﻿<?xml version="1.0" encoding="UTF-8"?>


<!-- The transform below can be substituted by any XSL file in the Transforms folder. The XML, XSL and CSS files all need to be in the same directory. -->
<?xml-stylesheet href="Australian Government Information Security Manual (ISM).xsl" type="text/xsl"?>

<manual>
  <title>Australian Government Information Security Manual 2012</title>
  <part>
    <title>Introduction</title>
    <chapter>
      <title>Australian Government Information Security Manual 2012</title>
      <section>
        <misc>
          <block>
            <content>
              <para>© Commonwealth of Australia 2011</para>
              <para>
                All material presented in this publication is provided under a Creative Commons Attribution 3.0 Australia licence. For the avoidance of doubt, this means this licence only applies to material as set out in this document.

                The details of the relevant licence conditions are available on the Creative Commons website as is the full legal code for the CC BY 3.0 AU licence.
                http://creativecommons.org/licenses/by/3.0/au/deed.en http://creativecommons.org/licenses/by/3.0/legalcode
              </para>
            </content>
          </block>
          <block>
            <title>Use of the Coat of Arms</title>
            <content>
              <para>
                The terms under which the Coat of Arms can be used are detailed on the Department of the Prime Minister and Cabinet’s website.
                http://www.dpmc.gov.au/guidelines/index.cfm
              </para>
            </content>
          </block>
          <block>
            <title>Contact</title>
            <content>
              <para>
                Inquiries regarding the licence and any use of this document are welcome at:
                Defence Signals Directorate, PO Box 5076, Kingston, ACT, 2604, phone 1300 CYBER1 (1300 292 371), email assist@dsd.gov.au.
              </para>
            </content>
          </block>
        </misc>
      </section>
      <section>
        <title>Foreword</title>
        <misc>
          <block>
            <content>
              <para>
                Advances in information technology have greatly benefited the conduct of government and commercial business, and have become essential to everyday communication. Information technology is providing greater accessibility, mobility, convenience and, importantly, efficiency and productivity. Australia’s prosperity is dependent on taking full advantage of the digital revolution and all it offers.
              </para>
              <para>
                But advances in information technology can be a double-edged sword. Australian networks, whether government, commercial or personal, are facing an unprecedented level of intrusion activities. Threats to information can come from a wide range of sources, including individuals, issue motivated groups, organised criminal syndicates and nation states.
              </para>
              <para>
                It is important to know that things can be done to mitigate the security risks presented by this evolving threat environment. DSD supports agencies in embracing the latest technology by providing the information and tools which enable them to minimise the risks involved. Ultimately, technology will change faster than people’s behaviour around it. Helping people make better decisions about new technology will allow us to stay ahead of the curve.
              </para>
              <para>
                The Australian Government Information Security Manual forms an important part of the government’s strategy to enhance its information security capability. The 2012 release of the manual comprises, for the first time, three complementary documents designed to provide greater accessibility and understanding at all levels of government. The accompanying controls manual provides a set of detailed measures which can be implemented to help mitigate security risks to agencies’ information and systems.
              </para>
              <para>
                I encourage you to apply the controls described here and to ensure you have effective security governance arrangements in place. Doing so will provide assurance that the information entrusted to you is properly protected.
              </para>
              <para>
                Ian McKenzie, Director, Defence Signals Directorate
              </para>
            </content>
          </block>
        </misc>
      </section>
    </chapter>
  </part>
  <part>
    <title>About Information Security</title>
    <chapter>
      <title>Australian Government Information Security Manual</title>
      <section>
        <title>Using This Manual</title>
        <objective>
          <block>
            <content>
              <para>
                The Australian Government Information Security Manual (ISM) is used for the risk-based application of information security to information and systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes how to interpret the content and layout of this manual.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Purpose of the Australian Government Information Security Manual</title>
            <content>
              <para>
                The purpose of this manual is to assist Australian government agencies in applying a risk-based approach to protecting their information and systems. While there are other standards and guidelines designed to protect information systems, the advice in this manual is specifically based on activity observed by Defence Signals Directorate (DSD) on Australian government networks.
              </para>
            </content>
          </block>
          <block>
            <title>Format of the Australian Government Information Security Manual</title>
            <content>

