGoFDF3RcBiYu4KIINNTgBN
JkdKwEgCFprEwEQWheYQsJiYUIVADAE0GUOPthYELDSJgbGoFDF3RcBiYu4KIINNTgBNJkdKwEgC
FprEwEQWheYQsJiYUIVADAE0GUOPthYELDTZnIG56667hmeffXZ49913u3i+8847w1tvvdXFWKZq
0vM4RY9LNPn2229XXedPPvnEYt0iZgECFptFgWHQZUcELDTZnIE5PDwc/v7mi908f3/j6nDp4vnh
sR/8rOvno6cfGX5+4dzw7t/u3e3z0vlzwz8ef3j49/kz1T3/ef6h4Zmnnuxoudz3UCw2i30TZfSx
BCw02aSBObr12tDL8433Xh6uXLgwnL/7bNfPx753bvjNEw8Nw4cndvt8+srDw9HFB4fPLj9Q3fPj
Sz/BwMSu0BW1t9gsKhoeqTRIwEKTGJjCZggDsx9Dg4FpcNVtNGWLzaJRFKRdCQELTWJgMDBZTn44
gTkxYGAqWUl3kIbFZrEDbAzRkICFJjEwGBgMTKaPtTAwhqsjob9CwGKzADEEYghYaBIDg4HBwGBg
Br4DE7M019fWYrOob5Rk1BIBC01iYDAwGBgMDAampZ1gQa4Wm8WCbrkEAqMELDSJgcHAYGAwMBiY
zjYei82iM0QMJzMBC01iYDAwGBgMDAYm82Ju3Z3FZmGdM/H7JmChSQwMBgYDg4HBwHS2d1hsFp0h
YjiZCVhoEgODgcHAYGAwMJkXc+vuLDYL65yJ3zcBC01iYDAwGBgMDAams73DYrPoDBHDyUzAQpMY
GAwMBgYDg4HJvJhbd2exWVjnTPy+CVhoEgODgcHAYGAwMJ3tHRabRWeIGE5mAhaaxMBgYDAwGBgM
TObF3Lo7i83COmfi903AQpMYGAwMBgYDg4HpbO+w2Cw6Q8RwMhOw0CQGBgODgcHAYGAyL+bW3Vls
FtY5E79vAhaabMrAnD59ejg8PByOCpuOlP2/8d7Lw5ULF7KYiPN3ny3WD/8bNf8bdd/Lc12js9gs
6hoh2bRGwEKTTRkYKRgGppwJiTFAGBgMTGsLbsv5WmwWLfMg9/IELDSJgSl8msMJzIlhyPQRTul+
nr7y8HB08cHhs8sPVPfkf6Muv8CnzMBis0iZH7H2R8BCkxgYDEyWj5U4geEEZn9LdrkRW2wW5UZD
zz0QsNAkBgYDg4HJdALECUwPy3AbY7DYLNoYOVnWSsBCkxgYDAwGBgPD30KqddXfmJfFZrExFZpB
4JiAhSYxMBgYDAwGBgPT2SZjsVl0hojhZCZgoUkMDAYGA4OBwcBkXsytu7PYLKxzJn7fBCw0iYHB
wGBgMDAYmM72DovNojNEDCczAQtNYmAwMBgYDAwGJvNibt2dxWZhnTPx+yZgoUkMDAYGA4OBwcB0
tndYbBadIWI4mQlYaBIDg4HBwGBgMDCZF3Pr7iw2C+ucid83AQtNYmAwMBgYDAwGprO9w2Kz6AwR
w8lMwEKTGBgMDAYGA4OBybyYW3dnsVlY50z8vglYaBIDg4HBwGBgMDCd7R0Wm0VniBhOZgIWmsTA
YGAwMBgYDEzmxdy6O4vNwjpn4vdNwEKTGBgMDAYGA4OB6WzvsNgsOkPEcDITsNBkkwbm5v/+OvTy
fPVfLwyXL1wYHv/Wub6fP3pk+OXls8Mn//n6bp9PXDo73LxwZvjvxQere75/8afDM089mXlJozsr
AhabhVWuxN0HAQtNNmdgfvjj7w+/+NWTw59eebmL50t/uD789rnnhusvXu/6+cJzLwzXnv/18Jc/
Pt/d85mnzw/ynBvbyy9eHf587XfDK9evVfl8+80397GS7mCUFpvFDrAxREMCFppszsAcHBwc/6+W
PCBQCwGLiVnL2MijTQJoss269Zy1hSYxMD0rhrFlIWAxMbMkTifdEkCT3Za22YFZaBID06wcSLwW
