MIME-Version: 1.0
Content-Type: multipart/related; boundary="----=_NextPart_01C684BB.A8D4B1A0"

This document is a Single File Web Page, also known as a Web Archive file.  If you are seeing this message, your browser or editor doesn't support Web Archive files.  Please download a browser that supports Web Archive, such as Microsoft Internet Explorer.

------=_NextPart_01C684BB.A8D4B1A0
Content-Location: file:///C:/486BB24E/__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scorecard_Prioritized_Action.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:w=3D"urn:schemas-microsoft-com:office:word"
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DWord.Document>
<meta name=3DGenerator content=3D"Microsoft Word 11">
<meta name=3DOriginator content=3D"Microsoft Word 11">
<link rel=3DFile-List
href=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Score=
card_Prioritized_Action_files/filelist.xml">
<link rel=3DEdit-Time-Data
href=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Score=
card_Prioritized_Action_files/editdata.mso">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<title>Microsoft Security Assessment Tool</title>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"place"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"City"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PlaceType"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PlaceName"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"Street"/>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"address"/>
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>a</o:Author>
  <o:LastAuthor>a</o:LastAuthor>
  <o:Revision>2</o:Revision>
  <o:TotalTime>22</o:TotalTime>
  <o:Created>2006-05-31T18:08:00Z</o:Created>
  <o:LastSaved>2006-05-31T18:08:00Z</o:LastSaved>
  <o:Pages>1</o:Pages>
  <o:Words>23297</o:Words>
  <o:Characters>132794</o:Characters>
  <o:Lines>1106</o:Lines>
  <o:Paragraphs>311</o:Paragraphs>
  <o:CharactersWithSpaces>155780</o:CharactersWithSpaces>
  <o:Version>11.6360</o:Version>
 </o:DocumentProperties>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:Zoom>115</w:Zoom>
  <w:GrammarState>Clean</w:GrammarState>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
 </w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState=3D"false" LatentStyleCount=3D"156">
 </w:LatentStyles>
</xml><![endif]--><!--[if !mso]><object
 classid=3D"clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id=3Dieooui></objec=
t>
<style>
st1\:*{behavior:url(#ieooui) }
</style>
<![endif]-->
<style>
<!--a.SCRIPTLINK
	{cursor:hand;}
A.scriptlink:hover { CURSOR: hand; COLOR: #6666ff; TEXT-DECORATION: underli=
ne }
A.navlink:hover { COLOR: #6666ff; TEXT-DECORATION: underline }
COLOR: #3333ff;
TEXT-DECORATION: none }
=09

 /* Font Definitions */
 @font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;
	mso-font-charset:2;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:0 268435456 0 0 -2147483648 0;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:536871559 0 0 0 415 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-parent:"";
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	mso-believe-normal-left:yes;}
h1
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:1;
	font-size:18.0pt;
	font-family:Arial;
	color:#6487DC;
	font-weight:normal;}
h2
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:2;
	font-size:14.0pt;
	font-family:Arial;
	color:black;
	font-weight:normal;}
h3
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:3;
	font-size:12.0pt;
	font-family:Arial;
	color:#6487DC;
	font-weight:bold;}
h4
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:4;
	font-size:10.0pt;
	font-family:Arial;
	color:black;
	font-weight:normal;
	font-style:italic;}
h5
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:5;
	font-size:14.0pt;
	font-family:Arial;
	color:black;
	font-weight:bold;}
p.MsoCaption, li.MsoCaption, div.MsoCaption
	{margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:8.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{color:blue;
	text-decoration:underline;
	text-underline:single;}
p
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.copy, li.copy, div.copy
	{mso-style-name:copy;
	margin-top:5.25pt;
	margin-right:0in;
	margin-bottom:5.25pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	background:white;
	font-size:8.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";}
p.msatbullet, li.msatbullet, div.msatbullet
	{mso-style-name:msatbullet;
	margin:.1in;
	mso-pagination:widow-orphan;
	background:white;
	font-size:7.0pt;
	font-family:Wingdings;
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Times New Roman";}
p.datatable, li.datatable, div.datatable
	{mso-style-name:datatable;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:0in 0in 0in 0in;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datatablenb, li.datatablenb, div.datatablenb
	{mso-style-name:datatablenb;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datacell, li.datacell, div.datacell
	{mso-style-name:datacell;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datacellnb, li.datacellnb, div.datacellnb
	{mso-style-name:datacellnb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
p.datacellhed1, li.datacellhed1, div.datacellhed1
	{mso-style-name:datacellhed1;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#0148B2;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed2, li.datacellhed2, div.datacellhed2
	{mso-style-name:datacellhed2;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#6487DC;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed3, li.datacellhed3, div.datacellhed3
	{mso-style-name:datacellhed3;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	border:none;
	mso-border-alt:solid black .5pt;
	padding:0in;
	mso-padding-alt:3.0pt 0in 0in 3.0pt;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	font-weight:bold;}
p.datacellhed1nb, li.datacellhed1nb, div.datacellhed1nb
	{mso-style-name:datacellhed1nb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#0148B2;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed2nb, li.datacellhed2nb, div.datacellhed2nb
	{mso-style-name:datacellhed2nb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	background:#6487DC;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	color:white;
	font-weight:bold;}
p.datacellhed3nb, li.datacellhed3nb, div.datacellhed3nb
	{mso-style-name:datacellhed3nb;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	font-weight:bold;}
p.header, li.header, div.header
	{mso-style-name:header;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:18.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;}
p.header1, li.header1, div.header1
	{mso-style-name:header1;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:18.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;}
p.header2, li.header2, div.header2
	{mso-style-name:header2;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:14.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;}
p.header3, li.header3, div.header3
	{mso-style-name:header3;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:#6487DC;
	font-weight:bold;}
p.header4, li.header4, div.header4
	{mso-style-name:header4;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:Arial;
	mso-fareast-font-family:"Times New Roman";
	color:black;
	font-weight:bold;}
p.header5, li.header5, div.header5
	{mso-style-name:header5;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:18.0pt;
	font-family:Verdana;
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Times New Roman";
	color:#6487DC;}
p.buttons, li.buttons, div.buttons
	{mso-style-name:buttons;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.45pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";}
span.msatbullet1
	{mso-style-name:msatbullet1;
	mso-ansi-font-size:7.0pt;
	mso-bidi-font-size:7.0pt;
	font-family:Wingdings;
	mso-ascii-font-family:Wingdings;
	mso-hansi-font-family:Wingdings;
	background:white;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:883639079;
	mso-list-template-ids:-1572183530;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1
	{mso-list-id:1050156527;
	mso-list-template-ids:628907110;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l2
	{mso-list-id:1152714431;
	mso-list-template-ids:389463608;}
@list l2:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l3
	{mso-list-id:1238322063;
	mso-list-template-ids:-949301402;}
@list l3:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l4
	{mso-list-id:2012371759;
	mso-list-template-ids:-988771572;}
@list l4:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l5
	{mso-list-id:2067794691;
	mso-list-template-ids:891867670;}
@list l5:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l6
	{mso-list-id:2112507824;
	mso-list-template-ids:-1488300944;}
@list l6:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
-->
</style>
<!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
</style>
<![endif]--><![if mso 9]>
<style>
p.MsoNormal
	{margin-left:19.65pt;}
</style>
<![endif]><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"2050"/>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1"/>
 </o:shapelayout></xml><![endif]-->
</head>

<body bgcolor=3Dwhite lang=3DEN-US link=3Dblue vlink=3Dblue style=3D'tab-in=
terval:.5in;
margin-left:19.65pt;margin-top:16.35pt;margin-right:16.35pt;margin-bottom:1=
6.35pt'>

<div class=3DSection1>

<h5 style=3D'margin-top:16.35pt;margin-right:16.35pt;margin-bottom:0in;
margin-left:0in;margin-bottom:.0001pt'><span style=3D'font-size:72.0pt;
color:red;background:yellow;mso-highlight:yellow'>Free </span><span
style=3D'background:yellow;mso-highlight:yellow'>Management Security Assess=
ment
MSA Executive Analysis Scorecard Prioritized Action</span> <span
style=3D'font-size:8.0pt'><a
href=3D"http://video.google.com/videoplay?docid=3D-417444910876190163&amp;q=
=3Drushinek+Accounting">http://video.google.com/videoplay?docid=3D-41744491=
0876190163&amp;q=3Drushinek+Accounting</a></span>
</h5>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>(888)ITISJo=
b.Net
-<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>Information Technology
Information Systems Job Network specializing in Managemnt Baseline Security
Analysis (MBSA) Vulnerability <span class=3DGramE>Assessment <span
style=3D'mso-spacerun:yes'>&nbsp;</span></span><a
href=3D"http://video.google.com/videoplay?docid=3D-2199987895572940206&amp;=
q=3Drushinek+Accounting">http://video.google.com/videoplay?docid=3D-2199987=
895572940206&amp;q=3Drushinek+Accounting</a>
</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>(888)Nets-E=
xpert.Org
- the Network of Experts Organization providing Expert Witness Testimony and
Computer Litigation Support Services <a href=3D"mailto:email@Nets-Expert.Or=
g">email@Nets-Expert.Org</a>
<a href=3D"http://video.google.com/videoplay?docid=3D5240188564675855151">h=
ttp://video.google.com/videoplay?docid=3D5240188564675855151</a>
</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>(305)6384-3=
97 <a
href=3D"http://video.google.com/videoplay?docid=3D-4470389520639706819&amp;=
q=3Drushinek+Accounting">http://video.google.com/videoplay?docid=3D-4470389=
520639706819&amp;q=3Drushinek+Accounting</a>
</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>Dr. A, &amp=
; S.
Rushinek, Ph.D. U. of Miami Professor, <a href=3D"mailto:eMail@OnAFree.com"=
>eMail@OnAFree.com</a>
, <st1:Street w:st=3D"on"><st1:address tabIndex=3D"0"
 style=3D"BACKGROUND-POSITION: left bottom; BACKGROUND-IMAGE: url(res://iet=
ag.dll/#34/#1001); BACKGROUND-REPEAT: repeat-x"
 w:st=3D"on">1205 Mariposa Ave.</st1:address></st1:Street> #208, Coral Gabl=
es Fl,
33146</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'>Accounting =
and
Computer Information Systems Dept., <st1:PlaceName w:st=3D"on">Business</st=
1:PlaceName>
<st1:PlaceType w:st=3D"on">School</st1:PlaceType><span class=3DGramE>,<span
style=3D'mso-spacerun:yes'>&nbsp; </span>417</span> Jenkins Bldg, U of <st1=
:City
w:st=3D"on">Miami</st1:City>, <st1:place w:st=3D"on"><st1:City w:st=3D"on">=
Coral
  Gables</st1:City></st1:place> Fl, 33124</p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><o:p>&nbsp;=
</o:p></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Free_Management_Secur=
ity_Assessment_MSA_Executive_Analysis_Scorecard_Prioritized_Action&nbsp;<sp=
an
style=3D'mso-spacerun:yes'>&nbsp; </span><a href=3D"http://www.webjobnet.co=
m/">http://www.webjobnet.com/</a>
<a href=3D"http://www.itisjob.net/">http://www.ITISJob.net</a> <o:p></o:p><=
/span></p>