								<image>
iVBORw0KGgoAAAANSUhEUgAAAZIAAAFQCAYAAACVovhFAAAKQ2lDQ1BJQ0MgcHJvZmlsZQAAeNqdU3dYk/cWPt/3ZQ9WQtjwsZdsgQAiI6wIyBBZohCSAGGEEBJAxYWIClYUFRGcSFXEgtUKSJ2I4qAouGdBiohai1VcOO4f3Ke1fXrv7e371/u855zn/M55zw+AERImkeaiagA5UoU8Otgfj09IxMm9gAIVSOAEIBDmy8JnBcUAAPADeXh+dLA//AGvbwACAHDVLiQSx+H/g7pQJlcAIJEA4CIS5wsBkFIAyC5UyBQAyBgAsFOzZAoAlAAAbHl8QiIAqg0A7PRJPgUA2KmT3BcA2KIcqQgAjQEAmShHJAJAuwBgVYFSLALAwgCgrEAiLgTArgGAWbYyRwKAvQUAdo5YkA9AYACAmUIszAAgOAIAQx4TzQMgTAOgMNK/4KlfcIW4SAEAwMuVzZdL0jMUuJXQGnfy8ODiIeLCbLFCYRcpEGYJ5CKcl5sjE0jnA0zODAAAGvnRwf44P5Dn5uTh5mbnbO/0xaL+a/BvIj4h8d/+vIwCBAAQTs/v2l/l5dYDcMcBsHW/a6lbANpWAGjf+V0z2wmgWgrQevmLeTj8QB6eoVDIPB0cCgsL7SViob0w44s+/zPhb+CLfvb8QB7+23rwAHGaQJmtwKOD/XFhbnauUo7nywRCMW735yP+x4V//Y4p0eI0sVwsFYrxWIm4UCJNx3m5UpFEIcmV4hLpfzLxH5b9CZN3DQCshk/ATrYHtctswH7uAQKLDljSdgBAfvMtjBoLkQAQZzQyefcAAJO/+Y9AKwEAzZek4wAAvOgYXKiUF0zGCAAARKCBKrBBBwzBFKzADpzBHbzAFwJhBkRADCTAPBBCBuSAHAqhGJZBGVTAOtgEtbADGqARmuEQtMExOA3n4BJcgetwFwZgGJ7CGLyGCQRByAgTYSE6iBFijtgizggXmY4EImFINJKApCDpiBRRIsXIcqQCqUJqkV1II/ItchQ5jVxA+pDbyCAyivyKvEcxlIGyUQPUAnVAuagfGorGoHPRdDQPXYCWomvRGrQePYC2oqfRS+h1dAB9io5jgNExDmaM2WFcjIdFYIlYGibHFmPlWDVWjzVjHVg3dhUbwJ5h7wgkAouAE+wIXoQQwmyCkJBHWExYQ6gl7CO0EroIVwmDhDHCJyKTqE+0JXoS+cR4YjqxkFhGrCbuIR4hniVeJw4TX5NIJA7JkuROCiElkDJJC0lrSNtILaRTpD7SEGmcTCbrkG3J3uQIsoCsIJeRt5APkE+S+8nD5LcUOsWI4kwJoiRSpJQSSjVlP+UEpZ8yQpmgqlHNqZ7UCKqIOp9aSW2gdlAvU4epEzR1miXNmxZDy6Qto9XQmmlnafdoL+l0ugndgx5Fl9CX0mvoB+nn6YP0dwwNhg2Dx0hiKBlrGXsZpxi3GS+ZTKYF05eZyFQw1zIbmWeYD5hvVVgq9ip8FZHKEpU6lVaVfpXnqlRVc1U/1XmqC1SrVQ+rXlZ9pkZVs1DjqQnUFqvVqR1Vu6k2rs5Sd1KPUM9RX6O+X/2C+mMNsoaFRqCGSKNUY7fGGY0hFsYyZfFYQtZyVgPrLGuYTWJbsvnsTHYF+xt2L3tMU0NzqmasZpFmneZxzQEOxrHg8DnZnErOIc4NznstAy0/LbHWaq1mrX6tN9p62r7aYu1y7Rbt69rvdXCdQJ0snfU6bTr3dQm6NrpRuoW623XP6j7TY+t56Qn1yvUO6d3RR/Vt9KP1F+rv1u/RHzcwNAg2kBlsMThj8MyQY+hrmGm40fCE4agRy2i6kcRoo9FJoye4Ju6HZ+M1eBc+ZqxvHGKsNN5l3Gs8YWJpMtukxKTF5L4pzZRrmma60bTTdMzMyCzcrNisyeyOOdWca55hvtm82/yNhaVFnMVKizaLx5balnzLBZZNlvesmFY+VnlW9VbXrEnWXOss623WV2xQG1ebDJs6m8u2qK2brcR2m23fFOIUjynSKfVTbtox7PzsCuya7AbtOfZh9iX2bfbPHcwcEh3WO3Q7fHJ0dcx2bHC866ThNMOpxKnD6VdnG2ehc53zNRemS5DLEpd2lxdTbaeKp26fesuV5RruutK10/Wjm7ub3K3ZbdTdzD3Ffav7TS6bG8ldwz3vQfTw91jicczjnaebp8LzkOcvXnZeWV77vR5Ps5wmntYwbcjbxFvgvct7YDo+PWX6zukDPsY+Ap96n4e+pr4i3z2+I37Wfpl+B/ye+zv6y/2P+L/hefIW8U4FYAHBAeUBvYEagbMDawMfBJkEpQc1BY0FuwYvDD4VQgwJDVkfcpNvwBfyG/ljM9xnLJrRFcoInRVaG/owzCZMHtYRjobPCN8Qfm+m+UzpzLYIiOBHbIi4H2kZmRf5fRQpKjKqLupRtFN0cXT3LNas5Fn7Z72O8Y+pjLk722q2cnZnrGpsUmxj7Ju4gLiquIF4h/hF8ZcSdBMkCe2J5MTYxD2J43MC52yaM5zkmlSWdGOu5dyiuRfm6c7Lnnc8WTVZkHw4hZgSl7I/5YMgQlAvGE/lp25NHRPyhJuFT0W+oo2iUbG3uEo8kuadVpX2ON07fUP6aIZPRnXGMwlPUit5kRmSuSPzTVZE1t6sz9lx2S05lJyUnKNSDWmWtCvXMLcot09mKyuTDeR55m3KG5OHyvfkI/lz89sVbIVM0aO0Uq5QDhZML6greFsYW3i4SL1IWtQz32b+6vkjC4IWfL2QsFC4sLPYuHhZ8eAiv0W7FiOLUxd3LjFdUrpkeGnw0n3LaMuylv1Q4lhSVfJqedzyjlKD0qWlQyuCVzSVqZTJy26u9Fq5YxVhlWRV72qX1VtWfyoXlV+scKyorviwRrjm4ldOX9V89Xlt2treSrfK7etI66Trbqz3Wb+vSr1qQdXQhvANrRvxjeUbX21K3nShemr1js20zcrNAzVhNe1bzLas2/KhNqP2ep1/XctW/a2rt77ZJtrWv913e/MOgx0VO97vlOy8tSt4V2u9RX31btLugt2PGmIbur/mft24R3dPxZ6Pe6V7B/ZF7+tqdG9s3K+/v7IJbVI2jR5IOnDlm4Bv2pvtmne1cFoqDsJB5cEn36Z8e+NQ6KHOw9zDzd+Zf7f1COtIeSvSOr91rC2jbaA9ob3v6IyjnR1eHUe+t/9+7zHjY3XHNY9XnqCdKD3x+eSCk+OnZKeenU4/PdSZ3Hn3TPyZa11RXb1nQ8+ePxd07ky3X/fJ897nj13wvHD0Ivdi2yW3S609rj1HfnD94UivW2/rZffL7Vc8rnT0Tes70e/Tf/pqwNVz1/jXLl2feb3vxuwbt24m3Ry4Jbr1+Hb27Rd3Cu5M3F16j3iv/L7a/eoH+g/qf7T+sWXAbeD4YMBgz8NZD+8OCYee/pT/04fh0kfMR9UjRiONj50fHxsNGr3yZM6T4aeypxPPyn5W/3nrc6vn3/3i+0vPWPzY8Av5i8+/rnmp83Lvq6mvOscjxx+8znk98ab8rc7bfe+477rfx70fmSj8QP5Q89H6Y8en0E/3Pud8/vwv94Tz+4A5JREAAAAGYktHRAD/AP8A/6C9p5MAAAAJcEhZcwAAD2EAAA9hAag/p2kAAAAHdElNRQfcAhoXLDNzxC0iAAAgAElEQVR42uy9WawsWXae9629IyIzz3jnmrq7urtEtjibg0kTHkRCLUMSTMGGKQt+sF8ECx7ePEgwDPtFD4JgwAYMGHwTDNu0+UDTFj3AokSJJkVIoszB3exmD8XurrnufIacImLvvfwQQ0ZERk7nnDvU7ZtA1q17bp7IGPZe/1r/Wutfot4r27xE+n7Y/1ltH1IBQUEC4IufiAFs+a5eofVW9YTg0BAap2BADCIRYBCxiNjyXLR80/Pnygtj29faI3WuWVYed/vvu/hLe8/pyo67ebGsWTPlv8uW36Orvls33F9pXL+0z0U6n0PLNeeLPzWsWPeCBkVVEWy9Brv7RDV0vqP7EdnulsoVP5adn7au/kJ5Gut4l5c8obVMZ52Uu1ufxTXqimvV9jPb+dlc/llKG0h0gwFYZwikYbsbF9b4fxFdAAkCYot3B3KKlwd8CSa+tfGLjWiQClC078auABLVzo2TCy02vdDjkMutn6dtSS59bFl/2WL6v68XAHX7J1Cuh8VhpPy6DsBJ93ih8ac03ov1uAAZKZwgLd/d0xDpNcRyIQO84RmoXMFT1t3P4bkDk6cHWPKkt90l1sbuy+HyzzFa7WXoDt8rK5x0rf8sPHRTHnbxXcF7EEGMdDaZrTeeMVXEYeqNLmKLO6bSY3h6gER7PNYlz7V7L1bfD7nwQ5eN0czzsBhXf2SbdSHL915k+c6pbrnAdPmYfX/vOgmdc9ZQGfI+r00W0XHHIVJVxNqGE+Qb4BJDkI5zVXyHSGWgteEA6RarR3cE8l2iat392a+Lwi8NJnK5dfny9Vy8ouUoZM0iluUQbymSqYxGYxO2Fp4uIpegSkBRDdg4Rqy0KK4QPMaYEjRse+FqtdE7oKFNIOkDk6ZBk87POueKNta5XmlssvFzustGfAKe4VZRQZ+9X2Esq+OJ7na+usG4ivY4CaBB25chRQBUmvRGVNxzWNVGcKTlG8QMEaP1GvVuimiOaAA1iDELMKqPrShaULuYC/BVuxvT/ujiSfFfumOEsstalSd//p/o1/NzT6LNIKJrQER3WxzaWXgKIQRUA2I8RgRMjoY5IThCCGADxgAMwAwXABHiAlwkgOQdQ1WBlvaAgyyiDV137k1vWq82eti04Xb6CgtqnsEiXQGguoHG0ksYqqX12DX+xXMtHr3UQNDKkYhSLKgFoEkz+tQFMGkINYgoigQt2FjjUa+oN6C+ESHb8jo7+RgtoER2vu/bgcl2VIZc8H5fFahcReTyrA3ndyOVt+Wd0eB1Y0gtm26qdAxJEZFouSlVFZEOdSWg6stEekFRCYLIFPConOL9mHx2RDYfFscwHozDWI+NHTYWrLmB5QgRaVFp1cLWitMufybVRtcdjapchSdwmQhkxe9KCia73ELXqwKSxjmsoz9XFm6sLxKQFd9feeBarr32Iy/XRUmfLv7ssm1Sxiq2WLOhXDtqy/V7hjAnpLdQTYmSOSI36iBDTFU4Uh64ypNIoBkHrY8g+wpFdOMz0CZD/cSc3wuueblqJ+dpgYls/tdnimu6Ohp9Yrkr2RCR9J6YsFtpQoMKqp3GhscnAqZJJXiEUOTafQAPLs0QHiFyhuoZPjxiOvsG52dvE8K4zKPcwNjXSYavMRi+zmAwZTC4DhJRVXoprgFk2o4utOuBrjBs0kn6djeSLHtIssJ4rt+DcjlnRy1489QW64KqXA8k0jUgq4Cle9OaFVNrT6cvUpGS0pJWoj2olsu5BBFd8/UqEBo/D0n5+XtoeId0quT8AfvmNrH+WxAPkMQuJ/DrA5iGwV8XlexabfiUPWSRHcGkEeF9YpLyn6SI41lEaLryXkUrT0YucmMrS13mQqrSSJUGPVwlKy2qpthamqNhgpU5s5N9pumXmE+UPJsTojOMPcImGTbKiZJ9IrmFjQ6woqAzsqwqB64wOSyAhFDz5S1gY1WJ7hb8suzyEDcll68i5JensHC29FB7QXn7UmjZ6lx0Bbg10hu179CISKRYi906irq+qhFFi5GSBUsgOPzc4LJz7n4w5nT2LV771Du8duNfhvgNMNHyNUpzu2+bUL54XuS5NshXCiZPyoC+ILTVUwPtdq4z2g1EtOev0gYQQuNLpIfALct6iQiquNyh+YyEMYR3mGbf4eHZX2UyPSTPPs3BvuUo/vPE+sPEeswgtkRDIEpQSVD1eHdelhFLI9rQmuOuaa0OkFT89fqSTF2xji/hMeqzWrwXrZDRLaMSaaxnWRNxbVm1pNsBSRdMquOHoEWE0TgVEVli2YplEFDKnEgIWBNhxAI5qmdk6Tnns/+N+6cnPDz5Msn+Hjf2/00GgwPgzoZbWwLZxihk1T3V58dI6YuY9H6Z+7jsK9oO0bqVONpKVGsIiyKV2kibnkjIl8lLgxiQPGD9FJd+wPhkn7l+g4cPPuAsfZXh4D7XXlGG0evE/nUic50oGRWHDR68QY0pOcEKLKqqGW34gc2TCC1vVXopeV2/1rb57DYL8zK1/7JNCe1mD0WWsg665nibft42eK0eDukHz00ArqorQHtdf08jX6INukpA1DTWZ+ls1OXkhdOj6gCHhD2s2Uf0MSHcZTy5x/3H76ASuHn9Oj77DB99MOVW9EccxjfKnigK+tZsS1vKGjBu5oDkk2+UP1EU18vX5YFk5aKQ3pCm6jpf7hWoko4lb60BcARvUAw2BMg8JntImH6J8+nbPJr+55xP3yJkP82t4zd5dfBvI/EcZ+5ibLGxg3pcyBbepfqya37ByUpVvYMimAZiSL8nqLp5jeu2oaNsQQfJ5Tap7gBauv35CesiUVkDIBuOr91Eu6zBg0U0In0OzIrv0E7UqaqNT2tR2WZM4cSIaZR3V99nyk4lj6pgGGHcAZgP8f4dzicfcHJyyvHRNW5f+wHOxgn3zv8O8bmwP/oBxFwroo7YgKkaGi11p7wYlrrg195jYW1v+a5Vty9fL1/PBkhkjWGoopJGVZZpdgJL3VOi2qSXPKoQFKzmiHvM7N6Ax+fv8eD8a4zDWwz3Iq7dusbR0XXMYIZGCiSIFVRc4Z+FBc8tmEV/SovaoqwCWwCM1idfea0NGm4l5S9r7OdFjPjF5AsU3Znh6M0BbWV1upHJsuesvSGa9EQZsgZUWEOVto+vGyKl7rVKI0JRLc5L1CAmKp2L4vlLGSVbiUAtQQIqAQkOdVPc/DVyPCePphhe484rnqPRIT7cIAtvc//ePrf3PNHoMRJdL3BJmyVhhQNVlAbLdpRx5x7rJ4ZO2rQfXkYl32VAsgZEGtUYy7y0tH63Jg40FO0etuxL9xk+m6DZNzgdf5OH2V/lLFPyyc9z8/gOd679PHYQkUf3wFjEGAI5IgUFYSiMQnEwUxsgEWn0RhraNZ5VU1h13gsA0Qa4VEZmM9Mlm6s4W96yXGpDylU0OS7b/TW0m6z4sHYJqhXH3wLEdE2U06tdJmsuQntiFm07FRgEgyGqS9JVFVEtNdsiRJOiZFdznHvMfJ4yj36NNBcORp/jxsEhmv84I2txB/+EDz56n3n4FawbYtI/x0COsCYGE9f8qarfoaudrSKwZ4cVL2KeRHmZJ7lSINnxZmopULem3F1rL0QLdksUwZNPhGxyyvhsyjgVYhtxfP02e3sjvBoMCUa0bBQuNjqVxhZdaZQKIBYRiVZ0Vd1p3zTqVY+AtkCkOFJY0CqyxiPXbSMEWY9IvZTZRQTldv1d2TLfo+t5lVXGpo/7X+JjdM1xd5EJaYNIS/FAmy5OKJ2J0NZwlEWuT9WgXtB0gMs/YDz9Dg8nKa/d3udgdMCju9cIuSFJcm5ee43z80d8/PHb3LiTcH30c2jucHaCifYwZQNtISq6bVe7rI0EP/k2+3mNSp6zcuut933H4dKLpl8vd23Rxe93pSdkUPWrDVptR0NJzySIZOT+bWb+F5m4EfP5G9y6NeTV67ewe0Ke55h4QJIcguQESYtYwcQFGAXTOF6zSqxBcRlTl3RKXeDZABG0+Kj2o2Azx3u5da+b2a7y/lz+oV7w97atWutWa+10Y7o6WLoGaHfVmuoHOKkcAwSligrcchVXkGI9qUddQsgh6LfIk/+ec3fGycM93vqh1xgkjj98+zcJ8svcufFZrtsf4sb+ER/e/4DRoeXmaEwgIk/n2BCIYsFEMWDrqsLdn9tLT3l3g/8UvltfhOciV3ZPop2ivD4rqA2l1K63IaEusYViwyqOPD/Fh9eYn3pOzu4j0XWGwyOuHX4GFw+Y57bK05eRgytq9Uv57kKqW0qAoO5eF7EFPV03pGmj41276iyL/3ZQY6maaZXu1Mb7tOODauRzLrYgdqngkh02aMcpYM15ruyxWVWhtBpAumXG0pWDXxPNSEPjSlGMCFKCitBQk1YDRISQomGOkRhrPLPTY2Y65Pz8j3nl1k2yyZDJ6ZTZuZCHiEQ+Jvaf5fDAcuMYTh/uY+fv88qnE0z4HDaOS/mUqFa41t76K10RiSzS7ctskjxHxvUCa/3CUYk+R+ZXr9ggf9IAZGVE0j8jQVckM1eeVEObqpBFCaVXaCAYVAN5foqTjGn264zTA66Nvo/B4A5R9DrWXicYMJEpgEhd4U0GQcWXyXVTRkKhZdCVgGCplY2kr3C03X1f/71Zibbpmjd1/MsqCqjPjGzS8dpmdsUqcc3lDSwiO2xKXQOousGgb1PlpS1pm/7jNp9vQ0m3e/wugGnbHFf5MZFQ+jVmkRTXwsFRnRbUqUzJ3ENm4Uuks4RXb/5ZTh6/x2P/y3hzSpYLj88MbvoZvu8Lt7lzY59vvnPKR9kvcvPNO0TZX8OEGJg1KNcFBdv21rq9VtLrF8hzaFC/eyKRbc/tWQDKNvTWkz+vaP3tCcsls9LDdTcE87onXswM8UXFjIDTM5x7QDrPOD+dsjeyDAd3MOYazu8h0QCbgFhbtqJUQ2QW0u4iZqHR1VXzrUp/pSPTUSfVV5Q090ViIluxNBejW2W7z+5Qvrv6/GTHRdW/MZogpDupE6/+N11SX+7Qoz1VYOudmgbNiSKii3S7NMvSyxLhkAGhLP2NCZO3cOErpNkJaTrkaC9B5AGz9DGn4zEYYRhFhOwW4wmcnYw5OLrFXmyYhvf5+KN7vHH9FPx1RE0h7GgowaQCkb55J/3PfEHLvmi4sEtU8km5/meVtO8rjHm65xJtniXScZQ6wojaXBA9pbL1dhFBxYDOyPMHzM5PmZwHDq7l7I/uYMwe0xQGA4iSQVlyX+YNQvME2j0qlUe5mFfS/LPdvyCipVyKNgyNqX8ma6dA9hXu6wUix1XGuT8q0Qt4FdKkoC5EIWyKWqRx2NVRVB8lKLK6IlDX6Wy1wKDjrCzl5hpFFLp4zlUfR1F7UW22HNUcwwGCkvMNZvJfkoe38Kc/x7WDU1L/VTJ3xmwWGA0so9E+Mzcj1X/M4/ERo+QvcDQYEfzb3L835/bB15D4LYy7WfauhMYUzy5Q6+Xt5AudRtFP4Pk+KzB5dosi6j2hJog0S1eFlQZiZcVw2eglImADkllU73E+/hCXCVmesb93i0FyGxPFqAi+TIIWshXr6KQKSEzjy00dtSwbRWlQG7IwMkZ7JiduY1w3G9ydvbRNQLPzopIrWJwXmwe7/tx7SpzF9EqdtAdDtaPd/vtXVewFtI4CTPH7ptlpb1AdErzFyDlRdEaannMyDYg+4NrB9yP5NU5P/z+y/ITEFhVdaepQD7EVprPHPHr0EfF+4MbhmEcnt/nww4+48+kJB/HPIAECrpyrY0pHvKR6W9HTotpwFztasHTPGkkuqjqt2xd6fKKw7buvnDja/s7JbvdHaQGSGEFMQEKC6gMm4w8gCPO5Z2/vGoP409jYgjW44BGlQQU0Fqt05ks0Io9270gT/BrJEjEIoZFgryIcfUK2docFtbZG/wIL80okvJ/mplhEHKraM3Gx+6z7gKtMaReLDmlW5Uk3Gogg2KJeJLpLkLeZZTPGJ4cc7+ccHsw5efyQs+wf4EUYxvvkuWc+y4kjZZAIeTbhYfYud5LPct3+WdLkI+6d/QrDScL+3k8ipQz90jOWvmFrtHNGuv3ye7q48TR6SZ5PEJHnct88F0DS3zgmqi12SJoki9BQ1G3QC42ekcXwKC36QSoQ0IjYTgjzMdYG8gwkHiA2Rkw1v6H76KLSgzNsrq1fdK0vjI02qsdo0xuqK3jGDkXUOB8lrF9hG/szZBteavVS1m3nZ+slzI5e3Frp1e/YdjTS7WJvoLmYhmSO1jpwFThVpepGhhgdgUxx4THiXuHh6e/z+Owr7I0Ch4M3mE0ekbm7+HyAhgzBFdVfJkYkQ8MclxsCj/EhQt3nSCLL3mjCyclN9uwZ1191qDvCRFoWO3QiLjE919NDM6teiXl7/rx7vWQP1SeBlnv6z+fi/SRXHZFUaqUtj7seHVfuU+2R7uhu9rAoAwZEY5JoBnkGNiHPPGoNmLLO35RzSmoBRluWGNtG9ECjf0Q7FEHzMfr6bspC5rX2qFo/28ro6rLhanxWl8pkV+0NvZg1bYLihRatXqEd0p1Pe+vrrUu4dQfKrNvjUj4r29De0kJlAQ0YE2EYoJyBfEQICQ8e/e9MZwk3Dv91RnbKQ/cL5DbDhGv4MAWdEZkYMRFKXrzDHtgxqXfMZmdESc6N45gP7o15kPwSx6++ieY/V7hsJpQ6XLQdI1kT5upmelNfKKP7Ir5e/Ogk6rV6sgLiemaiSzOp2fKuSqkRUQiV6q4BHJGkBbbIENUZIXgQj7XgTQAyIC6OoQbVqDTeZgFOS+30nRnr0uPV0W1W36UWfLMCba9520gBXJQjlp1+R1ZGLRf1BjeUMl/oa3RJ4l3bgz06VOuKqEnoGWFni851X1BZamdI5LHumDhc5+OPvsNsdsT1o4TI3mcyzZmnnpADajFYAhHGGIxA0KiQBLUWGzkm4yHZeMy1OykHe69zOEqZzz/k/Myzl5yAjyhGKMQLAcdV1OOmoPvC/UbPq50N3wUaXC82mEQLTfVdhu80yhg3dmQHyoQHQS3gEc0xNsKECLCEcu41JhSVVTgEi4gQgpZ1/qYhW9LSCF8RkTTpjubGk/WTD9fROztKmq/2npsgs3t0ItsYfZELAuRFIhVdTcmsO25vECid4KRT7KErnlvzY2ZRRVh1thdTJAVCUbmnOIJMgEeYwW9y//H74F7l5p1Dsvl3GI8hTyPURRgtImlbJvGtAdEEEGwUYSLDJL3Pqft7DP0B18PPc7x/l0eTx5yfZgyuv0dwHsM+ogIm6UwLXYn8C+dNLirA+fL1EkyeJrW1katcHllbhOXl/A+pPKyeXoCmlpUPiPMQRzDLy4bACMr8SJGjl8ITLct+iy72BV1RTT5c3fHcSdJ3G96aoLCCWeivTNsCRHZwEkWuoqLqiiiDJ7C+W9enmyi6hozNmg78bkOlqLR/p27PWZSCq/qyBkMxthBkDD4ny3PyOaT2HQ4PTknCF3BzYTL7CpN0jnM5Ros1bowBHSBEEAxGAgEPElDNCnVftczncybTx9g452hfmJwP2bMZIu8z1B9DIxAyMBV1+/LVb39eZDB5QhvuuQCSpYfaF4lQS8fTmPmBlDMe+mSyGx3HxghBweWKJDFMZuXvxiAWwaFajODVWs13VTTUlIPvdkubduJ/heGUNfRQ18hvLeXd11+xMwOxS9PgBRblVazhXfMg1XpaQ2stN9/JWhpHVJa8vUWBRUEfaQUyGgrbTcBohvOOLD1hcibM5AHXrqUM3YCThzPOZ3dJ8zNQV2oGAxKhIUFICpoMB5KiOkc1YG1ErEOydMLJ2YccHA85Otzn5PQhk/z/IPJDhtlPFedpZoV8yjYV51tN43xBjNJLmfkXBEhaJZfabxCDlo250ppDWFTLrDHcqkUSPYBRgxhXvCUugQSCOEKZEwmUpZtV8VhtiLQuAa461bVDrWiD6lqSO2+C0w7iqrIkO9LX3a1XY3R3rrbaRE9dZhrjJT6rKyjCdbdKmg5Km54TmsPLVoOplgCkDSdAMEVkqwU06Ozz4L/MZPwR0d5tmMd4NyKbj8nys1p3y9TNlwGMK/woNYAHcfVUSWsUiT3BR8zmD0lGMfH0e7m2t8d08iFxkjMYvsMwegX1FjFRTfnqunHPIiWFvA51nqXxvUqvRF9a5BcqIllroIRQVsAU5bqN/o315HftKYpEoPM6GS+mSkAWQ4aCGqzYdv1alYuR9uQ4bUnAt4mShZ/bjDK0HY00mBHd1n5rm2a50OChncBlM7e6sLly+U19yUOo6uYopK/YQRrzQ0Taz1Nk/UTFJuBIc+RuqKkuCUrwAwjnBPMNNPmvmXOHa/5Pkvv7+OjXyUlKSisu57ZrPdMdE9DgSiGFhW6XYDAGrM3xISENp8xThwlvcXz8CuePvsl8esJ5+D1s8sPE9k3Um1aufTWYNItIXvTqH+nJB+mLd40vJJA0KTvpm8HR9ibVls2FlSkWWTP5jSKHYqN6lghiyhnaZsGU1UOyujTGNgnji85s0Jbh6QYr2y2IzfO2r2SNqfSDBlcFHruB1uboTVpB7jJo7HKH+5PMi6a9xuAq01GebsxsNwSMeIK7jXcp8/l9pv46FsEwJYSMPLUEPWkIPBaOjzb05irjX9RJmIWzUjop1ngMKW5+k1lmGI0+5vDwEVl+zOn0jMHwa8TRpwvQtApWOj1PF31mL5DhahUAPV9Kx9vvjmd735+2yv0WExK1TXOVYCNrByG1yy4rGW0o5maHnh4BaVTjtPCMttBe5bWug4+NAiFNLnYb2fxuBU2f9305Lmv9MaTfSO+2YHcceHVFC3FZG0tX2o31T05W+AzLVYdF8UVRCagaoaEqt01R+Rgf/TrzcI/x41dIjEd5hPfn5JkQdIw1dhHRajWUqlx7Zf9Su0HSoMEUPpMRxIDXuwTuMpl9gcO9nyF3HzPO/w77aczB6KcxZlQUnkQGVVdE6XXyPVyhUXqScudP2Fr1VpRedbSy+zWodGzWM4W15t+edo5psQciqqFUdbJ81YeVoNQzHkQUQjnXQcpxt2JX3N0GXlkhShLIMjC66IjXUCgE9z5k07pplSZTSxKjtwR1O60nXaK2liXJ+36uuktEJFe0ya9q6NWWkvVyFeezfv77NpGgNkjKmrxUXeisdXJpUo7LLfpHSpl4UrJsztS9R57m4BMO9oV5ekKanjOdniMmI4ml+B1fVVZFpRJ2BSJaRiklyGizvymvJzFqsGT5h8ymn2ZvGJF54ezMciCeveMTrLkOvsi1LEQlA9TzUgxN/S15rhLRT/FcuotjZWn7050R8uxmW+mzfyYdLzzarY9BCVXvgwaM0p5QKLJiomijzNEIGkVoXpRAFgU1vpwBv+x9VPSCiC6SnjWh0J7K3V1IsulGb9tO0jnGskrt1TX1PekFotv2zfT8qKCO5BI7bs1M9jon0owUZQWdKDUVWg8wa/yemHLiIR5CKBoRJSXoKVn2gFl6jxD2iWzCcKCcnY+Zp+dM52OGg8BeYvFecMGWVYRRse4kb6ghCKqmKAfGFnNzgqImB3xxNiHC+bucp/d57XiPzB9yMvuIycEvg7/Nfv4XC6osKfuoaol5v4iCMIs4/wkDijyBTz5VO7rjeWmvovdzz/s9uWd/iUNHvdVZzVco6RwrZeDg0VJiAhsX/+ZC/WBms5wsDwz3hGFse73/4B0kCcwDqk2Ps2SwGuNyCdpD7egK4y0rQETWI8baELpvuJNs59Vf6uHLJf9ddwCQLQE0rL4WEdlBwHJFuKOdUQFL/9ZTki1aVqRradhNyUBWkYLDiMPNbuDzMVk2I+QWa3PiQc5k8pjZ9BzVKaOhx4iS5QVVpXTL2m19fiLNcQVVqrCc2amOEAwhKN4fYwPk2ZiDwRuk6WuMTxW1f4wM32MYXSOWwWIUgjSkUxRUfSHrUkbiiFmaq2OeqN/64ib3ZcMwv+cPXK4GRJ4EJRcVvG95knXjd/lNXtG8qHeXgcUYJQ+e3HuwFlWHQQh5IKiSBWU6yZjPHT4YzLEhMW3DHxSc80gyRKdSb5LFuN72gKoiZPGNnhApe09CSW914pCl1oIV81aCrp8FIrJExaheNLm+LbhsAx67RzGb53xc3pAU1Uvbgls/HbiQRJGlCGS58ELLtVp48kXvUTlvRgQNhqAWUYMxc7Jwl7n+AxyPkXBIJBk2GnPy+CFpNiaJMvaGBYikqUXEYK0t59jQoJqq8t+mAnFY5PW0iJaCjwkegpxC/A+ZZQdc3/9eDpI9HvvfhPEEw08SjT5H7F+hCO/L7ymbfAtwLCIULaMv6aF6Vz2vl4BxOYDR56qv5fkFkUVEUpPUxZyEStkXlGAAH4g8qPMMpinhbIIZHWH2hohXbB6wsRBFnqEowVp8cCRmWBwm9xBFBCAEJWgoxPTqvLw2zGS1YXuUfsUsqK1Gh/PKorENQ6PWclqNRbTZmb8ItXUxWmu5TFS2iEIuWk0mlzw3VlBT/VRkTXHpMg++SG43vcVQCoeGhYGVop7Qe3BOsTbHmAzvc+bpQyQ4hkmMmyXM8q+Tu1OKkbieEKTMfcT1OiwqFJVFl7xpKPgGIKCy6FUJ3iCBsmgkxZqAQUgntznPLc7MSGLw4U1mZxGHR+eov4loVl6TrSfNIwU9VzQ/luDRmki6CaxfgsgVcMEvTJPkkywOiFqlmUohu12p+lZ+UVB0lqHnY/L759z7+IzRwYzjm9fK8D1juK/IEPxYUBdzdj5jeGO/MAzeI8aipogwpJwaV8XkC+BaRCLNcshiXC/LEtwrVH9ryZZN4L4xw3uRCOSKK7Z2iko2RSFbZLVl23NYdct0aQDVkoFrRaGdZ9oBkaWnW6kW1P0VHbFOLdZr8Ip3vhjzzAznzsiyE0Z2SGwj0jxhOnuED1OsyQEld4YQIoxEhVx8qzenGKC2sOOhPTpXpAARiryKyBxjU4RCZXcgIzcAACAASURBVDjLz3D8GvHgmIG5QRYG5Oa3ycMN8J8pZVzmqCZoRaEZRU2pnt1c67KtUrVccq29jEy0boJ+eZ82RCTSsk+CQb2HvKS15inZOOVXP5zw6++fcv5wikxSjD3HDu4VQBIK6ssOLS4Ie4OY47MP+Heu3+C1owEHwwisYIFBYnG5hXmKGC0E8DpSJtJDK7X2RrfCWFYJNrKWStnWIVkr830hYLgIey07b4PlWuUt7sXGwpeL0m+rohFZvYGXAktt2McSsNSUPU0GtIhEwGPEMUhS8tSQho9x/gSjEeoduff4cFY4SCUoqSqmTKJLozeq/t+qW74WqjVUFVy1HpwpuVsNpVZcBJIQQoJRTwhjXEgJk09xcC0i1zMe3D/n6I1zxHpU4jryEbto8m1HaH05TV2zzq5yTV0py/Ly9YJEI2VEYhYefK12YiDkhDRFMsf4fM5v/O7b/OKXvo3MHaNgi1yHKOICEhwhgpBYBEsyOuKN7F1+9qd/lGEScbCfLC4otkSRhTyFsuZ+ZfuAhjLhuJgxsdoxkO0Mq66LPKQ/L6+bjOpVU0YXBRe9MgDdnSWRLSiu7c9HOoBUJ5ilyBuIMQvQCeVM9GDwXgneMUgyouSc+XiPyfxDvDslNnuoHzPPZnh9WEQLImWNVWnAm9HQUuJfOvUYi3OQKukvWkYQghKjIUbEYphjDDiXElLD7VdyTJjywd2U2fWPieIjkuFx4duRlMO5KJsvzQLgyiPTK4i54YG9dKovHpW8fG2KSBqJO1XQYsytxoKMYqyNuJ3BX3plyOuvD9GxkvgBxnliq6gzoJbBwDI8HHCORfeHJFPLv3R7SDIQ0gBJiVPqAyF3MBgic20UTEn9bg+a0v6oZGvDJP2/Wqtzdzw7rTbvLs7dk+q+lQv8/IrBpHU5srVhWgkmqhc6L2m2wDYbU6s1E4rEuCnr/5yb4sIJWTonS+8SGyWOIE33SLN3cfm0ACQMpmyYLSipBaBIZ058S6ZNaNCnlV6WdhjRojFSRQkhQtwANQ7kLul8D2zE8V7C3bt/wPXrb5EkBthDJUc0WeRpyvOrgWRjrWa3slAu4Bi8fL187RyRVN6/1lGAMSCjiGzPkh0N+fE3f4qf+jd+Cp0J+dxh5h6TZjz44JSzhzOOjva4cWOfaJLh05wPp58leW2I0widO9JBhBUhZL7grgdDdFJuDLNmbrqypAp/dYa6P0IpxrOai9POV9J9K1v+bPkzl6vSukjEImvAxPR4y1tGJbIY2Vw0BFL8WakriKkdDxGDesFGimggd1PS7DHzmcX7xyTJiNgKMz8gyx+jrigzF7GFoS7FGEWkVAlmQZ01pFfEtDlzEVuDiC41LALiytTUAd7tgQmY+EOm0xsMBje5cbjPt9/9OoOB5drxIcghGmLUFBVnCwpNaM60X1/+vsVze8n5v3xdbUQijTA9tL3PALEqEYJNyshlaIkfzrg/EP6Hf/qAf/jeKffHE+xoiLoxWQq39g/Ym6T8tz8x4nC4T2IHREEhFjzgIotmGWK1/fUia3QLO7ImFzJ8y0jQ9Zx1M591CUC4aAf8RegwvdqoZLW1X/tvrY70rXtZutFMJ6FOAIlrb12k6DdSHMbMUHuOm0Rk2SnnkzF7+0CYk+cB787KKYllBKGCEdvARNOYbyOdwgFt5E8aCtOVgq+hbKwNjeozGiX1WUGUqMf7E3z6Os7kDJKcPP8Gjx/dYrifMkh+tBw1bEvM1BI0bT9waFgfibx8XYHT9MlNuD+Ns44WdqbqTDfFaFyVIkDIFfGBuTdkKOcauPVgwm/ffcjf+tu/x715ihII12/jsjOiec57Ypnnc779nVf43KuG28cWzU0xszooEsWQpWALob2m0RAjSKjyGYsu+laSXfpu0w59GXXfzJqmvVULp/P92jtydxMY7Jps3/bn24LHEwSWHoDRfunF/vPojDGQBo2pVfd39ZxMBBKXkjkOmANTjD0huJg8P2c2u8vRgRD8nDSd43WM6BAkB83rqKNuNCxBROpRuLKi+GORrygc/FD2l2gNIgUGVU2ModD6AiQMCH6Mc5ZZmHK8F5H77/DgwZtck/sk9gcL+SGNQA3GVnpftv+5qVsGkE1G7yXO7EirfoLzJE/h1KPlXSyL2esiqA11c7sEZeACqRW+dDbm04dD/t1Xr/Pl++d83iT8hR/+QTKX8eWvfIf/TD1n5ojgLBoXrJWbzwmpQmSWbZ4poxHVTmWvdhZ+d0rjCqO01Pyua5yNC1Z0rXhC2pzcuDWgbA8iuubYqldI+22yNLLmnJcAd3lrbvrutpqvtnJnimAkQkyRzFY3x4czxMUgJ2Acoo5BrGTzDO/PSuPtEeJC2w1P1ZshdErQy9xLqSxXry8j/W6DqhT6XrKISFr3oxb6M0gQfG6Bj0hzw60b13G5kKbvk2Ujsuwxg2gPY7UnPyXbPS99XruzX76eSyS4UiDRDu8tQrCGTANaVLdzOM+ZDCJ+J/XEb73CX/nin+Rv/taHPDq9z/6fPuYLr73C/v8USL75AB2OGAmEOICHs1mKzQ2xLavEtCyblLJGx1RNitpOKNbgso08yfqoomgc25ZLvmyu5LJBp6wFse51bD8rS5/Cwu+ASSfaW9D03SbD5qXrWiAt1o0tYSnHh1M0uwnmFJUTjARGA8N8luL9BNUzCEMMSTmKt6SKJHQijWowVkcGpQaMFV35aloVVTXgy0JaR4gQBJcnBPMhWXqANQdIGAD3ybID5vP7iN0nsRFW5cmFDy+jkpevJxOR0DbcLBRLrBiMQJxY3CDi04cHTM/PcONT/sR8xv8zPOK3vh3xSpbxrWHCbRMxijL0YISJDWYQs2cGxPuWyUMgBMSAqTxN1TLX3okquh52K5Fc/l49n0I7oah0ani3i1CuKhx+8n5Kc2yXXtKiXDWbqv2YpdqD89KONmtFgUa5rRagUVBEUOgyOrzOC5kdTYkjYRbuMp9NwU+JTE5OhstTQnBFHKOhLiMvEuJmBX4vqre0V7JlaV5mnXCv1l/9KV2OwNQLLgTEOGbzMaoxSSyE3DKdfkC8lzKUIehBOQRohwmJsil6kcs97qfAjL58fXKikQWQaDckKbp1FVtI1RnBGCmmFjoYDSJ+7PZ13r435lsnKa9rypcfTfk/f+f/Zc6Q2Od8gYSbhzA4iusqmOGwkEzJci0qo0zAiGk0Kle6SYG+2ewrb265eZcplVWbb5fa3hX/plehwrqJ2trsMupKCeMtfr709z4xzMuDS2var7Rn0RSRSTMqKa9KK7mUulO2lkGpUg6KI4SU4DNiO8NKwOsHzKZzYpsRmTkhzAk+IwTFGEtR1ebKBHb1he0ktjaT7HWTYk2o9bJFUkm1lKKKhYRdj0aYNlZ1iEhiYTKdEA/2SOIRIQxI049x/i7oG4XqgztAbLRanbFXxeEJOzIvweQlgLSApCkXUpf/Fqq8aopFaowUkhEAsUEOEr74qSP+WXmN77kOtwz8q++e80/e+TYfZnNuaeCLb77BrevHDIcDwmSMGQSIIlCPNxl2f4CblfIo1Rz4JRDos2m6pRF8Cg/kUnZWL36wXSpI9BktVu02j3a00Rr4VolvLttcXUjQq5QVVRWKK6o5hBx0TpadEvJHBDcmMik+n+H8FOdTjPFlUj0u6NTG4Cjpsc6LiZlSgkrfqIKenpoq2U5Aq/2CtIJixdQCl2IsYgKBDOdGGDXYeIaNHpPP9zhN9zh+JSf4gB3kjRnv7V4VI1s2rT7JuVYvQeW7EkDWUFvVXJAiKhGKaKQIxxUPhMjwucSS3zjAHo147bOf5q/9mZjxn/48b58rn3qcc/1mzL3ZlGwyxcwCchyjhwOmJ3OIcmQvgakQtGFBFpalKCLTLSOSFdSS9kqE7G4Q1xrtncFEL7Cw1jT2iayOOnQd8LI6YhFz8YvVbrXVFo1zUlFDbUOtjclBUlVQlcZcQ1ZUXTEHHZPNH5POH0GYEUVzZtmM2XSG+ozIeoI3BI0W0bZKq/mwPnXpF5JkEaustKRSdbRrB3KEYlBWQ9naGFvOkgsgHu8V74UoTkniczL/EdP5b3Ht9Rvo/F9EI4AcNcXQrVo+BcqqLjboYLyMUF4CyBOntrpDhrSQL7EW1dID8gGXeZLYEozyLc35jW8/YP/YEn97zNG1Ax6cPuacA/4om/Mj96/xue+5hZ15yKdgBBMpkYFBbND5DIwWOZIl1dqm51rOwZD+KKQ9Xa8nyXslYcSG39mGodpqoawCrTXfv1K9eMuFu0oRWS7Qj9ACkQ3gvwqcO4rL2mBcW1MEtQAT76d4d4Z35wQ/Rv056id4lxYRSyv6WAzPas8TMYuvFq1rOuoZVj05EVrHqUQyK5UIs7Ct2gakxd+bmRQFPCIZqq7Ya3mCc2MePZpw/XAM4QAxUSGXr1qXKLdow616SGTzWnmZO3kJILtTWz3e62JmaVmjX/ZxhED+aMoH79znv/vSI37hN36PvTwQPX5ISGLy4QAjQ/LM8aODQ/7mdXjz1ZscHo6QUQTkJAmEzBJmaaX63Vr+VTVP7R1q18NuEs3aM+9Sn7N1seP56MJLvxgAao/20or/X1lwoBfrfpaqGzz0fG9fRVYbQBbFAw3laS28eWsWelOCwQcluJTgp7gKRMIE58a4fELwM0RzVH1Bn7ZGzZgGVWY6EVjZqLjECCkrNbdYjH/uRtDV7RCknXtpgoiC4BGZoV7I8xznXkHMGffvTbh+8BCCoOG4BFNfFB7IIk6ijk+uIPq4DGX7Eky+60Ckn9pqTIrSUCQQq+7vwSiBYcJn4oQf+tjzp27fwM5AZA87SDDDATaJ+Pg7H/BlCcyjAwbGwl4EkYUwx8/KCppkgM7Be+kXb1wzubECmtrD6xtIVdMUy0TucoPcFnSN7LJB9fILTPu47W2opV0Aawv6TNaVn7bLsZeLD3qeYfc+dlVtpVDiraYelsM+yuKMqFJsB/VFROIm+GyMc+d4P8a5Cd5N8T4rpNlVF5SSLjCs6BSvpiiaOopSbUj1SD8QytrQs4QHbatZa12cUUYrppBbWdwyj+qcNBOc9xg7J4rPUCzjybuM9mdYbhXnbXxRSVlSWtVwOIWePpcLAstLMHn5uhiQdAZIlbNJVBUVwVgDVsAF7OGAv/SvfIGf++Jn8LOc2Uy5cU3RMCdiyK/8N7/DX/7gMVO1SF4M/gkaIM9weY73DokHMJaCeKhUThsgILKGO1JdvVq7UirSLQPmErmSp+2t9EjCyBqvUzdEIDVI6Qpjv03F1iYLows3fOXN7um+7qrPi9TTBisKSkMxy7ygf1KCm+FdEYWEEkCCm+F9SggZReVhWearps5hFK8SQIyp13ux9Bey8ssOjKxdOwuaq11osJDhMe259JSqxaYQSy0qzCwuN4z2JkT2nDi6xenJBxCdczD4kaLZXRVjGgPoGt8VlA3J9xfFmdeVtOjLaORZAYn2eC8imMiW1IKimUe91nZZEstjCYxiw3GAaBQzJeLBx4YvERjOU2zmmOcRh1XzmEmIrxvyexE6mwOwt+/BLey/0CmD79AM/cnv/uZEKVVZr0yM/6nr7fQY7S5tJTvqWG0sBZaVEUd7zK1sAIoNm6W3AKqZ3C7zISJl82A5Cx0FP8e7CcFP8G6Mz8f4fEZwc0LICd4V0vKqizJtoRRBpAaS5twRWgMYm02H/Q5EN/pqzU8xfc+kPUJaRBuy8FUlWTmhVD0hFE2Uhn1UCrDM7btYewMTj5DQ+L7ILJ2L9DlgLyJ49P37k9qjV7b/X7BwTbWptdWD7qVVDwiEHDeew/ice+/e5+/+UcYv/vbXGc+mWJ+xrwUq7csx/0jPGATlmlWyYUQ2c4z2LNgBxpa89DwtwvOBxznFe627lbU0HcU5hiV+uuTd6vxJTSW0aJMVHv2LACYbN9eqfpLwFM51m+toyLI3KrekkTCTqvPcyGJYlOZoyFE/wbkzXH6Oz8YENyX4GcFXILKIuow0aq2WZEuERSVYY+4X3XW0+ZFXsvN1QK8lRYciNbW20PKq1YvL51L/rhTVXyE4XD7H6JQoSnH5Kan5GoP4LaLwZps666+9vBx0yPNlqJ7vPfpdCiKN5xKtpDZCQQy4EPC+aObyg4jcC5PE8cenj/jqyUM0mxGJ4jAYUW6mY26Q85Pf+3k+9+kjRocDxicpyTDBxhFkgeBzJEkgA58aTCyYyJTJVa3BRMsu5oVnaDrenbbLepr6XGKe3EN7Ip6JXBFhrZf83BZRiWxDhenmS6iTXWUCvHXchoCiMajPCJqjfkpw53h3jsvHeD8h+HlRpeXzUuyw/WVGGpMGmzhCJcrYZC5lvUU1/ZcnUs3UoXZsFmBSgZS0r61unjI1yBel9go4QsgwYYKGU/LpIeQxUfyYSD5TyLrUp2Yv75A8jyByGfWJl+Nxn+qzifpr/wqOOwTFOV+M0o3AjCIGg+vctDF/8TPfw40f+B6msxkhOMLeiPhgyEF2zish5ad/4DYH+4rPMkII+FBodemZLzqLR0PIYTqNkMSWG7SHY17S2JI2kFQJzqpUuC4BDg0wkUuZ5qtfqHqBjX7RsuX1m7IfynaguJYi2m0HjS1PP6yJHql0sIqEuIaAlsloHyZ4d06enZW0VpEXUZ+h3hXq0rWxZmkw1TI91e4V0S7N21x7strYSh1oVON5laDaaPQtUUibFXlmsYalamZc3Fvvc4ykGHNeDOKyv4XT2wz8DxdFCRvs/idaSusqJIyeOzB5+tGIPKVnEy3PNqi8TosxECUWo0psAibkZG5GFGb88O1rfM+dIWKGxJFFRhEmiZjpIWZouf8wZfpqgokte6MUE7TsQlYGe3vgJlCKN9Zw0Ny30owu2remqKwxvTpaXVWjJZUjfVZgsmUfyQYwuVDLmWrv92/srZceMOlGI9K0ubrd7RBZiSvSKN+rq6okUFQ1ZWiY4v05IRQ5Eg1zQhWNqF90hVQJdDGthsLefGDzJ9WcN636kWx7b8iKZktpSqtUVVuhmXIsGgkruXpp3kJpUGjNaDsnhCneCyIDcIZsriSDD7DJAHGvrdzfq6coSv+PnpfpiVetgXdFYPKJlZJ/SqfcSLZrgyQudouxQlzdSM3RdEZChtWUD79+l1/4pd/h9x+N+fY0I8MRmYx0nnFgB3xmcI2/8Tf+PH/i1SMO9iLUBfLJCZHsIYNDQv4xYorpcxWILMr9pS7/XIzelWVaq/pr6NT9141fzequdVP85FILVYysWP96iee//Qjh/t8o7+SO/YqLO7VlddYWQLiIFvtBpa9vvFUhpUWiXUNKCFOCr0BkRvBzNKQIjrr5sEIDqUp7m0UCbVBt52d1CVU0GJblXXRZubhcs6FO4mvZzBsW/VCy6GGptYFFG/+/eBc0ryP4ORAwxiEuIpspM77DwFoS/2qdK1FdZT+3RIjnwXHX552K/mRFI0/zGUXFpLguZVS9qpkNHiRChjfQ+QSTB/7We1N+iYjIwamfMSJw7eA67/kx9zTnM3cOsQJDW1HBBtV9nJsW0X00IEwV54qoRIwtjUrRyS7S8aY7M7JXy6LLzgvoMmBSGbxFh/1lwWOHxsNlXmntp7Zd0soqQcpNlNc2gbZsMGLS8x1FzgBNi052Py4BZQ6aIerQ4BtCjKYs1zDl8IOKQqoqoxpK0dL+ntYgrVow0tJuNOx+tvJ1iirBQomhNdy90WPambOiiymLRZ6ojGrUAUVJsJKBE4zdJ88eo7yDiQ+I63LosONaeZk7ePm6WqCPFva2SxdR5BlCWpQjmgQNAcMQ53K+/tF7fH5k+Ot/7kf5iZ/7PA9O78GtNzAYoizn4HiEBk8UWXQ6hWAQkxDCCXkawA5wTggVdyxlTX9DR6jWYOqQ04KsqUnZsFGWptCWDW+XiUya9IVerBtLL8wt6E6f2tY5672LchE6rgGwzcSX9J9TNS9GS/HD4od5ofIb5qjOCDojhBkhpEUVVwiLz5Y5Fq1BJCrXVyFDUnxpaJ1bc8xuM4ICA8bUsiaVFlhh9Bszc6QEj0rOp2p+NEJLxkeakZa0Ipu6QVJKoAm+TNbnaFBMGIJ68vwEj2WQ3UDNGSLDctZ8JR8jLHfey/MPHk94rMOVRSUXOs6ziUbkKX5ttHEiq7FIKKrcMxVs5smylJuDPV5LTvnCrRHOea7tH4M4jArGKtP3Txi8sl8s6igiBMHlyuDwkMnYQ54TDywjq7jM4WJHPLDQAxq9Xq3WxHxPDmXLcaO0tZDqXhaRzQtdlgkg1V14Au2AyK6Lc1MvjSwiOW3el+Y1ryhtlYUg4GYFgFWzL2TDOXfk5LWSGan+tUiwS5lk1zAjdxO8n6GaFvkSzQje40NxpsY0UvamBA780jyRSs6kqqhaUEum3b9e5lmkScPJIqehNHtBDKoWawu17KBKCB4Rj7WBEBYg4ksWQKRD5dWVXwZtFBzUsi1a3Iui3DmQh4+JogGiny2HjC4kWNoVaMrGCYtXFai8wB3tF8uTvNiUVg0kslCm63mZIqy3UmxYJ5iQEdQhA8O93PP3/+Bjwm/9MYejhBAbsnGOFQfRgC/+ez9GON7HRDFiFHUes3dI8ErIchjuM7ATsqljEHlIdBHuS1vhlI1GTXo9314jXTdey7Z4saTHdHlnSi4AIpvkwvvBRFeHYwWBqVr3WSw32rU/2xYcWNYE07VzWqQXcGsQqTSpVFE8Bl/QOjrF5VW577zw0jUnqMOrErRqWCxLfaVU1a11s7RU3zWF6i6mI/RJQa02tLAWa6mksUwzGpEy/1H2qhjAxJhgiWyEsULwiiuFGEUc1lYaYaGWsTfSlDSRRVQOBYhIwJgEJJQgV1DNQkYIc7x5H/UWm72OEVucQxTXat1bJ0D0CsDksvZS5MlHJVcFJmujkufjGuQpn8ZiWk5Nn0qnyscQVDBiSEQZjEb4fYef3uf/evd9/m9zD685sU04igwP0xQ1yq2jI/6rD77NT0Rv8NrhTSQy7O0JmntsHGGSBJenzJ1lMEiIk7io61cp3yxpNWpd86/9AEIXgNo7Q7v6Vbo5etV+zdcrWTS6dV5hF3DSnmirKaXRFEVs3EOa1FITDPqApW8Yu7QjM+2Z11FpZ4k0hl9KzaJK9SxDQMThNUWYo2GM92PyfIL6OWiODx5fSoWIrSr5PKHqg1dBJAZs0dEulcw7CxHSKqIoxRtFbDmFsZi/XkREoZGglzpyqdVJRIpzALCBoFMCHqzBmgjvhTQz3LwxYjpxTKYpo6FpzGCRVjFClWsRMRgTF3+KIDYGE8qiginBx+R8C6MRZD+OmgiighYM1hSSRlvkTJZXgjxdAHmaYHKlFVzPb+Rx5SCyxTOJlmROa9VXLb1VwWs5atd4CJAnET/zQ3f4w3tvce9kjM8Dw9GI/f0Bw8mcYcjY2z/kzZu32Y9HqAuILd2vNCWKYxgOmD7KmbgB0d4AGyWYErSkereMjTRS0YvJdfRNoaN9DbrCIK9MZzTVj9funYtzpf2lsnIFz7sP5DoAsyH1ro3mPZH1kaA0IrUFwEsn17AAEm31ayz0tKTUoZKyK12DQ5mjOiGEIhrJ8ymic6w4QlC8E6xEWFvNbNcaTIQYNEEYIlIMVFMykGwRZdROhylmvzeBxAhGFZWyMZZStl0WasHVqF4Rg7EeMTk+n5L7FGsGRHaEc4Y0MxiJcT4wT5WDgwjvA81K9wWdKCUIGowYjERFdaPYkgoLIHN8HpPr+8XnsnOwCcIIwWIkKgZriey8pDaXcF+1WsS6cQPPb15HWrqqeilYukq0lmeEZ1H/deliYZdcslNFrCEDzMGQf+0zlj/zsz9IlnqujzMYWdJBRjKPEGN536VwdEyOAedRI8jAkntHMAaJYjAQQjMCkTY4aDPi6JaRSi2LUkcazWikJce+MGZLDWcrauhrdeErhJFmw+VSp/WlF6Cuj05WRlGy0bDU3XZLDqRp3w2ROqJZmuQnnYCxBpJmJELdTBRCTggzNJzj/Sm5G6M6x0iGsQ4hJooiIlNIsBdjdCN8yMlyh6pio2JscxGBBDQEklgx1qNqyHMheGnkvgNBikZca8GW6zOUyWxjFpGWiME5JajHBYeox5iAsEcS7yEozluGwxG3buxx78GYa8eW0WiPLMvZP4w5H3uKYsVmNz8Yq3hffLeUwGKqWEGV4D1BUrx4jAhp+iFRtMdAbhBFA6yxW+Y+ltehyELevteB0KtsONENUclVDUp5kmDypEFk3ef0mQPIMpAsNYnJYr6CaqG3JQLlYKrZyRxrz3lsDrg2dcgoYrh3jH9wyuzxOW8cBTg6IBaPfzQhD5AFRbwSTFENYyOLsUUDiZQGZcGxNGdcL7zYNi3f2AQinTW+AJEmDdGltHTtc+qr5GqA0kWqs3pUhNcvAtlIjalu8l5080KUFclxaa+NmnppGSBZAfTNY2uHXWiAfcnpVPV4qor6HO9mOD/Gu1PUTzCSYW0G5MTxPqfnhulsxp1bCeCJohj1BvEVKxsgOBAIPhA0IDYwGFTS8hGph9wp1pSTDtQR1BURuI2KCCQUMvOmyGgXVVIUxcXeebLcF+DkYJQccXJiGQ4dcRIYTwyRifmd37vPj/7IPm+8OkJMzNFRwtn5tFFqLWhQrNWiUMAbfIBQRhaxldoTUlWCL4AkiCGfv0eSXCOKLOhxWx1bVsfUzchTKzK4MVSuyJ111bPlcn1X23jZKykufe4ARapxByJPCEQ2kGxXQgXuquW3/EyiFoisOV5kCrVryRzT85SHKfzauxl/98Pv8E8/fMhI5iSxsBcfs29ivv/DnP/iT6UcWo8VxRohRiC2KAmaZ4gYRnsDQu7QSAuZeik57Y5+qdZhf5PXX7xrRJA23dWqZq50vLZMcWjDWK80tFv+VNd4crrDmtKwbaOibvgZnfxRQyZEeuiO5sjAFccI2gZ46UQlFaBoDRrVjXdxOQAAIABJREFUMy08BKmHlXlCyHBuRp6PyfNzhCnWFvLw6dxhyJnPX2Eycfzjd+6jeI4OI4Km3L5lef21Ec7lRFFBTcUxJEnEeDpjOFRms0CWKiIJo4EligTFMZ3N2d8PiMAgMajGOCd473HeM0wsinBymrG/Z4iiqBSfDER2yHg8x8obnJ7kXL/5gDje5ytfH/M//8o38foGN37209y7PwdRnC8S9QU1VxjozOWE3LO/P2LPJJxPAkeHCaowTx0+KHEkaAjkaYqI4PV9hBk62EfISy35hSOwqbS9nWvX0nfU9s8aUe4CbMzVg8hOv/98AErTAdanMNH48rTiVYJeWXCyPvfVEL4DyD1kDvf4Mf/rH97lP/n7v89XvvoOp3cfw4OM6DTi5P27fOUPfpf/8fe/xjsfnnI6zZBYiGNDIhBbi40HpPMcxJAMY/Lc46t+kqoWvkVT9XgsreuT5XfLiSpmnSiFl9XlWXTNu30OsvUyb75DQ7jvIu+gWr/rWgRZrktoSc1U19x4U/H7YhriUIt/r9r1eu9pAxS0OaBSG4OolNZc8tY9FNN/j8Ki90ZDocOmISeU80ZcPiHPJqBzjHHEsZJmcHCg/PKvfo2/8h/9bWZzw3gC05ngvOXGjT0ODvY5G0cYMyKKhkxmoGo5HxuCH2LMiBvXj9gfHXN+PiBNBwziIUGL4g80ZjYzpKnBeUOWW/LcMp3BfA7TmcNGkMQJ8/mAEAY8ehxIBoH/9K//Pf6XX/02h0cW54RXb9/iP/z3f5p/4Z97g3sPAp/9zGukaUyWw/lUsdGA6QxmKThvmExhNgevlskMch8xz4Q8L3InUVTMVnHek7ucLL2Lcw8I7hT103atTEM8chvjXI9+00X/j64YC6AX8oa3/B2RHXba80V3Pck3l6bDd/Fat/+yqF/mQmvqoWI2Uh/I5zn7eSDyhvvnE/55Vf6Dm9f53fMxcxP4j7/vs5wOha9++Fn+8jff4V4+4bPRCHswArWoV8IsB19w00Es01nAxgkYu53wdUPLqG3wWZIJ16UmuAU1sDUo9EQ0226M7kaTnROfW3oQsuX5bEuZaXfMiSyV9YbQvqZmSqoGa237s80CiIX7Vj0Tj1DIoGiYQJgWTYdllZZzObEE5rlnmAzJ/Rwtpxv+yI/c4lOvHXJ2luN1xuGB4YOP73Hj+DV8CIgGXrljuPvglDu3D0hdjjGWD+5OGA1zPvf5fR48mmBiyB24kHD7TsI7702ZjAP7+/scHx5yfDTga28/YH8kvHL7kEFiufvwA7J0xD/z+bd4+Pic+dywNzrifKw8PoHbN2+Qp/t8/PBjbt9OuPPqOe98Z4LL9vnUpwd4l/DR3QlHR/vM05RhdMhbn9vnq19/yGuvDrlz6xjnhdl8zu1bI7xLeff9x+ztGQ72i8KA3I/xbohzj3DuITa+CboPalcsOllhjEsYEdNwKRYl5CtFPVcZHJHdAWQriqs/17P1pnrmcikvnrJAtGz4Ql1m27z3szwwm3uMU2K13MXx1q3rfPH73+Sr33mff3R6gn3Dc3NwzPcqzN6NySPlwJpCOlgKwRX1AeaKeoOPbHHMaAA2wjU6nqWTxO1WZ2ndb1B6ylLmWUpvu49K0sbivOik92Uw6UlJSkVByYUAXq+gCkQu6akFXS4FDZ1rb085LuZuqCz26oKJlzrX1sxRNVJwoB4f5qBT0DE+jMtke1ZWcAWCC6RzZX9vQNApg/+fvTePkuyq7zw/9963xJIZuWfWvqgkFZLQghAIJMCYzWAMDZgGvM7xNuOl292e424fe47H7uk+3fbY7hnbjd3Gx+0NL2OwAZvdCAQtEIsktIOWklSqPffY4y33/uaP9yIyIjIyK6tUAmFcOnlKlRkZ+fLd++5v+f6+32+QTSk5gfn5KdZrVYxxrKzGvP9DZ9k9vcDbvueFWKnzm7/zUSDhnW95GQuz+/jYbXdybmWJUmGMp0+uMjfr8/3vuIKxokerXmLxbJMPfPgeas0GV105yeH9MxzYN8/7P/gU83MBb37jPhJrWF8v8l9+4yl+/qeupzR5hjNn4OFHTjJWXuGBh67kyiMNGvWYO+5cZGriaoqlEn/zvkVKJeHHf7zI8ppjemo3H/rYffi+5btfex2nT3u874NP43nCzHSFajXC84R3vu1yjl5ZptluEwSC1kK7Y1GS3Tdr10mTc3h+BeNNgyqClHLW/PCelRFbePNrNlR/RiRR4nqDLluTeL9RB/c/S79c8oB7AX90/+ElAtaBtQ4rZB85DUqTgZGqqJGZAvsmQtz0BGZ/hSvDMaqiefeXT/BrX3qK3374NDOdmDKGVBQkDpwQuA5BoYxtpKSJEDswgU9qBefA6W4Lpq+/qzb38qWvTBPZeE1XVMN1A0y/snB/aad03ura3MIa1dIZ/OgW+3nJPzBkJji2aUGpzYNp/fFRBtoIz3TLDLXpztc/25Sf9oHmffdI+tpsw3tu4/OyMajR1xxx/a0xJ/0O51mwkFyU0dVwrgHSQZHmylkuzwEc4iBJyrTbHjNTFVqdmFOL56g2ViiOtbj8Ck1YEN79xx9lvdbiy/cc5/Y7HuP662Y5dDjknvtXeM+ffYErr9jNq77jRl72khfxmTue4m8+eIwrrzyC4PPrv/MpTi/W+NEfvJHrr93H0cuPUCrMceJUm+MnW/h+iDhDahWLSzXqzYhdC2WuvHyaKw7v56orDnHkyAxXXlkiikL+4v33cG65wfxCmS/c9XU+9um7ia0mKKdMTR3ifR96hLHxSfww4COfOMNTTzW4+YVX8N2vvYliYYIv332GO+9aZK1qCQsenqdpdyxzcyFaxSBtrK2RxEvE0SmS+Bw2rSESnQffuxA96VFViGx0CET6jOhkKGPYaSP4Ylpclwp7+af+59kLtN5wEBInOFxOCtPZ4YDC1wpd0HiBIbKKK2fGOVvXnJwfY7oc0PRC3n38LA2q6MRyvRFmvCJR6vAaMUHRQ6kOBOO4yCIW0lThF0LiNKWAwimdZbWofH5fjcRrpM9yBKUyee4u7KX6q5iNz42cKBw1wXXe+z2qypALXj45zysvfhhDtkgC1ZZMkt63qc1X6/pB+D41ZelVsN2DpDu+mq+bCJs1n6QvrKgeqJsVKmkm/2EbONvI2lvSQasUUZKR8nAoJVjnKIRjiI1ZWavzn3/9fjxfYYzwutcc4F1vv5yX3Xw1n/l0yh/9xR14QYeX33qAt73lCMeeOM3HPrXMwvwUb3/bjbQaU+xZmOL9//BZbr/jSV79iiYPPNDikUfX+eV/9y/YNT/N6vo5CoUCuEnW1mOcs2jtEycOcbM0m5ZG02NuoUgQKlKXEoYe83NjrNfX2LvrBZRLIcWyx8xckZtfdJQPfuSL3Ptgle/4jlkevrdDEsN3vPw6Upo8ebzOz/zEW3jNq/ayvJzw/W+f5/EnztDpCFECvm8wHoTO58y5CKMEJCJNaiRmBaXCjEmjDcoUwZR2MAYMm/lYff1KyRIFrdTmB2cb7ET19z531Op67k1mffsVLnLxgaQ3WaM1WhRpYrE2RQSM0RQLHir0cM5hjOHFV85RmZrg4GzIvmt28StlxaOmSKPeJHAJ+2YN+3ePU/AMJsmIaGI8pB2hfI1ThtR5hMPKqmq0tlb/mGTv4OoFkX6eyKB9Ktu0WUXUDh6uC8Mb1IW+k2yhStUvcLyDhe0fqx0WR1YDzPbzNL5UP4eHDSUBNawWICPlZATykcQ+LTKVuwHm0iddfKRXmYjLhEFtlPuM1LGulQk12iTnlUiP8e0ZH5EYZSylUonXv+4GLj8yRa3WYO/ekOr6GNdcm/Cut76K3/r9v+Taa/bx7//NdyGk1JuOz37+Hm59yfP587/+PI8fa5ImAafOLBKGmkOH4StfaZMklv0HfBwJxWIZvBXidogAhUKBIJikE0UkSQ2UIk0dzRY0W3Dy9BJTkxUKxQJOhPVaB3GaJE2ot6rcfNMV3P75B/jEJ0/xypffzEc/eTfl0jhJKqzX2nzx7gd5/tWH+NqxB3js8VXGymXOLa+TuikWl1vMzykchiR1GC+ANEWsw6mIKKoCAUqHaDOG9uPBXqMaBaAPanGp4WGVYSLtBVQAA63gC/bvUReIlXwrtLj+aQZIb0CJKRekEwU4SxqnaDwUgs6NoY0xxHHMtDLcOB6w0kiYuGKKNxwZ401vDImeWqXQhlXTYHxMY1IBm8nnJRhccw1CjRiDqAAnGdFLKRk4/DfA8eGA0r+NdY7pbDwCm6uXDa+H8waWHS+4cHHhZzQuft5HRKktA4psYYI4gHFt0snaRqVzWAer70GWvjYGIkN4zob8Sb/HyOCPy1nrOVM8Q81Mlu26BCcRzraxtoG1LZyNEbG5Q2L3qjw8z+BUTBA6Wq0WV1+X8qpXGk6d1hgNq8t1inaJ6ZkjVCplFpdqVMoHSNMTBH6ZThTz6OOnmZgpE/geN75ghjd/z2uwVlFtPsXd9z9KHKfMzikanTMUCimxWqGTVBgvh5TLZTwzgaJNktQJAo/UOao1QemQQlggCEJQBmd91mttKuPjxEnEyprllpdcw/W37eeOLzzOmROTfOr2u3nFS1/E3r0Vao0VavUGt332qxw8bHnFy4+gMNx44yRXPa+CdRH1pkNrwfMyXS8SAQc2TRCaCAHKjKG9Bl4QgW83csZMPoDh3SHbtr5Gyc/LjouIi1fW/ufqZGeB6RJKLV1kK8QbJi53bUoDo1A+meCi2VjXpVioeB4TE5pkrcqytpwyAfW1DmdqTW7/2jmONy0HXJOf2z/PQsGn5Enm6CZCHAiu4xDl4XkBcZRVOFptIcLYF0yy0jqDdpzYDfVWpfpwvY1g0y9BPyC0pgaxwG1V59WodtPFNKtGl/4XtNj91+K2fvS3smHtv/7NLn9qUyAaCNo9vFz6/r2JgdAH9fcrkkley2x4goi4fPYXnLM4lyKuQ+paSHdiSyzibG8ddHdqWTsQn9TVst9Fe5xdstQbhvExy979AdXqHH/34TuZmZrAScrjx59EFSKMqlAqFbj5pqv5mZ+4hihuMzUd0mjWaHdiKmMh+/eNE4SGr963wq23lukkyygpM17xiBNHFAnOldg1N8Ujj5+j3e6QWsfERJFmw7AwP4Nzwtp6h1LJZ2ZqlvVqk917C0xPF5G4ztGjEzz8yBi33X4/aZJwzdVzLC6ts2dPyPTkOD/142/mZa8IqK63AUhck9W1VSYmyvh+iogjTlKUAitBriqcYl0L6zTGGycIG4hrA2keSPL7L5bhUVC1E1ykh7vLdjzHZ+HcvxjF3W8UwM9z9Nq+sVWQ119xqr7f0WSivxBkUSRabHPyvhP83P0rPHXfMQJJiVaWWPI94sBHWYvnHGkYkE5UOKw1rz97ALNrin0VwVMJGocLNKlyiNYoHRJ3Onie6Zn9yPCBOSQH3z/qK9IVulN9x5XKRftkRIunf/lVnx/8iD0x0sN7u62hzrvVZIAdfPF7coAdPzxNO1CbjXq2ZWRQGebJuAHhSvraWgwILm6YKklPFn0jh1U91n4/UctZB8pm3jPOgSSIi3EuAtchtZ3MZ0S6ZNDMSdMY0DbFicW5IHsPJRQL44grMj1VptUoEjPD33/oDr72+OO89z3/ls989lF+9df+kp/96RfzQ+94Izdce5iP3XYHt75kH69/zfOw0qDVbDExbikVxnne0QqHDk5yz72LvO1Nb6TZqVKvd4jjiOuu3ccjjy6xXk2YOjhLklqUVpTLPpMTHidPrWOdJQgMU1NFisWAlSCkXC5w/OlVFhb2Uq+d5Pu+7wgPPxzx7j98Py+9+SgvfFGROGmiTJ03fffN/O57/oqp6bdx4wv202g2OH6ixuREhbAQc+pMnXLZMD7mow00qyrztMdmGmTSxI8bpEnmJIlrbxAUeyuoB+WDti0ptkquBGQU8PhsH9rqOXpgf4u30Z4BS94bPHpk0HvUaCAlch6IwzjF2eoqp6snEL/E3HiR60qTHClPsE977PE0UyZlagLC3bPccHgPQUGBtAGNFZXN6RMgOkEIsC5CAOscxoGTTL9V1NBGUFuRaTb69oqNymWgvaJGVCX0qdQOt263OOVlh9t8JwskF/1mW9uOq22Sw+30XWVTl2Lz/eoFjp4Efxfg0WyM+KpcKbpPqblbo3SHKFzuw+4EkTivSjqINHCug3MJ9FUhxsvEC5M0pd1J6cSOIFQ02x2iKGZudpK7vrLM6kpKo9Hiysv30tApd331Md76puvYvTDBd778Rv7r7/0tf/jH9/CG73wtv/Cz7+A//daf8xfv+yxfe/RJgkDz1InTPP/qaX7wXTfyslv28ODXDnDX3Sf4f959G9PTmssO7eK6aw5SLoY88dQ5fvcPPsquhQmazXbmO6JrxPE042OWA/un+cz/vIe/+2DKv3jzFZw5d4YgUJSLIeWiT6eV8WV2L0zgnOXI4UkmJzSFwhjtVoFd8x4ilr9632f5yCdCPE8Dluuum+Pqqycol0IKgcKmGR9L5S3eLh8HlemU2bRGmqySJhWMNwGEoALAoLQeaFptX1KoPoHJoQO9X73wG3Zu7zSoPFeDyaW+rktk2PUM/phf/Q+/+qtqU087E7lDQypC5ATdiknWm3w29WmoMqYUsneyyK27Z3jrkXlecnCKa66c5fBNB5l50R5237KbOLAEnoDzQHmkkhI3I+L4IU6ePkvCMlEac/jQ69FeiFIGtN4IBBq6xKgsC9pwgusN4A7QeLuWpkMgutqoYjaZUA0xw9FbjUqOsiLeQeVwMUv/jAzt+ocN1Bb/ZjM9pzeWvBmsHxlKe+rIfSZKve/v/5wa2Fa4bEBCiQUXgWTCjOKqWFvL/NglzrxF0Pi+R+D7+IEiCDSttgUCymOwvjJNrV7nC196jFOnanzpK0+ye9c4i0srrKzVeOfbrkObDnv3ACpG6wQ/rHPTjRVuuG4fjUaH2z77MKtrDa44Msvhg5NAyr69ZaYmJnDW4yt3n+D+BxYJgxIvfsFhpqYLTE0WOHVmhSePL/LY40v87E++lpfePEkcR8zOOkKzh2q1Q5RWOXwoZHbyCE88/RTXXzfHwoJPEgtBGBOa/aQ24gfe+XwKxTrr9acJwyZXXa0YL5eoN1IeO3aOk6dXsWnKgf2T7FkoEwYKYzQ2ze9pkj+vbNhSGy/IPkyQCVoKGYFTPBAfpb0sAGlFv57BcCegJ49DNkShVP9e6ltjtfUIfU9K5Vnlk6gL+9ozvhZ5bgSAb3IA6f0mLj/tNnSO8h6qkmyTKUidQhKFrLdZOraKf+9p7m1F3Jmk3Lm8wqP1OszME05N8tor53jL9XPMOeHIrjJBGKAdaN8DFRGtV1mp/Sl33vk4bb6IJeWWm36NUmkqI5gpkye6BqN1fi1dJksmpw0a5xwu9+p2Oc16wwu7r3W0iUQ1GgPeGURxfh+CgdHHS7FZZOeBSqkdbNUdKItvGuyU0V/ZktCs+yNTF7bRGRlVHGLTzGdEGnkQqeNclSTuBpM2Jh++iCMhiQU/gDBUdOKUMAwplw1Li3MUSwWKxRLGWJrtBnOzRU6dWiaOY45ePsmJU+ukacrCQkCr2abZ9LBpkcnKBNYaGg3L9OQYVqo0Wss4YiYnAjxToN32QMbxzRj1xjrG7+CcxebSJMYI5dIYntE4tc7KWo3LDo1jOMzXHjmDCU9z9IppmrUDnDh1Es+PmJpSRFFCueyxsjQDqk2zvcrUpEKZlDh2WdLkpgi8GeI4wbkOABMTBfzAUqvXyXRPs/ubNHI7bEmwYkEbvKBCWJwlLM4RFnbh+/MYbxZt5tC6gtIKZTSSO0n2Kyb1eFVd6ZuuoyOKnSjTq2EFg2fKcN/xgXcBweQZBRL5BgXAb4UgIt0ko+/dXB5ExGYtC60zhqIDgiD7tlqM1CIkNEQkyFKLxcfO8LmTEe+9+1EebqV0jOKmcolf/9+uZf/+XRQmpiiHWZvMNeucXXsPX7jjFE35FF7gcf01/4Hx8VmKhSyQOAfGeBjdlfWzeYDJAknWInEbIK0MGjf1d8GGwfLhVo88qyDhJdw+Fx1Q1DZBRrb9Edt+VUZdYj8GpHtimqqro5ZKtsdcgnM1YB1x2Ye1DWzayqe2knxSUGXViOeRJClxkuEmVgTnDNoYjClhTInllSa75sepVhs0Wy2ef9UMx08sEUVtCgVFrRYTBD7FEoyVNKlVJLEmioQ4hsmJElOTRZIkpt5skySOJLGUSoZ2J8X3QowOCIOAIDDEcUoUZ9czNmZodap0oiaKccJgnGIpwngdkjjEWp9OO81k5lVCEDrqdY+oo/CDiLHxFM8EGB1Srbep12NCf4bQn2ZywiNK6kRxSrtt8TxHoQCepzDGoBS0ay2cWJAUKxbRGu0VCYJx/HACL5ghDHfj+XvxvD0YbwZtNMpkFYkoO9jS7CvVu4EkK9Y3B5Itp7G2DR7yLB56OwwmSj0Hgsg3IZhccuMwGcRIeje3OynVHZHxsn522kxIohTta8yYx5lGm4cWmxw/UeX4iSZPrsUsBeNMJR2mxHL1TAHtx3gmpaSkh96K1aALoGOcNbQjizJ+1ns3Wasq87R2uS1qX1exq9zbbyrTJ4cyyqF6+L65UbjB0Ejwc3LeYxsi8qiHecDDZcuhg9GjNzIiUKkduLd2vTMynKrbu88HIlz+08SBpCjJMu2sKulOFyWZfZTSWOtwgGcyp8I4sdSblmLBp1QM6EQOi8X3HL7v2DVfxOiUUhGKoc96tUEUJczNFllerrF3d5nJSpnl1QanTtcZK/lMVEpUyj5RnI1o1KuWRlNoNBWlosfkZIFqrcnuXWU6kdBqJjQaFtAUCoZSwSOKY1ZXGyhtCXyfTsfRiBokaZJZ7CpDGGpKRWi3Y7SnqFfB0wHze8o8cfw0M1M+61VHp51SKhbZtzBF4FVQFHnqxDnGxx1KW8olh7OCpBoroMTl62JynzfB5FJESiw27WT4o5DhI4xh9FTeD9P9D9bQBhtULVAjvWgu5FAeZfF8AcHlgjxQtnvttwtm8o0IIFuA7Rt9Dz20uRyioB2lLB9f5ROPrrP60Cm+uFjn6+0O9YKhMFHkxQsV/vXrjnDtkVkOHygxUSlg8ShikI5FUgdGcE6jvCKiY1zq02q1MF4BZTRKO1yaAbY9OQ0lfczqnUJrij4O3Yh7OTiBNLzvnq1bri71m8jW0KPSaigQqG0etUEnye4kVj8hbWBOYYR7ZM/kqucfY3B98sSq2zKVFCTOAPZ81FdcC1zcKxl1jqdZ67BB5q4ZFDTjKuNnBH5AHEc0GpZOq4PWCXMzYywtNygVFcWi4sTJNSbGA1ZX2sxMFYk6wolaE99TLExXAIgjwSYpIopGI6LVipmsVNi/a4Zmu8nSYpVKpcDycgejM3yuWDBo5RPFKa1mhyBUjJUCRBROLOMlH2M8nGisywYFXKpoNFugE4phmdVmQrFgaNY1oV9mbS2iEJSozJRJE2jUBKUikJTZ6QL1Rg0/iDEqySp26w9UCpmlMD1VAaMEJw7nImxiseLQqoRRk/heA/woe/R7C6b7vMakB2hJt9U1NIyitjA6u7BgcjEH4IUYXcn2weSixBvlWQ4mlziVlW+cZIy3eV300CI4WjYl9DWrizX++qkz3H3qFGPW8cIg5A0L07zp6D5mJwvo6YBk9wRRIWSlLcyG4FzWIggCg/I9dOooCrQpoFyCtULqwPMMWlKi1AKFXFNryAypO46qehQEBqF2takaGcXl2zTO+kwlfi5yG24Lxm9zASM19ob8W/qrBDUgYjk81jtYo2SSJWq4+derYLa3rumSSLuVickOow2BLZSyQIxIB3KxQefaOJcCWftSRGOMj9KWNE1otFJsavBNgTjW1OspnvEohiW0tmhtUZJgdIYvJLFjcjxk93yFar1F1Ikx2qPg+dQbMWNlH60ErYQkTtEKxooe46WATidmabkDylIMDQrB9zw8oxFRJInDuRStFYXQxzlH1HagfDzPR3sml//RJOmGde/4WMhatY21itAvM1WZod2G2amQyUnHydM16vUOoW8oFjxsmpDYCJt4hF6I1jFaxTgJcaIQKyRJilIKzwt7+yWz4nWIpKQ2zgYXbIJRY/heHeeaiLSBEBE/e2asQ2m9uW7vV8m+JEnzBQaTHUrfb+8geCkqk2+0htdFBhX55mmNeVugpX2L7ujYFOOH1KKYghWK+LRJuc9ZnjqzyPtOL1OKEgpJC6UMY5UxDpXH+amfvonyxDiJNnheBp6rwOAnljYlfJuAQJoKxngolWBTIR8y6Tm0aTXUqtpisGoTB3cEi12GItNWh/mzE1zUIJ4zUjF1+5bCdtt6lDXqgIS7yKZOwaDKc7/t7GDFtulaBgLKaBUCRPc82ZHMrVD1VyPSxrkY55KcoJgFH5RBK4cGjK8IAsFZj8rYJGJ9Fhc72VgwFuOlaJUCgu9B4Gk6HUuaKtbXY5wzICE4D6U8Op2U8bEiSjk8I3TarXycOCFJYsbHQqamQjqxohPFiAi+NhhjcC5zMYxjRxh4BKFPHFuss2iteix9EYdNIU0UgR9QLoYcP3WG/fvLeNqnMl7izNkOH/3UI7z4hfu5/vmzGF1g3x6fOI7odGLiNMZaR+CXGCsVSF2bxAkahTYeSZpibZb0eZ7JB1JUbpVr86m4XOZIWVKvmemYuQZOGijno1QRdDj0YKkBNZVhAfmLq0ZGBZPRycrFHYhyccFEdvJQf7OFIEdcvzz3xCm9TdfcNc/Og4mIT9Ez+KnmhXum+BXRnC76rK61Wam1ORZZjiUpTytNTRdoOYtrx7xYGrzh2BKHD2lKc0WMKeT3wBGlCXEKxnoZG7ermCvdHFojro9w2McU6Zkh0bP37lXoSm3eoiPBdcV55UlGMX13ItC4VRbRG1PeoTtjl0XeyzTVzrbc0PG+KRJueKqP2pN9wWN7SRDyAAAgAElEQVRI30j64ovSaoB02F21DUxGUC5fN5fzSlwKRDhpIraOSBuxMc663lorpTDaYIyPI8U6aDQgjhV7dk/x2TtO8tfvv5cTJ9c4fGiKd33v89m9MMZkJaQdxUxNhTx+bI2xcoGF+RJLy00846PwsVgmJxVHKhWcKBqNlNV65vGxtFxnfNwnDD1qtZST52rsmi9R9g1CShTHxJFhsjKOUhlmo7SP5xk836Naa1Is+XSihHorZmLcz2wTnKZQNIxVFPNpkdQ6Gg3LVGWMp0+f5WOfvpfSmOPlt06zst7h1NkOxYIwO+OTppo4Tjl3rk5civF8y+REhSjyqNWEYiGgUimSppY4NVlrDZfjJjrHTTyMAlEGhcu4JXadNFkEHNpMoMltHiQft1eZSym5grZWGbdrax7XeZJn2WFwEXeJsnh1iYLJc+CwHlKOeC7/8YYvPJPpdpm3hzEo5VEyWaJYuXE/L7lxP5Fk/BIRCIzGKGgljvXldU41HDULtOpcftU+wiTFS9sZ2G4UzqW0o4Q0cVjr96Snpasam7dGer7g0JMsVyPsdYa1proQz6hCWvrXZ6Bftinv2qYbqy5wL1wkin8BScioKa0tO8pq9OdlxD82w6MbLPieFE2Xzd4L5JKxfLRCuXw9XdZqca4Nto5IHbHtvBIBxM+wuFwg1PMMSZqxtGen59Fqgg995B7+7u+/zJHDc7zyZUepN6tMTRnGykXSJGTfvlmWVlY4cGAPznpU63WUp5mYnESrcc4sLlJvJ8zPFVldjfELRebGysRJwp79CyRJTJwkFMsBYVFTKHmcPLPKwlyBsFhg8VxMs20oFgJEJaytOeLUMD9XYmbGY2oqZG29ReN0jMXgBwFB4GP8mMhGzExP4cSwtHKS8YmTvPIVe2m2X8V3veYAZ5fP4YchM+UpqvUasVW0O+BsARMm7D1QoFb3qbc0RvuUKwatDBZoRjG+5zYwE63zyaps6jHTNzJopXOF4DWU8RAET0D5AUpVMtmT3qFqenZ8WTLTd6ApfWEbeWQ3a6gquaQZtlxcMOk9SPJNDhrfRED+kgSSrqS3lV4rIuMAmo0F19mhUcg3Q5qXB2IjDDBWKXFdkOKljs74NB5gnSV1ca63ArFLaccRiQXrfJwkuX+IIEpvKNh2s11xuSlWz4R342sjcpH++NDflpGhto6MAF/k/Lj2jqA+kRFM+IvdA/3jlnK+Pai2bcNJX5Gx1e8mfRFnoK5RQ/doINh3WyrZtF1v4EFpFJbM1SbDRZw0M68R18pY2BgUPhmXQUgSwVqLF4B2ijQp8OWvnOM3f/vjXHv1Pv7PX3grQWB59NjTHNxfwomhGAY8+OhTPPT1k1x5ZD+FsMR4xTE/X8bZTErkoWNNvv5EncBfRWvDVc+bouBrHn+6yspKQjH0ueLyCrOzJdbXWiytd+jEin/87HFmpkM8XeKVLz/IerWJT8DV1y1z8mTMBz72NcbHKizMlViYL7Fn7wRJYllaSnAWHvzaCerNNnOzRV52yxxXXL6HKF2knZ5GEM4ttZmYGGPvnknE+TTadT7xmWNMVsrs3zfJZYcXePpUkyNH5jm3uMYDD50jTQOcSykUFS+6cR+tWkQUSY5HOUQ0SnloZVCislFfpTPw3VYzkUelUMpH6xJGlXN+1iC21lMKzqf2NojLMtTKPM9Z9w0/ny8imPQ/SN8IIy75p+Wd4o1ab5Esq+yl/ArA773OCtQSRzO2GNshkCYFL2TcK6Eni2ijCZxA7EiUJdIuy1ABK5bEplgLzmXTLVmY6Or/5JksWX/d9Y6qjfDRlTbveYd3r31IPmsAVFaqN+Uiw3jJFgfwTqC8nQDnzySRkP7SWw1ODKhtfoiMLDtki2vP7+0o7ma/A6LawEJEDZEOVa7gnP8chWQTWirjD4lEiLRw3SktiaFnmRbkr0mxTkhSS1BQaK2JOh6f+vRDdDopP/pDrwMMcRJjreAHRZq1af7oLx/kd97ztxw6OEuaPMEN117Fv/7p15DEMeurZX7jtz7HAw9/HVRKq5WyMDfHgX0RURzz2LETtFptwPH8a/bzY//La9m/5zL+6M8+yUc+fhegKBWL+L7HfffDv/ze5zE3p7jzrnN88uMpn7jtAYz20BoOH1zgl37+bezdM8V7/sfH+cfPfJU4bnPw4CSnTjX4+w/v5+d+8gd43rVlvvClx/jzv3qQavVa3vLmQ9SrC/zir3yAz3/5Po5esZd6PaJUKvJ7/+8Ps3tfnVZznv/0a3fyuc/fw1VH99FoRFTGx7jt001++scv69aBdFUflDIZnqI1Spv8mUlJ0xpOJXmgKWPMFEZiRIqbZjdU/kAp1Ze6qaENeNHZ0rMdXZ4B0P5sBRT5p2u8pYfXVmuVEQF1nr46t0lBQSuYDDR7xwy7J4pMT0xTHqvgFzTGczmBUCFaYUKPQmljk2qt8XyDaEjEIa6AVjYPEFnpofL/Mq8KcE7yD9WLbSKjq5LhA7JnxSujX7eBwWT/dV3+pO/DyejP93+cL4jIeT/UyI/Nb7bh3CgDH1s4L6pBPKT/YyPIZv9wbujrMjwokAtk5jpNXU/IzCQgl9KQfFLJZdWqch2ca+YWup3c9TAClfZaJpkVbP6hM1vYjJhqKBbLtDoxM1MVLrtsjhNnzrJeX+PI5eOk1nLiVJU/eu9H+Zkfezvvfc//wU/++Ov44l0P8p9/4wMsra5y+dGQu+/9Gi+84Vre91f/ij//H/+OF9xwlL/90KdQWvPf/usv8L6/+HVueelVfPqzD/Dk8RW0L3zprmMcOXyYT//DH/I3f/JfuPGGQ/z5//dpPvWZUzQ6bZrNaW649no+/8nf4zMf/b/56Z/4Xr56/1P84+0P0erEnF1cAYR3/+Yv8qd/8HP84s+/iceePMlH/vErJC5Be4pHj52g2bIYv8RjT57hxJkz/OSPvZk/+e+/wA9+/8t4/Mmn+fDHH6RWb3Fm+Tj33PsIr3rFrfzVn/wSf/qHv8AtL72av/nAbZw918R4Hg6DMV4mhaKytrTSPkp5eTVqM3FM28rJn03EZk6UkGyOB2pj52rV3/rp/3B9ieBz7aCUC/z8iIP/mR7+ww/cP/lA0ucBorpkxN4+UmBlY24diDqW9WqVRjXGNhW4LPPs2Ii1VoO1Vou2s+jARwfhRglkDIWiD0aTYHHOx+AwakOXR/XVH/1Bw+WjqbkiSs4z2Zg0kv4WzjbbR0ZgJsNrvdVjITt8ZOS8r92Zfpfs6L22f/1W39utPkW2+NpAUNu45g3rdZe3pFzeAskCidju2F1OOnRNcC0UGecDLEq5vCKRXitFa52D7QbP+IBHqxXz1PFTaKPxPOHA/nGKJThxap31WsTTp06wZ88EP/iD1zEx3eRd33eId7z11Tx9YpnxCjz0yP2MlcucObuOZZXxccV3vfZFTEyWmJ1P8Mtfp1B5gpe9YoY0Fb785VPgDuH7Ibv3jtPhccZmlnjn913O5ESF227/OqvVDje/+EZeesthVuorPHnyHE40jUab+x88TieJObe0xnq1zrXXXgb+WV7wwnlq1ZhP3X4PURKxe884xhj27llgdnaOD3z4SzRbTd78pkN03EN8z5vH+LEffiO33f4ASsWUyi0CP8OSYh6gUFrmda++joP75zh9ro7nByhlUNrLWlzKoHQ2ASfofG0kw6rSJDMNcx1EWog0UbSBeAT+pnryc0pttdvcUEC5kKpcjXiBYuf6dud7Mp5hMLnYgPKsBI/nbjDyNpUaojfrhjiwqcPGFtVKcK2Y+lyRtFHDjU0CDq8aExZCQnxCr4l4PtoEeS/M9iaQDIrQ98DziPFwKsbDR2vdA74UugeId/9TTtC6OxK80a93Msg1GeCRDLWd1BZBZLuq9nyzIDsDzLe20N2u0N7gwIwmFF5MQ6F/HFjEDd4rNbrtoPpF+RS96S/pTviROWBmrRAvo7E62wPYxTVAmnk1kqB1rnSg+/W4VA8FU6o7xWUolXwOHljg4UeeQKsQ3yuyXo2ZnS6zZ88Mv/Ifb2dutsL4RMBDDx/nqquLzM5MUW806XRa7FooZ+/nHEmcIrJI4O0BgVKpiO8HrKy02bUwh00s7U5EWIxpdVoEgUb7lpNnVzlwaJq9e/ZSrdUxZgZlhKdOPcrvvvszfO3hM1x/3RF8P2RyYgptPDzfMDc/Qb0Z4ZXg7NIavldg7+49tDoBzVYdazNfnmZLYZ1iz+45UgdB6FOpVCiEMSdOLhKnbQLfp95oMT87zdLyMuWix9TkDCJCvZFmRlpAFMVZe0syjGoDWVT5II2ASvOJuTbOtnCugRYfJfkEV+9YkI2WpxrZBB9xiF8IKDyK8f5MWmEXg41cJE9DqW+79tXOA0kvGRjMBkQEmya4ToIXW9xai1+7e5G//MxdPM8aXh8W2RvAK7/jeYztn0ZmDYVxKBQsziiss70DJ7M48RCtiZ1B0ULjY1Q2aqn71qkfGRnl1za8HUZObfVLiQ1BBcPtrmETqAvBS7b7qsj2wWer994pl0V29AzIgKz+yIGAYa0ltSnC0G08Zn14yYPRBlIlTmWdLucQG2egere1RQzkLa2+qJ+xI+hb66yv73uGWr2B5ynW1uvUG5bp6QorK8tMThaxaZmF+SmeOr5EEJAB9NojLIRorYnThMnJMcIgZLwyRqlcYGV1kWZrLqtwjE+xUCbwDU89VcV4WQAwQUaQTF1CYlu0Ok0WghnSVNFsNSgW57jjjpP8/n//NK959U38+//9RqyscffdT6GMjxcYwoLH7OwE55YXmV5w7Nk7QRCE1JsNxscnObe4jjEalKbVFkrFEoVim3J5nCeeeJrnXTWPsx5RFCMk+EGRcqlEtV5jbLxE3IlwJFhniWKL53kYA81mRBh4vTFeoYuP6N7DIQLOZlL2mRtlDWW8DE8RPwfet/AnGAgieVtUuoB8v232JcYXLgSvkAsNMhcBZH6bBoydYSTDPc8+jMAr+JixAMopzUKL64KIN0yUqMYdfuvMCf7V4llu+PQ9/If7nmS11SGxHWqdVaQdY02ZVjsnHVpH1HEQW7RNSVOflnLE3axbgTIq75PLZmigd8apgTLY9YKDGggcwxWIk20wFYYxgc0l9gZ2sX35LWzGIuQ8Paj+4YFRLPheG2qHVXP/67tTVAyw3PuvXdP1Exn4fZXKdoRsDjS9cW2VZ8BdH/YebhIBbaCRycVLknGAnEbEIJKNpqr8PejKrKjsNX4QoDXcdOPlOCf87d//T9ZqNV5wwyGUgkYjYu/eWZZX6xx7cpED+ycoFKZZr65RLIYUQp/F5SrawPp6leWVVbQus3fvOMZoGs02yoC1ljSNcM4Rhj42dYyPFykVQ4rFApcfmeW+e9d4+uQJDh3cTalY4CMf+zwrq2u88x23cPXV88zOzFJv1mm1GjiJqdVarK7WKVcSwtDgmRCtFalNQEUYXc5/bsz8fIVGs8Xp00tAyKEDhwj8Io1Wi6uOXsZEJcRKh0IxQJscTNeOxaUVPE+TphZRkhV5xlAsFQjDEN/30SYLJt0xYEUAeDgRrItI0hpxskqarmPTBuKSoXbT8P6WbVq0DDqYXYrgMUCAfDal33faEP5m/vlWGP/t3kxxG9mlqEwzKAfdTMFAOMHkRIW3H4p40y3znHyywf2PrPL50zX+/oHjvPfjD/IPn3iIF02M8+rdM3zPWJHiNQukkw5uPoLDo1132Haau92FtGxC5Byh6ZLdJLdWzb0rerhfRprq+cp3Lzk/GF03GMlmoHtzxj26WpbzVCbb5TGyk6RoJ3tdbf3I9re5tg4mQ1fXZ+y12c1xxMCCDAmjKLURhAW07tZ2pjf0pnpSKDZnqUeIdFC0UaqNqBhxac53MDkwr3JVZ4XgNoinufCg7wU453j+Nfs4dGieRx47weLSMvv2lWi2WuzePcGLXng5H/7oXTzw4Cle85pDPHGsxW2f+1JGIkxg33QBaxMqM5PMzYc0alMsry6RplmLzfeFKHI4iZmaqjAzU8E6xdRkhTAMqddSJiYVd975NFHc4ejR/ayvV0Es8/PjlEqW1bVTrK1CqRRQKCqMiVEKksQyO5tgfI/FczGr6yuEBY3ndZioTGE8DSoFlXD99Ye4595j3PPVJ/mu117Pgw8/yBe+dA9XXrGf6ZkSx55YodVq0W610cqjXA6AhOWVKsbPxuyttXi+oVgKSVPJ/EoSyW0WDEoFiKS9EXtrY0TXkUSBNgSqgHIT6K49pmIoiGzlu6kGlQ92PAZ8MdNRO2hxKbXNw3Ex1dI/uy1eWCDpSllgc/6IwQpYl01tOAdRbOlEKVMTBVABB+dLFKsh/kpEWxK+2KiyHI7xj2sxn5KU985Osu9kke9XY7y2FeGqLaIWVFspWEOhbIhji0bwNURK5WY7aiMhkf7kJO+hW8eGz3gfwak3mjpoHfxMMKut9d1U3+HrRj8UchH50XmCVzdwDvvcy6Ye7ijC13bWqhvkzH7gpPe+uq812BuO2MhEhUycUVycmVblFYmijZO4p+Ml4iGSqfxKDrKTT/opLChFkmYTYXv2TnLwYJkfeNfL+PydD/Mn772d9/61YmKizDvedgs33XiEo1fs5ROfeoA7v/x1Am+MwPf5kR9+FVdduYtTpxOElMqExqUhzXrEucVVdu2axHiKxcUq01PjRJ1Mmt3ZiOp6nTNnVllcWidJO5w8uYRWJd78xlt53WtuYM+ecd76lhfxF3/5OX7pl/+YmekSxcIke/fOMDMTsrq6wuxsicD3OXN2Fc9LOXV6jcmJMvv2zrG0tM7SUsr+fXMsLq1hbczLbr2MD3/0i/y3P/gAd997P61WQqFgePv33kirXWNlWaM1TM8GKFUmjh2e75iZKbNr1zhowYrDeIYodtkEnss5PrnmkFYaUV5WvSBYF2OTFCcp6BCjKxg/HtLQ6Y7nM2Kv9ZlWDe+nbUURLwblk2eAnVyidtY/VyJbX+GAH4lYkCT72xicGBKrNzL9tiVptlk+t8baKnzqM49xx8lFvlpdoyOCLZVZmCzw9luv4/q0xaNph9tXHPe1hF++Yop3vnQ3hSThRPNv+O1PPIlT97BrTvOyq/4tz798D9NlTa1lsGo8a7Yol/uNuEzLqEuyUjozGHI2s+bNrVm7BLntbAeGx1pli4dAbecStRPwQrZ+AOR8+2XEua92utXUTvwYhsiGfZXawHboydZIZoSUcwdUr7XYbUECVtDiyAhCHXBrIMvglnBuPTMiSxXOGhDTw1q01nlAdCjjcqtYQakQkYDUGqJI2LVQ4dSZZZaWqzQabUBxzVUHqdcd+/YscNdXHyROWjhbYrIyx0teOkNsl1hfLfLA/WsEhYjnXzeFTX2cDfnKXY9w5Mg0lYphcrLI6VOKL37xBFdfdZDnHd3Nj/yvv4V1jh/54VfSbLW44bqr2LOwl9Q1qdaWmJ4qsl5tsbi0wr33H2fPrgXCoMTRoxX27td8+tNPE3U8brppjiRpMz6RcPcXJygWShw++gQumecLn1/l6qt3s3u3T5IkRFFEkra466tPMDu1l8MHDxMWq8zOx9hols997izzCx679uRZoAm484tPsG/vGPv2TRG1k4zxbskmuHIullJZtajVxoi7VQkOi8OiPY9CYRfFwkGKxcsIwn2gQjZE7tzA7h3VGlWjavNRTFq5VIZSsn1wuGAMQ12iw/yZKgp/q1U+XT+STYSiPO3E0CUIOslKF10yBMqn0Sjw0btO8fsnThM36xgcLy1WeOPCLFfumeCFV0xTDmeoK8Urz3Y4dm6dm3aPEwYOEaEQGIJCSDvStNoRxs/AQecczoLT2TSRNtuemButrXzfaDVaqVRGBgY15LyxAykT2cFhLaMvWLbJmmQ4YIywjBe1/Xbr18dSqh/n2UaBS40evezJyKPzlhPofOZXDYj7mb4zIyMUIjG4dsZNsBG4NMdFJO+aSm98uN/RMsNZNqYhrJNsSEMEzyg8zzE/W2KiYvL11EyMFwm8BIi46ugClYqhXjPEkc/i4iqnzy4yWVngBdfvI7FVbJSQ5PpeRy6bYWoipFqvU622GC/P8ervfB6eMdRraxgDlx3exStffjWtVgtnfRQR9do66+s1At9RCDUH90+yb0+ZsfIESgVYW+fcmSrPv2oBRYHAi2m1Ynw9xs037aXVbhMnPgXf8OIXHaRU1CgSFhdXmZ0ps2/fFPXGPMWgQjG0tKM2xx6vsWt2nBfftB9lWkRxLWtXactlh6cJQ0Wa2F472LkB1+OBQzbD/TJuWKZC4MBZXNrll9SwporxxzPpGuUPQamS41+D2Ij0jXFvjUIyQo/nQg/7rQSQLhV+oi5xAHq2vv85YPXbN87n9dDn3s7z8kkMlbWUYodKBVXU4BytxBElwhVHp/nRfbdyZKbIS/aUGC97+L7BbzlM4mCuSKg0N19jeGkzyZwWZY1EGQoYiqWAJFW0mylBmIncpdZlCS0OrRTO9QNefW2Urs+66uO7qw0MQOcZWP/x3TtQRe9wmWQoy9piDc8jwrhVALmQ6fbzTWqpob6wyCgzKrVFW6vv774H3PUD/PnhbvKEUnWVibvmVS5LELAxStqINMG2wWbgurM6+7rrZq7Ss2Ptyqz3/3xBsFawNqVUCimVQlqtJnGcqQRLJimVW856tNs1nI1ZXk4ol8aZqBTpRIaFuYksKNkWRoM4B1YhNmZuuoTnC4oicZJSKgjFgiaKYmr1FgpHmsRoUibGQ449uUyaxChids2VM+M1hCROcGJZW11DnCGxHaztcGB/hXotJe7EBB6cOZXi7EkKhYSwUCKOEjQdWq0UVMqu+XHanZgTxztccXgXnY6h3W7jac1YqUAnalAINGITjM7uv7OWhbky7U6MTR2+yTArk7d/Va/1279x3IYEat5eVAJK0sydMq1iTQGUxXiVzON9oMrvV83ePCYufQoJwgazVSm1RVBQvcTg2Tswny085JtVPcg35n0uALvypOd3rocmJLLs0zhBUodzko0hlgMWfJ9XzIT8yysL2HZMioPIEDeFyu4yrZNrfOy+VV5//UymRlow4DRiSygSQh+Usfi+QyIfpWzeWxds6rKpH531hNWIX9w52bLYVf2VhjCkdNuTHrx0m+ESBZDt3vx8qr7SV8r3jzx3PV36Y53uiu6poYxyQGlZI+LyWiQ7fBxdXeaNG6tkg/wsLs0AdtuCrpaWTQbUfbMLdOj8G7Mg0iUyMijYqQSjhajTIY4zz3JjdCbD0r0GlyIqxdnstQi0Wg2ajSbg8DyVcSZcO9sVAloyTS+xQpRk/2+Aeq1GrVqnWAgZLxsuOzzDRKVE4FlWVpqUQwj8mDSNSeI0ez8vu87QU1idScKYFBLlUV1rsLbWIQwV4xUfFSggwXg242s4i+fFWXDL7aQDDxrNlDNnanjGwxgDYkkt4CWI10RwWGt7C6q1xvd0ThaW7hBdT023O3wibLQpuxI2mbpvPm4tKbgWzq6Tphqlc5kVFQD+oEpul6Ss+jhaXWXp7udUfx9ZhroCg0Gkv3JWW1pxyg6qkm9kMPkWB98vsfyLlxHHFJ7Ks/Uh5yINGCfEVohsh7ijkDu+xh8uNilVJnnDRIHDhyfw4xZmuc3TYcrffvJh/qwNe37oBmYPTrN3bwXta/BLKNXCSwUnCZ6fQuKjJMk3eq726/KN7gar6q35GAMuJH1ajF0vjOFumGzr9/FMZzW2ZMSPwE1kAGDf3GfeCW+k/yVONuayupmn9B8o+QPdlW0f9VDIputTm5SXN0aWc3KhpODinMXezHGSNIPdnOkFkSwQZGPmWRY6DMpmh6LuitAqQemMEJsmaW9tMxb8Rs8+TgRnoRB6hCUPaw1pAmlqSV2S+eEY3XOQjqOINHFZFe0bTJgd0DZt00zgF/7Nq1ivRiwtrtKJLOWSj28SnE1JkgRUtj+NUSQ2bxchGK3xAh+bpFTGMpl5gweezUZ/XV6BSUoaJ7nasYdLLRoYK4U450jTFJvGkFsP4yztTgPQPbMypSCJHdp0yYd9Gy2vyruvy+Rv+gRZ8z2hxPSqSmc7OFvFWUhTA6qANuNs6OztrP0z6GUiveStVyXnwngiF/uEPZMAIpsxU85/Fny7B4rzBpIsudxiDM9knu2Jyhjt9aUq/9fJBvc9vMLXY0VhZYkPKqHxWIE541NMNWdaVU6ur1IIJ5CiYaKUZ1bdsCQW69J8Z+tsLBQ/k3XQ/eNZgwdbN7vWfWzvri+J600xDZETVV/LRw2xy1XfATsCbL/wYCJDwWJrbGTLtpZsJ6eqtgksmysVN5TNZbdA9wUTGRiTl959dRu4Uo9fQk4ilJ7wgXNZxZqpjVtwWSBRxGTTWmlWfWiNEz87rJTNA4NkEh7k/gS58mwX3Fc6P3z0hgSHNpruWamVGiieRRyegFWQOsF1MptYcRptPPwg23u6py6d6bYpI1gHpLp3n4xWmLxq8z1DmkrPi945Qavs4O9l/6hcqkzlQHZWVSVW8uNO42wuO4TGufxDPFAWJ4ok7VNmEJ1VIJgcQ8o0yLQWtBaszYzg6N0DRZCDia6nDZRJFnXbj9KjjHaxL5evb7amuGxSUlxKatvZOLAqYXQ7F97sb33ncvV9E5Qjd6NI33GvNo/V9xII2SEIv1Xw2HlQ2U4TT/rOiPMbe6tvu0Bx3kCSZafbXG9gSNqWqGVZX27z5JMtak+cphB1EEk56xyr5TFO+z7K94mVISmWuGX3ODIeEJbDvjVxiE1J8p6usxohxuFnh4my2XSQ0n0Oh9Jruai+A06GDtFBUF2xyWd8KIhsjhmD3vDD37Mtvi6jwRLZabUyTPsYAL4Hr2+zSoMaqkZGPTwbQaiLd4i4vM21cREZFzEfdOgSDV32t1Iub3fkoVErXCoo59AuBUlQOXdE56KMorKWqc7vuUKBdnmA0L3DtQsCqz7ZAWHFDEYAACAASURBVNXrtLrBW6vUkJVyX+WWOqxzpM72AGfjGfwgs/B1snFIGD/z3EhSR5w4PM/LCHz5LWm2UlKb7S/P0zgnpGk2DeV5ZsCmWfJgJmTiotKdlEKwLpM/0Vqjtd+7p9kUXDbI4tLBM1HQaK0yKRmygGBM9jum1pE6N5BreaHpE9zs16zTG1L/krUss4Zl3v5VG/fUOofYbFRaKZe7KbZwto32xvIFGWxl9Thb/bpCSiFi86CoRh7zg/jKkLL1KB9puVDg/SLbyfmD/pwbDv4WqJa8AbmjUSemgkLZQ5kCBw4u8KOLizxZrPBoCkvK8sJChSvn58CmtCQmqhQpHZjmliPzXDZRJkAhqUOMwroU5RWpV1vEUYJg0RIg2Hw/m17bopdDifQeWp3LMWzabKqP/9DDBfr9R2RE62hES0e2FpyTHe/K4WkwtSViIrKzja+Grm+YkKjU0NjuiGqliy2pPlDeieu7J1lw6R4W3YkslTOi6Qo0SoZhKcnMqrSzONtBS6anpVQLaOXZrs7aIkr3VAvIW1uZaCO9Q8/RZ5glG71+nWNlTlzW+nSDbH1yCRC0YDyFcrmMl+SYjumqtdnersgkWBTGzyRVugBxRrS0iMsCpu9nUIPW/YlGTpTtV5XuZtbKbqxAV4okx4e0/v/Ze7cYTdLzvu/3vG9Vfcc+T8/MzmnPu1wetCRFmTJlyrYkOrZCGXaCGI4dw4iRxAgQxIgvAiMXQS4SJDASJFFyk4vAgWEbPgmwbMuWKYoyLUuiSJFLcrnLXe3uzOycZ7p7+vQdq+p9n1y8VfXVd+rp2V1SNKUGemd2uvvr+urwnP7/5/8vWYgCtlRt8IGpaCYeoGGsy4SMUFX94evWGOJ4vjsNeUuq7mnirClT19gC3k1L1EiBHYlmiM9RN0TzBI1X8f4Ao22QsByqmsw/RzqDUpZ+NqKVWCRykrvPsvVemckTJyWMxV/Tx0wsUjvWxT2J/EHyWHCNoqpSrM29Z89VEhv8SGh1V/gLn1tF/sxLHOU9+tmY9UaTVtStvjcdjMkPhzQ2OtgkAq+4zJPn0EvHrLVbDPspee7AetBGoI2Wk9SqqimqZB9YXOE4bShgT9CJmlR1i7Sr9IRZ6CmXp+TkL5/mxn1sIdHZx6XWwoT5dy2JLKD+ytSIcFqcPkyytDKmqnYGShXmMjgZU0iRlx1i8F/3bgR5kEEx9BDpIwyKiVRczOljJtI7eTE+C3tBUxVqJftfdJPF75aCduxV8c7jvFYVt8gEaxHxWOOx1RkLgd3lrpZQgzBpwFhMkOMpyQXeB49z7wuwX6rOSLWUxilAazGTIC0T3CYcD5VKdficKDUIYEyBVYjiRfHiCwtpX3QhdZdVLWx7pfgdQjJHcMqLvGCKgswUeJSp8AmxWuzohI6wqq+kpKekRUc5Dn5AvoHLdjGmBZIgdIGkEHW0M5vss6PxQhBUJnptJbNQ5yx1leUb84uSyUnJQ5aQVE5KIDozip6G7b6vO+3/DuM00dxFmGheoECWK73emM31JrvXDjnoDXjm6S2aSYPBYJ9jlzFs5Axch1yFhkY0uy3uXT3k0nOrgX0SBVm+ljpcNqDRaoANVWigtJcCGdR0rGpqN0WX4b0PHtOm2EvQidd7wE/kxNtyUVX/6CrjtD7VOu0euKALWZRATkJjTl7KlzlRyqWd1gltPPgwRy8wkIkAn6v20UrvdQwYE2MIoxQvHqcOl+cYdUTGYIkwNALTy4N6VwWPENdMEehMADXEg8knzK3yPHhDucukampBWYKLp4TuQaiPeUrVaJkLD5O4LMF3XQy+7JQI45iQTFyRSARfiUv6WgKZ9DW1oWHo3IqxW6kTFxqJQBOWEiavAqsE808voQqeEVGbLeDrPzd/T7tijCTVeagWEWvWuBJNKvuAL9bp9QYjCcZGRRI0+GxIrnuYPKLV7hA3V5iX55seayE1bbepMbLOmcgt70jej4LwoqnAYtXtxZzP2bGpfH+Syb/jYH90YiGuSmIgHaYceOG//XtvYMxD/utPfZhv3j/m//vV38aNDQ0nHI/7OGtpqmEzgrWkw1/7G3+cDz21RbtrETwNcYyO+rQ6bayNyAu2i1dfjC6mb1It574+OCxWKLougrlrHYdMt9u64OacdLCCyHsdqi75dpmXFNITOxdd+AAtX7dahuXo1IOu+ghAsjR2ofCaMRpGVsUBezxojsECMepjImOJrMX5nFwdmR+S5QcY38fLgEgyDA7VFK+O3LlC+r8MaCXrKAmJwozC58zWpWAxplAyKEKx+nDtw0gudDdoPrGXxaIaQHat9lUm57UMcDIz4w8Av0fJK2mRYPI2uXYeV8z+XeVnPr1YZyamXhis0WDyZopkZ3Sy6qPF3E4N6m0Bkpe+LiXBofRsMRXpeumHyWoy/xPZeGoYiRiZJilIuOalWVuYjAneGSAiy4/JzYjMH4E54ozZIG6cnS6cdDwhTMzhG3XZoklxOqHn6ylj6WxXIkuGv8qCku6USWT2t03ul+95fP8hYYtFcxesBp6JV7DCmbU2r1894lrW48qaEuX3efNen2uHPQZxm0gdLXI6Wcquh5ve8rGVFpGJiPDgDNgEazsYm6Pehc1lNSgZXs3EhbDwHZmwr8IOA6qY2nLcbHU+wUhm2RcnsziCSOSCa6vvDbTTRwDpVWU7+xMycyvP3v31/Z4l72WaRKAnJB2dxMG6nXK5xKkBdAdX4FKCU4tqjDiDuhGiD8DdRQYRZnCA0YzIlDYAUXh9l6FecDphCQnh+mJ2wPSBDviVMrPV8CzFkxdum5PsrH7GVzI2YKOq2ygFIGfrzIqxpNMrEdUt4yLQJkoGkgWbZz+Ns4UfsZNQVO5JVAnQV6Cx84HMVtknTCl3aIE3uWLUB+pLH5AcMaOwCKgxYhzI+ETGh9YTjUzYihVrsSoWgp2D+uLgSgsAr0VXo2GbnQTiHInB6Rom7pB13iJrPEUcxSGBmyGOMREtoEVJqdNZpQzVKYynjqFM5FZ0CseZA+LfS2eyRLhx2fM5VXAsmWD/gWzjiR3JEolmX5RiDqJWxIfPJPzzv/4Z+o0m297xFz824M99+iJ2+yyD/JgLT6yy3U3oj5V+HwaDfZ59chNjDDoaIa04UArjEVmekXtProZI01BB1lrt8uL6ch7vJ7TTRTV8fdehfsG9TipHMbJg4DMjIVJnbT0mVX02UE90qmZroCWVky6+bWUBEUBro4BlgwI9oQCqHp5aNtGp1kkrZpeTPBhWGYC42MsYI/4Aya7hx0Nc9muhMBBTLLhpoYWW450vql5XA6QVtFnM3D1istpVpAg+E9e9eqrX2S5gGCptKlJGDedZlnDnEnAI+FKpfNri9agFuwleVGfTaTGOCvToacvZQA6YAPPlGyjxkYnaghTnpehI1CIF8C+VOdUJpJCah5CYSWdS/Z3Q8fjchSLOuQI419CBoeDTQmevgdBEoxEkHidr2PhZ4uYFmvFnMQ3F0EfjFGdc0TUmM/jI4uVDWeCGeLqC/DRdyeJkol5PhVUuVfn+XnYlP0S7K9FSSNfI1HKi71iMVVaNwz8c8QvXjmjeGvIX4hFPXe7Q6DQ59Abpjdg8GtM1Wdgf8YH7br1SSjN5V8K6hRSH97UH1lSz+mlRX62AXmqO4VOBuviRMoFIbaYURjfm5GpnmV3iY3Ump0kgp+lvJtXR8k5EF4hO6syi16IRgkweyGIjPJwardGsDV4teW7xTlhtC51GyjB3DMaGhm6RRGNyMWRqIcsxQd+mUpEur3GwQw5Yg0gVikNlK6AVQ2xS5Ycq2yOV2tfkbJTMK5CwN+Jmz5JZco0nrKJJAikzqy2A7vq2f9mwLfbcCB2L1Eb/prZwOfG4n4Y/JkkvHEMWzsMUTuCKpFYmVDnxlrQcVoFpkkjK3RWqRKLeFW6lviAymGApJgbVDurWUB2COUJ0HCYJmhCR0bA7tBsW10g4JKEbGSIXJPCdpqFzrPxl7AwOKaeGHB9JelE5eVw7l0z4wXOolQ9KuPIHqiPRxRnemunHrxmjaQrHIw73hly9c8i5qw/J7+YcP9vEbrTodJqM9occj3LcimP9+WLfyYNmHhUfGDTlGKs6sVoxeRaGSqnbveqUOZPXWns81ZbqglmpL5g+i9keelL5/qgeRJdNYU9OICcLCevJx7cUUVmeQGRmWUWMmVTU1bn1KFFw6EvBeWFTwGofdWMeDo9oZBFt0+Po6AYHD3+DfOhCQZtLIQgYapEoDtvfExxdH6m1J3P/nbdG9sV5iiwVHfbxHrJFVT3TI6glBmLV3aPz7qtTIzM/fcxzZme6+D6QGY/0Re+u/v2pndbfrPaFCjMzLQ4mYI7l9VEiawuYVNBoDy95MdJLwDuMg9yBVU/uH5Dn75LKFsasYaNmId3YYKwjrHc0TFKT3jGnSB7vZeFvVnn4FAF2ye1x4uP9B5jIe+hIZFEQ8rXrIKTBbZt2LMhaQjRM+dLDY37LHbJz74hOM6HT6jL0hrjR5OPtFn/tpR4XGjHtqtsOc1r1PixiSfical+rgDZTj9f+nZoqVP1PCvG3CcVQZxQ4ilm5znYmJ5mGPB4ysvxveuqXnYdHTrlsdYLkhMwpjNWrV0JFiQmaWSiRJJioQ6pjnB8RxUISG6y7gHfXyFRxucUwIpIV4mZK1K60OAK2AuROcE6WKPDXNL90Vql2+h3O9pFRIXGQ52P6x37yNZmmPM8G5UWhatn3lLL6U3N0rTOTZhLAzOtNWTnX8Hk/a/W8pAaYPa5l94wpBwslNmhq53Ums1WjOAQnFkwUnhlPQVQoR7tRWHyRFPH77N7dhtEIt9Jn3M55ViLi5nkgJXcOI9Gk0FNXUxA/TQdyyrZBT4uRCMvA/BOgx1PG/feIlvxQJhCpJ5LZtepSs8cRePgBFNQUxiOh04qJ1xs8c7bJr200uXc4QMYt6KfEfpc8G4O1jFfO8s2dIfEZ4cmmrUoxW9B4vfpiDbGYTxtZIPKmtb2Q2gMs9RFXbaY/J8qwCNwuOO7GLKz6T8s+fzRKcsrkMcWrl4U332lymcgJnQgyJSk+oZDWU7WZJF4VjI2J4iaJDTP1RtIgtn2+ffUqX3j75+kfH2DGQ8ZZTu7WQ5khDsFVgyU81XLcfPU92wJMX4IZlZxp81MNQ6/wEgVIPaOOP6HlLpYAmt5p1QVdqla7TFO42dRproHxsoCYqzP3gs77vcy+uFZJtTaiWgSh1X5PbPvF1EcmadeY6vUqBtvsjViqO/uAaXlfO9pSay+yRHFKY+9t2vwN7EqXzvZF/rMPP8GlJ/+b6uVCMosql8xpBtnjBaV6Efh4wXs+gcwljxOXG08i6bwPuF1++GH6CGGaWlTzmwge2h6nBmuFViKMfIa6jL/+E0/yl57aon/tEG4cEzciom7M3oNDBnlKFhleaMC6KJigG+RRUsAV3iOZeJJquUznQobOMppKa+9q/KI1IbqJ8qgs7AxmlpUqh7fFXYks81M4MY3o6Zoa1WW77tPh/zH67mkm0nTArAdlM8UeyyeXvTrORqCDSoqYAxreAk3u9zoM0ut8585bXLtuOTiOyZzBRIpNLOPxiPFwjC93RoogbmOLtXbKNGsKfJZpX+H5TkHmRlsT7ahA2DKRn7JYlkXPrywhKCxziNVpHE5nko/qguut04lxrpNQncswuvDyTydZecRGUcJ6TdpDquRRjbemRXemnhW0ZIF7vE6AeDEWGwWdPGtjMtfCu4zmXsaZ/ZR/s3Kfn1i7x2Z3m5W4jZF27Xymi3HXx5o6zif2077GlAL4rNQ9J2D1S4brf5BATjXa0pmh76QzUQRf0CmjyJAYDa6Fec74Qc74t27SasS0riiNczHRWptzd0D2PL3VEe1zK8RRBC6sjg2dkhccdqdK7jxepvWxvPcYO5nXV06fMlMtziUcnTaemtrqPmH71euk8pOTh1Wnfg6WGbZXelane5p00a2ti+f7MsV7r+khzYyHppWBJyQHLdhCSgIYHH3I92mac0TS4u39d3jjwd/nnYMho3Qdk3RpJQ5rPdYorYbHt13wESk2uYParsFYU0sCi2wA5ISxkzArPll/UAMGUEjr1DvSurjnwvR68rUuCQFea0XCqYFiWTw11el72MiEmVgFubnuRpZ2QuVHwwyrLfW5ZFJaIE+NDSd9iscW3+OC5W5F8jBBV0wMljCe9FkO4yPy3R6v3GoQr17jE5cTntu8OHM+ownmRslGmyyYnr6xfy/J5KSR9aQz07mMMp+uZSlH4ITjkN+fJOFIK53YsA1blaY2bMYGCetC7m2coaMMfTji794c87d+9xapy+nEQta0+GaE8W26o5SnrPB/fThFO+CSCJsYWqqkSVBgHWvhJ2EmlF1fAu51jIP6JrpOmeWUG+1VhyE1CGUq4dSTZJGgpgfflXMfIo+Jj5zwNExpdOmc9ehy8PwEEFGWp53JOGdxiz6dWIrdAVwRzGzFrKJY/nM4WvERcdLEXd3jtesj0l7Kx184Q0OOaZkjVjoNVrpdbBQYeM57nNMgQSLBPEn9RFDSF5peXssg508IyZOAamZalTLB+MwHSjI53uRVkNSqUppIpujMSEh10enVgk8mOAGrGnahaj9aTzzTbpQyPXbSWUL6pFv2IuRARESEmYK46klksshJlfhn3T+Di2HZhUxYcjrTjVTPlfhihKnEMiBmgGoDZbUwMtOgIIHFERdqxD1c3mPnMKU/7HDcP8f+nvL0U7u4/AlsNMFDnNfCQjnsyaB5SCKiBSxr3gMGcoqJmC7uShZiI1PtyWP1/X+QPJZ2JNXZrg2h67ezFIVF5iE1aN/w2u/e4d3vvsZIGnRaK6RRREaK9ZZof5fXkzb/05//JJ1mDJrRJsaiJDFYUcYKxvsgzVEDIKeqcZ3IUsxujgTJ7tp4i+khvEgtIcn80FpliSjXQuK4nqo5V1nyZOgjFIFnLsH875OZLuWkBKQTJd0TnjWtZD/Cglq5sVFuboeuweDlAOjT27/Lg/vC2SZ85kOCkfOMs+fpNDfpNFcRDM67ikFnRDAStuCNMVUnopqGDXK1RTWcM6G/ztEBaglQamO6mtSIBu0no4XFgPpJp0XoAKc6IJ0VTZGaEdikOzdVxR6k4SeEhxm9NqmPhUt2Wv3vM++rOHBbIlTG4QuxR5nCcALzKRxa6dsy6SLrd1IrsrVxVpgiIAW1vrQwrgSIir0cDXszXj2+6r8EFR92fhSMGhK1RGrpqePI5TyfenSY84++dZ1v3PxF/uLLXbLx86yaFk5HiDQnJIWyI9G8OH/mPWQLXQCiy+KiSuoP4jKs5HTA/om5Ydnu3ff8Q3+QE8m8xlZYHCluAw3tfWQNptMk9UccxgP+vZUuL1x4lsRYmu0WDzPH3X6Pzvo61456/FPjuTnKeNlR8PPDA5DnrtBW8rgC3wjge6nSqtWWdikrrh68meyFCLVlrpmuo74oJlVCqT/0cqJ/+mwykblR06kGq/OA6iJl0qVrK7I4Ac72IFMJSKqua4L7TB+/LzWkynPtwxhKi+AYCag4lAyD4DLF+ae5ee9f8dX962y2e1xcO8vtg4j9I89IciIOSKRXiR4KQXhQEKyxmLKrpZRZb6A+xjNCGQYvGt+cCsr1xTWpaSBVhk61SVOUBJVeKvkTM33FVGcM0XR+RDZ1L5WHUsNzFpmMyXRSmeyI1FSM/ZIbpKBGh2+MWMxu0knyqI7PLHw9Ex1Vf/cVfiQFKWH6NScYSdGVSBO0gWeI0kdJUJqF9ElOmo8Yu3GgUIila8c0dcSlVaE/Ev7e14746Zdv0WpYjN/ERBFe4uANpPWu6hTA+2JWAe912z1I6/jJSGvGKXXBpHtpJ/9YHcrvx45kKtDOPFt56sLCl3o0johiQ+PMBmfPbPCZJw/50M9s0kgSOo02rfYqg/0Ra+2EX/qbHX7hxjUepCkyGkAnQUc5Izx56tBii9cXnYjzRZApqxipP/K1gCATNpfqZElxMqqZ3m5XqFGBZcZ29xE3YRlI5BRcdX28CkL15N9fVr/T7m264Gcn/xZIOnIiwFl2cb7QWPJaGDthiK0hshaVMCuPpUU6VI5He7z2zj/kuw8u8WPbH+L8WsQ3bn2Rgwc5UWeFo4HST4MPiOAxhZVu6EgKHw6pbfZoHraqq4o7jNeYqcWZC4BSE0WcjTumuPZlwDJTX9UlCxvVv4suayCrAKTIHA17luAQwGuZA87nxXFr77Hahp+9XoXlNIUSQPm+dH7TXWrkg8pAQQpmGzPj1bL3KK2SJTAzfTGGC1zKvHh2DFEUE5sGDbE0iUgaK8Rxhx89O+ABKV/4muG5s2+xtpbQlQ5x3ATiULD4QuFZCszlNBjJ0m7kMYJ2Df+YTSaT6zAjQzRlS/84Ainfj2SiP/iJZGoeM9uxS5hhO6/IOMdkgokCA2ulu0LLGnLtQ/qQWGBVGlzdHfJlGXFGoRlBGkc0kyZIjHjB2kOMOEwN6PVFV1LfDBGRqkOpP/haKgWrZ3rDvWZ8VW9Caj9f2dCKqYGK895tcmKi0ccYieppl+Wnp/RzkkG6xKZXZ0DaZQwfqkRdJmtXdYLhHMSAFcER472h08pJ2j2+cWuHf/t2xPm1mO56i73siJ3DBoMxWM0Zu+D0Udol+ZI+LII1gvETplgITnbiD6+FX0WBYshcaTrZZyp3OKTAXcJ3+dr3zM856sup1X+lJjImOo9p6WIsZOrxkJn4NjfenOlSZpRl55rZGkNMRGZ00uwC8c3pPiMprEHL+FnuqphZPKdOByhdRWe7MTVhGbVUicg8mYzBGNQk9HsZ1uQcn8k5tz2kvbvOl975Lk9e3GB98xmgWbzTpHgftrIkKEVZ5VFi2/XFm9r0YREr8TQtznx5WSvQHvFALmfMyQ9UoNf3cAzynqnZy0ZbixbZTKG5GuZbiFdk7NDhCPfgiP/7zX3+xT//Cr0UEo0ZtiIGDcMgj+jt7/IhE7Ox2iRd75AYizECRIixCHkh/x0CgfO+GqFVskY6UUut8BIp6b4lNuJnSB5aE1xctFc+YYZVd6bMM4amqJ0LPEwq7+lHTMcep9ZYtqG+WHpeF+BJNYxFp9vyqtvTcK598f8Uo8sK2DUWdbYYzexh45u8dmOft3c6/NylPSS6ze19z9FxE+cNNs2QGBpx2Cz1FRYckrWVwtBJTNFFTjoEX2y+zV3DGmNCanjAxPbXVDiDTNfgTNNmT7JQ9rXxxslyMvPlyOwto7UwzczuSHlBzNzP1i0Ayj2bSQE0Acknitj16nw6kXRKVhx1v5iJRXWZYaQkmtRGgxN9OSkmBMVZr3ZMXOGTYlHrGY1vg0+5N36Wi5f+CBcvZ7z6zlvcebDFxbWXsVE5FosLKr5B1VYPVkXRl0dtr3umt4dmNLwey5lXljqVnERQlkdu2P8ejrXmih157Bd4ZIhSnZ4InNyRzNIZykjuEVVsYeITJQYTWdAR/Tjl7u4R38kzGmNIrGGUCWOGXI42eam1wue2OnxsrY00IhQYZ57xeAxZXOymeHLnSUytbtTp3RGtVyRS2oX6antddYYGrFJtxJfLZMu2grU241o+8qp3ObI0mD/KRU3n8JJ5DGXCXDZLb4uFCWQKA6n20Ca1a62T8YW7YSWnLgaDL6i6TaxpkesA5/rce3jIwX7Kq7ce8PSlNZwMOBqmDDKHtSVI7xCnlA1eZXpYOvSZkGC0trzsKzLHZCw5MddaJI5iJp1jqGomGJCaiqZemnNVm9X1xDJ3vnXhnpCe0E2elsw33U0E0capObvUFv5Up1jrXmrSxFU346cX82R+LuoKMoMWL+Yn/1djORahwOtUMiu7O5VQyHmdUBXCKY7ABAaf91lxWC2OhvDu/iHrmrCy0uUr745otQ745MUmvnkBi0EKLTUzs9hzchLxc92IzgWy9+JXIrWAKFPPQT29yNLdnd9DTWB5P8Ou93F8Iqf4feH+WjzaKm5WU1AnQ6Dw+MgSbZ9hbfsM/9UTl/ncTz/LJ7yD9RWiFgyyEdtmndu/c5v95hH3Oh06OayJ4keOdNRD8hhH8J7OXJjISrEB60sJhwkjdwKmq6+qJpmqYrU24pnVuNK5sYDO3DhVpbNEOkEX+zAuCfDyyITx6O/zRRexDIHUpfWUFsmkdOgzUh/rUTw8AWQ3JsIYiykqXiMJ6mPEOvJ0h6v3vsrdB2/w4MDx+T90hVt7GUf7jp7zJE0futOskENxYWxoSoygZFZ5oQ5qaDlS0UnXODn3s11e8Peg9B7HFwq5eXGd6/4mtvZ1X7O8ZY5KJwsX1eZZecoC5SDRE+vUUiq/KkG0FL0yRZaVGqFgukMrMQutjScVJvhSzTJ69iMvhlgVbkiZtLUS4px+vCfOkyVdvOpYy06kFIA0UUEcGKI+JYoaiG/TGyjXdnZ4odHjye2E12/DWnKbj2wYJHoJGxmMr08XZGECmSaj6OQ+KI+jSKQqvsA79PQjmbkt9to11ymC8NSFF/kAKMEfcOI4fRL5PeiSRGqjrcrDucZmEMHaIBCb5spwkNIZZzjn+cL1h7idI358vUX3I1vocIeVbpfcNPjy/ohfPhL++5cHnF9rQQSRQOwznDN4UXKNyFyGt2CsJc893oKNDM778AAVUiiTjqSoWIpAW877y2UrrclxLXdNn9aQrXcE9Q3wuWp0oQfKbOLWU15YnVqUm62ApjugRUlEF4xWJtz5aru/wCpCIvE1ckIwjrImJjJBVSD3jsPxAautFWLv+erVnHfvWn7kQ2s0W33StMedB31MA5pdg1jIvAm+6lawOpHOLw/dmMmip1TFy2QurboY/5lWjfU1PKOwW5YJj2uy9FZeCLMQbXmcR0wXAfOPmDHrzDy/XOoL79nUDQQru2jV0gtEZ6ZxMrN5cvKHLawPJ1T4cK3F+CkVhQlhYbKHY0r5ecrKv1Bb30NIpgAAIABJREFUlonisQBOLWiCMZ4oGpPmGcOecnMc8fHn19g5Vr78+pt86PKQz27+dHhfeYrYxiO6kAneWX+OS7WKxW9f3mN0XoCTLCsIHjuZvM/jk/f2m37Pksf8aGvJgQRz6TD6KW72QX+Mycdob8Rv3OrTeWeHo/PrND7hGNw7xEbr+NY+46+8za/kEX/1Z5/imYYljmKiSGlZpZeG9tj5iNzneG8RMeS5RxPFWEPua3Lf1DASPKUWvdZa4FLqYbJbWJOAmLlt6uD6nPnTtEbGVFIp295Fzd6cltfCQK+crNU7b+M2m0ym383s6EWnPKqqEUpNjl4LnTHVUOlGNiEWA5ozTj1H/Yd0Wvv0j36Rt++l3NpL+PxPbvP2tW+jJkPWYozmmNxjFGxkEWMwdnpsVIPZquXB6rhUquullaQ6c55ElUmUugrADp1JHLqQku2k5birSCBi5zGPuUxyugdv0Zhz0QM87VtSE71XUzg3TrTOJnpnWvjs6DQ1QOojoNMFC+NtUWSXhBUDEux3VWaXemuJRCb+KkaoWVdP0TiKwiTCY4hsRmLHjN1N0uw27463+VzrOTbWbvHaW7/O1965xGef/6shkfgeaISR+ISwOKuvN1PczRT+8oEEzVMKtr7n7uOU0jCP+Vb0BzCBTBLJ0s21Euk2qCqJUTaaCV4T7BFcTPb5zYcP+J015fMPj1hd30ZWVnjn1gOu24yLg5y0l3HYzNjqRJgoorHSZuQcxtWqzBpzxhRy8b6kJy68gHqSyG3NWTFQd0UXb5EvYufIEnh+UcAXZQn9RD+QNlhrDxaPTF6TplJkIoJSapIFi1WDEKEmQ8Xj8eT5mFwjnDrE9ejIAXvpKv/qjSOajYRPPN3hQc9wMOjzsO8ZjZWmBZJioKRhAF7WsxOacs1prt4l1r0kKttVKWxeZ8+TqUQ7J/wrMw+iFyV+yUkSXQBqzMqxl3sej7hcMgOkn+S3V2qAlV4c1V6L6JTKr9Y314V5FQJZrgXGCYy8KiyXMvIafH1EtYZ7TjoNnevUqeFQtc2d0qjMgBWKBVOP5hH9kcGL51u37rGeWD770W3evOv5Z9/+VT7/whV84wJJHFULofNVvlSYYD2xlCsJpef99EBRPoAE8qh/+yDHRsoJXgk/NB/RvHa2TN31GhY9EIRmHJG2YqKdES+ZBn/n1pD/88EdvvGdh6w6S2/o+Kof8tv9Ps8lK7RxZHjGx2OaKx0kahM1xzAIjC1TPGQeX2glFRWRmIp+WJdAUVFkcf1+uiy+QE33dCZTJ5SsIu/pxpymeZ4GvNUleAu1h3QaVAyJpbC31QQlwVhwfoz3OalTcp+Sq2fV9oh1l7d2U75yLeWlC00+fcnyb24NOO6nHPYDCqvWokX1PxFVnADJZbKQ2oJefdm1CnZMWEOyYPw4EdSc96CfljoRpkUQZWoUSc3Gpp44/GOgljqLTciyJVNTHVs5mtEpheASO5dqW99IXQim1vuInkjkqA/QXMFymLqXpfbmZfG9OrvIW/2/mYDwgXFHIGUgxYJpjIglyyCynm/dvM+nnz3Lf/jxZ/mbv3SXf/nNX+OnrryESf4cIIzciFbUrOF1vhqpUU++NfB2CqDSuh/RxHbg/QXjR8vOf88ivvzAvMgHmUjMfIlbzm69BkMq5zGNCN+KsbFBzrR4aX+VT691+erxgFfu70KeYTKHlZgnkjb/0bltfrzdhAgG4yGu28JqjJeskmkoHxhf+HCXq0PBzHD5BnpJaX1c5sGiccXjXJCTOoTHe51lY7BFoPDMb3uEoYIUFV2YoPiKShXOblws/43DYmCeBQ9uNyJurfDm7Xf50tt9kuYKz51rc5gPGRztM0gj1GfE1mFEyNVW2Etd9yowXbUaV0nZ1fpitGaYk+YNeyEz57CubMCCAO5ngrNSUxqbsT6a2V5crEyuNbZ3KXKotc5pQqcVZN6euDzzdVMnCQw5qTCASddSnqZg/2wQY5D5xrsWRafPz5yer7ipW1ErSZnaOZRpNYjJSHHC8JrQqgNtu3wNI2bqvHoV4kJbS1CcS7m/N+LGVoMXr6zx1r1b/J1v3OMv/7E/g9eY2Lqw+OgtGMjVYwn08PmbvIZ9admZ1r4mH0QAXibTuVzY8/19/PBvwEdz2tjl/Nor6hTvHOo8GZYxSpQ7tAmf+Mwl/seNT/HOHcebD8ZcE8d+rHxku81PXtni5fNdjAM3HmBchs89GhlyrW+bU3Uk4KfGUG5qV2P670W9vTyZFAsoy8VXP6gLK7PrzSd8mMWdxFJM5ZFD+4WVWTmKCF81tXFOMbM3YdwVzo8jEYikR+pXeGPnDq+9fY+PfvgK5zcSvvbOHlnvISkJkXFY68CUMhxFQKwCZz3oyWSfRHXxUiBU3jeT8U49oDHFLKJS4tVgkFay20rdNF2Q32Xm/Mi8rNqiv8uCbxbR5QJ/FYYjNRWt+nXQidqsTt57uW9jpGSf6QKl4ZmEugjTrOwA5s/bfOFTMCClYNDJPK5W9zg0VaFga8nQEFlIrOA0LBff2x/xytU+Lz/b5dqD23zx9QN+7uO32dg8R8NQYFuWsDfmECPYE3f6ZAGe8ZgBXh8vqXzvQr78gL/eB5FIWHSfFTeUKSmAltgKxgqMcoa9HNd2rHZbfOp8xE+upPR7GfJcg0bchizj6OGIrS1BvSd2CaYM7E7IveB0ogXk1VfLiDoLa9aus5Hprp1KZsOzePXwFFIoH8TNs3DEVasY9eRxlpw0sFM93QMjNWukUhm3nCNpCaTmqIaOMIksSZJg6eNkxDfuXOeb9w9YXbW8sOm5ugc7O7tkfkwjaaBxAibB+Rzv0uD3LcFdL1ApQ+QpA6ExilUtrHxDtAoCgVpRWaUUdzSTkaNU4K5MqRkHgkCN7SWmWHeqdUCmbHtqmHW5pFqMecr9ovD9OjHfMtQICjI1WalGY6IzsjX1cWntGspkByb8bLhHPYXunCnGjqZ+t/qZPoPJHpTK1JhuXmN0wq5iyk5Zpvo0U7PfDcmk1Ekpujzv8eFxrwzO6u4SWopRlvRuY0hMKFeGQ8ethw+4eLbLi0+0+e5dz9/7nV/lP/nxi5zf+ONAXLExE2Pmn7cTJfe/F4FYZ7w3fz/1D9/zRBLGWSVAITY45Wl4iomLhyQdOvrX7/HP/vZ3+ZXdHu+ifHY94n94aYv+8Apf+dpd3taEv/j5C7RNg2aSBOE+Ecg93tugsaUyWYJSxUuo3NSBGqlvuD2arSETYTYtbvblQVhOld+XUQPNwpa8LqgkS/PASdjIvGbdSWQ/QWfS0CxA7IvqMQRPj5ChPsNIThI1aMcJ6o45yo947foDbh5lfOxCm4udIV94Rzk46CENS6uRk0uL1EegfdBhuHUKulY5ahQtPTyCb01kCk94MWjuIJ8Gc6VINEYm7CCq6l0nkiglg88zoXtP0cOpOjAKefqQpIprJaEKKd0HvacYPRX7EgUwXcExNTr85Pf7CqerIJ+iqyjv0aC2W5f1MZUTp3cujHStYiKpRoKiiqlJ1ZT7DTKhD9RebXq0WnYStqBET3clzDEQy5Gn1rftrRSjsKDcbEopL0/NGrik1ofsJ4V/jVchNjHWWvzYs9/f4cZOzsef2qaXrvDl736Tn3jqLdbbP0EcO7LckZgE68M9QbXb5BCxE8HNR/lQfxCy7TOb7wvWUT9AhtgP/4eZvUbeKc6FMQLWIIlFEhOqtzSFdESsGT//jTv8z3fv8XZ6zHHvIV86HNHaeJHe9jpfunvIz3/9Gld3h5ixYtfamEax2OSU3JkgxVC7UT2K0xk7B2UJqHyaCyeL5+zv+6ao8TgXfZ4KtpHZJnBKwb/ar2BWMHzh0SyGhws7WqcGpzawt3RMQxwNK6imPOwds9bZ5Lt33uXW3nVeOrfCS+cS3rh3zMH+A7TZAhsFW+Q8RV0KLkcK/azICi71GCMkzSioCbsgNGjwRGTEkSNpCjYqMoFzlSWvqMegQZOr6EyMEawJr1+OxSpguhi1WGOwJvwZ2TAiia0QRYUsiwoWwYqpvicyhshYjDVhWU7BuEBjNrYAlL3DiiuEJ304jgLPsAJxDJEpFnVFiST8jkgM1lislOOgUP0bG5YlrY0xRIgzWAyJhcQGhbEIxeLBu0CB92EJ2Baolmj4s6A3TGQpNehkWRMSqBWLwQbsAZmcJyvhHFmphDTDubNYMRixQaUZIRZDq2EhC0WBiQLEnjpwnhJuxxSdnUMY+5iRT7CS0rRHHB4OudPv8MKFFc529vnF196lJ4o1O4HtVSqMGqnUK/I8xbn89B34YxAlTh/g5ZSfH0AS0d8HicT5oMekQuV/EIozzyjN8OMxaTamH7f56IuX+If/6U/xj/7MH4Eza/RGHZ5KlZ99s8fgxj2uH2QM05r0RXA+wmu4QavRVqX8u0gZV2vubjoNoM4F5gU3hzwuQDfh2i+6ier7KSdWTaonPxOyWOtG3lfm07kE5bzgfEkDzklMEGjMfcZuf5dMG3zn1h364z1+7NIWT3Qsb9wZMO7tYVorSNQgz8FnGZqPwHmMRhi1GAwudRiBuGlQ56pK2hQAXOKFJANJPT73UCQPU1xXayQEdlswmAq78eqs62RWH5KMhGQhIbiLgC0CZfg0WFO8bpGYJkrEFEnIYBBMTkgGUREcnaJ52Jsy1F+D4nebWqILxxD+DK8XXjv47VgjRNaAM0Q2DouUTrAaElpIQGEkYIuEEZheASssJ07lrT9JJlTnCYU4sUUSMUViCJ1O/fikfg7K4zVF8lOBHKxYrI1oNhMkD4hN6CaL51TrhVn4d6/C2FlGuSWyOavNAf1Bxtu78Mx2wkfPjfjNV/f4+luvs7/zzXCejSkWHov71Dtyn+PULROWe2+B96SmZsqLZrkaty5dMD4puZwy6ej7T30/uKOtAheZBhXDKMZhGUcN4jgiij1xp4XRY3YPDml7R88I1+8e8mwsfC0dkeSOtYZlkI/p9Mc0rEWMI4psMLeiKkqmJDROUIKY6UplMUig04tGWqOdTs+fWWBbumgRbGZ69jiXtv76ssD0dxlm8ihRUlnc6Uv1oGvNBCosINo4IooszqfkWR+nTWy0wz/8xhFXHx7y4pUuuaa8em+MiGIjj8vHWC+ob9LqRORuSJobsrxB1LJEbUPDjfFpRj5wGAPtdgM3gkgysJtknRb93SParYit9Q4uUvZ3h1gbmD95ljM8HIRuwpbXKszdjZm8H2MNKhZ1PoC1Emyaw9woYG5iQncUxSGdOa+IL8oC66sRqXhBTAPTaTFOR7jDAY3VJq3NLfrHGY1GhBuPQPNCzsuSZ0o2UkRswArVB2zOKmopqPISvFjCjidu7FjZ7NLbT4nbMY31mLTvODwYFwnT4D2o8zQbwkbXkHvIMg2vBdgoJLKq6jKCFh1Uwwi9vRGNtQ7jUUZjJWbcS0mSqNDG8viMILhqBROVI6uQuG1sIfe0GpYM2L3bIxlCPrI0IosfOOLY0miG9+t9GAU6hLgZkw5yIusRccFOWSMySTk6usvNnXXWult84pk2X3z1VznzyVV+dPtnQWCU9ohMgpHgPSkmdEVLrQy/RxX87K9771Oz72eIlx/8RCKmpN2GykprwLtXIbcRdiXGjBzd/JDxu0N2xu/y8kaXj+3uc+P//SpH3ZgvHB6wFQlPrndQC4c7u6x0NmitemykNBKIDGSitQl/XbixjnjpnNd1HQCtNx46mwAX8sTlRDBNHseX+3EuvC6ob6a6khk9JDlJj4s5e3BT17Mqk4hXTLnJbmJMEh7+4TjDa5Nc7/Er3zkizzM+f2mDt27u8p3rfdYSyBuWcTpGJMGS0IpbDIfgrCWViNEwIxuMiAp9qXyQY43QjiPGxwbpGrxcwFx9yDu//BbbT3fpvLRG5/IKKhA1DHEsmFaG5IJmDj/yeDGoMcRiiEzhV+IdpmExjZh8mOMGHi+eIOZkwZtqcdHGSmwhy7VQIw7ArjiHmBzrDZYo7NRIk05HkFaQ7Bn1I/beHbBxvklkLI2mgxicBZdaRkNIGhYbW9SPcS5FYoVY0dwi3oROyXgkFuLIMNwf0Gg2SJ1j3Pe4LEJslygSohhyFZwqrcSxmuT0M884LxQcrIUIrA3MSa/grUEjg/WKy5S1s228GkYDxTYteqTh+PJCUbswoLSNwtNdgxSZbcYkTcvh9UPGuaf77BZmYxXE0Ew8cVM5fnBMa9XQbUQ45xmlOZlYciKipsUNMqzkWFHExGS+jcY56eAeb92FZ86e50+9nPDz/+JVvvXEBX70hXDLDtIDEtumabtghSgKSeU9xc5lWoqn5MjM0YH1D5xz338iEcGaAoAsglyZSIxAbEFig8YRF5zn2tjzv93v0e4d8Ou549vesbXX40Z/nz915TLPn9nAGmHv4UNoJ5DkxImjMfJYU5cBn+5IgozHolJkmZThtJVppf47ZWYjJ45gHzVSkhOWoOQ0rouLAD2te2PUn4vp45ZTzngnXizlMpkitsAyXE5/6GlYodvpcv1+n2uH9xmNj/nDz51hMEjZPRqCjvE4jImJXGgdnTpM/jZyP6HRPoecHWKxRF4YDR3j1GGsJ24YiMY0Vls0Npr0jtq8+WtfommFlfNbmLWc/vExzcQSR4ZxPyX3GV4MPnU0WwlZCuOxx0cG247otgxx5Ni5O2Q4GtJsR3RWLWmeMR5mRA3Bmph07EmHHvKcpK0YGyESMxp4NPPYaEyceMQ2EJPQjWHv3SGSp+RPj9E7A9z9PY7e3Gf1xXU2nm5DW+gNM/ojjzMdWOlgIjAyxvkUlSGjUUY2UuK4SyvpYiVDcocxAWi3VsjSnHTsyMfK6rkGLc7id3dJjwbEzRhZTWh2hX4+Ih3ldGJDf2jop5BkGd126NBUIPNKnntiDzb1uNQRNxvYSPBeiaKAf4zTjKQdoQ3BjC3DYUp/lNJZbQGWYar0j4bcfOU+fpDz4kqTaLWLPXbk949ZffYcbKeMjvIAwuORBlMqz3EMcRwcMVUjnI9IbAoMORwMubWfsr4qfOQJ4dXbQ37trVf4o89u0G1sYonwxXlyWpI29FQeISdG+/fUvSxPJh8c6H7KJPhDwdqqB+IZ8TRjDYl4yEPn8qc/3uBG/0W+eG2Pf/vgiFhSeh70zBk+/PLz/BefukTkw6gsWWsTxVHYZjeeqEgiorr4Yk4phdZkEx6jA9AFciIii8dJ9dHQkhQyf6POBHiZWyHUU41IKwmNx1BSqHtILOd0Fe83CqytPMsYp57WSpO4GXOvv89bd45YbQz5w1cu8zvX7/CwN6IVZ3jvsDTBJNDq4/MRu1fhq//gkK2LbZ76k3usrqzSaazS6MakRsmyMW6ccXCnB3nKE+1VzCDj3u2H/NR//lkOn7iE9r5O70aPtQtdNjbbjIxh/6Eycko6ULprDSQ2xM6U6w4MDnIaJqdhLGefX0czT55m5C7FOCBVjIVmo0GjY4i0j+gIMoclomENyUqLdJCTDTPoGiRq005GvHP1OHQMZ5U4aZKcb/PEEDZeWGP9fETvsE9DldwKYzHkIqhmqI5RUhBHHEFkAohu0uDJIl6xDZAojNvcIKe90iRaazK6v8srX75L7/4euJykHbP9zCYX/tAWeRf8IGe9HdNtJjTiDtnxEWR5GGdZSz7KGWeeRsuyttJAgKNejkHIjjLiOMKI4FOw3TgA6TZC4ggyS9JqMNxPaW60aG11GZ0/wPQzNlY7pJpw8NY9rn3lGp/8U5usfCQizyJssxmYlDLCOCEWiw4dcWSIrcdYxeUtlITI5NhozDAfc2u/x/ramM882+UffFv5wmu/zoe2n+Tc2s+F480HGKFwJwr4rH0vO4f6fuN5nf/4fUbCf0iSSbT8xJaCjQU9t5C/8JEw6sREWcxfeXqdP91p43LDk+rYvXHIsNvkmZ+8QnurSZ4rEkErTkicR8cpfuwZeiHzgf6rUAGY5X60LEHZFoHsWpvzVMVMwfKZ72xqfgiP5KnLgq/UeP5LJGVnhSBnJevnXEV0zlJ+cc+10Btg+uuFalWBOwV+TynCF1slNmPSYcRB/xa/u3uTg7Hlk092ef3+Hnu9HqoZEJRexRgia8idp9WIGLdj8vQQ8bC+vkLSaBK7C0TpGI6OacRNkjUD57u4vEdTR+xdv0e70+ZwnGDHqzTXE6K1i4yzJg8OIsa7AxqrT9Bq7pA0IdYV4p7QyD3j/jFHg5SV7Q26l9c5OOoxGMQMeoY8M3RaK2yu9xmmCSNdpZWP2Wxl+KjBg70xGQE3aa+tMdgbs9E9x9qZQ3S9yd0bwsGdfXbePmZlrc1za+uYJ5/kyG0wGr3Gm0mDS/tjOs7AehcZN9jMYcUKmfTRVgNGAw6PNxiLgnc42yDNlPV2hyfOHnN0PORwrBBlJHGGtQbvIvT2EXvXd/nsX/6T2K0BVkak+z1MM8Zri5XtNh23xcOjIcfDERefeZLI32UwglEqXLxyDpMr927v8u5R6Do21pu0MmFw95jo0gX8+ICVVdBhFxkoupkhLWGzt8r44JDR7X1Wnj/DyvY6/afPstZJGJ5/EnO1z/jmVdIjwe8bEtvkwlab8W7GYHMFPxiz0l7Fp00Or91BLnUxmmJNUKdw3iMmApMgXvFuxFHfcNBp8vRZuLP7Xf7J79zmv/zcz+Gcx1uPMTGxSgHu18a5qjUFi2n9rw8kfi+Yete7j7q3z6ONzz6AZHLKafnvQap7zESiJRYycRBUhEyVXBWbOshyssTSFw9rm6z8qKVzZ4C7ekB2BDcOUux4j2dHaxyNlV7eZNUaVhoWHebocESWCyMXQMWg3TgJ2EaKFRb5gOaUU34E88D0NOYiy7uQ2SRCTS5lpkN5HMvLiaT7DD5T6U+dbOe5MB9W8uBRuH5OyV3GSgNa0Zhb94XrB1e5tXuXuNHi45e7/P3ffgfLCCMu6Jz5YKccJR6fKm0bo90ucbRPp9NmdWud4/sj7r05JnEpt9++R9KIWd3ucvblJzBnhhzcS7n52g0Odgbc+OVX2XxmzNHTOdtrEb039zm+N8JlnmTD89SfWMFvdWCYcOMb77Dz9n22zjSwHcvqygXs4CJ7v/nb3P7udYxpcubCBbovnCHZ3uLB6w+48fo1TKI8/SObXP7sc6xc6eDevsPdr13n/s5NWu0W+dYFdlqHXPmpTVBleODYu3dI7yhl9d8Ytp/qkTvY/eYD1jaeI1rt0txqYXYzbn3pLd66/5D2Wkxz03Lxk0+wur1BY/AC+e++y41vvUGcWEwiZBtnaH4qZtiISWNDu20Ql+HEkHtLB9je6nD5Q89xMHqF2/eO2Hy2Q96LsIM2w/4B968PyO7toMNjjh9Ytj9pUW8xUYI7tDx4/T5vfOVthsdDts51iH72aZJD5d2v3Ofpn/0QiewjJufOt44xQ2X7jzcZjFMOXhlyfLRD7vu0W00azZzD1w5odBuIKukDy8GdYwwJ964+5LiZsb26zu1v7bD9M1doJRFrnTXSQcKNdwZsXdjEkwe2m3d4b8glQrCBAq0DjnsR1/I2H37CcPPBXf7t6zv8x3/oLlG8iuKIYoN1RRVlqQzsqoJWfeW5LjWNst+bMv77lFD+XaBpzXxM0X+9V5xz5IVnamSFdhLRbcQcZHBzLPyVrxzy1d0RJrd0vKdzKeZvffcGf+KXvsqfffPr/Nnbe3z+12/xv//qu2SjFBllZP0c8mA45AopFENt87geTI1MB1Z5BP9vSj10Vlfr0X2yiJlKInKKJLKQ3lcucy6kA56uCz95NFzTpirYWROzo4lCqsEUInjBuyNzMMw8iclYTXJ2hwd87fq7NM2ID283eXu/wSDt08/HOHGFBHkc9g00p5EI4gzNRgtrIsb9MXsHEfndIfe+8QZvfv0tfvTnfoTLP3KB2+8e8uYXX4P9AW51k80nL2BtwpmnnufMxy5w/uIT7H/9Nje+dYMnLnV58Y+9yMHeXW5/eQf21sjjDkd3HnCwe8TFn/5jdH/uU4y3hO/8yrd455WbPPPRs7z0medZubTNa197i9/8J7+DWenw4c89T7JqeONrO7z2y7cY377D2I1oXV5l++VLdF94gjt37vJbv/Rtdr7TJ26PaT+xggisba3RudwhOm/JTMS7b9yge/sWKinHV4V/9n98kWY04mMf3WKzZckPM/z9nMP4ItmDh/zaP/4Vnv3R8zz/maeIz7TZf7jLwVs7tFtnSKwy2uvTig1RI0LjBpm1HB0MOLxzi1t3UhpmA722y0YSEbWbRO/us/vadyHJsBfXuXXzAf/6/3mNLbpsXbjEwesPuPHNW5x7+hLP//hlzn/kPJqsQJrzzrd3MKOYOPKM8iYPfvche9f3yAFcTP/IIe0NrnzuaVZfvoxZbTM8GPDOOzs4n7J6psXqVpssG3Pu+Su0tyy+5XnnO/fgqpK6Bpl4BtcG3Lk2IuulZBnBIM0KYhSRBLQbBhrmiIeDfR4c9dk/yPn400+wsr7FP379Nxj536AZRVgT4ZZQ9IM1gi+ULyafj96wev9jrh8I5tTc25Qf8ERSaeEpTj3O15zKCmmU9XHOhZ19/vk3bjF+9R7xG/fZv3rIb319h7/9T77GvbsHXP7wh9jqdnn1V1/hy//yVfp5Ru5y0mFGpjC0Qi7B5MpI5cC9EOGY7z9Pum9O3iZ//yqhywP/lCLtrLjee/29epJYZf1b6o3/9M+EXYHgfJc7V9gVjbnVu8/VB3uc6SgvrVtevedQxoxcjiewpkJFKYg6GonFZ0JiGhixdJotZGUN21zh3Vs7fPSnfowH60POfmadiy8+x+3fvU3/1hGDxgXWnn+OVgdWn7uLO7OH3Poob3zjgIs/ss3Gj6/ycDPj459d4+tffAs5apObFuloEGR1uudY799jw9yBTBn1x6y+mLD1mTOs/thF1Obs3X9IdGWD+MPCp//8c2xunmO4m9ORPt3vVZ4bAAAgAElEQVRzlo1PnKfx6SvoJ6/wqf/gw7jM4XuWhukh57q02glrWytwISbrHpOmY8aZY/vyKuNuxCv/9OvkqSP68SbdP3qWT/6ln0BtwitffIv7B03S3Ye0m5bGk578vOOZf/9DdNbg2rfuYnSF/KjP6kaDbJDhc5BGhGx1ufDUNr/wv/x94u/s8fSZZ8k2zpI3Vtl58x7/6hde5+lPn+Wpz79A92de4vLzmxzsDDm42kNo8PZXruGGGS989tM8+ZknWf3IecR2aTUNeEM7WQ006GSNbqMLebEX5gKRIR8KW+cVR86DhyOGxyPyPKezGdE5G9HebuB9xurzF2hvgT1vWFlZIb2dko8b9Ppjbr1xl8h02Drbpr3eQkMrEZKJxKAtFMWZHr3xEQfHxzw4yPnUs89xpr3OL3zpi7xx/QtEcbh707BQxJyomE6sdkuzLmrmXd+7RHFa9ub3MbB/73LnBzTaqgmCmiIAYYK8RUFcBxc2lm9cP0KSiOO4QffKJij8ypevcTvO+UutBv/dxy7x3X6P//X1u7yVOx4y5pI2sZ1mYeMZ41MHU57SNWB4VqhOJjstWmgdyUIGh85IjJ8Cz6qZYJ3M2po3pBJ03s9YTu47hGkXw2mMZzHor3PbMnLigNUz0auKDFg87ThH/YDDvMX163d55Z1rbK+1uLJpuTdwuLSH1+DdXkkwWlNIgggqES43JHHAsjLniTNwIogK2diAV6wfI7kwHqfFQpwljmOMiUhaXZx3PLx3i0FvQHOly6GJicWRFd4maa+H92cCWGxyFItpWCKNyFPPeJzRaDZwmUfUc/7yGUz/mE6zzfjwGg9Ng24nobF+htaGQz307vawO3e58ZVb3MhT4jims7JBzJAsT0niBDQhjjzddgRPnKPdbuAdrHpHM4p4+sVnufz8Joc3c9ZalgtXtrj2rZs87YSVC5fxvljmSyKiKKLZcBzmgjUJGCH3BAmRNMW5Q7Y/epFYRozHOW+/ep/DB/+aT//5j3DvoSXbU5I4YfPyGUa7Q3Zfu8maV/rDlJFz6L2HHO4c88STG/jmFnnvdYyNGR+lpH3HM8+cZ3XrDA+PLU0Z0Gy1GR73sS7HRB5UiOIO3jg8fRqtbZIoJnMOsRFqIpomdLyRjXFRhMkznnzpad76ztt88tMvkx3A3Tv3eeZHPoJrxKyK57AfOopKM60K8oEOrd6RWcebd27zzJmYd3cdv/x6j+cu3eB8u8XYX6Fho5nt6OKpEVM91FIbQsjjggsnJo3Jc2jkvW6vfx8jvCrvr1L9XmEk5Uk0EFVa3x58Fv7Iob0Sc9jL2T548P+T9+YxlqXned/v/b7vLHetrbuqe3qblTOcleSMTFEiKYo0HSsW5DhyZAtOkMRQADsOHCSAA8SAHQcxECR/+O/AgRHDcAzEMmzZkS1ZmylSFHeOZkgOh7NPT+/Vtdxb996zfUv+OOeuVdUzI9Ii7QzQM9NdXbfuPec77/K8z/s8/LN/8iJv/98Zg72SLxlh48nH+NN/7DIbH93iWdfik18+xwu5J/MZsfQwbVMrCdsYr4vGXjW8y/U4XaYgzNRg5+wyTnQgDKemkiXxvbAgsT1lY8l7SCYrh/g9VzsL05RjlronuiLO3/SJvtfNtZh6nysJIBaFo6NzrB5yexTzrddvcu32dX7qQ+c424bnb2WYsFeLLwZXe3lP1YMbxdfK1TvVQoVIwHpP7CGT2iERYsK4IiQVkXRqeM1EiARMCFQuEKkWrVZK6Co67QSVtjgYK874ikJiQHB2BG6HdrtFknhCngEOkyRESYyIQgeDHVUoVdHrpFwvHf1Wl9wId/dLDnYHbKV9joYR2dU9bnzrJsrAB566iC0H3HxzQrBCIgnODojjFOcULXGEscdnlkCN85tRxejwkLh/Ab+nUCphkgcm45yzZ7uY0YjhyGCtRwpN3NYoB2kSiKKoZiTqWqBUtMbgSE3J3VuO9EKbD//Fz7D3xogXf/m3+I2/O+Kj/8WfZL23RVkFnv/8NdY6MXpU4roJH/r0o8TbHQ6v73J0lPPIeou4t0FXGXS/jW/3OHrjbd555y6DuwN8GtM3OZ3eJsODIVFwqKiqZVBMis0muMmIbr9DmiZIWdX32iuSEEAUpgq4tiHkju2nr/DNz38dM9ZM8oq8yLny1HkO1SFtJdx1CqVDvYPmHSEUzVlMiHWE9x4bV3z7zav8yafv48nLis9/x/LKrVfZudSmCvfhYoM6AYloiM+zR0MdA5/fO/yw5A1zQjKR98LkDD9iCeVHJJmY1WltvbULwVpwFfh6+KrTiHMPbvGhu7f4xneP+HqekatAN+7xsw/2ePKxLtLtcGvc4UtBUUUR291NVBxhnMeLoHRjg9rsO5wEjcqCNeuym9uKs1s4fkRCmLtSzDwgFs17ZhX7giZqWGVEhZn6q8jp1IqTHODfbYK22l3I6lb9iQywsLBwKMe+HmbveOEJEF8vy1UZXmcYk/P6mzd47WDIAzsJXV3yxrjHqLiDczmJUk1jV4vpTSVBlIopK0cURVQBJtmENZszkRTtAe8gTdGd2nlRSa3p5SuFNjFBKYqsJDFQESPkRImw1TF07jtHuHNIV0m9dJhAmjhsHijLirSVchglkGcEW5+ZylnilmCDUB3tU+Tg4w5uHGM6BhPnhHJE4D72ro0Y7md86M9/lmJT0ZvcYe33j5gcTLjQMRzlLbLCcnm9i7MDhm7CZDRhMspw3tHu7RC3EgY3b6D1RTa32mhl6Hc0d+4ecd461pIUELLCE8eCczllXpBlFcE5VPB4C2kakTtwlSckMYUWNs6ts+07PPeTj/Fb//IbTG4fURYWRHjsmQd54IM7FM5xpDW3BjnSi5FXbtBfSxkdFZjxLjaJKAIwqtjc7nDh0jY6CK6X4j0cTSZk4xGm1SagySaHRGs9osSQ2B6xaVxJUdjSUeZDrAajFalzSE+TSYKOIs5f2eTmd+6SFyOuPLKJ3WjhJjcZmtB4UTQdsbg5WzLEREajNJR5RuUqXruzz5XNhPNnYn77+Rc437/E+Y0M5xWly+lEnaUALlOnzGkZqU5KIqtGLvLeijyRE9W/7xmb32058l0IMv++JhMVVnE3aQYYAVzp8SV47wgusP3IFn/zzz7Cn/sPf4xnP/VhPvLpZ/jFn3mWv/7zH6P/wUcYYhgS2L6/zycuddlJWjitqbKigVt0LXvRBHk51n/IfHcF5vsVs6ZXlhhY4RhIFhoRSH8CUTa8rxu8LKB4Glg5D+Sc+uteCOsCE2UFH15MEnX35Wf2u/N3Uc9Agg9zO9Pmz50tKMoxeTlkVI64fvs6+1XJMxe6hGLC63cDpT3CeUeqIVK6HppKIzqo6sQfvGDiCEct3miMZyxRrdGER7cNqmPwRtCxIeBxTghK4YIjeE8cASrCpBVHowmvf+NNWnkg7W9xdC1HtEevRUQ6x1U1XB61I3JtmOQVSmo5kso5VFvwxjMZDGqWkDK4PKHd7RK3WrhySFAR+cQSxRHty4/gRkcoH1EUFbu3d0lbiqjTZ21rgzs33kGbGJNq2ps90jTCewuddTpn1hgdHCAuRhVCtnfE7o0DHnz6Pro7fVpiSRJD6T1OB6oqp3IO6xze2XqJzzqSVGOMJlBLnvi8ZLK7R6jG3Nwb0ulEbGy06W222TqzzrVvX+dwUDKMIrJsRMcNichJ19pcfPgM2aTC371KKYbxxBKykqQdUXnP0Z3b6FhR6RaTKkeLxaQapIXzFtEVUWIw8RpKCozRGGNwVVXvrCSatfU2ko9pJYqQtqFVcfnpc7zx7avceO0WDzy5wdh4wiRnmAeiRsOrhqEdUDXPTITRmjQVqjxDKcv3bg/ZSANPXoj47ptv8c3rt8Du4dyAUTmmtNUx4kstwalmcvmrz2I9hHd4HB5fe9dLWPhvmEnvBI4LrJ6WRN53eD5W6/2w2GU/hI5EVnu9RSBSGZRSqEgRtBBFGU9WXf7Hp1pkZcDpQBlrem3Dka0lGx6qPP/VTpeDTot2ZJBGaRUl6GBqRpFa2Z84FsSlYVzNfboDshREjw29FyYQxzbI/aLw43u5scte3dMh9/tO/EvmXMcroSXGXAgsE4ibf/vm/6eaMAuc3xoerJOvEY9QIiHGu4CXijET1luB33nxOs5ZHjibEsSzlznK/GD2oBolmGbvojatmL5vTxTXAbDKj+oA1ImIq8Nm/OkoR3fpeGEytgzHB7S7MT42JOUYhyFpGQb7Y3rbFWee2+G52w/xxks3yP/xF9i+uM21l2/w6T/zDO3tBOtyhkXJ4XDM4d5N2pu1WmxeZgQN40OLPhwjianlemJhNDwgblnUxDPOj0jaIFJw/6M7fO6X3+Gr/+f/w86DbcaZI4pgc7vDUZ4jRZuzlzb44m9+kd43Sx740EUyO6C3ljA4OKJTTPjgTz1BdXSXz/293+WJR7fZvTHgxq19fuI/fZb+lR7f/M0XmWQFrX6EwlFVJUEMWVkwrkokOEyssc4RpwnrRnPz+dvYYUl65oj9W2Ne/oPXefrHLmA3A8nWNhffvsCr33iFYjKmv9NlqyPsX9vjwo9doXXxHI988mFe/cpVvvfNlzCvO8rScfmnn8LfalOUJa987Sus3/FQRhzemHDl/nWME47GETaUeJVB6NbyOb6g0sI4L4lChmyA2ugwya7x5d/7EpejLmo9oZsWXHruPr73hRsk7Q7rV/rcKvZJex2cs4j1tbhmw4b3MoWkZBazA1C6AMHxxm7GWqfFBy8kfOmVO1zsvspzD6R0kudQorCVrQUljV6xZF5wT2TqOunnhWOQpWQzs30W9Z7aiu8ribxrhgn/XicS/bf+xt/8W8sJdO6y5tGoSCFG1T4K6gjiDul9m3Qv9ehe6NHeSqlKh2QVUlnGRUl6cY0HHt2hnRiSSCNGN3aiQplXDPNf51efL7H2GqkRnvvgZ1lvJbQNOBJsSOolRaERx3NTGb/mUMixnuAkNGkqt7KMdc4H+bL0ed+dMhHC3DPj9LnOysk84deiYdPS7oic0PmsDONltmw5nY0Iwdf6TkYs4jTeCsFkDPw+2hb82vOv0UtKHttsc+gqru+NcG6ERc8ky5Ha8Egaldwp7qcjTaiEhBGR3aC1s0FnY0gvTtAe1rfX0GuBWDy+atESS3ShTaqgsiXReMzFp7Yos5LDouTKBzY5tx7x6vPX2b++x2PPXWT98fO4RFFZS3kw4uxGi80nL5GaPYw4TLlBvCacf3SToAWtHHYCm+sJyYUtdHKHbmhTjSyhq9h+rM99G122kjaDO7sc3RkwOci4fP8GDz73AEPZJ/Ft1vsdJvkh2XDMI49cxk0KVJXRu9yi22+zfuUc25sx1f4Bb7x6h9Zai8vPnkdtGtY7MZXT2OGAS8+eoSpLXFUhThEbWH/yQXx1h6gVEVyou71K6Hvh6OqAl7/2FpPDER/51BUe+uwDBCbI0R4PP7bBxe0ek4MRN169xcGdIy4+sEnrbIfkfIfumR7DGwNuv3MHPykpDjLMTpvexjr3ba1jswOuv3yHcmi5fP8W9314A9NWWN+nXVo6ZzXdc12KcYURIRtXpO2Y+x7tIV3HmW6PyArDfEj7TI+0l5KIZv1Ch7c+f52zF89z6Sc2ODoY0jmzgViHd1VjFDZ/PmsHxFovDQTrhNJCZBSjPHB+I+WxrQ6//fKAVpLw+PmbdNo/iQQYZzlGa3SjPrwEgS91JU05M901kXk3vyzcehyROL7c/ANMIvKe//AHxiD9YcNbEiq3EqmYVb3eBZRpKBLW4ewQbVpg0mkdvcAiDoDDFQVBg9atWsFUy5z9BQwPJ7x58Ff5y39vRJF/ifVU8Zf+zP/OlY0OWy2w0iPzXbQIkQoEX2JdVdNR0Y0BjjRBtGljG4XbqfnR6hxhUWF4KaGs3Jz3zddYsbh9Lzdd3YMd5hcSlQ9+lrh88LN9F9UkZOfrxVHr6v2fOLK0E4+EDlWlsMWAu8OvsB8ZfuU3XuBjT+4QRSlvvnOdPCqxVV4PgoNDL63pNz7lM5vaQHBCp6VhvIVXjmjtDl712btRok2bKC3pdhX4dcL+IZO20OskoDXVtV2SbUOVB0o0ptcmG5a0uy2srdllbpJTVQEXGcLIstHSVFt9ytE1lFHobIdJccTaTkJWFFSVxY81vcSQJwmufAdJtxkcGlrtitgf4asOnbXzZMMDdBLwVtAmYNKEyfAGnaRHu91h78ZttHK0L13h9p6jmx2ycVkYXC/p37fDKDiyownlWDAhIo4mtFsZR5M2A9fnoa3A0dFtotQgcUQ1rBjfPUJfuIAd38BJLUiZGEUridGmjfcpzkldoDXeJjY7IojFJS3GB540NXS7hjJ3lIWj3Y842h3RuniWLBPKyYRWOwagOrzJ1uY2bdXhoDjgIBujdId2q40yBXo8YRxt4CYVymf0OlBMLCaKcJUiTSJEZxzsH7J27jxx3Ge8d5dOVzMpLFpS/OEhr//mIQ888wT68T3yUUWnv0ZVZNgir8s5JfOybmol3ARt5zyVCzXCoQwPric8sNHlmzeEUdnm5/9Ywkce+m+IWKeYFLRbHSJjGmHTlcA/U2x1uFBhvVuGw2QZCj/2+9mfy7+9TiS87y+850Ry2rznh/NPWGBtnRzxEFWbTzkfEAuSJYR2hBiwwyPs+AgdtzGdLpI0TOJImFQOQ0nUuJ7JEpamOIEWdQzm0Q0lz59mURAWOeULZI/FLjKE93Uw3h+ZcJl1tjq0PwlGu1eqWbQZ9z4sJBe/MG+ZCjPWAaj2Gwkzyi8NRox2BBvTSzP+4W+8zqXHtsgPRhy0NdF6ymhvgEgg0Rrva1+J5pbPP0/TdQkOMYHxJMb5jDTJMNbiiz3WUoNohzJtinGg8rtIx6ACHA2GBF8SOkI+rki00NYen43opIrh/j5OC8ZDrDVRLEQSKDrCrcrSOrxJ2hKyCUwmt1FKU90pSdqKOFYUXrg7sehiUCvy5iN2ui3GkyEVFa21NkUxwFNQDifoqMZe3NijRVP4CUU2wXcVZSbYG7tsxDFF6rl+dUyrY9i/fhVJE5RKCEEYj0ukU+Djkn4iRIcZ45HCeUcoa3+TgoBbbyHZLlGSYvOK0jq0qenrkyIntxalI3SIiFSMDwq0wbkxYVLSSSJs4TgYO4LWqMgwGZVsnutQDgdEucV7GB9M8AHOxpbJ8JAj7THacKbdwdqKarJPiCJ80qKVHyBSIrEhBEPcqhV9QwQjW6JtSbevsUd3cf4IYzS2rGHh9tmUL//T17l7zfGBT3yYo3FBu9vGZ2W9MmD0Euzslwo5hQ+glCFVtSwSorh9d0IcK378gS3+ydfv8uI7fc5tvMHZzmUS3a9l6RcUsFetjZe9FPwMjg+EGSVnztJyKwlmHi+Ukh98Evn/B5q19AHNnHaqFhY6Fi5s48+sjEJ1U4iam9Fq4W9myJoiKLBFiSsqHBUooagscb+WSwihaLatQZnpsH2uqbU6HF+WDAkr5IRwjDm1Grxn5lMrN/PeSVuOUW7lPVYUc/pxWDms4USmlcjyV+eJ8WS6OAuDedUkZhGNEodSgcpa4iTGliVajRCBW1nJm7sD4lRY8wUkQuErbFXVO0JhIfNO5fxlAT4L85mTEBCjMAkoVTORvFaEOEJ5VePtCkwkeJHaYU/VYookqvb/wOO8x6GogkJ34tomtnEfxAW8s2Aavw/vcWX9fqJO4wToQKsA1uKdxqHY3GyTGEdeQlF5TBqBD+STkrxsJN0NlJXFF552S9NONJNxxiTLSbst0n6LYKFSDgeoyOCdBxXIi4LCO3TUIt6IEXGUtiCUJV5pqsIRp7XjnwO8eIKqE7EWITUKIxHdXpda2hGkstjSUXlPSAKtJCK4Zr9KazAxKnKY4HDUPicQKLKidnZvaZQXtK2dEkVq6Fgn9d+zIjgjeFUrAqvC1uysVNeFnKtvu5L6vooIYmvDq0oUXilirXFWGB3kHN6+wc1rI9KkA2lGFMeICN5a0KC1aZhaU5vlxbMrzeyisQoOvl4u0MJhCbmzPLaT8PaB57e//Qf8zGM3eeDin10mZDXEYFnCuJqY4aWJMWHFo371GQz8aCgkrgSl8APqLn7I7C0zJ0yHxU2fBewLdAiImWOTLkA5nPDV33mdozww8Qo/KZGqYOwtITWkXc9HP/UUZy+s0ztTy+gASCSNFWk4nhSkDlq1e15YGvpO4bM64PolhtLx0L+oJHwvxWk5oWcIJ6YMeQ9taX0m/AnDvdMTxOq+y7QbmZ2LEBbebb0wKtTWx4GA1g7rLJFpMTywxLHD6oxrg4LvXss5s5nSdpaRjnBVgfOWSGuc9/iZ3PzxXmn2GcJ02SwQxOGqUBeAkSYEhUKD+NmQM1S1E+LUuEl5qatLH3CA9aGu4F1jFZsYVKxxpcVVHl+5RnNN1Vps2hMpj+BQ2mCmgn42QOkJLmF8OMQrRSVCHBlMVLsGmrTuXrQo8okhG1mMrumkcaIISmN0QAWLV2BdIATfQDG142GiNbGZ7u3W2mO5U7TbCeu9Fns3h6BMbfpEwFlPsK4hmQRasUGC0E77jPY93a6h17YURUWRl4i2gCPg6iVMHaN01Oxv1cwvGkjTOkdoHAbFBbStg7eNo7orEIcrLK6oCDoQDOBcvdluQFNbXOsZeaSu2hVgoqhOABaqylFNAsoLnY02URrxY3/qGbbW+px5UHNroPGlrVWitUZrTQg1fKWkTiazhV9ql8kpZ0pLQGEJScxoErh9VPDUuQ7/6m3H86+9yoe3r3Hhvp8nVoqizDHK4ENtHyx6MYmEOT14kYQip5WG025++al+94Xkf8vU3fecFH602V8myHSR7RRdqlAh3oFKZ2G/GhR8fveIv3V1n9f2h7gsR1yFEPChwiURT7RSLj11P2vrGtdvoZNpsq29DdRCx7HoUT5z92s21k+m1J6mAjylEIfji36n3JSwNC85vScNhHfpUORd65CTmWGLXddpwoxhPiNpsOd6CFnTG532ZFlGbkvS3g5Xr3+Bt27n6Mjw4HaPq7t7eMraCjc4gokaE+7a9tazsNW7VNXJjHGjBFAepTWik5qjq+puwzd/XaEQBd6oxg621iOWaVXZ/JkOCmMaEhpCsPXP15ECmpmNNwSnwBcIFqMgMhGhqIhjjdnoEUxN7VRJG5NGRAa094QyIK4iSiqyo4KoHYMydNdbUBT0+oo8c+iiwda9xVuP8wqlI4yJa3ta5v7r1ntcADEGr1oEp7CZp7feJa/8LLEnsdCKdK0+6prlTCL0KOfut8bovrD1wS0QT2o0WnuUdpReUZGgSNG06gAsHmlk2rXSBCeIFrwojASCUTUzydcsR3Gu7twiTVC1CGKQmoyhdLMzEubbS/W8omHtBsE5XVsXR0IQQTlBxzEmiti4f4O0rcncBF9UdYFpas+V4GuGlDCHSKd7YFPkKMi0Vq3XW10Dyw6ywK0QePxcwktv7fHlqwOefSIDRkCvhsWm52/2ELmlgmdRmWg+RQhLqMfJKMHC//+RVvQnDHN/EB3GSd8T3iO+9v4pqSsdyfQmyynyG8HVv6h1F01pyfYy3vjeDd5++01a7TaX7zuDUeCD5Y7zVEnEubhD/6FNpNuhnIyJkymcWVct08ogyDK3Qppkw4yb5ZdZTKs9iNQzlaXxuSxDQqcnkNPSgZwKnJ3+Kqe3zSsbIifeDO9P0ddaeC+6IRqo6V6NTP3DPZN8Qu5LCt/l6u4tdgcZF7dTzq/3+IMbe6S+wNgKFRtssxgqAvjQLBNNaRMyZ8aE+XByCksoo4BkZvQVFgoQVWeTBneeBpbGh0Bq+Ec3WwFMA1qA4JrErxWR+LryF4ULEcGXtVFUpIh0DV/F7QTTSSnGFl9YoigljiOiRLC5pfSWSBwGyyir0InG5QJOM7g1JNUtdKRZ69cWtdm4JFiPwtTOhTpGIo2EUG+Fe4tyntI7TCslmJRyd8TR2wMuPnGewtp6BuIsxmgUAVc5bFmLGHqf4ocHvPmNd0i2EjoPbpCkmiQ2aCkhuKZeTxAfo7xCeY33isgIkanN5oJS8w3sucY5edYUT76eBUSRam6fEFSYKzGE+RKsmjIXZyjDdJYBsa7vhXeKMnPkRw5lPPmRRQa27iQjhTa6cVFtzqmouiNnqmy0QMWddlYisyG8xzPKA1lW8tln2uweWF7drdgb3iQyt9DmaRJliAmgzUocYLYaIGFepM7JQn5JiW4ZWj75WQ0h/HA6kx90Mvl+uqM/5Oc3yD1+cBBc0FgHCld7PxtFyB2vDis+tr3FL631+eDlPju9Lj6KKDPDBM/obIvNs2tEAlJElJUH7SnLctac+lkwaW76dAMx+AWNnTqZhClOemJIl5Xu5F5Q1JzeHE7oFe6dDo53Ead3KfKuScT7k5YWp51AmJ2jafCQBZLCdIfEeTfr6DpG8dKtV9gbFGz1hMs9xWt3jlAiVNPL6+tKVUld2SJ+JQEvlH5SA43LchFzxsuSLP+JibbZB1q4T2H24IdZdSwyn8Ux9VWZ0ZENIjFK6vsfoogQdzl6+w57L+e1ppUek42HmKjP2oVtti5ZTKdPUXl6fUUSB0ZHnt039rj25m181qd/pkdnp4fDEOKYNBGSSIMoKutwVY51FZiAiaVeeMs9dlygopjBtQPe/uYt7l4bcPknH6DfTohFKKuCzEEURbQjg20kRybjirdeu84FuUCcBJyzeFOTU7KjkkRrOkZRuSE21HThJAEdgYpq0ot3nhA0WlStiTd9PmaI9PxezggY07ogyOz+yuIAdInHpBqWVf181t2NgJYaKkOoRp60E9X3aer70NgXzdPIQlcry4KrqnmvwYHznsIVJOK5Osi5dCYlIuHXX/4GH75geebi0xQ2kNtAojzRVBkDvXQOZUGDT0TqBcSm/PHBHSsDw4Kyxg8lmbyfYB9Wdf3Cj17yWmJtSXunMIcAACAASURBVJgJJE5fLBAovab0iiSU6HKM725irOMVa3j40Qf45Ad3mHywTdxLcZIigwoGGfddWEOlFlxgUkW4yuOoKPKi7kICOFH1kG5lTjDXuwrgwwITI5zaKsqJVfyiia+cIFZyrzTw3mgXq4nnvd6HaRIJJwBsIse77roArbuAKULsfJ2MPYJqKvlXbr9BZeHC2YjtFnz99SGtWJi4OnHoIOhmQVMBQdSqo9ZSMpGlPRs1k4GYYuxLV2mqSBwW07iaLYuedM3muWmKo6tmdlXbPouKmoDh68IjSvGmy+3vvcKLv3ubp59+nM3zmvEw5/aeJ9gu25dAdMLojmNja404HHL20jpbSY9WS/PAU2eIumsMRoH9/SE+lKSJYj2KGGcFBIcrc5zNKcuAKhWdXkQ3VYwnlvZazOOfusyj2xvI2RYHiSEJ0M49RWEZVYFOpEgigzcB6wPtTotet0Ovu0FsLHnpsEGTH5VMBgUbiaHb8hDqzjLWHXwWgRPEC1XpIK77uaB0nRhCI7Qpdi4hFMIKg3Cunba6kyvNNZ/KBmlVy+sEV5dtIXgirRDTsANFsAHiNMY7j/dNrtDzY6MWl3jD1BtHVqi3050sjw8lWjle2Z3wxy526bmIL159lY20zZPnhii62FDTFKLZpFUvPXCyYugzLUhCCKfaYNeFKz/EDuT90Lr+iN/juwaxcHoimZ0v35SuzVJaFClEecQJngiTO6JIeHgDnn/xNv+gHbMTt0n7lrG6Sz60qBKi7+3zM5++QBIn6MjV0vEUDVa6kBqmQ7K5ENbS0GzO1FqWHZkXOgu9xcJcRE6okeXUPuU0fRy5x+9XR3msVPWc6vU8Nw6bz4hW75sSmW34TytKHzwSVMNQ8SAlqT4D+hp+kvPVGzcpR/tcvK+F8iWvD3MIDiNCbPQ8eTVBgdBg2LPB+sq1kOVuQiQsJTuROd1hfu9kJkdRdxzN1Vli1ayyOOcVbJCa2TTfiozqxpmqIWEYgiQoiZiMCi49+zTVIwXPhad56V+/w2vPv8SZpx/iXKuEPWHv1piSXdbubzPRPa5cVqRJhxu3h6xxjp3UcLB7B0fE9TzQbrfYXo/ZG6ZUPnCmnxId5lR7GVGq2b91iFjHtS6UvT5p6yKhPORgckDmUny8zTl9lygYOpHmNZdgiiGVzfAO2t02JgrkdwqCitnot2kpjy0Uu9oQ97dJ3R36ojHqEkOXcfdoQBxy2jYQr8WMK4W1jl63VrkqvFtYwlu0Wp5ulqt3JaHPCVFNYdFI9NTQds2sEyWENMY7Zkyy+vVXleem8zxZSHALT3Cofd5jCWjxaAXWOW4NNTYr6bi7fPfGBhfOXee5jR5J9BBpZJYKwsUFxaWz1BCGpMExFgfqJ336k4btP3IQ1x9VN/J9dCZm8fuCb8yZpnFc1ZBWrAJeYnKliW1B3IFH233+4asv8T+9cJ0NW1EqT6Ehtw4Vp+yU0Nv5KZ66/zwXttZrXL/RdSLoJmjIMtEiyEo8P241uzoUXwhlK8F7TgWe0lzDid3IaeyIcI/fh2Pv4b1VDbJCR1z2M5m222p2XeZLU1Ms2jefpe5ACmLVp1KWohrznTdvstHKuLjR4e39nDd3M1JT4+GRUVRONzRNP1cSbgb40670XtdoQQhgClItfbRZUxvCwsedX3cJK8iZWsol1LLjDbwVpgNaDaGWylDYptLV9DfWieOEfDzh5ms3uPCpz3DhQ5s8/7mvMHZt3vj6m/yr/+sFfuGX/jS+a0h1wA4m/PL/8dv85C/+BL0nN/jev3iL7730MmlL6HcTlIc7dwf8wl/9DFH7PFGIGF094Gu//DXO7nR559ou5x/b4vH7t9mkxd/9336Vz/7nv0jy+Bnu/t5LvPC5t7ny+BMoucvB3QkSPJ/5n/9rDq5+gVYftKk91POjjMuP7HD3u0f8s7/z+1y8tMnd64dsbXb50H/wCcL2BlEr8Kt/9+u0EqHdCly9dpuf+LkPEPcUiMZWFTrSM9UcWTCpntcAMiM9LHP6l8iAy4lkJsHTLPo2i6/aaJRoVEvjrJ9vnItfmnQvamIpUbMbHnzN9qzZbXX3Y1RA64BRDm8db+5W7GxGfPRCxG9/p+Cff/HLPPcnHiLtP7rA3tRUzs+kfViA8O79DJ6ue6XkR18PK/wwllLeRzIxpzZcITRDtDrwuFCDpj5t4VXMp3sFo0sXuJ1ZDI6tOGYzhndu77Ofj+hd3uChSzv0ugm+zFFRG6I+jjs4p2dhqC6Mp9IKYVnI8AR21lRPJ9wz6HMsicybfFnxBjn+OsdT1mnqoidBQstk4ePcseVENGdlHa+IQlDzzxpkadgo+BrRtrtocXzj+j5Be3a2Yu4OJuRFLfuu1RwFn19TNVNSVSJzH4kgc2VlOZ5ElhP6omJAmNNywlybLKxcnqVB7wpRcAmeEFnSWAq+zjg+BCobIKtQDvKsYG17m/WHAuHggJsvf488LwiVQVlPt52y/eiTSDKAdszeQZfJuMIkNb23qjT7Nw/4xf/uZ+hudjg4mFD92td5+UtvceFTHyEMHd/9jRc4ODjiT/wnn+RjFxz7h0NUBba0ZJOS/to6R5MRh/sTjNH8xM/9LGJeBGv5l3/vG1z9jRfoPx5hHFhryTOPidrsv3abb/3WDZ77+Ef58E8/wLiI+Oo//iK//ytf5jO/9FFufvs2r730Bn/lr/9FNh7e5M3X3sa071AVjk4nYWwNo8LNNdoWb5cPs45gWXrnOD1+9oxJaAqY0DD16jPilVs4I/VrTuHQuhBRC6+vZnORqZzRzANdqRqLbXxspJm9xVoRGcU4dwyyCRu9FrEx9NvCuJzwhde+xSc/8nGgN4O0nA8NpXjeFS9jwougnmq6+0XPdzlBAJJjRev3Gfl/MN8m38eL/REmE7OkNdUYp0uTRLyzjY5OIGhBJREFoDuaRx4/w197+Bn8LUd2fUIxHOP9GPOZbeJLfToXt8C0cUWBnWToXguRiApLsBEiCqXqh0CJaYJbqJNKUAuDMWb6PTO6n6iGMRRODeZL1/8ERoIw32w9eTR+UjrgWKu8egBXvd+PKwcvVkfztnq+CzrvQBBVQ1BMbUdrxsmUQi3OU9jr5Dbju9f26fY0O5uG774zIBBoxXVynhLC1IKC3hSaUosJe2kYe/I1XTIfm+35yJK52CyenXJF68855/5PF83qzyhLW8wSBFRDvg71jgNUtJTCWc+t16+zHvZ547U3uPv2kIeeuMTlD9zPrVs3yLOMES02o4hKAs53CUFhWqCCYTjMsKXFJ5pwfh2/vkannfDCl17n/Mc/Sn5zwKsvvskHPno/7SsXGITXsUboGUM3xPR6Lcb7+6SXuuztHnH37gB6XcYI4it2rtzPi7/5VT7x+LMIBltZsklFFLfJDvbYe2fAp3/uo8iG46Dscu7+h7n+xucZ38rZf2eCFrhzMGJsL6IuPE6S5GS7Y9pGUyWG4bjAusBaSy+c+XqDfyaYuETjlhOnirMh/JKxXA1vqaCbuaWaNSvayMkV//QsyVywcX52QlP5q4YuXp8Opep9HRscRZlhraaq2mz3hesDy+devc5Tj11no30JpD8rKNT0nIS5nl7d5aqF53NaqC0vKsoJyr9/pFCWyLGBezh1NPIj0C0di5/H5ztmmSk0r9VDcARrcWVVt7Z9jW4CfuECqmX52neG/PMXb/Dl1+9wJJpOv83TA8tPm5SftgXseNpi0CTQDOcUgdikxCqjkoAWXVc4KJhJGUzfS8Pe8otVjixVxcv3Y4GF0mSKKUQUlkZ98y3u+SFbGQ0szVoWCAksDzJPLilWvr7SMC1u/k4H09PXnmqDyfSaSLMMF2xtNKZqVoqiwrucATmv3Nml1wqc6cEgK5nYUCfphSFnLd8vtRyHzDuD+fVcmFMsaRsJy9bB4US3h9n5kamU/1RIWJa9W2ZJc3Grfp6lZhJfSxIYTQJVQqwFoxUq1mituPXKa9y5eptRHtg4d5bOxhaddhtsigDtxFKSYEMLF1poo7G+IlWQmtowS0JONR4SmQ7tzRh91ZBIl/23X8U6z4XHL6LSCDXKMFpI+33YV3gX6K8bKh0TXKCVxnhfkGw69t4Yc+XhD/CNf/MVWpUnxGsEAu12l367w+tvHbJ3Z8BbL7zC+HMvcmM3pxiWVL5g7/AWVz60wSflCf7ff/BPuf9rj9Hf2eETf66N2eowGXmcrSdHWoUVaEaWoC05UVPqNCvoMDd6g3qK3lz76QD/uIuOrLANp0lFLSUShWrYVNPlVU0QKFztLxNp2OwItqx4Z3+E0S0ubKYc7Cf81ne+wX/0TEmUfLj5UR41m/DXe1Cz0iysli/q2LM9nRnJe24h3i8F9/0lk/BDnq3/4dhmy7HQHKvFFxwDva+3lK1zGDwqWCIdcXRU8nuvvclf/zu/x008PqqDXVsFXvoDx698IeWXzu3w5//q09y/caZ20gtgqzEShMTEGGUw0gh+iIYZjKMaGsh0SNtsTM2qHLWwdR2WZw5LsgzNLGGlA5l/RDk+5Xg38bawmolPcWcLq4nk5KXFedUW5rlkYegpoht4q2a34UF0qHHpUJFVY+76nNdu3GFnTdg0jhvDnNILKkBiZAn7DqHetp7Kx8xkURbfm8iKZPcqIybMOqT51TveeekFEE4Wg9RiBTzlaclC/l1cKpte76ZbUUqIjBBHiqyosM7x4FOPkD57EfKC7bUume8RRxpXGpCA8QOGpUYkAV97b5RlhZFAK45opW22zhiyfITOLaoV6Pf7RNJisDsgjmM2L21TlRnF3hFOtzHdLuGwJHjob5jaNjjSdLop44M7EA9II0OUtiFA7BwhXkOAVqtFS6Xs3TxCRBhMMvKq4ImP3Y9p9wmdjDK7y30/FpNsnefchZgv/dodbr1xnYefepjuxbOMixquSWQKUy5jhUqWqX9yUqJRx2HLGQ4vc9XpRYWJ6blRixOyxSH/YpCWFfovoHXNQJtS+UMI5Lb+Oy0jrMdCXllu7o85v2U4v+Gpyj5fffVVPnZRc277KbTWEGxT1C5278tncvaewtyue8rfkHeN/HLK1+UHk0QW2Knh3zFBrmNld2A5kdR31s+cnJQRNDHeRCgX8FlABw9rwlZq+OJ+D93u8xfLwP0XznDRjgnFiKs72/z6rQN+9eCAz4yFKy0P/QSJFEKEqIjgkmZyHDU/VxClMQYcmuDm8gd16zqVflTNgzMVZ1vg0ge5B9NqiQg5IxOEZk5wsgpwuAfvanGaEpaSRzjpMAW5N7l4KlvcsKKmwT8EQat6CdHWm35EWlAGBqOC3cmIGwd3iVKPUhWlq4PrIqN2sVqt5y5+SQdpHnROGbDLKbMnFpZGp7h6WLjOwrHPKCzbGUsIS2rTy0ji4j6EQKiX36oASpW0Oy3W+ylRN0WyA0QLk6wk9yVHB7dQEcSJwUmopUaikoAnm2RUZUWpLJUvyPOMvb0B8Xof09a4oeVgMGBgx6xfOEv6csL+W7ucv7BFsrHJeOwpjjI6AYwK3L4zYG3nLJ1OizvjIRIZyizmvjMxz3/uO6TdDsnmGsFWOOfI8xGh1+bBJ87zxrfHPPOTH2D94lniTofJ2FH4A4qxkB8JJl3jsY/vINFz/Iu//49467sHfGBzC3SEGAWlrTfFlVqJdTLvamX1ZMsJnfc0f8z3wqdQ6vI8ZYVY0vDST359tRRapEl6SjVnsIHL5l+fhoIaVs+qisNJxmYas6s9L7zzFlZf5+LZFtqvLS3lKh01kktTarGfLdPOoOhjEFdYQgLePRuc5KX4/c1DfuRov+81eZw8bF8Y4oY53Q+lkEijfKir4FGF351QXhuRF45XR4Fnf/wh/tKFiPZnL3A22qC6lUM/Jftff5W//fYu4yoilB6JNQiYYKgkwlUxwTtwMWhXy2ZojTEK72pXvqCa5aZmMEeoN6PVbEbiZ0lo7tsh8yB0IslKLf12yo7ilH5h8ZAvYZYhnJh2pnh/WIG4Fj3lj809qWdSIhoR3/xqkmsQtG+qP9E4pdBGMNoxKDOuD0fc3b1Lf8vgqpKRrQjBY5Q0TofNVvp0X4BQj+hPlb9fnY/M4YrVbf4ltp3IQtW6DDvKiv3c0qVUCxw7tZyIpwo5YRYMajkQj8epilAGsmxCTkXfe5RJOBpUpBsCKSRdxSQr2N29S3vdoVQF5Gij8JWjCgUS1ddkb3/MzlafqK2QApyvGPsj+pc3QSle+DcvceXRM6Rnz5AXA8qjMb4QjBI6WxtUg4w4TcjykrTTJrDGeHefG9fe5pk//lGOJKI9OUAUHA52eeedPdYubrB5do0XvvolHjz7DH0V2F5roUdjXEi5+2bB2tYZbHeDw1ZdzUdxSrfboswFZTzO6SXBTZBjc6yZJ9opnckxkVMWDdaWd7fC0ustWA0sPgdLc8I5cWKRwDEl1iBzxCD4QDn1i9dCXjnKwYTH1g3rvZSXr93GmBfp9TfoheeWhsBK5v3v7CqI1AxUFsNbDY+GhQXGkyu/01ic90gm/64wsX6AyWMpkchi0JP5mDQ4V6u8UvspWB8I7Rg3mbA/HHIpDnzrxm2+ee4KfyI+Q5ARu5M93npdMXKwnqS0NeQe4mGG7rcQ0URKQzA1lOUFCQmIR4tCS4xSpsbXZ4PyRqRwllCW3dKEZg13kZHBCbOh1doiyIkyKbJoPKWOB8/Thk1zvCAsi3t6WYYMme+FLCWjZvg4+1RSQ1um6cCqUFH4QDsEDI5hlnN9/whJQLIjrK9qy9cQMFoWBukszEDCAsJ9kiTCCs59LPgw0wg6pmUWTtjvkZOg4ZMVAZbU/5e6nynhQuO9p9tWaOO5fjjEijA4uMm5x3p4ibBZWZ9dXzCcjAlK2NgOHBwUbG1ssLUGpmXodRI2Yse3x0eUtmT7wW1sVtHveKxRFFVJakru++RD+KtP8Du/8kXe+MIrjLWwdblPer7PoISKwGh/wIOXL/GFvREhwEu//VXi9SGvf+llxns5f/a//zleObpDvxMRxYbeZkLwFcmZdT7yx5/gt375d+mbimE/5Xul5bXvXOUzv/AR7lwdcvXb+5zf6PPWF68yGg659IGtWoU5BPCC1lETSO3SLKDe91HHCxZhYVJ4PMkvqliHBbfReZE0p3nPKCor1rJhaQv7+HuqO5GFsyLzSYfztbsiIljrUEoxto61FPZGjm+/823On13j6XMfq9lbrkDreOnZr+Wcph2uOoYsL6tevBdGUjihI/n+k8mPahIR/rASKat+7Y30QqimSqKWYAOlMbhOxM7lHdp+h4996y3+6Vu3+F9eucY//ke/T1cbVCvlZSk56KZsb29wpq3BKNwwQ8UR0jILmK5BgkZ8DXMJCq0ixGuCb4bsUzrhFNIKClGNThRqQfhsgdjXVDWE4yP4xY+qlDqmVCCrD11YfPVwjCQcwnIVNKfpCsfMSlaYWktPebNDIY00jMw+Ye0yVw+sBesdpXUEP2FU5AyyjO1tg9ufUOHJm84l1mqJXjuFt8KC9MqxB2XhqVayCoEsKh6ok5PrMerltIINx6/tMvIxT+K1kAHHqA4CwdfztEQHBMvm/Rt85j/7JFv3pZikhS0DJopxRQUSOPvgJj//Vz6FL3Zpr6dIpfGjO/z4zz2FDhD2xzz0449yZstig6LXTcjuHvHoxx/iyocukLoR17/3Ehc//ih/4ZFzXH35baIio2U9caQY+opf+G//FL3tLcR6zmz3eeu7t+lpxe139rn/Q4/w2HMPcaAHGC1kRxX/8X/5s+j1kqrIIE25/OEz/PzZz3LjtV3uXt2jt5bw7Mcfococ690WWTVm984+T31sh2d/5j7WzySU4xxD7Y8SdNSwrj3L0ifHh8lqxc/jJP/zGbMrhAUiS3P6JTTWAnPV4FNcz5etQlYKikWGmCw4jVq17L891Q47KCzrLce+Mlzbv8pbt7s8tVOflcoWKB2tEGLUsiBieJdRR/ALh3Ml49xrUP59JRH/Iwdryff588xcNXchmIggBlQKSiuC90TGsJEa6imG51ObPf7y/Rf519f2+J3BAdaVBBwXjeETScynHt3ikU4tjpcVzUKZc1jn0bpuRwWDwiCuPvyh0VhSU4qqqrWW6halloWoVSHmQ96lyn7q8x5kRYJ9WS59YYZ74uFYpA7LibOWe1CBZwvezfsIYQESOFngZy4PLyh0439d/z639Q5PpDwbqXBYDrh1sMcoG7LVF3SoyINgme8MqBXL5NUxh6z6RRwLOAuDd05yplsUzVxZ0Awr127xIZV7ExpCA3WEBerw9JV149RponqHprthSFsaEzvKzNV2w1oRtCAqoLc6dHsJ7XXF/rDEaUdrI2Wze5ZOL9Df7pKePc/RxhGi63eS9hKK2BBiRRwHdtZj3Kjg4uPn2NxOEVeiOwKpRukSXEwllqI6opiUdPotnvzJh3l85xFG+wM6bShDgS4mmFabrYfWcWrIpCrxtqJKFWceXOfSo9sMcstEQGJF3I5QwbBmPWqc0ZWCQlVYcbixh2BRKExUQ8a+UscYWUpO7vsWKeZLhUyYS70HWdZ7mz1rjSrFcnGxcJ+mi6RLJAo51hnNN+JlYaJSk0im73t6PovKkqmCTtfgXc53blqevvw2928IY7eG9pZIxSuJTK/MdOY9lhxrotQJCeRdhu+nV6DvL4mIfH+JJIQfYgJZLhzNMUbRdInJRLXPQOwhOGxV39REHCIVZy4q/oe//Wn+wu2Kl14ZcMsFqtTwRDvi2X6CPpsg6ZhgNaiI3Ifay6KyzYGp1XMkKFTDzPLoWvJ6Ab6SUFfZU+ZW/eQs6C0wZ2UsSkHIAj67POxmJpu/apZzyjbKKXsj88FjWN28CyssqGNkDVku3CQ0AFatoVlTUuuHuAyB3DnWtSM1Ba/tH/Dy9ZukccF9a7B/ZCmUaWQn6r0YtaAMu5wMwkp/H1au1zL0sehvv0SPOU4XWD5G9/CslhWqwnF0UJbmI9Nrq7Q0suV1sOtvRhAMZV5STAqU1pioHkKLhqQVoYJHJQp1eIgPjmS9jS/bjLIR5U1Hp7VHfLZPKCZorYjSGB85fFRDjXGREa+1ORgNSNYitDLkeUFxVGAig24ZcuUZZAeUkwprKw7zXVx5ltJW2MMM7wti8UT9TdptQ5VH+ENF6R1lWeJjIVeCsxlqMsFojxkpXGkonUFSTdFS6MjUu1exJWQWow1RY0pV2Lml7UkrsDNSxQr0u6TNLgtn49jgUGbU2mNQp6ycBjkhycjJZBNZQJaUAh1ULX3v599TVZZBlXNmO6avU168oXnl5ktc6Wkm7sO0g0V7jVL6xPcFtbp1ODFuv0sgD6f83dOk2t9Pp/KD2FsR+UMlE/m30O0YgiN4QRp/iUU4w6AIlaUsPbHPmYwtmTF0SsVkp4+WEefOdLkvSbCjimxiafU0tjjg+vcMm4+uoyONSQpM1MIGh9UNy0J7lEoJ1mMw4GVqkcEURpVQU4ElhBrWaobus63pMB0mN0tIYYEnHk44JoGltl4WZm1yyvESNZ8TLEu9y7ISyEpClmMccZlXYCu8gJm0RA1mNckzIMo3syKHxBX7R7e5uTtimO/R6iZgq+Zh1IgojArL3H01h9mWRv1yUnBnZT5y745kNWmKvDuNJYRjSknHIa/pz5WVdN1whGsxV8GrgFK+TjC6DiTSMMNUEJz1VD5gBNJOq4ZrfEE71qSmQznxZIMBUcsQicbagMuK2vDL1z4vXiAbHGELh/UJURrhBII2WITSloQIEhN44JkLtLZa+DCh3L+FVo44Fbxr3ANdSVUOqGyJGEUsQqI1Sny9ExRDpQwBi9WBoA06pIgJtUWuq8+3EpBE1SKWrppvsLNYEAnHFgxPgipPqjBnXfNc+2F632RJk+14HFuVK0JO18GWxTMhU9HI+pn2M3a/orIeGyqCj+l2Ozx0JuKlG68Tooofv/IY4hK8FhStpaJvViCG5aLvOAR3GoX/1FLndDZwuLcd66wbEXk/3/YjAV29xxlJmNM1F+U6bMD4QFoEbr21x1/7/G2eON/nl2LLP7854XO/+RXuWqgkQiUxUWKIJZAfjeklPf7K3/goj1/Z4kK/3bC2IFe1VhICRrUIZYamZmp530BA06W86SxkpuSimsVdmbWqhGWpclnwJ1gNcou6VTPee7hHjSLLVYkSqbWujk+F60HiUnWglrHp2UuqOatpyn0XoX566r2RugKvq7JIB4yzFJRcG+6yezcHGaFjRTEuG08Sg+BrG1oJCyx6WWKrnci4WsGul//g3Y6frDZ7xw7tkmDe6gZ1OHk+NdsrWXodZg4DdQ1Rm0mBEMXxXBo81OSLonJY64kspGmKLStcWRAbQ5zE+K6ncg7nA84LZenxvmqWJgM21ESTdkvT7SYUuWU8KNHaYOIIWzmsdRgcaaR55BMP8MHqCnE3+v+oe7NgS7LrPO9be2fmOedONXVV9YRGD0CDxEgCFAhZokSGaZqURVthUZYZsoOhFyvsB/uB9osjFOFw+MFhvdLDi8MOWSHbNCWZJk3YoCwiwAEQyAaJiegBaPTc1TXXvfdMmbn38sPembkzT557b3U3gEZFdHR1dd17z8mz9xr+9a//59aNQzKbYY1BszyIB7p1UH8QwduMIrMUVtCqplqsEQPWCLUqtdPOxMyvEVfSLPlZC6YQnFd8HSXSTZ7sJA0/hW3b3CMwq256jqZ0b9U+YWJ7Ujqt5u8P+6UDQtqCsPG68erxClWl2L1dPnq14HMvXufGd5d8+sptnDTdSEEjodJPJukl9z34fsvQZARd2IAURv/qZtUkp85FNpDx0cLs7XUl8n2cs2QyMLUaHgyxGfnE83y1y79YWC65muW5ijdfXPKnJufQGjJj8BKYVWXtkcmMTx/ss1dfZOoPUFdD5llUFXmxT7muwU3D/EMNuPCP+oaypwl/yXYPRVMvsZKD0wAAIABJREFUju5hmd4Hn27yDqi6OjY6355ExgqWzeW7tNqWEy6NdOqq7SXyvdel7YRAgUmwi+U2Yu/x4h3l2WtzNK94cLfA1I7jOjBdCtui26R7/I0KawpDee1sjMfPpfSrWBm7aNsCxeatGBvqbosybaLfmK+kC6Uhy5jMYHPL6rgkL4rBcioYa4OlrIJ3irFCtpMhBAvfYDUcyA0mix4WLjgGigTPeB9/nvcg1pIVBmNsgGGstINp7xxmJ2cyyymriha3id2sRcDauJsRSSOxYlZjWnq8tRJ3qII8vDUmEFKI80GNsxCJK30RBhwO0vtBRAbJg41l075lSKpvQMJClFbpN13mHZ1pa/+zHA6ypdXUo90vajx1UkqKCBRZuPdlrRwtHbtFxUPnhJvrgt959jl+/sNLssnFNomISKuu3c7vxHWknVZuaRtBS/p2GqclCYWtnk6qo4XWWUYc79SwUb7Pw/qsZyaQZljfKWouDfzVD53j17PLXDk/Y/LAPv/+08pf/2s/TgVYs6aUKZrl7JU1DxRQ1Te4+sQVjAnD0Foc83LFxd1d1kuPd9NwMbBoLTGJdNVEl06i3lInLdvSEbs2M9WCMr3k0Qg9DibKvU33URiUscPU/RyvQ+ns7ezBVCyxE0gMUIGPWF7jWR/c8hRlBhTkUuO4yZs3Zrx2u+Tq+ZIHZxNur0qWVUg9edTDcwmDqlFeNYkSgOKxzWZ78pQ3HkKrmbRNVXkbgTH5W1tvgpyGgI2rsUrofnzUXrHGkuUZdbViMg3PsQ1wMSgbK3gXKvd8YrFFjis95drFpTuD2HjGjEVt89+EJVwXaOkQdhtsQwYMIrSICUq4vlZcVeNMTuUU8hxvBItpiR8my4NJl1OcC8G49nE4YExb9WcSvOwDXNmc56K1swXfBi9rmrtithYDmwBm2qGbkeJWRzqXtLuUXicxrMyFjkCsJErW0p+RyWDw72Mp5FtsO6SUIjNYMdS15/BwRX6Q8dTlguqtKX/44it86n2e/f0fH4Wwmw9L0YSUOOw4ttB60wXZsePbnm89eU9xQ6pPzjwnf7vJRH4Ai4wZDe2uocJ56Mw5FaeeWpWJsTx1fh9TTDl/VJFPCx7an5HPa9jfYX63ZH644tFHD/C3VnxuMeNCeY19M0OKA3IxTPwOqOKOdynlmNwZpJ61suZBDqUxvUkAmqQ7UHUMG3BJ3RM1YW8NB+2DWDiUTUkXF4eLVm1hprr5fUe6j5HwGPY6NOyIaLs5TFuBmlYsr6bynoWWTLM9bs2v46sZe5MJuXWs4gBzkgdfitJ3XZpJKs52btDCaY2Olm+dKcdvidDvVIdLWeNbH+l3kXH7ueS3srUwlDHAuFlSjFW4c0Cp2CyPFjodBOO1e/3Whi/0XtHS4V0ild8bCwQnQGlVbgm+5xC03hr4Jfp02CjRbrJwVpyD5drhaiXLbG+Tu1f/S9BBU1WcTxhFIogJzocmJpCgvA2CDWZmogH+HAZ91RPCSHJ/RharNqZkrbK2jsCP4wbVPfsoSZXtaIN4f0YT9tLTbrm11TamP4s0AdJT9agvWTtYkzMtci7vF3zt2ps89fAamAE1+ByJHWi4EKHzDAbVY0XTQBXjtACvw2RyRkTsvthQPzydSNKRJC/ex4o4Vn1ehFIdXqE0hkdnO/z5Kzc4/Oq3+U3dZ7XO+DvGs/OhSxxMhL1lxddfeZN/8tlv8xtml1/7G0/wmUdyJk9nUXkWqI/Q1S6lsRTOgC/iIQkXVlUS/nqkBLdzHI3DdhdlOKJicFqTaTcIl9SbbzDv0OEIMm3HVTcssTRJIKmUYzszEdnue9+GEtNBdBK2eTsfiU7g3aNUWnNcr1gx4fU7tzEUXNmfolJyrwzb7zMbnA9L57pKPlH1NTGJmHajP+D/vvVwML1dmDF5bdmQT9E2aJ/sw7J5aVO3kzFYRLYOHMPXNnLgPuZet3YUk3zgCNh9hRBIJCJKXTmqtQvW8abZUdLEVyNd1JNEBynOxRqFKO0W9pDAJMNDXXvqsgpqtpltxTBNci7UayRH+ShV03wWYZHPxs7ISqLWEGeAVsJZ01bVUtrArr7eLAT6Voj0FxJPDj2akkm2kShSBp8Mdn5GTeX6DqDtSnF87p5g2mbEJ/I6jVpw+HPRmnVlubNSJjl88IEdnr/xCker2+yKMskK8Cbu9nYdg8YObrzCT10i38kvbe/1WTqNdzWJvE321rubSBiAkj7oPsWOGzFQeaW8V3F8c86vvbTghVcWfGWxwNbKF3JBbt9DxHNcrbmjwu3aMylqinMzdGdCuaqZznKKzFKrxWtB4Q21t2Rqoy93HnYoGmPdZoiujUNJTDa6GdA2EFjtAnSzGc0Gy1lO+IA72qmOsjn6yagnyyKpgVNfiyssJMtgTKBxN0YJo1uL0wy0xNQL7qxe58ZhRZZ7zk0tR1XN8arGimIlYO3By5p2h0QkUIC7/05bKrCNCOQY22CD1bJJK5EzyVtvqBq1M6u2+NM0yOgoPNPGTW1c9qQ38IwCtQx57eEZNFpgMY2bFNaJWm4J00kSxVohzC9UW2eO1qcDNNJpTducmtDCYDLTPftYDLWbCqmdcPxMjHQLraYZsEs873QCowEm0ia39MkIA4gqVSQYCjqeZJjAtoQ+puiw4Z8zPj2TodhnQkVJfVQMgpo4fzEdMhDsJgRfg9NQEJSU7GWGPF+By/jCt77Bj71fefzKL4IaPGXYU4vdZdYWDoahGvBGIE5joepJ0n2DNkQG0Ph24OKkPa6334rI9qv8PfnVLyqy0fhhTIsTWRzWKIel4/U7xzz71l1ee+sek+MFtnJ80xrMWwZxa4yrWEmO2T/PJ/am5FcPONyfsLeqYJLF4WMGJmfihKWzYYdEcgxZ8D7wDuejuFti09nU6kShxnQepsOg1WtVt/Sc5mTmhaqcrWJIsbGRnZHhf3pH28o3EhQmQt8O8DKJs47biL/DrbsvcFzBfubZNUuMrigr17oeiliKXHrQg6omEvHautgN4bvh/ksLVPRgYu3tBujw8pwYkmBMEYDedGlkOa4Hj3UGWo2Jk2i336I9TDP5mYlIpKrGIbrpIO2eDAwbUvoyhHqaJBO9xtu5TezurG0G9U3Ckpau29cYiwVKnPmk3Z2IbKorpCoLSYBLn7NnzLyKzfM4WMzdoMP2iqS0eNAT7oX25h+qA3hM+1mpe6/90+PbeYp2dhHQzhQrY6i9UteBSj2dQeVgJyv40xe/zdW9uzz+wL8F4pnXSya2YCLTJG3ZLomMiUv01BtGkslYNjhLcE+fp/QtGd7NJkI2a6nvUz4JPzDr9i9SqqhrK/9aw17Dpamwd2HKf/DwHi/f3efamznlUji3O+GRg4Ll8RHLxTFZscfVRx7gY09d4iOTFcV0J3iOGKGuHMZB4S1rn8Uhuw2JRPKQSNTGjiRKg/jEaV274Xor8Dn2wQxhKBlhXjnGd7eS05VitWOGajKoziSVENH+h+u12/VqRW/x2Cgg503owDJbYA3cmCs3y5e4desa53cnVNWcW/NjVnVFZrqsYI0NezTNcVUfNsQllW9JsGzTwRatxW5PpI+OASUdc0fZIptyKiDcQTBDZd+zIcVJ1SoDB5QRzF6V3nZyY8MqyY/2A722TVgoSSKqSZcSoKU+1bsvj2/alQ5BBrL40CzaaVTB7Woe4ZSFuWbOsIk3jcB6Q8xQBjDtYOieZO+e0sUw+etm5zgs4qTH2TG9FyMynIRrssTYjCukm/U1xYCEcyvWxGrLsagrvFHEwqxYc3M55c3jl7m0K+wXD4e/m7AXO7mlQfE3HPttJA+5j0i+PdGImO9ZjJdRMsD3uBvRobGVbkltkTaJE3JvWe/mLD9whZ/70FXqv/5h6mMHRyXTbMFsVpNPC0w2Q1zchJ9UHJcVhVFMHqCXda1MVcjJWKklrwP+qZLHxcMwE/Fq8Ml+SP9zNdECWDc6k9abXWWrB8hJh0MHv1Edbzyg2d2UEer0QDZF6UFbzvkoi+8xonhRbEvGEYwKqiV3VzVvHL7G0dFdHnngIa6ta27NjzEiTIs8PAfC/MPGrV5taJS9BKK9uWVHP5ae9ShRGzhUy759nialgW6B+GR0wXCE7TaswsSMqgZssLZ0s/npq81oQpzQtlPQyHBqQgmxUrYyGK7KlmGrdF1C2+k2ulYxyRiRXgdlBvBRC632jJ1Dbz3GjBaVjQq+K4oaqZK+MKjZGuzGWVsnDWalJxnSTxybegRKr0ZopI02elF6NgKd2nB/eZch3ChdEWnis80lgH5r51hXnv3c8+AFy731Zb743W/w449OeHzv0UDcifR61X731P043dTs2ViBP6vM/AndimwAgz+8v9SfMCNh0zecpCqwothZTuGVyisXjkuOdj2f//Yt7jjD3nSGt4alXzKZGFi9Qb6c8K9/8hFqL1BHyqYNFqdOcqZaUFGAGpxTXK14Z8Cb4NFt4xa7jldhLTjkdUMJv88FH8QGM36pdJAxtA3+yYDYdAdNvUZ9ywZ6Mb2kMbx4qo0ScBPcTdzWrnHq4sE3rPUeaz1kVd3D1UdMdhylOwbxZCYPiYO8wSAx2EAzpXGHaxwQw/Zevyjty3v33KTiawrJqCMxjPMfTRJ0xhKznql8GvlYt6f9DQqlDnbDNmVfNOXxJ+rL/UJBRgKq9IbZkjyNPsauveebypCQIG4piaP54VZIusgxoGlI4Q1kk7H6yKsb7+Vk/Dsich8D3v7ej+rmn/X+dgrnqIwXF5p2Jzr+o6Rf0Nm4/KqRrl1qhdY1uzNhfyLcXNzj+r1vc3U25fH9nwCZxc/bhrgitL4t0vvJfRHTTer5NjWH+8WcGJkZvnN4S076H/r9SSK9RNJ/VaatesSHYJRJiO3HNeTXjvjCq9f4L//xH/P6Yo33DmctGIv3FWa5ZH9yjsf//s/x4EPn2dsTdic5eRYc0pxkFJpRyhSvnroKtEnnBN92Ic3CV59uqmrin/uu6vGbqp2qMhqt1CeDyKTVST1EUppvT902qWS66quTm+/w4UTF1CdcpUivJlI9G+Mh37C3vOfY3+Fu/SrrqsRoxWxfWFTHYCw7k52YjKTd+rft78c0jcYoUtqrvDeHfg0DLgnMOjLf6G0ID3/s5uB8VK/sBPhg26Jjf1bT5wpokkBI+HA6gL5HmqrRACy6WUqGYN6ZIm3AQwzZSck3kP5rbOdNMlwkHQ9aRkmSyemSJyKMdoXjIv6n4+BD+GvsZ7YFvcrm2ZNOWThN9sPBonbDTzruVhiaN4QIUznUO6Y2Y5LnlOt73LlzyI07U+YPvspe/iAwCx426jEUo2fTD5x5fWIhK8MDxqBjGcvqp9qs3tf8/L3Shpya8bJmsc5sPIAYJLIE9lflXBbYE//yjgU/5d+9OOOa8ZxnygenYQP19lsv84/ygutOeKosKfICK5b1OkIl9YTSCoZdquoIJXYlLsA16huLTNMLDKmxVOMFrmkC0X4yQWX8YpohvtsF/85YqQ82Np24EY3WtzGhGEk6YkkkHjo5ldA1dWEt2MZajM3wGmQ6BE+ta27N7/HG/DnK2oDM4ta1kMmEwuQ4X+N9FV93vFR2ABEMTmG/8uneT4f/b4/xZxO6SxV+5f4qp63haPt30QFXggGu39uCb/qsllGn/XnKKcmk9xxVexDiMMGlb92c8hy8+o38Pq6H2M96MnKh9ZSnPZo8RO7jU+qLc/Zf94hcypCOLWY8EA2H+22S9J1vvNISUhp4y4ghNxPQgtrlHC4yplZ46ECpqynPvv4mTzzqubT7MYw1rOo5RW4T421tZ5WePt/G9Iy+BGFLB9Yqjet9J5F3q1mQ70cCGRYS2xKJbv0GMQgbi5PAeVDn4d6aWpU39yf82I8/xH/21D7/2/V7nL/wOL/8qctM1jUvfemb/M/Peu65ir2FImaKkZyqhkId1DlLlMLvUFXHeBVqF5a6vCFCWqYVZuxB85ESrAke65W+aqn2t0dlWOjpuFNcM1xX7Ve27d8yHTUZuoTSX4hNdlF893rbCyW+/dowgMvxpkK8o9Yjbh0d8trdl8hsxt70HNZnZFZQyVFrcb6mVhf7kTBY904HsIWMis51w3SfDNF19FnI6LMaVsAnB4e3ddL1lIs3gDG30k7bwbJudEv9e+EHXyvbKeLteodugKwMLA02BTJ1y3tMXs/okrSc1rzhnTs5cehIcXGGD2cjfgz+QFW3dzy9yt2PUSgG31bbLi382/d+hqBBBCUO5K3NEZkwX1nq0nBumvPA+YrFWvjWG6+R7605yD9GVkDtHIV1YPKWiCEDE7qNPUNJ78eI6OOQXfBuD9B/YN2InnAATkgksiGipxvYXlP9iQNKR1avOGfg1s4e6+mMWV3zudWcB254Hr2x4mtvvcnOouCCeYyj6Q47WpCRMdsBWSlaBRqfVB4xGc5J3PSu8RqOkMauQCNzyzQMoiaRJBevt0egiRpvCnNpNzxNKYy9HW3tX5ANqqMPlrDeNywT08NMmq6mo6lqBznFn+2j50rowBwmmzLJC2x9C9a3sfUK9Xeoyam8oS4jRVQfgHoPr0tU70WaaZDc6I22dIt8fZJKVBPGTG+ItKmtJfL2s8Hp6Luc0ImMzF1SiAk5uQIfU29NN+vZ7Ex6FFo5XSRJevPFZKgsp9WNm25LPbhqpMo96Vm6NJFsaSVFuK8ksvXV6gmZZkg80bF5pGz58qYi820y6boSxVjCUmKEmowrEJlQ1TneWY7WhsoX3FtOqNXz2HxNdlkRv2JiStQJTrNAzTadSrgZwFl9go0OUe3RuuCdRP73wC7h+Bu6zxeV9Sjl7cafp9PgSh+eIloCNY/v5czP7VFY4VN3F/yDl1/lW39wyENlztfE4IFHp5Zyf4fMF0xs0ITyRvCVw5WKrxyFzUInokHR1atH1eC9tJLyGi04W+xVO8G8HsKgacUogzlJUnHqthJPotTImA9JwMS8j4nVGJyLOwNNReUHlaWRntKqxi1zJWxCe1czyXbJs5zM3WZV32a9mHPv6B4Ow3G5pPZCXYPwOgaPeEV8GByGDW3to3ppJzacmej2QNb3UOlf/K2K2icKODLA1U9jwmzUqSN/sqlOKyIjwpAn/aiTqmq2+m2cVpVLIkD1dlOvbA3Q26t5gLKqT076Ilvj3ZDwIGfqTnTb+IQTfTuGa4ljiaRt8ZUUaw7ScQpSoziQCeiUjCkZGV7u4fWQozLHZBf54NGTrI5/mmJWYLMa1RxXOyS3gTVpElq59v1T/ID9oCMyS+MzvHenjTjTisr3KoG8jSTSDttTRYZm6UHQHkHF1Z61B5nOqC4ZPmznPJgXPDDZ4dxjFT//woqvre9yWwxPzqb82GMP8uSVAjOtWa5WuGxGJkQL3+CUiPeos5hoWOSpgzBfKyFNKxFh2hZZEvn4fuBMzx+9gblJuo/BITamq1C1N+MbQCMJ+0qi+ZaRwGuXYRKLjDdtfkTUCxKLNxkqBqol+BKxYHaVpcw4LG9y/fAWh3euYYs9ymMXv0kdSAjtPkrYtrbGMJ0UFNMCAZzTFvNtlxLpzcxHpg2DKj6WX60USUMiHlbt+vaPrcj2byHbApSM3zTnXKjIN2i8ujU5bZ+RnP0yn2TTfNL3OFGKQ8a/8fCZbIRna0Z+nmz5y2eXfdctb1r1hL+0RUlc2V649WFGTUSDOljLeR8J6gWwgxWHkRV3qorj0uL8CvHCvJqTy2WO13eCAnRhoJiAHOB9oNdXdRm1zezm+2vusWy0t81wi1QRoi9uejZcV7d0JfI2V1Z+0Emk35E0l8v7aALUUEmlrXQrlHVm8fs7/OUH9pkU4YPIP7bPf1f/KFSeZ5dw+dacCxdrkGPKhcfXNdW0ACtoWeNqpXaBQeUri8ksWIMXxUdzq+afdC+ks4FtaKrSP5Dp/kg7X9E+HJIEnLSV1Q3vC90MuUnC8kYC1Nd0JOoT46aEWmob0USDqkXJonaQwYriqjWH8yXr1YQ3Fyv+xTPf5atfu4XZu4PxJTZzQX8IwakJ0F/M8TZqaTVDRJ8MEHsXUcaVTE+CrTbXGd/Z+RwCbHKCCup9Gc1tjdhneZ36Nm7sFixC3jm4vYnRn/R8u9dQez1hjnVyMj/zR6onzHo2BjtbkpjKyZ2Y6Ebf0vzeRzDSqwuFnATl8NwarJEwJ3LCarlgYt/ig8Wj/PLjGWoz1DhMHuT/0fC9vHdhnyhV8CVRDYgwdnsTJEFA4CReybaHcnIv/n1PIrxrSaTrSKKWULu/bNh4wFlmOLA567XjzmGJTOCl777CS6UFm/PhCzVXpjtcmCpH5REvv1zwE598HFfW5KtDMrMkCtsGHU4tcMzAl6i3uGZ/pJWKj4KNDcSFtEZG3V1OW1KJKsLJUuBw+IFsmeImwVIT69wTaI5NtPauwcRTddHoFWHCe3AajIhq79C1RyRjkmXsHFwiy1Ys1gX14nkWd1/m1s03uHd9DvMcqStMRlCLxbeJAjpRQNEyJn2lT5PWXkIYce8+9ZTK/ZxoPes5fQdGC/I2Lpbe/z16R4PO78FNT4fnY9TbngLD/Uaos7xeHX9Y+j15CNqRRkcKG9XUs0YpspzCZnhX4p2jXju0OOb6zZIX7r3AI7sfwc1nXDxQtPJIbsiKaVDvSEqullkm0qoMeFKEYpvgqG5RuuZdUgN+b85ENhNJT+qBZLLeUWLU+6iiKkynGZNbC15/Zck/+K+f4bXjY+7WFXd3piymBTvVEnPnNabnnuAf/f2/xsMP7TKb5eTGU68XCHuIZsAM9VWYF1TgasH7LMApEpfj4jzEex8Na8aE/2jnJY0kQ+iq0oTAQBq+ectm/LGmXiMjxlbtj9OON29aUV/T6l2EwXqGqlD5irKuoIJMHdOLMyZ2yvN/8hxf+4NDXr9znVdXj1C+XnNwbg+dzND1AmMl6o414n2NPlcjaJdhxQYfJfWtQq0PSDIublH3NKx6pkLjUwmDYjT8e2NXQ84Ykc98jOU+4pHcX1Y4Ka6qvtPcc0Lwl42YMlbVn4XMICcDTq2Rk279ntsrBD2lw1PdNk8765MSTrE/G7wk7cGZKaGhGcL7dhhl8dbgxKCuxrsanzlKk/Pn37jKr938Dg8+fMjVRy/y0x9/iKcfPw+TSWuV512JMRlI3rVpKYU7dv89o6wRu2nt2VnoO2v93s0aZSvP+N1NIm1HwphAW7o93A6hFWMMe8bwX/zpdT63uMsjyzVHBVxylsdKw3y15lAzrkxLtD5EHEieA5bKTZjmQnlUMdeSXJaIUVYuY1plVBRR1sK1jnDag2uEHvM7crm1B2MpPfXedAqdXs2UoSH0FYIZke7QPqrQCdPFZGviQln0TdfoN19rCOS1BtE5bzwl8NHLe8i9ii/dnPCPr13n5WqON/tw6f0c5FdwNmNdlbg4hmmX1xqlVQmGP5gMNXmYF+BxvutefOTl+/ZSptLdKUV186L7yEJrJck01Yo6a2k/gob0mFfbh5TpzEFP7aaGMOQZQDm9j9QhZ6YVnP2yK/eVTE78Vt5th5W2DrzbevqM7+HsSeRsHprbfq72XrYkplrdP42wbKMhrBjvEO+wcX54k5w/uHWbnariobLkQa88/dSFcE8UVCt8HSyOszxnqwOEppSt1DJirO7cZp0q3/8k8n3+lfVlocc0K8KEt3KwqD3TskSc52Wb85l/5RP8Nx+4ysHPPsZBEat7p+A8d6/fIr+wizWWqlzgs4zazaBYsD5asax3yMsVKrD2yrT2VJoj4pDEalfVh81vQ9/NoumWVEb6XwbbsbKphJ1SRDfuSL8jGfOu6VeXkabcY89KYKNFAytHkH2xRU5VeV59/g4vfe45/vmrN3jtzg1EhCIrMHJAvT7AqeurHLVmX51Uh0Z2XKMh5dKH0PDldcwXJFWB7UsXprC333YmzjaA4OxeJWe8LiKnTRfeRpWl74HrLe/sW5+B/vu2xQdHH9UZK9oTA6ic8X9J185FD5emuMUYDIYcIW8A8cg8nRvDPesw12/y7TvHPPnWNf7NX/ooAKX3iK/wdYXNcpwG5Y6x19/zp9dU/+s+5iJeR2jhP8gk8u7rp2SD08eG4E3MwJkoO5mQectxWfHx3TXPH77Fm8s9isUxuavxegtrzmPMOY6P4dJFIc9zVCzWGurMgC1wJiP3nlIh14TSGfcv0gCfmsBtMkg75lYfd9HWW12HVUHDtmo0s0YkD3RbgtkaHJNNWQ3Ddx9RWOpgFGYmOdlsh9qvuXJ3wfXbyv9084iXqxU/9cAlaufJxTDNC2YmDwwVDR1Bs3ApEWaSDVG78MpclFr37ZvQ7uti8knd6szgUkhi8qNR6sWfMmxXOXt1r2cO4XLab7+vg8R3NNfRkwOsvBuho0kkG/Q2He0276sskJMQkft8prKNNJtK0eiGYGUnc9ORgawIVgzrLKPMs8CiVA8aVghKgSXKncUKVPiiLviNL77Ezz/9APXD57mQ70Sr46yFy8yQThgH7w3NXhqR1lHtsA09mI2dG0Xe1gxOv2fJ5N2b3mSjgnWpdn7jCRENlKRQnDo+UStf+PMb/ObLKx755uvkJqfE4Hid2a7FzQ0/929/iMsPGfYuTAFLkUcxwDwnV88KxfjELyPqosrAyTWl+cogyekgRkgrnxLfg0/nJM3AUk4fHm7QZTWBPaNoY8JHaOE31ZhIIh+99mFpcNdipwX+uGL/2iFfuVbzW3cPofD8/AceQ1crqsWaoiiYzKZBpM4nhzcyw5p/q3Swnib6Xp0DvG7aRY+AQ7IVKNJRM10Z0YMdO5g6sr+RYvi65e/KWStZOTnkbua205Yk9cxXSs6QL2QUdIsnqbWOHucQ66lzkf4rsN5tfS3pKVBOG53I/SeHU5PSKXpU255vIiHf3c/usjXmbTObMbMmaAJGQotzNUYyEOHu8YplWfK/Luf8X888y+P31qcQAAAgAElEQVSLJ3j00gFklizfxatSt8th0lSD3euUYATHljPfG7brdjg2hbneDtr1tpPJqc2HjGiH3X+CyTY40KnmR2Li0OrP+IpZbplkE+5kGb99dMhb37oDGhLAynmyouDpc3vMrl3gL12APc4DGdZ4dFWSZwVrDOIcxNFXV42kuw8Dcbd0mDXGrBrZuRORdsFIxtrm9utkNKRobE1Tp0HtOdBpL1ZpA+9lQU9LrcV7h68cq/maxw72qdweX7j1Jrmv+NRkH7cOysdHaqDyiFuFiwJYY1qZcG3a+2GWY8RBfYTDL2OFqo4H2K1rGKcpQpzQnTQugWfd3xjVxHsHtdlZUoXcx1Uad9k8JWHJ9m17RvcuTv+VazcM3lBnGNskl5PD1EbaGn6mp4mEnXg05AwI2OYujiRJUQgdiSDcLhe40rX7Vc0MzzuP955Cgt3y0+WMr373Hr+1ep7/5Gd/NHQgXjHWYL2LSIgH52ORKHROZTJowWllXxJn+u334G0+r+9PZzLyQaiesVzqQVun3Ny0g0awpZIh3NmryZ+6yk89fJlHn7iAcSuOFwtKn5EXEx7NM/7Vjz/I5f1pWAgx0QugqphYw0oMU+8Tm1BtOwrZSJTadQFGEwqMbCwkSl9Ho/NJ2IAqzBYEpO++ob6fKNqEmvwkSTunCMFZBWPBWfB1SGaL+Yp7Ryu+/JWX+b3b13l/ZvnUuuTz3/wONXCkjspHWfnISsmMJRObaBBps2CzxZ9wcyi+WTElFGHdwnYfRvS2/RqrLHXr5nP60nR4Gc9UcesmBLJZvp499J6QDKVfZ75D4EC3BGnZ9OHojfhkQzZjPCZ1f1rEsyya9qLpWT6hKkA3Ok09LdFuVYYYKx70hM9OtjYvMvJaU2MsiazCzFisWBxCpSDWImKoqxL1jgemM3ZmUz66qPltv+YL7pi/c+OI7Ooee9ZgjXY3WRXU4ZxHTNhP2YgTQwOsXjrZEjt1M5mMGe59z5LJ/Y5EZJuSw/YyK9tscUwnsqaBo147DfsMhBnAYbniW+uMj105z9+7uMPDD+6wv/cA3gpuvmYxn7OyGRcPplhj8Ms1MrPM547dbBqZRWmV0UEsRiR6XfffSLoS0pcG62Cdzmr31KtwYjXfiDL6lMrVTNKbGUsMqn0BQ2nnJN4FOZPahcC/VOVSVfPta0t+59YdZqs1PyI5r3jDvbqmVKjxeOdbjxMRxYunlu5Kqm4qco72HpLI1w/eoehor9BplLUhT7fDnro95OhIMGkDlfQT/eYno4Op1LaDLP33fRbOvuoJOP0w4OnGGpLIQMTz1Gotmf1J0h30ukEdfLVsUNH15PIdg9t4nz59F4PvkZ7ZxO3ktIay/77lRBBnvB+VU0Gv3jmTjcTcZ3SpKKV3YHygAEtQDlf1gcnmHLfXa5bec9UYfjTPmIvnv/+97/Kff+Iq5z75cPg+6xrJCJ2HF6yRyAqT+4rOaTLe0ND6nrcT73IyOVNS0bFEkp6OzihpVTvWtWPHFogqtbUsUb7+1j0eufkmF24fwjmLnx5RWU92rOxUBbOLFZMiR2tPuSypnXC8UnbPTajcADqKpXyQiQ7D6jSZ6GYs71eWekrXqDrulbt1INuJxekgKDTrsakneEsHTobsvnJh8CcWUc/aKfndBV955R7/cn7Ih73wKMrvypqFelaq5Bp0f6wGNkrjTS6iA8OtWHf2JM4H1b9vlADS6rovbMlGCBvOK+SkEJfMnHSwezB4LfGDk23JQ0+qbU+ZgmzTW9ExWG2869aRinm0K9Exx8HxSyqjG2nSm+2lB1jHv6rlLzKEdNNEIpvLijahzKtuWiPLlveqW5OJ9iyIU/SbLbDwJoJ2H6w87UPR0vOpF4ITt0R6fLRzEINXh49DdwvMq4qqrrm1t8vH93f5uhH+2dde5le05kpMJGtVMg3B0BgTxFjF3F/k1/sUWft+dyXvJJlsTSrdN8z6+MxAUkTDUk6GCQFeYJILE9nnCQu//+p1/t7uA9z7k5v4ak61OkLNhAsH5ykmll999DIf2J9yRT1FHvxGIA6h0wvRra0GeXSRRPBw+PC1B3mlRlQSB9Smvax6Klx3UhWl2x6kdCe9S3Ye56HCUAOmdhhfY2dCnWf8yEHBd18Uvny05kpecMEJf14qc/VYDAUavE6sBAZKk1AjFqy9qmcr2swYYXd0nK4jUJYm4UTHwrn0hqHbujrZgDXSk7xZDY+Oghu8u3E5TIPhGYcsfa+MYZ9wwtxXxxNp32Vw2CKPdCqD+UfQHDWD16dtB6oDFp62BcIpoUPMoKOj76/e6177vj6S7B+noWEb9NcznBwJhGebMW3xnB+wK7ff2vC8rIDxvpULslaofJCNVx9JL87jRbhWLti1E54yBW8crfgfv/Mav/rS47zv4j47BxNaOwFj8M4l5nVnCdvSv0Y/sCHHGZMJvHOy1uCDz7Z/WuGQZcZiYrcgIlA79nPh4488yP9iX+ble0t2br5A5Rwu7kzk01uYfMbdzzzI8so+uhc0p2aF3cDTRftYvUkX5wbzm5Tt0oa8VuMq8shFRjHhbbj3Nkfm4axkExrWzptQCPphCrUqNZB7MM4zLTLm1uDevMfvfPnbfGV5xL+2t8ukrPjiaknhPLmxZKqhspKEcKCND2IAMJp2fjsDZvAudSytJM5eSc2bkhg2AntKyRx0NzJSyaoMIMmhpDky6HCGKsXaA8W2X1o5FVYb/azPtE2+7fInaV2GZ6MLxaIj0412M1r6O0GqiZSNMAZ4nZQ/jZFBjRA7/MGCZvrkx+KKJPDs2M/vWU5IZxO1VXhZT0Dkts1HGN9d2th892FHSlUQD5kqmXoywl6aj//PxGR5u1yg9S6/mOc8Xjl+88ZNPvP11/kbT15l7yMP9WDbVvS0ofU2UP82MzA9wxjlvfbrXVslCd8oG4+inlYsMdqJmmQ3I8+En9vJmDxyidW9Oce6wlswmaVaK1NbMLu6z09fnjHdz3FZgVKwrGoOrLSKu31Y4QTlzOai9YhaccchNaaJs2DRzZPcfq1nlBM75vSWOrSJpFBXVCaOzm2o4mKbjVcypxS5ZTKdMHOOYu75rRfv8ftHcz5iJ+xb4TkcrBcgOVmW4zQIyWkSnDeHohLsX2WbK17ytToO2WyDdLohaiOLLxu8fmQgwa/J3COtbumG/bIlXYz1Sjo6B9kyiJfxS9F0ct0zkpNQ+1OmZ+MmXiqyEYplMIOKDyFh9XUW0u2TkT7nR7dAQTqYDXDK32s950/qEnSgEZVW3rJpDCbI+Aa+bKGPqw4ddDegq/Hh//j9R2RzTtd8PlEmy0UvIBrTKgEjFisBbnZzx/N5yaNTy02f8c+eu8cn14YPf+QhwKO6RJgFNMSYriPRwWCxlyF0jA66bSZ/6szuew5v3X/7eKZfmeqAB516JTf4vFVEbeBXlxXogvlsh7/800/zSG45emzC3rldpjszqntr1nfW7F6eITtL1E1YLQIteFF5ZtbFLc/h1TGJLe0wI5w005CeH7eMiMnJCYNXPWErV9qD0Fz3hmOunVlVIh3irWCcx6pnkmdMpxn5YUX5xoLPvnyH55clf3dPmOuE7zhlr1zhc4ORCZ5uyN5ng8gIjLRtstz/c3NKRTSqb6TDarzPSNExqfOGCpl0QEakL1SiQxReBi9X+p7qujn70RQ/6MP37Rk2KdS0AQt26gCjsFwvGekgb0kHrQ6iuoxVp9obEnVJOA7CO8/70B9ucqia7nO8g+j98n4kyMgI+ykdq9OTvWn+nlfd0j32Kbjpw9dt9svDBSHVrdHr1M2SBHWQjc5G8BKKOxd/3/y5kQCBTZ3FHtd8fXLILzx8mY8uhP/njWP+YL3gA3c/QLEnlG7OJM8xdtpr1XxCfjmd/z5yv8xpYSwtFH5A2Nc7TCpZ80Z6ySTqlAe+tm8xpwBBGXRt+PUbCy6/cZNfurrH5eIiTCfMVwvyiSWfwfr1u9RXC3KrTHJLPs2oKgWzqQukWxamdGQVWn0n1JlSf4f3V0a6kbSjOMsTazzYW0MtOs0fiZbyvrlqVhCbId4hTinUYyrHYl7xfzz7KvXRio/v7jD3ju+sl5iyJiumODE49aj3WJF2HhlGfaZlsqUXR0+tVPpV23BQ3r/fXVCXYRIdHDAfq2kvHVVbkxRghuBX9KkfEeTvwBRpXkXzj6alRZdYm+Qhw3lRfA8NHNhUyM2wVNJqXVq5/y6lSVIMdKlPkoo3FQrtiR4kAVh7TCPpwYRipN1zSM+WSZwzNR3Ca1O2bN6L8a7JD6rl7nVvmps1y7pdgZQ2m6Y58xuVtRnhUp0CV/UEVs+g6XWGAJZ6qrciik1R2BQTNovvQfFGcCJY77B1zdp4Xq2VByaWn1ge8qWbFVe+eoNfeGgXeWIaXpVXOjOfoNwtBmxUhtj+ouXE9zkKuzZLxu0OkJ4poch7KqnIANpq7C0buQHpdwW1V7KJxXvDF194i3N/+Ax+usuPfuVNTFlxuFwzrw1+VlCJ4Wd+5eNcvVBQWEMmMJvaEGxk6wgzPltp9xS3Z/CEPKyygVX3qtUt3ciYOSBDVCfiz+q0NZAUH5KIasdYEmOwmUWdQiVkzlMuFrx5Z81vv36dJ7IZH9rd4ZuHR7y8XDKrPNlkF5yjVtfBZM3gVCSZFQ2qUtl6jLt4YcILNEYSvbGk8hlw4HuVd3eHuko1zq88gVnWKX7RbiC3JIH2VUt/LqG+255uh89dsgk/w7SJWjQmp3SAPux0kgXWJomYRJlB0z2lZrYmafMt7VBf+v1x2zW0HYh0S28iHTzVAoqDAjwN4iZ+rddO7SxsZ0sLJ2r7/TumW6842nK5m+6vTYyRqCLNMmviXKcRoolhtjchM8hABHdQIEia6OREmF22/2Y8rwy4N9sBz/gZG+kVQs0yekNO8fG9qQjOCLko1nhsrXxn7bm0n/OZwyM+qxWfffYmf2W+Yvb446AZq8ozLUwb/zzhbHedxZaNGzlZxbqRf9IxsSDVQTJ6L0zmObOeTrbxIMTEpb8sviHfvklrDOBQa7i6O+ePspo/PrqD+2aNqkPxHFcecuHSxau8r1b2jGEWX0xhBarowJhAjiat/NBTnp+ePNmTpErtKfZ2gUASSZFtH35YpG+sbJuKV1EfVZC9hirNmrg7aEHCAy3LEpNnvPndu/z+LceqrnmfUVZVzU2lkR8N3YwRbIqiJIEyJR6kgfSkz1loxCM1GmrpqO/KkAHVsXAG+xSpZ7g2n5u2iaaJ2UFELxXUDDW1FxvOlPpwGVU73xYxbUBuZ0+EJCjaONIkHYMxXcBsqs/kypko5N2T0ZH+5586X/p0sB27Tm2ThwYl2eYxmfD/el7isjmP6HUiwkDiI84ctetmVJPHpt2sRKU5C9ovJtLl0PinmRF8DKaayHZIWxBom6ha90tpkqiJyc2HzyjwoboyIHmdGkk3aqTrXE6dJsvILInBLIYelf80v8E0SXeQJj0FC2lVXmO8sYbKGjJn0PmSa+qZXDrPFa8888Yd/u/6iL+1fhw3EeraUWdCZkLKNzbexV4F5zdfpfr+AuMWxE8SskWfppJ8QPIe1fvdkliyjb8k4SB1exeW4SLQsc34W0/scPS+x3h9XrGsPGI8NjMYb6EwHMx2uVRV5HWNTrL2OzmviNMevinGtH4eXdnT30swwxFA462eLFt3y19jvK0xzaEtap2JTLwmgbl9RAl0gARGmokJQXxFvZqzKvZ58aW7/PGi5ByGi+r41rLm0MOO99SxHjQi5DLwXk8OXOrLoGP0U8a3hpXBwEGGS56SJK5UQsaMDptbZp22T6UNlNICXMG+tJsoKWoMXjKsumjhnODuSffiWyc6g0ZGkNGQGEyELdpuRIT0GkuSiKUtHBPuU7Pz0xQR6ttn6ZuklDhl+siUs1GhQAiCmC5qOuFcNzyXQVeUVO9dMpO22zcRXvNx3NbBM74NypIs3WhCyzdtt9I/AJkxeBEcBhdldFoaffM8pPOV8a0AYVzii8laEsitPefJ8/bqETFYa7rORM/Ul5xS/Aw2ENJZiLJZ0Ix0fMPOrJmVGa+IelyeU1nDpKzIVive8AvqR36EJ9yKZw7nfFYdP3Njyf6BwxvI82DmB2G3xCQvRlM218aO3tkG6DI6n9VBMtlGUXnvJZZN1lYb0VtgPMBaCmun1Maw3hd+5uAKj5+7w9UPP47Nc3bP7WAnluX1Y2YXJtRG8OcKfFlBXkBmcWUJ1lPUrhuUi2DjxW2HkPc77BmrinQToRy1Cd3yZV2tMADh0h0YiZWqNRjv2FEw53d5cprxjWvH/N7tJauq4mkyXvKe66sKQZiICek5DlpNwpBJaaBdwTu2TS3jyri6BV/QfrLQkRFuut3c30Qned++hY8kVVoW6TFpvDQzhzBnsxACUPRXbwKcabpgDX/uJeqLRSqn+K6Cb4UqmwF1MwhthEUjFGZG3lGfdWTxSfRyKFZM3DtwoTK3GdbmZHWFVaUWgcyiNYiriZ5reIKJmkmgtRQSbBKFGoMT4Vxdc89mSO3A1WCyoC7rpX22kmqMxsTaNpYaNJnTI59Z8GIwYhHvcJEQ0pgwC6khW0OiCc9dveK8i5+TwVqLNWGJFt90KBqa6IhK2CxK9jjtzuyQEZ0y/HQ7y0uGkPVwVWiLsor0Em7beLQFWftzTIguWTSCkzzHe4/HcXz7Hit1/NW9Kd8q4de/+Ap/96nz7H3qQfLcBuTAJpbQkpCz210cnwxhzWDX7Kz8q7Pzsd6rviTZqQE6JpIKWLmQ3SdT2HniIR75+DEv3oLPfuEFtHacn+WckyV/8S99nMefPKC+tAvrGl85dA3VaslyYpn0jI589Dy/H8LAtk5C2w1zeRt0OT1piBgPUW+71whqAzyVKUxq5dbRktkbd/nK60u+uvY8XQvvk5rP14Z5uSZHKIzFKtRN8GsKVtmkysoJXuBnsctNKzphOwuonTukdOpUpVekZVU21aJJaaJNQojPygl4TJT7jpz89r4FGoGRuMEvgdbsRVvCQTpDEK9JuxE+Bd9UnJLYD9Al5k7IQFv3zI4BJ221r2gsZGLQ1RpTVxhjsDZDqhW5WLwRjDXQuHWi+JZx1XQA9OZa3eAfvLE4azlwcJSb4LrnfOy4Ehy9Ycen8Jl0hcYmHBITrzF4Ma2pmdDNYkzbtUnX0YhEczQXX3+EU60lz/LYddWxU5HYxYTZRGZNtCvwMY4mCSAFY3uo1mbZspFIJNWK26SJyKBLHs4PRbSbLTWFqgnJOBfBAnWe4ySocle37nJXPD979YA/vWf43Wff5BfrkoNPP0QrpW02KBRbYPB0o0ruL4kksLz0Bp2M0qvf+4mktcbTZLAZ/rswGTYXCgR/y/BVKv6rF1c8//wbLN+6xmG1pprNmMwcH/rSN/ib167wHz39k7hcqIzFWMWJ4SBTfGHjbQkBpPY+HEwlQAenbvO+fe51vw0dEQqJWLCYjhPUiEGKMYiNhUdmwRryLLACXKXcPlpzYTfn67fm/MlS+YBYHjOOV0rHSmucQg7YaE1volaXiYwhr/QOo2wxw5HNKd6Z2RWy5TFKK0OTkmWTTsYafGwbJUIz2lIsDWJsqP5ioBdXY1wN4nDicYQHl5kszh6SYbwqWEMWhfd8lEVXI6AZYqUVw2yFKxt4Tky4xK2HvUPUteKIoh1k2MnLBBjJipDH815JKJay3fNktoD1nHJ5yGx2nuX6CCdCrc0cJiZBY8FmgdjgPXjX+2w8oVNQEXy5xK3W3HIe5ydkIkyKwC5yVQkmgyzHlQuq1RKTTzF5wyLyLZQoxqDN3CkeDptB7TzOOUQhN7aFNZvz451DfR0+s7jHZdSzZy1ZMaGqVpR1iV+sKVEym2OzAoyNc5Q62tk66qqZJYUDYdtEYO4D1jIbt1M2mIe0ShZjcJhgeldZIglEey6G/c5QIvRnVPFeOSpyvnlU8ZO+4jsr+Ic37/HLLx/zoXNTynMFOaY5nl0i08RS1RgQn9jwnj02yVCGfuRy/jAkEYBsYynJedRpHHp2rC0bpZv1sERvLfnWSzf4sy8/x8UrE/7DX/03uFAv4HDJH7224PN/9CL/8NXv8PNPXODy0w8xefg8SNjcphb8tAiXD0V8aJtrp6jzMah2VabqNq2EbeIJSeULmwt+MvJ7GfHUjtHHJFIt2nSvGDQDk9sg8OaUsqy5O6+4YJQv3TjkO/WUn82EmRGeWVQYD5mEAKSR4WSkrx9kBrCVjGDBeuaeN9FD2iIDMppURihhqiBWsCZDnUBdh2ZVYiAXgzVZIBwYE6pXF2jQu7t7FNYzr2rm6wqxliIv4lgc8DXq69jxWExd470GarWxiFhMu2PkUK0jAUS6GYuxYENwNVojvqngG8jL4RHqNgl5MoFclAKwqjg8lVHEL8m0xLs1GGWxukO2ey4stNWNxLgNuLmxmCxDsgxfe1xdteGvsUh2cQhubc5EhNXOLnk+JdeS3C1x6zVUNb4wkE+wZhdrC7yY0Od4H4e4sQOLPzOoqNoYZB3qK7yvMBgyY7tl3YZw4GpqXweKujXgPJlXzuUZBxPLXQd3fI3aArEmdEpa402OM1kUQlS8r5FKUZshsbPemFeIbHQTZyW0aqLJptK/u2OyP9LjlyVs4I1iq9uBkqjDpTbjOCv48tGSv209N2YF/+TuER989iZPPrLPYu8iu61+RfwJTtHaBzanbejbhuGU7GxVbcuyGLwz+SFKIeHN9DsSH3BPX/kWA27OhDOKakXmBSrP83dXfGp3xn989UE+9aFz2PIc5Z9d5zNPeNwfw/83X3NdMx6uDJNY3c9dia52yXdC0AkLYoGn7eL0UU0X/k/e6B0RxWtNuDaTywmcvEGb6tvt8TBw9J00hDGxiVHUGpwxVN5jasfMOR5U5Q/fWvLMYcVjuWXHwmsa8G+rkDfbsmJAtGVrjUxwEhy4v2kvJ4JxcmqulS1cUultojfvORQWYoRSK7K9C6j3+OMFtlxGoU1LZjIKUTJ1uHpNrQ6TTajyPWq/IDPKniqz6TQkB/W4co4v15gsw2Q52PBsJ2qYAqW1lEXRFgamrkKSiNVfmJ3UzR5rRN8UNYK3OVqHWUfmSox3VGLx1uCMxUmGZBaxhrqC6XqOnczYm+2wmt9lJbA42GV3eUQhOZlfA4LThlYbTpRTj3UuGEs5h/cuJBgrGGOxWKgqtKowtsBVS2arm0ycZ7m/x/xgB5tPKCqldCvK6pjCTCiKHZwPgT+L3uQVSh2hNFtXiPGdL47xGO/IJPD5jVechn/ExAQ72cVM9vDUqCuZoEwU/HTGG7Kmmu5RlTXnbcaBMawzw6qwOKcYdVhxWCtYMozYSKJIKNqNtpcxnOY6Nq6upv0dqa2Fo24kkIQ/0qvkJZ0RtufbdysIopSuhrXnuTzjqYMJN6uS3//m63z63gFPffQKInA0L8mnBSawhaBW1Ebf+Hc8q5Yt9IMfrl/ZkMCtXlsPDmMjv109q7Jm5dfseotY5SuHjlk+41ML8NfussgnmFJ539457NJzhwmLWcEMxXoFC15rfFljpybuZ4Rk4ZwGDwCnqJVRZEvYtN6UrSZJYxLP3YEadjlDxQPFIz5U26JgTLc8JzZUID4LF6lyHlvV7FU1k7rmC28teHXp+Au6Ym08LypMNcwMMokbuMmwUNNGXoZCER2Fs8c50yEYMHI4tyURYbCdLj2mkUTIQhqqrjEYA2tXMy0M4koWJs4q1JOJJxfPxCi5gKtqynpFvTPFW3hyfZtXvvxPOXfpg3D1k7BzHmML7HQX8kk06qqp8HgME2OYiIEso8yykMi9w4rH4EISMfG1+rAX4XGRKmyobIaXDOMd4iqsVhjvIKI9aie4rIDCIFZRqXHestY1Vg0HN5/jone8+b6Ps5pOEDslP76LYMNPMGEXykk4J1o7TFScFRRjcrIIP6kI1itSlRhyjus1sn+F6uA888yx9Mcc2JxZYcmYYVXR+RFufhtMRp5PKIwJXZ7AWj3eOfA1pq5pFBZ8HujShTGYCD1KE9glwI2Vq/C+BvEY8WTZhALYW9+keutrTC9/jMXkHIdTy7rw5DankAxWC+r1ChGH2OD9YY2NhY+PAqzSG6SLbHYZm5AOvTNPr8PQrfORbZBPEwtSUddeERbjWLOv1VCsfV2x44SvGMffzC7x9Krk+ddv8c3qmKerT6AW1qWnyh0TMYH12ywsvitBX9guqC8/FN1IkkgiXabBkwWywiKFRSM2OHWKry0TO8VPlU/v3OZ/eOub/JI+xo/8Lly8ssdlDH/2tVv8xtGCvf1zfPChA8zBhOXaodbh1WIKi1s1yUra4aKN1b7c7+cz6GVla+8hG+X+UKZFUq2VxtK2Ia5Z29E9DVhjyQxQKeXCUS1Lvnz9iBdvH/Fxm7HnPc/UNavas2OitHwzUGxozxIXP8dSwcZAsUsezVKZjPRbcoJCbx+E7qvwtsNhCSCbE0IwNDaY/yxq9t76Bu7as2QHn+DoymOsTY5zipZlgIWMJ5d9CrWsXYnZPcfyzVeYznbQJ36MhV4iO7rL8XQHM90h39kn847CO8r5XbzkrIsJfrqLKVfszY/QyRSTZWg+BVfhK0etBjU2dCPVCmMy8jyDoqB2JU4dWZ4jYijznWDI5j25MWhZMskMRVVTVNfI3nqBw90fYXb1cWrxVLdfxa2O+MBTn+EV3edwfhNz7mEyV7HnHFVdI3WNFYNmGXWszp2vWatnkuWYzGJXa1xdB/hpZ5fSe8x0Qu3WzA6f45HXv8qt1/6cc/tX8JPz7D/+F3CX3s9cHS6z5MUOk3zKHSOcrypsXZGpR42lLgrEWrIYDG8r7FOTqcc7g7pAxc8MLCXHugprIjxmLTs2ozI7zNcVjyxv8dy3Ps/7fUH28KfZWR9z7vY3yc5d5oZ/EJMV1PkurnLgHZnARD2ZzZkSZMUfT7wAACAASURBVNsXjRovMhicR5h6pAvZoH7IdhBMZdBNb9zrtBzbNlTs71O1d8tH3x8ML1SOy0Bd5Py/8znnnnmJv/jQefKHLzCZmIavHWWHe/X3OzSbkjOhJe/tjqShdfpuoIk1SGGD7EcTbEyGX1aUB4ajB3f5T//2T/Hs9Yz/85XbPPe5Z7jNCnfhAF/MeN+PPsq/88hl3n9hhhYZ95YV2cSDWph4qkUVaKDxaVkD1gStKtnCUtBTOo4RsL9f08j4MZVkXVclYNLNzkTfiSNogGmkKmUouQcqz2Je8dZizRdu3GI1X/FJO6P2yvOl50LtKGzg9696CSw+VzGDpa7uOuigwuu0uKQdiitj4nzCWFOiaeejA/eL9m6Eit9h8Mai+YRMKsQUrF75Os9+4/N87McewH7wo5jao+sSlmtktofd28WUFnWeqrrLrp1xdPNFdnb3eOPhJ1nfEK7aMvzdXDCFJ19XTLOMhVdKcahRTKHkTtByRT7dBWuwmZKZAEVUFbhihk4KXHXIzFgy48htTS1CWQt5npO5Y5Y2Y20y8rpiRx3GVWQqzFYLyuNv8Oq3/pBHP/Uky7uvo5fex+wjP0d2dJeXa0OxuMtUwLuKHes5l8G9coWzM1wuUGSs6xJjczAZtlphssZXJ6cu5+i0wE+nrFZzbJaxtzjEXf8StfFcffJjzIodXnn9O+xRhmQx28McTMmdo6jWrHxJToBVq7JCiwKdzWB9yDTLEfXcdgW7RY5dXMObfWozI5tlFLlnde8e3hkOLlyimE04vP4i9WKO27mKP3+Z53fh6s/8Cnr+KR6UGZPvvsyrz3+e93/4k2TTB8n3DvCr21SSUWuGF8VQsqs1e+rx0wPW5QojgSzRSAhpsmiqwsZZ3bzbMryYjJvXdCoEmg6/ez9nkzLvJUr8NGc//tPID83E8q31ir+iwof3ZvzvR3MuffUVPrCuOffoxQ59s5EqGBUJlL6iytmkQAcU6XevMXjnzdHb/KEZzU6HZAEyyOMCYtO6lQ5d1bzql3hd8nhtqMwOxhr+2w89zL9XzHhLKo6zmp0HDnh0usMnrl5k74kH0FnG2gh70Zq9VHDWwKJEnGsPmTWCyYK3cupCl3LKE0v3pEzRUSqrbMn2kqjY9sTfTJCibimXSruJ3PDkrQ2eB2QGMYayUhaLFfsKerTmn9+4x53Vis9MdjherLjmlYs1WAelEVzE2DGCbaE0E9bfREZHiNvm57SipNpt8MuADDmye6IDqmSqVdPsPpjYMRkkDFadxUoVOoPpBIxhcv4CC835ADcp59fh6DqHa8Od4x0evfwEN/yCS/mMi3LEG4tbHN6Z8+H5a+hqn9d2cq5e2OHC619n5RbIA4/wcnYednd50BkmsqK+/gLls88wWywpHnicGz/5C+wubrGe32XHCRfv3GG+f8Dq0oNcPX+ewxefwe7MqCfZ/8/cewdLdt13fp8Tbuj08ps8A2AGOZIgmINISQxKlrSSVrJL2tUmWfbacqm2tH/Yri3/4z9cZbu2dq2yvGtLK8uStSqF1dqSuKRIiZIIUiRBggAIgogDTHozL79ON53z8x/3dvftfv1mBgzeHaCBmXn9+t2+fc75pW8gWLmXfg5pdsBiJ2apu4Ps7dCIQnI0m8t3otH4XkLsMw56e9gbL7B89mG6BvRwi5SEwnpOqAIbBYRBH5IBubYcCxSX3IChjkh9wn02wOxepEtOK7CIjfG0eb2xSkuaeOMJbFnJNpbuxBYvsXv9FU6//WNkF76f3UGfxoMp+4Wl2LlBFnW4w/eQrdcIipyFeBEjIa8tHMcsLOKyPk23w/JwiywIMUpxr11nu9fnrOlz4FKGjbsZDHfwecb9ps9WeJKN4YCV/Dpnrn6Zl1/6CstL52iceIgbiydoLQS84rrcnRzQSjbZ3d/i2MF1TrdSLvU2udvs0W0d5/XtjAYFxfoSrYPrxOmQNzS0zWIFZS8mOl7VwvIj9F9Nn+xoX8HZRa/nDEEm8kZHuTXOC1i6hkRUSsbEdG10mUAVDtUfcDEKeChe4v5siac2hvxl4wY/86H7SgpEkpUAm1DVx8r4KoIZJW/ihFf/YQSPuVSBb6IiEeerSOvBWrSeVCbKCdLL8Tt9PnclYef1Tf7+Qp+18wv8yrV97ru2ywcfOYn83bfRCDRSeBKBNHcoA4PekCgOsA1TQjiV5qBQqLSoFEvLo9CYEpteaMWYmXgUT2IW3yDy5j4eNa2dNF++UcZr1/tJTV1CPjVeCUXu6HYzwljRPRjw5M42aw7e2VZ8Zjfhda85nhd0lWJQCScrUSWvolrZJQlWT5MFa4zzWZLhiIFchwyO99dsMFJqepBek5WXevuuVs7oCoWlVKlirL1DFSlaFejmMsHyKsoGuEaDoNlh9y9+hUF3DylS9nt7KBuxv3Ycf/+PETohufQV9vc28CK8/tSfsHbX96Affh/5k/8HV159hihucu3p65y57wPkj/0YL+3t8VjvCs/+xa/x6OM/wGuNU9yxtEbL9ki//H9z49obrK6dYmc4wDfbrPMQu7u79DevIlnC5a3Xef8P/Of0lt7D6UHG1pO/yrC/S5YnRHGDfp5z/Lv/NoW9F6u6bN14DR1EvP7akzx0+gJ9owkuPc2gdw05/zCXTl3g5Kt/wfVP/xYuz1k7foIXr77OQz/x33E9bsJgk4uf+hdsXH6Jhx95Ly9cfoFWe5U4Xib+vn+EvH4VpwXlhoStZYa7V9G+BA24aIGuCzH9A1o719k3Tfppl+WTZ9HPfpKXvv5ZmnFEmg65//63s/7Yz3JtN6ERDLgQwad+53/k7PE76HZ3uOuRH2fpjrfyuT/5Hzh912OsPfww3hk6CzF//bv/Ew9+4L+itXSeYP95Pvfcp3j0A3+PrHWMQdTgGAFP/+4/4uGf/1/Inn2WwfXnUVpxY+My/d2Ps/6en+Hzf/Df8+i7PkZTPU5DKbqLbZJX/4Sd3W2iD/1n+FdehUYHZUr3HOXdRPdrpMZbk6NRc6Cus0CTw8CRw39Wctim+Gj7Z8bSSCKqBibSGK1xRUac5Lxkck4rxeOh5jcOUj6/uc/PeMF7T3eY09CKxkRhbpJs1vhJ3/EA8p0IIjfBMd3OBdipSbaaluQYsTqzRPhCL+FXn99g80yLH20PePHSAV/azTnoF7x7b5+2Cemn4Kzjks7Z27F85J5mJSdSIn/CVkSkNWkty1AzctxKHdWWEWY6MVNeGPXXmqdSMMuNUvUbJnIYlVdl53XPoMx5iiSncI62DgmaEdIb8unNDRYK4XzYYSst2HUOVwhZFRPNeJBdwioPte80c8CMzK8l6u6PqCni1uEgomYw6qrm26KmLHwnarGM7QN09VMcipYvUGGAVNlcWCSgPOHqKksf/QWO7e/iLj/FxT//bc6oz9B/+98kvf/7uD9P6Q0OkI/+F2ztOpb+9H9j45XPcd/3/1127vsgF575NJc+/X/y8OIS+6tPkCQJ4jIax89wJr6bsGEZ9F/n2vU3uOeBt7Pzrr9Bw0Usv/hprrz0BVg9R/yxn+NkVnD/1nPsXX+JM+YediVn9cHvJjn/MAdra5y8/jKbf/qvsAdXSZYu0G6e5vT5e7hy9TL3ffgf0F28k4HzhIN9VBCgdUDn2lNsfvX/JfVw4Ud/gW77OPd88Q+49Ef/lDM/9A/Z0AFXNq/w0CMfRH7o52iI4uQ3vsDGX/8ha1svse8MUbxMtv8GwWKH1sm78Ruv0ktyom98kfO2w8Cuc817kmyX9TsfwX7xt3jp8lM89NP/GDnzENtP/j4v/uW/YVVg7cEfJXJ9Xvj4r/HY+38M99BHWOrt42/sosIGS0srLCwvUShI05zlICzZLB4yFLmpRDyjNmIiUAE+GbK2tMped4vi7ndyZnkF+dQrvOVjP8IN/R6GGO68+zGuvfgUC/c/wl5zkRWd0t28yNK595ENBhBHFRnQV+6mGsVEjLOukjCtFjGdxolSc+2sjhTcPQSLF27mqTiSxhnD+KXsMmgUOYqB96RO8Wp3SFsJH4gDNpOM3/7rK/zg6Rat4x1MoBnmBdZYTHW9o24XR/QAjjyIb2U9LG/yJf9/CyYyh0eidQ06J4crgYZlX2seClLWN67yyy8P+Rf/zuPzIYQxn/jCyyiflhhz8awmQwYLDRZUk4WfeZwLD5xh9c4OIRodheikIDcTIpGSUnPKS80QZ9x1mcB/lcybkMwfLM9vC6k50tjTFJrJYi8DiKaUbxEpoZeFCMMkJcsLltsBzTDk0sE+XzrY55FwiXOB8OJ+Tk/AFI5hJXBnKhmYsUZXHd971KB8prqo6/JITYJDanCz6fug5yZyMiVqPUE3jCCRI0SjUSVPxKPxRtN2GdgqsDqHVp7EFbQDy+7LN9hpH6dxzzvJ//y3SYpdNgNLe79LsrmJ00LS63JaMjYvPYuNY3ZOPEzw8haD4E4GkrN542usrT9Bnjo00I1bxCrkxrDLnXfcxyvJgCDL2PMhYXyMY+ECz21d493f/Z/wwm6fa81THD95gS994jf52NJ7uLiySnHsHnquoHnxIhvDhLjVINm9inQctNbR0TGaUUAhbfqDnEG7hfGeqBERN5dpX/8KG7tXOP/4j3DJLOLeuMTpk/dz8Rufp6dy2sEiLhvQ390jupHQtRGhXyQrhtjuNUJ7J14KFo/fzc72NQaDbdos8Ni7foRXn/szrjz1OxTBMsef+El6SYGVA66/9Fc8+M73snPqHrqZwr77I4Rf/GN2Lz7N+Ud/guHeNbpbV3j0+/5Lnt/PYOMG9vjdUCT0hwNUaEkR8gJsqAiCEOfyMiEIYWFxgaSxSh4soqwh2buOE8/p5RWuXOmRD3ICBDt07PdvsLa4jr/wVl7+2uc4/WCXa53T3DnYYLO3RevU45h+Hx/HJbfIVyrC2lAnAo6Z9FMmX3OQh7clVFhLNEXmr+05B68gla6YjOcqyktFBRG8UgzQKG+4dNDndDPie1oxv1U4/p+vXOEtyRr3nVtGIfR6DmmYkspzpM7sIdPk6RN6jvnekffhPyiXRTli2D5SYK37kdRObRVp4tWADx0I7kSbL1xr8IJP2AX6geZCmjEMAow4nIAO2zSjJqdbC7SbntCm+HyFXAX0Bzlt6uKMUslN1Ax1jmpVzYq2qRkgBrPEPZkeateCyUR0bfr1VF0iRE2CmR75gnhPSwe0taLfSxn2HR/f6nJP0KItmu2kYC8vwahWOaxWFApyVZPgUPPekzoiRDLl/Hfzj3Ua8jbv6ROp8FkOziRg69HG0rpkoGuLMSBayJXH+VLuJFQeFygS7+jtb9OWkODEIrvOkWcDosCz3D5Fv3D0k11asSFwiu39G6ydPEdPAnx/h8XAsnbiNK+89Bx3PuhoVNIdDrDWEhGT7m0BikQbgn5CuneFvd4B3jsSchp6nQXnyeNFtNJ0WzFrkWFhcJWlL/8xr379Lzl75kGu714kXlgjOJ3hdUyapQyGCUnWIwhbrIYxxgQlwaoYkgx36Q37qKXTRNLANdc5GBTsdfc4P7hBeOw4KEVzcYUkGbK0t0WSJwzTIWFscYVFK4ukAzo6QMVttg72uHT/h3nrve9gYeMZPvEnv0nT/wbxPe9h2LiXQdqlv7tH60ufJPna5xn291nuLIFWBK2QvUvPsdjqsBG2OKFz3Pq99L0nL3qEoa18y3O0DQgqccXC5azkKblPyNKEMMvB53iXE2hFYA2SDsk6JwjcMkWRk2cpRXMZA9izj5E7T//600R33sfBM59h9fgZCjGoIieMS9mRkrdSwpXryejEyUAfsrCea211hDXzoUN3TjfhEHlX1xOuGYRjreVmtCaUEt0nacZOYHjD55w3TV7b7fOHLxzw999xlmWgGRjCwEwldnVPJ5lBlB1K8WeDyKECTW47sM4z5lNKfYeqErkJaqtOqhlNoEawBinA5SwtQ7z0AD/1+AN8+MoeG9e2eGWwxUaQ8/dW74DzJ2kFhlRyBjcS3EZGnl/i3KMXcCogSRypg8GwoBVJzWpXpu/nTLWnbkeh+iZtrJu+eZG5WYTUB9q1wb+pIlfTKqxTvLg95PJWjyd39/jpqMP1pOBKmtP3I5KepyGeRJVlc7mmJ7yQKY+CeZvmptd/BATtSBr77LfXNvTIG2RkqVwF+VJ3wKC1xRoolMdV+nRGKXSRIaags3aOsLFMK9knHZYSGtpaGtJjPVzlkg3pNJostGNMr08uQhQvlPfaCIviCU+dYfv6ZaLVdZZ3l0BrnMvw1hFqS7K/jbUBvbzglGnQIEBMCErRGxbQHRKrnEHb0Yib7HZarO2+zhsvfJJQR7zlPX+T5PRbOL/9ZfrXX8cXQ0zRo7+3B0AzCghaTVQcMtCGxKUol+IRjFYQNlkeDqDRpL9blOshOaDZCACImhHbnTaGBgeZJUkTTCOGgSkVdvOEIIgonHAmHXB9Y4crWrNv7+Qd7/4R/vzP/y8+9D0/gG92uGw1extXWT5+P52Fu7jv5CpXlhZYEsvmIGDNxhSNNjv9A74raHIlO8D5CJcPaTbi8rCUAhOEUCkGOIFFl7EvBVmWEaQp3iU4UcQmQGtF3u+hmpo4CBHn6O3vYI6X1z40S9x9zxNcvfos55d+kmeeeZJ3fOSn2MoTcqChSnXk8X5ReuyxotSMsVNNoXfS3ZlrhjA/wMzMExmbz01Ztx0euKuaDcBoX+mRinipoNxUisI7XFFwkDu+mmW8pWE4GOR85uo273t9lyc6EdGJzpHnrtQ68GrKoVIOnT+HjJnmBZRvIiiIyK0Dyu1UQm+iJLITP9bao+bbjimROnHhibWhc2qBhWbA/eY0OzdSWkshAXsoGjjaxC1NeCaie/1OpLGIyj3G5pjI4j1INsAG+k3r0kwPo2XkVDHjqTdreypTP0Yxh+UuU08vX1GP5iMKIx4rnsIGJcLMeVTmuLbb43MbV7lXN9Ci2NGag7zAOU8MWG2qYKVKGRUYbyw9gyCb/+GqQ0PFwxjz2ZRB3RSYIFPd5DoCpgzudV8YURWEUzze+bJKSPNS9t5Bf5Cj0xyb9tELFte0aBWRZQOMd6RRQK8A6zNyhJ1UyNOCdnuFLO3RLPbYi4WmU3z9mS9z510P0k0SoqyHAI2FBq7vSfSAVqwpXE6khGG7ie4XaAqMsXSOraHsCnkO6e5LrC8t0TGWSIQbV1/iPb/4v/LcdkFDIlau9cmzASoMMcrQaC/SaDTQ7Q4ShwySLZJiQHNxkf7qcRb2TuC9546w4Nqx07x88QWeaMV8XTyt9QtsD3ZpNpvkaR8dWKwpyMWTFzmDwtEyUFBgw5DMQVYUrCytcsZGbOZ9dlpNLjzyDvxnfovXn/0Kx564m05zkZMr6wwfeCdXr/fg2F0MVE4rTVF7N8C22DzY4cFYc401Xt3dohVZIhWw0RtiblwnWCgw8Qq2OUQbgzYBg7hBg2Vy53FBBDZAGUWUKjZ2tjm7uMpSUuAOtlBaMRwOsEbhrMKmBRce+ShP/tmvkD/zCaKogbnjbcSXcoowRivBaIs3JYF1rIKs1UQhYQxbn6AjRc1aOhyG7x9KKtWMT2OtRz2Zb+qZmWc5H6m3fmXsp6KmksiAUnamEKGba96g4O5GwI1hiz/84lXax2MeO7lw+Npq1zAavuspR+k570uOqEBuk5git/CCkZkZ9JEBhKMCl9z2tVhqfghjSeRREMGADqqnJkhygGo2WV1tId2Mgyev8Ae7Q+zLV9iMHYN2QKAjVjpNJFN8qPEgC6shzcUAbUE1LZJmGKuZTc1Fbg/bMPHAmDayOeqbR7mJHCUJPK5OdE2+W1ebA6wvtZhEgTMKl3j6/YKr+11e2t/nx5diDgrPligK5wBFo9okIy2qQE1KzhFXgzktrlEWNz08nA/lnbSwbq+vPDMGm0CIR8qlY3h8Bf+t/uzFIz4Hb1FeE0cxVlmSfsKCjXHeEUeWvBOhiwKtFHEY0UOznwxoBwGJDtk0C4RLMc3Fk1y89AwP7F9Brd/P4IUvM+zucfL823h+cEA366M1NBY6DHuldEi7Y1lod1gIG1ztLBC6Pi7tkWYJw+4u4i2D5kns0HJ1e5NzgwN2B12cy+mmA86GK7idLZzVNJdX6YcBkjoGB30GgyH7w30Wj58pddUCy0EyQLQmDAIWm0t89cnf5/TPPkF04jTNq5/H6IC+WqfPkCwvaDUWObCGwCoyn2NsyNA5VjR0fY5txGRJhisKNlbXGQy3KU6ehXyfrYtPEYhwzLYoiDh24kG++tLnee+Ptjl5/hyXXn8JdeMi6ZlHWGx16Jx7B+EbnyPYeInNu08SP/QQ2euvsWrWOHPhAZIiYyH29F3B9tY2gQ0I4hb7ccxJVlldXsGHcRVIINQBjWaH7a0NVsMGy601jAnI8pww0Dhr6YjGtc5y8s67+cbn/5SzJ+9lsHQX8RtfwweLeEnQJiCo2qJ6xI9SNT20GhdKqpmn1CsV1ExrV3PI8OmIIny2EyPM4a1UgpJ+Brgy5mZVm98aRaAUA/G4IuMVL7xjeY3TvsPnXtnmwr7mgfefJzBhCW5WupSbVzK2EPWVNa83VK6hHG4ly5x2XT2g1IFASr3pIHLbVci3BRJW19qq+2iOak5VAaUVQIAnQqcWkpz//ZVt/udvvMS1G9uo/gDrhXZg2BOFi0NOdRbpbLZ5fOEYHb0MOPAGG4VzgBfzdeTr3iQTuQM5zOmZMJOOOFjnRebDN3ciFSIYYwhM6YvhXDmUs7kj3e7z3F7Ka2nOE80VitRxaehJAaMMumLDoyqfEkppFEbDdmoy6YfKT6lVRlUAmFlHs8ZJh4KRCEcBomV2cF+rdkbyKKNAHRhdKjYXgs9zjp9YYTMxDDNPz3vOry/xyvMDFtvHsKpsAUVWkxaC8YYHJeZaltPLClpxwJ1XXqUbn+CB7/05zGf/FQdf+FNOrT7P1uVXecs7v5/mhffSunrA6YU1LocN7LXr5MEKy40TLOltuklO1F5hfX+HQS9j9dSDuC//CW53H7t0N0W6zeLSKvvDlLxIWHjL+zm3+RTXP/GbHCNmdWGJK/tvgG0RqID+4hImeJhHBztc/vSvcd8P/yIvRx3Czhq9zZc53u+xcfa9vPUDGS9+6Y9I/u0/46wO+OrG67zru34WwlVOqBu87IT9zWvcOcy4lhWcbzbY8EKws0uxfh5sQC7g4gZawT16yKWv/RGh1ihleHX3Eo+/6/uw938XL+SGh9/9N3jLyiIv/94/o5kLywvLiDg6rQW24lWGS2vc+9YPc/X5z1F89S9oxk3EnuLku34ce/5RLn7x09jn/oiGhwOVokybJB9yarlNuO8ZpJ5QF+SSoQpYVpD0u9zbWuP13R4msjz89u9l6+olFp/615x4/PvYsrCTC3e97YNcefUlzpx/O9nOHnkQIeJQ3k98ZZhI++ixnE2d9DuyERZkdkg+kvufYaBPJ1nCUaD9eZTA2TVvavtvapY42hK+FKwNlcYoTSGer3cT1rznzijks5njwZd3eftqgD4eEgZxKb9cvYgWXwo7CihlQKsxIX4ar8+k0/At8Ddup2pRU4fkLQLHN9lOUyK1dyO+7Kv6kWWkZiRSlDpPNylY1Rq3M+AXvvg6v/mnT/O3Tq7w8AcfRkvC3mBAQ2uOtxpc2Q/5+e85RRBYtBqACRgmltjCZ3/5KX7w2RdpXrlOgOYXf/7DfLDThtWFkr2Mx+iSt5FmjsKVZanRauzfIDWf5rp21qGDmfn+xyMtqXEc05X5EB7REFlDZA3Oe3LniZ2QDTO2Xt3hEwcDvrbf56ejgK9uDfh6d4DXhtAYVOHQhZuyg51uv03zPepS8SKH50ZzIcwzCLXZiuXQIFOoe1vViJcy1R2YBBM11rQqR2cerYV8uEOa5DSjBYJQ0U338Zmns3SCxHkyn5LtbdDE0+icxDfbFGmPUFIKHTK0rXKjDvaIxJHnQxbThO6dj8BwSGQM0t0iICcLF0mai3SMxd14BUlTOo1l1PJpruPRexdpk1JITBKuohtNRDLWu9vkix3eaC7R2tqhMbhGxxYM0gSJlsjDFbLcE3mIXYEODUm2jVpaJzEBkffYQY+wfYI9J2iVs2gd+xe/hvFCfPwBBrpBTEGsHDsHGwRRAGaJoZNyzeQHBDpAhU2cCXDaYBqN0nFvf5fk6osE2ZBQKYLVU2QLKwy8QkUtyAY0pEBlffZ3r2AMtBfXyHxM4RvYICAOAoJiSLa/QZ72cIvnCBZaSGyR/oDetddRWmPjDgWWpeUTIAMGg01c5lhqr+AJy4ZEsk3EkNSssqPaOFVgdYLe22a1tcyOz3Er64hvc7x1la/87j/nPT/w33LQG9DVDSgyjC8QZfBKj0G/SunK+VSPE0CpOQxOCH1yGIMpt2hvH5pvygw+auJnKmr+XoCa77sqNQYRSp8YgTC02DDAeUemhLcHAfbUCr/TH/Aj95zkby8rooeWWF5agCCebODckeQlzFoHGm3MFBRfKiq8ulkgmc0Sv8WKRL3ZikPdWvz16Iqk/iJaj/3bQXAFFN5jRBgOctygYDWI+ck77+C/WV2gc2YRqxfpZzk6yRDnuRyUFrRegco9Xgl5IUR6ek4hMhGJvO2yq8ZqErkd7HMdvaWnUV0i1A3IdQURFBS5EwovFIUnzD1mkPF04djf3+PhcJFchF1jS6c7L3hdkg11ZYYz2Viz7bv60H1Gpr6OGps/+amts/mkSnVE4TUJWLXZUs0zauTrMTXDqYJO6S7XxCtFEcQEkSawIWJLKIE1Fm0tweIp2ji0iRh6QdkYS6nGqz1lCyRq0zCall2n6RxJMSJbQtxcwiqFeCH1BUprmq1VirCciRRFglGaZmedhhKyJKdQGu0yMNBrLCAmpJ0VBFjy5dPsr63QTBOioTDIBFwXj5DZJo12hyXdoegslg2VPEPlHskTjIrAxuSmYPHsy9VQ2AAAIABJREFUg7SbK2z1BgwP9ogbMe3FY2QmwGUHCIYgKJMPb5axCM4GUCU8Ps/JxSDNJeSORxBTEvXCxhLFzgZGhCzLMDoEE9OMO3RWTyEUOBGKbkKROKwrMEFE3lwg6yzg8TT2uhReSFJHQzdYXzuHsSHexvRcKa6olSEMF8ktKBvjvMJ5COI2TrcQF6G8EGlFGHYwCxYdRgTKYuMF1nq7XPzMv+Xs2QfYMzFD6yhcQaAVoQmphCEqLrEaS+3oalYyWncjKaJxhaBmKgmpni9yeNYJc3TipNa6PQwrrhMRJwewGs9Oda3FLpXS9+h95JVckgIuFZ77xPMYihcPynPgvd01XCxgshKUgS7/NTMVvkwabWrkCCfCTPvhOxJEpiuMbxJHfMs5iZrj2V5qm1bqrkLmPXl1sBkleA9pIfT2eiwmKa3dgvRSHxVrRHmS3RSXJCwuapQ6UQJnM4/X5aE8YtJPyZCM8pUafEtuFQblsAd7NRuu2Y6rqQNxPG4Xpj/UMTxdTYaCTihUpUycC4NhjutlfN17bJLwWHORywPFnjbEQFpb5EqZmpLuZFPoOZWEmg0EUkOfHBoczcJ61ZFyKOOylmmfhkk7sApwSsabbWxHWxfkqn5K4T0EMY0oQFSpshuHDVSQ47OMwJTGTFHUJBDHwJXol0hbLJY8KNtogcuILbggIjWWoN2iuXOVQlsKDCZu0bCGPMswWYqgCdpLREWOz1MyyQmUJY7atAPDwKTkwyHiSqmZrNHEaU1rmBBIQVZAsr1LogNEWZTKCa3FicJrTU6OsiFJOiRHEboCEzdwmSNyOVjBG0u/tcRe5QvSjGMwhoO0izUWFbTJKVV/lYaGCqqDtVzTWjy5F1zhiQf7NNMhptnEdBbI96/TsjHe5eSVFLwRRaYtKEvhFFmRkmmLBBqcgyyhoWIWgiZaG4axp/A5vkgpUIQmwpkIjKWhpPT60SFRHBFBmRwh5AjKdtBWk+WOIHc0jKWhNUkYsJMPGYoi7iragys8//Rn+KEf/6+56FJ8FKN7+xgTEtoAL4JzDl+nG9bX1Nh3Y+QRcxSBbwL+4Ki56Ty/kangIWhqxmlqOohNrm0yc0ULIqWshkjlXeNLyfmm0VyUjDuznLd7+OPU8eU84617KUQhJvCEocGgSvM3q8ctPXWEiUWdNHxE22F+RSBvIoAwrev3zQWf2/tl5ybvaiIBECiNMYq+FwZKc6KpiFsBSTrg9994gc8vHUe+PARXkOdDcglpNRqstZv8w7u63L8cckpBqFXlS1IOpI6ce98ms3LMVBV1WIVz3uejJlA/xllMbZHXA5KUAdOLECME4nmjm/DK7gHNQnGmtcR+WvBqf4g4RTtqYEXIRge7nua2aHUEXakiPc4it6Z6xzIHrDUbOI74/hEkUs2FsVcQ4FHpo2dnUWOlmnEQHHNhvAfJUcUoodJ4L+UaULo8pHzpByLaUmiDQhEKpZihOIosxRVdhs6jbVx6l1O6EPYLhwjENiztUYvS+U90qTUTiAfnSAXEeUIFTuvx17UrCLwn0hrRAYUqX1u5yhLXBhgUTpc+MRQOK0U5bNUGpQMIA5Qv1W1lmBFEhtCGpDanECGhlM1AGUSV1rTa5TitSCuTLS+C8x7xHiuKwCqCoIE2MboZIUYTNBfpDwZ4ExAojbicQdIrP31t0GGMNiGh0njtUCgyEXzhKAbJGGprTEhkQxSQovB5ik+7WBNgbYhSBlGjVm2GoEqjNQ+SeaxQIq5QZB6UNsQ2wDuHLwZc73e55+63o9rHCCpfFmsMYaU9p6sW1YhgPLI1VrVMaewIOP7aKL+TaaOn+phcDvMvlJ5UFrNwfqVqhthTkGBVa+XW1RxqtY1IdT8nZGmrNQYItOXqsCA2ikdwvNZP+PTVAR/VGrOygFWGwlftbD3DtB+PCmSWSHb4gL+V5/ut4kJ95vutViJvKpDcxMJsJHMwsitNNIjWSKB45OQyv9Nc4umkoPPadYo8xbuMXDSNuMlmq01xY6FEdSzGaGOJdanFI2N4sUyVtKN2aX2RqMNp9lhGfVxhjLS5dE0ihVnUgxrbrFKxXCcordpCqu6HLxxeBKME4z2XBwlf6h7wgG5xV7vJM9s9rgy7dHRMK44whYPClz7WNcCfngkks1XsIZl4pW/+sc+0tY56Qr2qmYWsj7ezqMqjYRqOPNnwI4CJYCl96a0rsJSOloVIJeduQBy+KChG0MrKdtZDeZBrTaigEMjFYVFERlM4R2pDbCUfk/uCtCgIbEDDBvgiJ8vKA1NpjdGCFcEXOUMpMN4RKIUyltxYAu8Q58oetTKEilJpWgQRV8Fhbdk+EyldF7Mc7XIC79FhAxU1UUG1NVIHaY4VCCKHWENuFEWR4ytrW1BYX2BcjjOaTGx5uKLGtsGBeALx6DBGaUPAANfbJ1g6R7/XJbCGKLBgDGJDfFE6R6pC0L7AKo0yhkIpcl/g8pQ86ZfGUguL6CCkYQJSl5MUKSYICMKo1Etj5LtuyF1BVhQE2hAqg3YOvMcagzaaTDyp9wR4Qq0JGm1cGOEYct/3/AwSr9PoDdCSEwRBOVAetYW1hqo9VENwzNjm6mkElp5pSclsK1fNOQv9GLarZpCJ8+2kK4sMNasMXmuzj4zrKijjiDwcqBKZ1VaWa8OCTjvkISl4ofD85daAt4fCiQtL+KLat2bEa6m99sR5bU7Srr59w3b590eBt2VWXyPPqPoHo0rXQu8JDaxocGkfZzL+zoV1PvDBd7C5m5B1EwotYIXsYEjgPX6twXedP07QjErvBmVJpSAatbBq4DCRaugmtxoWyeSAq1pU5bep8RBunoR0vU9JJXqodRVtdE2uXcrevHMe7z2+8PQKR5EUvCGaJTEsJxm7QcwGUvJFGIm/lXwRvJ74JzBSm55c35TPyJEKvXP6oTNubPOqEalp39e1yNS4nTd6TjWOVFTlvEw2fH2zeT8elOqa3aiM5Op8qZ4qWqHEoGVETKtmN96XuksjIyqkFKysCURqVWXGlMg4KlMrXV231qq08B1pOEkJL/W+gliPqlxjUFrjlcNpTw9FgsU4j/W+FA5UQcWXq/rVUlYyDjO2CdA2wJjSxbFwedniDSMKPD7PILQ0GxGSK/LMgSudLk1g0aZEHenRx2BU2fpSqvSqVwYnHp/22H/1rxjceJnT7/9pIlUOa2OtKXxBLgXGKEQZlLKMdd/GgJJyiKsrJJNYM/6cjFYExqCqDH2cyKhSddpoTVAFUltVM6J0FXhLsqlIJVCqBCky8DmmtYRePU560COiMs8a5WdqgkbUVaIodYhtrc01lUEdRR6WI6Z+40xT34J7O2+8rA4BWuq7z4lgKm9QqegQY21TVe5z7TzXvbDSzXgwanLRKz65vctP7B0j6nhMrBAb1CSWmOZ8qdu+3NuboMvRQeTNVSPyLV+Q9TIpH6fYpFJadmapIy88YaSIrZAkGQe9Pmo/49xKyB0LGm2a6E6Mbcew04d+DicLgvWSuON7GeKE1AmhkSlOx6iPPHUY3vItyfwMXJiQn+q5ikwTn0YCc2q8kaqDUkrnOydStkFyx+4g56CfsSuaCzokzhJey4fsiLCkA5TWVRY+QYEIEyKSqjgZs4iUCWHriOH4LDRyDmLrcMmmxoSoKc7iWMZ7EoZHk/1xBqgOe9DJSBNtNE+pDgtHaYmsR5tuNMyUMij40c+rgBvlueHHm9NUgVGpssVkx+eLoHR5gBqRalYHtnIbRCm0lO2TsVYnZUCS6nNsLXQQk7PrPDuZYyHzLOcFWlkKbREpnQKtUmitcErhjMWLKUX8bFBiTYoc7zO0ifBhgyJPKIqEyBdEvsDECwyMkA/6WDTaBihl0U6gcDijEWMw1mCsLd0cnWCiDrGK2N+/ymuvfIlT7/8JGrpN6nIiG4LypSeLtigV4QVcVd1pKRGLViu0DsaVbj6Cn4rDjiuDyqJYVwdaFcxDozFYDJVag+jSNraEh1QCo6MhsUO5AlN4fBhwsL9LtrfNQrSEHynpqml3xElratbHvSbKOKOgemjPygR9clilQ91WBq7V9JqWWmV+SCwSMKLKVmW1S8aBp9Kbs5Rt7huFIypy3tMOuaGFJ/cHfGh7iPawqBUmNIiyY6khAOc9xpjbnVx/SyTEuWfEm+aLvPlrtFKHw0525/gFAyNI7kh2Pds7Q375xS2+8eJVdBwROCEwZcaTOCHxkBSeTmg48arjn5zpsd4sPRO0VsRGoav5yzyCubqNN6jUYbjfYVeSWi9nrvnYGDReyUmXfA9RZcsm90LsBZsXbKeOryUJpwvFcRNwxeTsDAZor8rFoSbZshkHqanK/nCFJNMKwFqpmwSSo6KqmuM3PzHEOkRrHCULUlcNPizDP91QUIfELsczGD1yeawqjtq6kWpYKkqPjcCmepdT8LPpoeRIZkPVvk1VVWP5ez0mdCkRrNIEWtHzgm606JicRvcSwcUXCDdvEAYLDMSiVk/j185hWosYHeKHPRra4rzDhA08glMapwM0Dmm1MQrSZECeHBAKtIKAZrbDYOMi/fZxWkt3kTYb9AtH4DI6UQt1sMtOo4XRBlcMEA1iNC5PcMMhKgiQVkSzEVIg2OUOyY6CsIXSDmsjtGmSD3o0mwsMegdl9eE9ZpR8iJoiuRXj+++rSrO2K9TEf0bhy0BkTTXTqH3eVUJnqnGZVMFeKq6RRmFyR9hcpNFcIs8S0nRYDcbrLeQZdWs1rblVJyJPxpPq6DbNURtgZnai1M0TfanPQuVwpeNHfvOjxHZkHVEle15BDuAdewibmeO4zWkT8lfXhzyhhIdaEcYJ2uqaaH5ZpZcJ1HcoiMydi3wLv97Ua6hRa0tmKKF1SGx5Q0MNu/2CN64c8MlXdrn6/GW05BR7O6WHs7UoXfaFByiiRowKAz7yyGkePbvIXStNFJZQz2Qk9ZJ15Kw2Dg5y0zgqR8XWGrxPjiqd51Y9pU9BOSAVJCtwacFmkvFKUvD9mbBgFF8yll6W0sSgbFSOn6uFbPXI6GZmbjYjjz3Gr8PRFYk6jEg7bApU+7s6RLImgzKNLqxlkDKtfaTmBJHZ6/biJ8tD14LIiGzpa+51lfKxryYlI8OjqcClJnIa0+/Lj9eAVhMnulHwQpXVA14IjSE2ml6e4CSlufcG//pX/wkPvu27ab77B2kvnCW4foVcW4YmoNCC1564EbPcWiHfvobYkngmCvAp+BwVaEzUwBQDgtgSq4imCPnmZZ767O/zwZ/8JZYWVnh55xK6s4T0MoJ4FdOFvN0iDCLiPMSEIYQBrrdPjiOPI9LQsry8BNYSr63S7Q5LocxigA4DgqhBMchpxDHD7jZW2/F5PZI9n+LqVZLo2ldVi3hQqrrr1bxLCUocWmv0KFTItJihVN44o+alrxIBUQrrHDYvEK3pD3ZQaIwNcDLpMOiZQ6huYaCmjdQndg7qiMauqHmb+ybJtLplY0ZqiKTZrpCWaihezfX0OJlRY929XCkC5xgEloup43xYcFpZvridsNIQ7l3V2KZHGaYkoOTbMO6+VSXy5gOI3MbX1W0FEahI1yLMV4StFlkqwno7ZPlEh1/aGvDaxhIhCt2KysPAaJSUBMZhkWJjTd6JePepBZYWmlV/35N6IdYy8RGZd7FSI8rNjk1kxB3UKG6lMzNZ0348mxghRXRViSi0lIiVA21Y9mW3XGsoBjkv9DKu5Y4LTnAotimteI1QZW5qYok7kq6SkksyGrjNHsbjAbvMirodEe7U4UaeOiqgCDPjdGpy/GqqYpDqQKoPBOtSEShVa0+oSW+6mnGpkabSiM1ceb2rUVIwVRnVARB6/P8x5Fpm9L+q6xImmbeoeuAp0V1S6bp4DUEYIEZx7RtfoN1e4Pyj7yFbu4PVYcYmAfHSGsury2x+7XOE2ZD9nR2ud1Z4+IH38fWt1zi5fhoaLcLLz9Lb61FkPYIg4OTJu4g7i+w1V8kvv0a/v8V+b4e9jZewA+H4+beiuq9y6bmP8+rVy/TylPt+4B+wdOIekr3r+J0hBwdbtNpLnD13gUFrlcv72xRZVhoquRRlFOeMpdjbxSeerSvPc+aux8nTLpG1FJX44uhe6zF/aCRnM5ongRaNrlpCI9VdqeyclVKVh8Y0LN2PFBfEj1uefpROVLM5XWmxUc1jZPQafjovVCM18TlnjqpBb+dLas1AXuUmvXs1ww4/IrNWU1B4dbhR4aVqX1FrCfpDnC3GVUX5PbnzJIVDWctilnFpGHJpJ+MCCW49JArNGKml+Q7Zr4/OHK3f5KD9m5FXuclnBVV7WtWlOybSKN5DmoNDEy1HRMdb/NTDx7j2ww/SUYoFXfIsEicYL2gvFKkncwW76QELd6wTaGCQUjhh6IRQ+0N+LvOgwLOovxoOamp6IMjh8njWPXDqJNNo7XGq8loGjPf0lGK1KKGkSoTrw4Jnez1SFfBuB/taseuFsHDEqmxp2SpLHmX+gsIoqSnqTkr92dawUvM9U2aac9P3ZQ76S+ZVpHN4ODK18tT4GqeQAYe6ZvVDQY3RbaO6pW5CpqqUVMm0Quu063GNQ6D1pL0hMlNJjapTPwEAjH5WxZbGl7Ll5cwGwjAAcr7x4lOcOnuBxr1vo7cn2GSAayySZPv4Kxd5/elPsBa3iFptXn/xWQaXv8jqI9+LTXc52HmRVz//b/C+SZF0icKQv/6zX+eeux9h+UM/jdFCLg6UZtDdYTt9heXjZ/jqx/8lxoScuPc9nDp/D8377+PyX/85ey98iUAZcufYpIDefRx/7AcJHfjC02w0MVrRXl7ijU/9Ovv7l2l3lkmU4czpCwRhhyhukvW6GG1R1lYyO1LjZqiK1FczTavxh2YaWDNDbypX7ZHmlB63FvV4ZlpV+FojuhzKm8rDqGxhTices5XI+M/jPTGbRMrRVcnUdcq0qOEt58JqPm1jlILKpN82Aql4P+IK6mlLLjWhPYoojC+TpZ4TUiOcdo7tYcFL23CCISy0CI0GU97r0TzuWwknt6w4bimD8ibRXzf9eYe/ZutDsfowSpQuRccAZUGVimwYpTjZtCPzRCzQHn0whceEBSZXRO1FGqP5UiPAK8GrnFK9cdp3Q1X48zoKa1RJyEyPVKmj4LDzS7G5OlzVTESrUpARgbAo2HLCMkKYOa4C5AWnvDDUloEX+plDvBDZoLLrrMEbVV00WU0hoeai/jjM25B5lbu6WT6hDrFr5vNKJvDLMVuzNsgZVSxqjnLmdOtpEoDqrHw1m7TUkGKz3JdRC07pGudfqWlU3piXpqevY1SR6JL8Kk7AlAec8RmR8mzvbXL+0feiow52uEEaNAm10O4NuPTypzEW7v6un+LY2bMsPv9Znvy9f87qqXuRE+cw+102t67w1vf8DAv3PM5eELDw+d/jM//u1/nou34QfeZ+Frovsrqyyl1v+wBWnyBrrVLkfVbO3U/66PdCOGTnmc/wl7/3T3nibR/hHT/xj9m59DrFtS/x/NOfQq3fhV19FG0CkiTBFAkmE778zCf5j/7WL3HyiQ9T7B5w5dolTKON6/YJrUWjx458s/O+UUUyEh6tQ2On5INq/0xl7eN2j0y1PUde65NAUXM/rBImJRNy4eyAeyLxziEH1jJJmZ7jIHJ0i+pWweaWebeaJpLXuxVlCC3twOujPDUhNPvq2mxldue9MCw8WaxZV4LeH/CFIuRUI+LhYY6zmkwLgTEEel4T+1sqB2492xA5At717SiD5gzbZ4NIfQEpbQgqrZhMwFWELqVK21nvHc7nOO8pvMJ5TZ6XvI7lRojPHcrqaohVUFpICHUh6DevgF8NXccQvYl9opp6yqyT87QsSZl5eJSUktFBXrCXl5yRxWHBpjIsi+JM6tloKgZ5QZpmaIFAB6WrY4VaGpX6Upp1TG7mrFK8TOtlzVb3chNjtPrv9c02y9RwnRmJbXW4OpmKxvrw0L3GV5SZqmle1jQlwzKDpVc1GLO6aa0+km+Z8KRHAddoXbazvBpDq9Ea4zxGebI8p7V8opRk6e/SWzlDw6as90OefOmrPPb+H+aV5jp73nD8obfR/Y0uG68+zX3v+3FON/f4+I1rbPmUMI4JrWF3sFtaqWrYFEfkMg4GfbpBSOoMeW+PZrNBkfW4c6FNHIZcl4zYKo6dPM+zmcc3ljgZBrz06tdYeOA1VtbeijEheZHRbHfI9/Yp0h7DKy/z8rFzYGIG7Ra+16UBNMNG2SEYzZlmPngz+vuqlTK13lSd4Kdm2OFqJl0/vH6kPtcYK4VPWrpSm8nMHdRqPQOiUYfIVEcRa1FHwEDU0cPmWciOTGsDjTu3Mgt0kWqmVFXUU+6sI2qAlGq+lkrCx5Xv2yo4dpDwedG82C94sJfhjWYYKkxs5iGCvokW1Jt8AaVuiWz7dv6ykyxdap+fMHJOrCONkNJi1eDBgFeC6NFh7MkLTyEKJZrIlG2eEclHK40xFkkGpXjdPGtcfRjyKuoQJGl6yohMQwkPpfZS8hzGpX1Zno+WSiYlFDgTOJYXHAxzLicFkcDZZotNyen30pJP4jwhCqsrC9rZOUatZTRr5atmKvWp8/uW/Bl1ZHCta2bBnArgqKWp5rzulBje9NC0jpxUN3FyZGrKwVQbRc2bCE0deqOqx4/hWmMo80gHbMyJUCWHRDzKeeJWB1cM0Mbge3vYOGY5bNHLUhbXFsgHB2zcuMFb4pA4HZC+8jrDR9/C/Xfdx872FbqDHuCJGg3WV04hgwNUo8GJE6dptzpl6yzPaMYNsjQhCgOKTNEapmwpTVqk9F1G78Y+Bzs3cN5xfP0s+eZFXBhjw8XxPHGt3WDbZwRBSJJlLK6d5gd/4D/la89/FveNr9BptHjbR/8Ou0sn0IVCdvfKtmHVdp2tHI2axdvNSy9m/qs4hIBS9bUsowy+phQ9NWdUE7CG6JnZxxEcBjWdAs0PCnMCzC2T9fmox8Pdlsm+rDPnRyFTT505iomtb1V1+RHgAXKExAsMUzYKxTkU79Sa17b2+HwL3q0gPLOEMYrC5VgzOuC+FWjuNxGNDrW8vv2BRSiD62QByjQfrb4UjbiSrSwOlC97pWYyswhECH1BYQBXlC0jFVSkthIpYpXF5TmB1ZMsRyb6kFLrh4pS3KZB4lSrrH7zxhgwLyhTDgl1RZATXxIxcy+VQKDijn7GpeGQbyQ5dwUh5xqaF3NLtr1HKqXgYJlklWQwz4gnX2sdoaZ6jHJEI6puhjOv9XuzbELm9TLV7SyTWwjAKfUm0B+1a/cT4cuRvteskVa9/Thf5gXmYTlHGkmjmYqu4MR6NDj2HrwjildJs4Tl5WMcbF3muBuy2OqQZQPazSa7zbisRMOQtSKhoYWdg0v0BinLrQWyLKFnHFEjYrW5RJoM6Kyukbbb5C4nHxwQ+UXaYVy2QtIBugjppKVGU7MVErcW2L+xh3OOKAjxacKF9ZhN69Gmw8r6cVpLyyw2FBtFQlE4iixhZ+MVgnd+hHe973sJL7/KJ/7gX/LFP/td7nr3j6DCBVSgSyqnGoE93NQB6qWo3d/pPEHqe3uewucRh7ao6UJFZlozk3nZHHO1OYeIOpzpHEIiqUNzlfkrX81xCJ1FC8vU6pvIsahxaVxVH7U2bZ3QW09QR7JOmJJbN/rpTgQ1HHK9MKw0mrxLhN/d7/LF7YDHwxBzdgkF9IuCphJsEH6Tx/Tsiae46bD0OzU/EXVkHLNHZYez/cqS6WpxUmoIaUp0yKg0VFpQtlzkXgna6JJjIQqcB6vwhcMG0VhWYs5IbAalJLPt4CPfyNQBWIMz19V1fDVcGw0crRO8KJxodJGzXWRc1oa2FKwOcl6JA/LcoUURVwvYTjF1GTO1Z2cIEw+Ew1pa82Ymcyt5pQ5XGzM2nHK7/eGjb9ztNxWPeqpWcxJKNS11c6gik6nseIo8OTUJnhxOUiG9yh9ZMuF1xdZ2RUrcWmR1/QwbG29w58vPsm866LjNcLBH0WywsrxKI8mRRdg3lvU847O7G7TOPcSxdoP9Aezv7qFdho9i9hCSg13SLKMdBlht6O/uIMDJxRV2XAfvk6paD8mHB6yvr3AifCvPfeoPaIQer3K6gOT7bG1ugrYkCFme4X1BI4poLTbp7lzH33UXdz3+fh595i948vmneeI//sd0d/cxWUHh/Bhiq6usa3QHjZsD2JhaOOow7ajuycEc1OboM9IzrW+ZB+CYR5Sdl3jMQADmBQt16LJrvjk34Zuo6WpEZhS3x3G3JkE0BZcf3U81Wpt65p7JBLhYHZzal+ec9pqtNOdrDu5pNtkpAj612eWH+ivQDLFhjLVVwsXkfLh18BBu0oo4+r5908HqmwcD6Ju/fuWaONKjKClNZF6RFpAXJWrLe/Beo0wANkKZCGxUDtalVPwV8UheoKImUovqs9mQ1HXNp4hsR+fFRw3gZz8Uj8JRMrOVCFYUkZTDM51kXM5zNrXlhApoDAqeG3okcwQmoKUDYlXKJatKZl9phTEaoxV2hGgxulxcGoxRY+mJ8UNP/D60Ls1ztNIYXT706DGy+q2kV4xWU99bb/WUz5u8lq5+P3mM5DHUkY9SHoPxdYyvZ/T6Nfvh2esaP0Y/o5pBGT15aD35vvHraVV+ffS6evTQ5X01o+sw5f+ra9TKoxGsgkBrGjYg6e+R5Tlve/cPkecFz/3lHxKsdVg4foyD3h6yEPO2d36Mr37h06TpJurESTa+/FdkRc497/ohFgJhcWkdvMflCT4M6CrY6x/QihssBBELSuOdcNdd/x93b9okyXVdCZ77nrtHRGZG7rUXlipWFXYCEEmQoEhxF6URW2pJbdK0jWy6JbMxmU13q/s3qL/MTFt/mJ4vknXLZmxMkrFNakEgRY5IERQgkgC4orDXhqpCrVm5Z0bG5u7v3fnwnrs/3yIiCyBHNgVLK1RlVoSH+3vv3nvuueeXlQi+AAAgAElEQVScwfqVC6BBB/LIYcSs0WjOAPEQBw7OYb59EE888GH8/T88g/bBBbQPHcGFc9/DJz/0SRw8fgZ7wxCx1vCkh+lWG/Pzs+hdv4QOA2/cuITbq9fxkac+h91+B1EcotlowPc9A7Ek91ISEpmz5L5IMv0SicztUtovr+qZCzJT/PY1pUUZpF27nsyef/77zpd9TgmbK/0iUfgzpdckKP+6Qjiv71xzeo2UrR9h91n6le63bP9k75d//dJedFxBRe7eCIjC5xTSzkzZf+QTocWMaRBaRNgKI7zS28FpnzCnBb6zuYP+6g6G3SE8Yb2drLcwM09QIfDovG6S4DIyC3x/oS5vInzNXoQQRqIimVSXMps1EFb2WQq2cxv5yGsUkmQqmeFCW4mnFucaxMmgGzksnvzMZKZG78osoLIRwYmFcGSnTQWBAw8iMhxn6g1wUSm0oXCQgFsNH2oQwlM6NbiKXR0pEqVA5k63cLVDfK4WrxzK4lL3oRrmSvyvUa2xwxOvsBGwV96sNA36XHKV5FRR2OnW5gxW3MYu1cEZNYA5kWXwuRAmGbKH4TOZvx/GIeaOn8bTn/8tXHrlBbz0J3+Ilc01LB+5Dx/6jX+DxQ9+CrevXcSbX/sTrO91MNeewS//s9/D8n0Pox9GuHnrKubmlhDFGhICfjjEVHsZ3eEQm2t3MHX8Xjz0gUfww+e/jK//5X/BqQ9+Fk//+u+D4hjT0gd3trEdeDi4fAIPfeyX8IMffxPP/d//K/Y6u2Ct8cjnfxuqeQCd/hDTC4exsHAAqxtrkF3C5R98Ffof/hzKb6DRnMbjj3wcenoW/aEyBx1rIyCKBAXgbK0kUjaVlrQ0gthQ0VfjKoXa7K/Z6TeMhOxLcJnDzOPJsP48PSBPN6nqt7voAzt6XTpHYqrov9bcmRwj0YqXajttTGwk5iUzhNKmFywDbGlgMYrQYolvrfTxSRlgaaZpoFlpiQpKOe2SUQJJY54b4+4k5n8azfbKCyWgov4z8gpss00pcpPbabeAldP8I2dogkz6ZP8o3KlPzrRwGO6cRTZnkExTp//GNYGy/5AEldghZE2SEkl2jmMTmJo+tE+QoUY0jKAGIe4ojYe1QpMYVwMfrW4PgDA9HW16Im5PInM4zJr+Ofe32iAyghdO4xuKeL9zC6qDDKgCCgGqO6QF+YmiJzVRaXNS6X7WfXguKMQauQ9l1xrByL/3wxBYOoCTP/8ltA+dws1Lr+NUcxZoTGH2wEnskcaZz/4upnY3EQ92sbCwgL0HPoRGt48uMxaOnMbnf/m3MbN4HJH0ISDROPk4/ud/9x/Q5SlsDzoID3wAv/X7/ws6a+uYabRxaf0mHv2V34ffmENDzmD99k1wpNA68WGcCIHuyjU8euYggplZLJx8HJ1+hEFvD4vHH8HHp2chpw5jtt3EQ5//l9DrNxD4Pk5/8KOQS8dxc2Mdw50NtBeOWF0sbaRKKO9yIYQoHPxUg37QBMuNKlESrgRCitAq1zOrUCbSFBMkqmAaUSGgEdevWXOGUB7iYs6u0h3aHbOfqBz+oLVNWNlgXMnoggTgexKyGeBmzLgvDHEsaOB7G1t4ICDML09BTPtmcDuZ3UoRPj0212MuJla0/02/nx7JXcisePXYecWGZoaUxvcYpKs3PRUOPseyVXgCOuqZSsZhLCUImnFKFLn5hap+jxUlzlEVmbLKJZcRJUNTlrIXKQ2lNGYaHpoE7IQKW90urvs+HtYCB4cxzvsBFDRm/ABRbKx2tchwQBKiMPXqHJyOrWj1/D3lt/kkD7gi8PCoBVLsndyVD3N92KA6N9REx4uz0irnK0E1eDoqnndVRekEa2IB4RlqpYbGlDQWtM1hiIgExPJxTE8tQskGNGv09/ZAezuQ7QPA0VNQ3Q1ssMJgrw9eu4WpxQOYXziG1mNfxPp2DKViiMEA08sn0G5PY/udi9hZuQJuPojGodNYOPIo9Mp1+N09zM8dR6yBVnMWjZ1NhFubmD14L06d+Sg6pz4Emp2H3++hNxwi7PVADCweexgzJx9HRzYRd3fB9z6CvROPYnlvE0MlIHd2QP0eDiwfxaDbMf05magf6zyRQ8rS0Uc0uv9WfAaTAB/5fgNNiLG7lPBJ8Zi6aiZr3FOF8GJShWRSS7ah7hhcTXb+UskWhJmMGjI7hBKrRA1KxEqBXcW4HWkclhLB9BSe297Fwu4ClsMYYqEFIkJMgJ942Wt7+CXK1wVVy5IuGBwfdvwUgshPBdqqfOZcX4JVmbIQp2eslASEIYSX2d2yC+U4/hzJkBSlEBDlbGPTAMJ5ngblhAbJabobWmmoGaFmTCuNQBG6ocJ6f4DbjWn8IkfoqhAviRjzmjDd8NDjGHvaDiOJLHMml27sNO24wrlxZCAZPXE4UQY56r247kVpzCu7g4ejftSZos59QzvPJRcIqeYgo3JCRMUAZdVZNdkgIhDHEZgZLSnR8ptQUYhetwNJHpZJIuxsIRoO0WwEmGpNQ8UKw/U1eHEIjiNMe0NQYwa6N0Sv8w66/izWN2+iNT2LpjeDzZ0d3NpYg9+cxbETi0C/D331KjpTbfQ048D8UVAUo7+7Dt0G5tuL8Fgj3tnEgDU0AXp3G7EMEJIwVsOSMYhi9GIFr2fo8Kd8BSkEwtYs+sM+EO6iJTxwOIDveVa6gwGrBAzXnlrIcrPduavFZjrtE/TkEUEle0saCS1XKt9VHHAlEzhGheQ8lZKrTOYpq0qYuXT9PGEKT4XxBIOaUIqcJLBb4lviEUFpRg8aNxRwIiLc25rG/7G1i4/vhljoA2h5oMBDZL1qvDRB1/ZddHmWi0ZgcBMFkJ/RHMk4KXrOuR+PWYZuA8PhTGvL0fYEgVUTsQC0ViClwSys05pE6EtD9LKSzomirKBEa4kyDSdX4JE5xcmLU9epA5t99EJICE2IQ4VurLAXaWzJAB8YRugIwu1mgJkoRsAZy0tIYUTxCPlgVyk5Ss6m5UKvgUoj6zRBtGCurjp5BETGpedF43t1RJXPufYaKyC3tHKQVBrEogKuXtV/qWWk2J6LdSNJszUpPetJngzjCUivAZYBtBBGFl16BitnDS0kWApo+JZSbD5v4jk/JB9Bcwp+ECAQEhoJzVhBqxBCSHjtBcD3EQy60GEfWhNa022wiiClD8DKiVh5eS0ESDNUHENKCd/zEYMQMiB0CGhGt99DpBVazVlMzSxARyFYK+zsbGBm4aAxulKx6TGyFXtLfklRTlNcV8J0f1R2LDL9Nq4PJORkx1w6BiaQ7yisd66pkokKCgtUUyEXZik1cQpXMFnZT6ZcAOGcpQLyL1CxMXI22NarKJ1FsZL+ieeLsoeD1gocK2w3fHha48Oigbd2QsxNCxzrhPDnBPymtPA/5+R/ipYQxaqEqKYq+ZkMHY6eS/OqvsPEI8hhVLfTM6ZX4Wc0CD4BPswUuaLYOMfFMVj48KSEH3jghgSRBmJjLgU2InRSGFXehMKrne5D0h9h4lJBzLB9EzuVCiL4lr0RxxqbkUIv1hh6DZza6+JiI8C7nsTBUCGGcfNjIeAbFUbHqIZypln5jJxz5jmltl1xU/FdP8MKO2GqnFphHr/fmahaosKhfIqiiVZprs1xo0zVZQuNX3fotDgGQ0XBFfdKdEaplnYOyE7SaxZgMGIVG/dDL4Cy1+NJAd1sQMBocilWZrBWACSMb4SQRsmWhARFEaamZxB4PnzPWAhrzdAqAukYXnMWXmsGOhqgSYCKQzAz2u0F9DsbYCkhPB9gjTgeQmrAEz40KxAUpPTgexJaaZCKELO2HiIBAl8ijkOoYc+sNWbMzR9EGIaWuWSkQouZvBCisu5NKpFKh04uN3vTtcwVa8pxGOR9njtUJd0xYjEWRQhpHKZKMJbJ9tuaE/g9STR1Ru0llDQvctTkmml6hhlsdu9dYjZGBGucRpDKMArvECEMNT5GHv6uO8SyCDC7G2K+5cNv+VlyToVgMopfU4S0JmV+/XRjSTmQZHIWrugf1zAxJjvd2KnMBOnccAypGIIFpogQt1uYDgT6UWyyTlZAFEOIANJ6MMQ5+IjzTmrusEzKFsumbwkaHgFNYYLOSqRxfaCBWOMQM7pSIGJGkzNRQyYCCYYHUZqWp1o0jyaLDRUzGO/Hk03wY67u8ZcXmQuFFP4/y4QqpvFrWreuXXEahLjcNE3Mltyqqs6PJlVsTgT+mKFlUnHazZxsdtYgnSmuai+jXZJl28hkZiAdnjSqDcyAJwkkG+axsIJPxuxKEwAtIQRD6BACGtKT0MLMJQgo+NYUC1DwPGM+ZTTMYkMVFxIkGEpHkEQIPAFoGAtg28RNrICZtcmAWRvnTTgioIW7LoUYscYKkGHFHFNV3OZS851qZt+4pldboQtUCCA0DlqqmTOpY6ElTqsyp6Nl5fFTgk6xqqLSa5Trgsy/JzONy2wWiLLABU9CEKMXK6hOiEXJOBLFuK0beHcYYn7gA3NNewU6yQTqz89k8t6B+O++7/nTq1y8UlRLjZl0BiUxOwKclKqF1jXuUuUzWy5rp1POlv/PUgJKmeonVhj4PhYkoR8qEAkorcFaQ4LhiUymPaG8coIR6+qNUTUUS8xoWfOfjmJcjyIcUsBxFWPDl9AxY1bH0CLTPRWwZg8J7qqzIa2iHEtKhaXibmQUSYVEkyLU5QN80uDCqIKeqvHqSnhrRHO88o6zAyi7Kqsud5QKzic0IkkhR3iwADPIVL7DulxqZT3Y4/SahdXmIknpZUgWqb8zw1Q2AKB1DEBDeh58z4NWMXQcwycJz5Ngz65JZuh4YN7Dk+kBzzqGHwRgVtA6hhQSnvWc13EMz/MNzKUVlA4hhYfAk2BNUNrMAQnYOQkSxmhLM7ROYDuk2GpJvUo4CU4VvbrY96qCRMgdIi1k7VyhA8dcebIXz7cqR88qYjzVQb1UJJ1U9NU40yGT9nrNIDrleidp5Y1iZU2Vg40uzMbWdyg1WCM4YqKmIjLwvQciYBDHGHY1rk0FuF/FeEszrg5jPNIbwou1eWZkeiK6lE9OROH66QSNuzTG8ka9LRcaYkQZvDHycHHmR7Tz2poZCDWmpgR4agYwrFpc3xng5zpDqPZ0ao6TNLJgs4xMiiST46gexrWIrk7E/8wyEtoM2A8UgyKFHRJoacZ8pLDHjJ5ixFzweafMkS49GqWhjGVq2K6fRj5vy2/GYrOTCgybu3iANBrTzlhOFaUQjXnhClmFSrZVcf04E9fCgTldrxSqOFgqYojzeapYLAVNNiebdDNFElkPQTvDR2wdFi3vxlZIyAY/mSCkhJdqs5mJcsWcerJnXjQEBWVYesaDOB2eI5aGIuoZn3WSBFLGXVMICaXMMxGwg3pWwkewESMlYYQC4RBOSkQFKkuHUCUHRuRtmAv22un65erakGvPNS41L0Y+4/oHXfoJqpL3KFUq1gMI2bBfkoCklQSq27llvbni9dGIjmY2YgC2Ksz2z9JWz4qBjgIO7w2wQh4u9yKc2tyD1/Ahmx7Ih33A9aPqzBWJ3ciA8rMfKPH2cykTZaaF5pXmRGGejW91FGJqRuCe+Ta2pZGqv7Ldg7fWQXiwZaEAs+iFlTNQSSAhl41BeVndooEJssUE63qolJnG5xgYgHCABObCIW4ICSg7SGmzZuHATu6AfY7pm1tgnJNkSTc2V0t/ZtCQuKtgUTx8mcuLMBMh4foUr6qD6aoBM1dqG1FN9z0dBGOdycADmc+6e4hRhd5SRVClgrMGV+HFJOwgrAPGWMl5YXtsggis3fTW+G9kem+U4t5J30Eg05Vi6wapmbOgZD+TkNYmjK0Dof2wwpMmMAkJ4QkIkjB6GVbexCIbSepEwkS/pJkrWKTGbFwrR6IqcvsqVCnvEEMl3JOc+ayM5loeJnQrEa7h65DtW1aUEiPqaqo4SPNSTdU23bl+aQpzIrcbE+JP8dXz1U1F77GQCBWVvd1nk6ANDRjJaMGEDSY8sDfA1WAa7+zFaOldHF6cQUt6RloqSVBrzoI6cvW+acA/20BSISmNCdX0XQ9mSoIIQ2uFEATJGkIwZqZ8HJ7xsS09sFRY2wuBnUEq0QymrJxHUpEQmDRyzKySg2JSpur0m8QMoTW2SGAxjLChCRsQmFYKB5gRE6EfRyDNRj8nmVinwmOlbBGnqtnuIcuOGFxaH2tH8M6d1KWaZt8E2cQYSq7bi+DczuByBlmxZKmg0FrVIKkroIgdaCQxB2IuNC3duMU5qfNSflgQb0x+Lhk8y9GuydqlWgg1tQC26hTkRP9UKpzzysuJMrRw/U+c2s6wgZLwb5rwTFmlQ4XulFkOEuRJ81pWOJSc2RjWlA1H2YBIruio5vxqKQhrmsepCvVb3ZghRmTXxWZ81m3jwgbXaTTm9LmXfeXqZ0vqKnAac3SOtnjndM4vm19yrxWVaRuX1n81e40qq5Q8BCuSathhjsZE0DHQZ+CeoUI3HuK1ngb8Bk5Oa7CUUIjhCW/sAZuZ0XG5KuH9sHd+hhVJsbLYb+RLWkmJ053SAnGo0JQCQSvA8RmFc54PpiG2ugMM94ZoKuOymEqkJD0W7fQd3JOM7EGhM8XZhBYskoNeK0jN6AuCjBU6DKxpwlHNWCDGdSEQDQfGIlfkN3OqcJqTOufMt0pkTdyk/5Mel1wm4KaSMJUbfMIFME7WIQf3lqdIxsJoNYgDFUogqsC6mTPrU6ooxDitTApMIaoRknFkzIVwpTrKZT9TBm9lnvLk8i6yD8IZJMmc9RakMJPLwl6PJOF4xVBOSVZZGaCEWsuCncrLaeRTQjs3olZCZg6frI20BjQ5/SzrcWO9crLECKm3Bxf2otY0YqSLnPp09GQ7Z7E99ZLJPUIu8kNq5pRG9WlyCp11wYwq56ErMfwCISTxBUp7nMkgesGygUdAqFV9GK7J2JK1LFxI1Va0RITQDkLvCMLRbh/XSOGyp3FwLsZJZZo5xMpg/CQKzEVU2DP8o0Cy9hFI3suvomiilSlgj8CNBnYaTTy6NIMfB22sa8bq9iYudGfxoV4E+BYXlhKkpGnUc959r+rOZcNGAqmjNGsI6zcyFwMrvsRurLE8jOBBYNeTGJJCoJSFZCRYugNcInNWdKxpiZxll7IQOMtdbXZEObVTGgENjWKy1MBSVA09coGVk2N8FCJOrq3KKMEQlFNspWq1gVxwzKqfZO4nG5yjTMLbPeQoI3NUySJn9x7VysmuyjCXp66p4KuSqiCAc7M2Rp4+y/ZF8v8umcM28JWdKdJALphShYIoOYZQmQS+MHNSSQElCpWqxU/Tqq04b1Mlw1xhOCYq5jcIRXgrU0tLAhcl69nJINipuN06hdyAXpgFoqrue24vFPqGXJ20EnO1OmsOzSan05OpH+eSINfqwE1GilVHxbxMCm9RlkhVcA2cZ2Tuv2/X1VBpdFQMCghtr4GB0rjTHeBQYwoCXrIIkJXJ/zggq0l/ifc/iOSJsEkGL8nAAX1J2PZ8nFmcxaGgiYZsYqe7jXcGHeh+H1CcKnV6UpREAke9L7su02w0cKRdyPNxjFueh44QOBJGIAAbnkQEoKk0Aq6SWaw4IGiye0BVzeuaGFBvxMkj4MNxt9+Bioo8dco2Xem9qQwz5Mp1OBldhTR5SVOr8L5VwYjGympj8ntfEULqXp5GSOvX07vr3CGL1Scqn3nCVBNitHw/UWUBPuJ6uSKIFN97zN0i168D1a5lda+VCyJc7XpYsYZLa4+qoKzxjcJKIVAalXjxiM/ivr+zR4pzg8U5KiqmfYyAgIYAYqWwHg0hIXAwaCFWCu929tDXygQRltUT7PtZ8/z/p0AywWeNSWDK9xBYiXOoCAMd26YKT+6OVqhwuaoZZV/JY0YIQswETxukW9mJ+USShcY+PM4fzPt92FWH6L7OxrtbKTTpk6FRUJcDYtBoaIzovQaB0Rt/TP6yr/ekiRq/+79+muA6R6vzVqBBo96LaGLcIx8neKJPQCPPuH3s10nmSGqy/InXbClJGeX/Pv7+3t1BlyVyieaesueRJ0xVNFQaOrXo+EcXG/a33pljrnQ5G7GoGIDW2vLczZfve/BlPi5FmtFVEYZhiCYUGkoDgwDdnQjDRoTLt+/g3720jRvPfhuSffxPX/wIfu++g7j58UNY4xgfuLOHOJbQFICFBHkE7Qtoz/gZSM2QbKoOFoAmDU0asVYIY0IUAiIGKIoxjBkDxYiiCLFSiGIgjgmxvX4jgW854Xb+IPMqyAcrbTW+UuXiCTcj38UiKbNuMkl8ZkNk4JQenci6iBKiUOVGJ2yVSNAgaEfyn6DZzEhoJOiUMyHNo6qoKtjBGaxCBi+IxMYUaqJ7UvRd02R8tnXi70Iy9WwpYHt53peZXAO0MtpVFcw6oiI9e0QtM8Lrob6Y5jLl9C6lLhrNqf2lqXV/ldOuq/tBfl+ieEnVt2Y2jcElcoD7yprtYYz8WnPvMuf8sB2qHeedGMk1iCa3H1hY75QIQGUQmTkT7bJy+ZzJelRG8qnVEGg1JDQJUODh+P3zuP/kHHwCoPtoCitnI8j4OZFvDQIZ0DGgFbTWYDJmNCwL3QmrgEuJ6rGdm6OUC59kesIRidx/lcOF0QJvf0dZlc8F11eejqESQYJJQPkCuulhKhA4NDWFzx5S+KvpeezpAb58ewsH5qbxhWEDx/0WtgIfYWClMARSNo3HgHC4fSodnxdGC8kLzA30NEIdIyRApTNdPkhLCI8hlXnyyUI0A2GwQ2GJCU/G5EoOw4QBpNkNMBXNTBofQPbtT5MeeMm0/X7aXJO6JDqHRuFQzkE+YxJCLiw85snvQe1lc+1xPMFhyYXD0J/oDlUxdkbGj8ozlyfepMWqetwvrdX+y6XS4GH2gJkniQB6JMw17sMVLbIZxd4eO5bZ2TmTKE4ka1MICY+8gnQ8cvu18p5zeUzYfWZEZciSnHMtZ3Vhk0vBGcEoQS2SikhAAlpDM6MXayilQOEAOzsNbGwFWGg3MOtPQVAMUFyQGtIZE9WpsphoBF2hguI9Fja4+1/ePsEP52abixXpB6LKusYjAZYS0o7HqqYAs8CsT2jOzeO3Tjbw9r3H8Nr2KlZvv4uv9IcIVkN8+r4FDJ44BJoOENvsmbQ5/GWsbfQwGTOLTCVYkoSQElJFgIqwNYyw3htCKKABQIEQCzJMMB1DcZx5XlvePqmEdWF/56rMLX9TuMozJOd3PaIyKYoyclXoKZAwE20fKQy1lG11wdlcRFlMQ6cVB7OANn6PebMiZ9MIAQhSuYoBjt/DKCYfc92nts+NCRoeNNP+yndnYwvbICYYxQGtbaWodV7iI6VqO/inMMKKtiuahzd4dCJQCZ8UPjtXbasis6poUcw/GyCDS4Oq+cb7pMnBfqrICfCxMkOM6pMGSv3qGYp1yuYre7cXg7GtdIhL+49KPRqqDia5CiWbj3KRigyi16ZPbPeX53vwJEFGGiImbGz00Fcapw63MX9oBux7IMl5oTtWWUAhdmDyKjldG3QtG4RSYVL6qQSQQiDZRxBxKOSJSQvVJLAmkEhAmPlhQQTJhAAw/OpWE4/PM/63B47ij24G+PK5n+B8v4Oz6GJp2MCTLQ8HWxLXfQ86HCDuh1AhYTiM4bGhZ8KX0DZQiSTrjdnIELCRjN+IQwRKYUYLxMJDlMgcaGNQwxyUMVU7t0Daocwy8s3/5LBkrsi0arLv/Sre1TUI7UKiyJlsZka1z2AVL18DHOYyOHfXJBmXoAJBmSrmUSoGC6ven3I3gcEInax78gXO7mnBxdeuqIJS7r3TZmINVvkGKbke4ftqxrxHHL3u/jFP9t5isvcZf+g7z7NYqLwvn5tH9gtzP0N5WakKTD57vuxqBOb7eJwfowITO+3zNDcaX5VSvq/k7osksTSvbTEuAND2Z1RKTMZQRSACmpoRIEQUBwj7hEG/Ce5GoGkf7PtW9oYslKWMhhwSdMqeUaJQVaWKH5ZJKVBL+sSIAcxJsqcEBkyKQ2/UIca5OpcKWbhliljRuuRAZaLSTKqfZPfJRpUEHTKihge6bx6Hfufn8Nnrm3jhj7u4ubaJZ85exNXZKfzBbBvLR6Yh7puHUBGi3i7UMEAcm0Ex6RnOvbYQGtkZFBUzhrtD7K51cGFlG69sbKMRRljQQAiJkCSklVUg5yRxMXyi6uZgWjLmzJuq739RPPFueiSjNr3xp9AOPEA5kcwxzbFUVNcVZzS/C5tZZd7wKJgTca3R1shugHPmGSyYHGxea871Jrg23wI0q8w7kTIcO4EjGVSogbLPncpnpAdR9swph4/fDWTI7+HfVoBNPMEsl/T2f5BXZOrZjBGNrbrenw4t1QezCSG+bN4LdWrw+Xo+UcfIkUdqnglXnoiOyKipEtIeDSNHRSfOBkuTta7si01rxhQBe76Cnia0HzqNh9pNYMrDUAs0BKWz+EqbKxbCCpci2yfVnB+ROQaWaZWotv94b4/RK74glxZb9clUUo0SqEPjTO+iOCDtEUgxtCewsBDgi+EUFh6+F19/p4GvXbuDCxTgD197E7+4PY+fo+M4MjONFk2j1fSgaQDlSSgZgGMChiFiVoi1AvkNKCaofozubh/9vRCDPhAPYdhagQAHwDCMocPYyVi44FGQpmIlHJXYLX15opFCnqBneTcZnrYBIQc71mE0hQsguzg9T+bkwwk6La3jUFvICDV8DBrdr+ARllucyZ9IKa2KLdUeCKU7SgSlFZSKAcjKGYv8yFx+ZiJLCjQyr+9x947fQ5CYDBYbeahWHL6+3Oc4mNMf4QL2X6ez9n4Gi33dPR7fa+EEJhmBBGQwMztDxlyZ3FUBfFSsIm02LoWEtPefdWZsl5BZkn5KGCmoSEHZAe2IGF0JbA9DRKHEra0uOn2FKcWIVIxAeuZ5CAEmaeVz6hOrUrzgpLnODoxEZeOs9xXa4nJWyVz0yPwdm/cAACAASURBVKZSv3G0HaZ9TFyzqYS50ypW0GDQwgwe/92P4JQKcfo75/DCO5v4xg9fQefaLC59fwWnjy3ioQcO4977FrB0OIRozyAiD+jEoG4E1jE0KTApxCwQxTEGwxB7e33s7uwBUYxQa4dVYRNyzXnqMI/nzBPKDTjcTTB5D0dSpj3GtvNR4VM4Brxm5ho5iIy9IhL1gELAGDknUAOljOL2aM67S5bWZPGViC2jjlLjMyaCSjI1a6Ym0vkgMm6FzsZLv89OVZQcCED5MzK/b4fqeLLM5O/VmEj+uvp1883lKvkVLmHWhH30Re6CW8vjKukx+6lq9sQpFLKAQVTf8+HqOZPyiI1O9fzYqUgS9elkfSbogdYAQ5nve4Q9T0OQh83BAGudHhbmJOARml4DQgamEyg8O9+Tm5SrsF8oJiSFoJMGkfenunQHUz1Hpc0JIm514mZxVKar181TJPS6JGvOWbqZf+Z7AoiUdaJhtKckWrGPX73/ID7CAk+tHMZX1oBvhD6uDQX8GAhDxmZ/EYGSEFBoAmhNNxDIBoRgxAT0hjFCOUBfEHY1Y1OZrLoHStlYSU6mSaTS0O7Np3yZVsmZp+JG4foNUe6d8HsuKZncsr18CKc3ekRw5DEHHzk+GPlFiRqTIq7MfCc5Peo3db4f44rRpNIYBEfjjFNaJzkZdtHQiJyeGBw6dya3W71BaZLNSEXIcAQfrLJHMvni6E2McRc1a/I9C3YPG3YEUnTJVOan1zca1+ehctAgGkFEr1L4zSP2+fov/YbI3Uhy1mFGkrdTIuzYhqfPXGSVSbJuJWUy02SGtXsK8IcCDA/T7Sk0ppqIg9jYCKgYJLzMr4RgpOdZje8hUqFe4UTkUdxdH67mAElJVqwVuxeQQFkZs4NyDyw3izdqKI8B1hYWAazyabmMV/0IHMWIBRAKkyFK8uC1GlDMWNnt49K1VbxyvYPzaxFUTJj3BU4stnDq4DSW5xqYm2mg3QrgCUJ/MMTG9i76Wz1sbnTx0soeXtnqIIoUGkTwpYBPprfCJFJ9G06zC7tIuCgdUob0Ev/24qn8fvRCeAzyThWZIb8fcARRCXZxpVdGZmcVn1RXSNFzVczjcuY/amQhnd/ROmcXm2qupX0ScszvuHTfcgGowqiOa/s+4/YYjwgcFR+K+a4XDQmxj1VVXi85WZmUgWn7b1ZiyL1wwl0ElLGe0nUNDh5RmU6ylqkyqNSeWXVnLHOO8k5uzySF2DKHVBcyNwV0ovBhhGtZmxATMaEVePjYgQY+cc80Dn/gGIKDTbSkBxELSD+AtndcpmevLsn9VweS6ipiInx9n8/SK75oJm1EeQjjbqBgO8yXLFjN5UxCeBKaNXzJkIKBYQgfGhR7QCBxXyvA0kIbD8WE4VQIXwu0fAEv8CCbHuKGBLcEmtOekT3Z2cWtW5fR2uthbi/CL0R9PMpdKMFmyFAISGmzhYT+mXMKdnJ8zRVEh6KS7z7Kc7rLiDLil2QzlLlfWIS5ik5chjfSvKaQXRONaYjWZZAVdq3Vct7jWWCs2ShLWEaLsGq9gnL+c0gmyIgrJC2Ya8y1RjyCURuQJ3zWhEp5/kmeYfEqY19W9l1qE4vi4eyoSeSeT1qljfelmXSp7zvVqYCycgOH2j5/qgjSVO0fglHdL64rrrmyx1eC0rjaytcM/SaSUWaIVhs5aXgsMa1a2On20b/aA60R7jl+Lw4tH0W/10ezNQVXVTxJxmhU340qnr+bnY5LOvfpwOiNelFy/AloP1pThZKRHJMrbYd2hAW7yBfwhG++yxqKATXoQ0YAoibIE5BHFjB7ZBEA0JSEQADxYIBou4eZoIlIMhqeEfQa7G5g/eZVCB2j6TVAMwy0CNIqsDIR4lRk0/KtbQ+AOW8FRyNmHIhG1QrIWcjeTTOSJ3nQMHIzd4cUVBwOyYS4cGTOmasXXo3AHjsmX6MOwLF+NzUneiZT7/4uLOFDZGKLxetPAAuRN8nSd1PFcX1CzSNYR1RBv6TCJH7ukKx4RlRRMabN1IIycilhoPxnzz9bzrMVqzYzF7F397PRRM+w+Jmqac9jglBVF51GeOZU/JkqUNmyR/oonLqsq5Wr2hLWlVWQZkjbj1Xpv9AgRMlwsx9iby/CYP0GtFSYarRwaPkowjBEEJjBWZKeFUKd4IznAmQ6agah3vBk4mBSttpNFVmdzU+YINpXHwycM7kyLoSakzKNjNaWJ83ouVYQ1AALM/4PAkgSGla8UTpv6fkNiDlThQQEbG9vY2N7E2rQx71HD0FIDw0Z2EE9649i61JtacuZ1DjtCx6qw7NpAqmIn4URzajPUMxWM5l2kXlwpAuQ0wPH/Xn30Ei+qg/46vfe3z0oHor5IOFev5SO9W3h+vMHMVV+tkmujcYE/qrgNeq1qFLNt3wf8z9bkJGPwrEBuDLo2QBUGbDcPlmxwilUNLk1sY8Ce6L7NKaqIunlPc/HOX9OmhmMo1lypZ1jCT6rSmpYKwiSeVjcvmavvw2lhtjb2sTGnRUcOnwEg2EI6XnlyokcElRNg5EKrqK18hK1CdJkwcQrSkpzuQKsjuoTLpccps0MrWB40dIGEXIbYAQIHxR4RlBRGO9qstICQwaiWEMrRrPpI2h6Bt6INNbWV3Dp8kXMzbdx4uQR+H4LAoGVaIYtLE0Gqh0b3cQH21UrLxZfVLn43cyMxwSO6gBTYshMtMl4osq07pdbbVQFEpF4IlhKrHb6XNkVkMNjr5jqniCIcM0WJ+TplWmezxnQqjWyIcjkQBECUljjKCuKZ+iYOj3oyCEPZHMkXJDSGFWF0tjg7V7TqJ9zK8BRlV1l4Cn8vFJqbJAr3X83iDKXV1hiFUxlx5xSAHYOm3GBsTIgTQidlXaZswZKjWSqDo6CCPlJJa6tgrhiuDXpzXGpv5e4ZNpZJnumuC37WLPRBlOmihbWCTNZ6wIRhsM5hHEfV6/exjvvXMahw0dMPWPn9dyEiooNSx6zbnkiXv0oq5gx0FaVIBqV2UC0j2qkqh4URJCCUxw7b75nDwBPpCJWipWZLJcET5hsUzJBwUjEC9tvUhyj1++h3x9gdq6NIGhCKY1+v4PAbyKQgTkUWZtBNtbGBlTkDawym1b3sKNUtNANHJxq39QNSoma4FK10WhM0HjvTfT0ACnh55zCjknPiMg4y7HVIcsdfu5hW1BB5gk4oTxy7XI6F0BEpTQp2UBuk9joV5qDUlM2QJkEEpd7mMrVJ/fAfrb8QZutidK9H3FQJ4lSHaRXaUibMKUS5gtN9vyKVHWdeKbUwYzsDptS6XuMfLWZ+sQkh3VFFcsVhIgkZ+JRkCdXV1w529gRiUipX+IcUelKEaJSnofBUAkLU2Ay9l1VZZLRWnOJFStzEzRc4cZcOz5LzFiYlnmSvEoBKRl+owXyfDSaO+j3+rh16xaWl5dz8mVaa9vTkmX2C09Q2dVVW0T1/ZS67+V7JNVn2mQKp3V3nguwD4zeljBSAkQikzRJFook6zponBIFJ5sdEDYAERhSMogloCXiMESns4swVgbuEj6UInS7XXR2Owj8AK1GC5oVlFY5m9AqaKsksl0BlHLBapTtZGuePVMgCRPVBJXJ+7j7C9x1FcG4ikWkn1Gp/EFbZHEVN3gVvZAov8LdNVulTlwNReWrWuZsmDEZLFRWX0vYTBq2/1G8TspBNUm1lXw+aVwIRWa3nL/e8udPgogbcMdl11WHbP7+jq9+imiFq3pcPqTzW7jYrC9ChMXXGQVdFmFBKvRZaEwQmgSGrcJd6okKXGZrJQkf60wJwk5Rkx2C3XeyVsemoTosIyHy2N/TQtAQRPzARxB48BsNgBqYnp7DzvY2Lpw/j/m5efi+n7JeY61AUpY/d7poJwsiXAXX3YWFhykAY8Ujk2OawK299IGq4J9M7DHLMMsHmPsqSjF0HIO1mXwW5C4U81K9Xg9nX/kJpJRotVqpSFkcR4jjyK4XqoYcaH89knzjSlcc+lTZ2ARRzc/UZ0T8Pk0Wl21tJ+sBmMxJF6Ahkb5GdiBwKWCWg0kRJ2bnmXPu9bSlnOaejSutpfPXkwSOKI6gYmWUm6VwKhKkTouZBIpzPdZ73YUhXdgpH9SQ6wm5QQQ11UjWZ8yvjeTgV0pDa+UYS1Gpd5K9X5LN6sIbeOZzCyr1s0ZCZBX4vZQSQoj0+efWYwHqqSpJ3Osvnry5awPnxU8ngRFHrF0aOfhYK5jyHvqP4yqZ/BBgGkTYDSqmUhVEkJ6EFwTwffMs+/0+hsMh1lbX8OCDD+LMmTPpVQ/DIXzPh/Rkel9LyTBXBxGeJGMtOF1W3v/KimTEC44DzbQjmkd1g2mOxj+XVdSsNHTByxuAlATWAkopSDu9LIT9syfBWqPb6+LK1Xdx8sT9OHr0KLa2t7FyewWe76HR8DEcDjEIh2aTCJEePimjgvaxgIpZGBcCFOV9CPJzA0XGwj4bzjw5k55GaSVRXjurMnBZBV3tYOGJEnKiiuzi69W4/6j+CZcO5iSjT2QmEkFQOIHL3AZbeQgjGSGlBGlGFDHCUEEIbZvuyL8XKNPToiLWnzD1dd7bvXDvitm6G/hKMvmVlVD2elJ6kFIgihSiKMz1b1zI1Q0kRrFaQxVk46XMgpNbrZQZVlQKisVnH8caZANJggbUJTdVJIX0ugv3z+2LcIF9xyVziskIKu+duJInid9FmlZUPEWR5JgdD1yomPK/pCKIKIIQBCklPM/D9PQ0VnkVN65dx5nTZ9DrddFoNmqS99Ew+RjOwigX40l7JDRZhKa6pmGxRB+fIRdVnetV9a2XiSdSlpdpsGkQPMRxhAvnzuHI4UMIGg30ej0MB8N04caxhbOUsgwyAkhDJYcC6xT/HTVBUGoUcgZpcS4oOtWl4jysVaQLEyZusmKCsYWqv3WZNOWGZv5/koNaSNME1AKA0ukBKhK/a21kuzPox2HlaV3THKa0sS1IQLM2TX2RZ1eBrVSKTuUYqwNR4vNujb2S5xcEvs3aVXpYSSmyjleq0kol6Cut2IrIrCtNnny+xCbCmWYuJlHSsgKVUlBKZWQGW3l3Oh30+300Gg00m800O2VmQOmM9FCx46X0oLWCss+n2fSglEIURaWKya0ShQPlam08MdxJbCEIURSln0cIUapqRlU5ppIZzYBzA8c4YkYerRotAyNoH4ys91CdjPSY4bzNRLGKq53hIEKsDKmItekPTk/PwPcJ991zL27fvo0333wD9584Yde0rEkU/r/75eV2Bk0WRcbDLlTzEKk6qNBozF7UNNpW19Zw5cpl/PwnPoHuXhcbGxuI4xie54FZI44jaKUhBaVZAVv9KC7ggSOH+JzmbK7xmygdM1CeWqaJovtkfvQVa3aiDVimaaYBP8HUi+wtSAMNxWw9SZJM3lQiSsVQSlsNIQlQPmvVWpn7lLJ+XGgGGY2FMijJBCDKggdVZdYAQxdgSNvH0RpBo4Eg8BHHMZSKobXOixDmmoacBpz8vSvIi9seTPL/mrnws2V6bnI4CmkyS63M/WCyMIcNhFNTTUxNNR2hv6Krny5AhAn0ZNhpUZwx0prNBgaDAQaDOB24zQ+cGt8az/Osfw0hDEOzP+zB73nmGcdRhDAM4fs+Go1G2iAuQprF4EmUHczZ96rPjSSxqePv0SQe8ZhkP0wSUCYw4dqH85qbn3EBbuMqynB6zwhaMZR1PG02YqhI4vg992B9fR1vvvEmjh47DiElgkaQJgMGKZhkFGMf5pZ3H0gqbvD78g51tFfkm+yjytQKWYMgCHBnZQXnz53HwuISWlMt9Lo9dDodSCERBD6URppxEdmxZiegZZpCVMkwKB5Y5u9krhJzoZO6z1wpX0F3eSt5f2V9qfdDjny65twBL6WBreI4QhgOU6w8yxwV4jhO/R9ISpCQFt4zDcwEdlQ6MZEyAUukzWvCYDDAzEwbg34fnb0uGo0G5ubmAJjn5Yq/J8QIThvjOu0FuDRfCILWCmEYmkAXx4YOnFQjzg5K/m2sNVSsMshKZDAayLxeEoxyDpn2fmXNbUqz8SDwQUQYDoeI4xhaM2baM+j3+xj0B5hqTUFIk7UPBv3082QZppus5A8AzaaCgMNIS4LX9vY2lK2+AQ+ebcRqrSGlwdyHwyF2d3dT4y8hJVqtpk0OtA3KwPzCvL12jTiK0z4ZpTAwg20A5hyRxHU7zCrGsZV0Kr8zOvGqTriq3SpHb40qGetJbYEnTfwy/5scCCGoMADrJHqcVewgmDUUxdjb62BxaRF73S7eeecS7j9xP1pTBwAAYRgaxWwxGVw+kb7eqFdy2VuF2+jhff/lChszqpSYqOCJPOmnUkqlm+7mzZu4du06Hn3sURg0QKHb3UOz2UKjERiYROly4LCKS8TlRnilhhgyf460ikoOySJMV9GP2G8QGTnwtp+VUPGeSfbrSqWzzsMfUTTEYDCAJz0EQWCnv/OVQHKwpoecPRCTJl+awbJ0xOLMYdvv9TAz04bn+5iZnkkb4wXPo4JdqukPaM0wDGWRugtKKU02p7WBMm01Itgyt+zB7HmeZb6IWny/OCSdvB9yPRXY100ywYyJk7DcoihGFEXQWiHwfTAzhsMh5hfm7XVGiGNTqZBveiJpvyl9X8p5Amj7+loPS9d/4MAh7HW76OzuAlBQSWBy7l+j2UCr1YTnmynpQb+PMIoyxqGFjPv9Pt599xpmZ9uYn583cJVzXYkaABXYPen3x8CuVJEX0QhV5NEDoFUuh+MOU0L1hPVkSIHrzIhqtLq+Mc2coitZTy3zxwEDQkiQIIRhBNYDrK+vY3FxCb1eD1evXMXc3ByWlw9kiUJVolon2uoATzzCKoDG9MGqKxLCXQ2gTBJMuET7tGg5YURfYjTMBQDX372GtdU1tNttfODkSVy8eAGDwcDO0LGBN1Kc3DQPE9ySLESiCw3hfFDgyjBeakgzj862aikp9RulXh/pPUBjQIktkwZUQTmWjud5OHToEKIoQr/XR6PZQKPRtAyjGMPhMM3Mh8NhuT9CBE/KnKquii0s4wHt9iymp6dw9cq7aLVamJ9fRqfTSZ9vrGJoC50RGSMf7fRqUuxeJxWKeYae9KCgAJZoNVuIIgNx+X6A1lTLXKNSiJXCoN9PX8cEoqSashMAjqyyGR7TaVNdSAkpJeLYBItkHbfmWuj1etja3MKx48ewtLyEa+9ew+bmJl568SUsLS1hpt3G2uoa/MDH0tISuntdsAZUZOBCpYxXtxQSKla5AAwGmo0GPM/4VCRB081MZ2ZmEIYhhkPTJ/QD3/QItcbU9DQC38fq6iqiKMLS0pKZtQpDBEGAMIzgeR52dnbxwt8/j4cefhiPffAxNBoBpBBQWiOOY0sUkLkDioSAimPEyrDPhMiGGYsHEU9wgNdKxtRl2Mxp5Z9Rw4v9QuFA2OygEZNDZiVWrd4vBOfOn3BFH5bArMBapHt0OBxib6+D9uwstre3ceXKFRw5egQzM234vm91A7P5qkkJCLmBzjEoRt2zceOGd9dQy5j7xciriyJtJ5adveoeYPql2WwgEIaDIS5fvowoivDAAw9ge2cb3W4P4TC0uKFpsmutbNZAYKUzKfGk+Zvra4iJKgOXdjmy0cVjqIs8bunx2CDL4LsFdLN7oTWk51ss32TKg8EAuzu72NzcxObmBoIgwML8AmbaMzhx8iSklBgMBgjDEFFobENlEjjSgC9TTN0cuDE8TyIRmr518zZeeP55zM8v4Bc+9QuIogiNRsPAK/aAllLC9/20KZwc+gbnl5btFMHzfPi+hOdJCCEhRIxhGOL2zVtYuXMHUkjMz8/jyNEjOLC8jCiKMegPbJO7BUFkZlA4oTu765PsNWVNac8TECTBOkYcxebeMWPl9h28evYsrl69io9+7KM4deo0Lpw/j29961tgZjz22GPo7Hbw6tlXIaXE0x9/2lYewq7ZGGEYwvM8CF9CKYU4VhCC4HmmOvR9H9evX0cYhtBKodPpgJkxMzuHQ4cO4fDhw9jd3UWn04Hv+/B8D8IG4163i41+H1//m6/h9u1b+PXf+A3ce++9hkYqJPrDPjzPw/bWFl54/nkIKXDmzBm0Wi3T3LdQi3T6LOyQTOLYQIuCBKQnIaWpXN2KtmxJUGNnsx8mZXqoO/0uUdVlqZr+p333XdwAUtlHp8IezKEI7CRyTl+JMwNB017UpnKx+2d7axvLBw5gfn4e77zzDq69ew0PP/IIpEjov0j7ZYLk6LOVqvPkSdsZdcHk/Ye2CockV3hbkcXa6rBQra1pkcULmRhaKQwGQ+zu7uDG9Rs4feY05ubmcP7cOQSB8VwX0gijJZliHg5yfZ2dpqn1Wq7r4dQFkvGHNlU8vH1E7AkzixItuYLSWZpLcB5THEdQKkaz2Uwnyr/5t3+Ln7zyE4O7qxgz7TYee+yD+NjTH8Ojjz2KOBIYqBjT0y2EYYQoihAEAaamWuh2e1AqRrs9C2WfmYElNZqtKQwHA3S7XQSNBlZX76Df7wMA2u0Z3LmziiAI0Gq1LOvOsJCmplqmP8BAGA5t0IsBgnWnI+x1upibn4cnPbz80vfx3e98F+fefhvLBw7g5MmT+PRnPo3jx46j09kDMzAYDKHtfBIzo9PpYGFxAYIEWq0Wtre30Wg0QGTIB3Fk7kUURqCGQBAE0FpjenoazIzl5WW8/vrruH79Bj7z2c9iaXkZ4euv4/VXX8O//rd/gEceeQSHDx3C66+9jjsrKxgOhjh69CiiKMLW9hYAoNFoIPCDtHoygT6AIIGp1hSGwyG6e1288cYbuHz5Mra3tjEcDvGxp5/Ggw89hMXFJfh+AM/z0Gw0EYUxBv0+fN8HCYH2zIytphSazRaWlpdx4fx5LCwuQlvYmMhUp71uDwAQ2ea7FAKNZhNBYF5/OBymkGYS8LVS8CyUx8yIVFRKzErCk1wlQun6AhWhoHIiVQLGNNcM4HLJInpcl70MUlT3OVK3VKpP7PLnR14gtjwoaCryMIwgPYlut4tTp07B87z0zDt1+nSqp2WUKDTYoajnXrquWtlvL9zek2Iw8SY+xPYLf3EV06iCQFMKImboCkLArRMS3+KXvvcigsDHoYMH0dnZhRAC3b2uyRZ9D1prhJYGKUr+v0Wa7mistIQDl3BZHoME3/0DG1uiVvD7KwUT0xkISg+KJFAaZpuRjDEUVJMhv/HG6zh+/Dj+1b/+V9jb28PW5hb+0//+n3DgwDJOnLgfANDv9y1LKkIch/A8kcIzw0EIor1M7poM9DHo9eD7AQ4dOoT/7pd/GVtbW7jv3ntw8dIlTE1NYX5+Dp4VpzMN6yj7CGwglCBowJMSnc4e+v0eAILveRgOQzSbTfzohz/CH//RH+NTn/oU/uT/+j/RaDRw/vx5LC4soNfvY2d3F0ePHkWz2UQcxegPzEG7u9sBQIiVQhhF2Nvrwg8CBL6PQb+fjuIPBwP0eoa2KwQhCiN0u3tYWl7Gr/3ar+Gzn/ks4jjC1StXMBwMobTGwvw8ms0m9rpdPP7EE2g0Gmg1W7h16zZmZmawtLQMrTSiOEphxrS6s1Ca0hp37tzBv//Df48nn3wS//0//+eYn5vH3Nwsrt24ialWC51OB1EUYTAYYnp6BsNeD0EQoN1uY2NzE9Kbxxd+8RcxNzeH2bk5vHr2VRw+cgS+H1ipcgNJTU9P21ktD3Nz8xgOBtBaG2qwZkRhjN5eD0EjgPQkBv0BAEKj0UyDD+tMkcqViOHioCW4klVETi+hDM9WJ/25ZgUjN8yacHZoH4O+umIOZ9Q0PhHbwMiuE1ZZGZrziWx6hazhqs0J+6OCBC5fvoz5+XkcOHgQZ8+eRevSJRNInL6lqjiLitTtDHK+2477WNbWmAOvgOuPxeZHlVB1fWiLDwvBNutU8KzXglIRfvzjH4EEcPzIMezs7KQsHSEtlq61FUUzzV4WzjBaXZmG8vCYW8WUM5JJ1F0r9JlKPRUagzztn99eGUjs4klLZmHEMRMoJ8uytIVXhtjb62J6uos4jrGwsIiDBw/iC7/4Bbz44otYWFzAmTNncPDgAbz11tt4/bXX0O8PsLCwgLm5Ofz8Jz8BKT189dmv4PCRw/j5T3wSnd1dtNttfPOb38CxY8dx4sQJvPLKT8DMWFpexOLiAn74gx/g7bfPpf2KY8eO4sGHHsLc3BxefullhOEQd+6soj0zgyNHjuDBhx7G/Pwctrd30Ov10e/3cf3aNdy4cR3T09N44sknMTc3h3PnzuHwoUNQSmN3Zwe3b93GKz95Bb1e18BIwkA4DzzwIHr9HtrtNt54/XW8+uqr6Ox20Gw2ceLECdx34n60Z2Zw/4kTWFtdw7efew7dXheDwRBLi4v4uQ9/CBfOX8Dt27fx+c9/DlEY4fLly2g1m/j7b/89er0+lpaWcOnSRUjp4amnnkKr1cTW1ia+/dxzGAwH2OvsYW5+Ho888jBm5+YwPTUFrRQUCN29Lv7hH76Dw4cP4+mPP42ZmRlEUYhur2c+n9YIwxA//uEPsbGxgc987nMpLfS//eVf4uChQ1hcWMC5t9/G6uoqPvb005iemcFUq4UffP/7uL2ygs7uLhrNJrrdHoQQ8KTEpUsXsXJ7BTeuX0d/0AeYsbS8jI89/TQAxs7ODi5duohr717D6uoqFhYW8IlPfgLtdhu+H1gWYAghZcomSyRpuKpZjtFeKlXij1xx7hTPKFEhFkpjION0ZKBavz5PEklFX40lboWJTel/07m7lPmIvCRRohsHRqPRwNb2Fmbbszhx8iQ6ux288fprePSxx9Kzy/P86nt1FyoZLppThrPKVcBdO8FXySDk2ReZDapAXr4ssWklFD0vknI3qUIUkjDQ7/Xw5htvotWawrFjx7G+sY69vT3b/DM0T81m+DDDuzOJD/dLO2J9jgyjKQ+T6WqdMYW0tqrBzNacy2QNwIb1PwAAIABJREFU2d+N+LJN4dx7slt9lb+v9d186XRKOysHE466Tt9POfdHa841rxO2URD4aE214Hke9vY6WF9fx2MffAyXLl7CG6+/gW63i9XVNTz7zLO4dOkdLC4uot/v47lvfQs3rl/H9evX8dWvfhUvv/Sy8VIgQHoS3/vu93DlymUMwyFeeP4FvPXWW1hf34DvBzh79lVcuXwZgKGgGsaYxpUrV/AXf/EXWFtbx9LyMq5cuYo//dM/w49+/CNsbW9jc3MTg+EAhw4fQnt2FnfurCIMQ1y79i6iMMLpU6ewvb2D9fV1XLt2DX/8R3+Er37lWRxYPoDZ2Vk8+8xf47nnvg2yvYjVO6t45plnsLW5hZn2DBaXFvHss8/i4vkLAIC11TX8+Z//Gb72N3+D3Z1dnD59GmEUYn5+HhcvXsQ3v/ENrG9sIIojdLumqmm322i1TLZ+/tx5fP/ll9Hrm+rswoUL+OY3v4m9zh7uu/8+tNttq74g4PsBwshI/XS7XXzvu9/FmTNn8JnPfBYL8wtgBrp7XUxNT6HZbECpGD/60Y/w3e98B7u7Oxa20/jKs8/i/LlzCKMQr7/+Op75q7/C1atXMDMzjWvX3sV//fKXcf3aNbRn2wh8H1orzMzM4OChg2i32/h/vvY1XLt2DdNT07h16xZe+fFP8N3vfAdaMw4ePIBvfuOb6Hb38NgHH4OQAltbW+j2evB8458RxTG0UuN7obafwhX/GcFVnc7Y1H4lSgPJZL79s7sX3fcqfuWvp3x2uOdCEkeS3jlrnVcJZlcfLmE4JoOwyKkJ62RPKgVtrcGVtoPUWmNqagoba+vY3d3B6dOnATDOnj2LXreHKLURqFZYrgzKNHk1Uj0MyjUVyV3OjYyCYIqNtVyfxNGDMZVBlrkntDbZMHIA3W4XFy9cwNzcHA4cOIDtnS2TqXGcZtXZgaxSDC+jpeoSi7o47FZVSo9vwPFkVUmZVLeP5h5N+H71Qnq2UIfWCaylUiqnW2Em1YDn+elUs7L9CAN9Abu7u9Ca8fWvfR1KK/yP/+Jf4IEHH8C1d9/FubfP4SvPfgX/w+/8Dh566CFcuHABb775Jj7wgQ/g/Pnz8AMfx44fx+zsLLrdLqamWmg0mnjj9Tfw6tlXceLECTz10adw9OhRbG9vY3e3g5dfehlPPvkkvvhLX8SHP/xh/O3f/i3+43/4j1i5fRtPP/207aXEKaNvfn4O99xzD95+62384Affx+kzZ3DPvfdASIHz585jbm4OH/rwh/GFX/oiBv0+Njc38fWvfR0Xzp/H0vIyXn75JfS6Pfz6r/86Pvb009jb24NSGusb69DMuHL1Cl54/gV89KMfxa/8ky9hbm4O92zeYwkAhqwQxzEOHDiAEydP4MUXX8TnvvD59DNpZnS7XUur1fjW330Li4uLePzJJ/Dkk0+i1+uZeRqbicZxbCEugZ2dHRw9dhQkCFvbW+j1ulhbW8dPfvITPPTQg5hpt7HX6WBnZwdSCAS+j/W1dZOUxbGRImeGUgqzs7MQRPjW3/0dpCfxiU9+Ak88+STevXoV//XLX8Zep4PVO3ewducOev0e/uXv/S7uP3E/VKzwZ3/6Z3jpey/i05/+NNbW1hAOh1haWsZv/uZv4ubNm+h0OhgOh+jsGui52Wg4MjdcqhZKe3BMNTJKtoWofAaZ99Wl/mFZYTrfo6itPireN1HVKTO5uJ6P41LxE+HPxKNMa0vXz8grABDFpu+1uLSI9bU1vP32W3j44Yfhp9UI5/iwXNckr0CNxv59ZS/LrUh+SmZL1YY5Bagpp/HIiK3Ug/tr5c4qLlva29z8LO7cuQMQDFXUSsMrbb6qpriz7ELnKoJRmVHdVz7bR+G13a+qrKRchdR9la9bT/wa9devbVVSXa0BhoEVBIFhI1niQhiG6PUM7JNQc1/83otYXl7G0tIinv/23+Pau9ews7uDldsrICJ87vOfw3A4xKtnz6LRaOC1V1/F4UOHcfr0aUzPTENIkTbZX331Vdy6dQv3n7gf9913H6T04HlGJ+37L38fJ06cwKWLl/C1v/kabt68iSiK8M6ld3D9+jUws53ANvTgpz76UfyTX/tVnDp9Cn/1V8/g3/6bP8Czf/0sdrZ3sLS0hH6/jzAMsba6irW1NfzKl76EgwcP4sUXX0Sj0cD21jYef+JxtGdn8dprr+Hll17CysoKfvD9H5jDX5nBzMefeALLy8sYDAY4fPgwut0upqemEAQBhBBYXFzE8gEzONbr9bCzs4Pt7W3Etg9CRHZm4yp+9Z/+Gs6cOYPNzU0Mh0P0ej07/GldMG2gFEJgbm4OOzs72NjYwGAwxMrKbfz1M8/g8pXL6VAlMxvGlhTo7O0CAPzAUEWbzQYajQYWFuYRRiEuXLiAT33qU3jk0UcQRSGEFGg2m9CsMRwO8MrZszhx4gSOHD2CV8+exVtvvQkioD/oG9XtcIijx47ixRe/h//yn/8z7txZwfF7jmFhcQG9XhexitNeSrlK1rkKuurv3O9lvzvrF4WvXOWh7WCpSgcxkwolX7Vw7ivzJ+CUZp7OM7mVEQpVTVqpcAF9qPjS5Rm7rDoxwT62a80QYhSEJxGFITY2N7C4uIiFhUVcungR/X4fvW4PcaxKh+rYXitx+Qv7//J+GkGkLtuoiorkUFGrSqatrW1ce/cqVm7fxmOPPWpuWq9vKYjIueG5/YuEfZJk1mVByWop9PH02vENof16pldF+1H04ir+el12l/tEXIYjkwnuIAigVJwOGMZxDG2n2RcWFnD1ylUMBgMIQfB9H91uFz/64Q8RxzFu3riJfr+H4/fcg6WlJTBrHDt+HCdPnsD16zfQ7XZx6eIlPPDgA/B9D+tr60Zzy266ZI5kaXkZcRzj9soKGo2GaRJvbOCll17CcDDE+vo67rv/Pjz8yMM4deoUZmdn0Ww1EUURVlfvoNfvY3FhAU8++QQWlxZx6PBhvPD88/jrZ57Bxz/xcUxPT0MIgb29DjzPQ7s9A4CxsDCPSxcvQkqBO6t3cPvWbdy4cQPn3j6HgwcPYm5+Dvfeew8ARrfXTe/nysptzMy0sbfXSaHYMAzRaARpkAaAzY0NCCHQbrdTUkMUheh0OpY5JuAHPtbX19FoGIjKKA0Q4tgw4vb2Omg2G1hZWQER0J6ZgdIK7XYbURSi3x9gZmYGnmcIJ4IIg37fVpdGUSDpTZjXjbG7u4u1tTVIT2I4HOL27duI7DyJlBJCSlx+5x28/dbbuHHjBoaDoaFNt5p46qmnEMUxFhcX8fTPfxybm5t47lvP4c0338SvfOlLOH3mNJaWl9DvD6BsVUUWQk00wkYdPVX7o+idUpesuvB68ntZkWK822XV+9a1HIjca6tDi6pmxlzxysJ7kVE0gM4S1r6Fu5rNJtpts/YuXbqEU6dOodFsFM66vB4i0XhU425/eeNu6v6xrkKW72gXU41BcgJDJZE/gSm01rh48TwunL+A4/fcg1gpbG5s2AidiPRxpa4+Wzgr4bBzRfNrXCk9ycFfH2XuzpRq0h/fv8x83l5WWAMnpRVUrBCrGCrFk00vJQojMBitqSmsrq0a2MtORi8tLeHgoYM4c+YMfuu3fyvNlpVSWF9fR6vVxIc+8hH86Ac/xM2bN7C6uopPfuqTUFpjfX3NMMiEYUkFQYDm/8vam3VHct13gr/YMyNyxb6vtQC1kCxWcRNFiqREtWxZliy3p9vz1meepr+E9AVmuq15neOxz+k+3rolt3RsyaZEWRIpUlTthdqwFvYEkMg9IyJju/Nwb9yM3AAUJZ6DIxWATERG3Hv/22+JxaAoMnc6FEURapwSCS9cvIhr115C3TSRTqVhJAwosszbWgFDGBm6Dj8IYNk2JiYmcOHCBWSzGfzl//uXeHD/AebmZiFKIoaHh2EkDGysr2N8YgKFYhGLi4sYGBzE8PAwDnIHePn6y/jaH3wNFxcW+KFr2zby+WMMDAxA1TQYhoFcLoe+/j7EYjHuVBgSFuv1OgYGBqAbBq30NBWiJIEQwLJt1Go1yLKM42PK1+nry9KWUK2KICRJsmSoXq+jr68fe3t7qFSriOlxCIKAvv4+6LoBQQBSqRR0Xaey+q4LUZIooVCSuWRLSN4zTYsvuFq1BkmSMDI8jGKpBACo1WoIfB+Dg4OwZi1844+/gZmZWThOA0PDw/A8j6PEFhYWMDM9jc3NLfzD3/09PvzZzzA0NIi5+Tns7uzCcd0mTJg0e//PS0juKo/ffui3Se+3IsOElqH+aXuoPXgQkBOgvae3/buanjEh1CZgphPmGjB16sAHfEY2rdfqyGQzyGSy2NnaRl8mi0w6AwEC5x+dZOX8ec+SXu8lnvnNzlrltLWKOqBvPd6bBASe69EhI+v3VSoVLD99CsPQcePGdeT2c6hUKlRLicmat5Sv4UVE0FfNUtfvKDm7laK9htlnaXuFQ++ubabI8O/38dW7Zm5Ku3fzpuDXFToj+gE834NZryMW01A36/A9H5ZlwfU81Gs1HB8f8/f42h/+ATLZDBqNBnK5HF5743WIooREMgnTshAQAi1GpTgmJycQi8Xw43/+MdLpNLLZLONGyKibdTTsBlzXxfQ0HTLfvXMXtVoNff197P0PsLCwgP29PYiShLm5ORgJA5VKBbV6Ha7rNg9vkWbQNAA6MOt1KApVxS0UChgaGsTU9DQCP8DKygpldw/04/GjR3AcB6Njo6hWaaVSLBbwyiuvYHp6Gjvb2zDrdYiCiFQqhbm5OeTzedy/fx/9AwMYHh6C57owTROOQ4eejkOrDUkSUSqVUCwWkE6nKKDBcWAkDGiahkw2i76+LA4PDrG1tYW6aaJULlNSX8StslAs4tLly7hy9Qru3b2Hne1tpjxAmfTFYgGu6+KIsdZDjTnHofparusimUzC9z3UajXWBnExMjqMiclJHB4ecgHLcqkEy7KgKDIGhwYxNj6GWq2GxcUFSLKIbF8W9XoNa6srUBQZjYaN3P4+VE3F5SuXkEwlEQQBisUCNjc3+doJuTE+Hyj7XUAmZ2z7Rgfq7UP0tn0S/VnL/ycBfPYVBcf43b4f+CDEB0gAEvjNr5Z/By2Om62fJzKcb/sKZWX4GRPh3pPwnjFCrChQiH2j0aCim67HYcrVahXb21usY+HTRBGnJ8q/jyDSgdr6fZkpnXrRXXRqQvhu1ODq8PAQ5XIZL770Ig4PDikUmDQVMsOGElV8jT7IoEnUix6u7Qdyl+Dxuxz8rX+r7SuK2jjjV+eiO/t8pVtAaX4u0rK5QAhs24aiKHAdF7qhQ5IkVMplDI+MYOnBA/zohz/Cu++9i7GxMdh2A//p//hP0OM6fvLjn8DzacZ+87c3sbO9zbPidCaDvoF+fPabzzA1PYVUKgXP9xGPxShTnbVUZmZnMDY+hvW1dWw+20SpSAl6A4MDePudt/Ho4SM8evgQpVIJZr2OWq2GWq0Gy7L4LEGLUUJk4PvI5XJIplJ4uPQQv/zFL2EYBnTdQKlYhCAA6XQa1WoV9+/dx4c/+xCKrGBqahqF42Mkk0lkMll87y++h83NTQwODWF1dQ3bO9uw7QYUVcFL117Cp598gr/9m79FJpulrTk2q4nHYzg6OsLU9DS/PtO00D/QD8/3US6XUTguoFwuQ5Yk3HjlFfz8w5/j7p07fCiuaRokJoWix+OcyzI3N4eJyQn8zX//G6yvroEQAkVVEASEcUNSmJqeQjKZxKNHjzAwMMBFLrPZLHx2eIdcD0VR8JX3v4KlpSX8j7//B5gWFT7VdR31uonlp0/xyiuvIAgCfO8v/h/s7uyi0Wjg8OAQmqbBZr351ZVVkIDgo199hGKhgJHREWSzfVAVhfGCCHzfo1Uvky+iAcFvm2O0HdTh99j3QVqDQ69A1ILMbEdxRX6vuUcis5mWvR9eQ7f5Suu+7nZuNCNCjzMhOpdpm9OGSannMykcQjic22OJXr1eo8TE+Xn80z/9E1wWWGhyFcqxkB5zpy5J/3MgdNv/k77zne9897mIcJ8negntTn2RniWLmo1GA7qu85+tra5iaWkJo6NjXIOpWq0yvR9AlmSIksD1k6KEodYb1Drw7kK+aKuq2kykzjiEbx+u9Xr9afDHk39GOkrlZg6DDuIUv7vRhRwxqmrK6DeHtJ7voVwqcxXb5adPcXx8jImJCbz/1a8y1I+HVIq2sSzTxONHj7C7s4P19Q3av43HYBgGstksx+FfuryI8YkJOI6DeDwOz/MwPDSM8xfOc22vSqWC/f19LC0tQVFkTE9NQdM0igKyG1hbXcOjR4/wbOMZJElC/0A/FFmBz8hy1UoVa2trWHqwhEcPH2J5eRkHuQP8x//9z/HCiy+gWCjgJz/+CWLxGDRNxeNHj9FoNPD1P/o6Ll2+BIm1gnRDp7OavX2srqxib3cXqqJiYIi2vvoHKIHQaTSwurKCumlCEEQ0HAeqqmFmdhae66JQKCKVSuHixQtIJlOwLAu+H2BkdBQz09OI6zpsy0K9XofjODg8PEShUIQkidBUFVosxmUyBIF6hSSSSUxNTcFxHdy7ew8PHz7EtevXMDo6imQiCV2PIx6Pw2k4WFtdw8Olh5iZmcHk1CRGRkbgOi6MhI7LVy5z8mE6lUalUsbe7i6OjqiG3eUrl3HlyhXs7+9jYHAAJCDY39/H/Xv3cfvWbbiuh0QyAd/z8fHHH+P4+Bj5oyP09fXjpWsvoa+vj4pCgkBh7VDSdvCHrOxO8YnIIJq08i5a+SPkxJZUr1ZYt0q9ewXfQrLv2N/d9n4vbtdpCXbTl6f1fdGiNh2SVQmTvqHf94MAyWQS+XwesixjaGiQJQtUNkqUxBPOddKTynGWAMJ/P/C7T27P9gYnmMZ0I9WRLlUJAesB12AYCVpeV8r49ccf4+nTp/j2t7+Nx48fgyBAvVaDwPxJwoPQD3v76C5JL0QNMLpBkNv8J3pN1D9ftXZCSRmQswdj4fRr6Tpk7GKnGkqzh+2TUHnW8zzYto2BgQFUKlU6yI5p2NjYgGEkOJM7CAiODg8xOzeHg4McPJdCg9OZNA4Pj9isgxpMuS4lOHqeD12PI5lMolgsYWBwAKZpolYNh95JnkyUyxU0Gg309WWR7ctSHSqGHAsCmoHLkgTLsmHZFiQ2t9E0yni3bRuWbUNh+lTJVAr7+/voy2ZRKBbxX/6v/xvXrl3DN775xygWihgaGmRD74APMVVVhWXZdCivKNDjcfgB1QGL6zoMXYdpWSgWCojFYnBcF0NDQ6hWqnCcBoYZisv3fcgSNWDzfJ+tW3oPJVlCLEbFMAPfh2la8DwXsXicS8QEPjWv8nwK+fSDAIlEAroeh+c2RRIlWURuP4dsXxaZTAa5/Rw9eEQq5dKwbVQqVYyOjsKyLdRrdWT7sqhUKujL9iGVTuHZxgZkWeFyN6lUErph4NnGMySTSXg+tbz2fI/JyMQQ13XUa3XEYjGUy2X4vodMJgvdoFI4tt2gRmnMXiDwqbtj6FcTqk90Cpd25fN2mVuQM7dhhHZ/IOEUhD56SWYFZ6KBd7f+PUVtmLQHvYDLsUiixAQaW8V8dcMAACwsXMQPf/hDTIxP4E++/W0ABJVKBbqhc7WIrqCcqLz15yQvtvJIzoz+6TVYPt3VLBppQ69tCnPzoGoaf4ud7W08efIE115+GeVKmZvw+EEAiVmRhoY7QRB6M0QUNCOKn+HQXRDatPT5ohSeM2g872CenPzSE9xmuuLrhd5/M8qF4TpiXTIvEAIqMEpd2eiAmB465VIZ5UqZ9vMNHalUCqkUzaYLhQIkSUY6k8Huzg6MhIHh4RFsb29Bi8VgGDpvm4R/N8baWABYRu6jzobM8XgclUoVtt1AJpNGMpWEkUhQEIDnoV43mbIvlQjxXDdizwvIzDNFFKjfhh0qAgsCh0+G8wHXo+0Bz/Vgmux9ZQpxVhSFX7NpWpRMJ0nQNA2u68K0LMRjMWiGAdu2YdbrkGQZmqpRKRFRhFmrc6kZp+HAdRyIIhWZpD4rPlfOJYQKNJIgYL4pEnRDZyq8Duq1GmzbZrIv1EFRVhTIoPLv1UoFgigipsWgqArEgK75YqEIwoJUMplkLSo684rFYyCEIB6LU+0tpiJRLpdhWiZkWUE6nYJtN+AHPkqlMvZzOSSTScZMp89Q0zQOtw7FOz2P3rtYPM64LVThOGEYAAR4rsfl57lYKjvNScd+7L09uqFBz3p+RQUm0UtBnfTOk8mpZ0S7pwrV0uo01xJODCLoYUEckADwwdF8vh/AD+i8RBQF1OsmxsbGUK6UsbW1hampKWgxrWVU0D2IdIOfkd9fIDl7QDnlzG1jxnD2tSDxXwsJbxRDb+HBgwfIZDKYnZ3Fg/v3ERAq/xC9hhBrHfYi22UMQn+F5qEcuQjhjCS/njeUnP3zt6O4TtgUYiT96iWlfZLGA2m776QNmdZpE9wMvpIsQVVUeL6HTDpDD37Tgud7yO3nmAFVhmlreUilUhwy2t/fz4ydVG7IE3AzMLrEPNeDw/hBtWoNkixBlhVkMxnKd6hWkcvlqDGZpnIIaouqMA8cAtWgkmWW0QJuw0Wj0YCqqYhpMd5PrtfqlNjnuhBEKsgYBid6cDdgMll5AQJkRYYiyxCZpwdME7ZtQ1NVqpSrS2yg7QESIBDGCWFGVYqigpA6h1abDC4siVR63bbpoJQQAkdwGP9FYGKLElzHpYmVqkLXDf4+IZkwEKjTocjaHE6jgbJpIpvJIB6ngcM2LarIy3S3Go0GD3ohSshxHR5QQovfg4NDeijIErRYDIPJQZSKJYjsOciyAsu2UC6VocVilG8SEFiWDcPQoarUqVGSJMhMTNNjcv7o0ibp1aI6U/V/VvuEoFt583xz3bNaJ5EuBujkDFIpTaQp4RbOnfueJn9CIECSBD6PaTQaUFUV+/v7mJmZwf37D/BwaQmjY1RDTRRF2LYFRVF5RRMm2T0/0OcIJvJz3VDhczgr9YDFhdEwPCwsi+olPXnyBKZl4fr169je3kapXGKyEQJziANvsdDhWeuCFCL9/iZ7vu1gDpozgpPvV+uD7RUUzh5fyIl7wY/KS7cHlzPd2zZIc7smWsscptVVLQgIPHjc+yPMiCRRgqjSwTgIQa1W47IciUQSCgDLsplXB21jKKrC/UCoIint06qCylFN4fX4HG0HqKqGhGFwV0HTtJjYJIX6Et9jDGDCPUhC/5JYPMYRQ3SgG/D2EFWFppXKl959BxfOn2e8GcahYZuMwmaZwq/oU1tbSUY8FkfgB6jVqpy9Ho/HoaoqN6hqKiz48LxOXwdRbJqDybLUhKCCsLaPDw9AXI/TAM7cKKvVKgSBVnbxWByyDPi+wNA8NDCXymWm8ySy9p+KwA9gmjblqMgKPdQ9Kn0vCAJUNoMxzTqsusW94CVJhCzJIAFgmTb3PyGEwPc8JIwEspkMbVs2GhAEQFEUqvRsWghI0BLo6AAbLarb/CwJv9eh2Pg7QFXJ6cHneY5I0sXp8NRWWvSsPEUhvKsoZdv/cthyEIAw/lUQ0IpbDAIQWcbBQY6ZXvXj4PAQKysrOH/+fMTGur29f6rD3nMFk+eSkW+5qR03iQCCeOrDb/FyDpVpJQlHh0dwnAZ2trfR398PRZZRKBR4WUwYr0QIRKpFw0vlNmOYiJdHd6npyKW3SSEQ0jkj6SVdfdpyPLOfSIePM1PMZa/3Ceki+3BaBtVtEbeL1pGWWUoQ+PB9xi8RxaavNnNODOcrhpFAPBbnVY0f+HAbNl+wuq4jFo9BJuHw3meqthI/QEPpdi+0jkUoOCfAtGxUa7WmBa0gISSPEkIVcn3fZ7MSmSGdfHiuCwuALFOkEAlCZePQWVGCJEtYXFxE/0A/jo8LCAICWZY4G5225Si6CD7g+5T7oMgaavU6GrUGkokEBgcH4Xk+t8sVIlWv5/mQJMIP5VAR2ffB5wEi63c3Dapoe5d4HrLZDIXyHh1RgqEkYXBoCK7rwGWq1ooswyEEgUu5IRMTE1SF2KxDkRUoClUFsE0TqVSSWvAyeC+dNVECqqqqqNdrvLUVj8d45up5PjzPhSRKLcmJadbh+wFkWeIKBJJEuKFWyAkKeWBnak2RNjLv7wk8ejLsFb2r/lPPrzO00kIpeJzEJSEn3pfOTkQoF0/4uiIiTZLK5QpM00Qmm0Uul8OzjQ0MDg5CZ2oLgvAcQeRzBJMO1NZp4V447c17zEXakQAtbaoggG7o+PDDD5HP53H+3Hk4joNKuQzXcyFAYFjqsFUlNGGuJywCwpFNiCAgOpFcHPlEuiMp2iFzpAPp1fwSzki8IQSR4Rpaesf8yO8ArgitYDPShcQEUGHJlp8JEVAaaQ0qrE/tc7x7wIIK+zea/Vu6eEPTsIDDmanxlEQJhYLIsvcaqygoDJj6WCiolKvcoMoPAu7jEAa70PWtOU8grc86hC4HzedAPdBt1Gp1rk0V+kaE8xVZkiCJdPBt6AmUyxXeiisWC7BtG3aDMrd9jwW4gMDzAwaNpjIfvu9DlhUUSyXKn0kkIcsyl5KJx+NwXZcpKbtNuR+WoVPJC48eMqII13FACDhpsFqt4eZvb+Jf/uVfoCgqzl84j1KpxGyQ6fs1bBsAoMgyHcLKElfLDisAQaCy7pVyBeMT45AkCcViic9wAkJYYAK1p1ZVVskHzFSLERgREVOMODaGVUoTukvbJaIoRERPg1MTqej+a8/OT0M8dkOB9gwMHVtZ6Nw/vXhZJyAp26+tU4OL9ERXnvbajs5IF+FZCjgKoKoKisUipiYnkUymsLy8jHgsjvGJ8dZAInT6v5zorHjGoCM/TxA5U2+yzVwp/MDtASQaXERRxMcffYzd3V1cv34DXuBjd2eH+a9rvKccKmH6zR5Vl6S7VQ4hKl/SPIzJc6CwyIkich2+0+Rk5FuvhROtAHi21FaNnERXPqIgAAAgAElEQVTqJHgO/+luXiZBKw6f9u5FCIEAIvb6/AHru1OlWkpQa3CY6pCu4/j4GBvr66hVazwjvrBwkTvqKTLNainDnlrjhi2jKIm0abpEnQNd16ItI0mCwpBfmUwWtVoNlUqFmkSpKpRYHK5bZ0NtEaZpQpbLqFYqiMVi6O/vh6ZpKBSOkd/bw/y5c3ym4XkunEYDlmVhYiIN27axvbsHRVWwtbmFgYEBTM1M0wpNEOC6HmeN9/X3UXHKWp2hwjwOnaZaZ+DSJfTzunCcBm+ZHR0eIZlKolanFUCDEdBCnxZdN6AkVEhMKTgUSA0CAjdwGeSWnpp379zFyMgIfM9DMpGEbdlo2DZq1Sqfm+i6Dt3Q4bPnEq5fP2iFg4aaX1ShtrleJFmG0u4HFFrudkFGdoXmfs55bTdJkw6U6Bl7YF33GOk++G2vaAQBrdWIcPpePPtnD9A2ZKVJo+/D8RqYmJjExsYGlh4+xJe//GWUy2XcuXMH5y+cR19fX8uZ3K119rtWJvKZg8iZ/IA7IRHtlQcvhaTmsD23v4+dnW3Mzc1B0zQcHBxQbSBCb1TQfhODoG24FX3gEWNf0rlgOlpOQg8ExQkL7jQo4lmlV5pcmu6okJag8nsaPkY1gU7Kjjo3idD1503lYJoRuywTFwUq71EoFPCP3/8BZX67LuKxGJ48eYLJyUl881vfRLFUglk3oTBXP9u2QIgIXY+jWCzx1hNl9LJBrizh1s27WF5exquvvYq33n4bx8fHODw8QH9/P8bHx1EoHEOUJOTzeYyPj2NnZxuqpkHXdWT7smg4DeiGjs3NZ8hm+3D71m1srK+DEEKd6NihSAiBrlN3wn/7+b/h008/RSKRQOH4GMPDw7BtG3/8rW9iaoqy85PJJMw6hTbXmOWt73sQRQnDI8OcN+J5Pur1OsbGxpDL5aBqGkZHx+C6Dm8TeZ7P3e98z0M8HoMgAJ4ncUKgKEmoV6swDMqW95gVQCwWgx/4ODrK40c//BG++a1vYnR0lCoX+D60mIZEMgHXoTMfQaCD8SAIunYS2vdwCx+EHXSB33TgpLwlcImintk6eb4DtT1JPgmU0j0o/O46eC0tqR6D9ZM8hZ6bSkC6t8BIxBQr1KuTRAkHBwfQ9TgSyQQ+++wzvP7GG8hkqBqFoigtElTdZ+DPH0zks1Yhz4vaIl3MT5qkG8L63/T7jx4/xuHhEW688ipqtSoODw869LHC0QohTb+Skwf6pOuYgKDjG8+1oEhP68weZfZJMvttVU3ngI2czUTsOf7r9RzbK5GzthB45urTXr/veaxS8WDbNGM9PDrEN77xx7h85TJM08JvP/sMn37yCc5fuABJEqHrBg4ODlE4LkCSJSwsLECSZFQrFSSSCcTjOhKJGAhJwXUd1Go1OI7DJULyR0eQJBmZTBaO42B7ZxvHR3kMDQ8hlUqxg5Iq8pp1E7s7OygVS9BUDTMzs1BUyhw/OjpCpVzhCYck0dlQLBZHEBCsr68hnU7hf/sP/4HNIRz88H/9Iz741w/w7T/9NiYmJnB8fIyd7W0EDAq8uHgJkiRid3cXx/k8tUiQJCiqAkBBoViEqmko5I/huR5kRebQaPr3A8oh8SnpTBBFioBjrd9EMoF0Jg1JlOAHtCUVstaTsSSWny4jn6dS8qqmQlVUTExMoFwuo1goQpZljt5qtgW7JxCE63/5ndk+oaKVoiByodTTqg3SPh856zKPHABEEE4NFL8vLb2uGXxXp9fWa+x2CD93LAHpuFehEogsSyiXSyxICHi2sYGh4WEMDQ7hzp07mJmdZS1Xpyun5LkieI8Ll08t+547iERk2klzPtFsawmIztvX1taw+WwDc3NzcFwq7x3+vYANYxF9vSDwIHHSIUmCLv7lLc9WBE6BHXLBt56CbYSLubXr2rSjNrorDJ+ctfRSTG6i0p4roTk1IERbGKe15NpfH/bTJQbRJYTANk0cHhzCtmxaBTQaGBkZxrnz57C0tIRSqQhZVvDXf/XXqFWrGBsfx9DQIK5evYrd3R0sLT1ArVZDqVRGJpPGlStXMTs3h/39fWxubmJzcxMBCZBIJnD16lUQQnDr5i2sra6ibpoYHRnB9OwMxsbGMDY2Rh0Eb91Ebm+fCkCm03j1tVexs72DjY0N6rK4vQ1JljAzM4P+/n5IsoxKpYzx8QlkMlkcHR5CkmSMjY1DURXMzs7ipx/8FK7rIp/P4wff/wEqlQouXryI/v5+HB0dYmN9A0+fPkXDtmEkDExPz2Bufg79/f3Y2d5BJpvB8vIyNp89QyqdxsEB9bKXRFq1P7j/gJpkvfkmNE3D3u4u7t65g7Hxcbz51hdh1mq4d+8ejg4PUWf2urOzs+jv78fx8TE8z8Pf/e3f4eoLV/HWW29ha2sLy8vLWH66jPn5ebz/1feZkVhrC7p9DhCKq0Z/1gHyaG/FEpxY6bZ2Fs6WNEW7CgI5I4jlDAf4aX+7daYQzQaFLvOPyLWewsR/rgDXVsFFK0RRlGDbDdh2A8lUCnE9jrGxMawsL8MwDIyPj7dUI0Hgs7mWeLaq5IRgIp+U2gtnGrZ0Ip84gqot2xbbjOld18XK8jKOjwu4fuMVHB/ncXB4SNsBTFu/OWNpol5C/+z2a+icOQSRNlc7NyM440M8KcOJuqSRrmVt6BTZabN7xgyIIaZanklnXHyuqoWcQILs7hLcXR67hQTJhrEh/8P3A1iWhRJTk02lUqhUKojrlLRYq1ZRLBRx5eoVlEslXLx4EX/6Z3+G3d1d+EGAT379CVaWlzE7N4exsTGsr6+jWqlifGIc6XSGya8AgwODGBgYgOM4+O1nn6FwXMD8uXOU1+EH+PSTT/G1P/gaXNfFbz79DZaWHmBsbAwD+gBisRgsy0Z/fz9UVUUQBDAMHaOjo0gkEvCYGVStWoNp0lmHZVMLg0qlgoAE2N7aRjwehyiK2N7axtrqKt7/6vt459330GhQ6fuffvABxsbHcO78eezt7eLO7duQZRmJRBJ1s47PPvsMQUDNpqjHCeW1BEwd4PGjR8jlcpibn8OFCxchKzJu3boFx3Hwzrvv4Pj4GOtra5BlBTEthiEm5ZLJZDA8Mozt7W28/PI1nL9wAdVqFXfv3EW2L4v33nsPpmWiVCohHo9D13UOcBA4C78JbT5JMiPMjgMSQITEPTeiBmrN92hrEZNWa9SzHugnziE/JyrrJFn61vXeNO47iW1/2jzneYAD/G8HpKPDE56tdCRARRwHBgYwOz+Hpfv3MTI6gsnJyZYgQp+ZcKY5VPezonmdMiFB1xeeLdslzblEl4crMChpNMCEWb7v+dja3MSd23fw4osvwnEc5HI5KhrIJCBaMx8BAQIIpBP11e7EyLX9+cwm4GXwmYurbqRFckpm3rbIBLY5OrUqSY/OV6dHitAWcILn8kl5nqEl4bwGgjMQt3oGFzAUF0VzqRrljpSKJVy6fAmrK6t49PAR5ufnMTwyjGKhSN0SDQPpdAr5fB6bzzbx9OkTvPDCC3j7S1/CwOAgPv3kE/z4n3+MpaUlJvk+QDWhrl7B0PAwfN/H6uoaLl+5jK+8/z7K5TKqlSpWV1fwm09/A1GSsLa2hqmpabzy2qt89pFKpSBJEn71q18CW8D0zCzm5uZQq9Wwvr6OwcFBJFMpCpv1fehxKkiZz+dRrVSwubmJ8xcuQGQwTMdxkEqnYdkWCvlj/P3f/R1EUcQX3nwT8+fOYWN9Hf/rB/+Ihw+XMDc/D8dx8OuPP8Yf/OEf4q2334Kqqrh58yY21jfguZSYKCsKY8JT75LBwUHKefE8FAoF/OD734dl2fjWt76JyakpDA4NcpVfTdNg2xbm5ufxzrvv4IN//QArK8u4du1lvPeV91CtVnGQO2CExwCeF/TEz0R78r2SLhFAIPgtwoPRhK5977bsp6BNueEENCZOCSbhXu02n3meAXx7AtjRehaF7tXVCe3pkzL/ExFgXSDTQZs8lKrRyrJYLKJQKOCLX/wiDCOBzWeb6Ovrx8zMDD34ZaUFun6mofsJ1YncM+KfmuGSDmYmumYshC+gqOPb0dERbt++DcMwMDg0hKPDQ+SP8lRSQ5Lg+T7r3UbFzwSatZywSDp7u82MQSACtbg8y9ygy2Hb4vHOMfKkhWDVkjlENl23nrEgdjpGkraWYossCnl+5Ef7PeqVMYUBvv3ZkyiJq8sGaEF4sYyU+AHvxQ4MDECSJPz3//bfMDExga2tLfT39+Pd997DyMgonm1s0Ew2CLC3t4dEMgFFkVEulZFKp+G4LvJHR8hkMvA9D3t7e3j5+nXIsowqG2ZbTKcql8thcnISuzs7ODg4gCCIjOcgQRJF7O7sUCisKME060gYBnZ2djhLHwBSaapQLLGKQTeo9wn19xDxbOUZvv8/v4/DgwO4rouh4SG8+967GB8fQz5/BADIH+VRq1a5urEoiojrceSPjpBOp6FqKrY2t6DrcRSYF4nMoMWFQgGlUgn1eh0BCejQNGFAkulcJfwZQOVKqOCjC8PQke2jviilYhmWZSKRSGB4eASEAMVCEffv3cf8/DwuXbqM1dVV/O3f/C1eeuklxGJxpNNp1OsUWRcaT0UriGYl0V5NN/+/7xMEQXtbLGhLXASQbpswHGAHZ203kQ75E6GLtlX3OePpc5ST9Oya7ye0Mue7vUf0b7fvK0E4tRd9eitO4J0RCASKpEAQBVQrFdRNE8+ePcPM7AxWV1fxcGkJqVQK2WwGgNRzFvrcwSQaSMiZ2ZhdgshZKhc+maISGbdu3kSpWMKFCxdgWSZWVpbR19cHy7JROC5gYGAAh4eHbJPJLUiFsN6IOqChpQIhLVo1LcoFZ5wXtLd1WqoC0pR+5tVOmzwC6SJzEvh+68yIUC4BLy+j79UmwtiL9XoayqSr1lbbPORMOPxuwSlSZocwzxC9RQl5MmrVGnzfx8LiIs6dP4cXr71E5w8DAygWi/wZKaoCRVXhMRVgRaHEunQqhVKpRNnSzIfcdRzO+A9FDPf2irAtC9vbW5AVGfu7e0il05iemcbI8DCCIGAscQHpTAqEBFRcMgggABgaGkLhuADf83B0eIhGowFZllCtVLhoYSwWhyzLuLhwERcXLkJVVSwuLiKu6zg6OmKDdBHj4+PI9vVhe2sLpVIRi5cuYXR0jMv8iKIIy6bs9UKhAIepBoefU4/rkBVKqqzVaiiXyxBA2ehGwoBlWRBEgUOc8/k8JiYnkEqlqOOhREmcVHKoDlGk0i/xuA7DSODK1SsYHx/Ho0ePcO/uPfyf//k/s8CTpD40rsWCsMQrC+r/g475ZC+0XyuiqwmAOak91q6Vd+pabGtfCaQ9u46a2p2B9Ifezoxhe7p1bknQnpme5iHf/sY9vP5ar/EE5GmU4E0Cwsi/tM1l6DqePn2K69ev83Wy/PQp3vjCF1jg91uVgX8HTI/cLdric6OEeouSNRcQQT5/hCePHyOdzmB6Zhq//vhjqJrGpS9ClAuVRmkb4EfbKgJaHND47KOHFMJJEN1eCqTRtln3w5yg5dwnJLywtuDTysanyqcCpMj9bsd4tx/yJwWTXmV1azXVWs0REN4qPMsC7raIo79PLVwJG+JRKZDQhvbGKzcwNz+PUrEIQghKxSKqlQoMpl4qsuduWxSRlEgmYNs2dMPg3BRFUZBOpykxjyGMHMdBQALk83kIgoDZ2Vn8u6/9OxzkDkAIwdDQEJU4z+chKzJXpbWYvlZIvgudHSvlMkbZYF7TNBSLRT730TQKmb18+TJf5nXmj5LJZFAsFuH7AUrlEg8Yvh+gcFxA4fgYWkxjaLCm4KPjOEizAfuNV27ANE24rsMUHYByuQzLtGgyRahkTa1WAwiBqip8riFAwN7eHmbn5vBsfQOZbIYKUNbqXGIGoB4/iUQSly5fxltvv43/7y//En/9V3+F//jnf055N6oCm82BJElm9ss+s2kWu7Z2STdNuR4yH+F+bofwNrP34DlaUd3nJfywZ4nNWdpbhJzWZoq2qprJntBlr7S3v04CDZBeYIGTgDih9DvnszCfI2bLK7ToCwJPnjzBa6+9hh/98EcQBIFV9JSoqwhKk4ohfP5gIj8vzIv/RaEDnnAirDQcxB7kcnj08CH6+vowOTWF7e1t+MzbgTqAUUatqqoUg04EiGLrwJeEvb1wZbZVUu1D/q6DH9I9oHRtZ5GgN9KkWzYBwmYbYpt3Qae8dGjS9fkgiW3BInIx3Tg27QgcClxA78DRTdQ5+r4RNFvgB/AFnzO8QzatJFGtJtM04TQanMMgCiLXWQtY5m3WTSZhnkJMiyF/dEQRJwkDu7u7ICDIZLMwDAOSKNGWlG1D0zQsLCzg8YVHVPxxPwdFUZDNZrG+vo6xsTEQQrCwsAgAKBYKCIKAS9gHJOBGW6HVbCKZgAABiUSCD5xrtRoaTAQxxkQLG6H1KWs3SZII13GpE6JhYHpmGtVKFYeHh1hYXMT21hYcx8H4xDjq9TouXb6M3372W6r1JdF7ElYudsOmSLfRETiOg3K5gnOahqGhIaTSaVQqVHJ/eHiYttTyeUxOTmFgcBCKItOKXlNhmnVuyuV5LgzDgCzRgGQYBnWVdB24rhdB8KClLRWSHenB3Grm1NtOgrS1YDrnLDxRE9C1pQpCTkjtT9bKa0FwkdMH+afxR1oqLCHUZCBtxyXpQFSdhUF+FmBA124CaGeDRFrsLQx43+caefPn5lGtVHDr1i1cuXoFyWSS20KHShKfN5hI3/3Od77bdeDyPHosvLxqfY3n+fCDkFdAN+79+/fx4P59zJ87h6mpSdy5fZt7TFM5arBsSGo7zCN2lEEPg6puWUc3mOxJ3I4eKJCojMpJ5Xz3hdDsF4eVSOQk7vwbaJNWiMIwew07QVoCSG+jntbA2A1a3BKVhE4SJyGkCbsMETIi5eTQQ5Qxqwm4YdLw8DB0XUelXGHeClTWg4DgN59+isGBQYxPjCORSCAej2Nnh9rJrq2tYWd7Gxtr65BkGTdu3EAmk2Hw1aeoVCvwPR/nzp8HBAErKyvY3t7G+voGNrc2sbG+gYbTwMjICIyEgfW1dTx69BC7u3sol0rQDQM6a00VjgsQRWpuFQaKuB6HZVFNrSePH6NcLuPiwgKvOEpFCmF2HMpv2d/bx9jYKAaHhqAb1KhtZ3sbe3v7OMjl8OTxE4iigIWFRYyOjSKTyaBSoYZtTx4/webmJnZ3d1AoFHBx4SLS6TQEADs7O2g0GqhUyni4tITVlVUMDA5g8fIlDA8OoVQqYfPZJg6PDrG9tcUMpVTEYhru3buP0dFRxOMxrKysYG11DblcDkf5I9y6dRNf+MKbGBgciDgoNnvvYfBoT5hIxHkvaCcId5EU6i0tQjo92ElnAKIJWPScEVqSJqHbnmUKuUEXC9yTgkkH4EVom2ES0jOhazfQQodJVasLIonoGZET23idZx454ZpD7xeFac9JkoTp6WkUi0VsbjzD+MQ4MukMRJGqPYS/346sPXMgiWptCc+jDnjKf6EveCjsVixSdM6nn3wC13Xx6muvYXl5GcVikfMOmnEp0mcNSGRBRw5GBD2dy/jiRO+HEoU29xJYbDnYQ/0gPzSbEboKv5EeHiDR71G0BFr+HZbi0Wtp2oZGKokTYHWtLo2tNqBB0KpZ1Rr4SdfWVUcgCdpdIFsPi4A0jYtEUQQBQcOmw+axsXFk+7IQ+IyJ2oiSIEDgB5icmkJ/fz/8wKc+GjXqyW6aJrWSTaVw7tw8Jicn6RxB16FqGjyHalkl0ykkE0lmTepjZ2cXlXIZEICxUXpgq6qKSrmCYrHIqgmHm0FZlgXHcZFIGIwMKHEYqeu6iMfjtPqJxTA5Nckzd9/3+e9SQy+C8YkJaKoGAdTWd3hkmMKIa3VomoqRkVFcfeEqZ6YvLi7CNE2sra4iCHxks1lk0hlcunwJA/0DSGfSFA0XBDDNOsy6ianpabz11lsYHR1DMpliOl1VVKtVlMtlZLIZTExMQJZl9GX7sLS0hOPjY0xPT4MQgl/96lc4OjzC5ctXMDA4AMMwurROOxvEzXXb9COPDufRUzUhajUd8FknaU/ASGel3UQwRvZsWFF3JQlGgggJuE7YaRpZUcmXFl3AiLYYadlD6EhaW/Yhmq1s0hFEgpbksFnYNQOL0KPFFt1/7QGYRFruAqhMDQG1cTAtEzMzM1hZWYFtWZiYmqRt5ESCVS8BBFFoSeLPPHMPfJ+cCf71HHOTgDmghfhmy7IQi8XwLz/5CW7fuoWrL76IoaFBLD1Y4iiu9kyha2Ruo2IIQuewXYgM6/iCQKfTYMvQ7wT0RLRMbYn8EDhKLdpZI91UFAG2GMHZ36IkQRIlutBZq04UJWapKXQEkPCaQw/ubs8qiMjqd2cVd2ZSrUKaXbKwsNRtC1I9nz3z1RZZ3940qY1sMpVCJpOB03BQr9cQsKoyIAE0TeNeINUqdfJrNBrMlInOQnTD4E581WoVU5OTzJ72iAYoQaCmTaoCURCxtb2FZDIJRZahMJ+VwA+4/0hI1tPjVM8tNM4KvTcs04Rl2Xygnc6kcZzPo1AsIpuhfi1ixC9FEiXIioyjoyOkUikEDPklS9R3Jfz7kky1wcrlCiRZogGq0aBSQGz9q6oG0zIxMjICk/mhgBCmFEzXTjqVRiKZwOHBAROfdGDblAGvyDK/39tbW9wN0TAoMMGybNi2zYAKOgqFYx4MQn2sXvM2nvEGAdMMC1pUooVee+KEwXxrcOh+DglR6HBb0GiHsfJDPGgGlK5/D2gToIyoO0giVT4WW5n6oWRTN3fHaADp2CvtiJ8uqt9hchJ+1s/TfusM+PQ1skJbzOfPn8f29jY2Nzfx/lffx41XXuHPz2k4XFlBFJ4P0SWfGUN8VkQXMx0KszUAcBi08pNf/xoDg4PIZNK4dfMW9+7uhSo6iRwjkCY0tqnZE3oZ06GkIIlc6jw6PI9Cg0VR6FoWNw/nZgUR9ToJSKhcK/JBYpPNTyKleHsHjkBWFLYRmwqrIQRWEKS2fdLZg+6VEUXJX+2S+HSTi5yM1LyvYltfi3Dzo85ed6tzW1SGPrqBokFc0zRozFI2dCZUVZWpDQeQiEidCB2qakulyk14Lm2R6YYOXddh1us4ODiA02hwwhUAxOPUgTF/lIdtW0il00ilUpAliT37AAETOhREEXFd5/akoZS9zFSIRUmiviA+nVupqsqViB2mDNyXzXJuVHiYRDNeQ9ebBxcEpj3m8CARl3WIkoR4nFr0lstlBL6PRCKJRDJBZ0mOQz1QggAmG+aHdseuSz266/UaSuUSKuUypqamKKLL0Hny5nk+isUCdPY9227ArJtIppIA6KFVLBY5pwBw4Xk+Ty6iiQki8NqoQnRIQmz+PmVK0wqt1UyNRBIqSWKeGr7fhh7slpSGqEC07KnwObV2L2iglkSJIbpoF6EDScUCRXhWcKtuBsdvVk4eDazs99rPBZ94PKkTejofki6zEaEloISdhvB+9gLOdDW8OgHBxpMcJvWjaRqePnmCy1evwHVdfPSrj/D6G29Q4zNNg+s4XJkCpPV6Tg0kn4uEcsaqJAho2R+Lx/EvP/4J6nUTl68Mo16ro1wu84WmqEr33mW3uUcb5yGE/BGWCRORfV+kLnge70UG7PmJbRmXyGCNQkvvMrwvoQsjzUxaMw8K9wQIkTpmD90H+ZSI6fgOy0CaFVXgBxAlMBy+2BX11gKRJK2kxuAE2W6uDMAMwcLNKQiEfSaxZ/DuZLWTjrZXa2uiuTEEQWDtHsDzXFimxTN8iQTca8ZpONxvI4QMe74H3/Mpsa9QgKIoiMViGBoagqZpyOfzKBYKiOsGfM/HwOAAgoCgXq/hIHeAGPNZd22a7cuKDEkQUS6VaYbPIMcA4DPJdD/wqaNf4FMRyZjGkwbbblCfdSYT3z7QJSDcL6ThONwrJYTyVqtVroDMExlCkDAM6gtimtjf22dKurRSsW0bcV3nToRcut/34bBDeGRkFCJrm1XKZQiiCEWRuez/8DBFrWUyaSiKAtOkVr19/X0wzToajQaGhgbZgeH3BMs0me5MU80PIlWyxFWZKbhM7EgKw7WpMB8TwAstUnpm3dF2EiBBlJoL0WOIN1EUuM5YaMomqVLL4d4tIRVYwuv7HgLf5+2rMKD5XsD96UW6yRkBkUnls+vyA/DXtrPEW1vZkYojwsmhZ5PXlKDphkQL24Bd5jAd/YYwUWbzV0WWIckyF+d0XBeqquLc+XP46b/+FJ/8+hO88YU3WpBp4d4O1bfP0uqSvvud7363dYDVZaAFnDqcCi8gVC+l2Ry9gEqljL/4L/8VX/+jr2NkZAT3791DLB7nctXt8uXcPa0Xia5t4BQOmgVR5GxeTdUgKzKzhnWZY14ojdLKuI1mQ6GhD/W8CCIZakCDkCAyK9mIxwq7hpYZBEs4fJ+aLoWzgGQqSTNzUeRMXllRILIqIOwDN2cbPuNlSAzXDwbJbJK9woFoGDDCrFBkbOXoQg6BbmELg8+M2AahMuIuheOKFCLIM2o2s2r6TfgccRNFyHBf+IDyZkRB5As8RCcFvh/xIwlRMAKX2Qiz5tCoKsySPM+DbVGvcEmSIUoih+829YNo1SOI1Pvd8zw4DaqoSwBmpUufZZh5BdHNyZ6dJNMDyXVd1Ot1WJYFz/WgGwZ1CGRsc4F5uoTFYxAEHHxAlXtZ9iwKkBWVPuvwubHXuU7TsEtVqYqvWTcBAu534jJHRFmiw1NFUXBwcIBYLMYrXernQg/r0BwsRJaFa1OSKc+kXqtheHgY5VIpkqAgEiQohDs8JEOUncDsjUNEXtieputM5NV1iAZqPbxFaKrGZPfdrocuvadi0zYi8CMd1oBJx7jwPZ87Pfqej4AlMKEJHgmozYHP29JUMFOSJZ4A+X7AkU1RZQrC1qYky9A0jYFDfJ85X9gAACAASURBVN72asr0U7fKMCUM/IAFNIHDy13XpfuAwk/54SxLMr1WEiBg66a5jYLOgNo+yO+G5uoykCcBges6sG0b6XQalXIFsXgMAwMD+NkHH+C1N16HoihQNbXphsmShfA8Oa3gYIHkZIjpSV9hLzA8lEIJ7NAlDQC+91+/h/e+/B7SmQzW19bRcBpo2DaSqRS16LQt1gZrHaC1QH57kHX4YIplGOVKGbquc68Mhy24aPuBHrxR8bUmOsRnmXB4uASsIglbTAEzdyKR4Z8gCnxBhtcqCCIbcrlwXAeqwqQLCkX85Mc/BkAwODQIVdW69o9pBhJwX47wUKC8Bz8yiG9FpTSFMQVWgdD38D2feY37LbOjsPQXJQmiIKLhOGjYNt0sssIPYS4ORzqRZFGQju8HEZOs5oOTJAmyojDjK3qwhgTNsC8uilLz99nnlXi2R9eXaZqo1WqQZBlxPc7Wj81bOiGsWGSkPNdx4HouUkmqYyXJFO4oRg+8MFFAs03h+z5FoLF7Ftd1ZDMZ6t8ei8GyTHpAgw0n2VrxAx9N0yR6mPqeTwOzLNNsN2hFOoVmV6EysCzL0GIx6AbVJWs0GrBtG67rQpZlqBq10rUsC+l0GrZlc55LeJ9kmfa6G6wVGAZaWZZ54InFYigWi0xBonk/fN5yEtsIhE2V5zBZiQYRKo0jcoXgcHjbyj2i7xmw92kfQvvMNC1sYwU8EAQ8gaGfJaIxJdIDnLedw6qJBZPo3LLpJw/+c5+VRiQyUwnXnCLLzFKA8FkuT9SYVYLHErvQOjq0dYZA11+YMItSs1IL56HhHva9yP2IgBBaWmZdUZidxYnQRoIOPWcUhSojhDbOfX1ZWJaN1ZVVvHz9On99M3FEy+zrdwwkp1ckUWVfgC4oTaNM3Vs3b2J/fx9GwgAJApRKJVQrFTbMYrBf16ObmGVx7exYgqBnhRT2M8MUynNdKLLMxf80VYVtNzgaIWxx0QyL9mrDCsN1qY9GyKQXBHAFVlmWYZkWcrl9xOM6LyXNuolyuQKA0KAggKOWQqy5KIqIx+MghKBcLuP+vXtIJJOYm5tH/ugIv/nkEzQcB5lMBrIs8+AQ8htkWYbvB3Ad6mwnSWJL2yHaZw4XfNgq8jyPuxeGLSbXcWCZFkzL5BlqtVJBoVCAkTAwMjICQRCZTAdFI/Fnw1oJMmOuc78MFkA0TYVhGCyIRXrgIrXTDXzqWUIiLROf2fEGQcCksJsKwn7QzOhk5qUQIqRCiDEEgUnriFhdWcWdO3cQBAEGBwdo9ssCUD6fh9NweGYdXpvEqp1Qht33fYyMjkBRFVSrVcRiMdTqdRSKBdy+dRu2ZUFVVMRiccRiMe6c6Lpus0JhOkySKLE+vM+qXZ+7CgoQqKEXO3Bl1oIw63U0mH2x51Mzq3g8Dsdx2QEmNAMR83xvB2REh8cS86yPBis+w1JVEIA6RNo0IIUilLZtY/npU+zt7SGVSqGvr4+vYVVV4TQciJIIWZJo0sUOYNpWplVT2M4khMBuUNDA7u4uarUa4no8Yj8stnAjCNuPzapGYGrg4HtClmU4joNqtYp0JsMRgtSjnsneMw96VdMgiSIc5jJJ24exFtfEptRKROYFQKlUwkEuh1g8Dt2gygJ3bt/GzjaFqKdTadaNYYFeVUECgoZtIxaLIZlKMW200HKaetQ07Aa1mw6BOxBaE0FB7EB2RpGY7cjSbrbhYYDxg4AnE2HQS2cyEERKZJ2fP8efe/gcw/PnLJBgGcLnCx5NNFIrIkpRNTa0A9bX1vDpp58im8kgCAJsbW2hYdMNErYkAhK0RliBtGySZqso4HIElGEbYYyzHirgwzAScF0Xt2/fgaoouPrCVSSSSWiy1tKvDW+Q5zloOI3mwaJpHCwQ+HTTCaLA5MQrWFtbRyaT5a0FWvrT13gePUhCFns4qJMlmRsl2baNep3OiCRRRDKZhMg2doNlLmGWFwZkVVPhOA63fNU0Db7vUeMjIUSeKPzwdhyHtvN8qmYrSSI2n21ifX0doiggmUgiruv0wBdE7vMdOt+VS2VaWTJ2t6JSnoTjOVBkBaLcDLaO7zPrVto6tEyTeoJrKpMmBwLf5cRD1/O4VawgihACn0s7EMbcpigqH54b8JZULBajz4YdIgEJeMtGVRR2mDFiYQSJI0giZEXhmXR48IYgj3A46/s+GsyxMQgClEpl3L93F7VaHW9+8U3o8TgUmTLjfd9DXNchifQQDXv24UHcYh5EaKuj4Thw2DqTJXoICprALHI9FpDoGssfHcG27ebcixAsLC6ygEc4aCE6ewiDSfh53LASVjWorDKxGzYUX6HVpiTT+y+KEIIACcPggRqRwFIul6GodP1tb21hf38fOzs7uHzlCnSdzn+CaG+e0DmgqIiQFRmO69BZREDXie/5WH76FLphoH+gn1YTkdke3c+EtyQFUYAiKPzfkixBUVQk4jFAELC8soxHDx/h/a9+FQAQkzW4LJGi9zUOLa405yi2zZ05RVGCxCyfw/kYz7CZfbHgedjb3cPuzg6SqRQMBvyg5M9JOt8F4etUkiXEFAoishs27IbNk1EIAjSN2ldQ8EMdWkxDPK4zOLzHzzVFUSApAuN3BF1H1KStDKH8rh6ghbCVzJ5TuVxG4fgYc3NzKBwX8OHPfoY//bN/z9vLnUXCKcN28px+I9HhUfSPhL1NSZYQ13VYlomd3V2USyVcv34dR4eHKBVLzT6lKHGeCO1tEohBgABii54PCaGnTOuH3ZamAByz/AzNeRq2jZXlZe52l0gmcOPGDYiiSBnDoLITMU2DYSRo6R8EMC0bff19FK4pSYjFYqgwqGmYYRwcHGBnexvz5+aR0CmRLZQbD/u9stpsKWiaRuXG2TXqhgFFkdnQkfaXE4kEFhcXoRs6HfSyv51KpxGLaWgwNrjLBtMiy1xpRSWjVqvygKGqBt+UYRYRsq/X19dxkMthbHyctmmyGRhGAqJEKydd1yHJEoeGKooCPR6H3bAZlJU5FXo+LMuCoirU1tV1IAoi9JjOlGZtWLaFeIxaxrourTQkWUKFZbKapvFg7rguY9RSyG3oaBiW+qZp0pZe4KNarSBhJDAyMoJSuYR6rc7bFY7jQBAFjI6Ooo+JF8qSzA2wBEGAYRi0v+64HJobQng1SYKqaVAVBY1GA1ubm7j525tIZzI4yB0g25fF0PAw5s+dw/TMNHTdQKFAvT5s24asUG6LLFPvdVESufOgHtehsVZvWIWrqsqcEj3eSiKE4CB3gKdPn2BhYRETkxPI5/O8ZSVKEvR4nHJlWKYebnrXo9W0xhIhgVUlnuvCc13IioIsI1nW6nXULZPBs03oug4jkYBlWyiXypyAOTg4iMVLl6BpGoaGh7C+vo6d3R3kcjnMzM4ixTJtQRShhocPe9bVahWyIiOZTEESRTQCqrZsWRavcOh10+rUsizYto2BwQEMDg6gcFyA53nNNpTvI8YyZkGg7b5Go4GD3AH29/bgug6y2T4mVVPg1TkhdMZnmhZkWUI8rkNWFFi2hVq9jkwmg4Bxl0LrgyDwEYvFeVtxd3cHe3t7mCsWkEgYGJ8Yh+d5uLhwEcfHBfg+nZupmgbLNGHbdO9PT8/g6OgIlmXCMBKQZQlOw4HjuIjHY0gmk0zFANATKSiKDM+jCUGjYaNeNzkkOzzgSQ9vJBJVqiCdUithqyycnXqeh3w+j+GREVy6dAkffvghlh4s4dq1a7zSC/dpsx0nngz/fZ5gchJ9v9FoQJd1bGxs4NcffYRSqYRvfftP8OD+AxSOC6hWKzzD5QQ2NoOAIMCDBzHoXkbRPqjQxssQeMtAVRUQQltbe3t7+NI7X4IgCHjy+AkuX7kCWVFg2zbMeh137tzBlStXKQyUECw/XcbKygreefddlMslKjc+OQXXdZFKpzE4OMh7h+VyGWbdRDwWR7FQwIMHDwAAs3NzSBgGPNbiWFleRiaTgWEY1EpVVXHt5Zf5TEQ3DJgWdev7t5//G1PDHUGpVMKjhw/h+XTon0wmcZA7wOjYGC5dvoQnj5/g0cOHGBsfYxLoMna2tzEzN4uR4RGoGoWsKopMWw+ihK2tLezu7OCVV1/F7OwsP1Qt20KlUsHPf/Yh3/SapuHw4ABDw8O4dPkSatUafvzP/4xUKoULFy8iCHwc5A6Qz+eRTqdx7vx5OI6D4+Nj1KpVXLh4ERcvXsRHv/oV7t+/jxdeeAHJZBKNRgN3796FrusYn5iAqqo8s3v77bcxOTWFFcZWf+/LX6atC0nG40ePICsKXnvtNRzkcvif//A/EI/HMT8/D03TUK1W0Wg08OJLL6F/oB8f/fJXWF9fx7vvvYdkMomnTx7j4dJDpNJpZDJp9PcPYHxiAtVKBaVSiW+O5adPcXh4iJevX8fCwgJisRg8z4OqKDBNE+lMBmurq7h39y4ToVxAqVjC7Vu30NffD4BWY7V6HdPT0zh/4QLW19bw2W9+gxdefBGeRxFpR4eHSGcyuHHjBpel4HpfjQYOcjnk9nM4d+48UqkUPNdDX38fCAEOcjn89IMPoKoqRoaHAUHA/v4+dD2Oa9dehpFI4O7du9SbRFEwOjqKkdERGLqBx48eYWNjA1986y0MDQ3Bsnws3b+PldVVfOMb30A+n8cnv/41Li4soL+/H6IkQYvF8PFHH2Fnexvf+pM/QTKRhGlSFF2hUEA8HodpWbh75w4uXriAK8xcbH19HY8fPcKVq1cwOzcP0zRpi0nRUDfrKBQKvL1YrVbwy1/8Anpcx9T0NHZ2tlGv1bGyuoKFhUW89vrrePZsA8/WNzA9MwNREqGqKhXSdD3UajW4rovj/DEcx0GpVMQv/+0XiOs6zp07h2QyCS0Ww+2bN6HFYnj7S29DVRXs7e3i5m9v4sYrN3DhwkX89rPPsLW1hdHREcrl0TRkM1kkU3TtVqtV+J6P3H4OuqHjH//xBxgeGsaX3n0HyWQSv/j5z2FaFubn5wEBuH/3HvoH+vHqa6/Dtm387Kc/Q+D7WLx8CbIkI5fLoVgs4rXXX0cikcBPP/gAuf0czl84j1gsDsMwMDY2xvkfoZxSV1ZY2/nN6QhdDApDYEhohXD37l309/fjy1/5Cj782YdYX1/H1//o69ANg3aNI9VJgFYFgSi6VDy7rlMXIl/ktSHapl6v4/7de1hbW8Pk1BQqlSpyuRxqtWpTW4mVa5TQFDJAAx5c+IwgCFqgtiFzOmRPtyMXfN9HpVJBuVzG0PAwpqdncHx8zIUCCSEolUrY3dml1yyI/KA9OjriOPy93T3E4nFceeEq5ufnee88k04z1IyETDoDI5FgvV4dExMTSLI+8tDgEBYXF/H6G2/g3Pnz2NzcxJMnT1AqlXjF4DgU168oKjVMsiwIoohsXx9m5mZx48YNfOELb+L69RvwfA/H+TxH71i2hflz5/Dy9euYnJqisho7O6hWq3Act2Xh+b6HUpEO2IaHhyHJEgqFAhcD9D0fW1tbMIwEFi8tYmFxEfV6HU8eP8ZB7gCZTAau6yKbzeLatWu4fPkKEokEatUqdF3H1atXcf7ceSQTCa5eEPg+SqUSXNfF5StX8MKLL2JichKGYaC/vx+vvPIK3n//fbz66quwLAubW1uwLAvHx8fY3d1BqVTiFcbh4SE2nz2DKAjwfJ9Wk7EY3v7Sl/D2O3QTP1xaQqVSgaY2A4uqqqhVa9jZ3kGlUsG5+XkqBTIwAOJTEuTIyAimpqYwMTGBbJaSGm3LQq1WQzKZhMGgudlsFgnDwNHREXK5HK8yKpUKcrkcFi5exPXr13H9xg3IEs3G47EYYpoGy7Jw/vx5XLp0GVeuXOHs93DIHs4EwxmGpmkYHR2FbVl48ugx+vv7sbq8ArNex+HBATafPUN/fz8uX7mC+fl5ZDMZ3Ll9B5VKBbZt4/j4GJZlYXR0FNevX8fExCSd5bHPZVoU2NLX1wdFVVEpl+H51D/+4OAAQ0NDmJ6eph7fto3DgwPIsgwjYfB2pSiKMAwD6XQaY2NjUGQZddOk7TvXxfr6OtfQCz3qJZFWjWFWHDoyGrqB4/wxgiDA/Ll5XLh4ETOzs2g0HJj1OmRZwtHhIWr1OgaHBjHD/GLGxycgyTJt97EZpgCBqzxLkojZuTn09ffB96n9wP7+PhqNBm8T72xvY39vH5Ik4vDwEJ7nYnp6BpOTUxgZHuFqC1T92Ydu6EimUlQ41HHh+T6GhoZRLpfx5MkTyLKMc+fPYXx8Aq7rYntrm0r91+rY2d5GKpXCyy9fx8LiIpLJBPb39uA0GiiVijjIHUDXdbz+xhv4wptvYmh4iIINAjqY7+ZYiW5setJEpJIg8hVV1gjRZ6JIPXWePYMsyxgdG8XdO3fw7NmzlrZpy7nPv8ToeAni53XZ64Y3D/u0GxvraDQaGB0dw53bt9mwr3lDAgar9SNs3rAsJiHZibTLG4AjgbjSZeRD0haKj/X1ddqrFkX09WeRTCaxubmJapVKk9t2AwAdWFu2xbOP8H3K5Qp/uOL/396XNUlyndedXKuy9r2q9+7BDMAxAAoAAZIgxVVLhBeGbJERtn+Aw/4FjtCT/SPs8IP1IEco5KAUCtmixRWECGIZgOBA2NiD6ekBpge9d1d1VXUtWZXL9cNd8mZW1tIApCd2BCIwM93Vudx7v+873/nOYQN8hm6g3+/TRp5hYOw4gqnhuK6AsThc0+lSSOz09BSnJycicx6PxwICM82EaMCrqoJBvw/TNJHJZJDL5XBxcYGTkxMcnxxjPBqj2WrRrHdI4YfRiCrYAkClWkXzvCngE14ec8aF6zh0etr3YSUtEEafzGQy2Nt7QJvLjTqy2RzK5TKKRToJ3e120R9Q2qtPCPqDASzLQqPRoIuHQUpmwoRlpTAcUA+MEWN5EULgsE2by+WQzWbpfR0f4/T0FCo7ULqdDlzXpZx3Rin1WGOYPisTZiIRImHYto1Ouy3Ugwf9ATzPQyaTQT6fRzKRwHg8wtHRESzLElURT2oMw4DjOLhotXB0dASfEHS7XfR6PeGWyBu9pkmDvcZk7BVFQbPZRKfToVpFwyGqtRqWl5ehqhr6vR6G7ABVFIVRlRk06Plonp+Lxqxu6KIZ7jgOnnnmC3jk+nW89957ePPNN3H79m08cv06VlfXcHFxAcdxUCqV4DgOzs7OUG80WE+njYtWi5JMPA/VWg2O68Ie0mZ3KpWC4zh0nRKCTrstBhKJBFXrDNpLJBIolctUIFOnkMtwaAsxTp31Fka2jUq1ivu7uwKeajVpYGg0GtBYL811XQyGQ8EA5P0z13NhGAZG4xHAlJGTVpK+f0KVk/t9qoh8dnqGTrsN1/VwdHRIZ2PYLFAmm0WtXkc6lRa9s/F4DM9jrEWGfDiOi35/IFiliUQCJyenODk+RjqdQbVWQ7VWQ6FYxOXlJfvdrhjc9H0K7VqWBddx4BMfew/2MBqNUCoVoaoqyuUyNjY30G638eH9++Jc1Q0DzWYTnueKXq7jOijkC0halEH34YcfCrdM2rPkPU8vdoYvGkD4ORzQ4cMJOWdU8nfIGyynp6dYXaNIwZtv/ErMeMWjUZPT/GpUOCNeWmO6+mQwmEfZHq++8gr29/fxz//Fv8T93V2cn5/TF8s8EcDhKI9myz6hNDNOvRM3zucWhNyBH5rtIBLtF6A8/OFwSBliqTQePnyIt26/haE9xOHBAfq9Pm3Ieh5Mk2LO9nAIAoJsJiNw+uvXH8F3/uiP0Dxv4i/+/M/x4osvwjRNIcWgaxo81w2oh4AgELhsIO3s7Az37u3i1muvYWeH+qzwYCt6KUwvisJMGYozmyYODw7w+q3X8aMf/hBvvP46du/tCoc83pj1fZ/dL6W9rq2t4vLyEmlGF/U8l3HAFQEDuq5LoRwm2eH5NMM6PjpmzT0TJ8fHIL6PpeVlKhMyHNJZBgBWMgl7OGTBhcp2ZLNZ2gDVNGSyGQBAsVjEeDwSNFbCIEHHcdBqUvihVq8LIblslnpg8Gw8mUxStz7GgjEMg7HA6LPWVNoH4BVMvlCAlUrBccYikel0Ohiw4DcYDFAqlwXbJplMYn1jA51OB//vBz/Ar3/9a7RaLQpLsn6HaZqCkssZYr3LSySSSWSyWZimKdiH1WoVhUIB77z9NrrdLh597FHRLHdcF5lMBh57RjQgmgwmcUPyHFytuD/oY2lpCd/93vfwta9/Ha/fuoX/9Wd/hjt3tsU+ff+99/HzF17Aj3/0Izzc28Ozzz2HdDotGqi6rqNWq1GZmcEAmqqiUCiIvheFlC5hs0SE04ITjNnU7/fRPD/H2Rk16uKHWq/Xo++UTf0rrMexsrIiJPjPz89xcnKCLz//PA0ihNCBODbhz9cvJ5j4no9cPi+GHXVdQzqdEWdMtVYTJmhvvPE6fvbTn+KFn/2MBQcfhmEKWPHiooVevw/P96DrhqhO+SHOBxDl8YR0Jo2z01MMhgOUy2X4vs88Ymgz3LaHorfK6brjMdVoM1jP8OjoEKqqolavo3nexOnpCXIMvdjf3xfJUCaTQbN5Tl00WY9oPKLyQU89/TRVgn7jV/jT//mnePedd+keMWi/lZNDghkzTASQ4D8y8Z8sYul5QWA0TROplIW7H3wA4hN889vfwvvvv4+XfvGLK2lu6XGK4dPNnpTYCVH+dfeDu/jpj3+CZ579AvXkvmgJ1ok8HxIMYvkTo/0T063ReRIEn+GrwUCboqo4ePgQZ6enKBSKODw4BCEEVtLC2dk5Oh3quJewkqIJmslkoGqaGPSikhspWFYKz3zhGdzfvY/t7W0Ge6XRbLXgeh4yDPbodruCO28PbegGXbx3795FMpHA81/5CnSd+mvzZ2WyDIpnu5zmmEpZ6HY6uLezg4ODA6xvbOCpp56Cqmm49eqrUBlNln/xPhNXFKZUSU8MK/psoKrXu0Q2m6X6TyzDL5aKGPTpHEStXker1cJoNIJhGKJv5bouo5yOQ002ucFLWNauqio814XDDkxIsuo84HM6NA+m8ueoqopsJoM8oz87joNSuSz+3XVddNod+CKjCggFgf4RCeZcCIHBsq1EIgHPddHtdkVF2el0cHBwAE3TcP3GDVjJJHK5HBqNBkzThG3b4r44NKob1PtjMBhAZwHQ931BhS2Xy+KA5omCYRjo93uhzJIHKQ5t8d4iPwQSrDrOZDICJ3/w4AENTOMxNFVFtVrBzZs30WxRAzj+LHzfRyqVgut56F1eImlZoqnPG9bHx8eo1+swTVMcppwOzN8L15fisy+2bYss1xXsKR2GRB3OZrP44IMPkEgkUKlWscw8XXz22ePxGJl0WsAq/ICn8yYeTNMSuDufEB8ObUq1TiTw5OefxBNPPokP7mzj44/3mWtmPmCt+R6y2SwLkDYL1ArtM2YyAKuOLcuCZaVwcnIs+p6ZYgYGCzy6Tu0JxuNRaP25LtVKS6VS6PcH8FjVPx6PkEpRkkv7oo3l5WXatB8MxXukvVx6gHMqNJ8tsW0bg0Ef5XIFjz32OTz46CPceu017O3tYXllGdlsViQiXLYoQHGm6d9Jqskzlck9wQzs9/u4+8FdrG+sY3llBb986SU8+tijWFtfj5z1ykRMEBVJVH4kWp34UxQv5a/Ly0u8+uor6Ha7WFtbw9HRIZrNJht+gljIouTyKO2TzGngc70fP9I/IazHwqdfXdfBRx9+hHK5jK9/8+v4xje/ga9942v40pe/RNkwJyewh0P6YjxPGBu5Ds1Q+FCZYdIJz8/dvIlHrj+Cfr+PVrMJy7JEJWSaFCvmgzu6rlOan0ZhjYP9faEw22g0KGTDsk/TTFB4bDwSw0ue58FimPv+/j6a5+dIpVLIM90omjWkGItFE4wk/ox4X4Rm5X4g/c30rXj2s3P3Lh7u7bGpb1Uw0trtNjqdDjY2N2AlLVxeXkJVVdrsdR2RmSiSBg9/n75PKbpjVmnxRc+fb/BzssyGL3paKqvEhraN8/NzdDptDIe2YNm57HdctC9C7CZBA5Yml0UlyzI3TaOHgm3Tg6VSqaBer6N9cYHDgwMkkklcu3YNhWJRQFtcJNEXVs8K8oUCarUaNI1a9PLKyzRNpk5MIUN7OKRrJZWik8KmCd+nGTmnBycSCUZfJsK7heP23BeekzparZaA7uhhawp5mEw2i7W1NQHBuZ6HQrGIxtISQAhOT0+pdhmDvRzHEUGrVC6jXKmw6WwE1QEbwuVsNt7PGLOMmA8S8vfMAzUArK6t4f7uLo6OjrC5uYlKpYLhYCAGIl3XpX0W1mPhgYSvIw4ngk2b8+8ZjccYj0ZIp9JYWVmhTEtGoZcP0JE9EtUJp5lrqsbYkikBxfFr5pX2yB4hk80iXyig027Dtqkz5mg0Yo3uILDZti3W3Nhx4PkeRqMRyhVKtjg9PWWBwkf74gLZbFYEeg6rpVNpAVFz+K3T7qB9cQHTNLF17Rqy2SzOzs6YjBTEQKZcdfDJ80D3zBOy/mF9vvC8HVdr5kxT1w1g73v3aBJbKpXgeR5eeZme59Nkc+RgMiHaGPUyIrLfxLSpRk3DD/72b3F8dIxv/d63cWf7DrrdDlzXo7MNQsrDm5AqF9LQynSxYQJ/womNT8Dyz7eHNk5PT7G8soxqtcpofAR5Zrd6eHCIpaUl1Bt1lEpFtJot5lM9QKdNp+HH4zEuLtpoty/w8cOH6Ha6zN40wxaWgUQigb0HD4T0MqdvckpdfzBAPpdDoVBEp0N1nbilrCdRPW17hOGAUg1p72aIQqGAYqmETqcNz/Nw2euhwzy6FUXB0KZQXDKZxOUlrTQ4xdZMJAQPnjrzedA1BYV8AUbFwPLKCvY//hh3trcxYL2OVCqFbDZLF+7pKfYe7AlobnNzE/lCHg/3HgpxQ8914TKKtaoqQu+IS8AkEgl0Oh1GczbE4cUzME6L5gejw6Aky7IwYFlzMpGE3zHfIgAAG/tJREFU6zpot9vQVBVJdvDyQ1ZVFTFtTucMWNboOLQqZHBKt9NBtVrF6uoqjo+PcXh4iLFDs1PHdUUQODk5QSadxvHREe3TMPtdnxBYqRRACFqtFjyXEgh4Q59DGZ1OB++9957I3lutFlZWVsJmV3xiXDp8PdeFmkwKTTLCKrXRaEQhV7bYh8MhNjY2YJom1tbWMBwOMRwO8eCjj5DJZjEejdDpdlGuVFAulykjazBAt9tFJptFfzBAuVKhjMpUCr1eDwcHVGK/1WohXyhAZQHeNE0MB9RczGDP3GGZ83AwoPpjFh3C5AO/5XIZ6VQKj1y/jrsf3IXnuqg3GpTWy+VAWNDnUCyvJBUGr/A/u64Hl7jo9fuBNpeho9lsQtVU0WfM5fOwLEs8S03TcHZ2xhAGlSVdtH9Bg/8QxVIJzeY5dnd3kc/lcXx8JBKkhGlic3MTOzt38d677wqmVqPegJUyUCyWYBgGzs7OkErTc2Jk27BSFgih0N/W1hZs28Zbt98SkOK1a9dgWRaarWbQx2VzMoNBn0KNqRRW19aw/Zvf4GB/H4MhfXeVSgXZbE7Qf8PJvT9VDl8mQ3E9r+BnI+QlPxDjTCaTFHo7P2cU90288/bb+Fff+Y7oCc1SG54v2hjDW47ShW3bxqsvv4KNzQ2srKzgJ+/9WMoOSNBIl3Soop+hME9BxGrwk5DJDc2IfCE1wPnf4/GYusflcnTGQFGQtCw8/vjjeOFnLwgMu9FYwjvvvIPt7d8gk6E4f6VaYc3YIzz46IHAMVdWVlAoFDAYDJBMJFAsFrG/v49qtYpyuSyGz/ghqSgK1tbXcXJygr/6y++jVqszGC0LwvoXPIsbDGhWxBvBVsrC1tYW+r0ednbu4s72NjRNQ7FYFN+jaTo9IBgWnNCo3EU2mxXGNPLU69AeotPpYG1tFZqq4vDwEDs7O2g0GlhaXsbm5ia+8tWv4N133sWLP/85Mhlqcfv4c89Sfw82LKcoishKPc9DLkdxbWc8hs3uO5fLodfrQVEUZLNZNM/PRVYwHo+RSqXEIvR4Js0+M5VO47HHHsPhwQHu37+Pf3jrLegGlWi5ceMGFeB0HOTzhWC4cUyH3Sx2faPxiBpVpdPoswNxdW0N7XYbOzs72P7Nb3D9xg1sbW2hUq3istfDy7/8JXTDQIf5pWdZ9aapKsqlEo6OjvDW7dtYXVuD67ooV6sYsJ5OrVbDyLaxvb0N3/eRzeVgM8aU67r08DUM4Tjqep4YQuXEDCLJ+/ieh8ODAzx48ED0cy5aLfzBH/4hkpYlAsKdO3dw69YtAb2UKxVYloWlRkNYCx8fHQnJ/aeffprKyheLOD09xf7+Pvq9HnTDQKPREFVJLp+n8vKuS5vuLIFJWtTcK8sIE+VKBeesf2IlkygUi0xckva4SsWimN3hX6Zh0LUhWQLQg54qMus67V+Mx5StlU6nkbIsdLtdvPnmrzAejTG0qSRMo16nVaTvI51O03d52cXh4SFq9Roq1So0TWdNfRr46406RqMRbv/6NnyGSOTyOQo1KwrWNzZwf3cX93d3USzRebJSqYyUkkK1WkWxVEK7fYFityjkTjhMlU5ncPPxf4Z7O/fwPhsHSGfS2Ly2RdGHEYXU6N7xoWl0fxYKBbRaTezeu4fXXn1V9Ahdz8XW1hby+RxDXVRJey9gu3KfJlmiXlFISCkg6poYIDrBRLyqUjHSUrGIezv3sLHp4oknn8CH9+/jh3/3d/i3//7fMRjQochKzDyJ9l/+a7xESsiPQjrYuZMWj+b9fh8v/f0vcHR0hOe++EXs3N0Rm9zzvXjJE0IC3VSC0BR7SNOf6U3FSddTGjDFHTkTRNd1bGxssEniEdVuktRZy+UyqtUq8vkCKpUylpaWsLS8jOXlJWxubqFeryORMJFKU5mQtfU1VCpVZDIZ9Pt9OoCYzgAgqFSryOXz0FQVmWwWyWQSjuOgUqmgWCyiXquhUq1hfWMDqysrqFQqyOdzgKLA0HXUqlXk83khIpjL55GyUkhn0qjValheXkG90UC+UEA2l0WukEeGkQLS6TSyuSyV/+CMEE1DpVINs+hcT7DLcnk6Q5HJZJDOZFAul5HL51CulFEoFGEmEkin0yiViihXyqjV6jDYQZ7OZMSQH5f94NAbH8LjzeQCa34TALl8HrVajR6ShMA0DBQKBZTKZQyHQ6TTafT6fdSqVZRKJWoBq+vI5XKo1mrYWF/HxuYmVldWkM5kqEwK+/d6o0HhAXYI1ut1ZDIZSlVNpVAoFMTGzOdySCaTSCSTqNfrqNXrqNfrWF1dRTpF4ZaV5WXcvHlTzAyprKnPD88ce8ecVUcbrS59rpUK6rUayuUylldXcf36daiKimwuK4ZWFdafURQFBntOyWSS6sGNRlA1DQaDd/gMyLWtLaysrmJ9Y4Nqno3HsJJJVKpVlMpllEolVNg6SqVSVCafBRxOX65UKtjY3BSJT6NepxBfo4Hl5WWsb2zQSo8NpeYLBehsoJEHmEwmg2w2Sym2Ks34rVSKsuFydPbo+OgI93Z2cP3GDQHn+Ew1m/g+LMuilPF0Cq7joFIuI8NgZgDI5+k6t4c2UqkUVE1FPl/A0tIypV+zd7uxsYlHrj+CVMoSdOJMJoNCsYBMlrprJljCR2FsKkWiKiqSySQKhTyWV5Zx49FH8eSTTyKXz2M0GkFVFSSSSRQKBeQLeToRn0gwKR4TukaHGTNMzj+ZTKLKklY+SgAAuWwW9UZdkDC4ggZ/F7lcFpqms6HUBFZX17C+sY4s69EVS0Xk8wVUa1Ukk1ZI/gaIautB2FYER7UyQ43dF4GHhOwllKBXJ5TCNVSqVfz9z1/E+vo6iqUiEokERowRG516V/wZzQ9FPvz9cI+CU1fv3r2L//Hf/ju+9e1vI2kl8as33oCmaugP+sLgSJcx2IgsNRQF6vyiaELv32N9Fj4Zq+s6DNNALpfDwf4BnQHgUiIOgyx4o1o3RFbLm9M6+zuOVWtM4VPXqZpqq9lEuVxG0rLw8cOHlM7KRCd7vZ5gbNUbDUqrZI1hPnTGNbT4xuEzNa7nUn0mrmFlUFMZjmHyPoTwCZD8GLjBjmmaaDVbKJaKQqCSC0+KKXemf8QxepfRlnnTL8UOBi5i6LlUTp1vEIrDuzANUzSMbduGaRhIsOE9YdjF3rfHhBm55AxPPvg8z8rKCg4PD5FhAYUzhFKpFMYjakAFSY6eB7Z+r4dSuYz2xQU9gFk/gmP+fFNwVQCZJMChOIPBlALjZaq5nGHGm9FCQ4uLQjLY0HVdCs0YBnM/pDMaKabHdHJ8jHK5LOA/K5lEkplYjUcjmAlK/x4OBuLnrFQKHgsYXHLE87zQfSQSCRisAT5kbMHG0pLotWgsYJnSe6aqxY4I9rph0Oc7GKBSreL87AwJNvXuOlQpW1MD+XTuz6KpKhOeVNgEN22yG6aJd995Bzt37+L3fv/3xftwHEcEkkq1guOjY9RqNeGKSv1EKGOQq1G3223U63XBGFRVFVbKguvQ9acxWROOcFD6tC6gGyEcyXxibC6JYlBVZccZUytokwaI8XgEx3GQTtNgSXwqvTO0hxQlSNL3wue+dEOHZVlsPxMBubqMCZVOpYWy+ZAhDnyokO9jTdPZ3htRTTKdyew4jMSg65KGGuLnR2QLAwndCalpx7jNyrJTVCJfFeeebdtoNJaYvlwCz33xi/jJj3+MWq2Gf/3Hf4zHPvc59Ht0TIF6PqmC3j21IgnBUQTC/4NDOaqq4s72Nt5++23s7e3hq7/7u3j91i20Wi2qTsoHYdhNCSVdoWLpSz7jcXxoEjJSkks7X2J0cVVceqCYAAH1g9B1oUbLOdM8kKmaipFt4/KyC98nAmflMx2yUJnCDg6+QME2N2FNQtd14bDMSNU0yqNvtaAyU6cho8zyA13Q+CQ2iBzLB/0But2OyEy5eJqYv+HBWF5EbPFMONtBCtaMujhg+LnrugGPXKFNR+5/TucdXDjMxpYruMqNch4oiDQMStia4e+I2+lyxplQLJZ0f3jwASMxJExTMK/oYg8o5rzRyyV6+N+rbFqXB/VOh87ZQGrK8w3FKyndMGgSIiVMolnPehby9crrma8HvmZ8SbGYm3i5rFkv5Mf5ZzK5cl9KhCD/nQzp+j4U9vv4OpdhBYMxwywmm+I4AfTQ6/Vw0WoFSQhL6GzbRu/yUlSIvJelsH3pSSrPMimCSNWFeB5MEwqE4PDwEO2LC5RKJVGB0YHLIHF03UBzTRXCo8G0NBepFFIghMsu6eFDMmqRK12rUAFm3j8+s3+gBmV0ANkQtgREqPnyZvbYGYs1yz+HwvOKMM7jlgY06RiLs5GfGYHBnGSspUBS+JVIIZK2F5EyeM8LZPC5ZbDcRJ9KUELEAIvEz5rIVhe0Ee+JhHo0soV1wvNf/QpeefllXHvkGsrlCiX6iMBIgnNyVkXieR4UWRUTioietm3jpV/8An/1/b/Ed7/3PbzyysvsYPCo34RPAMYckiWQZWhr2pR8HMU4SnGj2kOBHSb1Ug8WLWeAhPssQWCiwnm0v+KxxauqmsQW8wR7RGXKt+La2CaRh+YMKSPm7Ba+IKl8NCYqMp7dclhON3TJjEfCQhUIlVTHdeB7vvAP4PL1VDMqnqLNm90049HE5pcDeFTlk9+/XBFougZn7DB9IEWUuESqXHkmy5+PYRgwTFPIafOMiwsd8i9ueOUydVYhAigCZ7hS5p8zdqTrYdWQplHRQj70p2lUgZcbH0WVcVWmf+V5HoPAEuI++VqLrk9arepwHCpuKVeTstICTUw08TyjzDVVGCVBJDKKooaEJTltmZMOOMvQMA0ooHpqfE7DcwOTJE7jVSQOj67RjN51HDiMBWiYJsasOtUNQwhXyjLsOjNIcl2XWhKrgeeNjBBwOEze73yt8wqJz81o7PmN2fPTdEpxFYZSjKQQyMWrohI3DAM6g4j4wKfOdOyoz48i1Lt55e+5VDNOZxUBH9DklO+hPYSmamJvUQiKXh8XXuX7kFfzmq4xh0kWiJkwKGd2Un+fwIaBBnU1MNubwpSllb0aaYorU/AazOxhxznQ8nUYtRr2mOBu0qIV6tbWFoa2jQ+27+A//8mfoFKtBImwQzXlVFUNWFtxX0JSmIRZVXRi1MP7772Pra0tdLtdWJaFbqcryUGTua68syjFUVOXqM2smHYnPhQ29KmrmijDQxaXSuDqzvJ0iUaqQFGMEMwlM8To/1NpbIXal9GhLN+Hx5qkIdlplrlBUYQyrBwQZXiHXx+HuegGCBpnmq5JRjc869XEoc8tgFUt8DaY9kw1VQPRmRWxP8nyUFj2xTeK7I4Wuj4JllNVVdjZqtximS1gncmd82AJdvjLDWb+ffz+uGx4EIA1Yd0sbzpFlSxSFUgTumEjT9mQSa7cCAhUXxXvn79TDgHK9xnl4kc3Pe15GSFHTe7/wMkg4RkcRfydK5hN0rvjGW9knosP5QpPDV0Pe4aztRcV1lMkozifEErTZlRtWeVVlWArXl3ypEmVgjoPFHwNhvYx+z2qqoC2NskERq+oCnRVD30eP+xFAGAChapkl8Atetn4g9j78rsT60MLPzdIA3ye6wmYXhacVfh7VMN7mRCWxDG4LLAIkCpdWX6EqT17qgdXCRSmVSIpljPbAFXXwmxUSQrKJz6Ir01NDGcFkrizdd74htxT5dRr4hM0m03ahyvk8Td//df4D//pP4p5KB64QwOJ0xrufJhKiYzFv/H6G+j1LvH0M8/gwUcfCciLP3CiSCr5UwYc590gr0TiHphsdQnFh87c8lSfwHHHsuFZ5NAMy9/zw8JxCFyX9zAIk2vQIj8TZHiqpkGXLGU5BCK/eEVk7IRx0mhAotIr4YonqLiCLCFEdPAD9U7h5MZ7K5oaCq6xrpKqCkMxwkWwtP9lPwS5F6NIB7GQXpf8PIiqQCWK6I2IiosdTLxPwqsaOVPV2O/ha4wrBQMAYQeNsEBlVQXfzFz/TFwfgsFHVVOheKq4D/mQCa6P3S+/Z10NQY5iUA9hqFCGEDyP9pBUXRUHiONSIzWesdNsUvYmV4Vnh+wbwp87z8RF5cLgHd/zRYAzmEKEIMBIvUue8U5eMwF8QpMlnwiYjFfPCiOBeH4gW86HEoXhFYPa9JiJZw55cc0rKGF7aO7WqbGegO8FsumhgESIsG7g60+FKingKgChsJTneoFihhToeX8kQAAYTM/7Dg4Rbo28J8iVJQLZdV9UsFxxWCYCaZoKVTVEZRHN+HnPRHjIcxMzbiwH2hPl1xk17gv2iCZ6jPGuiIvLWs06a33Z4Isldbqu4+HeQywtL2NlZRW3br2GL9x+Fr/z1FMTP6svoqHFefd8Sd7b2cEvX3qJSnN0u2ieN4NsjelPYYoVZNycyOw2+2w5e75dXLihrC2gHsd/hsqkl31hROQz+1AtlHnSxShJwvg+fJaJx8k0KwAUKaCQaIVFFOG5EmD9ykQFNq00lY2L2IkbHL4+mbA+FkJrsjlOQJWT4MXgOYAJa/LPdF36bInEOycyXi2VxiQCacj9EJWEB1AVRYHCHSilKjhgDE5WWb7iBeoIwn9BCbH54LKqg8MuISe+MFQQsFeCjDpuU8cJlspZrVz5KboSycTDiYzvI1QVys9LHFjgdsVkyjWQ2L3Am6qiUAGRXhMz2lKIdHj7IckNX1jbshCkqcEcmOdFqlhFPDdNC3zLCSYTGvrZgKL4gIsJDSh+raLfR9TJwWhl8sBW/LB/BvEJPMUX6z1O2gkqQp7uvjToKjejFSm5kgP59HOIBUU1COByIhEkv/TPDnHDyAkP3mrY896PnDVxZ+S08zTsXxL3c0RCS3SxnzWNVlyDwQB3tu/gy88/j63ja/j+X/xvfP7zv0Ptn+IGEmec2HAdV9hz9hj3vtvpIPnoDew92BNy3MlkMliILDPg3iJxU/Lzyi0lNKg4m9ql+EqokU1C3uH+FGkXZWKAh0MivKfBD9Bo1j7pREYWC4TT32zoe2T4LXRYKfRexUKXFxlI5FBSQnAO54/Lz4N7MsuHjlzO+ZGm4DSjm2hfikQb2GI7xbxK6bkKGI2QcAAAmWDuyb27UAWtBPdHfALHc8LrL+a9xL1XmQwSff+hgCz9vJi49+WpYyKqEF+ySZDvjX9G3KHBryO0hqQ/O27A2JGhteh6l2Vp5All8UykwMWDLL9e3jeM9nL4wUchO7Zvoha67N3JSRKHcEBiqmdZDkhZIK9UECvbEeprsrNEfi7ynpCDgi/ZLnO4c+IalOnK6EEQ8QHfhxfZmyAQiZp8TaKRryhQZAJBRD7+sxDZ5dfps7ONJwH8xvigqGmaODs9xf3dXWxsbODs7Axvv/0PePa55wT7bS79V1ZatSwLztjBiz9/Af/3b/4Ptq5t4bJ7iR5TOtUNXWj3EKkSEKUliWQfcWbD0cNWQcgvetZDjGKJciCZyEgEPU6RDqHJikmeIo0Gn4lrib2PmcTqWa958luU+IlSYU2K+MxVDiSCxh0JJNHdKnu/L2IjEP37cBbqR3YfmeJ/E27+yQdd3PuL+7twUqCEewwhsocfqxmkKHF9pvDzCP9+Err26DMQct4kSFBk/2uZeBK3rqIQRvi9kJjmqjL1HcXtj7DcRVi3iR8s8pxB3F7g7yuAfzCRLEYzbrmfEA0kSkTlYmpvgCyyzyA+X/5c+Vlwb/JosisnJiKQRH5nFLIPWQVHkoxoIIleS9RymEQQhKnHNJlMrBAzLjFrVlD0kZWwWomqaiKpbJ6f47kvfREAcHZ6in/z3e/i5s2b0FjSpC/yy3RNZ/iei9dvvY7WRQvlThkHBwcCP+WLQpXwel/owXghOpo8JBh/jCqRw1NdKBJPEyiLMsEmYZ/puFv0JSox3x/b5FaU2AJEmbIAw39W57wThPsbkeAXvse44Ehi+0bRPouiTF6fHJwmqoqYXtjk4ROfBIQDoDrxDqJrY+qmiQlo8gMg0oEc/Tn5e+LWmszVn7dpZXFRGbaKBve4qjPai5HfS3Q2QF6u0c+X72n6ORuBDv1wRct7E3GHWbjiCQfIuPenMG9y0ViOgb8nJT7it2a08p6XbEzvwZIpKhoxUGtMv3VaHhwtIKN7MLrvMCXxC9bk1fseV61OJs5HFkC5jcbBx/toLC3hzV+9iSee/Dwef+IJcQ0L9Ug834OhGDB0A83mOYhP8O6776JYLAoanc68lIPySC7NeBZ4tZtbrIGEqQfyvKol7qCctmjnvsBFQMoF723av8sHzvQMZTLCTPzMtFW+4MKMY5JMYzdFM9KFIc3PYK3MInhMq6zioMqJntOcBGba58xj4Cx6H7PW+TyP7blsnpi1ocxYSyJoRGCzeYf69CpemfmsJ37vgntu1j6VA9002PNKvyOaOcY8h1lV41VYrVf9insPcr8reg2O48L3PWSzORyfnOD27dvI5XM4PTkJMRXnBhLP9UQzSmfa+IPBAIQ5kfmSlLim2bEZa5zH8MKHwrQXRmZ8/pxscuHFMOdgmPkyldkLcZoU/3z6AfnHOZDJ1RbovE3wWTBJZn7u1HUx+/mE+03TU955Ve9UPBSf7jnOyvpnJXvz3smsdRvXf4o7ZEMueVJvJVQRRfqOcT1BQuIRidAenZgjCydBBPP7rLOhwtlH0iLL+SoJzCc6fz6jr+nJA5mARnkywGFZXmk+3NsT7/1w/yA0TwJgfiBRVUVM0zpjByObusxxlU+P8f7jSve5p9bCL0fCTcniWefcg3uBw2haICFz4AIFyqc+eOdthGnQyEIZ1RWzVeWKldW8+1ukypuVmc46hK8SnBYhTpAYT+xFK4RZVeXMHsACAeEqVc0iAWVetST/R2JYgEpMryiugpHFW+PW6byKhMwJJvNgwk8b6Kd9/qykNu7+5iUSE/+24Jqaua9mBHNZCYOTRILKhI5U2LaNdCollM2TySSda5obSDQNKtNeskc21jc20O/30b64oHMAui54ziFK4Ez4ZTb+f5Vo/UlKvNhDncyWHYjGl6DfM7samX0Qzv9hZZa8/hVgqIVqHXLV54hPFLwIFqODK8r8z5sKnSywoacGgimUykWuZ97vnnYt4UPuaslqXL9sEWRnVuCaHtQDCEglWgxcM/35kLlUVWXiWccH+vmJwywY8bPqKyyaCMQ9w6vCWdHe7EQ1NydZjAbd6LOMe+4KPCF7bxgm1dZSVeTyeXiej36vLwLJBGsrrolFtXVos/3+7q74RVyjfiIikrj5DTITh519niqzT+y4z5t3MkVfZCy0o8yGLCYOr88gY1c+GdZ7laz000BbV4aaroJVT7uHBQNxPAObLLAGIt9GyCe+pkUh3MVvYLFkalHIbtGqZmZ1GHlgod+/4Jrl0j+LPNuJ6yGfDN5dJIDMgxanEXcWhlMj93clWJtcMSuf8r3z0BWZlKMzCRhdp0OwDjPRS6dTwnY6NpDIvH9Flh2Qbphr20zz9FVib5BcbcNcJZB8JkDiJ/j8T9Lsu9J9/xN+Efz267df/7Rfym8fwaffov+4G9d1XDiuA03ThSRMXPD8/+K2z6KAleN1AAAAAElFTkSuQmCC
								</image>

