Attachment J.9_Information Security Self Assessment.pdf
PDF 744 KB Posted
- Attached to
- 2012 Career Forum Federal contract opportunity
- Solicitation number
- CC11HQQ0013
About this file
Information Security Self-Assessment
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
INFORMATION RISK MANAGEMENT
Communicate. Integrate. Deliver.
O
Comptroller of the Currency Administrator of National Banks
US Department of the Treasury
Service Provider Self Assessment
Build IT:
Integrate information security into business functions and processes.
Verify IT:
Guide the examination of security controls and define the approach to risk management activities.
Make IT Better:
Provide stewardship of OCC information resources by improving institutional capacity and maintaining a sound governance system.
ii | InformatIon rISK manaGEmEnt operational ProceduresO
CC 9070-02 (rEV 10/08) | iiiVersion 1.0
1. EXECUTIVE SUMMARY 1
2. INSTRUCTIONS 2
3. INFORMATION SECURITY CONTROl QUESTIONNAIRE 3
3.1 ACCESS CONTROL (AC)
3.2 AWARENESS AND TRAINING (AT)
3.3 AUDIT AND ACCOUNTABILITY (AU)
3.4 CERTIFICATION, ACCREDITATION, AND
SECURITY ASSESSMENTS (CA)
3.5 CONFIGURATION MANAGEMENT (CM)
3.6 CONTINGENCY PLANNING (CP)
3.7 IDENTIFICATION AND AUTHENTICATION (IA) . . 10
3.8 INCIDENT RESPONSE (IR)
3.9 MAINTENANCE (MA)
3.10 MEDIA PROTECTION (MP)
3.11 PHYSICAL AND ENVIRONMENTAL
PROTECTION (PE)
3.12 PLANNING (PL)
3.13 PERSONNEL SECURITY (PS)
3.14 RISK ASSESSMENT (RA)
3.15 SYSTEM AND SERVICES ACQUISITION (SA). . . 18
3.16 SYSTEM AND COMMUNICATIONS
PROTECTION (SC)
3.17 SYSTEM AND INFORMATION INTEGRITY (SI) . . 20
4. FREQUENTlY ASKED QUESTIONS 21
5. ATTESTATION lETTER 23
Table of Contents iv | InformatIon rISK manaGEmEnt operational ProceduresO
CC 9070-02 (rEV 10/08) | 1Version 1.0
1. EXECUTIVE SUMMARY
The Office of the Comptroller of the Currency (OCC) requires all service providers to have an information se curity program that provides management, operational, and technical safeguards designed to protect OCC data.
This publication is based on security control requirements established by Federal Information Process ing Standard (FIPS) Publication 200, “Minimum Security Requirements for Federal Information and Information Systems.”
Once completed, this self assessment will be analyzed by OCC information Risk Management personnel to provide the OCC’s contracting officer with a preliminary assessment of the respondents’ security program. OCC’s analysis will rely on the quality and completeness of the information provided. OCC Risk Management person nel will conduct further analyses, review, and testing of the apparent winning bidder’s security control environment based on a full set of control requirements.
Explanation of terms, concepts, and other items related to federal information security requirements can be found in the “Frequently Asked Questions” section of this publication.
O2 | InformatIon rISK manaGEmEnt operational Procedures
The self assessment questionnaire must be filled out by staff responsible for, and knowledgeable of, the security control environment that will be utilized to protect the confidentiality, integrity, and availability of Office of the Comptroller of the Currency (OCC) data.
The OCC requires attestations for all self assessments made by its service providers. Once completed, the questionnaire must be reviewed and approved by a senior officer of the organization. The formal attestation letter (appendix A) should be submitted as part of any official response to the request for proposal, statement of work, and/or other contracting document.
Terms used in this document are based on “Glossary of Key Information Security Terms,” NIST Interagency Reports (NIST IR 7298), dated April 2006.
Please review the checklist in table 1 below to ensure completeness prior to final submission.
All questions within the self assessment have been completed.
Self assessment has been reviewed and approved by knowledgeable staff.
Detailed comments have been provided where applicable.
Attestation letter has been reviewed and signed by a senior officer of the organization.
Table 1: Completion Checklist
2. INSTRUCTIONS
CC 9070-02 (rEV 10/08) | 3Version 1.0
3. INFORMATION SECURITY
CONTROl QUESTIONNAIRE
3.1 ACCESS CONTROl (AC)
Organizations must limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.