<div align=3Dcenter>

<table class=3DMsoNormalTable border=3D0 cellpadding=3D0 width=3D"100%"
 style=3D'width:100.0%;mso-cellspacing:1.5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><!--[if g=
te vml 1]><v:shapetype
   id=3D"_x0000_t75" coordsize=3D"21600,21600" o:spt=3D"75" o:preferrelativ=
e=3D"t"
   path=3D"m@4@5l@4@11@9@11@9@5xe" filled=3D"f" stroked=3D"f">
   <v:stroke joinstyle=3D"miter"/>
   <v:formulas>
    <v:f eqn=3D"if lineDrawn pixelLineWidth 0"/>
    <v:f eqn=3D"sum @0 1 0"/>
    <v:f eqn=3D"sum 0 0 @1"/>
    <v:f eqn=3D"prod @2 1 2"/>
    <v:f eqn=3D"prod @3 21600 pixelWidth"/>
    <v:f eqn=3D"prod @3 21600 pixelHeight"/>
    <v:f eqn=3D"sum @0 0 1"/>
    <v:f eqn=3D"prod @6 1 2"/>
    <v:f eqn=3D"prod @7 21600 pixelWidth"/>
    <v:f eqn=3D"sum @8 21600 0"/>
    <v:f eqn=3D"prod @7 21600 pixelHeight"/>
    <v:f eqn=3D"sum @10 21600 0"/>
   </v:formulas>
   <v:path o:extrusionok=3D"f" gradientshapeok=3D"t" o:connecttype=3D"rect"=
/>
   <o:lock v:ext=3D"edit" aspectratio=3D"t"/>
  </v:shapetype><v:shape id=3D"_x0000_i1120" type=3D"#_x0000_t75" alt=3D"" =
style=3D'width:93.75pt;
   height:136.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image001.jpg"
    o:href=3D"http://www.webjobnet.com/srushinek.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D125 height=3D182
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image001.jpg"
  v:shapes=3D"_x0000_i1120"><![endif]><!--[if gte vml 1]><v:shape id=3D"_x0=
000_i1121"
   type=3D"#_x0000_t75" alt=3D"MOL03E.ASF" style=3D'width:120pt;height:90pt=
'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image002.jpg"
    o:href=3D"http://www.webjobnet.com/th_MOL03E.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D160 height=3D120
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image002.jpg"
  alt=3DMOL03E.ASF v:shapes=3D"_x0000_i1121"><![endif]><!--[if gte vml 1]><=
v:shape
   id=3D"_x0000_i1122" type=3D"#_x0000_t75" alt=3D"" style=3D'width:120pt;h=
eight:90pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image003.jpg"
    o:href=3D"http://www.webjobnet.com/th_MOL024-SplitBackgroundPPTandWhite=
Board.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D160 height=3D120
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image003.jpg"
  v:shapes=3D"_x0000_i1122"><![endif]><!--[if gte vml 1]><v:shape id=3D"_x0=
000_i1123"
   type=3D"#_x0000_t75" alt=3D"" style=3D'width:95.25pt;height:136.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image004.jpg"
    o:href=3D"http://www.webjobnet.com/arushinek.jpg"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D127 height=3D182
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image004.jpg"
  v:shapes=3D"_x0000_i1123"><![endif]><!--[if gte vml 1]><v:shape id=3D"_x0=
000_i1124"
   type=3D"#_x0000_t75" alt=3D"" style=3D'width:131.25pt;height:120pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image005.gif"
    o:href=3D"http://www.webjobnet.com/pullups_male_md_wht_22041.gif"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D175 height=3D160
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image005.gif"
  v:shapes=3D"_x0000_i1124"><![endif]></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td valign=3Dbottom style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:18.0pt;font-family:Arial;color:black'><!--[if gte vml =
1]><v:shape
   id=3D"_x0000_i1125" type=3D"#_x0000_t75" alt=3D"" style=3D'width:18.75pt=
;height:16.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image006.gif"
    o:href=3D"http://www.webjobnet.com/_phonecall.gif"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D25 height=3D22
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image006.gif"
  v:shapes=3D"_x0000_i1125"><![endif]>(305)Web-Job-Net a Network of Jobs on=
 the
  Web</span></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:18.0pt;font-family:Arial;color:black'><!--[if gte vml =
1]><v:shape
   id=3D"_x0000_i1126" type=3D"#_x0000_t75" alt=3D"" style=3D'width:18.75pt=
;height:16.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image006.gif"
    o:href=3D"http://www.webjobnet.com/_phonecall.gif"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D25 height=3D22
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image006.gif"
  v:shapes=3D"_x0000_i1126"><![endif]>(305)932-5626 a Network of Jobs on th=
e Web</span></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:10.0pt;font-family:Arial;color:black'>&nbsp;</span></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:10.0pt;font-family:Arial;color:black'>e-Mail: <a
  href=3D"mailto:ARsuh@OnTrial.Org"><span style=3D'color:black'>ARsuh@OnTri=
al.Org</span></a>&nbsp;
  The On Trial Expert Witness Testimony &amp; Computer Litigation team</spa=
n></p>
  <p class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span
  style=3D'font-size:10.0pt;font-family:Arial;color:black'>Dr. A. Rush
  (305)668-7425</span></p>
  <p align=3Dcenter style=3D'text-align:center'><o:p>&nbsp;</o:p></p>
  </td>
 </tr>
</table>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"http://www.onafree.com/default.aspx">http://www.onafree.com/default=
.aspx</a>
<span style=3D'mso-spacerun:yes'>&nbsp;</span><a
href=3D"http://www.onafree.com/Quiz%20Engine%20Projects/1Free%20Managemnt%2=
0Baseline%20Security%20Analysis%20(MBSA)%20Vulnerability%20Assessment%20Tru=
stworthy%20Computing%20Scanner.htm">http://www.onafree.com/Quiz%20Engine%20=
Projects/1Free%20Managemnt%20Baseline%20Security%20Analysis%20(MBSA)%20Vuln=
erability%20Assessment%20Trustworthy%20Computing%20Scanner.htm</a>
<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"http://www.onafree.com/Lists/Announcements/DispForm.aspx?ID=3D13&am=
p;Source=3Dhttp%3A%2F%2Fwww%2Eonafree%2Ecom%2Fdefault%2Easpx">http://www.on=
afree.com/Lists/Announcements/DispForm.aspx?ID=3D13&amp;Source=3Dhttp%3A%2F=
%2Fwww%2Eonafree%2Ecom%2Fdefault%2Easpx</a>
<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This report contains =
the
following sections:<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;
mso-bidi-font-family:Arial'>q</span></span><span style=3D'font-size:10.0pt;
font-family:Arial'><a href=3D"#ExecSum">Executive Summary</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Intro">Introduction</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Process">Background: Assessment Process and Scope</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Situation">Situation Analysis</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#ScoreCard">Scorecard</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Improvement">Security Initiatives</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>q</span></span><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"#Detail">Assessment in Detail</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Areas">Areas of Analysis</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#Infrastructure">Infrastructure</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#Applications">Applications</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#Operations">Operations</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0=
pt;
font-family:Arial'><a href=3D"#People">People</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>q</span></span><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"#Recommendations">Prioritized Action List</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>q</span></span><span style=3D'font-size:10.0pt;font-family:Arial'><a
href=3D"#Appendices">Appendices</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#QA">Questions and Answers</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Glossary">Glossary</a><br>
</span><span class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-fo=
nt-family:
Arial'>&nbsp;&nbsp;w</span></span><span style=3D'font-size:10.0pt;font-fami=
ly:
Arial'><a href=3D"#Interpreting">Interpreting the Graphs</a><o:p></o:p></sp=
an></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>A Microsoft partner c=
an
review this report with you and help with developing a detailed action plan=
 for
implementing the recommendations. If you do not have an existing relationsh=
ip
with a Microsoft partner, you may wish to view a list of Microsoft Partners=
 for
Security Solutions at <a href=3D"http://directory.microsoft.com/mprd/"
target=3D"_new">http://directory.microsoft.com/mprd/</a>.<o:p></o:p></span>=
</p>

<div class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
text-align:center'><span style=3D'font-size:10.0pt;font-family:Arial'>

<hr size=3D2 width=3D"100%" align=3Dcenter>

</span></div>

<p class=3Dcopy>The Microsoft Security Assessment Tool is designed to help =
you
determine the level of risk your computing infrastructure faces and the ste=
ps
you have taken to mitigate that <span class=3DGramE>risk,</span> and to off=
er
suggestions of additional steps you can take to help further reduce your le=
vel
of risk. It is not a replacement for an audit by a professional security
consultant.<br>
<br>
Use of the Microsoft Security Assessment Tool is governed by the terms of t=
he
End-User License Agreement (EULA) which accompanied the software, and this
report is subject to the exclusions, disclaimers, and limitations of liabil=
ity
contained in the EULA.<br>
<br>
This report is for informational purposes only. <span class=3DGramE>Neither
Microsoft Corporation, its suppliers, or</span> partners make any
representation or warranty of any kind, whether express or implied, concern=
ing
the Security Assessment Tool, or the use, accuracy, or reliability of the
results of the Assessment and information contained in this report.</p>

<div class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
text-align:center'><span style=3D'font-size:10.0pt;font-family:Arial'>

<hr size=3D2 width=3D"100%" align=3Dcenter>

</span></div>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><br clear=3Dall style=3D'mso-s=
pecial-character:
line-break'>
<o:p></o:p></span></p>

<h1 style=3D'page-break-before:always'><a name=3DExecSum></a>Executive Summ=
ary</h1>

<h2><a name=3DIntro></a>Introduction</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This Microsoft Securi=
ty
Assessment Tool is designed to assist you with identifying and addressing
security risks in your computing environment. The tool employs a holistic
approach to measuring security strategy by covering topics across people,
process, and technology. Findings are coupled with recommended mitigation
efforts, including links to more information for additional guidance if nee=
ded.
These resources may assist you in learning more about the specific tools and
methods that can help increase the security of your environment.<o:p></o:p>=
</span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This summary section =
is
intended to give IT and senior managers a snapshot of the company's overall
security posture. Detailed findings and recommendations can be found in the
detailed report following.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><br style=3D'mso-special-chara=
cter:
line-break'>
<![if !supportLineBreakNewLine]><br style=3D'mso-special-character:line-bre=
ak'>
<![endif]><o:p></o:p></span></p>

<h2><a name=3DProcess></a>Background: Assessment Process and Scope</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The assessment is des=
igned
to identify the business risk of your organization and the security measures
deployed to mitigate risk. Focusing on common issues in this market segment,
the questions have been developed to provide a high-level security risk
assessment of the technology, processes, and people that support the busine=
ss.<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Beginning with a seri=
es of
questions about your company's business model, the tool builds a Business R=
isk
Profile (BRP), measuring the risk of doing business your company must face =
due
to the industry and business model chosen. A second series of questions are
posed to compile a listing of the security measures your company has deploy=
ed
over time. Together, these security measures form layers of defense, provid=
ing
greater protection against security risk and specific vulnerabilities. Each
layer contributes to a combined strategy for defense-in-depth. This sum is
referred to as the Defense-in-Depth Index (DiDI). The BRP and DiDI are then
compared to measure risk distribution across the areas of analysis
(AoAs)&#8212;infrastructure, applications, operations, and people.<o:p></o:=
p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>In addition to measur=
ing
the alignment of security risk and defenses, this tool also measures the
security maturity of your organization. Security maturity refers to the
evolution of strong security and maintainable practices. At the low end, few
security defenses are employed and actions are reactive. At the high end,
established and proven processes allow a company to be more proactive, and
respond more efficiently and consistently when needed.<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Risk management
recommendations are suggested for your environment by taking into considera=
tion
existing technology deployment, current security posture, and defense-in-de=
pth
strategies. Suggestions are designed to move you along a path toward recogn=
ized
best practices.<o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This
assessment&#8212;including the questions, measures, and
recommendations&#8212;is designed for midsize organizations that have betwe=
en
50 and 500 desktops in their environment. It is meant to broadly cover area=
s of
potential risk across your environment, rather than provide an in-depth ana=
lysis
of a particular technology or process. As a result, the tool cannot measure=
 the
effectiveness of the security measures employed. To that end, this report
should be used as a preliminary guide to help you focus on specific areas t=
hat
require more rigorous attention, and should not replace a focused assessmen=
t by
trained third-party assessment teams.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<h2><a name=3DSituation></a>Situation Analysis</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This section graphica=
lly
represents the concepts described above for your organization, based on the
answers you provided. As a reminder:<o:p></o:p></span></p>

