Attachment_4_CFPB_Third_Party_Service_Provider_Self-Assessment.pdf

PDF 502 KB Posted

Attached to
Diversity Compliance Support Services Federal contract opportunity
Solicitation number
CFP-14-R-00006
Issued by
Consumer Financial Protection Bureau

About this file

Attachment 4 CFPB Third Party Service Provider Self-Assessment

View the file

Other files for this federal contract opportunity

Other files attached to Diversity Compliance Support Services, newest first.
File Type Posted
Attachment_5_CFPB_Response_to_Questions.pdf PDF
CFP-14-R-00006_Amendment_0001.pdf PDF
Attachment_3_Past_Performance_Questionnaire.docx DOCX document
CFP-14-R-00006.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Third Party Service Provider Self-Assessment

CFPB

April 2013

Technology & Innovation

Cybersecurity

TABLE OF CONTENTS

1 EXECUTIVE SUMMARY

2 INTRODUCTION

2.1 PURPOSE

2.2 SCOPE

2.3 REFERENCES

3 SELF-IDENTIFICATION

4 INFORMATION SECURITY CONTROL QUESTIONNAIRE

4.1 ACCESS CONTROL (AC)

4.2 AWARENESS AND TRAINING (AT)

4.3 AUDIT AND ACCOUNTABILITY (AU)

4.4 CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS (CA)

4.5 CONFIGURATION MANAGEMENT (CM)

4.6 CONTINGENCY PLANNING (CP)

4.7 IDENTIFICATION AND AUTHENTICATION (LA)

4.8 INCIDENT RESPONSE (IR)

4.9 MAINTENANCE (MA)

4.10 MEDIA PROTECTION (MP)

4.11 PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

4.12 PLANNING (PL)

4.13 PERSONNEL SECURITY (PS)

4.14 RISK ASSESSMENT (RA)

4.15 SYSTEM AND SERVICES ACQUISITION (SA)

4.16 SYSTEM AND COMMUNICATIONS PROTECTION (SC)

4.17 SYSTEM AND INFORMATION INTEGRITY (SI)

5 FREQUENTLY ASKED QUESTIONS

6 ATTESTATION LETTER

LIST OF TABLES

Table 1: Completion Checklist

Revision History

Review Period: Annual Last reviewed: 4/12/2013

Effective Version Explain the Change Action By 10/19/2012 1.00 Initial draft JB 4/12/2013 1.00 Add Self-Identification section for initial release DS

Third Party Service Provider Self-Assessment 4

1 Executive Summary The Consumer Financial Protection Bureau (CFPB) requires all service providers to have an information security program that provides management, operational, and technical safeguards designed to protect CFPB data.

This publication is based on security control requirements established by Federal Information Processing Standard (FIPS) Publication 200, “Minimum Security Requirements for Federal Information and Information Systems.”

Once completed, this self-assessment will be analyzed by CFPB Strategy and Risk Management personnel to provide the CFPB’s contracting officer with a preliminary assessment of the respondents’ security program. CFPB’s analysis will rely on the quality and completeness of the information provided. CFPB Risk Management personnel will conduct further analyses, reviews, and testing of the apparent winning bidder’s security control environment based on a full set of control requirements.

Explanation of terms, concepts, and other items related to federal information security requirements can be found in the “Frequently Asked Questions” section of this publication.

Third Party Service Provider Self-Assessment 5

2 Introduction

2.1 Purpose

The CFPB requires attestations for all self-assessments made by its service providers. Once completed, the questionnaire must be reviewed and approved by a senior officer of the organization. The formal attestation letter (appendix A) will be submitted as part of any official response to the request for proposal, statement of work, and/or other contracting document.

2.2 Scope

The self-identification section and self-assessment questionnaire must be filled out by staff responsible for, and knowledgeable of, the security control environment that will be utilized to protect the confidentiality, integrity, and availability of Consumer Financial Protection Bureau (CFPB) data.

Please review the checklist below to ensure completeness prior to final submission.

Table 1: Completion Checklist

Completion Checklist Self-identification section has been completed.

All questions within the self-assessment have been completed.

Self-assessment has been reviewed and approved by knowledgeable staff.

Detailed comments have been provided where applicable.

Attestation letter has been reviewed and signed by a senior officer of the organization.

2.3 References

Terms used in this document are based on "Glossary of Key Information Security Terms," NIST Interagency Reports (NIST IR 7298), dated April 2006.