              <para>
                The three parts of the new format manual are designed to complement each other and provide agencies with the necessary information to conduct informed risk-based decisions based on their own business requirements, specific circumstances and risk appetite.
              </para>
              <para>
                The executive companion is targeted towards the most senior executives in each agency, such as Deputy Secretaries, Secretaries and Chief Executive Officers, and comprises broader strategic messaging about key information security issues.
              </para>
              <para>
                The principles document is aimed at Security Executives, Chief Information Security Officers, Chief Information Officers and senior decision makers across government and focuses on providing them with a better understanding of the cyber threat environment and rationale to assist them in developing informed information security policies within their agencies.
              </para>
              <para>
                The controls manual is aimed at Information Technology Security Advisors, Information Technology Security Managers, infosec-registered assessors and security practitioners across government. This manual provides a set of detailed controls which, when implemented, will help agencies adhere to the higher level principles document.
              </para>
              <para>
                DSD provides further information security advice in the form of device specific guides, Australian Communications Security Instructions (ACSIs) and ‘Protect’ products – such as the Top 35 Strategies to Mitigate Targeted Cyber Intrusions. While these products reflect the policy specified in this manual, not all requirements in this manual can be implemented on all devices or in all environments. In these cases, device specific advice may take precedence over the non-platform specific advice in this manual.
              </para>
            </content>
          </block>
          <block>
            <title>Framework</title>
            <content>
              <list>
                <head>This manual uses a framework to present information in a consistent manner. The framework consists of a number of headings in each section:</head>
                <item>
                  Objective—the desired outcome of complying with the controls specified in the section, expressed as if the outcome has already been achieved
                </item>
                <item>
                  Scope and Context—the scope and applicability of the section. It can also include definitions, legislative context and background information
                </item>
                <item>
                  Controls—procedures with associated compliance requirements for reducing the level of security risks
                </item>
                <item>
                  References—external sources of information that can assist in interpreting or implementing controls.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>System applicability</title>
            <content>
              <list>
                <head>Each control in this manual has an applicability indicator that indicates the information and systems to which the control applies. The applicability indicator has up to five elements, indicating whether the control applies to:</head>
                <item>
                  G: Government systems containing unclassified but sensitive information not intended for public release, such as Dissemination Limiting Marker information; note 'Government' is not a security classification under the Australian Government Security Classification System
                </item>
                <item>
                  P: PROTECTED information and systems
                </item>
                <item>
                  C: CONFIDENTIAL information and systems
                </item>
                <item>
                  S: SECRET information and systems
                </item>
                <item>
                  TS: TOP SECRET information and systems.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>Public systems</title>
            <content>
              <para>
                Agencies deploying public systems can determine their own security measures based on their risk appetite and security risks to their systems. However, DSD encourages such agencies to use this manual, particularly the objectives, as a guide when determining security measures for their systems.
              </para>
            </content>
          </block>
          <block>
            <title>Applicability of controls</title>
            <content>
              <para>
                While this manual provides controls for various technologies, not all systems will use all of the technologies mentioned. When agencies develop systems they will need to determine the appropriate scope of the systems and which controls in this manual are applicable.
              </para>
            </content>
          </block>
          <block>
            <title>Authority to approve non-compliance</title>
            <content>
              <list>
                <head>Each control specifies the authority that must provide approval for non-compliance with the control. The authority indicator indicates one of the three authorities:</head>
                <item>
                  DSD: Director DSD
                </item>
                <item>
                  AH: agency head
                </item>
                <item>
                  AA: accreditation authority.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>Compliance language</title>
            <content>
              <para>
                There are two categories of compliance associated with the controls in this manual – ‘must’ and ‘should’. These compliance requirements are determined according to the degree of security risk an agency will be accepting by not implementing the associated control. While the majority of controls can be risk managed within an agency, the compliance requirements provide an indication of the appropriate level within the agency where any residual security risks must be accepted in order to grant non-compliance. The full implications need to be considered before granting non-compliance with a control.
              </para>
            </content>
          </block>
          <block>
            <title>Non-compliance with multiple controls</title>
            <content>
              <para>
                When an agency is non-compliant with multiple controls, they may choose to logically group the areas of non-compliance when following the processes for non-compliance.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Granting non-compliance</title>
            <content>
              <para>
                Non-compliance with ‘must’ and ‘must not’ controls are likely to represent a high security risk to information and systems. Therefore, the agency head, in association with the accreditation authority, is required to consider the justification for non-compliance and accept the associated residual security risk. Non-compliance with controls relating to High Grade Cryptographic Equipment must be granted by the Director DSD. These controls are marked accordingly in this manual.
              </para>
              <para>
                Non-compliance with ‘should’ and ‘should not’ controls are likely to represent a medium-to-low security risk to information and systems. As the risk for non-compliance is not as high as those with a ‘must’ and ‘must not’ compliance requirement, the accreditation authority can consider the justification for non-compliance and accept the associated residual security risk without the input of the agency head.
              </para>
            </content>
            <controls>
              <block>
                <ID>0001</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Granting non-compliance</title>
                <content>
                  <para>
                    System owners seeking approval for non-compliance with any control with a ‘must’ or ‘must not’ compliance requirement must be granted non-compliance from their accreditation authority and their agency head and, if the authority field on a control is 'DSD', the Director DSD. 
                  </para>
                </content>
              </block>
              <block>
                <ID>1061</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Granting non-compliance</title>
                <content>
                  <para>
                    System owners seeking approval for non-compliance with any control with a ‘should’ or ‘should not’ compliance requirement must be granted non-compliance from their accreditation authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Justification for non-compliance</title>
            <content>
              <para>
                Without sufficient justification, and consideration of the security risks, the agency head or their authorised delegate will lack the appropriate information to make an informed decision on whether to accept the residual security risk and grant non-compliance to the system owner.
              </para>
            </content>
            <controls>
              <block>
                <ID>0710</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Justification for non-compliance</title>
                <content>
                  <list>
                    <head>System owners seeking approval for non-compliance with any control must document:</head>
                    <item>
                      the justification for non-compliance
                    </item>
                    <item>
                      the alternative mitigation measures to be implemented, if any
                    </item>
                    <item>
                      an assessment of the security risks.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Consultation on non-compliance</title>
            <content>