<ul type=3Dsquare>
 <li class=3DMsoNormal style=3D'mso-list:l0 level1 lfo1;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>BRP is a measure of the r=
isk
     related to the industry and business model of the company <o:p></o:p><=
/span></li>
 <li class=3DMsoNormal style=3D'mso-list:l0 level1 lfo1;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>DiDI is a measure of the
     security defenses used across people, process, and technology to help
     mitigate identified risks to the business <o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l0 level1 lfo1;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Security Maturity is a me=
asure
     of the organization's ability to effectively use the tools available to
     create a maintainable security level across many disciplines <o:p></o:=
p></span></li>
</ul>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>[See <a href=3D"#Appe=
ndices">Appendices</a>
for additional information on these terms and how to interpret the graphs.]=
<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<h2>Results:</h2>

<div align=3Dcenter>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;mso-border-alt:solid =
black .5pt;
   background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Areas of Analysi=
s<o:p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.0=
001pt;
   text-align:center'><b><span style=3D'font-size:9.0pt;font-family:Arial;
   color:white'>Risk-Defense Distribution<o:p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.0=
001pt;
   text-align:center'><b><span style=3D'font-size:9.0pt;font-family:Arial;
   color:white'>Security Maturity<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Infrastructure<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1027" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image007.gif"
  v:shapes=3D"_x0000_i1027"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1028" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image008.gif"
  v:shapes=3D"_x0000_i1028"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p></o:p></span=
></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1029" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image008.gif"
  v:shapes=3D"_x0000_i1029"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1030" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image008.gif"
  v:shapes=3D"_x0000_i1030"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Operations<o:p></o:p></span><=
/p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1031" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image007.gif"
  v:shapes=3D"_x0000_i1031"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1032" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
    o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image008.gif"
  v:shapes=3D"_x0000_i1032"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:4;mso-yfti-lastrow:yes;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>People<o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1033" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image007.gif"
  v:shapes=3D"_x0000_i1033"><![endif]><o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!--=
[if gte vml 1]><v:shape
   id=3D"_x0000_i1034" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;h=
eight:7.5pt'>
   <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive=
_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
    o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
  </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
  src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scor=
ecard_Prioritized_Action_files/image007.gif"
  v:shapes=3D"_x0000_i1034"><![endif]><o:p></o:p></span></p>
  </td>
 </tr>
</table>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h3>Risk-Defense Distribution</h3>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This chart indicates
differences in the Defense-in-Depth score, organized by Area of Analysis. B=
ased
on your answers to the risk assessment and as depicted in the chart below, =
it
appears that additional focus is needed to shore up security measures in so=
me
areas. This is a strong indicator that your security posture is based on a =
few
standard security solutions. Contacting a security partner that can help you
identify critical areas of risk should be made a priority of your near term
security plans.<o:p></o:p></span></p>

<p align=3Dcenter style=3D'text-align:center'><span style=3D'font-size:10.0=
pt;
font-family:Arial'><!--[if gte vml 1]><v:shape id=3D"_x0000_i1035" type=3D"=
#_x0000_t75"
 alt=3D"" style=3D'width:420pt;height:240pt'>
 <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive_A=
nalysis_Scorecard_Prioritized_Action_files/image009.png"
  o:href=3D"cid:CHILKAT-CID-929ef4a5-9c66-46bd-8df0-d467ca56a928"/>
</v:shape><![endif]--><![if !vml]><img border=3D0 width=3D560 height=3D320
src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scorec=
ard_Prioritized_Action_files/image010.gif"
align=3Dcenter v:shapes=3D"_x0000_i1035"><![endif]><o:p></o:p></span></p>

<p class=3DMsoCaption align=3Dcenter style=3D'text-align:center'><span
style=3D'font-family:Arial'>Figure 1: Comparison of BRP and DiDI<o:p></o:p>=
</span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>In general, it is bes=
t to
have a DiDI rating on par with the BRP rating for the same category. An
imbalance either within a category or across categories&#8212;in either
direction&#8212;may indicate the need to realign your IT investments.<o:p><=
/o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h3>Security Maturity</h3>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Security maturity is
inclusive of controls (both physical and technical), the technical acumen o=
f IT
resources, policy, process, and maintainable practices. Security maturity c=
an
be measured only through the organization's ability to effectively use the
tools available to create a maintainable security level across many
disciplines. A baseline of security maturity should be established and used=
 to
define areas of focus for the organization's security programs. Not all
organizations should strive to reach the optimized level, but all should as=
sess
where they are and determine where they should be, in light of the business
risk they face. For example, a company with a low-risk environment may never
need to advance beyond the upper range of the Baseline level or the lower r=
ange
of the Standardized level. A company with a high-risk environment will like=
ly
push well into the Optimized level. Your Business Risk Profile scores help =
you
gauge your risk.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Security Maturity<o:p></o:p><=
/span></p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>A measure of a company's prac=
tices
  against industry best practices for maintainable security. Each company
  should strive to align its maturity level, and associated security strate=
gy,
  relative to the risks taken in doing business:<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Baseline<o:p></o:p></span></p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Some proactive security measu=
res
  deployed as first-line defenses; operations and incident response still v=
ery
  reactive<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Standardized<o:p></o:p></span=
></p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Multiple layers of defense de=
ployed
  in support of a defined strategy<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;mso-yfti-lastrow:yes'>
  <td width=3D"30%" valign=3Dtop style=3D'width:30.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  class=3Dmsatbullet1><span style=3D'font-size:7.0pt;mso-bidi-font-family:A=
rial'>n</span></span><span
  style=3D'font-size:9.0pt;font-family:Arial'>Optimized<o:p></o:p></span></=
p>
  </td>
  <td width=3D"70%" valign=3Dtop style=3D'width:70.0%;padding:3.25pt 0in 0i=
n 3.25pt'>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'>Effectively protecting the ri=
ght
  things the right way and ensuring ongoing utilization of best practices<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Based on your answers=
 to
the risk assessment and as depicted in the chart below, your company is doi=
ng
well in that it has a defined security strategy and a practices defense in
depth. You can further enhance your maturity by leveraging your comprehensi=
ve
corporate security policy, IT security policies and procedures for the IT
infrastructure. Use those to define a layered approach to security that fol=
lows
industry best practices, and applies only the necessary amount of protectio=
n to
assets.<o:p></o:p></span></p>

<p align=3Dcenter style=3D'text-align:center'><span style=3D'font-size:10.0=
pt;
font-family:Arial'><!--[if gte vml 1]><v:shape id=3D"_x0000_i1036" type=3D"=
#_x0000_t75"
 alt=3D"" style=3D'width:420pt;height:165pt'>
 <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executive_A=
nalysis_Scorecard_Prioritized_Action_files/image011.png"
  o:href=3D"cid:CHILKAT-CID-e7b77dd2-3392-4b00-bc33-8ec20b29787b"/>
</v:shape><![endif]--><![if !vml]><img border=3D0 width=3D560 height=3D220
src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Scorec=
ard_Prioritized_Action_files/image012.gif"
align=3Dcenter v:shapes=3D"_x0000_i1036"><![endif]><o:p></o:p></span></p>

<p class=3DMsoCaption align=3Dcenter style=3D'text-align:center'><span
style=3D'font-family:Arial'>Figure 2: Security Maturity<o:p></o:p></span></=
p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h2><a name=3DScoreCard></a>Scorecard</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Based on your answers=
 to
the risk assessment, the following ratings have been applied to your defens=
ive
measures. The <a href=3D"#Detail">Assessment Detail</a> and <a
href=3D"#Recommendations">Prioritized Action List</a> sections of this repo=
rt
include further detail for each, including the findings, best practices, an=
d recommendations.<o:p></o:p></span></p>