RESPONSE COMMENTS
Does the service provider limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)?
Yes
No
Does the service provider limit information system access to the types of transactions and functions that authorized users are permitted to exercise?
Yes
No
O4 | InformatIon rISK manaGEmEnt operational Procedures
3.2 AWARENESS AND TRAINING (AT)
Organizations must: (i) ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems; and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsiblities.
RESPONSE COMMENTS
Does the service provider ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, directives, policies, standards, instructions, regulations, or procedures related to the security of the service provider’s information systems?
Yes
No
Does the service provider ensure that personnel are adequately trained to carry out their assigned information security-related duties and responsibilities?
CC 9070-02 (rEV 10/08) | 5Version 1.0
3.3 AUDIT AND ACCOUNTABIlITY (AU)
Organizations must: (i) create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.
RESPONSE COMMENTS
Does the service provider create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity?
Yes
No
Does the service provider ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions?
O6 | InformatIon rISK manaGEmEnt operational Procedures
3.3 CERTIFICATION, ACCREDITATION, AND SECURITY
ASSESSMENTS (CA)
Organizations must: (i) periodically assess the security controls in organizational information systems to determine if the controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organization informaion systems; (iii) authorize the operation of organizational information systems or any associated information system connections; and (iv) monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.
RESPONSE COMMENTS
Does the service provider periodically assess the security controls in organizational information systems to determine if the security controls are effective?
Yes
No
Does the service provider develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems?
Yes
No
Does the service provider authorize the operation of organizational information systems and any associated information system connections?
Yes
No
Does the service provider monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the security controls?
CC 9070-02 (rEV 10/08) | 7Version 1.0
Does the service provider have a corporate information security division to ensure that the organization implements the appropriate guidance to protect information resources?
Yes
No
Does the service provider subscribe to either mandatory or voluntary information security frameworks and guidelines [e.g., COSO, CoBIT, ITIL, ISO/IEC 27001, ISO/IEC 17799 (BS7799), NSA IAM], or is the service provider required to report on its internal controls under the GBLA, SOX, HIPAA, FISMA, PCI, California Security Breach Information Act (SB-1386), Safe Harbor, Basel II Accord, or a framework/ regulatory requirement not mentioned here? (Please note in the comment section below what framework is utilized and which regulatory requirements govern your information security practices.)
Yes
RESPONSE COMMENTS
O8 | InformatIon rISK manaGEmEnt operational Procedures
3.5 CONFIGURATION MANAGEMENT (CM)
Organizations must: (i) establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; and (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems.
RESPONSE COMMENTS
Does the service provider establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles?
Yes
No
Does the service provider establish and enforce security configuration settings for information technology products employed in organizational information systems?
CC 9070-02 (rEV 10/08) | 9Version 1.0
3.6 CONTINGENCY PlANNING (CP)
Organizations must: establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.
RESPONSE COMMENTS
Does the service provider establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations?
O10 | InformatIon rISK manaGEmEnt operational Procedures
3.7 IDENTIFICATION AND AUTHENTICATION (IA)
Organizations must identify information system users, processes acting on behalf of users, or devices and authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
RESPONSE COMMENTS
Does the service provider identify information system users, processes acting on behalf of users, or devices; and does it authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems?
Yes
No
Are the encryption technologies that the service provider uses to safeguard workstations, laptops, servers, portable media/devices, and backup tapes compliant with Federal Information Processing Standards (FIPS) Publication 140-2; and does the service provider allow remote access to its information technology resources only via encrypted, two-factor authentication technologies?
CC 9070-02 (rEV 10/08) | 11Version 1.0
3.8 INCIDENT RESPONSE (IR)
Organizations must: (i) establish an operational incident handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents to appropriate organizational officials and/or authorities.
RESPONSE COMMENTS
Does the service provider establish an operational information/computer security incident handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and response activities?
Yes
No
Does the service provider track, document, and report information/computer security incidents to appropriate organizational officials and/or authorities?
Yes
No
Does the service provider have policy, procedures, and regularly tested breach notification practices, to include additional provisions for sensitive data?1
Yes
No
Does the service provider have publicly available materials on its breach notification practices?
Yes
No
1 “Sensitive data” includes personally identifiable information (PII) that can be used to distinguish or trace an individual’s identity. Such information, which includes a person’s name, social security number, and biometric records, can be used alone or in combination with other personal or identifying information that is linked or linkable to a specific individual, such as date of birth, place of birth, mother’s maiden name, etc.