              <para>
                When an agency processes, stores or communicates information on their systems that belongs to another agency or foreign government they have an obligation to inform that third party when they desire to risk manage the controls specified in this manual. If the agency fails to do so, the third party will be unaware that their information has been placed at a heightened risk of compromise. The third party is thus denied the opportunity to consider additional security measures for their information.
              </para>
              <list>
                <head>The extent of consultation with other agencies and foreign governments may include:</head>
                <item>
                  a notification of the intent to be non-compliant
                </item>
                <item>
                  the justification for non-compliance
                </item>
                <item>
                  any mitigation measures that may have been implemented
                </item>
                <item>
                  an assessment of the security risks relating to the information they have been entrusted with.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0711</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Consultation on non-compliance</title>
                <content>
                  <para>
                    If a system processes, stores or communicates information from another agency, that agency must be consulted as part of granting non-compliance with any control.
                  </para>
                </content>
              </block>
              <block>
                <ID>0712</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Consultation on non-compliance</title>
                <content>
                  <para>
                    If a system processes, stores or communicates information from a foreign government, that government must be consulted as part of granting non-compliance with any control.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Notification of non-compliance</title>
            <content>
              <para>
                The purpose of notifying authorities of any decisions to grant non-compliance with controls is two-fold: firstly to ensure that an accurate picture of the state of information security across government can be maintained, and secondly as feedback to ensure the continuing refinement of this manual.
              </para>
            </content>
            <controls>
              <block>
                <ID>0713</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Notification of non-compliance</title>
                <content>
                  <para>
                    Agencies must notify the Cyber Security Operations Centre at DSD when granting non-compliance with any control.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Reviewing non-compliance</title>
            <content>
              <para>
                When seeking approval for non-compliance, the system owner must provide a justification for non-compliance, outline any alternative mitigation measures to be implemented and conduct an assessment of the security risks. As the justification for non-compliance may change, and the risk environment will continue to evolve over time, it is important that the system owner update their approval for non-compliance at least every two years. In doing so it should be resubmitted to the appropriate authority for review and have any decision to grant non-compliance either reaffirmed or, if necessary, rejected if the justification or residual security risk is no longer acceptable.
              </para>
            </content>
            <controls>
              <block>
                <ID>0876</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Reviewing non-compliance</title>
                <content>
                  <para>
                    Agencies should review decisions to grant non-compliance with any control, including the justification, any mitigation measures and security risks, at least every two years or when significant changes occur to ensure its continuing relevance, adequacy and effectiveness.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Recording non-compliance</title>
            <content>
              <para>
                Without appropriate records of decisions to grant non-compliance with controls, agencies have no record of the status of their security posture. Furthermore, a lack of such records will hinder any auditing activities that may be conducted by the agency or by external parties such as the Australian National Audit Office (ANAO). Failing to maintain such records is also a breach of the Archives Act 1983 (the Archives Act).
              </para>
            </content>
            <controls>
              <block>
                <ID>0003</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Recording non-compliance</title>
                <content>
                  <para>
                    Agencies must retain a copy of decisions to grant non-compliance with any control from this manual.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                This manual is updated regularly. It is therefore important that agencies ensure that they are using the latest baseline comprising the latest release, errata and interim policy releases. This manual, additional information, tools and discussion topics can be accessed from the OnSecure website at https://members.onsecure.gov.au/.
              </para>
              <para>
                Supplementary information to this manual can be found in the following documents.
              </para>
              <table>
                <header>
									<cell>Topic</cell>
									<cell>Documentation</cell>
									<cell>Author</cell>
								</header>
																