<div align=3Dcenter>

<table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td colspan=3D2 style=3D'padding:.75pt .75pt .75pt 3.25pt'>
  <div align=3Dcenter>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
    <td width=3D"10%" nowrap valign=3Dtop style=3D'width:10.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Legend:<o:p></o:p></span></=
p>
    </td>
    <td width=3D"5%" nowrap valign=3Dtop style=3D'width:5.0%;padding:3.25pt=
 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><!--[if gte vml 1]><v:shape=
 id=3D"_x0000_i1037"
     type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1037"><![endif]><o:p></o:p></span></p>
    </td>
    <td width=3D"25%" nowrap valign=3Dtop style=3D'width:25.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Meets best practice<o:p></o=
:p></span></p>
    </td>
    <td width=3D"5%" nowrap valign=3Dtop style=3D'width:5.0%;padding:3.25pt=
 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><!--[if gte vml 1]><v:shape=
 id=3D"_x0000_i1038"
     type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1038"><![endif]><o:p></o:p></span></p>
    </td>
    <td width=3D"25%" nowrap valign=3Dtop style=3D'width:25.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Needs improvement<o:p></o:p=
></span></p>
    </td>
    <td width=3D"5%" nowrap valign=3Dtop style=3D'width:5.0%;padding:3.25pt=
 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><!--[if gte vml 1]><v:shape=
 id=3D"_x0000_i1039"
     type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1039"><![endif]><o:p></o:p></span></p>
    </td>
    <td width=3D"25%" nowrap valign=3Dtop style=3D'width:25.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Severely lacking<o:p></o:p>=
</span></p>
    </td>
   </tr>
  </table>
  </div>
  <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.00=
01pt;
  text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><o:p=
></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1'>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Infrastructure<o:p></o:p></=
span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1040" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1040"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Perimeter Defense<o:p></o:p=
></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1041" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1041"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and Filters<=
o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1042" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1042"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1043" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1043"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desktops<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1044" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1044"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Servers<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1045" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1045"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p></o:p></s=
pan></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1046" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1046"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1047" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1047"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Users<o:p></o=
:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1048" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1048"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detection System =
(IDS)<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1049" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1049"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:p></span><=
/p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1050" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1050"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:p></o:p></=
span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1051" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1051"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:12'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Administrative Users<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1052" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1052"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:13'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Internal Users<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1053" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1053"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:14'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Users<o:p></o=
:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1054" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1054"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:15'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1055" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1055"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:16'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies - Adminis=
trator
    Account<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1056" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1056"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:17'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies - User Ac=
count<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1057" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1057"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:18'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies - Remote-=
Access
    Account<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1058" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1058"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:19'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management and Monitoring<o=
:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1059" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1059"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:20'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Build<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1060" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1060"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:21'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1061" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1061"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:22'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-Party Relationships<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1062" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1062"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:23'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Physical Security<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1063" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1063"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:24;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Operations<o:p></o:p></span=
></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1064" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1064"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Environment<o:p></o:p></spa=
n></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1065" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1065"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and Filters<=
o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1066" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1066"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Administrative Users<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1067" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1067"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management Host<o:p></o:p><=
/span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1068" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1068"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Servers<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1069" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1069"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Network D=
evices<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1070" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1070"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-Party Relationships<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1071" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1071"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o:p></o:p><=
/span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1072" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1072"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1073" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1073"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Protocols &amp; Services<o:=
p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1074" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1074"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Acceptable Use<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1075" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1075"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:12'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>User Account Management<o:p=
></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1076" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1076"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:13'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Requirements<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1077" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1077"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:14'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Governance<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1078" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1078"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:15'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o:p></o:p><=
/span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1079" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1079"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:16'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Patch &amp; Update Manageme=
nt<o:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1080" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1080"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:17'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Network Documentation<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1081" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1081"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:18'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Application Data Flow<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1082" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1082"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:19'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Patch Management<o:p></o:p>=
</span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1083" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1083"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:20'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Virus Signatures<o:p></o:p>=
</span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1084" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1084"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:21'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Change Management and
    Configuration<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1085" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1085"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:22'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup and Recovery<o:p></o=
:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1086" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1086"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:23'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Log Files<o:p></o:p></span>=
</p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1087" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1087"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:24'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Log Files - Rotation<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1088" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1088"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:25'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1089" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1089"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:26'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup Media<o:p></o:p></sp=
an></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1090" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1090"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:27'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Restore<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1091" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1091"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:28;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;mso-yfti-lastrow:yes'>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p></o:p></sp=
an></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1092" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1092"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Applications<o:p></o:p></sp=
an></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1093" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1093"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Load-Balancing<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1094" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1094"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1095" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1095"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Application &amp; Data Reco=
very<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1096" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1096"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-party independent sof=
tware
    vendor (ISV)<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1097" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1097"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Internally Developed<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1098" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1098"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Vulnerabilities<o:p></o:p><=
/span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1099" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1099"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Application Design<o:p></o:=
p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1100" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1100"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:p></o:p></=
span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1101" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1101"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Password Policies<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1102" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1102"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Authorization &amp; Access
    Control<o:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1103" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1103"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:12'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p></span></=
p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1104" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1104"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:13'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<o:p></o:p>=
</span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1105" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1105"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:14'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Data Storage &amp; Communic=
ations<o:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1106" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1106"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:15'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Encryption<o:p></o:p></span=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1107" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1107"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:16'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Encryption - Algorithm<o:p>=
</o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1108" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1108"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:17;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
  <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
  <table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D"100%"
   style=3D'width:100.0%;border-collapse:collapse'>
   <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>People<o:p></o:p></span></b=
></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1109" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1109"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:1'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Requirements &amp; Assessme=
nts<o:p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1110" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1110"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:2'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Requirements<o:p><=
/o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1111" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1111"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:3'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Assessments<o:p></=
o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1112" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1112"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:4'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Awareness<o:p></o:=
p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1113" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1113"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:5'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Policy &amp; Procedures<o:p=
></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1114" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1114"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:6'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Background Checks<o:p></o:p=
></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1115" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1115"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:7'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Human Resources Policy<o:p>=
</o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1116" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image013.gif"
      o:href=3D"cid:CHILKAT-CID-c6452042-1523-4af1-ac03-20963eb81e33"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image013.gif"
    v:shapes=3D"_x0000_i1116"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:8'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Third-Party Relationships<o=
:p></o:p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1117" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image008.gif"
      o:href=3D"cid:CHILKAT-CID-5685753d-bee2-4c76-b4f7-3a72ec60f0da"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image008.gif"
    v:shapes=3D"_x0000_i1117"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:9'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 6.55pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
    style=3D'font-size:9.0pt;font-family:Arial'>Training &amp; Awareness<o:=
p></o:p></span></b></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1118" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1118"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:10'>
    <td width=3D"87%" nowrap valign=3Dtop style=3D'width:87.0%;padding:3.25=
pt 0in 0in 13.1pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'>Security Awareness<o:p></o:=
p></span></p>
    </td>
    <td width=3D"13%" nowrap valign=3Dtop style=3D'width:13.0%;padding:3.25=
pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal align=3Dcenter style=3D'margin:0in;margin-bottom:.=
0001pt;
    text-align:center'><span style=3D'font-size:9.0pt;font-family:Arial'><!=
--[if gte vml 1]><v:shape
     id=3D"_x0000_i1119" type=3D"#_x0000_t75" alt=3D"" style=3D'width:7.5pt=
;height:7.5pt'>
     <v:imagedata src=3D"__2Free_Management_Security_Assessment_MSA_Executi=
ve_Analysis_Scorecard_Prioritized_Action_files/image007.gif"
      o:href=3D"cid:CHILKAT-CID-7f05e581-7f8a-4e95-b922-14e1a07ebee2"/>
    </v:shape><![endif]--><![if !vml]><img border=3D0 width=3D10 height=3D10
    src=3D"__2Free_Management_Security_Assessment_MSA_Executive_Analysis_Sc=
orecard_Prioritized_Action_files/image007.gif"
    v:shapes=3D"_x0000_i1119"><![endif]><o:p></o:p></span></p>
    </td>
   </tr>
   <tr style=3D'mso-yfti-irow:11;mso-yfti-lastrow:yes'>
    <td valign=3Dtop style=3D'padding:3.25pt 0in 0in 3.25pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:9.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>
    </td>
    <td style=3D'padding:.75pt .75pt .75pt .75pt'>
    <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
    style=3D'font-size:10.0pt'><o:p>&nbsp;</o:p></span></p>
    </td>
   </tr>
  </table>
  <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
  style=3D'font-size:9.0pt;font-family:Arial'><o:p></o:p></span></p>
  </td>
 </tr>
</table>

</div>

<h2><a name=3DImprovement></a>Security Initiatives</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The following areas f=
all
short of best practices and should be addressed to increase the security of
your environment. The <a href=3D"#Detail">Assessment Detail</a> and <a
href=3D"#Recommendations">Prioritized Action List</a> sections of this repo=
rt
include further detail for each, including the findings, best practices, and
recommendations.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;mso-border-alt:solid =
black .5pt;
   background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>High Priority<o:=
p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Medium Priority<=
o:p></o:p></span></b></p>
   </td>
   <td valign=3Dtop style=3D'border:solid black 1.0pt;border-left:none;mso-=
border-left-alt:
   solid black .5pt;mso-border-alt:solid black .5pt;background:#6487DC;
   padding:3.25pt 0in 0in 3.25pt'>
   <p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><b><span
   style=3D'font-size:9.0pt;font-family:Arial;color:white'>Low Priority<o:p=
></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes;page-break-inside:avoid'>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Servers=
<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></o:p=
></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desktop=
s<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Se=
rvers<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp; Da=
ta
  Recovery<o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Virus Signatures<o:p=
></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Protocols &amp; Serv=
ices<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detection =
System
  (IDS)<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Application Data Flo=
w<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Restore=
<o:p></o:p></span></p>
  </td>
  <td width=3D"33%" valign=3Dtop style=3D'width:33.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and F=
ilters<o:p></o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Governance<o:p></o:p=
></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host<o:p>=
</o:p></span></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup<o:p></o:p></s=
pan></p>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management Host - Ne=
twork
  Devices<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<span style=3D'font-size:10.0pt;font-family:Arial;mso-fareast-font-family:"=
Times New Roman";
mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA'=
><br
clear=3Dall style=3D'mso-special-character:line-break;page-break-before:alw=
ays'>
</span>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<h1><a name=3DDetail></a>Assessment in Detail</h1>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This section of the r=
eport
provides the detailed findings for each category, as well as best practices,
recommendations, and references for additional information. Recommendations=
 are
prioritized in the following section.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></span></p>

<h2><a name=3DAreas></a>Areas of Analysis</h2>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The following table l=
ists
the areas that were included for high-level analysis in this security risk
assessment and describes each area's relevance to security. The Assessment
Detail section of this document describes your organization's security post=
ure
(based on answers you gave during the assessment) in each of these areas and
provides industry-recognized best practices and recommendations for achievi=
ng
those practices.<o:p></o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;page-break-inside:avoi=
d'>
   <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1=
.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Cate=
gory<o:p></o:p></span></b></p>
   </td>
   <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border:solid black 1=
.0pt;
   border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:sol=
id black .5pt;
   background:#0148B2;padding:3.25pt 0in 0in 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Impo=
rtance
   to security<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
 <tr style=3D'mso-yfti-irow:1;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Busin=
ess
  Risk Profile<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:2;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Business Risk Profil=
e<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Understanding how the
  nature of your business affects risk is important in determining where to
  apply resources in order to help mitigate those risks. Recognizing critic=
al
  areas of business risk will help you to optimize allocation of your secur=
ity
  budget. <o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:3;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Infra=
structure<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:4;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Perimeter Defense<o:=
p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Perimeter defense
  addresses security at network borders, where your internal network connec=
ts
  to the outside world. This constitutes your first line of defense against
  intruders.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:5;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Rigorous authenticat=
ion
  procedures for users, administrators, and remote users help to ensure that
  outsiders do not gain unauthorized access to the network through the use =
of
  local or remote attacks.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:6;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management &amp;
  Monitoring<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Management, monitori=
ng,
  and proper logging are critical to maintaining and analyzing IT environme=
nts.
  These tools are even more important after an attack has occurred and inci=
dent
  analysis is required.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:7;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Workstations<o:p></o=
:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security of indi=
vidual
  workstations is a critical factor in the defense of any environment,
  especially when remote access is allowed. Workstations should have safegu=
ards
  in place to resist common attacks.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:8;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Appli=
cations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:9;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Deployment &amp; Use=
<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>When business-critic=
al
  applications are deployed in production, the security and availability of
  those applications and servers must be ensured. Continued maintenance is
  essential to help ensure that security bugs are patched and that new
  vulnerabilities are not introduced into the environment.<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:10;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Application Design<o=
:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Design that does not
  properly address security mechanisms such as authentication, authorizatio=
n,
  and data validation can allow attackers to exploit security vulnerabiliti=
es
  and thereby gain access to sensitive information.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:11;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Data Storage &amp;
  Communications<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Integrity and
  confidentiality of data is one of the greatest concerns for any business.
  Data loss or theft can hurt an organization's revenue as well as reputati=
on.
  It is important to understand how applications handle business critical d=
ata
  and how that data is protected.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:12;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Opera=
tions<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:13;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Environment<o:p></o:=
p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The security of an
  organization is dependent on the operational procedures, processes and
  guidelines that are applied to the environment. They can enhance the secu=
rity
  of an organization by including more than just technology defenses. Accur=
ate
  environment documentation and guidelines are critical to the operation te=
am's
  ability to support and maintain the security of the environment.<o:p></o:=
p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:14;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security Policy<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Corporate security p=
olicy
  refers to individual policies and guidelines that exist to govern the sec=
ure
  and appropriate use of technology and processes within the organization. =
This
  area covers policies to address all types of security, such as user, syst=
em,
  and data.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:15;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Backup &amp; Recover=
y<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Data backup and reco=
very
  is essential to maintaining business continuity in the event of a disaste=
r or
  hardware/software failure. Lack of appropriate backup and recovery proced=
ures
  could lead to significant loss of data and productivity.<o:p></o:p></span=
></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:16;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Patch &amp; Update
  Management<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Good management of p=
atches
  and updates is important to securing an organization's IT environment. Th=
e timely
  application of patches and updates is necessary to help protect against k=
nown
  and exploitable vulnerabilities.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:17;page-break-inside:avoid'>
  <td colspan=3D2 valign=3Dtop style=3D'border:solid black 1.0pt;border-top=
:none;
  mso-border-top-alt:solid black .5pt;mso-border-alt:solid black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Peopl=
e<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:18;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Requirements and
  Assessments<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Security requirements
  should be understood by all decision-makers so that both their technical =
and
  business decisions enhance security rather than conflict with it. Regular
  assessments by a third party can help a company review, evaluate, and
  identify areas for improvement.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:19;page-break-inside:avoid'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Policies and Procedu=
res<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Clear, practical
  procedures for managing relationships with vendors and partners can help
  limit your company's exposure to risk. Procedures covering employee hiring
  and termination can help protect your company from unscrupulous or
  disgruntled employees.<o:p></o:p></span></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:20;mso-yfti-lastrow:yes;page-break-inside:avoid=
'>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Training and Awarene=
ss<o:p></o:p></span></p>
  </td>
  <td width=3D"60%" valign=3Dtop style=3D'width:60.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Employees should be
  trained and made aware of how security applies to their daily job activit=
ies
  so that they do not inadvertently expose their company to greater risks.<=
o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>&nbsp;<o:p></o:p></sp=
an></p>