AhYTs5axkUebBNBkm3XrOWsLTWJgelYMY8tCwGJiZkmcTrolgCa7LW2zA7PQJAamWTmQeC0ELCZm
LWMjjzYJoMk269Zz1haaxMD0rBjGloWAxcTMkjiddEsATXZb2mYHZqFJDEyzciDxWghYTMxaxkYe
bRJAk23WreesLTSJgelZMYwtCwGLiZklcTrplgCa7La0zQ7MQpMYmGblQOK1ELCYmLWMjTzaJIAm
26xbz1lbaBID07NiGFsWAhYTM0vidNItATTZbWmbHZiFJjEwzcqBxGshYDExaxkbebRJAE22Wbee
s7bQJAamZ8UwtiwELCZmlsTppFsCaLLb0jY7MAtNYmCalQOJ10LAYmLWMjbyaJMAmmyzbj1nbaFJ
DEzPimFsWQhYTMwsidNJtwTQZLelbXZgFprEwDQrBxKvhYDFxKxlbOTRJgE02Wbdes7aQpMYmJ4V
w9iyELCYmFkSp5NuCaDJbkvb7MAsNImBaVYOJF4LAYuJWcvYyKNNAmiyzbr1nLWFJjEwPSuGsWUh
YDExsyROJ90SQJPdlrbZgVloEgPTrBxIvBYCFhOzlrGRR5sE0GSbdes5awtNYmB6Vgxjy0LAYmJm
SZxOuiWAJrstbbMDs9BkUwbm9OnTw4kTJ4aDgwOeMEADaAANoAE00JAGTp06ldSANWVgZOT33HNP
UgB7Dfbxxx8Ph4eHex1+0nFfu3ZteP/995PG3Gsw5neayjO/03CUKMzvdCxTR2rOwKQGQDwIQAAC
EIAABNojgIFpr2ZkDAEIQAACENg9AQxMIxIIfe8nderShzz0z9TxidcGAV9rmnVKXcTGSq3V2Hza
qGzfWbq6XTJSt+ZL67/0urn+U8WZ66f39zEwjVQ4JPjUkyB1vEbQkqZDYEpnKfURGyu2vV/01PEQ
VV4Cfv2W1HPJNVajKNm31ZhKxMXAlKC+oc85AzN297Hmdf+uduxOXE9p9P0Nw6FJpQTGFtaQjuZe
C20qoZOTsTj+aaCrtzmt+nfXIa2G4lVaFtKaIDClWVdDfr3X6Mk/hfTXRvRWRqIYmDLcV/camjCh
zcCfsG5HS69fep0/qVcPigZVEhgzpv4ivUVbrvn1DcrYZrPEyIRymYvv6pc74iqluCipJQYmpN2x
18ZMdkhPIW3OzQtu/BaVddFFGJhFmMpfFJqkY64/9Lo/qXxDFDI+oTtodwMK3TmXJ0UGqQj4C+3Y
icrUScacGQ7pacp4+KZ5TKO+OfG1OtcuFUPi2BNYYmCWmIopM7JEx1NrI3qz0QEGxoZr8qhTBmbJ
5Ji6ex7bFKYMTPIBErBaAlN3pEsNxVItrdko1hgdH+6SOVNtQUjsKwRqMzCh8qA3G9FiYGy4Jo+6
1MDE3A37m8faTSf5oAmYncAanfmnHFOGYuxUcMnroTvjJaZqSz7ZgdNhEgJTBmHsJDF0Uzd2o4fe
kpQpeRAMTHKkNgHdI3B/QrpHl2OLfWiCz03sJYvC2N2PDQWi5iDgay1kVMY0t0QzSwzJmJEaM9lT
88N9z+U3ZfZzcKaPtASm6uzrdYl+pwwOektbu63RMDBbydEOAhCAAASqJ8BNVvUl2pwgBmYzOhpC
AAIQgEDtBDAwtVdoe34YmO3saAkBCEAAAhCAQCECGJhC4OkWAhCAAAQgAIHtBDAw29nREgIQgAAE
IACBQgQwMIXA0y0EIAABCEAAAtsJYGC2s6MlBCAAAQhAAAKFCGBgCoGnWwhAAAIQgAAEthPAwGxn
R0sIQAACEIAABAoRwMAUAk+3EIAABCAAAQhsJ4CB2c6OlhCAAAQgAAEIFCKAgSkEnm4hAAEIQAAC
ENhOAAOznR0tIQABCEAAAhAoRAADUwg83UIAAhCAAAQgsJ0ABmY7O1pCAAIQgAAEIFCIAAamEHi6
hQAEIAABCEBgOwEMzHZ2tIQABCAAAQhAoBABDEwh8HQLAQhAAAIQgMB2AhiY7exoCQEIQAACEIBA