								<row>
									<cell rowspan="4">Archiving of information</cell>
								</row>
								<row>
									<cell>The Archives Act 1983</cell>
									<cell>National Archives of Australia (NAA)</cell>
								</row>
								<row>
									<cell>
										<para>Administrative Functions Disposal Authority – Revised 2010</para>
									</cell>
									<cell>NAA</cell>
								</row>
								<row>
									<cell>
										<para>General Disposal Authority for Encrypted Records Created in Online Security Processes</para>
									</cell>
									<cell>NAA</cell>
								</row>
								<row>
									<cell rowspan="3">Business continuity</cell>
									<cell>
										<para>HB 221:2004, Business Continuity Management</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>HB 292-2006, A practitioners guide to business continuity management</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>HB 293-2006, Executive guide to business continuity management</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
                <cell>Cabinet information</cell>
									<cell>
										<para>Cabinet Handbook, Security and Handling of Cabinet Documents</para>
									</cell>
									<cell>Department of Prime Minister and Cabinet</cell>
								</row>
								<row>
									<cell>Cable security</cell>
									<cell>
										<para>ACSI 61, Guidelines for the Installation of Communications and Information Processing Equipment and Systems</para>
									</cell>
									<cell>DSD</cell>
								</row>
								<row>
									<cell>Communications security roles and responsibilities</cell>
									<cell>
										<para>ACSI 53, Communications Security Handbook</para>
									</cell>
									<cell>DSD</cell>
								</row>
								<row>
									<cell>Communications security incident reporting</cell>
									<cell>
										<para>ACSI 107, Reporting and Evaluating Communications Security Incidents</para>
									</cell>
									<cell>DSD</cell>
								</row>
								<row>
									<cell>Emanation security</cell>
									<cell>
										<para>ACSI 71, A guide to the Assessment of Electromagnetic Security in Military and High-risk Environments</para>
									</cell>
									<cell>DSD</cell>
								</row>
								<row>
									<cell rowspan="4">Information and records management for information and communications technology systems</cell>
									<cell>
										<para>Australian Government Recordkeeping Metadata Standard V2.0 </para>
									</cell>
									<cell>NAA</cell>
								</row>
								<row>
									<cell>
										<para>ISO 16175-1:2010, Principles and functional requirements for records in electronic office environments – Part 1: Overview and statement of principles </para>
									</cell>
									<cell>International Organization for Standardization (ISO)</cell>
								</row>
								<row>
									<cell>
										<para>ISO 16175-2:2011, Principles and functional requirements for records in electronic office environments – Part 2:Guidelines and functional requirements for digital records management systems</para>
									</cell>
									<cell>ISO</cell>
								</row>
								<row>
									<cell>
										<para>ISO 16175-3:2010, Principles and functional requirements for records in electronic office environments – Part 3:Guidelines and functional requirements for records in business systems</para>
									</cell>
									<cell>ISO</cell>
								</row>
								<row>
									<cell rowspan="6">Information security management</cell>
									<cell>
										<para>Australian Government Information Security Management Protocol</para>
									</cell>
									<cell>Attorney-General’s Department (AGD)</cell>
								</row>
								<row>
									<cell>
										<para>ISO/IEC 27000:2009, Information technology – Security techniques – Information security management systems – Overview and vocabulary</para>
									</cell>
									<cell>ISO / International Electrotechnical Commission (IEC)</cell>
								</row>
								<row>
									<cell>
										<para>AS/NZS ISO/IEC 27001:2006, Information technology – Security techniques – Information security management systems – Requirements</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>AS/NZS ISO/IEC 27002:2006, Information technology – Security techniques – Code of practice for information security management</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>ISO/IEC 27003:2010, Information technology – Security techniques – Information security management systems implementation guidance</para>
									</cell>
									<cell>ISO/IEC</cell>
								</row>
								<row>
									<cell>ISO/IEC 27004:2009, Information technology – Security techniques – Information security management – Measurement</cell>
									<cell>ISO/IEC</cell>
								</row>
								<row>
									<cell>Key management – commercial grade</cell>
									<cell>
										<para>AS 11770.1-2003, Information technology – Security techniques – Key management – Framework</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
                <cell>Key management – high grade</cell>
									<cell>
										<para>ACSI 105, Cryptographic Controlling Authorities and Keying Material Management</para>
									</cell>
									<cell>DSD</cell>
								</row>
								<row>
									<cell>Management of electronic records that may be used as evidence</cell>
									<cell>
										<para>HB 171-2003, Guidelines for the management of IT evidence</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>Personnel security</cell>
									<cell>
										<para>Australian Government Personnel Security Management Protocol</para>
									</cell>
									<cell>AGD</cell>
								</row>
								<row>
									<cell>Physical security</cell>
									<cell>
										<para>Australian Government Physical Security Management Protocol</para>
									</cell>
									<cell>AGD</cell>
								</row>
								<row>
									<cell>Privacy requirements</cell>
									<cell>
										<para>The Privacy Act 1988</para>
									</cell>
									<cell>AGD</cell>
								</row>
								<row>
									<cell>Protective security</cell>
									<cell>
										<para>Australian Government Protective Security Policy Framework</para>
									</cell>
									<cell>AGD</cell>
								</row>
								<row>
									<cell rowspan="7">Risk management</cell>
									<cell>
										<para>AS/NZS ISO 31000:2009, Risk Management – Principles and guidelines</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>HB 327:2010, Communicating and consulting about risk (Companion to AS/NZS ISO 31000:2009)</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>ISO/IEC Guide 73, Risk Management – Vocabulary – Guidelines for use in Standards</para>
									</cell>
									<cell>ISO/IEC</cell>
								</row>
								<row>
									<cell>
										<para>ISO/IEC 27005:2008, Information technology – Security techniques – Information security risk management</para>
									</cell>
									<cell>ISO/IEC</cell>
								</row>
								<row>
									<cell>
										<para>HB 167:2006, Security risk management</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>HB 231:2004, Information security risk management guidelines</para>
									</cell>
									<cell>Standards Australia</cell>
								</row>
								<row>
									<cell>
										<para>NIST SP 800-30, Risk Management Guide for Information Technology Systems</para>
									</cell>
									<cell>National Institute of Standards and Technology (NIST)</cell>
								</row>
              </table>