Third Party Service Provider Self-Assessment 6

3 Self-Identification

Please complete the fields below with the appropriate information.

COMPANY INFORMATION

Company Name:

Company Address:

COMPANY POINT OF CONTACT (POC)

Full Name:

Phone Number:

Email Address:

CONTRACT INFORMATION

Contract Name:

Contract Number:

SYSTEM/PROJECT INFORMATION

System/Project Name:

Description of Service:

Third Party Service Provider Self-Assessment 7

4 Information Security Control Questionnaire

4.1 ACCESS CONTROL (AC)

Organizations must limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.

RESPONSE COMMENTS

Does the service provider limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)? Please explain the response.

Yes

No

Does the service provider limit information system access to the types of transactions and functions that authorized users are permitted to exercise? Please explain the response.

Can the service provider integrate into an external authentication source such as an agency Active Directory?

Can access to the CFPB IT environment be restricted by source IP, username, or other mechanism?

Is it possible to grant access on the basis of least privilege (i.e. Can different levels of access be granted to end-users versus administrator roles)?

Third Party Service Provider Self-Assessment 8

Can all access control settings be accessed through the Application Programming Interface (API)?

If you answered ‘Yes’ above, please describe how access to the API is restricted?

Is access to audit logs detailing user access information (i.e. information pertaining to user name, source IP, resource, and pages) permitted?

Is access to change logs that detail all changes in the system (i.e. data upload, setting changes, or data removal) allowed?

Can access to change logs be traced back to individual user accounts?

4.2 AWARENESS AND TRAINING (AT)

Organizations must: (i) ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, Third Party Service Provider Self-Assessment 9 directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems; and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security- related duties and responsibilities.

RESPONSE COMMENTS

Does the service provider ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, directives, policies, standards, instructions, regulations, or procedures related to the security of the service provider's information systems? Please explain the response.

Does the service provider ensure that personnel are adequately trained to carry out their assigned information security-related duties and responsibilities? Please explain the response.

4.3 AUDIT AND ACCOUNTABILITY (AU)

Organizations must: (i) create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.

RESPONSE COMMENTS

Does the service provider create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity? Please explain the response.

Third Party Service Provider Self-Assessment 10

Does the service provider ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions? Please explain

If you answered ‘Yes’ above, please list the various logs generated and retained for audit purposes. Also, provide brief description of the information captured by each of the listed logs.

4.4 CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS (CA)

Organizations must: (i) periodically assess the security controls in organizational information systems to determine if the controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organization information systems; (iii) authorize the operation of organizational information systems or any associated information system connections; and (iv) monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.

RESPONSE COMMENTS

Does the service provider periodically assess the security controls in organizational information systems to determine if the security controls are effective? If Yes, please describe frequency and type of assessments. If no, please explain the response.

Based on guidance provided in Statements on Standards for Attestations Engagement No. 16 (SSAE 16), does the service provider contract an independent assessor to test all its controls on an annual basis?

Third Party Service Provider Self-Assessment 11

If you answered ‘Yes', please provide the most recent copy of the SSAE 16 (formerly known as ‘SAS 70’) report.

Does the service provider develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems?

Please explain the response.

Does the service provider authorize the operation of organizational information systems and any associated information system connections? Please explain the response.

Does the service provider monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the security controls? Please explain the response.

RESPONSE COMMENTS

Does the service provider have a corporate information security division to ensure that the organization implements the appropriate guidance to protect information resources? Please explain the response.

Does the service provider subscribe to either mandatory or voluntary information security frameworks and guidelines [e.g., COSO, CoBIT, ITIL, ISO/IEC 27001, ISO/IEC 17799 (BS7799), NSA IAM], or is the service provider required to report on its internal controls under the GBLA, SOX, HIPAA, FISMA, PCI, California Security Breach Information Act (SB-1386), Safe Harbor, Third Party Service Provider Self-Assessment 12

Basel II Accord, or a framework/ regulatory requirement not mentioned here? (Please note in the comment section below what framework is utilized and which regulatory requirements govern your information security practices.) Please explain the response.

4.5 CONFIGURATION MANAGEMENT (CM)

Organizations must: (i) establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; and (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems.

RESPONSE COMMENTS

Does the service provider establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles? Please explain the response.