<h2><a name=3DAnalysis></a>Assessment Analysis</h2>

<p><a name=3DInfrastructure><span style=3D'font-size:10.0pt;font-family:Ari=
al'>This
section is divided into the four major areas of analysis&#8212;Infrastructu=
re,
Applications, Operations, and People.<o:p></o:p></span></a></p>

<h3><span style=3D'mso-bookmark:Infrastructure'>Infrastructure</span></h3>

<span style=3D'mso-bookmark:Infrastructure'></span>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Infrastructure securi=
ty
focuses on how the network should function, what business processes (intern=
al
or external) it must support, how hosts are built and deployed, and how the
network will be managed and maintained. Effective infrastructure security c=
an
help provide significant improvements in the areas of network defense, inci=
dent
response, network availability, and fault analysis. By establishing a sound
infrastructure design that is understood and followed, an organization can
identify areas of risk and can design methods of threat mitigation. The
assessment reviews high-level procedures that an organization can follow to
help mitigate infrastructure risk by focusing on the following areas of
infrastructure security: <o:p></o:p></span></p>

<ul type=3Ddisc>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Perimeter
     Defense&#8212;Firewalls, Anti-virus, Remote Access, Segmentation<o:p><=
/o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Authentication&#8212;Pass=
word
     Policies <o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Management &amp;
     Monitoring&#8212;Management Hosts, Log files<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l1 level1 lfo2;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Workstation&#8212;Build
     Configuration<o:p></o:p></span></li>
</ul>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Peri=
meter
   Defense<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules an=
d Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Firewalls are a firs=
t-line
  defense mechanism and should be placed at all network border locations. R=
ules
  implemented on firewalls should be highly restrictive and set on a
  host-by-host and service-by-service basis.<br>
  <br>
  When creating firewall rules and router ACLs (Access Control Lists), focu=
s on
  first protecting access control devices and the network from attack. <br>
  <br>
  <br>
  + Enforce data flow by use of network ACLs and firewall rules. <br>
  + Test firewall rules and router ACLs to determine whether or not existin=
g rules
  contribute to Denial of Service (DoS) attacks.<br>
  + Deploy one or more DMZs as part of a systematic and formal firewall
  development. <br>
  + Place all Internet accessible servers there. Restrict connectivity to a=
nd
  from the DMZs.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  not only have you deployed firewalls at network borders, you have also ta=
ken
  an extra precaution by creating one or more DMZ segments to protect
  Internet-accessible resources.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review firewall poli=
cies
  regularly and prune old or improper rules. Implement rules for controlling
  inbound and outbound access and consider implementing egress filtering to
  prevent unnecessary outbound connections.<br>
  <br>
  Limit internal users' direct access to DMZ segments as it is not likely t=
hey
  would work with the host computers that reside in the DMZ on a regular ba=
sis.
  Limit access from the core network into the DMZ segment to only specific
  hosts or administrative networks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  host-based firewall software is used to protect servers.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue installing
  host-based firewalls on all servers, and consider extending this software=
 to
  all desktops and laptops in the organization also.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Securing Your Netw=
ork<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This article, written=
 for
network administrators and IT professionals, presents an overview of the top
network-level threats and the ways in which you can counter them. The autho=
rs
review security issues and the configuration settings to be applied to rout=
ers,
firewalls and switches.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh15.asp"
target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMC=
h15.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>FAQ About Internet
Firewalls<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This FAQ is appropria=
te for
users who are not IT professionals and who have questions about using and
deploying a firewall.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/security/protect/firewall.asp" target=3D"_=
new">http://www.microsoft.com/security/protect/firewall.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Deploy anti-virus
  solutions throughout the environment on both the server and desktop level=
s.
  Deploy specialized anti-virus solutions for specific tasks such as file
  server scanners, content screening tools, and data upload and download
  scanners. Configure anti-virus solutions to scan for viruses both entering
  and leaving the environment.<br>
  <br>
  Anti-virus solutions should be implemented first on critical file servers=
 and
  then extended to mail, database, and Web servers.<br>
  <br>
  For desktops and laptops an anti-virus solution should be included in the
  default build environment.<br>
  <br>
  If you are using Microsoft Exchange, use the additional anti-virus and
  content filtering-capabilities it offers at the mailbox level.<o:p></o:p>=
</span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  perimeter hosts have anti-virus software installed.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  email servers have anti-virus software installed.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>FAQ About Anti-vir=
us
Software<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This FAQ is appropria=
te for
users who are not IT professionals and who have questions about using antiv=
irus
software.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/security/protect/antivirus.asp" target=3D"=
_new">http://www.microsoft.com/security/protect/antivirus.asp</a><o:p></o:p=
></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desk=
tops<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Desk=
tops<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  anti-virus solutions have not been deployed at the desktop level.<o:p></o=
:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider deploying an
  anti-virus solution to all employees' laptops and/or desktops. Add the
  anti-virus client in the default workstation build environment.<o:p></o:p=
></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Serv=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Anti-virus - Serv=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  anti-virus solutions have not been deployed at the server level.<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider deploying an
  anti-virus solution to critical file servers initially and then to e-mail,
  database, and web servers. If you are using Microsoft Exchange, consider
  using the additional anti-virus and content-filtering capabilities at the
  mailbox level.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Workstations are a
  critical factor in the defense of any environment, especially if there are
  remote and roaming users that connect to the environment.<br>
  <br>
  Tools such as personal firewalls, anti-virus, and remote-access software
  should be present and properly configured on all workstations. <br>
  <br>
  Implement a policy which requires periodic review of these tools to make =
sure
  their configurations reflect changes in applications and services being u=
sed,
  but at the same time still keep the workstation resistant to attacks.<o:p=
></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  remote access to your organization's network is available<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  not only have you implemented a VPN for remote access, but you have also
  incorporated multifactor authentication as a second line of defense.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Regularly audit the =
access
  list for all the users on the VPN device. Consider managing the VPN device
  from inside the corporate network only.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  employees and/or partners remotely connect to your internal network, but =
no
  VPN technology is currently being used to secure access for these users.<=
o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Deploy VPN for
  remote-user-access connectivity based on IP Security (IPSec), Secure Sock=
ets
  Layer (SSL), and Secure Shell (SSH) technologies.<br>
  <br>
  Deploy site-to-site connectivity based on IPSec technology. Configure net=
work
  access lists and user access lists for restricting access to necessary
  corporate resources.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote Access<o:p=
></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the VPN is capable of limiting connectivity to <span class=3DGramE>a quar=
antine</span>
  until all necessary security checks have been passed.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best =
Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Use segmentation to
  separate specific extranets from vendor, partner, and customer access.<br>
  <br>
  Each external network segment should allow only specific application traf=
fic
  to be routed to the specific application hosts and ports that are used to
  supply services to customers.<br>
  <br>
  Ensure that network controls are in place to restrict access to only what=
 is
  required for each third-party connection.<br>
  <br>
  Restrict access to and from the network services being provided, and rest=
rict
  access between network segments.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that Internet-facing services are hosted on your organization's network<o=
:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Ensure that firewall=
s,
  segmentation and intrusion-detection systems are in place in order to pro=
tect
  the company's infrastructure from Internet-based attacks.<o:p></o:p></spa=
n></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the network has more than one segment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue using netwo=
rk
  segmentation in order to better manage network traffic and limit access t=
o resources
  based on user requirements.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answer indicate=
s that
  network segmentation is not currently being used in the environment. It is
  important to keep customer-/partner-specific extranet services on their o=
wn
  network segments.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Move extranet access
  servers to a physically separate network segment.<br>
  <br>
  Apply restrictive access controls to allow third-party access to specific
  hosts only, restrict access to only necessary corporate infrastructure, a=
nd
  block connection attempts to remote networks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  hosts are grouped into network segments based on offering similar service=
s.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Segmentation<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  hosts are grouped into network segments based on providing only the neces=
sary
  services for the users that connect.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement complex pa=
ssword
  controls for all users of remote access, whether this access is granted
  through the use of dial-up or VPN technologies. A password is considered =
to
  be complex if it meets the following criteria:<br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<br>
  <br>
  Implement an additional factor of authentication for accounts that are
  granted remote access. Also consider implementing advanced controls around
  account management (do not allow sharing of accounts) and account access
  logging.<br>
  <br>
  In the case of remote access, it is especially important to protect the
  environment through the use of strong account management practices, sound
  logging practices, and incident detection capabilities. To further mitiga=
te
  the risks of brute-force password attacks, consider implementing the
  following controls:<br>
  <br>
  <br>
  + Password expiration<br>
  + Account lockout after 7 to 10 failed login attempts<br>
  + System logging<br>
  <br>
  Remote-access services should also take into account systems that will be
  used to access the network or hosts. Also consider implementing controls
  around hosts that are allowed to access the network via remote access.<o:=
p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  employees are not able to remotely connect to the network.<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>By not allowing remo=
te
  access, you reduce your overall risk. However if remote access is planned=
 or
  implemented in the future, be sure to follow best practice when deploying=
 the
  remote-access solution in order to minimize the risk associated with that
  access.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  contractors are not able to remotely connect to the network.<o:p></o:p></=
span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>By not allowing remo=
te
  access, you reduce your overall risk. However if remote access is planned=
 or
  implemented in the future, be sure to follow best practice when deploying=
 the
  remote-access solution in order to minimize the risk associated with that
  access.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  third parties are not able to remotely connect to the network.<o:p></o:p>=
</span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>By not allowing remo=
te
  access, you reduce your overall risk. However if remote access is planned=
 or
  implemented in the future, be sure to follow best practice when deploying=
 the
  remote-access solution in order to minimize the risk associated with that
  access.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Both network- and
  host-based intrusion-detection systems should be deployed to detect and
  notify of attacks against corporate systems.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are using intrusion-detection hardware or software.<o:p></o:p></span>=
</p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using a host-based intrusion-detection system (HIDS)<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider deploying
  host-based intrusion-detection systems, which can help notify administrat=
ors
  that an attack is occurring against your hosts and help the administrators
  respond in a timely manner.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Intrusion-Detecti=
on
  System (IDS)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are using a network-based intrusion-detection system (NIDS)<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue the practic=
e of
  deploying a network-based intrusion-detection system. Ensure that the
  signatures are kept current, and investigate intrusion-prevention technol=
ogy
  as it becomes more widely available.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Auditing &amp; Int=
rusion
Detection<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This document provide=
s a
high-level overview of what types of events you should be logging and their
importance in trying to detect an intruder. It also covers different monito=
ring
techniques and detection methods.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/security/prodtech/win2000/secwin2k/09detect.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/security/prodtech/win2000/secwin2k/09detect.asp</a><o:p></o:p><=
/span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Best practice for wi=
reless
  implementation should include ensuring that the network does not broadcast
  its SSID; that WPA encryption is used; that the network is fundamentally
  treated as untrustworthy.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  wireless connectivity to the network is available<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>In order to minimize=
 the
  risk associated with wireless networks, the implementation should include
  non-broadcast of SSID, WPA encryption, and treating the network as untrus=
ted.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  the wireless network is not treated as untrusted.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider <span
  class=3DGramE>migrating</span> your wireless network to an untrusted netw=
ork
  segment and requiring the use of VPN or similar technologies in order to
  better preserve data integrity.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using WEP encryption in your wireless environment.<o:p></o:p>=
</span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>If you are currently=
 using
  no encryption, consider using WPA to prevent wireless network traffic fro=
m being
  'sniffed' and read as clear text.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using WPA encryption in your wireless environment.<o:p></o:p>=
</span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>If you are currently=
 using
  no encryption, consider using WPA to prevent wireless network traffic from
  being 'sniffed' and read as clear text.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you have not disabled broadcasting of the SSID on the access point.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider disabling S=