            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Applicability, Authority and Compliance</title>
        <objective>
          <block>
            <content>
              <para>
                Requirements in the ISM are complied with.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This manual is the primary policy produced by DSD relating to information security. Its role is to promote a consistent risk-based approach to information security across all Australian federal, state and territory agencies and bodies for the protection of information and systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Applicability</title>
            <content>
              <list>
                <head>This manual applies to:</head>
                <item>
                  Australian government agencies that are subject to the Financial Management and Accountability Act 1997
                </item>
                <item>
                  bodies that are subject to the Commonwealth Authorities and Companies Act 1997 and that have received notice in accordance with that Act that the ISM applies to them as a general policy of the government
                </item>
                <item>
                  other bodies established for a public purpose under the law of the Commonwealth and other Australian government agencies, where the body or agency has received a notice from their Portfolio Minister that the ISM applies to them
                </item>
                <item>
                  state and territory agencies that hold or access federal sensitive or classified information
                </item>
                <item>
                  organisations that have entered a Deed of Agreement with the government to have access to sensitive or classified information.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>Authority</title>
            <content>
              <list>
                <head>The Intelligence Services Act 2001 (the ISA) states that two functions of DSD are:</head>
                <item>to provide material, advice and other assistance to Commonwealth and State authorities on matters relating to the security and integrity of information that is processed, stored or communicated by electronic or similar means</item>
                <item>to provide assistance to Commonwealth and State authorities in relation to cryptography, and communication and computer technologies.</item>
              </list>
              <para>
                This manual represents the considered advice of DSD provided in accordance with its designated functions under the ISA. Therefore agencies are not required as a matter of law to comply with this manual, unless legislation, or a direction given under legislation or by some other lawful authority, compels them to comply with it.
              </para>
            </content>
          </block>
          <block>
            <title>Compliance by smaller agencies</title>
            <content>
              <para>
                As smaller agencies may not always have sufficient personnel or budgets to comply with this manual, they may choose to consolidate their resources with another larger host agency to undertake a joint approach to compliance.
              </para>
              <para>
                In such circumstances, smaller agencies may choose to either operate on systems fully hosted by another agency using their information security policies and security resources, or share security resources to jointly develop information security policies and systems for use by both agencies. In these cases, the requirements in this manual can be interpreted as either relating to the host agency or to both agencies, depending on the approach taken.
              </para>
              <para>
                In situations where agencies choose a joint approach to compliance, especially when an agency agrees to fully host another agency, the agency heads may choose to seek a memorandum of understanding regarding their security responsibilities.
              </para>
            </content>
          </block>
          <block>
            <title>Legislation and legal considerations</title>
            <content>
              <para>
                This manual does not override any obligations imposed by legislation or law. Furthermore, if this manual conflicts with legislation or law the later takes precedence.
              </para>
              <para>
                While this manual contains examples of when legislation or laws may be relevant for agencies, there is no comprehensive consideration of such issues. Accordingly, agencies should rely on their own inquiries in that regard.
              </para>
            </content>
          </block>
          <block>
            <title>Auditing of compliance by the Australian National Audit Office</title>
            <content>
              <para>All controls in this manual are capable of being audited for compliance by the ANAO.</para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Compliance</title>
            <content>
              <para>
                By using the latest baseline of this manual for system design activities, agencies will be taking steps to protect themselves from the current threats to Australian government systems.
              </para>
              <para>
                DSD produces information security policies in addition to this manual, such as the ACSI suite. These policies may be updated to address specific security risks to government information and systems. In such cases, specific timeframes for compliance may be specified.
              </para>
            </content>
            <controls>
              <block>
                <ID>0007</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Compliance</title>
                <content>
                  <para>
                    Agencies undertaking system design activities for in-house or out-sourced projects must use the latest baseline of this manual for security requirements.
                  </para>
                </content>
              </block>
              <block>
                <ID>0008</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Compliance</title>
                <content>
                  <para>
                    Agencies must comply with any specified compliance timeframes for information security policies that DSD determines are of particular importance.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
  </part>
  <part>
    <title>Information Security Governance</title>
    <chapter>
      <title>Information Security Engagement</title>
      <section>
        <title>Government Engagement</title>
        <objective>
          <block>
            <content>
              <para>
                Security personnel are aware of and use security services offered in the Australian Government.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the agencies and bodies involved in providing information security advice.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Defence Signals Directorate</title>
            <content>
              <para>
                The Defence Signals Directorate (DSD) is required under the Intelligence Services Act 2001 (the ISA) to perform various functions, including the provision of material, advice and other assistance to Commonwealth and State authorities on matters relating to the security of information that is processed, stored or communicated by electronic or similar means.
              </para>
              <para>
                DSD provides assistance to Commonwealth and State authorities in relation to cryptography, communications and computer technologies.
              </para>
              <para>
                DSD works with industry to develop new cryptographic products. It has established the Australian Information Security Evaluation Program in order to deal with the increasing requirement to evaluate products with security functionality.
              </para>
              <para>
                DSD can be contacted for advice and assistance in implementing this manual through any of an agency’s Information Technology Security Managers (ITSMs) or it’s Information Technology Security Advisor (ITSA). ITSMs and ITSAs can send questions to DSD by email at assist@dsd.gov.au or phone on 1300 CYBER1 (1300 292 371).
              </para>
              <para>
                DSD can be contacted for advice and assistance on cyber security incidents. DSD’s response will be commensurate with the urgency of the cyber security incident. There is a 24-hour, seven day a week service available if necessary. The Cyber Security Operations Centre can be contacted by email at assist@dsd.gov.au or phone on 1300 CYBER1 (1300 292 371).
              </para>
              <para>
                DSD can be contacted for advice and assistance on the purchasing, provision, deployment, operation and disposal of High Grade Cryptographic Equipment. The Crypto Liaison section can also be contacted by email at assist@dsd.gov.au.
              </para>
            </content>
          </block>
          <block>
            <title>Other government agencies and bodies</title>
            <content>