IQIYmELg6RYCEIAABCAAge0EMDDb2dESAhCAAAQgAIFCBDAwhcDTLQQgAAEIQAAC2wlgYLazoyUE
IAABCEAAAoUIYGAKgadbCEAAAhCAAAS2E8DAbGdHSwhAAAIQgAAEChHAwBQCT7cQgAAEIAABCGwn
gIHZzo6WEIAABCAAAQgUIoCBKQSebiEAAQhAAAIQ2E6gGwNz33e/PRwcHCR7Sjwe/RC49+S9ybQh
OpN4PNojcOq+byTVgcTjUTeB79z7zaQ1l3g86iDQjYGRTeXo1mvJnhKPRz8EpJ7n7z6b7Ik+2tTG
cd0+PJHsiQ7q14HU6LPLDyR7UvN6at7NLo2BqUdUNWaCgamxKvlzwsDkZ166RwxM6QrY9Y+BGTm1
wWXbia5EZAxMCer19YmBqa8m1hlhYKwJl4uPgcHAlFNfxp4xMBlhV9wVBqbi4hilhoExAltBWAwM
BqYCGdqngIGxZ9xCDxiYFqqUNkcMTFqeNUXDwGBgatKjWS4YGDO0TQXGwDRVriTJYmCSYKwyCAYG
A1OlMFMnhYFJTbTNeBiYNusWkzUGJoZe3W0xMCsMzKeffjpcvXp1tqIfffTRcP/99w+vv/767LVc
kIdATgNzdHQ0PProo9EDc/UmupPfYx8p8orNoWT7nAZG5r+sA/J89dVXiww7lW6KJJ+o0xwGxq21
MJd6f/DBB4lG8NUwe5/DLg0MzAoDo8ZkTpWyYN28eXP4/PPP5y6dfT/lArRn4ec0MFIz1cBsgScu
cPUmC+RWPbl1L7WRxnBI2TaXgZH6iw6khvJUTaQcy1gsd82I0U2OXHP0kcPAyLySmmu9Zf0/efKk
iYmRuDy+JICB2WhgZDORxUFctuu25TUR2EsvvXS84cjvcucs18jvt27dOv5ZniJyfbivq3OXO3mN
JddJG5kgGss94fEXKvk9lJe2cTcy6Uee8vDz1df8fFubQDkNjCxkoVMYYSivy59u7eQ1qbnWTE9a
pgyMX1+ph+hJtSV60tqJhsbq7l8/pmuJFdJoizqw/ofspA6hmwUxFloH+VPnsm8qXc46L/35L7+r
llRX+pq7ZrjrwpK4ri57qPfxJpfhH7JTA+POB51b+prOWXfd9+uo81bnoc5p9zTHNTCuBrRta3My
Jl8MzEYDI4uPCElNhfwsG4883btv+VkWMzUd6sr1rkwXDG2jm5bEERG7saStHk/6p0Hq/kUM+vGV
XiPi13zlT3m4k8CdaH6+fqxW7+BzGRipp5hXrYO7qGj9tPZ6nTCV92SxklrJz9LOrfFcfSWG3vFr
DMlhrO5yjcZU0+1e7+taxyM5uhqNWXxKtM1xAiPzPfTxsWw2wlxZqtHVjx/UJOoaoXVUE+POf42l
d/y6/vhrhtZY9DQXd8maVKJmsX2WMjCuYR1bR6fmoeSt81Daq4nRtXusbSyvltpjYCIMjC5GrmnQ
n9UouBuPvCfGRDcn2cDUEKgZ8r/n4LZ3TceYgfFflwVNP3pw208ZGM1dY/nHoi0JXHPNZWDcekl9
1aT4plE3FHndv1PThS9kYMbqq4bX3dB07KG66+ap18im65oTfd39LteYRlvSQw4D48955TNmSFUb
elLrf/Sk37tz66inudLGnadj649ozNWimKZQXLlOT496qLfwyGVghJewk6f+rDcFoY+XtFbuKdvY
PHRP9VQHrilSDfinOy3NzS25YmASGhg1I/7dshoCKZAKXBcKbaNf2BRxSns1MrEGxhXFFgOj+Uge
ejqzRWil2+QwMFIzdxHThSxkJFxD4xsY/X2JgdHYejempnis1u7i5+oy1KcusHMaLV3bNf3nMDB6
SurnJaZBzYFvcvR3PY3T+SZ/hoyGGGB9T9uEbprcuO7pqast/2ZGb8zG1qQ1vGu4NpeBcW9o3XHr