O12 | InformatIon rISK manaGEmEnt operational Procedures
3.9 MAINTENANCE (MA)
Organizations must: (i) perform periodic and timely maintenance on organizational information systems; and
(ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.
RESPONSE COMMENTS
Does the service provider perform periodic and timely maintenance on organizational information systems?
Yes
No
Does the service provider provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance?
CC 9070-02 (rEV 10/08) | 13Version 1.0
3.10 MEDIA PROTECTION (MP)
Organizations must: (i) protect information system media, both paper and digital; (ii) limit access to information on information system media to authorized users; and (iii) sanitize or destroy information system media before disposal or release for reuse.
RESPONSE COMMENTS
Does the service provider protect information system media, both paper and digital?
Yes
No
Does the service provider limit access to information on information system media to authorized users?
Yes
No
Does the service provider sanitize or destroy information system media before disposal or release for reuse?
O14 | InformatIon rISK manaGEmEnt operational Procedures
3.11 PHYSICAl AND ENVIRONMENTAl PROTECTION
(PE)
Organizations must: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.
RESPONSE COMMENTS
Does the service provider limit physical access to information systems, equipment, and the different operating environments to authorized individuals?
Yes
No
Does the service provider protect the physical plant and support infrastructure for information systems?
Yes
No
Does the service provider provide supporting utilities for information systems?
Yes
No
Does the service provider protect information systems against environmental hazards?
Yes
No
Does the service provider provide appropriate environmental controls in facilities containing information systems?
CC 9070-02 (rEV 10/08) | 15Version 1.0
3.12 PlANNING (Pl)
Organizations must develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems.
RESPONSE COMMENTS
Does the service provider develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing information systems?
O16 | InformatIon rISK manaGEmEnt operational Procedures
3.13 PERSONNEl SECURITY (PS)
Organizations must: (i) ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.
RESPONSE COMMENTS
Does the service provider ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions?
Yes
No
Does the service provider ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers?
Yes
No
Does the service provider employ formal sanctions for personnel failing to comply with organizational security policies and procedures?
CC 9070-02 (rEV 10/08) | 17Version 1.0
3.14 RISK ASSESSMENT (RA)
Organizations must periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information.
RESPONSE COMMENTS
Does the service provider periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information?
O18 | InformatIon rISK manaGEmEnt operational Procedures
3.15 SYSTEM AND SERVICES ACQUISITION (SA)
Organizations must: (i) allocate sufficient resources to adequately protect organizational information systems;
(ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions; and (iv) ensure that third-party providers employ adequate security measures to protect information, applicatons, and/or services outsourced from the organization.
RESPONSE COMMENTS
Does the service provider allocate sufficient resources to adequately protect organizational information systems?
Yes
No
Does the service provider employ system development life cycle processes that incorporate information security considerations?
Yes
No
Does the service provider employ software usage and installation restrictions?
Yes
No
Does the service provider ensure that other third-party providers employ adequate security measures to protect information, applications, and/or services outsourced from the organization?
CC 9070-02 (rEV 10/08) | 19Version 1.0
3.16 SYSTEM AND COMMUNICATIONS PROTECTION
(SC)
Organizations must: (i) monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.
RESPONSE COMMENTS
Does the service provider monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems?
Yes
No
Does the service provider employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems?
O20 | InformatIon rISK manaGEmEnt operational Procedures
3.17 SYSTEM AND INFORMATION INTEGRITY (SI)
Organizations must: (i) identify, report, and correct information and information system flaws in a timely manner; (ii) provide protection from malicious code at appropriate locations within organizational information systems; and (iii) monitor information system security alerts and advisories and take appropriate actions in response.
RESPONSE COMMENTS
Does the service provider identify, report, and correct information and information system flaws in a timely manner?
Yes
No
Does the service provider provide protection from malicious code at appropriate locations within organizational information systems?
Yes
No
Does the service provider monitor information system security alerts and advisories and take appropriate actions in response?
CC 9070-02 (rEV 10/08) | 21Version 1.0
4. Frequently Asked Questions
(5) How does the government define “security control”?