              <para>
                The table below contains a brief description of the other government agencies and bodies that have a role in information security in government.
              </para>
              <table>
                
                  <header>
                      <cell>Agency or body</cell>
                      <cell>Services</cell>
                  </header>

                    <row>
                      <cell>Attorney-General’s Department</cell>
                      <cell>Responsible for information security policy and cyber security incident preparation, preparedness, response and recovery arrangements across government.</cell>
                    </row>
                    <row>
                      <cell>Attorney-General’s Department – Protective Security Training Centre</cell>
                      <cell>Protective security training</cell>
                    </row>
                    <row>
                      <cell>Australasian Information Security Evaluation Program</cell>
                      <cell>Scheme implemented by Australia and New Zealand to evaluate products with security functionality</cell>
                    </row>
                    <row>
                      <cell>Australian Federal Police – Australian High Tech Crime Centre</cell>
                      <cell>Law enforcement in relation to electronic and other high tech crimes</cell>
                    </row>
                    <row>
                      <cell>Australian Government Information Management Office</cell>
                      <cell>Development, coordination and oversight of policy on electronic commerce, online services and the Internet</cell>
                    </row>
                    <row>
                      <cell>Australian National Audit Office</cell>
                      <cell>Performance audits on information security</cell>
                    </row>
                    <row>
                      <cell>Australian Security Intelligence Organisation – T4 Protective Security</cell>
                      <cell>Protective security advice and training, technical surveillance counter-measures, physical security certifications, protective security risk reviews and physical security equipment testing</cell>
                    </row>
                    <row>
                      <cell>Computer Emergency Response Team Australia</cell>
                      <cell>Provides the private sector with information and assistance to help them protect their Information and Communications Technology (ICT) infrastructure from cyber threats and vulnerabilities; coordination role during a serious cyber incident</cell>
                    </row>
                    <row>
                      <cell>Cyber Security Policy and Coordination Committee</cell>
                      <cell>Coordinates the development of cyber security policy for the Australian Government</cell>
                    </row>
                    <row>
                      <cell>Department of Foreign Affairs and Trade</cell>
                      <cell>Policy and advice for security overseas</cell>
                    </row>
                    <row>
                      <cell>Department of the Prime Minister and Cabinet</cell>
                      <cell>Coordination of cyber and information security policy and initiatives across government</cell>
                    </row>
                    <row>
                      <cell>National Archives of Australia</cell>
                      <cell>Provides standards and advice on capturing and managing records to ensure their integrity as evidence is maintained; authorises the disposal of all Commonwealth records, including those relating to ICT and security processes and incidents</cell>
                    </row>
                    <row>
                      <cell>Protective Security Policy Committee</cell>
                      <cell>Coordinates the development of protective security policy</cell>
                    </row>
                    <row>
                      <cell>Security Construction and Equipment Committee</cell>
                      <cell>Oversees the evaluation of security equipment</cell>
                    </row>


              </table>

            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Organisations providing information security services</title>
            <content>
              <para>
                If security personnel are unaware of the roles government organisations play in the information security space, they could miss out on valuable insight and assistance in developing effective security measures.
              </para>
            </content>
            <controls>
              <block>
                <ID>0879</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Organisations providing information security services</title>
                <content>
                  <para>
                    Security personnel should familiarise themselves with the information security roles and services provided by Australian Government agencies and bodies.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <list>
                <head>The following websites can be used to obtain additional information about agencies and bodies involved in the security of government information and systems:</head>
                <item>
                  http://www.dsd.gov.au/
                </item>
                <item>
                  http://www.ag.gov.au/pspf
                </item>
                <item>
                  http://www.ag.gov.au/cybersecurity
                </item>
                <item>
                  http://www.ag.gov.au/identitysecurity
                </item>
                <item>
                  http://www.ag.gov.au/www/agd/agd.nsf/Page/Security_training
                </item>
                <item>
                  http://www.dsd.gov.au/infosec/aisep.htm
                </item>
                <item>
                  http://www.afp.gov.au/
                </item>
                <item>
                  http://www.finance.gov.au/agimo/index.html
                </item>
                <item>
                  http://www.anao.gov.au/
                </item>
                <item>
                  http://www.asio.gov.au/
                </item>
                <item>
                  http://www.cert.gov.au/
                </item>
                <item>
                  http://www.dfat.gov.au/
                </item>
                <item>
                  http://www.pmc.gov.au/
                </item>
                <item>
                  http://www.naa.gov.au/records-management/index.aspx
                </item>
                <item>
                  http://www.scec.gov.au/.
                </item>
              </list>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Industry Engagement and Outsourcing</title>
        <objective>
          <block>
            <content>
              <para>
                Industry partners handle information appropriately and implement the same security measures as their sponsoring agency.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes information on outsourcing information technology services and functions to industry as well as providing them with access to information in order to undertake their duties.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Cloud computing</title>
            <content>

              <para>
                Cloud computing is a form of outsourcing information technology services and functions over the Internet. The requirements in this section equally apply to providers of cloud computing services.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Accrediting service providers’ systems</title>
            <content>
              <para>
                Service providers can be provided with information as long as their systems are accredited to process, store and communicate the information. This ensures that when they are provided with information that it receives an appropriate level of protection.
              </para>
            </content>
            <controls>
              <block>
                <ID>0872</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accrediting service providers’ systems</title>
                <content>
                  <para>
                    Systems used by service providers for the provision of information technology services and functions must be accredited to the same minimum standard as the sponsoring agency’s systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Service providers’ systems</title>
            <content>
              <para>
                While this manual recommends against the outsourcing of information technology services and functions outside of Australia it does not preclude the use of services of foreign owned service providers in Australia. When such service providers are engaged agencies are strongly encouraged to ensure that all information provided to the service provider is hosted in Australia and does not leave Australian borders.
              </para>
            </content>
            <controls>
              <block>
                <ID>0873</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Service providers’ systems</title>
                <content>
                  <para>
                    Service providers’ systems should be located in Australia.
                  </para>
                </content>
              </block>
              <block>
                <ID>1073</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Service providers’ systems</title>
                <content>
                  <para>
                    Service providers should not allow information to leave Australian borders unless approved by the sponsoring agency.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Service providers’ Information Technology Security Manager</title>
            <content>
              <para>
                When an agency engages a service provider for the provision of information technology services and functions, having a central point of contact for information security issues will greatly assist incident response and reporting procedures.
              </para>
            </content>
            <controls>
              <block>
                <ID>0744</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Service providers’ Information Technology Security Manager</title>
                <content>
                  <para>
                    Service providers should provide a single point of contact who will act as an equivalent to an ITSM.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Developing an industry security program</title>
            <content>
              <para>
                The development of an industry security program will assist the agency in undertaking a coordinated approach to the engagement and use of service providers for outsourcing and provision of information technology services and functions.
              </para>
            </content>
            <controls>
              <block>
                <ID>1052</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Developing an industry security program</title>
                <content>
                  <para>
                    Agencies should develop an industry security program to manage service providers that have been approved for the provision of information technology services and functions.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Additional information regarding cloud computing security considerations can be found in the Cloud Computing Security Considerations document on the DSD website at http://www.dsd.gov.au/infosec/cloudsecurity.htm.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Roles and Responsibilities</title>
      <section>
        <title>The Chief Information Security Officer</title>
        <objective>
          <block>
            <content>
              <para>
                The Chief Information Security Officer (CISO) sets the strategic direction for information security.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the information security role of a CISO.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>The Security Executive and their Chief Information Security Officer role</title>
            <content>
              <para>
                The requirement to appoint a member of the Senior Executive Service, or in an equivalent management position, to the role of CISO does not require a new dedicated position to be created in each agency. This role is intended to be performed by the Security Executive, which is a position in each agency mandated by the Australian Government Protective Security Policy Framework. The introduction of the CISO role is aimed at providing a more meaningful title for a subset of the Security Executive’s responsibilities that relate to information security.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Requirement for a Chief Information Security Officer</title>
            <content>
              <list>
                <head>The role of the CISO is based on industry best practice and has been introduced to ensure that information security is managed at the senior executive level. The CISO is typically responsible for:</head>
                <item>
                  facilitating communications between security personnel, Information and Communications Technology (ICT) personnel and business personnel to ensure alignment of business and security objectives
                </item>
                <item>
                  providing strategic-level guidance for the agency security program
                </item>
                <item>
                  ensuring compliance with national policy, standards, regulations and legislation.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0714</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Requirement for a Chief Information Security Officer</title>
                <content>
                  <para>
                    Agencies must appoint a senior executive, commonly referred to as the CISO, who is responsible for coordinating communication between security and business functions as well as overseeing the application of controls and security risk management processes.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>The Information Technology Security Advisor</title>
        <objective>
          <block>
            <content>
              <para>
                The Information Technology Security Advisor (ITSA) coordinates information technology security.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the information security role of an Information Technology Security Manager (ITSM) when designated as the ITSA. Information on the responsibilities of ITSMs can be found in the Information Technology Security Managers section of this chapter.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>The Information Technology Security Advisor</title>
            <content>
              <para>
                The ITSM who has responsibility for information technology security management across the agency is designated as the ITSA. This title reflects the responsibility this ITSM has as the first point of contact for the CISO and external agencies on any information technology security management issues.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Requirement for an Information Technology Security Advisor</title>
            <content>
              <para>
                An ITSM, when fulfilling the designation of ITSA, still maintains full responsibilities for their role as an ITSM in addition to ITSA responsibilities. An ITSA traditionally has the added responsibility of coordinating other ITSMs to ensure that security measures and efforts are undertaken in a coordinated manner.
              </para>
            </content>
            <controls>
              <block>
                <ID>0013</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Requirement for an Information Technology Security Advisor</title>
                <content>
                  <para>
                    Agencies must designate an ITSM as the ITSA, to have responsibility for information technology security management across the agency.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Contacting Information Technology Security Advisors</title>
            <content>
              <para>
                As security personnel in agencies often need to communicate with security personnel from other agencies, often to provide warnings of threats to their systems, it is important that a consistent contact method is available across government to facilitate such communication.
              </para>
            </content>
            <controls>
              <block>
                <ID>0025</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Contacting Information Technology Security Advisors</title>
                <content>
                  <para>
                    Agencies should maintain an email address for their ITSA in the form of ITSA@agency
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Information Technology Security Managers</title>
        <objective>
          <block>
            <content>
              <para>
                ITSMs provide information security leadership and management.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the information security role of ITSMs.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Information Technology Security Managers</title>
            <content>
              <para>
                ITSMs are executives that coordinate the strategic directions provided by the CISO and the technical efforts of Information Technology Security Officers (ITSOs). The main area of responsibility of an ITSM is that of the day-to-day management of information security within an agency.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Requirement for Information Technology Security Managers</title>
            <content>
              <list>
                <head>ITSMs are generally considered information security experts and are typically responsible for:</head>
                <item>
                  managing the implementation of security measures
                </item>
                <item>
                  monitoring information security for systems and responding to any cyber security incidents
                </item>
                <item>
                  identifying and incorporating appropriate security measures in the development of ICT projects and the information security program
                </item>
                <item>
                  establishing contracts and service-level agreements on behalf of the CISO
                </item>
                <item>
                  assisting the CISO to develop security budget projections and resource allocations
                </item>
                <item>
                  providing regular reports on cyber security incidents and other areas of particular concern to the CISO
                </item>
                <item>
                  helping system owners to understand and respond to reported audit failures
                </item>
                <item>
                  guiding the selection of appropriate strategies to achieve the direction set by the CISO with respect to disaster recovery policies and standards
                </item>
                <item>
                  delivering information security awareness and training programs to personnel.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0741</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Requirement for Information Technology Security Managers</title>
                <content>
                  <para>
                    Agencies must appoint at least one executive, commonly referred to as an ITSM, to manage the day-to-day operations of information security within the agency, in line with the strategic directions provided by the CISO.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Information Technology Security Officers</title>
        <objective>
          <block>
            <content>
              <para>
                ITSOs provide information security operational support.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes information security role of ITSOs.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Information Technology Security Officers</title>
            <content>
              <para>
                ITSOs implement technical solutions under the guidance of an ITSM to ensure that the strategic direction for information security within the agency set by the CISO is achieved.
              </para>
            </content>
          </block>
          <block>
            <title>Appointing Information Technology Security Officers</title>
            <content>
              <para>
                The ITSO role may be combined with that of the ITSM. Small agencies may choose to assign both ITSM and ITSO responsibilities to one person under the title of the ITSA. Furthermore, agencies may choose to have this role performed by existing system administrators with an additional reporting chain to an ITSM for the security aspects of their role.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Requirement for Information Technology Security Officers</title>
            <content>
              <list>
                <head>Appointing a person whose responsibility is to ensure the technical security of systems is essential to comply with the controls in this manual. The main responsibility of ITSOs is the implementation and monitoring of technical security measures for systems. Other responsibilities often include:</head>
                <item>
                  conducting vulnerability assessments and taking actions to mitigate threats and remediate vulnerabilities
                </item>
                <item>
                  working with ITSMs to respond to cyber security incidents
                </item>
                <item>
                  assisting ITSMs with technical remediation activities required as a result of audits
                </item>
                <item>
                  assisting in the selection of security measures to achieve the strategies selected by ITSMs with respect to disaster recovery
                </item>
                <item>
                  raising awareness of information security issues with system owners and personnel.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0768</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Requirement for Information Technology Security Officers</title>
                <content>
                  <para>
                    Agencies must appoint at least one expert, commonly referred to as an ITSO, in administering and configuring a broad range of systems as well as analysing and reporting on information security issues.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Nil.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>System Owners</title>
        <objective>
          <block>
            <content>
              <para>
                System owners obtain and maintain accreditation of their systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the information security role of system owners.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                The system owner is the person responsible for an information resource.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Requirement for system owners</title>
            <content>
              <para>
                While the system owner is responsible for the operation of the system, they will delegate the day-to-day management and operation of the system to a system manager or managers.
              </para>
              <para>
                While it is strongly recommended that a system owner is a member of the Senior Executive Service, or in an equivalent management position, it does not imply that the system managers should also be at such a level.
              </para>
            </content>
            <controls>
              <block>
                <ID>1071</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Requirement for system owners</title>
                <content>
                  <para>
                    Each system must have a system owner who is responsible for the operation of the system.
                  </para>
                </content>
              </block>
              <block>
                <ID>1072</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Requirement for system owners</title>
                <content>
                  <para>
                    System owners should be a member of the Senior Executive Service or in an equivalent management position.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Accreditation responsibilities</title>
            <content>
              <para>
                The system owner is responsible for the secure operation of their system and needs to ensure it is accredited. If modifications are undertaken to a system the system owner will need to ensure that the changes are undertaken and documented in an appropriate manner, and that any necessary reaccreditation activities are completed.
              </para>
            </content>
            <controls>
              <block>
                <ID>0027</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accreditation responsibilities</title>
                <content>
                  <para>
                    System owners must obtain and maintain accreditation for their systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Information Security Documentation</title>
      <section>
        <title>Documentation Fundamentals</title>
        <objective>
          <block>
            <content>
              <para>
                Information security documentation is produced for systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the information security documentation that each agency needs to develop.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                The suite of documents outlined in this chapter forms the Information Security Management Framework, as mandated in the Australian Government Information Security Management Protocol.
              </para>
              <para>
                Documentation is vital to any information security regime as it supports the accurate and consistent application of policy and procedures within an agency. Documentation also provides increased accountability and a standard against which compliance can be measured.
              </para>
              <para>
                More detailed information about each document can be found in the relevant sections of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Information Security Policy</title>
            <content>
              <para>
                The Information Security Policy (ISP) is a statement of high-level information security policies and is therefore an essential part of information security documentation.
              </para>
            </content>
            <controls>
              <block>
                <ID>0039</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Information Security Policy</title>
                <content>
                  <para>
                    Agencies must have an ISP.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Security Risk Management Plan</title>
            <content>
              <para>
                The Security Risk Management Plan (SRMP) is a best practice approach to identifying and reducing potential security risks. Depending on the documentation framework chosen, multiple systems could refer to, or build upon, a single SRMP.
              </para>
            </content>
            <controls>
              <block>
                <ID>0040</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Security Risk Management Plan</title>
                <content>
                  <para>
                    Agencies must ensure that every system is covered by a SRMP.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System Security Plan</title>
            <content>
              <para>
                The System Security Plan (SSP) is derived from this manual and the SRMP and describes the implementation and operation of controls for a system. Depending on the documentation framework chosen, some details common to multiple systems could be consolidated in a higher level SSP.
              </para>
            </content>
            <controls>
              <block>
                <ID>0041</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System Security Plan</title>
                <content>
                  <para>
                    Agencies must ensure that every system is covered by a SSP.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Standard Operating Procedures</title>
            <content>
              <para>
                Standard Operating Procedures (SOPs) provide a step-by-step guide to undertaking security related tasks. They provide assurance that tasks can be undertaken in a repeatable manner, even by system users without strong knowledge of the system. Depending on the documentation framework chosen, some procedures common to multiple systems could be consolidated into a higher level SOP.
              </para>
            </content>
            <controls>
              <block>
                <ID>0042</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Standard Operating Procedures</title>
                <content>
                  <para>
                    Agencies should ensure that SOPs are developed for systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Incident Response Plan</title>
            <content>
              <para>
                Having an Incident Response Plan (IRP) ensures that when a cyber security incident occurs, a plan is in place to respond appropriately to the situation. In most situations, the aim of the response will be to preserve any evidence relating to the cyber security incident and to prevent the incident escalating.
              </para>
            </content>
            <controls>
              <block>
                <ID>0043</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Incident Response Plan</title>
                <content>
                  <para>
                    Agencies must develop an IRP and supporting procedures.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Developing content</title>
            <content>
              <para>
                It is likely that the most useful and accurate information security documentation will be developed by personnel who are knowledgeable about both information security issues and the business requirements.
              </para>
            </content>
            <controls>
              <block>
                <ID>0886</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Developing content</title>
                <content>
                  <para>
                    Agencies should ensure that information security documentation is developed by personnel with a good understanding of both the subject matter and the business requirements.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Documentation content</title>
            <content>
              <para>
                As the SRMP, SSP, SOPs and IRP form a documentation suite for a system, it is essential that they are logically connected and consistent. Furthermore, each documentation suite developed for a system will need to be consistent with the ISP.
              </para>
            </content>
            <controls>
              <block>
                <ID>0044</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Documentation content</title>
                <content>
                  <para>
                    Agencies should ensure that their SRMP, SSP, SOPs and IRP are logically connected and consistent for each system and with the ISP.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Using a documentation framework</title>
            <content>

              <para>
                Having a documentation framework for information security documents ensures that they are accounted for and maintained appropriately. Furthermore, the framework can be used to describe relationships between documents, especially when higher level documents are used to avoid repetition of information in lower level documents.
              </para>
            </content>
            <controls>
              <block>
                <ID>0787</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Using a documentation framework</title>
                <content>
                  <para>
                    Agencies should create and maintain a document framework including a hierarchical listing of all information security documentation and their relationships.
                  </para>
                </content>
              </block>
              <block>
                <ID>0885</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Using a documentation framework</title>
                <content>
                  <para>
                    Agencies should adopt the naming conventions provided in this manual for their information security documentation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Outsourcing development of content</title>
            <content>

              <para>
                Agencies outsourcing the development of information security documentation still need to review and control the contents to make sure it meets their requirements.
              </para>
            </content>
            <controls>
              <block>
                <ID>0046</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Outsourcing development of content</title>
                <content>
                  <list>
                    <head>When information security documentation development is outsourced, agencies should:</head>
                    <item>
                      review the documents for suitability
                    </item>
                    <item>
                      retain control over the content
                    </item>
                    <item>
                      ensure that all policy requirements are met.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Obtaining formal approval</title>
            <content>
              <para>
                If information security policy does not have formal approval, security personnel will have difficulty ensuring appropriate systems security procedures are in place. Having formal approval not only assists in the implementation of procedures, it also ensures senior managers are aware of information security issues and security risks.
              </para>
            </content>
            <controls>
              <block>
                <ID>0047</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Obtaining formal approval</title>
                <content>
                  <para>
                    All information security documentation should be formally approved by a person with an appropriate level of seniority and authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0887</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Obtaining formal approval</title>
                <content>
                  <list>
                    <head>Agencies should ensure that:</head>
                    <item>
                      all high-level information security documentation is approved by the agency head or their delegate
                    </item>
                    <item>
                      all system-specific documentation is approved by the system owner and an Information Technology Security Manager (ITSM).
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Publication of documentation</title>
            <content>

              <para>
                If stakeholders are not made aware of new information security documentation, or changes to existing information security documentation, they will not know about any changes they may need to make to the security measures for their systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>1153</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Publication of documentation</title>
                <content>
                  <para>
                    Once information security documentation has been approved it should be published and communicated to all stakeholders.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Documentation maintenance</title>
            <content>

              <para>
                The threat environment and agencies’ businesses are dynamic. If an agency fails to keep their information security documentation current to reflect the changing environment, their security measures and processes may cease to be effective. In that situation, resources could be devoted to areas that have reduced effectiveness, or are no longer relevant.
              </para>
            </content>
            <controls>
              <block>
                <ID>0888</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Documentation maintenance</title>
                <content>
                  <list>
                    <head>Agencies should review information security documentation:</head>
                    <item>
                      at least annually
                    </item>
                    <item>
                      in response to significant changes in the environment, business or system.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1154</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Documentation maintenance</title>
                <content>
                  <para>
                    Agencies should record the date of the most recent review on each information security document.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Information Security Policies</title>
        <objective>
          <block>
            <content>
              <para>
                ISPs set the strategic direction for information security.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the development of ISPs.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								ISPs are a component of an agency’s Information Security Management Framework, as mandated in the Australian Government Information Security Management Protocol.
							</para>
							<para>
								Information about other mandatory documentation can be found in the Documentation Fundamentals section of this chapter.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Contents of Information Security Policies</title>
            <content>
              <list>
                <head>Agencies may wish to consider the following when developing their ISP:</head>
                <item>
                  the policy objectives
                </item>
                <item>
                  how the policy objectives will be achieved
                </item>
                <item>
                  the guidelines and legal framework under which the policy will operate
                </item>
                <item>
                  the stakeholders
                </item>
                <item>
                  what resourcing will be available to support the implementation of the policy
                </item>
                <item>
                  what performance measures will be established to ensure that the policy is being implemented effectively.
                </item>
              </list>
              <para>
                In developing the contents of the ISP, agencies may also consult any agency-specific directives that could be applicable to information security.
              </para>
              <para>
                Agencies should avoid including controls for systems in their ISP. Instead, they should be documented in the SSP.
              </para>
            </content>
            <controls>
              <block>
                <ID>0049</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Contents of Information Security Policies</title>
                <content>
                  <para>
                    The ISP should describe information security policies, standards and responsibilities.
                  </para>
                </content>
              </block>
              <block>
                <ID>0890</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Contents of Information Security Policies</title>
                <content>
                  <list>
                    <head>The ISP should cover topics such as:</head>
                    <item>
                      accreditation processes
                    </item>
                    <item>
                      personnel responsibilities
                    </item>
                    <item>
                      configuration control
                    </item>
                    <item>
                      access control
                    </item>
                    <item>
                      networking and connections with other systems
                    </item>
                    <item>
                      physical security and media control
                    </item>
                    <item>
                      emergency procedures and cyber security incident management
                    </item>
                    <item>
                      change management
                    </item>
                    <item>
                      information security awareness and training.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Security Risk Management Plans</title>
        <objective>
          <block>
            <content>
              <para>
                SRMPs identify security risks and appropriate mitigation measures for systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the development of SRMPs, focusing on security risks related to the operation of systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                SRMPs are a component of an agency’s Information Security Management Framework, as mandated in the Australian Government Information Security Management Protocol.
              </para>
              <para>
                Information about other mandatory documentation can be found in the Documentation Fundamentals section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>System specific security risks</title>
            <content>
              <para>
                While a baseline of controls are provided in this manual, agencies will almost certainly have differing circumstances to those considered during the development of this manual. In such cases an agency needs to follow its own security risk management processes to determine its risk appetite and associated risk acceptance, risk avoidance and risk tolerance thresholds.
              </para>
            </content>
            <controls>
              <block>
                <ID>0009</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>System specific security risks</title>
                <content>
                  <para>
                    Agencies should determine system specific security risks that could warrant additional controls to those specified in this manual.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Contents of Security Risk Management Plans</title>
            <content>
              <para>
                Security risks cannot be managed if they are not known. Even if they are known, failing to deal with them is a failure of security risk management. For this reason SRMPs consist of two components, a security risk assessment and a corresponding risk treatment strategy.
              </para>
            </content>
            <controls>
              <block>
                <ID>0788</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Contents of Security Risk Management Plans</title>
                <content>
                  <para>
                    The SRMP should contain a security risk assessment and a corresponding risk treatment strategy.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Agency risk management</title>
            <content>
              <para>
                If an agency fails to incorporate SRMPs for systems into their wider agency risk management plan then the agency will be unable to manage risks in a coordinated and consistent manner across the agency.
              </para>
            </content>
            <controls>
              <block>
                <ID>0893</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Agency risk management</title>
                <content>
                  <para>
                    Agencies should incorporate their SRMP into their wider agency risk management plan.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Risk management standards</title>
            <content>
              <para>
                For security risk management to be of true value to an agency it should relate to the specific circumstances of an agency and its systems, as well as being based on an industry recognised approach to risk management, such as those produced by Standards Australia and the International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC).
              </para>
              <para>
                Standards Australia produces AS/NZS ISO 31000:2009, Risk Management – Principles and guidelines while the ISO/IEC has developed the risk management standard ISO/IEC 27005:2008, Information technology – Security techniques – Information security risk management, as part of the ISO/IEC 27000 family of standards.
              </para>
            </content>
            <controls>
              <block>
                <ID>0894</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Risk management standards</title>
                <content>
                  <para>
                    Agencies should develop their SRMP in accordance with Australian or international standards for risk management.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Information on the development of SRMPs can be found in HB 231:2004, Information security risk management guidelines. In particular, section 5 discusses documentation. It is available from Standards Australia at http://www.standards.org.au/.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>System Security Plans</title>
        <objective>
          <block>
            <content>
              <para>
                SSPs specify the security measures for systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the development of SSPs.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                SSPs are a component of an agency’s Information Security Management Framework, as mandated in the Australian Government Information Security Management Protocol.
              </para>
              <para>
                Information about other mandatory documentation can be found in the Documentation Fundamentals section of this chapter.
              </para>
              <para>
                Further information to be included in SSPs about specific functionality or technologies that could be implemented for a system can be found in the applicable areas of this manual.
              </para>
            </content>
          </block>
          <block>
            <title>Stakeholders</title>
            <content>

              <list>
                <head>There can be many stakeholders involved in defining a SSP, including representatives from the:</head>
                <item>
                  project, who must deliver the capability (including contractors)
                </item>
                <item>
                  owners of the information to be handled
                </item>
                <item>
                  system users for whom the capability is being developed
                </item>
                <item>
                  management audit authority
                </item>
                <item>
                  information management planning areas
                </item>
                <item>
                  infrastructure management.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Contents of System Security Plans</title>
            <content>
              <para>
                This manual provides a list of controls that are potentially applicable to a system based on its classification, its functionality and the technology it is implementing. Agencies need to determine which controls are in scope of the system and translate those controls to the SSP. These controls will then be assessed on their implementation and effectiveness during the accreditation process for the system.
              </para>
              <para>
                In performing accreditations against the latest baseline of this manual, agencies are ensuring that they are taking the most recent threat environment into consideration. The Defence Signals Directorate continually monitors the threat environment and conducts research into the security impact of emerging trends. With each release of this manual, controls can be added, rescinded or modified depending on changes in the threat environment.
              </para>
            </content>
            <controls>
              <block>
                <ID>0895</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Contents of System Security Plans</title>
                <content>
                  <para>
                    Agencies must select controls from this manual to be included in the SSP based on the scope of the system with additional system specific controls being included as a result of the associated SRMP or higher-level SSP.
                  </para>
                </content>
              </block>
              <block>
                <ID>0067</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Contents of System Security Plans</title>
                <content>
                  <para>
                    Agencies should use the latest baseline of this manual when developing, and updating, their SSPs as part of accreditation and reaccreditation of their systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Standard Operating Procedures</title>
        <objective>
          <block>
            <content>
              <para>
                SOPs ensure security procedures are followed in an appropriate and repeatable manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the development of security related SOPs. 
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                SOPs are a component of an agency’s Information Security Management Framework, as mandated in the Australian Government Information Security Management Protocol.
              </para>
              <para>
                Information about other mandatory documentation can be found in the Documentation Fundamentals section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Development of Standard Operating Procedures</title>
            <content>
              <para>
                To ensure that personnel undertake their duties appropriately, with a minimum of confusion, it is important that the roles of ITSMs, Information Technology Security Officers (ITSOs), system administrators and system users are covered by SOPs. Furthermore, ensuring that SOPs are consistent with SSPs reduces the potential for confusion resulting from conflicts in policy and procedures.
              </para>
            </content>
            <controls>
              <block>
                <ID>0051</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Development of Standard Operating Procedures</title>
                <content>
                  <list>
                    <head>Agencies should develop SOPs for each of the following roles:</head>
                    <item>
                      ITSM
                    </item>
                    <item>
                      ITSO
                    </item>
                    <item>
                      system administrator
                    </item>
                    <item>
                      system user.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Information Technology Security Manager Standard Operating Procedures</title>
            <content>

              <para>
                The ITSM SOPs cover the management and leadership activities related to system operations.
              </para>
            </content>
            <controls>
              <block>
                <ID>0789</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Information Technology Security Manager Standard Operating Procedures</title>
                <content>
                  <para>
                    The following procedures should be documented in the ITSM’s SOPs.
                  </para>
                  <table>
                        <header>
                          <cell>Topic</cell>
                          <cell>Procedures to be included</cell>
                        </header>
                        <row>
                          <cell>Cyber security incidents</cell>
                          <cell>Reporting and managing cyber security incidents</cell>
                        </row>
                  </table>

                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Information Technology Security Officer Standard Operating Procedures</title>
            <content>

              <para>
                The ITSO SOPs cover the operationally focused activities related to system operations.
              </para>
            </content>
            <controls>
              <block>
                <ID>0790</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Information Technology Security Officer Standard Operating Procedures</title>
                <content>
                  <para>
                    The following procedures should be documented in the ITSO’s SOPs.
                  </para>
                  <table >
                        <header>
                          <cell>Topic</cell>
                          <cell>Procedures to be included</cell>
                        </header>
                        <row>
                          <cell>Access control</cell>
                          <cell>Authorising access rights to applications and data</cell>
                        </row>
                        <row>
                          <cell>Asset musters</cell>
                          <cell>Labelling, registering and mustering assets, including media</cell>
                        </row>
                        <row>
                          <cell>Audit logs</cell>
                          <cell>Reviewing system audit trails and manual logs, particularly for privileged users</cell>
                        </row>
                        <row>
                          <cell>Configuration control</cell>
                          <cell>Approving and releasing changes to the system software or configurations</cell>
                        </row>
                        <row>
                          <cell rowspan="3">Cyber security incidents</cell>
                          <cell>Detecting potential cyber security incidents</cell>
                        </row>
                        <row>
                          <cell>Establishing the cause of any cyber security incident, whether accidental or deliberate</cell>
                        </row>
                        <row>
                          <cell>Actions to be taken to recover and minimise the exposure from a cyber security incident</cell>
                        </row>
                        <row>
                          <cell rowspan="2">Data transfers</cell>
                          <cell>Managing the review of media containing information that is to be transferred off-site</cell>
                        </row>
                        <row>
                          <cell>Managing the review of incoming media for viruses or unapproved software</cell>
                        </row>
                        <row>
                          <cell>Information and Communications Technology (ICT) equipment</cell>
                          <cell>Managing the destruction of unserviceable ICT equipment and media</cell>
                        </row>
                        <row>
                          <cell rowspan="4">System integrity audit</cell>
                          <cell>Reviewing system user accounts, system parameters and access controls to ensure that the system is secure</cell>
                        </row>
                        <row>
                          <cell>Checking the integrity of system software</cell>
                        </row>
                        <row>
                          <cell>Testing access controls</cell>
                        </row>
                        <row>
                          <cell>Inspecting ICT equipment and cabling</cell>
                        </row>
                        <row>
                          <cell>System maintenance</cell>
                          <cell>Managing the ongoing security and functionality of system software, including: maintaining awareness of current software vulnerabilities, testing and applying software patches/updates/signatures, and applying appropriate hardening techniques</cell>
                        </row>
                        <row>
                          <cell>User account management</cell>
                          <cell>Authorising new system users</cell>
                        </row>
                  </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System administrator Standard Operating Procedures</title>
            <content>
              <para>
                The system administrator SOPs support the ITSO SOPs; however, they focus on the administrative activities related to system operations.
              </para>
            </content>
            <controls>
              <block>
                <ID>0055</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>System administrator Standard Operating Procedures</title>
                <content>
                  <para>
                    The following procedures should be documented in the system administrator’s SOPs.
                  </para>
                  <table>
                        <header>
                          <cell>Topic</cell>
                          <cell>Procedures to be included</cell>
                        </header>
                        <row>
                          <cell>Access control</cell>
                          <cell>Implementing access rights to applications and data</cell>
                        </row>
                        <row>
                          <cell>Configuration control</cell>
                          <cell>Implementing changes to the system software or configurations</cell>
                        </row>
                        <row>
                          <cell rowspan="3">System backup and recovery</cell>
                          <cell>Backing up data, including audit logs</cell>
                        </row>
                        <row>
                          <cell>Securing backup tapes</cell>
                        </row>
                        <row>
                          <cell>Recovering from system failures</cell>
                        </row>
                        <row>
                          <cell rowspan="3">User account management</cell>
                          <cell>Adding and removing system users</cell>
                        </row>
                        <row>
                          <cell>Setting system user privileges</cell>
                        </row>
                        <row>
                          <cell>Cleaning up directories and files when a system user departs or changes roles</cell>
                        </row>
                  </table>

                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System user Standard Operating Procedures</title>
            <content>

              <para>
                The system user SOPs focus on day-to-day activities that system users need to know about, and comply with, when using systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0056</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>System user Standard Operating Procedures</title>
                <content>
                  <para>
                    The following procedures should be documented in the system user’s SOPs.
                  </para>
                  <table>
                        <header>
                          <cell>Topic</cell>
                          <cell>Procedures to be included</cell>
                        </header>
                        <row>
                          <cell>Cyber security incidents</cell>
                          <cell>What to do in the case of a suspected or actual cyber security incident</cell>
                        </row>
                        <row>
                          <cell>End of day</cell>
                          <cell>How to secure systems at the end of the day</cell>
                        </row>
                        <row>
                          <cell>Media control</cell>
                          <cell>Procedures for handling and using media</cell>
                        </row>
                        <row>
                          <cell>Passphrases</cell>
                          <cell>Choosing and protecting passphrases</cell>
                        </row>
                        <row>
                          <cell>Temporary absence</cell>
                          <cell>How to secure systems when temporarily absent</cell>
                        </row>
                  </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Agreement to abide by Standard Operating Procedures</title>
            <content>
              <para>
                When SOPs are produced the intended audience needs to be made aware of their existence and acknowledge that they have read, understood and agree to abide by their contents.
              </para>
            </content>
            <controls>
              <block>
                <ID>0057</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Agreement to abide by Standard Operating Procedures</title>
                <content>
                  <para>
                    ITSMs, ITSOs, system administrators and system users should sign a statement that they have read and agree to abide by their respective SOPs.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Incident Response Plans</title>
        <objective>
          <block>
            <content>
              <para>
                IRPs outline actions to take in response to a cyber security incident.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the development of IRPs to address cyber security incidents. It does not cover physical security incidents.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                IRPs are a component of an agency’s Information Security Management Framework, as mandated in the Australian Government Information Security Management Protocol.
              </para>
              <para>
                Information about other mandatory documentation can be found in the Documentation Fundamentals section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Contents of Incident Response Plans</title>
            <content>
              <para>
                The guidance provided on the content of IRPs ensures that agencies have a baseline to develop an IRP with sufficient flexibility, scope and level of detail to address the majority of cyber security incidents that could arise.
              </para>
            </content>
            <controls>
              <block>
                <ID>0058</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Contents of Incident Response Plans</title>
                <content>
                  <list>
                    <head>Agencies must include, as a minimum, the following content in their IRP:</head>
                    <item>
                      broad guidelines on what constitutes a cyber security incident
                    </item>
                    <item>
                      the minimum level of cyber security incident response and investigation training for system users and system administrators
                    </item>
                    <item>
                      the authority responsible for initiating investigations of a cyber security incident
                    </item>
                    <item>
                      the steps necessary to ensure the integrity of evidence supporting a cyber security incident
                    </item>
                    <item>
                      the steps necessary to ensure that critical systems remain operational
                    </item>
                    <item>
                      how to formally report cyber security incidents.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0059</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <title>Contents of Incident Response Plans</title>
                <content>
                  <list>
                    <head>Agencies should include the following content in their IRP:</head>
                    <item>
                      clear definitions of the types of cyber security incidents that are likely to be encountered
                    </item>
                    <item>
                      the expected response to each cyber security incident type
                    </item>
                    <item>
                      the authority responsible for responding to cyber security incidents
                    </item>
                    <item>
                      the criteria by which the responsible authority would initiate or request formal, police or Australian Security Intelligence Organisation investigations of a cyber security incident
                    </item>
                    <item>
                      other authorities which need to be informed in the event of an investigation being undertaken
                    </item>
                    <item>
                      the details of the system contingency measures or a reference to these details if they are located in a separate document.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Emergency Procedures</title>
        <objective>
          <block>
            <content>
              <para>
                Information and systems are secured before personnel evacuate a facility in the event of an emergency.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the requirements for securing information and systems as part of the procedures for evacuating a facility in the event of an emergency.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Emergency procedures are a component of an agency’s Information Security Management Framework, as mandated in the Australian Government Information Security Management Protocol.
              </para>
              <para>
                Information about other mandatory documentation can be found in the Documentation Fundamentals section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Evacuating facilities</title>
            <content>

              <para>
                During the evacuation of a facility it is important that personnel secure information and systems as they would at the end of operational hours. This includes, but is not limited to, securing media and logging off workstations. This is important as an attacker could use such an opportunity to gain access to applications or databases that a system user had already authenticated to, or use another system user’s credentials, for a malicious purpose.
              </para>
            </content>
            <controls>
              <block>
                <ID>0062</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Evacuating facilities</title>
                <content>
                  <para>
                    Agencies must include in evacuation procedures the requirement to secure information and systems before the evacuation; unless the chief warden, to avoid serious injury or loss of life, authorises personnel to evacuate immediately without securing information and systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Preparing for the evacuation of facilities</title>
            <content>
              <para>
                The warning phase before the evacuation of a facility alerts personnel that they may be required to evacuate the facility. This warning phase is the ideal time for personnel to begin securing information and systems to ensure that if they need to evacuate the facility they can do so immediately.
              </para>
            </content>
            <controls>
              <block>
                <ID>1159</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Preparing for the evacuation of facilities</title>
                <content>
                  <para>
                    Agencies should include in evacuation procedures the requirement to secure information and systems during the warning phase before the evacuation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>System Accreditation</title>
      <section>
        <title>Accreditation Framework</title>
        <objective>
          <block>
            <content>
              <para>
                Accreditation formalises the acceptance of security risks relating to the operation of a system.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the accreditation framework for systems and agencies’ responsibilities.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                All systems must be accredited before they can be put into operation.
              </para>
              <para>
                Accreditation is the process by which the accreditation authority formally recognises and accepts the residual security risk to a system and the information it processes, stores and communicates.
              </para>
              <list>
                <head>The accreditation framework comprises three layers:</head>
                <list>
                  <head>audit:</head>
                  <item>reviewing the information security documentation</item>
                  <item>assessing the appropriateness of the controls applied to the system</item>
                  <item>assessing the effectiveness of the implementation of the controls</item>
                </list>
                <list>
                  <head>certification:</head>
                  <item>providing independent assurance and acceptance of the audit</item>
                  <item>determining the residual security risk relating to the operation of the system</item>
                </list>
                <list>
                  <head>accreditation:</head>
                  <item>formally accepting the residual security risk</item>
                  <item>awarding approval to operate the system.</item>
                </list>
              </list>
              <para>
                Detailed information about the processes and the requirements for conducting accreditations, certification and audits is given in the Conducting Accreditations, Conducting Certifications and Conducting Audits sections of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Accreditation framework</title>
            <content>
              <para>
                Developing an accreditation framework ensures that accreditation activities are conducted in a repeatable and consistent manner across the agency.
              </para>
            </content>
            <controls>
              <block>
                <ID>0791</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accreditation framework</title>
                <content>
                  <para>
                    Agencies must develop an accreditation framework.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Accreditation</title>
            <content>

              <para>
                Accreditation of a system ensures that either sufficient security measures have been put in place or that deficiencies in such measures have been accepted by an appropriate authority. When systems are awarded accreditation the accreditation authority accepts that the residual security risks are appropriate for the sensitivity or classification of the information that the system processes, stores or communicates.
              </para>
              <para>
                Monitoring the accredited systems will assist in assessing changes to the environment and operation and to determine the implications for the security risk profile and accreditation status of the system.
              </para>
            </content>
            <controls>
              <block>
                <ID>0064</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accreditation</title>
                <content>
                  <para>
                    Agencies must ensure that that all systems are awarded accreditation before they are used to process, store or communicate sensitive or classified information.
                  </para>
                </content>
              </block>
              <block>
                <ID>0065</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accreditation</title>
                <content>
                  <para>
                    Agencies must ensure that all systems are awarded accreditation before connecting them via a gateway.
                  </para>
                </content>
              </block>
              <block>
                <ID>0086</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Accreditation</title>
                <content>
                  <para>
                    Agencies should ensure information security monitoring activities are conducted on accredited systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Determining authorities</title>
            <content>

              <para>
                For multi-national and multi-agency systems, determining the certification and accreditation authorities through a formal agreement between the parties ensures that the system owner has appropriate points of contact and does not receive conflicting advice from different authorities.
              </para>
            </content>
            <controls>
              <block>
                <ID>0793</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Determining authorities</title>
                <content>
                  <para>
                    For multi-national and multi-agency systems, the certification and accreditation authorities should be determined by a formal agreement between the parties involved.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Notifying authorities</title>
            <content>


              <para>
                In advising the certification and accreditation authorities of their intent to seek certification and accreditation for a system, the system owner can seek information on the latest processes and requirements for their system.
              </para>
              <para>
                The list of accreditation and certification authorities is given in the Conducting Accreditations and Conducting Certifications sections of this chapter.
              </para>
            </content>
            <controls>
              <block>
                <ID>0082</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Notifying authorities</title>
                <content>
                  <para>
                    Before beginning the accreditation process, the system owner should advise the certification and accreditation authorities of their intent to seek certification and accreditation for their system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Due diligence</title>
            <content>

              <para>
                When an agency is connecting to a system not under their control or passing information to another party, the agency needs to be aware of the security measures that have been implemented to protect the agency’s information. More importantly, the agency needs to accept the security risks associated with non-compliance with controls in this manual by the other party before connecting or passing information to them. The security risks include the system potentially being used as a platform to attack the agency’s system or spilling information onto a system not under their control and requiring subsequent cleanup of the spilled information.
              </para>
              <list>
                <head>Methods that an agency may use to ensure compliance with security requirements, and to assist in security risks being identified and accepted by the agency, include:</head>
                <item>
                  conducting an accreditation of the non-agency system
                </item>
                <item>
                  having an information security review performed by an infosec-registered assessor on the non-agency system
                </item>
                <item>
                  reviewing a copy of an existing certification report for the non-agency system in order to make an accreditation decision on the non-agency system.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0071</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Due diligence</title>
                <content>
                  <para>
                    If information is processed, stored or communicated by a system not under an agency’s control, the agency must ensure that the non-agency system has appropriate security measures in place to protect the agency’s information.
                  </para>
                </content>
              </block>
              <block>
                <ID>0900</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Due diligence</title>
                <content>
                  <para>
                    Agencies should review an accreditation report when determining whether the non-agency system has appropriate security measures in place to protect the agency’s information.
                  </para>
                </content>
              </block>
              <block>
                <ID>0072</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Due diligence</title>
                <content>
                  <list>
                    <head>Agencies must ensure that security requirements are documented in either:</head>
                    <item>
                      contract provisions
                    </item>
                    <item>
                      a memorandum of understanding.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0073</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Due diligence</title>
                <content>
                  <para>
                    Agencies must ensure that a process is in place to provide assurance to its management that a non-agency system meets, and will continue to meet, the agency’s security requirements.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Processing restrictions</title>
            <content>
              <para>
                When security is applied to systems, security measures are put in place based on the sensitivity or classification that will be processed, stored or communicated by the system. If information is placed on a system, and its sensitivity or classification is higher than the level of accreditation for the system, the information will be inadequately protected and will be exposed to a greater risk of compromise.
              </para>
            </content>
            <controls>
              <block>
                <ID>0076</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Processing restrictions</title>
                <content>
                  <para>
                    Agencies must not allow a system to process, store or communicate information above the sensitivity or classification for which the system has received accreditation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Accrediting systems bearing a caveat or compartment</title>
            <content>

              <para>
                When processing caveated or compartmented information on a system, agencies need to ensure that the system has received accreditation for the caveated or compartmented information.
              </para>
            </content>
            <controls>
              <block>
                <ID>0077</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accrediting systems bearing a caveat or compartment</title>
                <content>
                  <para>
                    A system that processes, stores or communicates caveated or compartmented information must be accredited for such caveated or compartmented information.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Requirement for Australian control</title>
            <content>

              <para>
                As Australian Eyes Only (AUSTEO) and Australian Government Access Only (AGAO) systems process, store and communicate information that is particularly sensitive to the government of Australia, it is essential that control of such systems is maintained by Australian citizens working for the government of Australia.
              </para>
            </content>
            <controls>
              <block>
                <ID>0078</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Requirement for Australian control</title>
                <content>
                  <para>
                    Agencies must ensure that systems processing, storing or communicating AUSTEO or AGAO information remain at all times under the control of an Australian national working for the government.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Reaccreditation</title>
            <content>

              <para>
                Agencies should reaccredit their systems every two years. However, they can be given an additional year’s grace if they follow the procedures defined in this manual for non-compliance with ‘should’ requirements: that is, providing a suitable justification, conducting a security risk assessment and obtaining formal approval from the accreditation authority.
              </para>
              <para>
                Once three years has elapsed since the last accreditation, the agency needs to either reaccredit the system or seek approval for non-compliance from the agency head.
              </para>
              <list>
                <head>Other reasons an agency could seek reaccreditation include:</head>
                <item>
                  changes in information security policies
                </item>
                <item>
                  detection of new or emerging threats to systems
                </item>
                <item>
                  the discovery that controls are not operating as effectively as planned
                </item>
                <item>
                  a major cyber security incident
                </item>
                <item>
                  changes to the system or the security risk profile.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0069</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Reaccreditation</title>
                <content>
                  <para>
                    Agencies should ensure that the period between accreditations of systems does not exceed two years.
                  </para>
                </content>
              </block>
              <block>
                <ID>0070</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reaccreditation</title>
                <content>
                  <para>
                    Agencies must ensure that the period between accreditations of systems does not exceed three years.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Conducting Accreditations</title>
        <objective>
          <block>
            <content>
              <para>
                Systems are accredited before they are used operationally.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes conducting an accreditation for a system.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Accreditation aim</title>
            <content>
              <para>
                The aim of accreditation is to formally recognise and accept the residual security risk to a system and the information it processes, stores or communicates.
              </para>
            </content>
          </block>
          <block>
            <title>Accreditation authorities</title>
            <content>