SID
  broadcast to make it more difficult for a casual user to attempt to conne=
ct
  to your wireless network.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are not using MAC restrictions in your wireless environment.<o:p></o:=
p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider using WPA
  authentication in addition to MAC filtering in order to prevent unauthori=
zed
  computers from connecting to the network.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Wireless<o:p></o:=
p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response is tha=
t you
  have changed the SSID on the access point from the default.<o:p></o:p></s=
pan></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Changing the default=
 SSID
  is the first step in securing your wireless network. However, this needs =
to
  be combined with further best practices in order to minimize risk. These
  include non-broadcast of SSID, WPA encryption, and treating the network as
  untrusted.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Auth=
entication<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Administrative Us=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>For administrative
  accounts, implement a strict policy that requires the use of complex
  passwords that meet the following criteria:<br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 14 characters<br>
  <br>
  To further mitigate the risk of a password attack, implement the following
  controls:<br>
  <br>
  + Password expiration<br>
  + Account lockout after 7 to 10 failed login attempts<br>
  + System logging<br>
  <br>
  In addition to implementing complex passwords, consider implementing
  multifactor authentication. Implement advanced controls around account
  management (do not allow account sharing) and account-access logging.<o:p=
></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Administrative Us=
ers<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
ed
  that currently there is either none or only simple password authentication
  required for administrative access to manage devices and hosts.<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  complex password controls for all administrative accounts and service
  accounts. A password is considered to be complex if it meets the following
  criteria:<br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internal Users<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>For user accounts,
  implement a policy that requires the use of complex passwords that meet t=
he
  following criteria<span class=3DGramE>:</span><br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<br>
  <br>
  To further mitigate the risk of a password attack implement the following
  controls:<br>
  <br>
  <br>
  + Password expiration<br>
  + Account lockout after at least 10 failed login attempts<br>
  + System logging<br>
  <br>
  In addition to complex passwords, consider implementing multifactor
  authentication.<br>
  <br>
  Implement advanced controls around account management (do not allow shari=
ng
  of accounts) and account-access logging.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internal Users<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  multifactor authentication is required for user access to the internal
  network and hosts.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To further mitigate =
the
  risk of access to the environment being gained through low-level user
  accounts, consider implementing the following controls<span class=3DGramE=
>:</span><br>
  <br>
  + Password expiration<br>
  + Account lockout after at least 10 failed login attempts<br>
  + System logging<br>
  <br>
  Ensure that password controls for both local and domain accounts are
  enforced.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement complex pa=
ssword
  controls for all users of remote access, whether this access is granted
  through the use of dial-up or VPN technologies. A password is considered =
to
  be complex if it meets the following criteria:<br>
  <br>
  <br>
  + Alphanumeric<br>
  + Upper and lower case<br>
  + At least one special character<br>
  + Minimum length of 8 characters<br>
  <br>
  Implement an additional factor of authentication for accounts that are
  granted remote access. Also consider implementing advanced controls around
  account management (do not allow sharing of accounts) and account access
  logging.<br>
  <br>
  In the case of remote access, it is especially important to protect the
  environment through the use of strong account management practices, sound
  logging practices, and incident detection capabilities. To further mitiga=
te
  the risks of brute-force password attacks, consider implementing the
  following controls:<br>
  <br>
  <br>
  + Password expiration<br>
  + Account lockout after 7 to 10 failed login attempts<br>
  + System logging<br>
  <br>
  Remote-access services should also take into account systems that will be
  used to access the network or hosts. Also consider implementing controls
  around hosts that are allowed to access the network via remote access.<o:=
p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Remote-Access Use=
rs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You indicated that
  multifactor authentication is required for users who remotely access your
  internal network and host computers.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To further mitigate =
the
  risks of brute-force password attacks through remote access services,
  consider implementing the following controls:<br>
  <br>
  + Password expiration<br>
  + Account logout<br>
  + System logging<br>
  <br>
  In the case of remote access, it is especially important to protect the
  environment through the use of strong account management practices, sound
  logging practices, and incident detection capabilities.<br>
  <br>
  Remote-access services should also take into account the systems that wil=
l be
  used to access the network or hosts. Consider implementing controls around
  the hosts that are allowed to access the network via remote access.<o:p><=
/o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Typically the restri=
ctions
  around creating passwords for administrators should be greater than those=
 for
  normal accounts.<br>
  <br>
  On Windows systems, administrative accounts (and service accounts) should=
 be
  set with passwords that are 14 characters in length and use alphanumeric =
and
  special characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Administrator Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Administrator Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  administrator accounts have password policies implemented.<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  additional protections around administrative accounts, such as logging and
  monitoring services, around all successful and failed authentications.<br>
  <br>
  Migrate away from clear text protocols.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  User Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  User Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  user accounts have password policies implemented.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  logging thresholds around failed authentications so that alerts can be se=
nt to
  systems administrators.<br>
  <br>
  Consider testing the password policies in place.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Remote-Access Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
 -
  Remote-Access Account<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  remote access accounts have password policies implemented.<o:p></o:p></sp=
an></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  additional security around remote-access accounts through the use of logg=
ing
  and monitoring services on the remote-access device/host.<br>
  <br>
  Consider implementing logging thresholds around failed authentications so
  that alerts can be sent to systems administrators.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Mana=
gement
   and Monitoring<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Build<o:p></o:p><=
/span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Maintain a build pro=
cess
  with all vendor patches and recommended lockdown configuration. Test this
  process regularly.<br>
  <br>
  Use host-hardening procedures to patch and properly configure services and
  applications on each host. Disable all nonessential services and
  applications.<br>
  <br>
  Workstations should be hardened by installing recommended patches, removi=
ng
  all unnecessary services and packages, and auditing file permissions.<br>
  <br>
  Incorporate host-hardening steps into standard workstation build procedur=
es.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your system builds include host-hardening procedures.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  remote control/management software is not used in the environment.<o:p></=
o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue the practic=
e of
  not using remote control/management software.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  disk-encryption software is not used in the environment.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider using disk
  encryption software in order to prevent data compromise in the event of
  machine theft.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat a
  password-protected screen saver is not used in the environment.<o:p></o:p=
></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider requiring a=
ll
  users to have a password-protected screen saver with a short time-out per=
iod.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  personal firewalls have not been installed on all of the workstations in =
the
  environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Implement a policy w=
hich
  calls for periodic review of default firewall settings, so as to allow for
  changes in applications or services being used.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  client-side remote access software has been installed on workstations that
  connect remotely to the internal network.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider using a sin=
gle
  remote-access solution for the environment, if there are multiple types of
  solution deployed.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Secure Build<o:p>=
</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  modems are not used in the environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue disabling m=
odem
  and dial-up access in order to reduce the risk of having machines able to=
 be
  directly dialed into.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Windows Server 2003
Security Guide<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This guide provides
easy-to-understand advice, tools, and templates to help you secure
Microsoft&reg; Windows Server&#8482; 2003 operating system in many
environments. Network administrators and IT professionals responsible for
installing and configuring servers would likely benefit the most from this
information.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/security/prodtech/win2003/w2003hg/sgch00.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/security/prodtech/win2003/w2003hg/sgch00.asp</a><o:p></o:p></sp=
an></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Microsoft Gold Cer=
tified
Partners<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>The Microsoft&reg; Go=
ld
Certified Partner Program for Security Solutions will help you find special=
ists
in building and deploying IT solutions that help protect user security. Mic=
rosoft
works closely with partners to help ensure they have the highest level of
expertise with Microsoft technologies and solutions.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://directory.microsoft.com/resourcedirectory/Services.aspx"
target=3D"_new">http://directory.microsoft.com/resourcedirectory/Services.a=
spx</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Securing Your Data=
base
Server<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Database architects a=
nd
database administrators will benefit most from this guide, which provides a
proven methodology for securing database servers--Microsoft&reg; SQL
Server&#8482; in particular. The guide reviews the most common threats that
affect database servers, then steps through the process of applying a secure
configuration.<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMCh18.asp"
target=3D"_new">http://msdn.microsoft.com/library/en-us/dnnetsec/html/THCMC=
h18.asp</a><o:p></o:p></span></p>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>passfilt.dll<o:p><=
/o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>Passfilt.dll is a
replacement .dll for Microsoft&reg; Windows NT&reg; 4.0 operating system. U=
sing
passfilt, you can modify the operating system's default parameters to provi=
de
strong password support and administrative account lockout (at the network
level).<o:p></o:p></span></p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://msdn.microsoft.com/library/default.asp?url=3D/library/en-us/=
security/security/strong_password_enforcement_and_passfilt_dll.asp"
target=3D"_new">http://msdn.microsoft.com/library/default.asp?url=3D/librar=
y/en-us/security/security/strong_password_enforcement_and_passfilt_dll.asp<=
/a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party
  Relationships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To help reduce the r=
isk of
  exposure, formal policies and procedures should exist to govern relations=
hips
  with third parties. These policies and procedures help to identify securi=
ty
  issues and the responsibilities of each party in mitigating them. <br>
  <br>
  These policies should include: <br>
  + Level of connectivity and access <br>
  + Data presentation and manipulation <br>
  + Roles and responsibilities (including authority) of each party <br>
  + Management of the relationship&#8212;setup, ongoing, and termination.<o=
:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-Party
  Relationships<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  systems are configured by internal staff.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Systems should be
  configured by internal staff following a tested build image.<o:p></o:p></=
span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>All computer systems
  should be secured to prevent easy theft. Servers and networking equipment
  should be secured in locked cabinets in locked rooms with controlled acce=
ss.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
ted
  that physical security controls have been deployed to secure your
  organization's assets.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue use of phys=
ical
  controls, and consider extending them to all computer equipment, if that =
has
  not already been done.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  servers are not in a lockable cabinet or rack.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Having servers in a
  lockable cabinet/rack further protects against unauthorized tampering. If
  possible, consider migrating servers to lockable enclosures.<o:p></o:p></=
span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat an
  alarm system has not been installed to detect and report break-ins<o:p></=
o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider installing =
an
  alarm system in order to detect and report break-ins.<o:p></o:p></span></=
p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  networking equipment is not in a locked room with restricted access.<o:p>=
</o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Networking equipment
  should be secured in a locked room or closet. Plan to <span class=3DGramE=
>migrate</span>
  network equipment to a more secure area.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  workstations are not secured with cable locks<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>In order to prevent =
theft,
  consider securing workstations with cable locks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  laptops are not secured with cable locks<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>In order to prevent =
theft,
  consider securing laptops with cable locks.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  sensitive printed materials are not stored in locked file cabinets.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Sensitive documents =
should
  be kept in locked cabinets in order to prevent theft and disclosure of
  sensitive information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  network equipment is also in a lockable cabinet or rack.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Having network equip=
ment
  in a lockable cabinet/rack further protects against unauthorized tamperin=
g.
  Ensure that access to keys/combinations is limited to only those who have=
 a
  business need.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Physical Security=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  servers are not in a locked room with restricted access.<o:p></o:p></span=
></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Servers should be se=
cured
  in a locked room or closet. Plan to <span class=3DGramE>migrate</span> the
  servers to a more secure area.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<h3>Resources</h3>