Kahb0zEdjM3DUL3cePrz3v7iCAYmo4Hx755VrPp5p4rePZlZa2B0E9VY7vdb1hoYP5Ysmq1OkBwG
xj0y9k82XMMiP+tHjfKzb2BCd2Gqg7H6+icqcwZG+/DzDJ3s6cefbu1djdawSS3NIYeB0e+u+V+6
dmvkGxj92NA9GZExjc1f/0Rl7KZJX/fj6keOvi71uxxTa9JS1rVcV9rATK2jS+dh6MTMb7vHL2xj
YDIaGP3YQBcfPaLVO13dFGTR0c875Wf9QrC7KenCI+/Jxinv6R2Y/K53ge6i6fYn4pdrpL2fh3tn
7sfiOzBf/o/Wxxuh99BNyH1ZjnT1zsz9DoNbY72DVl3o9WMfOYTqqzrQkz3fwLgfVboGSjeyUJ/+
CYxqUTc5q78marnx5TAwkr/+LRR3TrtzR++Ylb/78Y7LWerofgdG2eiJm7Z357+7ZvjGRj/WdLU6
dgLTQ72FV2kDIzmMraN6IxOah5K3qx/9Pp3Wy20r142dAFnOp9KxMTArDIwu/Fo09/sq+h2EqWvk
PT3FkM3J/X6K3m2Ji3a/+Knfl5H3XWPhxtIvD7tikmv9WPp5uV4ni6wsjm4eoX9rRGOl+HdISgk+
xwmMXx8dq76um4Zwd1nqCYx7t+1rzGcfqq+0l9iuZlSP7veaNLZcpxpw6zKm6zGNlqrpln5zGRid
n25N3Hz1xkK/d+SPJdTO15fUSf/WoFszt/6+bjSuv1bo77IWuG3ken8d2cK9ZJscBsbnFhrv2Doa
mod68yK10DntryeqsdAcLsk7Z98YmJUGJmdx6CsdgRwGZi5b/wRNr/c/QpqLw/vbCeQ0MFNZ+h8h
bR8RLecI5DAwczmsfd//KHdt+71cj4HBwOxC6zUYmLGP30InL7soSoFB1mJg9vh9hQLlPu6yRQPj
fwepFLva+8XAYGBq12iS/GowMEkGQpAoArUYmKhB0HgVgRYNzKoB7vjibgzMHXd+7dhpp3pKPB79
ELj9ttuTaUM0JvF4tEfgzjtuS6oDicejbgJ33J527ks8HnUQ6MbA1IGTLCAAAQhAAAIQyEEAA5OD
Mn1AAAIQgAAEIJCUAAYmKU6CQQACEIAABCCQgwAGJgdl+oAABCAAAQhAICkBDExSnASDAAQgAAEI
QCAHAQxMDsr0AQEIQAACEIBAUgIYmKQ4CQYBCEAAAhCAQA4CGJgclOkDAhCAAAQgAIGkBDAwSXES
DAIQgAAEIACBHAQwMDko0wcEIAABCEAAAkkJYGCS4iQYBCAAAQhAAAI5CGBgclCmDwhAAAIQgAAE
khLAwCTFSTAIQAACEIAABHIQwMDkoEwfEIAABCAAAQgkJYCBSYqTYBCAAAQgAAEI5CCAgclBmT4g
AAEIQAACEEhKAAOTFCfBIAABCEAAAhDIQQADk4MyfUAAAhCAAAQgkJQABiYpToJBAAIQgAAEIJCD
AAYmB2X6gAAEIAABCEAgKQEMTFKcBIMABCAAAQhAIAcBDEwOyvQBAQhAAAIQgEBSAhiYpDgJBgEI
QAACEIBADgIYmByU6QMCEIAABCAAgaQEMDBJcRIMAhCAAAQgAIEcBDAwOSjTBwQgAAEIQAACSQlg
YJLiJBgEIAABCEAAAjkIYGByUKYPCEAAAhCAAASSEsDAJMVJMAhAAAIQgAAEchDAwOSgTB8QgAAE
IAABCCQlgIFJipNgEIAABCAAAQjkIICByUGZPiAAAQhAAAIQSErg/3qWn5ZCCE9aAAAAAElFTkSu
QmCC

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image012.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODdhMALcAHcAACH+GlNvZnR3YXJlOiBNaWNyb3NvZnQgT2ZmaWNlACwAAAAAMALcAIYAAAAZ