Does the service provider establish and enforce security configuration settings for information technology products employed in organizational information systems? Please explain the

4.6 CONTINGENCY PLANNING (CP)

Organizations must: establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems

Third Party Service Provider Self-Assessment 13 to ensure the availability of critical information resources and continuity of operations in emergency situations.

RESPONSE COMMENTS

Does the service provider establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations? Please explain the response.

4.7 IDENTIFICATION AND AUTHENTICATION (lA)

Organizations must identify information system users, processes acting on behalf of users, or devices and authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

RESPONSE COMMENTS

Does the service provider identify information system users, processes acting on behalf of users, or devices; and does it authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems? Please

Are the encryption technologies that the service provider uses to safeguard workstations, laptops, servers, portable media/devices, and backup tapes compliant with Federal Information Processing Standards (FIPS) Publication 140-2; and does the service provider allow remote access to its information technology resources only via encrypted, two-factor authentication technologies? Please explain the response.

Third Party Service Provider Self-Assessment 14

4.8 INCIDENT RESPONSE (IR)

Organizations must: (i) establish an operational incident handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents to appropriate organizational officials and/or authorities.

RESPONSE COMMENTS

Does the service provider establish an operational information/computer security incident handling capability for organizational information systems that includes adequate preparation, detection, analysis, recovery, response, containment, activities? Please explain the response.

Does the service provider track, document, and report information/computer security incidents to appropriate organizational officials and/or authorities? Please explain the response.

Does the service provider have policy, procedures, and regularly tested breach notification practices, to include additional provisions for sensitive data?1 Please explain the response.

1 “Sensitive data” includes personally identifiable information (PII) that can be used to distinguish or trace an individual’s identity. Such information, which includes a person’s name, social security number, and biometric records, can be used alone or in combination with other personal or identifying information that is linked or linkable to a specific individual, such as date of birth, place of birth, mother’s maiden name, etc.

Third Party Service Provider Self-Assessment 15

Does the service provider have publicly available materials on its breach notification practices?

Please explain the response.

4.9 MAINTENANCE (MA)

Organizations must: (i) perform periodic and timely maintenance on organizational information systems; and (ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance. Please explain the response.

RESPONSE COMMENTS

Does the service provider perform periodic and timely maintenance on organizational information systems? Please explain the response.

Does the service provider provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance? Please explain the response.

4.10 MEDIA PROTECTION (MP)

Organizations must: (i) protect information system media, both paper and digital; (ii) limit access to information on information system media to authorized users; and (iii) sanitize or destroy information system media before disposal or release for reuse.

RESPONSE COMMENTS

Does the service provider protect information system media, both paper and digital? Please

Third Party Service Provider Self-Assessment 16

Does the service provider limit access to information on information system media to authorized users? Please explain the response.

Does the service provider implement appropriate labeling practices in categorizing information? Please explain response.

Does the service provider sanitize or destroy information system media before disposal or release for reuse? Please explain the response.

4.11 PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

Organizations must: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.

RESPONSE COMMENTS

Does the service provider limit physical access to information systems, equipment, and the different operating environments to authorized individuals? Please explain the response.

Third Party Service Provider Self-Assessment 17

Does the service provider protect the physical plant and support infrastructure for information systems? Please explain the response.

Does the service provider provide supporting utilities for information systems? Please explain

Does the service provider protect information systems against environmental hazards? Please

Does the service provider provide appropriate environmental controls in facilities containing

4.12 PLANNING (Pl)

Organizations must develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems.

Third Party Service Provider Self-Assessment 18

RESPONSE COMMENTS

Does the service provider develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing

4.13 PERSONNEL SECURITY (PS)

Organizations must: (i) ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers;

and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.

RESPONSE COMMENTS

Does the service provider ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions? Please explain the response.

Does the service provider ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers? Please

Does the service provider employ formal sanctions for personnel failing to comply with organizational security policies and procedures? Please explain the response.

Third Party Service Provider Self-Assessment 19

4.14 RISK ASSESSMENT (RA)

Organizations must periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information.

RESPONSE COMMENTS

Does the service provider periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information? Please explain the response.

4.15 SYSTEM AND SERVICES ACQUISITION (SA)

Organizations must: (i) allocate sufficient resources to adequately protect organizational information systems; (ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions;

and (iv) ensure that third-party providers employ adequate security measures to protect information, applications, and/or services outsourced from the organization.