<p><b><span style=3D'font-size:10.0pt;font-family:Arial'>Basic Physical Sec=
urity<o:p></o:p></span></b></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'>This resource provide=
s a
snapshot of the three basic principles of physical security: keeping people
away, keeping people out, and protecting your plumbing.<o:p></o:p></span></=
p>

<p><span style=3D'font-size:8.0pt;font-family:Arial'><a
href=3D"http://www.microsoft.com/technet/treeview/default.asp?url=3D/techne=
t/columns/security/5min/5min-203.asp"
target=3D"_new">http://www.microsoft.com/technet/treeview/default.asp?url=
=3D/technet/columns/security/5min/5min-203.asp</a><o:p></o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

</div>

<h3>Applications</h3>

<div>

<p><a name=3DApplications></a><span style=3D'font-size:10.0pt;font-family:A=
rial'>A
thorough understanding of application security requires in-depth knowledge =
of
the basic underlying application architecture as well as a solid understand=
ing
of the application's user base. Only then can you begin identifying the
potential threat vectors.<br>
<br>
Given the limited scope of this self assessment, a complete analysis of
application architecture and thorough understanding of the user base is not
possible. This assessment is meant to help you review applications within y=
our
organization and assess them from a security and availability standpoint. It
examines technologies used within the environment to help enhance
Defense-in-Depth. The assessment reviews the high level procedures an organ=
ization
can follow to help mitigate application risk by focusing on the following a=
reas
of application security:<o:p></o:p></span></p>

<ul type=3Ddisc>
 <li class=3DMsoNormal style=3D'mso-list:l2 level1 lfo3;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Deployment &amp;
     Use&#8212;Mechanisms to enhance availability<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l2 level1 lfo3;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Application Design
     &#8212;Authentication, Access Control, Update Management, Input
     Validation, Logging &amp; Auditing<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l2 level1 lfo3;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Data Storage &amp;
     Communications&#8212;Encryption, Data Transfer, Restrictive Access<o:p=
></o:p></span></li>
</ul>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Appl=
ications<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Load-Balancing<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Load-Balancing<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  load balancers are currently deployed in the environment.<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Periodically audit t=
he
  configuration of your load balancers and run diagnostics on a regular bas=
is
  to make sure they are functioning properly.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Clustering<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  clustering is not deployed in your environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To ensure high
  availability for critical databases and file shares, consider deploying
  clustering mechanisms.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp;=
 Data
  Recovery<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:Arial'><o=
:p>&nbsp;</o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp;=
 Data
  Recovery<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization has line of business applications<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Any Line of Business
  applications should be periodically evaluated for security, backed up
  regularly, fully documented, and <span class=3DGramE>have</span> continge=
ncies
  in place in case they fail.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Application &amp;=
 Data
  Recovery<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that regular testing of application and data recovery is not performed.<o=
:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Perform full backups
  regularly. Perform regular tests of the backup and recovery mechanism that
  permits restoration of the application to a normal operating state.<o:p><=
/o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party indep=
endent
  software vendor (ISV)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The third-party
  independent software vendor (ISV) should regularly provide patches and up=
grades
  for their application, and they should explain the purpose of patches and=
 any
  impact you may expect in terms of the functionality, configuration, or
  security of the application being patched. <br>
  <br>
  The third-party ISV should clearly identify critical patches so that they=
 can
  quickly be applied. <br>
  <br>
  The third-party ISV should explain all of the application's security
  mechanisms and provide up-to-date documentation. <br>
  <br>
  The organization should be aware of any configuration requirements necess=
ary
  to ensure the highest level of security.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party indep=
endent
  software vendor (ISV)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  third party vendors have developed one or more of the key applications in
  your environment.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Ensure that the third
  party who has developed your key software will continue to support that
  software, provide updates in a timely manner, and can provide you with so=
urce
  code in the event that the third party can no longer support the applicat=
ion.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Third-party indep=
endent
  software vendor (ISV)<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you do not know the answer to this question<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Review this open ite=
m with
  your IT staff or a security partner. Input the most appropriate answer to
  this question in the MSAT for further information.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internally Develo=
ped<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The in-house develop=
ment
  team should regularly provide patches and upgrades for their application,=
 and
  they should explain the purpose of patches and any impact you may expect =
in
  terms of the functionality, configuration, or security of the application
  being patched <br>
  <br>
  The development team should clearly identify critical patches so that the
  organization can quickly apply them. <br>
  <br>
  The development team should explain all of the application's security
  mechanisms and provide up-to-date documentation. <br>
  <br>
  The organization should be aware of any configuration requirements necess=
ary
  to ensure the highest level of security. <br>
  <br>
  Consider contracting with an independent third party to review the
  application's architecture and deployment and identify any security issue=
s of
  concern.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internally Develo=
ped<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  your organization uses custom macros for office applications.<o:p></o:p><=
/span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Using custom macros
  requires that the security settings in Office are downgraded, exposing yo=
ur
  office applications to malicious documents. Consider limiting the ability=
 to
  develop and run custom macros to only those that have a business need.<o:=
p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Internally Develo=
ped<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your responses indic=
ate
  that your in-house development team provides you with regular software
  updates and security patches for applications developed by them. <o:p></o=
:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue to work wit=
h the
  development team to address all application and security issues in the
  deployed applications.<br>
  <br>
  When a patch is made available, thoroughly test the patch in a lab
  environment before deploying it into production.<br>
  <br>
  Work with the development team to audit the application configuration to
  ensure maximum security.<br>
  <br>
  Consider contracting with an independent third party to review the
  application's architecture and deployment and identify any security issue=
s of
  concern.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Vulnerabilities<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>All known security
  vulnerabilities should be identified and patched. Regularly monitor vendor
  and third-party security sites for new vulnerability information and
  available patches. <br>
  <br>
  If there are any known security vulnerabilities that do not have available
  patches, determine when a patch will be available and develop an interim
  mitigation plan to address that vulnerability. <br>
  <br>
  Consider using a third party to conduct periodic assessments to evaluate =
the
  application's security design. A third-party assessment may also turn up
  areas where additional security mechanisms are beneficial.<o:p></o:p></sp=
an></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Vulnerabilities<o=
:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your responses indic=
ate
  that procedures exist for addressing known security vulnerabilities in
  applications you are currently using.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>These procedures sho=
uld
  include lab testing of the patches as well as application testing after t=
he
  patch has been applied, to identify conflicts that may require the patch =
to
  be rolled back.<br>
  <br>
  Periodically revisit these procedures and verify that they meet current
  application requirements.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Appl=
ication
   Design<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The application shou=
ld
  implement an authentication mechanism whose strength is commensurate with
  requirements governing security of data or access to functionality.
  Applications that rely on passwords should provide for password complexity
  constraints that include character mix (alpha, numeric, and symbols), min=
imum
  length, history maintenance, enforced lifetime, pre-expiration, and
  dictionary checking. <br>
  <br>
  The application should log failed login attempts, excluding the password.
  Each component that provides access to data or functionality should verify
  the existence of proper authentication credentials. <br>
  <br>
  Administrative access to systems should be protected with the strongest f=
orms
  of authentication available. Typically the restrictions around password c=
reation
  for administrators should be greater than those for normal accounts.<br>
  <br>
  In addition to strong passwords with good password policies, for added
  security multifactor authentication should be considered.<o:p></o:p></spa=
n></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authentication<o:=
p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your responses indic=
ate
  that multifactor authentication is being used for key applications.<o:p><=
/o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>To further mitigate =
the
  risks of brute-force password attacks for external applications, consider
  implementing the following controls:<br>
  <br>
  + Password expiration<br>
  + Account lockout after at least 10 failed login attempts<br>
  + System logging<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The use of strong
  passwords is a basic element of Defense-in-Depth. Strong passwords should=
 be
  8 to 14 characters in length, with alphanumeric and special characters.
  Minimum length, history maintenance, lifetime, and pre-expiration of
  passwords should all be set to provide additional defenses to password
  strength. In general, password expiration should be set to the following:=
<br>
  <br>
  + Maximum length 90 days<br>
  + New accounts must change password at login<br>
  + Password history of 8 passwords (8 days minimum)<br>
  <br>
  Administrative access to systems should be protected with the strongest f=
orms
  of authentication available. Typically, the restrictions around password =
creation
  for administrators should be greater than those for normal accounts&#8212=
;if
  normal accounts require a password length of 8 characters, then
  administrative accounts should have 14-character passwords.<br>
  <br>
  Account lockout, after 10 failed login attempts, should be enabled on all
  user accounts. The controls around account lockout can vary from simply b=
eing
  focused on blocking brute-force password attacks to as complex as requiri=
ng
  administrator intervention to unlock. Consider the following guidelines w=
hen
  implementing controls around account lockout:<br>
  <br>
  + Account lockout after at least 10 failed login attempts for user accoun=
ts<br>
  + Require administrative access to re-enable accounts for critical
  applications and automatically re-enable regular user accounts after 5
  minutes for other applications<br>
  + 30-minute length to cache failures for regular user accounts<o:p></o:p>=
</span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that strong password controls are implemented across key applications.<o:=
p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  logging thresholds around failed authentications so that alerts can be se=
nt
  to systems administrators. Also consider extending the use of strong
  passwords across all applications.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes that
  account lockout controls are not implemented across key applications.<o:p=
></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Think about implemen=
ting
  account lockout (after 10 failed attempts), initially for all critical
  external applications. The controls around account lockout can vary from
  being focused on blocking brute-force password attacks to as complex as
  requiring administrator intervention to unlock the account. Consider the
  following guidelines when implementing controls around account lockout:<b=
r>
  <br>
  + Lockout after 10 failed login attempts<br>
  + Require administrative access to re-enable accounts<br>
  + 30 minute length to cache failures for regular user accounts<o:p></o:p>=
</span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Password Policies=
<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that a password-expiration control is not implemented across key
  applications.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider implementing
  password expiration for all types of accounts for critical applications b=
ased
  on the guidelines mentioned in the Best Practice column. In general, pass=
word
  expiration should be set to the following:<br>
  <br>
  + Maximum length 90 days<br>
  + New accounts must change password at login<br>
  + Password history of 8 passwords (8 days minimum)<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authorization &am=
p;
  Access Control<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Applications should
  implement an authorization mechanism that provides access to sensitive da=
ta
  and functionality only to suitably permitted users or clients.<br>
  <br>
  Role-based access controls should be enforced at the database level as we=
ll
  as at the application interface. <br>
  <br>
  This will protect the database in the event that the client application is
  exploited. <br>
  <br>
  Authorization checks should require prior successful authentication to ha=
ve
  occurred. <br>
  <br>
  All attempts to obtain access without proper authorization should be logg=
ed. <br>
  <br>
  Conduct regular testing of key applications that process sensitive data a=
nd
  of the interfaces available to users from the Internet. Include both
  &quot;black box&quot; and &quot;informed&quot; testing against the
  application. Determine if users can gain access to data from other accoun=
ts. <o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Authorization &am=
p;
  Access Control<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that key applications restrict access to sensitive data and functionality
  based on privileges assigned to the account.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider conducting
  focused application testing on key applications that process sensitive da=
ta
  and on the interfaces available to users from the Internet.<br>
  <br>
  Include both 'black box' and 'informed' testing against the application a=
nd
  test for privilege escalation.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Logging should be en=
abled
  across all applications in the environment. Log file data is important for
  incident and trend analysis as well as for auditing purposes. <br>
  <br>
  The applications should log failed and successful authentication attempts,
  changes to application data including user accounts, severe application
  errors, and failed and successful access to resources. <br>
  <br>
  When writing log data, the application should avoid writing sensitive dat=
a to
  log files.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your answers indicat=
e that
  various events are being logged by applications in the environment. The a=
pplications
  should log all events based on listed best practices.<o:p></o:p></span></=
p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>For ease of log-file
  management and analysis, consider integrating with a centralized logging
  mechanism. The logging mechanism should retain and archive logs in accord=
ance
  with applicable corporate data retention policies.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  changes to user accounts are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging cha=
nges
  to user accounts in order to detect privilege escalations and unauthorized
  new account creations.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  successful access to resources is not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging
  successful access to resources in order to trace malicious behavior after=
 the
  fact.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  access denied to resources is not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging acc=
ess
  denied to resources in order to be able to detect attempts at privilege
  escalation.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  changes to data are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging cha=
nges
  to data in order to track malicious activity.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  application errors are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging
  application errors in order to be able to troubleshoot and detect any Tro=
jan
  horses or malicious code.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  successful authentications are not logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider logging
  successful authentications in order to track user activity.<o:p></o:p></s=
pan></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Logging<o:p></o:p=
></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  failed authentication attempts are logged.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue logging fai=
led
  authentication attempts.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The application may =
accept
  input at multiple points from external sources, such as users, client app=
lications,
  and data feeds. It should perform validation checks of the syntactic and
  semantic validity of the input. It should also check that input data does=
 not
  violate limitations of underlying or dependent components, particularly
  string length and character set. <br>
  <br>
  All user-supplied fields should be validated at the server side.<o:p></o:=
p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that input from data feeds is not validated.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Work with the applic=
ation
  vendor (ISV or internal development team) to implement mechanisms to vali=
date
  all data input.<br>
  <br>
  The validation constraints to input data should accept data that is
  syntactically and semantically correct; the constraints should not rely
  solely on screening of input for invalid characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that all end-user input is validated.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Continue to audit ea=
ch
  application to ensure that user input is consistently and appropriately
  validated.<br>
  <br>
  The validation constraints to input data should accept data that is
  syntactically and semantically correct; the constraints should not rely
  solely on screening of input for invalid characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Input Validation<=
o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that client application input is not validated.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Work with the applic=
ation
  vendor (ISV or internal development team) to implement mechanisms to vali=
date
  all data input.<br>
  <br>
  The validation constraints to input data should accept data that is
  syntactically and semantically correct; the constraints should not rely
  solely on screening of input for invalid characters.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Data
   Storage &amp; Communications<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Sensitive data shoul=
d be
  encrypted or hashed in the database and file system. The application shou=
ld
  differentiate between data that is sensitive to disclosure and must be
  encrypted, data that is sensitive only to tampering and for which a keyed
  hash value (HMAC) must be generated, and data that can be irreversibly
  transformed (hashed) without loss of functionality (such as passwords). T=
he
  application should store keys used for decryption separately from the
  encrypted data. <br>
  <br>
  Sensitive data should be encrypted prior to transmission to other compone=
nts.
  Verify that intermediate components that handle the data in clear-text fo=
rm,
  prior to transmission or subsequent to receipt, do not present an undue
  threat to the data. The application should take advantage of authenticati=
on
  features available within the transport security mechanism. <br>
  <br>
  Examples of widely accepted strong ciphers are 3DES, AES, RSA, RC4, and
  Blowfish. Use 128-bit keys (1024 bits for RSA) at a minimum.<o:p></o:p></=
span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption<o:p></=
o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Your response indica=
tes
  that key applications in your environment are encrypting sensitive data p=
rior
  to transmission. Your answer indicates that key applications in your
  environment do encrypt sensitive data that is in storage.<o:p></o:p></spa=
n></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Use industry-standard
  encryption algorithms for all encryption.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption - Algo=
rithm<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>The application shou=
ld use
  industry-standard cryptographic algorithms with keys of appropriate sizes=
 and
  cryptographic modes appropriate to the need. <br>
  <br>
  Industry recognized strong ciphers include 3DES, AES, RSA, Blowfish, and =
RC4.
  <br>
  <br>
  A minimum key size of 128 bits (1024 bits for RSA) should be used.<o:p></=
o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Findi=
ngs<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Recom=
mendations<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Encryption - Algo=
rithm<o:p></o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>You have indicated t=
hat
  you are using DES encryption.<o:p></o:p></span></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Consider upgrading y=
our
  encryption to 3DES or AES in order to make it much more difficult to break
  through brute-force techniques.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-top:0in;margin-right:0in;margin-bottom=
:12.0pt;
margin-left:0in'><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&n=
bsp;</o:p></span></p>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