GRkBAQEPEA4NDA0QDwwPDQ04OjUwMDAgICAtLysoJSgwLSQuKCc8PDwlJSVUHkxSN05SMU1TKk1T
OU9ISEhQUFBXVlRRQE9bVU1XVE1ZVVVfWUtAQEBYVVVcV0xRUVFkXl1mXEphWExkX1RgYl1/f39n
Z2dzf2N4enV0dnFrampxbnFtam1wbGV8d2x1bmN5cG96cXBwcHBjY2N0dHSIU0uYVEiQVEqHm26F
l22UlJSFhYWVrXW/VkWjVUi9VkWvVkengyiim5u/v7+np6elpaWhoaGioqKvr6+xsbGjo6OjwH2/
5ozPV0PTnBXT09PPz8/Z2dnMzMzhWEH+tgH+/v7z8/Pm5uYBAgMBAgMBAgMBAgMBAgMBAgMBAgMB
AgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMB
AgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMBAgMH/4BWgoOEhYaHiImKi4yNjo+Q
kZKTlJWWl5iZmpucnZ6foKGio6SlpqeoqaqrrK2ur7CxsrO0tba3uLm6u7y9vr/AwcLDxMXGx8jJ
ysvMzc7P0NHS09TV1tfY2drb3N3e3+Dh4uPk5ebn6Onq6+zt7u/w8fLz9PX29/j5+QD8/KIAkgAi
EqiJoL6DCLMZtLIQVMOBD/0petiIYsKLGI1FJGWxkESPHRlSCpmxpEldJPsZUinIoECA/l72W0hT
JCGYN1nOtNmyZ8yWO2+eHEqUVkeCLge9FMoQqdKeTJ/WdPqUZ9KmVW3WLMq16yqWUaFurHpVa1ix
ZKGmVWs269KsXv/jyuX4cetYtG7zelT7Nmffq2Wp8pxLuLAnmTP7hlUsWHDexhL/Mg2s17Dly5YU
n2XLGC7OlVLXigYcNSlJzKgtj7V7iHRlkXc/tx09ubTQ06lzz93K17bVzpwHe66tVDLQ4MFx617e
NfHKj8Vd/hyMtO7AxdE/65we2Drz7+BTKVc1Prz585HKo1KPvr37nLigv59Pv779+/jz69/Pv7//
/wAGKOCABBZo4IEIJqjgggw26OCDEEYo4YQUVmjhhRhmqOGGHHbo4YcghijiiCSWaOKJKKao4oos
tujii+hVQAR9RMw4X4002tgLACbQZ0KP8/3oI5A7EumekEEa2R7/kkUO6WSSv/D45HtMHqkkSlee
V+WSWZq3JZZTWhnmLlJCaSaVXd5SJppjovdlLmuKeaacTc7JZZtwpgnem17q+R2favrJHKB7Croc
obXEeaedbhoqi6KN4tlnlI7mhuiglaZ26SyQapkpapvqFmosnU7KqKeUShreqJp+6kqpq7p6Gaug
ysoKrIWqmqsvAZxQxK/ABivssMQWa6ywRhxx7LLMNntsss5GK22xJ/hKLBLTZhssFPLQipm3rViQ
w7jklmvuueimq+65KFwQwbvwxivvvPTWa++9EWCQgRD89uvvvwAHLPDABAusgQ03JKzwwgw37PDD
N+AQQre2GgYu/ysWNKHxxhx37PHHIIfscQ8bQGDyySinrPLKLLfsMgQSiFDFzDTXbPPNOOes8845
c+ADFUAHLfTQRBdtNBVOTBzPxRZXrErGIkct9dQck/zy1VhnrXLMPHft9dde+3z02GQXnTTFutYC
NdVst111yVrHLffKXINt991fi1323mSfvbTThDH9tNuEt2313IjPXTfejDdes958R0603/AIHjjg
qKxd+OYhH57451gv7vjod0Mu+elIK1055nJZnjnnsIPsOei0syw66bh3bTrqkVP+juuts26K5rEX
P3vtyJ98e+7M47w773v77g7wcVFfCvHFw3588sgv3/z3Mz8Pff/fqv8uvFfWk4J99ptvzz3t3oPf
vPjjHy19O+lzlb8o67NPuPvv+1z85Jc7+tXPbOWb3vm6sr9Q9M9/hoNbALsnMwIS0IAHHNr92NHA