RESPONSE COMMENTS

Does the service provider allocate sufficient resources to adequately protect organizational

Third Party Service Provider Self-Assessment 20

Does the service provider employ system development life cycle processes that incorporate information security considerations? Please explain the response.

Does the service provider employ software usage and installation restrictions? Please explain

Does the service provider ensure that other third-party providers employ adequate security measures to protect information, applications, and/or services outsourced from the organization? Please explain the response.

4.16 SYSTEM AND COMMUNICATIONS PROTECTION (SC)

Organizations must: (i) monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.

RESPONSE COMMENTS

Does the service provider monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems? Please explain the

Third Party Service Provider Self-Assessment 21

Does the service provider employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems? Please explain the response. Provide copies of any architectural design, implementation plan, and concept of operations document relevant to the proposed change developed by the service provider

Do you provide information using published Application Programming Interfaces (APIs)?

4.17 SYSTEM AND INFORMATION INTEGRITY (SI)

Organizations must: (i) identify, report, and correct information and information system flaws in a timely manner; (ii) provide protection from malicious code at appropriate locations within organizational information systems; and (iii) monitor information system security alerts and advisories and take appropriate actions in response.

RESPONSE COMMENTS

Does the service provider identify, report, and correct information and information system flaws in a timely manner? Please explain the response.

Does the service provider provide protection from malicious code at appropriate locations within organizational information systems? Please explain the response.

Third Party Service Provider Self-Assessment 22

Does the service provider monitor information system security alerts and advisories and take appropriate actions in response? Please explain the response.

5 Frequently Asked Questions

Why does the CFPB require its service providers to complete this self-assessment questionnaire?

The E-Government Act of 2002 and Office of Management and Budget (OMB) directives require that all information systems that process government information maintain adequate security.

“Adequate security” is commensurate with the harm that would result from the loss, misuse, or unauthorized access to or modification of information. Adequate security ensures that systems and applications operate effectively and provide appropriate measures of confidentiality, integrity, and availability through the use of managerial, operational, and technical security controls. This requirement applies to all information and information systems that support the operations and assets of the government, including those provided or managed by another government agency, contractor, or other source.

What does “information security” mean?

“Information security” is protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.

What does “information system” mean?

An information system is a discrete set of information resources organized for the collection, processing, maintenance, transmission, and dissemination of information, in accordance with defined procedures, whether automated or manual.

What do the terms “confidentiality, integrity and availability” mean?

Confidentiality is preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.

Integrity is protecting information from improper modification or destruction, and includes ensuring that information is authentic and reliable.

Third Party Service Provider Self-Assessment 23

Availability is ensuring timely and reliable access to and use of information.

How does the government define “security control”?

The CFPB’s information security controls are based on Federal Information Processing Standard (FIPS) Publication 200 (“Minimum Security Requirements for Federal Information and Information Systems”). Security controls are the management, operational, and technical safeguards or countermeasures prescribed for an information system to protect the confidentiality, integrity, and availability of a system and its information. Management controls focus on the management of risk and the management of information system security.

Operational controls are those safeguards that are primarily implemented and executed by people (as opposed to systems). Technical controls are primarily implemented and executed by an information system through mechanisms in the hardware, software, or firmware components of the system.

What is FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems,” and where can I find more information about it?

That publication is a mandatory standard (it cannot be waived) developed in response to the Federal Information Security Management Act of 2002. The combination of FIPS 200 and NIST Special Publication 800-53 establishes the foundation for most federal information security practices and procedures.

What is NIST Special Publication (SP) 800-53, Revision III, “Recommended Security Controls for Federal Information Systems,” August 2009 and where can I find more information on it?

That publication provides guidelines for selecting and specifying security controls for information systems supporting the executive agencies of the federal government. These guidelines apply to all components of an information system that process, store, or transmit federal information. The publication provides guidance to federal agencies implementing FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems.”

What are the standards and guides used to create this preliminary self-assessment?

This questionnaire is derived from the FIPS 200 publication, "Minimum Security Requirements for Federal Information and Information Systems."

Can a service provider obtain the standards and guides?

NIST information security-related publications can be obtained free of charge from the NIST public Web site located at http://csrc.nist.gov/publications/index.html.

Where can I get assistance if l need help completing this assessment?

Third Party Service Provider Self-Assessment 24

If you have any questions concerning the completion of this form, please contact Joy Salazar at

(202) 435-9121.