</div>

<h3>Operations</h3>

<div>

<p><a name=3DOperations></a><span style=3D'font-size:10.0pt;font-family:Ari=
al'>This
area of analysis examines the operational practices, procedures, and guidel=
ines
followed by the organization to help enhance Defence-in-Depth. This assessm=
ent
examines policies and procedures that govern system builds, network
documentation, and the use of technology within the environment. It also
includes supporting activities required to manage the information and
procedures used by the administrators and operations staff within the
environment. By establishing operational practices, procedures, and guideli=
nes
that are understood and followed, an organization can potentially enhance i=
ts
Defense-in-Depth posture. The assessment reviews high level procedures an
organization can follow to help mitigate operations risk by focusing on the=
 following
areas of operations security:<o:p></o:p></span></p>

<ul type=3Ddisc>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Environment&#8212;System =
Build,
     Network Documentation, Application Data Flow, Application Architecture=
<o:p></o:p></span></li>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Security Policy&#8212;Pro=
tocols
     &amp; Services, Acceptable Use, User Account Management <o:p></o:p></s=
pan></li>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Patch &amp; Update
     Management&#8212;Patch Management, Virus Signatures<o:p></o:p></span><=
/li>
 <li class=3DMsoNormal style=3D'mso-list:l6 level1 lfo4;tab-stops:list .5in=
'><span
     style=3D'font-size:10.0pt;font-family:Arial'>Backup &amp;
     Recovery&#8212;Backup, Storage, Testing<o:p></o:p></span></li>
</ul>

</div>

<p><span style=3D'font-size:10.0pt;font-family:Arial'><o:p>&nbsp;</o:p></sp=
an></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <thead>
  <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes'>
   <td width=3D"100%" valign=3Dtop style=3D'width:100.0%;border:solid black=
 1.0pt;
   mso-border-alt:solid black .5pt;background:#0148B2;padding:3.25pt 0in 0i=
n 3.25pt'>
   <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Envi=
ronment<o:p></o:p></span></b></p>
   </td>
  </tr>
 </thead>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Subca=
tegory<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border:solid black 1.=
0pt;
  border-left:none;mso-border-left-alt:solid black .5pt;mso-border-alt:soli=
d black .5pt;
  background:#6487DC;padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial;color:white'>Best
  Practices<o:p></o:p></span></b></p>
  </td>
 </tr>
 <tr style=3D'mso-yfti-irow:1;mso-yfti-lastrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  border-top:none;mso-border-top-alt:solid black .5pt;mso-border-alt:solid =
black .5pt;
  padding:3.25pt 0in 0in 3.25pt'>
  <p><b><span style=3D'font-size:9.0pt;font-family:Arial'>Firewall Rules and
  Filters<o:p></o:p></span></b></p>
  </td>
  <td width=3D"80%" valign=3Dtop style=3D'width:80.0%;border-top:none;borde=
r-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  mso-border-top-alt:solid black .5pt;mso-border-left-alt:solid black .5pt;
  mso-border-alt:solid black .5pt;padding:3.25pt 0in 0in 3.25pt'>
  <p><span style=3D'font-size:9.0pt;font-family:Arial'>Firewalls are a firs=
t-line
  defense mechanism and should be placed at all network border locations. R=
ules
  implemented on firewalls should be highly restrictive and set on a
  host-by-host and service-by-service basis.<br>
  <br>
  When creating firewall rules and router ACLs (Access Control Lists), focu=
s on
  first protecting access control devices and the network from attack. <br>
  <br>
  <br>
  + Enforce data flow by use of network ACLs and firewall rules. <br>
  + Test firewall rules and router ACLs to determine whether or not existing
  rules contribute to Denial of Service (DoS) attacks.<br>
  + Deploy one or more DMZs as part of a systematic and formal firewall
  development. <br>
  + Place all Internet accessible servers there. Restrict connectivity to a=
nd
  from the DMZs.<o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin:0in;margin-bottom:.0001pt'><span
style=3D'font-size:10.0pt;font-family:Arial;display:none;mso-hide:all'><o:p=
>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D1 cellspacing=3D0 cellpadding=3D0 wi=
dth=3D"100%"
 style=3D'width:100.0%;border-collapse:collapse;border:none;mso-border-alt:=
solid black .5pt'>
 <tr style=3D'mso-yfti-irow:0;mso-yfti-firstrow:yes'>
  <td width=3D"20%" valign=3Dtop style=3D'width:20.0%;border:solid black 1.=
0pt;
  mso-border-alt:solid black .5pt;background:#6487DC;padding:3.25pt 0in 0in=
 3.25pt'>
  <p class=3DMsoNormal><b><span style=3D'font-size:9.0pt;font-family:Arial;
  color:white'><o:p>&nbsp;</o:p></span></b></p>
  </td>
  <td width=3D"40%" valign=3Dtop style=3D'width:40.0%;border:solid black 1.=
0pt