oXTwEw+EINUAOEHFVdCC4MNgBoO2wXV80CQv7EQIRSg1EpYwbgNEoeNUuMLUoe1UuJghDUVmwxtm
LYc6ZBwPV9hCdcQwI0/chBCHKDsJGjFxSExi6X7Ww7E1MR1RvEgYMzFFKo7Milc0oRbnx8UuGu2L
6BgjQuRoiQ6U0YxvS6MAT7hG0i0xg3A8Bx31MchK3BGPGiuiHluWxT6GrY1unFwC8bdA/VWSf4iM
4CIR10hH8uz/jwcMpDkKiQ9STuKQiFTkJrfGR08qEZKRFJooy2FKe9QyEqjEoypXibJOurJnsIwl
0GZJjlvSw5iPyKUZd8lLk/nylzcDZf2IOQ5k/rAXyqQiM5v5TGg+LpjCpKY4rPm3X2RziNvkZTe9
GT5wxlKc4SDn6syZSbalc5XrZKc0xwdPcMjTfPSs59Tuucl8enOf0OvnN/6pwIAKNGoEXaRBoYlQ
3inUGwylpEMf2jk0NtNlE/1lRVF30W5klIOXdCBHIerRj9qulex8pDAleU068eKcNIyoHkPqypGe
rqTcOKkLUwoKnIpQp2nkqSd9KjmgbkOoTiQqCFdKxJa6lJUx/93iTDU4SZSmjRZGhSBSr6hURzK1
d10d6ldnYQEmuPWtcI2rXOdK17rKVQcemIBe98rXvvr1r4ANrGAnQIERPOGwiE2sYhfL2MY69rGN
/cAPgEDZylr2spjNrGaBEIS0RnWtsjhACVJA2tKa9rSoTa1qV3taFayABbCNrWxnS9va2va2uGVB
C1zwgt769rfADa5wh0vc4ZKABMOFQQxkwNzmOve50I2udJk7hJouqk5sAmKsUqXdXWUXuza9bnjB
1N0/SRWG5+0ErswLWkullxPrxVR7W8Xd744XVb6I76HeixGogpG/BQFwQvwbRwHP0cCX0K+oEExI
BueDwEpxcP8pJXwPCI+SwgHBcD0sTEsNH9PDj1Cwe+dbq/re11T2JROIrRup8hplxeV08X5NLN4a
txi8NsZvism7Yx2fOFAk/haM59mLDgggMUhOspKXzOQmO/nJUI6ylKdM5Spb+cpYzrKWt8zlLnv5
y2AO85IR8IsERCMKFojGDJIQDTNDA81qZjOM5kznOttZQ86ZhGwQEhT1KGfPFYEHWEAjnM0sgj35
KQskEM0O0wQkxHp+h2MMnWAGAaYumF4KTMAyaEmDBDFAwbRWIjNq2DRlO9UpNDqmghWV4KTPp46M
qBl9HyRb5dZOeXVo2CJp15jaJ8fJ9Vumg5dfyycdU9G0T7T/Q53eyMTSk9lOdnQt7E4L+i+u3vWo
iZ1rt+xk0sjeS7eNDWy+fBsuCHI0clg97n3MRjbwxvVjXnPrdrC63Mz+db3pfSB1c1ve8QZ3o28j
loAH++AFn428seIOqpBa2WYBjrFpbZ88tzrU0QG2w4/dcGlffOOl3vNPNo3q4qga2daRNblNnWdO
A/rOMOcFxWNO82XMvOY4z7nOd87znvv850APutCHTvSiG/3oSE+60pfO9KY7/elQj7rUp071qlv9
6ljPuta3zvWue/3rYA+72MdO9rKb/exoT7va1872tru9PwqosgLmsYAqL6AdDKgyA9DRgCo3IDUA
KNzNtQEA/8QNfhoAYNzhmwEA3i0eH4En3OOtUfi5Tf4Zicfb5ZPReNRtnh6Rd9vnpVF5uY3e5opf
teMBL/h5lD5up1dG5u8We2J0/nS1l3Tr5fF6reX+GLO32++DcXvJDb/Ru49H77N2fNun/hzFj1zz
1RH6tk0fGcvH2vWJ/3xzRJ9v24d+8q0gBRogYgoO2IE4sn+1hhABBJAovxVoIAVIwD+/3R/EDhzg
AB50gv5Rsnr6x380wANKUAn3x3vjh36I4ABLcAWQAID2l1+GZwg04ICPwIA7AIGMcH/+h3+aVwgO