The OCC’s information security controls are based on Federal Information Processing Standard (FIPS) Publication 200. Security controls are the management, operational, and technical safeguards or countermeasures prescribed for an information system to protect the confidentiality, integrity, and availability of a system and its information. Management controls focus on the management of risk and the management of information system security. Operational controls are those safeguards that are primarily implemented and executed by people (as opposed to systems).
Technical controls are primarily implemented and executed by an information system through mechanisms in the hardware, software, or firmware components of the system.
(6) What is FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems,” and where can I find more information about it?
That publication is a mandatory standard (it cannot be waived) developed in response to the Federal Information Security Management Act of 2002.
The combination of FIPS 200 and NIST Special Publication 800-53 establishes the foundation for most federal information security practices and procedures.
(7) What is NIST Special Publication (SP) 800- 53, Revision II, “Recommended Security Controls for Federal Information Systems,” December 2007 and where can I find more information on it?
That publication provides guidelines for selecting and specifying security controls for information systems supporting the executive agencies of the federal government. These guidelines apply to all components of an information system that process, store, or transmit federal information. The publication provides guidance to federal agencies implementing FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems.”
(1) Why does the OCC require its service providers to complete this self assessment questionnaire?
The E-Government Act of 2002 and Office of Management and Budget (OMB) directives require that all information systems that process government information maintain adequate security. “Adequate security” is commensurate with the harm that would result from the loss, misuse, or unauthorized access to or modification of information. Adequate security ensures that systems and applications operate effectively and provide appropriate measures of confidentiality, integrity, and availability through the use of managerial, operational, and technical security controls. This requirement applies to all information and information systems that support the operations and assets of the government, including those provided or managed by another government agency, contractor, or other source.
(2) What does “information security” mean?
“Information security” is protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.
(3) What does “information system” mean?
An information system is a discrete set of information resources organized for the collection, processing, maintenance, transmission, and dissemination of information, in accordance with defined procedures, whether automated or manual.
(4) What do the terms “confidentiality, integrity and availability” mean?
Confidentiality is preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.
Integrity is protecting information from improper modification or destruction, and includes ensuring that information is authentic and reliable. Availability is ensuring timely and reliable access to and use of information.
O22 | InformatIon rISK manaGEmEnt operational Procedures
(8) What are the standards and guides used to create this preliminary self-assessment?
This questionnaire is derived from FIPS publication 200, “Minimum Security Requirements for Federal Information and Information Systems.”
(9) Can a service provider obtain the standards and guides?
NIST information security-related publications can be obtained free of charge from the NIST public Web site located at http://csrc.nist.gov/publications/index.html.
(10) Where can I get assistance if I need help completing this assessment?
If you have any questions concerning the completion of this form, please contact the OCC Information Risk Management Office at (202) 874-4480.
CC 9070-02 (rEV 10/08) | 23Version 1.0
5. Attestation letter
1. To the best of my knowledge, statements made in response to the Office of the Comptroller of the
Currency’s “Service Provider Self Assessment” dated ____________________ are accurate;
2. Statements made in response to the Office of the Comptroller of the Currency’s “Service Provider Self Assessment” were made by knowledgeable and qualified professionals in the internal control structure of my organization;
3. General Representations:
There are no:
a. Knowledge of fraud involving (1) management, (2) employees who have significant roles in the internal control structure, or (3) others where the fraud could have a material effect on the organization’s ability to maintain operations, ensure adequate safeguards over client information, and/ or cause serious harm to the reputation of the organization and/or its clients;
b. Communications from federal agencies concerning noncompliance with, or deficiencies in, financial reporting practices that could have a significant effect on the organization; or
c. Knowledge of any allegations of fraud or suspected fraud affecting the organization received in communications from employees, former employees, analysts, regulators, or others.
4. The undersigned attests to the completeness and accuracy of the applicable responses made in support of submitting Office of the Comptroller of the Currency’s “Service Provider Self Assessment.”
5. The undersigned has authority to legally bind ____________________________ and has been authorized to do so.
Corporate Officer (Signature) Witness (Signature)
Printed Name/Title Printed Name/Title
Date Date
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| No: Enter data here: response limited to 500 characters |
| Currency’s “Service Provider Self Assessment” dated: |
| The undersigned has authority to legally bind: |
| (Corporate Officer (Signature), <Row 1>): |
| (Witness (Signature), <Row 1>): |
| (Printed Name/Title, <Row 1>): |
| (Printed Name/Title, <Row 1>): |
File details come from the government source that posted it. Updated .