Third Party Service Provider Self-Assessment 25

6 Attestation letter

1. To the best of my knowledge, statements made in response to the Consumer Financial Protection Bureau’s “Third Party Service Provider Self-assessment” dated are accurate;

2. Statements made in response to the Consumer Financial Protection Bureau’s “Third

Party Service Provider Self-assessment” were made by knowledgeable and qualified professionals in the internal control structure of my organization;

3. There is no:

a. Knowledge of fraud involving (1) management, (2) employees who have significant roles in the internal control structure, or (3) others where the fraud could have a material effect on the organization’s ability to maintain operations, ensure adequate safeguards over client information, and/ or cause serious harm to the reputation of the organization and/or its clients;

b. Communication from federal agencies concerning noncompliance with, or deficiencies in, financial reporting practices that could have a significant effect on the organization; or

c. Knowledge of any allegations of fraud or suspected fraud affecting the organization received in communications from employees, former employees, analysts, regulators, or others.

4. The undersigned attests to the completeness and accuracy of the applicable responses made in support of submitting Consumer Financial Protection Bureau’s “Third Party Service Provider Self-assessment.”

Corporate Officer (Signature)

Printed Name/Title

Date

1 Executive Summary
2 Introduction
2.1 Purpose
2.2 Scope
2.3 References
3 Self-Identification
4 Information Security Control Questionnaire
4.1 ACCESS CONTROL (AC)
4.2 AWARENESS AND TRAINING (AT)
4.3 AUDIT AND ACCOUNTABILITY (AU)
4.4 CERTIFICATION, ACCREDITATION, AND SECURITY ASSESSMENTS (CA)
4.5 CONFIGURATION MANAGEMENT (CM)
4.6 CONTINGENCY PLANNING (CP)
4.7 IDENTIFICATION AND AUTHENTICATION (lA)
4.8 INCIDENT RESPONSE (IR)
4.9 MAINTENANCE (MA)
4.10 MEDIA PROTECTION (MP)
4.11 PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)
4.12 PLANNING (Pl)
4.13 PERSONNEL SECURITY (PS)
4.14 RISK ASSESSMENT (RA)
4.15 SYSTEM AND SERVICES ACQUISITION (SA)
4.16 SYSTEM AND COMMUNICATIONS PROTECTION (SC)
4.17 SYSTEM AND INFORMATION INTEGRITY (SI)
5 Frequently Asked Questions
6 Attestation letter
Printed NameTitle:
Date:
Description of Service:
System/Project Name:
Contract Number:
Contract Name:
Email Address:
Phone Number:
Full Name:
Company Name:
Company Address:
Checklist1: Off
Checklist2: Off
Checklist3: Off
Checklist4: Off
Checklist5: Off
Group3: Off
Group4: Off
Group5: Off
Group6: Off
Text6:
Text7:
Text8:
Text9:
Text10:
Text11:
Text12:
Text13:
Text14:
Text15:
Text16:
Text17:
Text18:
Text19:
Text20:
Text21:
Text22:
Text23:
Text24:
Group7: Off
Group8: Off
Group9: Off
Group10: Off
Group11: Off
Text25:
Text26:
Text27:
Text28:
Text29:
Text30:
Group12: Off
Text31:
Text32:
Text33:
Text34:
Text35:
Text36:
Group13: Off
Group14: Off
Group15: Off
Text37:
Text38:
Text39:
Text40:
Text41:
Text42:
Group16: Off
Group17: Off
Group18: Off
Group19: Off
Text43:
Text44:
Group20: Off
21: Off
22: Off
45:
46:
47:
48:
49:
50:
23: Off
24: Off
25: Off
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
26: Off
27: Off
28: Off
61:
62:
63:
64:
65:
66:
29: Off
30: Off
31: Off
67:
68:
69:
70:
71:
72:
73:
74:
32: Off
33: Off
34: Off
35: Off
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
36: Off
37: Off
38: Off
39: Off
40: Off
85:
86:
87:
88:
89:
90:
41: Off
42: Off
43: Off
91:
92:
93:
94:
95:
96:
44: Off
a: Off
b: Off
97:
98:
99:
100:
101:
102:
103:
104:
c: Off
d: Off
e: Off
f: Off
105:
106:
107:
108:
109:
110:
111:
112:
g: Off
h: Off
i: Off
j: Off
113:
114:
115:
116:
k: Off
Group1: Off
Group2: Off

File details come from the government source that posted it. Updated .