QANTMAUXmAkAuIEB6HmEwAMOUIJL8AAHOAkPAHoL6ABWcP8FO6AEBmgFO/AANaCDUsADV4AFPMAD
SyAIRtiDRACEVsADU0CE6ueDHLgDPfiD6veBOLIDQwiBVpiErcB+L9MQDvB+g8ADRMADU0gESmCF
9aeBVdiDVrAER4gFPvgAWSgIacgDdqiDPDiDSziDX5F/S5CA86d+OxCFH2gFS2gjUOh/ezgjTVgD
VMiIR+iIUTiFgfgqAigILniGH/iFg7CHfbgDdDiDNWgFpNhwN2gFU/AAUPgAUiAFGOgAIECEMmiC
6ueA6CcFV4CBD1CADGgFL0iMiegASvCKU2AFqXiExHiLv3iMi0geFUgIO0CJDmCHzEiCNECJPPAA
S6AED4D/BQxYjOmHfjxIguLoig+wjDWoBC/4g+wYi/XHiw5Qf4MYgoMAAlOohzjIf0Swf4wog+I4
I8GIhi/4ir5Yi1OABQT5AAbJjbu4BL0Yhp34hDgoCDSwi9JoBfA4BfI4BQAAhcjIjB4Zj6mIfJJH
CAw4jOlHjMtYjORHjjXgf7CIjzBpkq6YkQmZkVcAganYjP5XjOgHgylJjZYngstYA5Sokw75hB+4
keVYgj55Bb5YgkEpCDVYhoIAAhTJk+p3k6+SfzIpCFOplUNIgiZofqlYhFJQlDn5gjzQlDvAlp4I
f2LJiSx4hg8AAiDQlztplMRoI145jIVokueIfmC4DtXH/zYG0ZI8OZQxuYxW4Jc8cIvkRwMPcI85
mYouSZWFkJVQmZOvyH+2GIbVKAhS0Jd+KZom6YxQOZXDKAjwWJOiuZWUeYQu6X/lt5k4KR75V4DW
CH8yKZebSYBOOYLfOJkwCZsM2Iw42JuceSsX+YkseZynKZO6mZHPSYym+ZIqKXosiYO7GZfLOIxH
qIOCUJOdaZY8OQWrqYcGqZWeKJnkl4pY0I9IaXqEsJH7mISpSIujWZlfCZPxqYpEwJU6mZVe2ZUF
SoxSuJ7TuB7514QcOJg5yYz5aX4IqpNzKQjmOJl16Yl2iZHqaQXsSZ176YkZOQgHmp8E6qDDOKI1
2KCVGP+e1jeeOwmi9lmMDjmXsEiMNVmSDhCEKQmEmrmMNFCAXBmkINCNQSqTS+qCE7oeqamhg7AE
OHiQJfmNc0me/6ikTEoENVCAf6mVNkl+/XeC5VmkLiiIwKmPWQqEVAqia9qUbgqROgmPPJCkQvqL
McmU4+ih/zikcCoe1dmigzCl/aemfUqeADCkdliDtPilrLiShICPmgqBmjoI+TkFP6mHO6CN5OiK
nsqFOAmS2viWgrAERBCqvwmSv7mfsMeSheCOWLAE+HiJOlJ/qTqqergEpUp+56mEruqiqsmBAamN
+Uh7hoAFRCCsg1CGFEkI0aqNlEl+qKqEy4iT0ToIlGnMlaLKrF9xkeJqCLLqqce6k1IgrabKiOtq
b+MnaVeKCEc5oNcQfGBzGmVJeRdJCbN5D41JNeFXDGLoMiQxoTiCDfr6Naehggz7r5NwopA3rw1X
r6uWf+TwfXtTsOUwAFU2APNAAFVGAO1QAFVWAOhgAFVmAG/3sjAbszI7szRbszZ7szibszq7szzb
sz77s0AbtEI7tERbtEZ7tEibtEq7tEzbtE77tFAbtVI7tVRbtVZ7tVibtVq7tVzbtV77tWAbtmI7
tmRbtmZrCIEAADs=

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/image013.gif
Content-Transfer-Encoding: base64
Content-Type: image/gif

R0lGODlhCgAKAPcAAAAAAIAAAACAAICAAAAAgIAAgACAgICAgMDAwP8AAAD/AP//AAAA//8A/wD/
/////wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMwAAZgAAmQAAzAAA/wAzAAAzMwAzZgAzmQAzzAAz/wBm
AABmMwBmZgBmmQBmzABm/wCZAACZMwCZZgCZmQCZzACZ/wDMAADMMwDMZgDMmQDMzADM/wD/AAD/
MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMzADMzMzMzZjMzmTMzzDMz/zNmADNmMzNm
ZjNmmTNmzDNm/zOZADOZMzOZZjOZmTOZzDOZ/zPMADPMMzPMZjPMmTPMzDPM/zP/ADP/MzP/ZjP/
mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2YzAGYzM2YzZmYzmWYzzGYz/2ZmAGZmM2ZmZmZmmWZm
zGZm/2aZAGaZM2aZZmaZmWaZzGaZ/2bMAGbMM2bMZmbMmWbMzGbM/2b/AGb/M2b/Zmb/mWb/zGb/
/5kAAJkAM5kAZpkAmZkAzJkA/5kzAJkzM5kzZpkzmZkzzJkz/5lmAJlmM5lmZplmmZlmzJlm/5mZ
AJmZM5mZZpmZmZmZzJmZ/5nMAJnMM5nMZpnMmZnMzJnM/5n/AJn/M5n/Zpn/mZn/zJn//8wAAMwA
M8wAZswAmcwAzMwA/8wzAMwzM8wzZswzmcwzzMwz/8xmAMxmM8xmZsxmmcxmzMxm/8yZAMyZM8yZ
ZsyZmcyZzMyZ/8zMAMzMM8zMZszMmczMzMzM/8z/AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8A
mf8AzP8A//8zAP8zM/8zZv8zmf8zzP8z//9mAP9mM/9mZv9mmf9mzP9m//+ZAP+ZM/+ZZv+Zmf+Z
zP+Z///MAP/MM//MZv/Mmf/MzP/M////AP//M///Zv//mf//zP///ywAAAAACgAKAAAIIgD/CRxI
cCCNgzQKIkRocCHDfw4fRjwocGLCig4VPizIMSAAOy==

------=_NextPart_01C684B8.FAE701D0
Content-Location: file:///C:/A10454C5/3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOrganizationalLecturesWWWInternetE-Commerce_files/filelist.xml
Content-Transfer-Encoding: quoted-printable
Content-Type: text/xml; charset="utf-8"

<xml xmlns:o=3D"urn:schemas-microsoft-com:office:office">
 <o:MainFile
  HRef=3D"../3fITGovernanceDigitalMediaSurveillanceDVDRecordedPod-castingOr=
ganizationalLecturesWWWInternetE-Commerce.htm"/>
 <o:File HRef=3D"image001.jpg"/>
 <o:File HRef=3D"image002.jpg"/>
 <o:File HRef=3D"image003.jpg"/>
 <o:File HRef=3D"image004.jpg"/>
 <o:File HRef=3D"image005.gif"/>
 <o:File HRef=3D"image006.gif"/>
 <o:File HRef=3D"image007.gif"/>
 <o:File HRef=3D"image008.gif"/>
 <o:File HRef=3D"image009.png"/>
 <o:File HRef=3D"image010.gif"/>
 <o:File HRef=3D"image011.png"/>
 <o:File HRef=3D"image012.gif"/>
 <o:File HRef=3D"image013.gif"/>
 <o:File HRef=3D"filelist.xml"/>
</xml>
------=_NextPart_01C684B8.FAE701D0--