              <para>
                For standard systems the accreditation authority is the agency head or their delegate, which is strongly recommended to be the Chief Information Security Officer (CISO).
              </para>
              <para>
                For systems that process, store or communicate caveated or compartmented information there may be an accreditation authority external to the agency operating the system.
              </para>
              <para>
                For multi-national and multi-agency systems the accreditation authority is determined by a formal agreement between the parties involved.
              </para>
              <para>
                For gateway services of commercial providers the accreditation authority is the agency head or their delegate, which is strongly recommended to be the CISO.
              </para>
              <para>
                For commercial providers supporting agencies the accreditation authority is the head of the supported agency or their authorised delegate, which is strongly recommended to be the CISO.
              </para>
              <para>
                In all cases the accreditation authority will be at least a senior executive who has an appropriate level of understanding of the security risks they are accepting on behalf of the agency.
              </para>
              <para>
                Depending on the circumstances and practices of an agency, the agency head can choose to delegate their authority to multiple senior executives who have the authority to accept security risks for the specific business functions; for example the CISO and the business owner.
              </para>
            </content>
          </block>
          <block>
            <title>Accreditation outcomes</title>
            <content>
              <para>
                Accreditation is awarded when the accreditation authority accepts the residual security risk relating to the operation of the system and gives formal approval for the system to operate. However, in some cases the accreditation authority may not accept the residual security risk relating to the operation of the system. This is predominantly due to security risks being insufficiently considered and documented in the Security Risk Management Plan (SRMP), resulting in security measures being inaccurately scoped in the System Security Plan (SSP). In such cases the accreditation authority may request that the SRMP and SSP be amended and security measures reassessed before reconsidering the system for accreditation.
              </para>
              <para>
                In awarding accreditation for a system, the accreditation authority may specify a shorter period before reaccreditation than that specified in this manual. The accreditation authority may also place restrictions on the use of the system which must be enforced until reaccreditation takes place or until required changes are made to the system.
              </para>
							<title>Accreditation process</title>
              <para>
                The following diagram shows, at a high level, the process of accreditation.
              </para>
              <image>
iVBORw0KGgoAAAANSUhEUgAAAikAAAJ/CAYAAAC9REP0AAAKQ2lDQ1BJQ0MgcHJvZmlsZQAAeNqdU3dYk/cWPt/3ZQ9WQtjwsZdsgQAiI6wIyBBZohCSAGGEEBJAxYWIClYUFRGcSFXEgtUKSJ2I4qAouGdBiohai1VcOO4f3Ke1fXrv7e371/u855zn/M55zw+AERImkeaiagA5UoU8Otgfj09IxMm9gAIVSOAEIBDmy8JnBcUAAPADeXh+dLA//AGvbwACAHDVLiQSx+H/g7pQJlcAIJEA4CIS5wsBkFIAyC5UyBQAyBgAsFOzZAoAlAAAbHl8QiIAqg0A7PRJPgUA2KmT3BcA2KIcqQgAjQEAmShHJAJAuwBgVYFSLALAwgCgrEAiLgTArgGAWbYyRwKAvQUAdo5YkA9AYACAmUIszAAgOAIAQx4TzQMgTAOgMNK/4KlfcIW4SAEAwMuVzZdL0jMUuJXQGnfy8ODiIeLCbLFCYRcpEGYJ5CKcl5sjE0jnA0zODAAAGvnRwf44P5Dn5uTh5mbnbO/0xaL+a/BvIj4h8d/+vIwCBAAQTs/v2l/l5dYDcMcBsHW/a6lbANpWAGjf+V0z2wmgWgrQevmLeTj8QB6eoVDIPB0cCgsL7SViob0w44s+/zPhb+CLfvb8QB7+23rwAHGaQJmtwKOD/XFhbnauUo7nywRCMW735yP+x4V//Y4p0eI0sVwsFYrxWIm4UCJNx3m5UpFEIcmV4hLpfzLxH5b9CZN3DQCshk/ATrYHtctswH7uAQKLDljSdgBAfvMtjBoLkQAQZzQyefcAAJO/+Y9AKwEAzZek4wAAvOgYXKiUF0zGCAAARKCBKrBBBwzBFKzADpzBHbzAFwJhBkRADCTAPBBCBuSAHAqhGJZBGVTAOtgEtbADGqARmuEQtMExOA3n4BJcgetwFwZgGJ7CGLyGCQRByAgTYSE6iBFijtgizggXmY4EImFINJKApCDpiBRRIsXIcqQCqUJqkV1II/ItchQ5jVxA+pDbyCAyivyKvEcxlIGyUQPUAnVAuagfGorGoHPRdDQPXYCWomvRGrQePYC2oqfRS+h1dAB9io5jgNExDmaM2WFcjIdFYIlYGibHFmPlWDVWjzVjHVg3dhUbwJ5h7wgkAouAE+wIXoQQwmyCkJBHWExYQ6gl7CO0EroIVwmDhDHCJyKTqE+0JXoS+cR4YjqxkFhGrCbuIR4hniVeJw4TX5NIJA7JkuROCiElkDJJC0lrSNtILaRTpD7SEGmcTCbrkG3J3uQIsoCsIJeRt5APkE+S+8nD5LcUOsWI4kwJoiRSpJQSSjVlP+UEpZ8yQpmgqlHNqZ7UCKqIOp9aSW2gdlAvU4epEzR1miXNmxZDy6Qto9XQmmlnafdoL+l0ugndgx5Fl9CX0mvoB+nn6YP0dwwNhg2Dx0hiKBlrGXsZpxi3GS+ZTKYF05eZyFQw1zIbmWeYD5hvVVgq9ip8FZHKEpU6lVaVfpXnqlRVc1U/1XmqC1SrVQ+rXlZ9pkZVs1DjqQnUFqvVqR1Vu6k2rs5Sd1KPUM9RX6O+X/2C+mMNsoaFRqCGSKNUY7fGGY0hFsYyZfFYQtZyVgPrLGuYTWJbsvnsTHYF+xt2L3tMU0NzqmasZpFmneZxzQEOxrHg8DnZnErOIc4NznstAy0/LbHWaq1mrX6tN9p62r7aYu1y7Rbt69rvdXCdQJ0snfU6bTr3dQm6NrpRuoW623XP6j7TY+t56Qn1yvUO6d3RR/Vt9KP1F+rv1u/RHzcwNAg2kBlsMThj8MyQY+hrmGm40fCE4agRy2i6kcRoo9FJoye4Ju6HZ+M1eBc+ZqxvHGKsNN5l3Gs8YWJpMtukxKTF5L4pzZRrmma60bTTdMzMyCzcrNisyeyOOdWca55hvtm82/yNhaVFnMVKizaLx5balnzLBZZNlvesmFY+VnlW9VbXrEnWXOss623WV2xQG1ebDJs6m8u2qK2brcR2m23fFOIUjynSKfVTbtox7PzsCuya7AbtOfZh9iX2bfbPHcwcEh3WO3Q7fHJ0dcx2bHC866ThNMOpxKnD6VdnG2ehc53zNRemS5DLEpd2lxdTbaeKp26fesuV5RruutK10/Wjm7ub3K3ZbdTdzD3Ffav7TS6bG8ldwz3vQfTw91jicczjnaebp8LzkOcvXnZeWV77vR5Ps5wmntYwbcjbxFvgvct7YDo+PWX6zukDPsY+Ap96n4e+pr4i3z2+I37Wfpl+B/ye+zv6y/2P+L/hefIW8U4FYAHBAeUBvYEagbMDawMfBJkEpQc1BY0FuwYvDD4VQgwJDVkfcpNvwBfyG/ljM9xnLJrRFcoInRVaG/owzCZMHtYRjobPCN8Qfm+m+UzpzLYIiOBHbIi4H2kZmRf5fRQpKjKqLupRtFN0cXT3LNas5Fn7Z72O8Y+pjLk722q2cnZnrGpsUmxj7Ju4gLiquIF4h/hF8ZcSdBMkCe2J5MTYxD2J43MC52yaM5zkmlSWdGOu5dyiuRfm6c7Lnnc8WTVZkHw4hZgSl7I/5YMgQlAvGE/lp25NHRPyhJuFT0W+oo2iUbG3uEo8kuadVpX2ON07fUP6aIZPRnXGMwlPUit5kRmSuSPzTVZE1t6sz9lx2S05lJyUnKNSDWmWtCvXMLcot09mKyuTDeR55m3KG5OHyvfkI/lz89sVbIVM0aO0Uq5QDhZML6greFsYW3i4SL1IWtQz32b+6vkjC4IWfL2QsFC4sLPYuHhZ8eAiv0W7FiOLUxd3LjFdUrpkeGnw0n3LaMuylv1Q4lhSVfJqedzyjlKD0qWlQyuCVzSVqZTJy26u9Fq5YxVhlWRV72qX1VtWfyoXlV+scKyorviwRrjm4ldOX9V89Xlt2treSrfK7etI66Trbqz3Wb+vSr1qQdXQhvANrRvxjeUbX21K3nShemr1js20zcrNAzVhNe1bzLas2/KhNqP2ep1/XctW/a2rt77ZJtrWv913e/MOgx0VO97vlOy8tSt4V2u9RX31btLugt2PGmIbur/mft24R3dPxZ6Pe6V7B/ZF7+tqdG9s3K+/v7IJbVI2jR5IOnDlm4Bv2pvtmne1cFoqDsJB5cEn36Z8e+NQ6KHOw9zDzd+Zf7f1COtIeSvSOr91rC2jbaA9ob3v6IyjnR1eHUe+t/9+7zHjY3XHNY9XnqCdKD3x+eSCk+OnZKeenU4/PdSZ3Hn3TPyZa11RXb1nQ8+ePxd07ky3X/fJ897nj13wvHD0Ivdi2yW3S609rj1HfnD94UivW2/rZffL7Vc8rnT0Tes70e/Tf/pqwNVz1/jXLl2feb3vxuwbt24m3Ry4Jbr1+Hb27Rd3Cu5M3F16j3iv/L7a/eoH+g/qf7T+sWXAbeD4YMBgz8NZD+8OCYee/pT/04fh0kfMR9UjRiONj50fHxsNGr3yZM6T4aeypxPPyn5W/3nrc6vn3/3i+0vPWPzY8Av5i8+/rnmp83Lvq6mvOscjxx+8znk98ab8rc7bfe+477rfx70fmSj8QP5Q89H6Y8en0E/3Pud8/vwv94Tz+4A5JREAAAAJcEhZcwAAD2EAAA9hAag/p2kAAAAHdElNRQfcAhoXFSj3JWl0AAAgAElEQVR42uzdeVyU1f4H8M/sGwzDDDsoKC4ICihu5VKpZdavrq126+bNNFNLs26ZGrm158Z1uZW3rK62mWXbzfRq7rmhouICqIAioizDADPDMNvvD2BkmWFRTMTP+77uyzhz5pzznHNm5jvnPPM8AqfT6QQRERFRKyNkFxARERGDFCIiIiIGKURERMQghYiIiIhBChERETFIISIiIrpOxDX/eHnZFpgtNvYKueWlkAB2/mKdPAv0VcFosrIjyKMwf2+UlFrYEeTR/UM6o0OYpn6QsnFfJkpNFewhcitY5wWLkR9A5Fl850CczS1hR5BHt3YPRXpWITuCPBrcp53rv7ndQ0RERK0SgxQiIiJikEJERETEIIWIiIgYpBARERExSCEiIiIGKUREREQMUoiIiIgYpBARERGDFCIiIiIGKURERMQghYiIiIhBClHjvJRSRHfwg5dSelMcr1QiQnQHP2jVcg6+B3KZGJ3a+d40xyuViNAlXAuNN+cEMUhpcSKhAF6KG+MDRiIWQiJmjNea9OwaiFVv3IeB8WH458vDMCA+7KrLVCkkLVZWSwvx98KqN+7D3bdG3tDHJxIKIJeJr7ocpVyCN58fjL7dQwAAXcK1+Ord+/HW5MHwVknx1uTB6NUtsMXraU0CdSosn3kXhvQNb7PHSAxSrosx9/bA4c+fxtFVT2PnB0/A9wq+CUx+OAGrXv+/a9pOX285Ppo2HCe/egYnv3oGH7wyHD4qGWdSjTe3Tf/6K/4z9/+uazsEVf+rNm5kPP41fXijz3OXr25Z16ufmnoMf1ZftUSgP/VvffDLskfw85KHMWfCwGaX8bd7Y/Du1NsvH4ug8v8AMGp4N9jtTjz52i8AAIcDcDqvrK0N1dOy80KMtQsewNIZd15x21psXtQ4xmtVx41IIRPjo7kj8OYLt7Ez/gTi1tCI6Ag/zBozAB/9kIKPfkxB1/Za6EvLG32ev0aJCqsdBqMFADAgNrRecCMSCRHgq0SRwQyL1V4v4FApJCgoNqO8wlb5TUSrgqXChuIyi9s635t0O3pHBWHES98CAL6edz/enXQ7Js7f0KxjVqtkUKuk0JeWw2i2NrnNPioZvJRSXNIbYbU5Wt2EGtyrHeQyMWIi/RER4oOsXEO9DyadjwKX9CY4HE6PaWqVFCqFFAXFJlhtDohEQvhpFNCXlKOiTp9Uf+iLhJXvqEazFVMW/K/W431jgustgau9ZFDJJbikN8Fud7jN564ssUgInUaBwmIzbPbaY+CtlMJbJUVxqQWmcusV95M77o6hZr8KBIJ6feOprTX7tyl9dS08+3BP3DMwEsu+PoD9qRegUkhqra5ofRQwlFnqHZOXUgqVQoJCgxk9owKh9qr8kmAqt+K1pdsvv1a8ZdCXVs6XCqsdry/fXrtvxEJo1XIUFJtd8w4AvFVSKOUSFOhNsFelN1RPzb72VcuhLymv1dfV7S01WmAqtzXYJ/1jQyGTihAVoUO7IDXO5ZU02o8121b3+IQe5oS7dtbt25rH6KmOm1GvmCDIpGJEtvdFSIA3ci+V1npc4y2H1Wav9b7uLk0kFECjlqOkrAJWm/3KyhAJofGWobjU4noPq6ZSSKCQS1DsZpwZpDRTXOcAAMDmA9nQl5Zjz7FczH56AJ66pwf6PfMfXNKbMLR3OD6ePgJDpnyF3PwyrHj1btzaIxRmiw0Lv96HIK0K/aIrlyZPrXkWnR79CEMSwvH+pNthtTmg9pJh3spd+GbzCQRqVVj75kgEalUoKDbBVy3H2i1pGBQXBrVKBh8vGb79PQ3TP9haq50BvkoM6x2Bj348hPRzRQCAtVvSMO6+OLz17GA8fmc0Ep7+HEUlZswdOxCP3xWNuNErYbLYsHjKEAT7eeGFpM34eu79CAvwxsUiI4K0Kvy48xSmLd8Cu8PZaJuDdSoYy60YNOlLWG2WVjeh7uzXARt2n8GQPhEY1rcDPv4hxfXY7QntMXv8IMilImSeL8bjiT/VS3th4SasnHUvArVKmCw23Df1W/TvEYhZzwyE1WaHWiXDglV78cPW9MoAt4Mf5k4YBI233PVCDNSqcGD1GHyw9iA+/uEwJo/qjYRuQQCA/f95Cv2e+hz/mXsfQgO8AQB2uwOvLt2CW2PDauXrM/ozBGpV+HXJo66y7ugd7mqLWCTE3BU7se3gWfj7KrHitREI8fdCvt6EAF8l1u8+g7krdtb6AGyonyJCfPDd+w9i4ep9+PK3YxjWNwLvTbkD499a77Ztrm/SI2Iw+t7u0Krl2LQvG69/uB12u8NtW49nFtTq37HzfsWad0d67Ks1/zuBx4ZHY/jz36Cg2ITBvdph8UvD8ODL3yG7CR+gnqgUEtw7KBK7UnLw09aMOh/UIfjH6L6w2hzwVkrxrzWHsH7naeg0Cvxz2jD4+SphLrdia/JZxHapfO/Y8MEo/G3mz/jy3fvx2Y9HoZCLEVfjsdGJv2D12/fhk3WH8fVvJ3BrXCheeaofZFIxsi8YMPHNDRAKBVg2/U4E+3tVzQsn5q3Yhb7dgz3W88Wvxyq/IPUMw8uj+6LC5oBYJMCCz/chPbsIC/8xBIE6FQqLzfDzVeL3fdlY8Plet3MCAAYntMOW5LMY1DMMtyW0w+r/HkO7IDVWzr0HH6w5hO83p2Fwr3Z4/dkBeHnh7+hTp23j5q4HADx8Z1c8elcUNGo5th84h/dW7obd4XTbzt2Hz9fr2xfnb8a/Z49w9WXNOoZP/AaTRvXCA0O6YNS0H1FkMKN/bCjeeG4Qxsz6L3IulrbpIKV/XCj+OJSDvrEh6B8Xgu//l1b1RUGEl5/uh5hOfrBY7Viz/gR+35NdL23DzjPoFR2EZ0f1hM3ugEohxec/HMGWvdnNKqNPj2A8O6pX5etbKMSH3xzEgWN58FXLMXfyYGg1ClgsNkx+ayNs5hs3SGkV2z1p2YUAgFljBqBHpD8A4L9/nK5aHancKx+SEI60s0XIzDXgzr4RGBzfDk/O+wU9x3yGH7Zl4L3Ve7H3eC7SzxWh06MfwUclw5Kpw7Do6/245dlVePvzP/Dm+EEI8FXCSyFBWIA33lu9B7dOWI05n+zC34bH4OtNJ9FrzGd4d9UejBoahZ5dAuut+AgEQFp2kSvtZHYhBAKg0GCu/MZR9WIeFNcOAoEAfaKDAQB9ugVj26Fz8FJIEBHsg3dX7cHAiV9gxofb8eBtXTAorl2T2vzOqj2I+/unKDG2vgBFKZfg1thQbEk+iz1Hz2NY34haKwxvTByM/cdzMWjcajzz1nq3aSqFBCH+Xvjn18m4ffwXEAiAt5+7DR+uPYh7pqxB0pf7MWPMLfDTKCGTirD4H0ORlWvA8Oe+xtsr/3DbrqXfJOPAiTyczilGn9GfweFwYvqyLbjj2S8wdMKXSD9bhBf+2qdevrq8lVLMmzAIP2xNw13PfY0ft6XjzUmD4V317bN9kBpLvk7G/039Fm9+8gf+b2An3NIjtFn95ElDbVuz6QTunvwN3v50N4bf0gG39Aj12NYgnapW/5aZKhqs53/7sgAA/bpXzuOB8e1w6pz+qgIUAIiK0EEsFuJI+qV63+RnjL0Vn/+Uisen/4SP1qZgyuMJ0PoooJRLEKhT4d/fpeCBF7/HP79IxpH0S5XjP/GbWuV8/P1hj495KaV49elbcOjkRdw/ZS3+seD3qu0gJ9789x944MXv8eBL63AqR4/xD8U3WFZ1edOe6o9fd57BqFd+wG+7MjH96VsQoFUiNMAbH39/GH+b+TMWr9qHO/tHoHd0kMdthD4xwdh1KAfJx/MwqFe7RvvRU9t+3JKBx179Ef9cvR939GmP3jHBHtvppZTW69ua39bd1bH9wLnKVYWqc3z69QhG5vniNh+gyGVixEUFYP/RCziSdgn94i6/vnt3D0Js1wC8/dEfGP/6r9h54JzbNJVCguf/1htrfjuB5+ZtwOqfUzH2oTho1PIml6FUSDDxrwn4fU8WJs75DVv2ZeO5J3pDWbV64q9V4sufUzE28b8wma03dJ+3iiDlYPpFzPt0FzqGavDTew9h4eQhSMm4iItFRgysClJu79ke6/ecAQCUmSo7fXB8OwgFcG331HRrj1CoFBL8sD0dAgGQeqYAYpEQCVGX3yCqv8tUr4oUGEy1/vbzUdTZoqk8qddccXnJtnpJ/8z5YhiMFiR0DUKovzdC/b1w4GQeBvQIQ7CfF0L9vbE95Vy9uk+d1wMAdD6KZrW5NRrcsx3sDif2HcvFzpRz6NzeF+2D1JVBWkwwlHIJvtucBpvdAaPZ6jbNdZxVB9onOgRKuQS/7joNgQA4kVUIsUiI+C4B6Nc9BH4aJdb87wQczTzZ4PylUsR3DcTo/+sOrVqBIJ2q0ef0jq5s7+/7swEAW5PPQimXuFYearY7M7e4ckvRzS9vGuqnK1FhrfyWdDpHX7UsLGu0rU3trsPpF5GvN7lOoBwQF4bN+7Oueq6ovaRVr+WKelsXSrkYm/ZmQSAATp3VQywSonukX70+vlLxXQOglIvxy/ZTsNkdtbblLhSUoXsnfzx6VxR8veXw1yobXwmuKm/nocrX9x8pOVDKxYitWiGubu/ZqsDO01Za/9hQOBxOHDp5EXuP5qJjmMa12tdc1VvBWRcqtxF9vGQNtNO/2X177HQ+CovN6FU1n/p2D8GOgzltf6snOggOB5CakY9Dx/PQPliNIL/KlTdz1VZebFQABAIBjGar27SYzv5QyMTYeeAcBAIgM6cYIpEQXSO0TS+jkx8UMjH2H70AAEhOvQCFTIzomq+TNtLn4tbSkE//exQ/7jiF+c/djgdv64K9x3Lx255MDO/fAV3aaxHi5+UKUrYeOosFX+7DsyPj8cDgLpi0cCMOpV+sVV71zzK/nvcXSMRC5BebsGrDMdeLtikEdc6MK6v6EFXIJDWWrSvfbA1GC3YdyUGvroHIzivB/hMXsP1wDu4f2AnHMgtQUGzG8awCdAzReKirZdp8PQ3rF4HM3GL07Bro2noZ2jcCn/50BFp1ZcBXaqyoMUb10+qq/pBfkTgCEpEIhQYTvt10EmfzSlwfAtWrWM1Z8Vk27S4IhQKsXp+KrAvF0PkENfo8XVXQWh0kl1Z9wGq85YCHMRK4ObvSUz9tSc5ukXEQCAQe29rcE9KdTmDz/mwM6ROOyDBfBOlU2Lzv6ttZHZB6qWr/ms+n6ryHhf8YArFICH1JOX7amoGcS1f3Dd1Z49O3Okio7pvL80KMt6fcDqFAgLWbTuJcXonbILPeHK0qr/qYylzzwsM5HB5OuL0toR3O5pWgeyc/1/kFgxPaYeehFvjwF3hup4+3HOeauQLidAI7Dp3DwJ7tEBHigwCtEjsOnmvzQUr/uFCcv1iKqI5a1/lK/eJC8OPmdKScvIhvfj2O+4Z0xqCEdkj6fL/btOpze2ZNGgSxWIjiknL8b1cm8gqMyM41NKkMn6qxrA6wq1dLvFVt7/IL4tbUmKISMz5YdwhDEsIRHuSD/+4+jb/f0x1P3xuLM7nFSD97eZtl+fcH8cXGY9iYNAozR9+CRxJ/qFVW9QfXayu24+jp/FqPRYZqrqh9J6q2paLaay8vW4frXI9tTzmH2U8PhL7Ugm0p57DjcA6m/60/hvYOx47D5xr9lnIt2vxnbvUMiAvDqRw9Hr87GgCgLynHsKogpaik8tgCtEocz7w83nXT3M0JAHhn5W4czyyo9Vj7YPXlQOZ809t678BIxHUJwLBJX0FfUl5rpaqx+Vn5pi6rWg2QuY6zJfqpetWjpV5L7tpa1Iy2Vtu0NxOP3dUNj98djewLBteKzdXIOKuH0+lEr6hArNuc7kovrjph/p9fJCO9xrYqALS7itWmmqrr8NMokF6jy4f174CYSD88/PI6GEotrnNamlqeuupXft5V/xaXNn1LViETo0/3YGTlGvDg0K6VX3xKLRjUqx12ttCHv+d2ll9RedsPnMPIO7rgwWFdce5iaZNO/r6RyWVixHcLwLkLpRgxuPJn/yVlFvSLrQxSAOCHzenYtDsL86cNwRP3xWDOsh310n7dVnkqwyffpeDMueJ69TSnjOprQqmq/i0ps7S5fm8V2z2BWhUGxoWhU5gvnry7OwDgYHoeDpzMwyW9CfcN7ORaRQEqf9UTpFNBKhFBKBC4zow2W2zQeiuglImx6+h5lBgtmPxwAtQqGUQiIbpF6K6qnRcKyrDrSA5GDeuG3lFB6B0VhEeGdMWOw+eQV2jEtpRzUMjEuKNXe2w7dA4nswuRX2zCsN4R2JbS+BvNtWjzn2VQzzBIJSK8vPh3vLBgE15YsAk/bktHVIQOof7e2H/sAkzlVjx6Zzd4K6UI1KncptW179gFlJoqMHZkHLyVUohEQnSpChL3pebCVG7FY3dFQyRqeCqXV9jg6y2DQiaGsGp1w901eWrmq6u6vSNu7QihQIDh/TvAaLYi+cSFFuknpVwMh9OJmEg/CAUCyKXiJret6W3Na/S5des5nH4JBcUmDL+lIza3UCClLynH1uSz6B8bioeGdUVYoDc6t/fFoZMXUWaqwBP3xsBLKYVIKEDHME0DbbXDx0vW6HVWan5BSEm7BFO5Dfff0RleSin8fZWu1czK1VFJs+pJSbsEs8WGof3CIRAIcEef9jCVW3E47VLTv6HHhkAqEWHOBzuRuGw7Epdtx/pdZ9C5vS/kcgmcTieiOmghEAggk4quqA+upp3u6kg9VYAigxl39G7fYoFUa9YrOggSsQgLP92L9z/eg/c/3oMt+7LRIUyDAK0SGm85tD4K16+qbHan27TUjHyYzFY8MKwrlIrKXyWGh/i4VvmaVMapfJRbbBjYKwwCgQC39gyFudyG46cLGKRcCz07B+DTmffgf0mjcM8tHfHRDynYnJwNh9OJ3/acgVImxm81gpSBcWHY+a8nsPffo2Gy2PD2f3YDqNwykstESPn8aZSaKvDs+xvQtb0Whz8fg/Svn8FH0+6u98bfXP9YtgUZ54rw7Zsj8e2bI5GWXYR/LN0CAMgrNCL9XBH0JeWu81p2HD4HuVSMHYcbX7K9Vm3+Mwzr2wEnMgtxsch4+ZtW1RvX0L4RKDVVYNaHOxDT0Q9bVzyBf/7jTrdpdZWZKvCPxZvRuZ0vtq54Ans+G40FLw6BTCpCibECr/xzC7p10GHrR4/j3cm3o7i0HAXFpnrlfLXhOGRSMbZ89AR+2XkKe1NzseqN+7By9r24Z0Cka5WuZj534/P6B9txV78O2PPZaAy/pSMSP9hW7yfkV9pPfaJD8NF3KRjaJwK7PxuNuRMG4Xx+qWuFraG2Nb2tFY0+t249DqcTm/dnQyETY3PVibQtIWl1Mnal5ODZh3vi03n34umRsTCarZjzwU50CPXBusUPYv2/HsXciYMgk4jclrHu93TIpCKsW/Rgk+stM1Xg/c/2ICpCh3WLH8Sbzw8GAPxvdxYOnMjD8hl3IWnaMAztF4EzOcWN1lNmqsB7K/fgtoT2WP+vR3F7n/Z455M9MJY3fV4MTmiPjOwi5Osvz909RyqXB3t2DcB/fk7FoJ7t8OvyRzBtTH/kFRhdq2JN7QNP7TQ1oZ3u6nA6ndhxMAdymfim2OrpFxeCzJxiFNXYXj54LK/qsVD06OKPJYl34YPZd6O8wo4vfk51m2Yqt2Lhp3vRPliNT968F6vevx8vjekHqUTU9DLMViz/8gD6x4di1fv349b4MCz7Mtl1/kpbInDW2KyNHb3StXf9Z5NJRPBVy1FcanFdswSovC7JLd1DMXjSF/Xye6ukKDSYa31LEomEkImFMFlstVZe7A6nawm8JWiqls+Lr9Hy2rVo89UK1nnBYry6M8UlYiF8vauuTeF0ekxzR+ejgMPpdLu9ovNRwAlAX2L2uK0mEgkhFQthrpobKoUEXkopDHXmXN187srRquUoKimvd22CFnktSEXQ+ShgKrfVW4pvrG0t1da69cx6ZiB6Rwfh/hfXNvi8+M6BOJvbvF/+qBQSSCWieuOqVcthdzphaGTbRCQUQCIRodzSvDdosVgIjZcMhYbyWuesKOUSqBQSlBgtsFTYm1xP9XUvikvKXecrtPR7pEYtR7nFBkOd953m9MGVttNdHf8Y3RfxXQPx5Gs/N7mcW7uHIj2rsE0GMhKxCEqFGCVlFtf7kLs01+eItxwOp7PWNk1zyhAJBVB7yVBSZrkmc+56mTauP3pWnZTdar6iW6x25BUaa6WpVTLcN6ATVm845ja/pbj+B7jd7oCpzptxvptv1ler+Brv/V2LNrcGVpsDl/SmRtPcaegE2aacPGu3O2CuMTeMZqvbVZC6+dw9nq+/duNjqbAjN7+sScfQlGO+krbWrMdbKcXwWzrg2/+dvCbH62kcmnr+jN3hhN3S/G+QNpsDBW7eQ0zlVrerC43VY3c4UVh87b5UWKx2XKzzHnklfXCl7axbh5dSijv6hNe7zs3NzGqzw1BqbzTN9Tni5nyg5pRhdzibdU7cjahV33zmlu4hOHVej593nuLsJ7pOekcHI/O8ARtqbLkSxXUNwNkLBmxJPsvOoGumVZ/ssGFvJjbszeQoEV1HW5KzW+zn0dR27DqUg12HctgRdE3xNr5ERETEIIWIiIiIQQoRERExSCEiIiJikEJEREQMUoiIiIgYpBARERExSCEiIiIGKUREREQMUoiIiKitqHVZ/H5RwaiocLBXyC2FXAwviZgdQR75a5SICtOyI8ij0AAvdG7ny44gj9QqmfsgJf+Sye3dSIkAIEinglTOfiDPNMEyCPg9hxrQNVwHh42ThDzT+Shc/83tHiIiImqVGKQQERERgxQiIiIiBilERETEIIWIiIiIQQoRERExSCEiIiJikEJERETEIIWIiIgYpBARERExSCEiIiIGKUREREQMUoiIiIhBChEREVErIG7pArtHajD+gQj2bCuT9OUpnMktY0cQEdHNG6R0DPVCt/bs2NYmJEDJIIWIiG4o3O4hIiIiBilEREREDFKIiIiIQQoRERERgxQPrFYbyspMHFEiIqI2QtwWDuKvT7wMQICAAC1Onz6HsU8/hAdGDr3u7VqybDX8/Hzx+GP3cqYRERHdjEHK4SPp+ObLhejRozNycvJw14jx6NcvFiHB/gAAm82O/AI9Avy0EIlrLx5dvFgAiVQCra9Pk+pqqKzcC/nw9lLC21sFADh+/Ax6J8Q0mIeIiIjacJBSU1hYEPx0GmRkZCEk2B9bt+3HoqTP0blTOI6fOI25s59D3z49kJqagdlzl6Nbt47IL9CjIF+P775Ngl5fgj79R+Hg/rVQq1XY9UcKZr62GNu2fO6xLKvVhjFjEwEAEokYU194EtnZuUhJOYHMrPOw2e0YO+bBenniYrtyBhIREd0sQUpJiRF6Qyk6dghDebkFibOWYN13S+Dv54vU1Ay88NI72Lj+33h+yltYMP8V9E6IwYkTZ/DkUzMaLNdTWZs3rsTuPSnIzy/ChvUrXPnjYrvi1/U70DshBuPGPoTtO5Lr5SEiIiLP2syJs9u2J+OLr37BtOkLMStxAtq1C0bK4ZPoEBEGfz9fAEBAgBY55y9iy9Z9cDqd9bZiGuKprMKiYgQF+iPvYgGSDxzz+Pym5CEiIqLL2sxKisNpx8effI+ff1gGLy8lAKBYX4qsrBy8On0RnE4n/Pw1eGPOFJSWmqDz0zSrfE9lKRUK6LposGj+NMyZuxz+/losXjgNGo261vO7dAlvNA8RERG1wSDljtv6oSC/GDMSk7A0aSYAQKvzgbdahffefalW3l1/pMBgKHVbjkDgvnxPZVUbOrQ/hgzph3HjZ+PDFWswfdq4K8pDREREldrUxdxmTH8GaScz8cVXvwCoPC+kqNCA/cmprjx2ux294qNgMJQhLS2rXhkqlRJSqQSZWTm10j2VVfNfgUAApUoOh8MJAJDJJCgzGhvMQ0RERO61qRNnFQoZFi2YhidGv4pe8dHo1q0jli5JxMzXFiMgQAe73Y7Q0EAsnP8K5r/3MqZMfRvxcVHIL9C7ypBIxJg6ZTQmPvcG4uO6IiMjGzExnSCTST2WtW1bMpKWroJQKIRQKMDs1ycBAB59ZARefuV9iIRixERHus1DRERE7gmcTqfrK/3Iqd/BaLZeVYH3Dw7D5If9Wt2BXsovgkwqhY+PlyvNbnNAbyjBpYuFGD1mJpL3fuN6zGQsR1GxAb4aNVQqRaNllZdbYDZb4Otb+zwTu80Bh9MBiUTsMc+f4dV/HsO+oxevqgx/XwXUMglfNTVfQEIRFCotO6JKTCd/CBzsB/IsITYYDhsnCXnWOVIHjY+87a2kNCTAv/4HiUgshJ9Og/xLRfUeU6rkUKrkTS5LLpdBLpe5rUNUtavmKc+f4fdvF0Off/6qyjjH146b8ZVg+Oil7AgiomtAzC4A5AoZort1bNPHOOj+CUg+fnUrKX4+cnhLuZJSLe3ADygpZOhGRMQg5RrqEBGK/3z2jutvs9mCrOzz6BbVdgIXH78QyNRXN9wqrQo+ciknTHWf6sJhLL7IjiAiukaE7IL6Tp06iyf/PgM2mx3vvPcxDIayqyqvpcohIiJikEIAAKfTCZvNBqez8iSvJctW48uv/9uk59bMW7ccIiIiagNBSpHegEuXCuulV1RYcSGvAA6Ho8G04uJSXMgrcP1ts9lxIa8Adg9nlxuNZjiqggmJRIzXX5vgujLs8eNnYDKWN6l9NfPWLae6rXl12goABkMZzudegsVSwdlJREQ3tVZ9Tsqzk+ZCJpPCZDSjoLAYKz9+A1pfH/y+ZR9mz1mK7t07Q6fT4M15U+qlzXx1PO57YBJCggMRExOJ6dPGebyLMQCkpWVhZmISQsMCUW6+HIh06joCmzeuxOEjJ2vd1XjC+Ec9tu+nn7fUy1tdTnh4MH7bsBPLln+JqKgOOHkyE4sWvIrQ0AA88NAUhIT4w99fi+QDxy12N4oAACAASURBVDFpwig88vBwzlIiImKQ0tp8uHwWBFXXqZ/xWhLWfLsBT43+C6ZNX4AVH85Br57RACqvUVI3Ta8vQXb2BaxbuxRqtarBuxjb7XZMmjwPc2dPxsABPXH0aAbGjEus1Zb777uj1l2NPbVvwvhH3eatZjaVY2ZiEn5atwxhYUH48affMWvOUnywfBbOZOZg7ZokqNUqHDh4DOMnzGGQQkREDFJaI4FAgPT0bOzbfwSnT5+Dl0qBlMMnIZPJXMEIALdpdTV0F+Nz5/Jgs9oxcEDPq25fY1KOnIRW64OwsCAAwKBBCXh52gKYzLW3kfx0Wp5oS0REDFJaI5vNjhdefAfBwf54cOQwnM+9BKvVhmJ9KTQar1p53aXV1dBdjPPyCpp9V2RP7WtMsb4UKpXS9be3lwpOpxMlDEiIiIhujCBl06bd0OtLsHxp5bbLbxt3wWq1wVerRv4lfa287tLqauguxmq1F4oKDS3SvsZofL1RUmJ0/V1aZoRQKISPxpuzkYiIqIZW++seS0WF25/sxsdFwQkntm7b32BaXQ3dxbhnfDcYTWYcOHiswTbVvKuxp/a5y1ur/bFRMBhKcPpM5ZVKt27bjz69u0NxnS6XT0RE1Fq12pWUu+4cgHU/bML4iXMQER6K3btT8MjDwyGTSbFowTS8OmMxOkSEIijIDwvnv1IvLXHms3WCBs93MVYoZFi+NBGJs5aiU6f2KMjXIyI8pF6bat7VeNzYh9y2z13eyc8/7kpXKOV4+82pmDBxLjp0DMPZsxewNGkmZyIREVEdrf4uyCUlRphMZuh0Gkgkl2Mqm82OoqJi+PtrXb+wcZfmjru7GAOVF13LL9BDKpFA42H7peZdjRtqn7u8NVmtNuiLS+Cn00AovPYLWnNX5mJnyqWrKiNIp4IvL4vvkpb8A3JP78Mdo95mZ1ThXZCpMbwLMjXmhroLslqtglqtqpcuFosQEKBrNM0dd3cxBip/rePpsWo172rcUPvc5a1JIhE3WhcREdHNjJfFJyIiIgYpRERERAxSiIiI6IbW4uekmCw22B0i9mwrY6mwsROIiOjmDlI27c3Dpr157FkiIiK6KtzuISIiIgYpRERERAxSiIiIiEEKEREREYMUIiIiYpBCRERExCCFiIiIiEEKERERMUghIiIiYpBCREREDFKIiIiIGKQQERERgxQi8qiivAx2q6X+A04nTKX57CAiohYkZhcQNc/mb6ZDF9QVFZYyWCvKcXzPNyjIPYkO3YdB6e3PDiIiYpBC9OeTyr2gDeqMi2dTXGlZx7dAJJYguEMCO4iIqAVxu4eomcIi+9dLC2gXB7FEzs4hImKQQnT9BLTvAYlUWSsttFM/dgwREYMUouv8ohFJENzx8taOVO4N/9AYdgwREYMUousvpOPllZOQyD4QCPlSIiJikELUCmgDI6Hw9gMAhEZyq4eIiEEKUWshECA0si+8NMHw8QtnfxARXQP8CTLRFQqN7A+RWMqOICK6UYKU7pEajH8ggj3byiR9eQpncstaRVtuidfhllhNG+jVSJSbe0KuuPF/emyzO7HkizN8oRBR2w5SOoZ6oVt7dmxrExKgbDVBSpdwFSKCbW3oJXTjH4uTO79E1ArxnYmIiIgYpBARERExSCEiIiIGKUREREQMUjywWm0oKzNxRIlzhIiojWgT10n56xMvAxAgIECL06fPYezTD+GBkUOve7uWLFsNPz9fPP7YvZxpnCOcI0REN2OQcvhIOr75ciF69OiMnJw83DViPPr1i0VIsD8AwGazI79AjwA/LUTi2otHFy8WQCKVQOvr06S6Gior90I+vL2U8PZWAQCOHz+D3gkxDeYhzhHOESKiNhyk1BQWFgQ/nQYZGVkICfbH1m37sSjpc3TuFI7jJ05j7uzn0LdPD6SmZmD23OXo1q0j8gv0KMjX47tvk6DXl6BP/1E4uH8t1GoVdv2RgpmvLca2LZ97LMtqtWHM2EQAgEQixtQXnkR2di5SUk4gM+s8bHY7xo55sF6euNiunIGcI5wjREQ3S5BSUmKE3lCKjh3CUF5uQeKsJVj33RL4+/kiNTUDL7z0Djau/zeen/IWFsx/Bb0TYnDixBk8+dSMBsv1VNbmjSuxe08K8vOLsGH9Clf+uNiu+HX9DvROiMG4sQ9h+47kenmIc4RzhIjIszZz4uy27cn44qtfMG36QsxKnIB27YKRcvgkOkSEwd/PFwAQEKBFzvmL2LJ1H5xOZ71l9oZ4KquwqBhBgf7Iu1iA5APHPD6/KXmIc4RzhIioDa6kOJx2fPzJ9/j5h2Xw8lICAIr1pcjKysGr0xfB6XTCz1+DN+ZMQWmpCTq/5t07xlNZSoUCui4aLJo/DXPmLoe/vxaLF06DRqOu9fwuXcIbzUOcI5wjRERtMEi547Z+KMgvxozEJCxNmgkA0Op84K1W4b13X6qVd9cfKTAYSt2WIxC4L99TWdWGDu2PIUP6Ydz42fhwxRpMnzbuivIQ5wjnCBFRpTZ1MbcZ059B2slMfPHVLwAq9/yLCg3Yn5zqymO329ErPgoGQxnS0rLqlaFSKSGVSpCZlVMr3VNZNf8VCARQquRwOJwAAJlMgjKjscE8xDnCOUJE1MZXUgBAoZBh0YJpeGL0q+gVH41u3Tpi6ZJEzHxtMQICdLDb7QgNDcTC+a9g/nsvY8rUtxEfF4X8Ar2rDIlEjKlTRmPic28gPq4rMjKyERPTCTKZ1GNZ27YlI2npKgiFQgiFAsx+fRIA4NFHRuDlV96HSChGTHSk2zzEOcI5QkTknsDpdLq+ro2c+h2MZqv7nA4HCk7+DKVfZyj8ukAgdB/f3D84DJMf9mt1B3opvwgyqRQ+Pl6Xv+XaHNAbSnDpYiFGj5mJ5L3fuB4zGctRVGyAr0YNlUrRaFnl5RaYzRb4+tY+h8Buc8DhdEAiEXvM82eYuzIXO1MuXVUZQToVfOVSj4877FYc37MGAeFx8A+JhkDofqHu739pj4QoAedIK5ojTgjxwnuZV11OTCd/CBx8YyXPEmKD4bBxkpBnnSN10PjIm7mSIhRCJFHi4qFVEEmUUAbFwjukJ2Sa9jfEQQf4a+ulicRC+Ok0yL9UVO8xpUoOpUre5LLkchnkcpnbOkRVu2qe8rQVQpEEdnsFkjcug1TujdDIvgiJ7Asfv3DOEc4RIqJm8xikOB02OOy1V1Wk6qDKb35WE0rP7UHpuT0QK3XwCukJ7+B4iJW6G7IT5AoZort1bNMDba0oh91qvqoybBUCWAW2BvP4+kfi/Km9qCgvReaxzcg8thlemmCEduqHkMi+UKi0nCNERNQkHrd7ijO3Qp++oTlFQa7tiMeemojEZ2PYs61Mn4HjoM8/f30nm0AAv9AYzJs3DXcO8OegtCLc7qE/C7d7qDHN2u4JiHvc9d8VZXkoPv17veBEpmkPr5CeUAX1gI8usE12mtlsQVb2eXSLujG/TScMGYUjJ/OuqgyNtxxekoanjKEgC6ePbqwXnPgGdkZY5/4ICu8Jrc7vhuu/6vNPwkID+Q5CRPQnafATRyiWQxXUw/W39XT+5ScqdfAK7gnvkBt3m6c5Tp06izHjErFn15eYv/BTTJrwWK2TIpvLZrO3SDlNFRwRg9PFV7d6oWvkxFkAKC3Odf23l08QQjv3v+G2eeqOTWpqBiY8Nw/PT3oc/frF4vff92Ds0w+1aB1ERNTMIKXeakLhKajb9YNXSC/INO0ACG66DnM6nbDZbHA6K5crlyxbDT8/Xzz+2L2NPrdm3rrltIm+cThQcP4EImLuQGhk/xvmhNnGxmbV6p8x8i9D8dioETh9+iwslooWr4OIiNwsljT9w9mBoN5PQxc9suoXPS0foBQXl+JCXkGtb5sX8gpgr7N/WaQ34NKlwnrPr6iw4kJeARwOR4NpdevyVE81o9EMR9WHiUQixuuvTXBdrvz48TMwGcvrPcddG2vmrVtOdVvz3LTVYCjD+dxLV/zh+KcFKXCi/z0vIbrfqOsWoLgbb0/jW3MONDQ2hpIyaHy8AQCRke0xaeJfG62zJcf/RpoDRETXZSVFIBACgmtzgVqTsRz3PTAJIcGBiImJxPRp4zze8v7ZSXMhk0lhMppRUFiMlR+/Aa2vD37fsg+z5yxF9+6dodNp8Oa8KW7T6tbVv1+c23oAIC0tCzMTkxAaFohy8+VApFPXEdi8cSUOHzmJlJQTyMw6D5vdjgnjHwUAt23cufNgvbzV5YSHB+O3DTuxbPmXiIrqgJMnM7FowasIDQ3AAw9NQUiIP/z9tUg+cByTJozCIw8Pb50Rr1B0Xet3N97u5lH36M615kB0t0iPY5N6LKPWY106R+Dd9/6Njb/922OdLTX+XbqEw2g031BzgIjougQp15KlogLZ2Rewbu1SqNWqBm95/+HyWRBU3TxlxmtJWPPtBjw1+i+YNn0BVnw4B716RgOovHBW3bS6dUmlYgwbPs5tPXa7HZMmz8Pc2ZMxcEBPHD2agTHjEmu1+/777sCv63egd0IMxo29fI6CuzZOGP+o27wAYDaVY2ZiEn5atwxhYUH48affMWvOUnywfBbOZOZg7ZokqNUqHDh4DOMnzOEHlBvuxtvTPFr7TVKt+QbA49jce89g/PzLVtdjv2/Z12CdLTn+X3+5ABUVVs4BIrpptcp79zR0y3uBQID09Gys/uJnnD59DoUFeqQcPgmZTFbrg8JdWnPqOZqaAZvVjoEDeja7/e7a2ODxHjkJrdYHYWGV16EZNCgBBw4eh8lcexvJT6eFwVDGWethLN3NAbfjW1h8zepsyfE3m+pvI3IOEBFXUq4zT7e8l0qkeG7ymwgO9seDI4fhfO4lWK02FOtLodF41SujblpT61EqFMjLK4DOT9Pstttsdrzw4jv12thYO1Qqpetvby8VnE4nSvhh1Kw5424OuB3fOpewb8k6W3L8DSVlkMmkHFwiYpDSmni65f1vv+2EXl+C5Usrt11+27gLVqsNvlo18i/V/rbqLq2p9QCAWu2FokJDs9u+adNut21siMbXGyUlRtffpWVGCIVC+Gi8OUObyN14expfvb7kmtXZouPv443ycgsHl4huWq1yu8fTLe8tFRVuf7IZHxcFJ5zYum1/g2lNrQcAesZ3g9FkxoGDxxpsq0wmQZnx8geMpza6y+tqa2wUDIYSnD5zDgCwddt+9OndHQrew6XJ3I13Q+Pb1LFpbp0tOv4Kjj8RcSWl1fF0y/s3503Buh82YfzEOYgID8Xu3Sl45OHhkMmkWLRgGl6dsRgdIkIRFOSHhfNfcZvWlHoWzn8FCoUMy5cmInHWUnTq1B4F+XpEhIfUa+ujj4zAy6+8D5FQjMnPP4677hzgto3u8lZTKOV4+82pmDBxLjp0DMPZsxewNGkmZ2cz54y78XY3vokzn210HK+0Tk9zlONPRNR8Dd67x3BmG8KHzm5WgfcPDsPkh1vusufubnlfUmKEyWSGTqeBpMZl2m02O4qKiuHvr3X9usJdWlPrASov3pZfoIdUIoHGw/aL3eaAw+mo1RZPbXSXt5rVaoO+uAR+Og2EwpZd5Jq7Mhc7Uy5dVRlBTbjibFP8/S/tkRB1bS4E6Gm8PY1vY+N4pXW2tvFvDO/dQ38W3ruHGtOse/dcb+5uea9Wq1w/Ha21LCQWISBA12haU+sBKn+p4emxaiKxEKI6O2ee2ugubzWJRNxoXdQwT+PdlH5taGyaWyfHn4jo6gnZBURERMQghYiIiIhBChEREd3IWvyclHMXjTibH8CebWUuFZlbTVuyzpsRFujTJvo1I+M0tFpf6HQ39rkkVpuzVbUnupMXAv3EfOG2ImUmB/YfKWFH0I0dpBxK02PsG3r2LHm0LTkf25Lz28SxbFz9IiJjhyMy9m4ObAuK6SSBrzcvZNeaVNil2H+E/UB/Lm73EBEREYMUIiIiIgYpRERExCCFiIiIiEEKUSsjEvNGgEREDFKIWiGBkC8jIiIGKURERMQghYiIiIhBChERERGDFCIiImKQQtTG2SrM7ARqdcxmC06cPMOOIAYpREStidVqQ1mZ6abug1OnzuLJv8+AzWbHO+99DIOhjBODbki8zSgRtRl/feJlAAIEBGhx+vQ5jH36ITwwcuh1b9eSZavh5+eLxx+790+t1+l0wmazwel0XNd2EDFIIaJW7/zZk/DRBMBLrb0m5R8+ko5vvlyIHj06IycnD3eNGI9+/WIREuwPm82O/AI9Avy0EInrLyJfvFgAiVQCra9Pk+pqqLzcC/nw9lLC21sFADh+/Ax6J8Q0mKeuIr0BNqsNAQG6ZvWB0WiGoyookUjEeP21Ca7H3LWDiEEKEREAm7UCHy54FhGd4tEtbhC6RveHWCK9JnWFhQXBT6dBRkYW0tOzsCjpc3TuFI7jJ05j7uzn0LdPDwBAamoGZs9djm7dOiK/QI+CfD2++zYJen0J+vQfhYP710KtVmHXHymY+dpibNvyObZu2++2PKvVhjFjE10BwtQXnkR2di5SUk4gM+s8bHY7xo55sF6euNiutdr+7KS5kMmkMBnNKCgsxsqP34AAAo/tAYC0tCzMTExCaFggys3lrrI6dR2BzRtX4vCRk7XaMWH8o5yQxCCFiKhauw7dIZJIcSb9IM6kH8RG2UeIir4F0fGD0b5jdwgELXeaXEmJEXpDKUJDAvDU2ESs+24J/P18kZqagRdeegebN66E3W7H81PewoL5r6B3QgxOnDiDJ5+a0WC55eUWJM5a4ra83XtSkJ9fhA3rV7jyx8V2xa/rd6B3QgzGjX0I23ck18tT14fLZ0EgEAAAZryWhDXfbsCoR+72mN9ut2PS5HmYO3syBg7oiaNHMzBmXGKtPPffd0etdhAxSCG6CRz74ysUXkhjRwA4vV8GOBvOI6wRiFgt5Th6aAuOHtoCbx8douMGIyZ+MADfK27Dtu3JOJKahh07DmJW4gQUFBajQ0QY/P0qywwI0CLn/EUUFhXj7NkLcDqdzdoCSTl80mN5QYH+yLtYgOQDxzyW2ZQ8AoEA6enZ2Lf/CE6fPgcvlaLBNh1NzYDNasfAAT05CYlBChFV8guJAgDYLCZ2BgCLyNZokOK0292mO+w22G022KzWq2qDw2nHx598j59/WAYvLyV++20nsrJy8Or0RXA6nfDz1+CNOVOgVChwMa8QOj9Ns8ov1pd6LE/XRYNF86dhztzl8PfXYvHCadBo1LWe36VLeIN5bDY7XnjxHQQH++PBkcNwPvcSrFZbg23Kyyto9nEQMUghauP63j2VnVBDTCd/CByeH7fZrFjy1ujLb0ASKbpG90e3uEGI6BQPYQvcrPGO2/qhIL8YMxKTsDRpJrQ6H3irVXjv3Zfq5fVWe8FgKPWwmuG+/IbKA4ChQ/tjyJB+GDd+Nj5csQbTp41rVp5Nm3ZDry/B8qWV2zW/bdwFq9XmsT0AoFZ7oajQwAlIbQ6vk0JEf5qsjBTYbTaER8ZixEPP4/kZn+LeR15Axy69WiRAqTZj+jNIO5mJL776BXGxXVFUaMD+5FTX4/aq1Zxe8VEwGMqQlpZVrwyVSgmpVILMrJxa6Q2VV/2vQCCAUiWHw1G5rCSTSVBmNDaYp5qlosL1k+GmtAcAesZ3g9FkxoGDxxrsl5rtIOJKChFRDQqlNya8/CG8fXTXth6FDIsWTMMTo19Fr/hoLF2SiJmvLUZAgA52ux2hoYFYOP8VKJRyzH/vZUyZ+jbi46KQX6B3lSGRiDF1ymhMfO4NxMd1RUZGNmJiOkEmk3osb9u2ZCQtXQWhUAihUIDZr08CADz6yAi8/Mr7EAnFiImOdJun2l13DsC6HzZh/MQ5iAgPxe7dKXjk4eEe21N9vMuXJiJx1lJ06tQeBfl6RISH1OuXmu2Y/PzjnJDU6gmcTqcrjB859TsYzZX7wcWZW2E4sw3hQ2ezlwgAEKRTwVcuZUeQR41t9zTVI3f7wtfb0uLtu5RfBJlUCh8fr1rpdpsDekMJLl0sxOgxM5G89xvXYyZjOYqKDfDVqKGqcwKru/LKyy0wmy3w9VXXq8PhdEAiEXvMU1NJiREmkxk6nQYSibhJ7XE6ncgv0EMqkUCj8XZbbs12NEeFXYrPvi++6jFIiA2Gw+bgi4U86hypg8ZHzpUUIrq5BPi7v4icSCyEn06D/EtF9R5TquRQquRNLk8ul0Eul7mtQ1S1w+4pT01qtQpqtapZ7REIBB6P0V07iFo7zlQiouoAQyFDdLeO7AgiBilERK1Lh4hQ/Oezd9gRRAxSiIiIiBikEBEREYMUIiIiIgYpRERExCCFiIiIiEEKERERMUghIiIiYpBCRERExCCFiIiIbly8dw8RtTrf/qZvE8dhNpZi488fof/gBxEYcqNfbt/UqlqTEG2BUFDBF0trmu8VKqRmtOzaB1dSiIiuEavNgrTU3TCZStgZRAxSiIhaH4lEzk4gYpBCREREDFKIiIioHrPZghMnz/ypdZqM5cg5f5FBChERUVtis9lhNltarLxTp87iyb/P+NPan5qagbvueQY7dx5EZtZ5fLLyOwYpRERENzK7zYHZc5fjtiFP4fEnX8G773983du0ZNlqfPn1f5v1nFWrf8bIvwzFY6NGwGG3w2KpuOZ1/ln4E2QiomvE6XSwE1qxRf/8DOnpWdi88WPI5TLYbZfHq6LCiqIiAwICtBAKa3+fNxjKUGY0wU+ngUwmrfWY0WiGoxnjXlFhRWGRAYFV9Rw/fga9E2Jq5cm9kA9vLyW8vVVuyzCUlKFz53AAQGRke0ya2L7W48XFpTCXWxAc5Oe2PHd1MkghImrjKsrL2QmtlMVSgVVf/IxPVrwBuVwGABCJK4OR3zbsxLLlXyIqqgNOnszEogWvokuXcBiNZjzw0BSEhPjD31+L5APHMWnCKDzy8HCkpWVhZmISQsMCUW6+PO56fQn69B+Fg/vXQq1WYdcfKZj52mJs2/I5ft+yD7PnLEX37p2h02nQt08PpKScQGbWedjsdowd8yDGjE0EAEgkYkx94UnExXatdRz//XV7red06RyBd9/7Nzb+9m+YjOW474FJCAkORExMJP7x4lP1ysvOzq31/AnjH2WQQkREdD2lpWXBbLLU+9A3m8oxMzEJP61bhrCwIPz40++YNWcpvv5yASoqrDiTmYO1a5KgVqtw4OAxjJ8wBw8+MAyTJs/D3NmTMXBATxw9moEx4xIbrL+83IJp0xdgxYdz0KtntCv91/U70DshBuPGPoTtO5KRn1+EDetXeCzn3nsG4+dftrqe8/uWfZcDsYoKZGdfwLq1S6FWq9yWFxfbtVadrQ3PSSEioptOsaEEMpkUUqmkVnrKkZPQan0QFhYEABg0KAEHDh6H2VR/VcxPp4XBUIajqRmwWe0YOKBnk+tPOXwSMpmsVoBSV1CgP/IuFiD5wLEWOeaWLo9BChER0TWgVnvBYqlARYW1dvCiL4VKpXT97e2lgtPphKGkzGNZeXkF0Plpmhck6Uuh0Xg1mKdLl3Asmj8Nc+Yux5ixiSguvrorF7d0eQxSiIiIroGunSMglUpw+EharXSNrzdKSoyuv0vLjBAKhfDx8W4w4CkqNLh9TCBw/xxfrRr5lxq/R9XQof3x84/LIRQK8eGKNVd93C1dHoMUIiKiFqZQyvHwQ3dh0eLPUF5eeY0Uu82B+NgoGAwlOH3mHABg67b96NO7OxQKmceyesZ3g9FkxoGD9bdRVColpFIJMrNyaqXHx0XBCSe2bttfK10mk6DMWBkk2e32qkBHAKVKDofDeVXH7Km8mnW2NjxxloiIbkozXh2HGa8l4Y6hYxAY5IfY7l0wb+7zePvNqZgwcS46dAzD2bMXsDRpZsMBj0KG5UsTkThrKTp1ao+CfD0iwkMAVP2KZspoTHzuDcTHdUVGRjZiYjpBJpNi0YJpeHXGYnSICEVQkB8Wzn8Fjz4yAi+/8j5EQjFioiORtHQVhEIhhEIBZr8+6aqOd9u2ZLfl1axz8vOPt6oxEjidTldoNnLqdzCaK/fnijO3wnBmG8KHzuZMJgBAkE4FX7mUHUEexXTyh4CXBnHJzzuLT5e9iMefeQth4VHsEAAJscFw2DxPklWfLYNcJsfA24YjOKSd53KiLRAKKlqkTWVlJlgqKqDTXj6vxGq1QV9cAj+dpt51UjxxOp3IL9BDKpFAo6m9PWQylqOo2ABfjRoqlcKVbrPZUVRUDH9/LQRVe0N2mwMOpwMSiRjl5RaYzRb4+qpb5Fg9lVezzitlrlAhNePqN2g6R+qg8ZFzJYWIiFqXuPi+eGfeS/j+28/QuWt3DBh0JwYMvhNeXuprVqeXlxJeUNZKk0jECPDXNu9bv0Dg8TlKlRxKVf27YYvFIgQE6GqlicRCiKrOxpDLZa7ruLQET+XVrLM1YZBCRHSN5Z0/DbFYwo4AcEZpgNPueSVFJr38AZqRloqMtFSs/mwp4nvdgkG3342eCbdCImFf3iwYpBARXWO//7qSnXAVbDYbkvftQPK+HfDzC8RzU2chIZrbZwxSiIjoivnqgjB64vvsiBq6dfZrcCXFaCzDW3Om1koTCkXoHpuAQbffjT59B0EmVwCwsDPdMJstyMo+j25RHRmkEBFRA2+wEimCQiPZETV07NTwibN7/9jq+u/wDp0x+Pa7ccuAofDV+rHzmuDUqbMYMy4RyXu/gc1mx/yFn2LShMfg4+PFIIWIiOhqpJ08jPsffAIDBg1H+/DWsxqwZNlq+Pn54vHH7r1h+tLpdMJms7nuxn0jHgODFCIiajWeHDPF9VPc6yn3Qj68vZTw9lYBAI4fP4PeCTG18hTpDbBZbfV+nQMAFy8WQCKVQOvrUyvdZrMjv0CPAD+t667L7jRUtidGoxkO5+VVKolEjNdfm+D6290xMEghIiJqousdoFitNowZm+j6kJ/6wpPIzs5FSsoJZGadh81uz/FaeQAAIABJREFUx4Txj+LZSXMhk0lhMppRUFiMlR+/Aa2vD44cScfcN/6Fbt06Ir9Aj8KCYqxdsxhA5dVrFyV9js6dwnH8xGnMnf0c+vbpUa8N7soWQIA+/Ufh4P61UKtV2PVHCma+thjbtnyOtLQszExMQmhYIMrNtW+E2KnrCGzeuBKHj5ysdwwMUoiIiG4gu/ekID+/CBvWr3ClxcV2xa/rd6B3QgzGjX0IAPDh8lmugGrGa0lY8+0GPPP0w3h+yptYtPBV9E6IwYkTZ/DkUzMAVF5ELXHWEqz7bgn8/XyRmpqBF156B5s31v/ll7uyRz1yt9v22u12TJo8D3NnT8bAAT1x9GgGxoxLrJfv/vvuqHcMDFKIiIhuIEGB/si7WIDkA8ca3BoRCARIT8/Gvv1HcPr0OXipFEg5cgICgcDt81IOn0SHiDD4+/kCAAICtMg5fxGFRcW1rnTrqWxPjqZmwGa1Y+CAnm1yPBikEBERVenSJRyL5k/DnLnL4e+vxeKF06DR1L7arc1mxwsvvoPgYH88OHIYzudegtVqQ/4lPXR+GrflFutLkZWVg1enL4LT6YSfvwZvzJkCpULRpLI9ycsr8FgngxQiIqI2ZujQ/hgypB/GjZ+ND1eswfRp42o9vmnTbuj1JVi+tHJb5beNu2C12qD28UJJSZnbMrU6H3irVXjv3ZcarNtT2Z5O1VGrvVBUaGizYyHkdCQiIqpkt9sBVG65KFVyOByV9+CVySQoMxoBAJaKCtfPemvqGd8NxcVlyMjIrvdYXGxXFBUasD85tV5dNXkqW6VSQiqVIDMrp16dRpMZBw4ea/TYah7DjYIrKURERFW2bUtG0tJVEAqFEAoFmP36JADAo4+MwMuvvA+RUIxxYx/Cuh82YfzEOYgID8Xu3Sl45OHhUChkSFr0Kl78f/buPDDKKs/3/7uK1JIUqVRSqQRIxoCENcjSiNqC2i0qOF5bbAX79qg9DgwCKtC2IkJkEacVEcglMs04jtP+tL3dCEO3NCBeFwLaqCwdFtnCEhBIyL5VKkstvz+ASEhVEiBKls/rL+rUc855zvd5Qr55lnN+s5D+/XpSWFR6QYJgJn1ZKrNmLyUuzonP5yMhIZ7Fi56t1/9ddw4P2rbJFMb0qY8y+YkFDB7Uh6ys46SkJBMebmF5eiqpc9JJTr6Ggvxiuid1Czq2C8fw1JO/bBPHwxAIBALnP4yZvhq3pxaAkmObKD2aQdLIuTprBYAuThvRVrMCISGlJLsw+BUHCW3owMZnnG12O/2rMRpqvpd9rKqqxuOpJjq6/rMoPq8ff8CPyXT27/uyMjeVlR6cTkddGZydRK2iopKsw8eZOv1lPs94p147eflFWMzmRmeBDdV2pbuKopJSoh12bBc8UBsIBMgvKMZsMuFwRIZs9+IxtCRPjY29WVd+g6ZXTyeOKKuupIiIiFzMarVgtVoalHcKM9Lpgqck7HYbdrut3jYnT50hoVscNls4q1Z/FHQelDhXTJP7EKxtgAiblQibteEVB4OhWe1ePIbWTkmKiIhIC3nzv1bz5Ve78Hq99OvXkxfnPqmgKEkRERG5+ubNmaIgtCC93SMiIiKtUotfSRnQ08HE+7srsq1M2nuHOXq6QoEQkXahqCwck8nabsZTXl7B7//7HR54cAzdunVtm2NwAwRad5JybUJn+l2jH6DWpltchJIUEWk3jp1sX6+RFRRU8Pv/fpek5JvpW91FB/gc3e4RERERJSkiIiIiSlJERERESUpbs2dPFjU1tTr6IiIiSlJal/sfnEpOToGOvoiIiJKUKzP81kfI3HWg3QV/2evv8t4f1+ksFBERaatJSll5BV7vd0taFxeXcTonH9+5Rap8Ph85uQV4PNUN6uYXFJOXX9Ro+17v2fq+IIteNbevxtooLa3g1Ok8qqvrL4a1b99RKt1V9cpO5+RTXu7WmSkiIh1em5oW3+328LP7n+AfErvidDrYs+cQo0ffwrZtu+nWLZ6vv97Nb55+jDH33Y7b7eGeeyczdGgKZpOJrMPHWfTqM/TonlCvzU0Z21iS9ja9kpPYt/8I8+c+wQ3Drrukvhpr4/4HptKtmwuXK4btO/YxZdJDjH1wFB+s/YzMzP0cyz6F1+dj/GM/57HxqQBnl+Se9giDBvbRGSoiIkpS2oKamlqOH89hzap07HYbX361i4cfncm+PR9gNpv49NOvmL/g3xlz3+3U1NRy8tQZ1q9dQYTNyoYNW3jm2UWsfj+trr2qqmpS5yxjzepluGKj2bs3i2lPv8wnH73V7L5GjxreaBtHj51k1co07HYbO3Z+w8RJ8xj74Ch+du9PWb9hC9cPTWHC+AfYvGU7+flFbNzwhs5KERER2viDs127xAFgNpsAcLliKAtxq2TkyJvYszeLvLzCurLMXQfo0T0RV2w0AHFxMZw8dYbCopJm93UpbcQ6YygtDT7ra5d4F7lnCti+4xudlSIiInSgVZDNZhPWcDOFRaV1ZSXF5WRnn+S5mUsIBALEuhwsmDeViPBwqqqqm9VuS7QB0Lt3EksWzWDe/OW4XDEsXTwDh8OuM1RERJSktHcVFZV4KquJj3fWlcU4o4i021j4ytMNtm9ugtESbZw3cuRN3H77jUyYOJcVb6xk5owJOkNFRKTD6jDzpLy/aiM3/3gQMdFRdWWDBvahqLCUbdv31pX5fL5LavdK2rBYTFS43fXqGAwGImxW/P7A1QlUwK+fChERaRXa/ZWUWS+k4amqprSknLQlMy9KEsykL0tl1uylxMU58fl8JCTEs3jRs81u/0raGDf2bp559lU6GcNI6d+TtPR3MBqNGI0G5r4w5QeLUa2nGPfpv1OZf5Cu14/HEGbWT4aIiFx1hkAgUPcn+5jpq3F7zk4XX3JsE6VHM0gaOfeSGvzZrYk89WDsVR9YcXEZw256iK1fvIfZZCIqqnOj2+flF2Exm5vcrqXb8Hn9+AN+TKYwqqqq8XiqiY5u+WdR5r91ms8z8+o++71VuHP3UHH671QVZwMB7P9wE87+94Vso4vTRrRVCYyElpLswqCLcdKIoQO74vfqJLlYQcEZnpr4AHP/7d/p229gh45Fr55OHFHWjnElxRYeToTN2uR2ca6YK+7rctroFGak07m7blarBavV8v0FI+CnsuAQFad3Upm3n4Dfe9HOmPAUHg5ZvaQ2HJ85TP+bSEjZ5GAIKA4Smtl/Cr9PSUrDJCVXQQii3f7GCQvrxIABvTB2MugoA9WVFeTt+r+4z3wDBP8tUpa9hbLsLSHb0I+QNOVrhUBElKQ0LTLSxp9XL7sqfe/Zk0WfPt3r5lRpDSwRnYkb/E94PUVUnM6kIieTWnd+vW0c1/6EyIRhIdtwRYdjt5j0UyMh9U5y6naPNGpAXxd+ny63hRIdE6sgdIQk5Wq6/8GpfPLRWyQldW19Bzw8BkfP23H0vJ3q0hNnE5bcXfhrKqkuyyG6V+hbVpbONiL0TIo0IipGz6RI4+K66JkUUZJyxZa9/i6xsdH88hf3tNsxWqKuwRJ1Dc6+/4vK/AO4z+zBV+uhkylcJ4CIiFx17XKelJqaWnJyC/D7/fXKci8qOy/YKsXBViguKSknJ7egWW1eqNWvbGwwEhHXH9d1DylBERGRVqPdXUn59LOvmTsvnQEDeuF0Onjpxal8uPFzXl/+Hn379uDAgWMsee05evdOCrlKscVirrdC8aP/9DPuvX8K3brGk5LSk5kzJoRs80K1tV6tbCwiIqIk5ew09DNmvsYbK+bxoyH9AfBUVjErNY0P1rxOYmIX/vLBp8yZl84f33st5CrFO75+v94KxcXFZfVWRG6szQtt/TJTKxuLiIhcpnZ1uydz1wEsFktdggKQufsAMTFRJCZ2AeCWW4ayY+c+PJVVDeo3tkpxvX6a2aZWNhYREVGSApxdkdjh6NygzGaLqPsc2dlGIBCgtKziivppTpsXrmz82PhUSkrKdMaJiIh0xCQlOsZOfl5xvTJHdCRlZd89tFpe4cZoNBIVFXnZ/VxKmyNH3sTavyzHaDSy4o2VOuNEREQ6YpIyeFBfAgTYlLHtu7KBfSktLePI0W8B2JSxjWHXDyA8vPHp5y9cobhBP81ss9WsbCwiItIGtasHZy0WM0tem8Fzzy+lR/cEunSJZfGiZ/ntS9OZNHk+Pa5N5MSJHNLTZjXZ1oUrFD/8T/+r3nfhEdZmtZmRsf2qrWwsIiLS1rXLVZC9Xh9FRSW4XDEYDGfX7qmt9VJcUkas04HR2LwLSBeuUBxMc9r8Plc2vhQXr4J8ObQKsjRFqyBLU7QKsjSl3a+CHBbWibg4Z70ykynsklcpvnCF4mCa0+b3vrKxiIhIO2VUCERERERJioiIiIiSFBEREWnLWvyZlMpqLz5/J0W2lamu8SoIItJu2MKNGPWrplWprQ1QVd2yU220eJLy8Ve5fPxVbpsPdv43/wOAK+XnOvNERFqZvj08GA01CkQr4qmxsTerZW/QhCmswfmryxUEERGRq0jPpIiIiIiSFBERERElKSIiIt8Dj6ea/QeOarxKUkRERK6M1+vD46lusfYOHz7BI796vsPE72qOVw/OiohIu+Tz+nnx337Hx598SVxcNDfeMJCZMyZc1X1a9vq7xMZG88tf3KMDpCRFREQ6qiX/5/ccOpTNJx+9idVqwXfBwoY1NbUUFZUSFxdTb4HY0tIKKtyVxDodWCwNF1R1uz34A81fILGmppbColLiz/Wzb99Rrh+aUm+b0zn5RHaOIDLSFrKdYNt4vT7yC4qJi42hU5gxZJ+NjbepMV/qeJWkiIiINKG6uoZ3/rCW/3pjQd0ir+d/kX+48XNeX/4effv24MCBYyx57TkSEuK4/4GpdOvmwuWKYfuOfUyZ9BBjHxwFwMGD2cxKTSMhMZ4qTxUAxcVlDLvpIXZuW4XdbuOLv2Uya/ZSMj57G4BPP/uaufPSGTCgF06ngxuGXUdm5n6OZZ/C6/Mx/rGf89j4VODsgrXTpz3CoIF96o2jttYbdJtNGdtYkvY2vZKT2Lf/CPPnPsENw65r0OdLL04NOt7evZNwuz0hxxxsvEpSREREWsDBg9l4Kqsb/NL3VFYxKzWND9a8TmJiF/7ywafMmZfO75bP4eixk6xamYbdbmPHzm+YOGkeYx8chc/nY8pTLzJ/7lOMGD6EPXuyeGxCaqP9V1VVM2Pma7yxYh4/GtK/rnz9hi1cPzSFCeMfYPOW7eTnF7Fxwxsh29n6ZWaDbaqqqkmds4w1q5fhio1m794spj39Mus++F2DPkON94/vvUZNTW3QMf/8/jsuebzfFz04KyIi7U5JaRkWixmz2VSvPHP3AWJiokhM7ALALbcMZcfOfVRedLUg1hlDaWkFAHv2ZuGt9TFi+JBm95+56wAWi6VegnKxLvEucs8UsH3HN5e0TeauA/TonogrNhqAuLgYTp46wyefftWgz1Dj9VQ2vDpyfsyXM15dSREREWkmu70z1dU11NTU1ktUSorLsdki6j5HdrYRCAQoO5eQBJObW4Az1nFpSVJxOQ5H50a36d07iSWLZjBv/nJcrhiWLp6Bw2FvcpuS4nKys0/y3MwlBAIBYl0OFsybSk1NbYM+Q423tKwi6DM3lzteXUkRERFppj69umM2m9i1+2C9ckd0JGVl7rrP5RVujEYjUY7IRhOeosLSBuUGQ+j+o2Ps5OcVN7mfI0fexNq/LMdoNLLijZXN2ibGGUWk3cbCV57m1YW/YcYz4xk3dhTdurka9BlyvFGXPl4lKSIiIi0gPMLKgw/cxZKlv6eq6uwcKT6vn8ED+1JaWsaRo98CsCljG8OuH0D4uYdrgxkyuB/uSg87dta/LWOzRWA2mziWfbJBncGD+hIgwKaMbfXKLRYTFe6zSYPP5zuX7BiIsFnx+xuuIBxsm0ED+1BUWMq27XvrbResz5DjDb/08V4Nut0jIiKtxqo//hfRMS5uvPkndO5sv6K2nn9uAs/PTuOnIx8jvkssAwf05sX5T/Lbl6YzafJ8elybyIkTOaSnzWo84Qm3sDw9ldQ56SQnX0NBfjHdk7qdfdtm6qNMfmIBgwf1ISvrOCkpyeeSETNLXpvBc88vpUf3BLp0iWXxomcZN/Zunnn2VToZw0jp35O09HcwGo0YjQbmvjClQd8ZGdsbbGOxmElflsqs2UuJi3Pi8/lISIhn8aJng/bZUuO9GgyBQKAudRszfTVuTy0AJcc2UXo0g6SRczvkD8qZnWdfIYv/0a/0v8Y5XZw2oq1mBUJCSkl2YfArDhLa0IFd8XtDnyTbv97C4leex2Qy8aPrhzPitlEMGXoznTp1qt9O/2qMhppm9VlRUUl1TQ3OmO+es6it9VJcUkas09Fg3pBQAoEA+QXFmE0mHBfcHqp0V1FUUkq0w47NFl6vjtfro6ioBJcrBsO5+0M+rx9/wI/JFEZVVTUeTzXR0aETssa2ycsvwmI2ExXVudE+W3K8oXhqbOzNuvIbNL16OnFEWXUlpSm+Wg++Wo8Ccf7ErzFQa/AqEBL6P1NPhZIUaSJhKCfQSJJyzTU9z/1SreWrrZv4ausmOne2M/zWOxl+y5306jPgkvvs3DmCzkTUKzOZwohzxVzaX/UGQ9A6ETYrETZr0DphYZ2Ii3PWK+sUZqTTuactrFZL3TwuoTS2TbD9CdZnS473h6QkpRHVJcc58emLCsQ5JxQCacL/Uwjke0lsyti4fjUb168mISGJCZNnMLR/XwWmA1CSEkJUj5/QuduPFIgLOCKtdDbplJHQErvYMQQUBwnt2mscBPyhT5KqKg8rXv9tg/Jrkq5l+C2jGHHrXcTEuoBqBVNJSsdljU5SEC7i1DMp0oQ+eiZFmtDUMyk7t/+t7t/RMbH8ePhIbv3JaJJ69FLwmsHjqSb7+Cn69b1WSYqIiEhLytyxlRG33sUtPxnNgIFDMRo7KSiX4PDhEzw2IZXtX/0Jr9fHosX/zZRJv6j3YK2SFBERkcvwyL9MxWQytbr9Wvb6u8TGRvPLX9zTZmIZCATwer0Ezq1i3BbHoMncRESk1WgtCcrpnHzKy7+bqXXfvqNUuuuvd1NUXEpeXmHQ+mfOFFBU3HDWVq/XR05uAT5v4/dFG2s7FLfbgz/gvyCWYbwwe1LdVPvBxtDa6UqKiIjIObW1Xh4bn1r3S376tEc4fvw0mZn7OZZ9Cq/Px6SJ43h8ynwsFjOVbg8FhSW89eYCYqKj2L37EPMX/Dv9+l1LfkExhQUlrFq5FDg72+uStLfplZzEvv1HmD/3CW4Ydl2DfQjWtgEDw256iJ3bVmG32/jib5nMmr2UjM/e5uDBbGalppGQGE/VRQslJve5m08+eotduw80GIOSFBERkTZk65eZ5OcXsXHDG3Vlgwb2Yf2GLVw/NIUJ4x8AYMXyOXUTpT0/O42V72/kX//lQZ6c+hJLFj/H9UNT2L//KI/88/PA2QnZUucsY83qZbhio9m7N4tpT7/MJx+91WAfgrX90NjRQffX5/Mx5akXmT/3KUYMH8KePVk8NiG1wXY/u/enDcagJEVERKQN6RLvIvdMAdt3fMP1Q1NCbmcwGDh06Dhfb9vNkSPf0tkWTubu/RgMhqD1MncdoEf3RFyx0QDExcVw8tQZCotK6s2EG6rtUPbszcJb62PE8CHt8ngoSRERETmnd+8kliyawbz5y3G5Yli6eEbdMx3neb0+pv36Zbp2dfHzMXdw6nQetbVe8vOKccY6grZbUlxOdvZJnpu5hEAgQKzLwYJ5U4kID29W26Hk5haE7FNJioiISDszcuRN3H77jUyYOJcVb6xk5owJ9b7/+OOtFBeXsTz97G2VDz/6gtpaL/aozpSVVQRtM8YZRaTdxsJXnm6071Btn7v704Dd3pmiwtJ2eyz0do+IiMg5Pp8POHvLJcJmxX9udlyLxUSF++zbPtU1NXWv9V5oyOB+lJRUkJV1vMF3gwb2oaiwlG3b9zbo60Kh2rbZIjCbTRzLPtmgT3elhx07v2lybBeOoa3QlRQREZFzMjK2k5b+DkajEaPRwNwXpgAwbuzdPPPsq3QyhjFh/AOs+fPHTJw8j+5JCWzdmsnYB0cRHm4hbclz/Po3C+nfryeFRaUXJAhm0pelMmv2UuLinPh8PhIS4lm86Nl6/d915/CgbZtMYUyf+iiTn1jA4EF9yMo6TkpKMuHhFpanp5I6J53k5GsoyC+me1K3oGO7cAxPPfnLNnE8DIFAoG4RhTHTV+P21AJQcmwTpUczSBo5V2etANBF0+JLE1I0Lb40oalp8ZvdTv9qjIaa72Ufq6qq8XiqiY6u/yyKz+vHH/BjOreGWVmZm8pKD06no64Mzk6iVlFRSdbh40yd/jKfZ7xTr528/CIsZnOjs8CGarvSXUVRSSnRDju2Cx6oDQQC5BcUYzaZcDgiQ7Z78RhakqfGxt6sK79B06unE0eUVVdSRERELma1WrBaLQ3KO4UZ6XTBUxJ2uw273VZvm5OnzpDQLQ6bLZxVqz8KOg9KnCumyX0I1jZAhM1KhM3a8IqDwdCsdi8eQ2unJEVERKSFvPlfq/nyq114vV769evJi3OfVFCUpIiIiFx98+ZMURBakN7uERERkVZJV1JEpNX5yY0OEuIMCkQrUuY2sPbTolazP6cLrJjCwttNfD2VHj766CNG3DICp9PZJsdQ4QkAASUpItK+uaIN2KzVCkQrYjK1rjf7cvJa/hfi1VRQUMKrrywkPDKJvv2idcKdo9s9IiIioiRFREREREmKiIiIKEkREZEflsdTzf4DRxUIUZIiIiKty+HDJ3jkV88D4PX6eHnhm5SWVigwoiRFRKQtuudnk1nxxsp2N65AIIDX661bPXfZ6+/y3h/X6YCLkhQRkbZg9+5DAHyw9tOg35/Oyae83N1kmdfrIye3AN9Fi+Q1t/7FiopLycsrvKSxuN0e/IHv+jeZwnhh9iQcjrML4u3bd5RKd5UOurR5midFRDqEdRs28+jD9/G7//gThw+fIDn5GgBqa708Nj617pf99GmP0L9fzwZlgwb2YVPGNpakvU2v5CT27T/C/LlPMGRwv2bXv9jjU+ZjsZipdHsoKCzhrTcXYMDAsJseYue2VdjtNr74WyazZi8l47O3OXgwm1mpaSQkxlPlqZ+EJPe5m08+eotduw+QmbmfY9mn8Pp8TJo4TgdflKSIiLRWgUCAjRs/Z9X7aRzKymb9h5uZ+uTDAGz9MpP8/CI2bnijbvvNW7Y3KKuqqiZ1zjLWrF6GKzaavXuzmPb0y8x9YUqz6gezYvkcDIazM+s+PzuNle9v5KGxo4Nu6/P5mPLUi8yf+xQjhg9hz54sHpuQ2mC7n937U9Zv2ML1Q1OYMP4BHXxp03S7R0TavcxdB4iPjyXW6WDk7Texbv2Wuu+6xLvIPVPA9h3fNFqWuesAPbon4oo9OxtoXFwMJ0+dwWq1Nqt+MAaDgUOHjvPuH9Zy5Mi3FBYUh9x2z94svLU+RgwfogMqHYaupIhIu7du/Wbsdhsr39+I1+fl2LGTHDyYTZ8+3endO4kli2Ywb/5yXK4Yli6eEbSspLic7OyTPDdzCYFAgFiXgwXzpnLdgF7Nqn/+eZHzvF4f0379Ml27uvj5mDs4dTqP2lpvyDHk5hbgjHXoYEqHoispItKu+f1+1m/Ywp133Iw90kaMI4obbxjI+g83120zcuRNrP3LcoxGY93bPxeXxTijiLTbWPjK07y68DfMeGY848aOIjzc0qz6F/v4460UF5eROutx+vfviclkOnd1Jfg47PbOFBWW6oCKkhQRkfZix859OBydGTd2FKNHj2D06BGMGzuK9evPJik+n+9ccmAgwmbF7w8ELRs0sA9FhaVs2763rm2fz9fs+herrqmpe2X4QjZbBGaziWPZJ+uVDxncD3elhx07v2lyzBaLiQq3Wwdf2jzd7hGRdu2v6zIYddfwemU//ckNzJi5mP37j5KTk09a+jsYjUaMRgNzX5hCRsb2BmUWi5n0ZanMmr2UuDgnPp+PhIR47rn71mbVv9hddw5nzZ8/ZuLkeXRPSmDr1kzGPjjq7NtAUx9l8hMLGDyoD1lZx0lJSSY83MLy9FRS56STnHwNBfnFdE/qFnTM48bezTPPvkonYxhPPflLnQTSZhkCgUBdij9m+mrcnloASo5tovRoBkkj5ypKAkAXp41oq1mBkJBSkl0Y/FfeztjR0URHVv9g+11VVY3HU010tL3RsvPy8ouwmM1ERXW+rPoXKitzU1npwel0YDJ993djpbuKopJSoh12bLbwuvJAIEB+QTFmkwmHIzJkuz6vH3/AX6/NK1HjM/P7/ym54naGDuyK3+vXD8tFCgrO8NTEB5j7b/9O334DO3QsevV04oiy6kqKiAiA1WrBarU0WXZenCvmiupfyG63YbfbGpRH2KxE2KwN/7I0GBr0H0ynMCOddEdf2jidwSIiIqIkRURERERJiohIB+HxVLP/wFEFQpSkiIhI63L48Ake+dXzCoQoSRERkUuz7PV3ee+P6xQIESUpIiLNU1JSTk5uQd1nr9dHTm4Bvotekc0vKCYvvyhoGzU1teTmFuD3+0O2vW/fUSrdVY3uS1FxKXl5hQ3KS0srOHU6j+rqmqD13G4P/sDVf6U34PNz9NBOjhzYrhNLWoxeQRaRDqfSXcW990+hW9d4UlJ6MnPGBDZlbGNJ2tv0Sk5i3/4jzJ/7BCn9k7nn3skMHZqC2WQi6/BxFr36DD26JwDw4cbPeX35e/Tt24MDB46x5LXnSEyIr9d2/349yczcz7HsU3h9PiZNHNdgfx6fMh+LxUyl20NBYQlvvbkAi9nM/Q9MpVs3Fy5XDNt37GPKpIcY++AoAA4ezGZWahoJifFUeaquWixzTx1h364M9u36nEp3KRN+na4TTJSkiIhcruqaGo4fz2HNqnTAd7ShAAAgAElEQVTsdhtVVdWkzlnGmtXLcMVGs3dvFtOefplVf0rj5KkzrF+7ggiblQ0btvDMs4tY/X4ansoqZqWm8cGa10lM7MJfPviUOfPS+d3yOfXaBli/YQvXD01hwvgHgu7PiuVzMJxbtOf52WmsfH8jD40dzdFjJ1m1Mg273caOnd8wcdI8xj44Cp/Px5SnXmT+3KcYMXwIe/Zk8diE1B8sfmWlBezbtZlv/p5BYf530/dHOVzEOLvpBBMlKSIiLSVz1wF6dE/EFRsNQFxcDCdPnaGwsP4MqyNH3sS0p18hL6+QI0e/JSYmisTELgDccstQnpnxGpWXcVXDYDBw6NBxvt62myNHvqXzBTPMnhfrjKG0tAKAPXuz8Nb6GDF8yA8ap4N7t7Lzyw2cPL4/6LpDbncJ/7FkSqNtWMxhEAjopLtIaUmRgqAkRUSkoZLicrKzT/LczCUEAgFiXQ4WzJtKxEXJgtlswhpuprColJLicmy2iLrvIjvbCAQClJ1LJJrL6/Ux7dcv07Wri5+PuYNTp/OorfU2Wic3twBnrOMHj9O1vYbg9dbQqVMnThzb2+A5HIs5gr4Dbm60jS5xNgJ+JSmhOJ0uBUFJiojId2KcUUTabSx85el65cXFZfU+V1RU4qmsJj7eSUlJGWVl3600XF7hxmg0EtXIejrBfPzxVoqLy1iefvZ2zYcffdFkkmK3d6aosPQHj5PJYiVl8G2kDL6NirIi9u3awje7NpGfewKA6upKbr7tQUwWa8g2tHaPXAq93SMiHd6ggX0oKixl2/a9dWU+n6/Bdu+v2sjNPx5ETHQUgwf2pbS0jCNHvwVgU8Y2hl0/gPAg6/VYLCYq3O6gfVfX1AS9ddKYIYP74a70sGPnN1ctZp3tMdxwy3089uRS/vnJxVx/871YIyI5mvV3nVDSYnQlRUQ6PIvFTPqyVGbNXkpcnBOfz0dCQjypsx4HYNYLaXiqqiktKSdtyUwAwiOs/Pal6UyaPJ8e1yZy4kQO6WmzgrY/buzdPPPsq3QyhvHUk7+s991ddw5nzZ8/ZuLkeXRPSmDr1sy6N3hCCQ+3sDw9ldQ56SQnX0NBfjHdk67eA6txXbpz+z/+Mz8Z/SjlJfk6oaTFGAKB755gGjN9NW5PLQAlxzZRejSDpJFzFSUBoIvTRrTVrEBISCnJLgwtcCV/7OhooiOrr8oY8vKLsJjNREV1pri4jGE3PcTWL97DbDIRFdW5wfa1tV6KS8qIdTowGkNfnPZ5/fgDfkym4H8blpW5qaz04HQ6Qm5zsUAgQH5BMWaTCccl3ma6VDU+M7//n5Irbke3e6QpvXo6cURZdSVFRKTBVQFXTIMyW3g4Ebbgz1mYTGFB61ysU5iRTo3cYbfbbXWvLDf7r0yDoVl9i7RVeiZFRCSEsLBODBjQC2Mng4IhoiRFRKT1iIy08efVy7AGeRgWWmb14T17sqipqb3ifd2zJwuv16eDJkpSREQ6Cq/Xx8sL36ybSO1CLbH68P0PTiUnp+Cy9wHOPu9y/4NTKSgo1gETJSkiIh1FIBDA6/Ve8mvC7W0fRJSkiIh8j5q76vHpnHzKy8/Oa2IyhfHC7Ek4HPZ621zq6sOhVjluzv4G24cL91GkvdLbPSLS7jV31eMhg/vx2PjUuuRk+rRHGDSwD8l97uaTj94iKalryNWHz7+uvHPbKux2G1/8LZNZs5eS8dnbQVc5jomOuqT9Pb8P3bq5GuzjgP696ur6fD4e/edZ3D16BA//0706+KIkRUSkNWvuqsdzX5hCfn4RGze8EbSdy119ONgqx5Mmjmv2/l5o65eZDfbxwitBS9P+P5KSuipBkXZBt3tEpMMJteqx1Wol90wB23cEn27+clcfPr/K8bt/WMuRI99SeAUPuHaJd4Xcx08++5LtO75h/twndZClXdCVFBHpcEKtenzdgF4sWTSDefOX43LFsHTxjHrPgVzO6sOXs8pxY3r3Tmqwj5Gdz86E+4f3/so//fJ/NXvGWpHWTldSRKTDuXDV41cX/oYZz4xn3NhRhIdbGDnyJtb+ZTlGo5EVb6ysV6+x1YcNIeZ7O7/Kceqsx+nfvycmk+mK9z/UPr704lR+t+JPHDh4TAdZlKSIiLRFoVY9Pr/yscFgIMJmxe8P1KvX2OrDNlsEZrOJY9kn65VfzirHjWlsH7t1jWPenCk88dQCysr05o+0fbomKCIdTqhVj++5+1bS0t/BaDRiNBqY+8KUevUaW33YZApj+tRHmfzEAgYP6kNW1nFSUpIva5XjxmRkbG90H+8Y+WO++mo3v3n2Vd5YMa/ugV2RtkirIEuzaRVkaUpbXAX5wlWPAaqqqvF4qomOtoes09jqw5XuKopKSol22LHZwuvKL2eV41Cas48tTasgyw9FqyCLiJxz8SrCVqsl5Fo9dX/dNbL6cITNGnTF5MtZ5TiU5uyjSHugZ1JERERESYqIiIiIkhQRERFRkiIiIiLS0vTgrIi0OlnHvXSNa5sPhu7K3EV29nHuG/OzdnVMyt16I0eUpIiIkLm/nMz9bXPfN3+0mX27tmCOvkUHUuQK6XaPiIiIKEkRERERUZIiIiIiSlJERERElKSIiIiIkhQRERERJSkiIiIiSlJERERESYqIiIiIkhQRERFRkiIiIiKiJEVERESUpIiIyCUpzD/F/j2f462tqSvz+31kH9nN4QNfK0Ail0mrIIuIXKGYmK783zdfYN37yzBbrNTUVPN/FjxCbW01/3vCiwqQyGXSlRQRkStk6GSk/6AR+P0+qjxu/D4vtbXVRDlcJCb1V4BElKSIiFw9/Qfd1rBs8G0YDAYFR0RJiojI1dMloSfOuH+4KHG5VYERUZIiInL1pQz+LinpmpiM05WgoIgoSRERaQVJyqDbMBiMdf8WESUpIiKtQmSUk3/o0R+jsRN9B41QQESukF5BFhFpQSmDb8NkthIRYVcwRJSkiIi0Hn1Sfkx4RJQCIaIkRUTao3tvjyE+xttG994OxLe7Y+Kp7sQf1hbr5BQlKSLSsVnNAYwGrwLRiphMeoRRfng660RERERJioiIiIiSFBGRNsbjqWb/gaMKhIiSFBGR1uXw4RM88qvnFQgRJSkiIk2752eTWfHGSgVCREmKiEjrsXv3IQA+WPvpZdUvKi4lL68w6HclJeXk5BbUfXa7PfgD/gbbnc7Jp7zcrYMhHZJeQRYRCWHdhs08+vB9/O4//sThwydITr6G9/64jnXrNvOHdxYCsGjxW3zzzWF+/9ZvAXjpt/+BKzaGnZn7sFjMVLo9FBSW8NabC4iJjqLSXcW990+hW9d4UlJ6cv99dzArNY2ExHiqPFV1fdfWenlsfCoAJlMY06c9wqCBfXRQREmKiEhHFwgE2Ljxc1a9n8ahrGzWf7iZqU8+zG23DuO3L/8ntbVeTKYwvvxyNwUFxVRX12CxmPnyy10sXjSDif/6IAaDAYDnZ6ex8v2NTJo4juqaGo4fz2HNqnRsNit33f2vzJ/7FCOGD2HPniwem3A2Mdn6ZSb5+UVs3PCGDoZ0WLrdIyISROauA8THxxLrdDDy9ptYt34LAAnd4kjoFsfuPQfJyyskMjKCwYP7sm37XkpKyigtLadPn+4YDAYOHTrOu39Yy5Ej31JY0HC21j17s/DW+hgxfEiD77rEu8g9U8D2Hd/oYEiHpSspIiJBrFu/Gbvdxsr3N+L1eTl27CQHD2bTp093br31erZt28vRYye57dZh2KM6s+XznbjdHm65ZSher49pv36Zrl1d/HzMHZw6nUdtbcMZdHNzC3DGOoL237t3EksWzWDe/OW4XDEsXTwDh0OLFkrHoispIiIX8fv9rN+whTvvuBl7pI0YRxQ33jCQ9R9uBuC2W6/n62172bxlB7fdNoxbRgzliy928uVXu7jt1mF8/PFWiovLSJ31OP3798RkMgXtx27vTFFhacj9GDnyJtb+ZTlGo1FvGImSFBERgR079+FwdGbc2FGMHj2C0aNHMG7sKNavP5uk3DDsOg4eyub0qTyu7ZFInCsGg9HA37buYvjNQ6iuqSEQ5E2diw0Z3A93pYcdOxve0vH5fAAYDAYibFb8/oAOjHQ4ut0jInKRv67LYNRdw+uV/fQnNzBj5mL27z9Kv37X0r/ftSQkfLfa8a23DOXvfz9A584R3HXncNb8+WMmTp5H96QEtm7NZOyDoxr0Ex5uYXl6Kqlz0klOvoaC/GK6J3UDICNjO2np72A0GjEaDcx9YYoOjHQ4hkAgUJeej5m+GrenFoCSY5soPZpB0si5ipIA0MVpI9pqViAkpJRkFwb/lbczdnQ00ZHVbT4eZWVuKis9OJ0OTKbQfxMGAgHyC4oxm0w4HJF15VVV1Xg81URHX/1nUWp8Zn7/PyVX3M7QgV3xe/36YZGQevV04oiyArqSIiLyvbHbbdjttqb/WjQYiHPFNCi3Wi1YrRYFUjosPZMiIiIiSlJERERElKSIiPyAKt1VnDx1RoEQUZIiInL1eL0+Xl74JqWlFQDs3ZvFXf/4r3z++U6OZZ/iv95a3eJ9iChJERGRoJa9/i7v/XEdcPZtHK/XWzcXyjvvrmXMfSP5xUN34/f5qK6uafE+RJSkiIi0czU1teTkFuD3f/fL3+v1kZNbgO+iV2NLSsrJyS0AYN++o1S6z65SbDKF8cLsSXXT1JeWVeCIOvvqcM+e1zBl8v9uss+i4lLy8grrbddYH+fbyb2onfNKSys4dTrvshMkkdZIryCLSIfx6WdfM3deOgMG9MLpdPDSi1PZlLGNJWlv0ys5iX37jzB/7hMM6N+Le++fQreu8aSk9KR/v55kZu7nWPYpvD4fkyaOI7nP3Xzy0Vvs/Sar3ne9e3XnlYX/yUcf/mfIPh+fMh+LxUyl20NBYQlvvbmAzz/fGbKPpKSufLjxc15f/h59+/bgwIFjLHntOXr3TsLt9nD/A1Pp1s2FyxXD9h37mDLpoaCTx4koSRERaYWqqqqZMfM13lgxjx8N6V9XljpnGWtWL8MVG83evVlMe/plVv0pjePHc1izKr1unpP1G7Zw/dAUJox/oF679/zjraz966a67z797OtG+wRYsXwOBoMBgOdnp7Hy/Y1MmjguZB+eyipmpabxwZrXSUzswl8++JQ589L543uvUVNTy9FjJ1m1Mg273caOnd8wcdI8JSnSLuh2j4h0CJm7DmCxWOolC5m7DtCjeyKu2GgA4uJiOHnqDIWFJd9bn3B28rZDh47z7h/WcuTItxQWFDfezu4DxMREkZjYBYBbbhnKjp378FRWNdg21hmjh22l3dCVFBHpEEqKy3E4Ojcoy84+yXMzlxAIBIh1OVgwbyoRtvDvrU+v18e0X79M164ufj7mDk6dzqO21ttkOzZbRN3nyM42AoEApWUVWCxaqkKUpIiItGnRMXby8+pfsYhxRhFpt7HwlafrlRcXl31vfX788VaKi8tYnp4KwIcffdFkkuKIjqSszF33ubzCjdFoJCoqkqqqah1cabd0u0dEOoTBg/oSIMCmjG11ZYMG9qGosJRt2/fWlfl8vqD1LRYTFW73FfdZXVMT8rXiUH0MHtiX0tIyjhz9FoBNGdsYdv0AwsO1ro+0b7qSIiIdgsViZslrM3ju+aX06J5Aly6xLF70LOnLUpk1eylxcU58Ph8JCfGkznq8Qf1xY+/mmWdfpZMxjKee/OVl9/nSi1NZ8+ePmTh5Ht2TEti6NbPuIddQfYRHWPntS9OZNHk+Pa5N5MSJHNLTZumgSrtnCAQCgfMfxkxfjdtTC0DJsU2UHs0gaeRcRUkA6OK0EW3V/W8JLSXZhaEF5h4bOzqa6Mjv5zaG1+ujqKgElyum7g0bgLz8IixmM1FRnUPW9Xn9+AN+TKawK+6zrMxNZaUHp9NRr73G+qit9VJcUkas04HR+MNeCK/xmfn9/1z5A8VDB3bF79UEdRJar55OHFFWXUkRkY4nLKwTcXHOBuVxrpgm63YKM9LpMu6SB+vTbrfVvd7c3D5MprBm7adIe6FnUkRERERJioiIiIiSFBEREWnT9EyK/OCGpkQzbECUAtGKeL0B3lx9vNXsz/EcH7Vea5uMZV5eAVarGbvd3q7OkTK3HnYVJSnSAQxIjqR/94AC0YoEWtlF1a93lbXZWP7367+hZ++h3HrXwzqxRK6QbveIiIiIkhQRERERJSkiIiKiJEVERERESYqIiIgoSRERERFRkiIiIiKiJEU6snt+NpkVb6xUIERElKSItB67dx8C4IO1nzb47nROPuXl7ibLvF4fObkF+C5abv77qC8i0pFpxlnpUNZt2MyjD9/H7/7jTxw+fILk5GuorfXy2PhUAEymMKZPe4T+/Xo2KBs0sA+bMraxJO1teiUnsW//EebPfYIhg/u1eP1BA/voYImIkhSFQDqKQCDAxo2fs+r9NA5lZbP+w81MffJhtn6ZSX5+ERs3vFG37eYt2xuUVVVVkzpnGWtWL8MVG83evVlMe/pl5r4wpcXri4iIbvdIB5K56wDx8bHEOh2MvP0m1q3fAkCXeBe5ZwrYvuObum2DlWXuOkCP7om4YqMBiIuL4eSpM1it1havLyIiupIiHci69Zux222sfH8jXp+XY8dOcvBgNn36dGfJohnMm78clyuGpYtn0Lt3UoOykuJysrNP8tzMJQQCAWJdDhbMm8p1A3q1eH2Hw64DJiIdnq6kSIfg9/tZv2ELd95xM/ZIGzGOKG68YSDrP9wMwMiRN7H2L8sxGo11b/5cXBbjjCLSbmPhK0/z6sLfMOOZ8YwbO4rwcMv3Ul9EREmKSAewY+c+HI7OjBs7itGjRzB69AjGjR3F+vWb8fl8ABgMBiJsVvz+QNCyQQP7UFRYyrbte+va9fl830t9ERHR7R7pIP66LoNRdw2vV/bTn9zAjJmLeffdv7L6z/8Po9GI0Whg7gtTyMjYTlr6O/XKLBYz6ctSmTV7KXFxTnw+HwkJ8dxz960Ntr3S+q1VlbsYqy1aJ5SI/CAMgUCg7s+2MdNX4/bUAlBybBOlRzNIGjlXURIAujhtRFvNV9zOr+67hqF9Da3rl29VNR5PNdHR9kbLzsvLL8JiNhMV1fl7q/9DCmBk2sJjQb+rqSrn9JGvOHVkG3H/MIBeQ+4N2U5KsguDv2P/nPz367+mZ++h3HrXw/pPI4ihA7vi9/oVCAmpV08njiirrqSInGe1WrBaLU2WnRfnivne619NPm8ted/u4lTWl+Sf3kfAf/aXyqDb/kUni4j8YJSkiMhZgQBFeYc5mfUludk78dZ46n1tMBg5czyTM400UXHKhqEFH6nx+33U1FS1qTDm556gZ++hOp9ElKSINK3SXUVRSSmJCfEKRiMKcw9yZNeHFOYeqrtycnESc3TPxkbbOG689GfxO3UKI8xsaRcxNBqNREY56Wx36oQSUZIi0pDX62PR4v9myqRf8O23OUx64kWenPJLbrxxIJ9++iXj/+WBFmv//DMl7YGza1+cXftSXVnCqSPbOHVkK+VFp7/LUQhwy/1zsUZEhWxDz6SISIsm/gqBtAfLXn+X9/647twf/AG8Xi+BgJ933l3LmPtG8ouH7sbv81FdXdOi7bflOIViiXBw7XV3csuYOdwyZg7XXncnlggHAPkn9+pkExElKdIx1dTUkpNbgP/c7YZQKwYDlJSUk5NbAMC+fUepdJ99dsFkCuOF2ZNwOOyUllXgiIoEoGfPa5gy+X832h9AUXEpeXmF9bYL1f6F7eRe1A5AaWkFp07nNZkcXTiWxsadX1BMXn5RyNgF24dQcWqOyJhu9B32ALc/9DI3jJ4e/DaQiMj3RLd7pNX49LOvmTsvnQEDeuF0Orhj5I8brBh8w7DrqHRXce/9U+jWNZ6UlJ7079eTzMz9HMs+hdfnY9LEcST3uZunpz9ar7x3r+68svA/+ejD/wza30svTuXxKfOxWMxUuj0UFJbw1psL+PzznUHb/+Sjt0hK6sqHGz/n9eXv0bdvDw4cOMaS154jISGO+x+YSrduLlyuGLbv2MeUSQ8x9sFR9cZ88VhmzpgQdKXklP7J3HPvZIYOTcFsMpF1+DiLXn2GHt0TAILuQ2JCfJNxai6DwUBst77Qra9OVBFRkiIdS1VVNTNmvsYbK+bxoyH9qaqq5o5RExqsGPzJR29RXVPD8eM5rFmVjt1uA2D9hi1cPzSFCeO/e97knn/8Cbv3ZNWVf/rZ1yH7O2/F8jkYDGfncHl+dhor39/IpInjgrYP4KmsYlZqGh+seZ3ExC785YNPmTMvnd8tn8PRYydZtTINu93Gjp3fMHHSvAZJysVjCbVS8qo/pXHy1BnWr11BhM3Khg1beObZRax+P63RfWhOnEREWivd7pFWIXPXASwWS13CEGrF4MKiku+lvwuvGBw6dJx3/7CWI0e+pbCguPF2dh8gJiaKxMQuANxyy1B27NxHpaf+LZVYZwylpRXN2q+g4y6sP+6RI29iz94s8vIKm70PIiK6kiJyGUqKy3E4Otf7HGzF4IjwcKqqqlu8Pzj7HMi0X79M164ufj7mDk6dzqO21ttkOzZbRN3nyM42AoEAZc1ISEK1F3TctvB625nNJqzhZgqLSlt8H0RElKSIXCA6xk5+3ndXLS5cMfhiLZGkXNwfwMcfb6W4uIzl6akAfPjRF00mKY7oSMrK3HWfyyvcGI1GohyRl7VfocZdXFxW73NFRSWeymri452UlJS16D6IiLQWut0jrcLgQX0JEGBTxjaAkCsGh2KxmKhwuy+7Pzj7fEio14pDtT94YF9KS8s4cvRbADZlbGPY9QMIv8wp7ps77vdXbeTmHw8iJjrqkvbhUuMkInI16UqKtAoWi5klr83gueeX0qN7Al26xAZdMXjxomeD1h839m6eefZVOhnDeOrJX15Wfy+9OJU1f/6YiZPn0T0pga1bM+sedA3VfniEld++NJ1Jk+fT49pETpzIIT1t1hXFIdi4U2c9DsCsF9LwVFVTWlJO2pKZl7wPlxonEZGrSasgS7P9EKsge70+iopKcLli6t6yuXjF4FB8Xj/+gB+Tqfm5d7D+ysrcVFZ6cDod9dpqrP3aWi/FJWXEOh0YjS1zgfLCcRcXlzHspofY+sV7mE2moLFo7j4EG0djqyBfCs04K03RKsjSFK2CLK1WWFgn4uLqr3ty8YrBoXQKM9LpEu9gBuvPbrfVvbLb3PZNprBm72dzBWvPFh5OhM16RftwOXESEbka9D+VSBtJ3gYM6IWxk0HBEJGO83+fQiDS+kVG2vjz6mUKhIh0KLqSIiIiIkpSRERERJSkiIiISJumZ1LkB+f1BggEdOq1JgH0QK6IKEkR4Q/rvuUP69r2GP6+6T+x2ePp/aOf6YCKiHxPdLtH5DJUu0uordL08iIiSlJERERESYqIiIiIkhQRERERJSkiIiKiJEVERERESYqIiIgoSRERERFRkiIiIiJKUkRERESUpIiIiIgoSRERERElKSLtW0VpLn6ft0F5bU0lnooiBUhEpIVpFWSRZqpyF/Hlutdwdu2Lp6IQb001X3+YRlFuFrc++KICJCKiJEXk6nB26YvBGEbOse0AeNwlUAwx8b2I6OxUgEREWphu94g0k8FoJKHnsAblCck3KjgiIkpSRK6ubj3rJyTGTia69hiqwIiIKEkRubrsMYnYYxLrPscnDSTMHK7AiIgoSRG5+i68mpJwrW71iIgoSRFpJRJ6DsNgNGK2RuJKTFFARES+J3q7R+QSWSIcOLv0pbMjHoOxkwIiIqIkRaT1SEi+EVtUFwVCRERJirQnQ1OiGTYgqk2PobY2AZPJ1G6Oidcb4M3Vx3VyioiSFOnYBiRH0r97oB386ATazTEJ6PE0EWmF9D+TiIiIKEkRERERUZIiIiIiSlJE5Pvn8VSz/8DRy66/Z08WNTW1CqSIKEkRkUvn9fp4eeGblJZWNPju8OETPPKr5y+77fsfnEpOToGCLCJKUkSuxD0/m8yKN1Z2uHEHAgG8Xi+BgF8ngYgoSVEIpLXZvfsQAB+s/TTo96dz8ikvdzdZ5vX6yMktwOf1t2j9UNtfqKSknJzcgktuy2QK44XZk3A47PW2cbs9+C8hcSkqLiUvr1Ank4i0aZonRVqddRs28+jD9/G7//gThw+fIDn5GgBqa708Nj617pf59GmP0L9fzwZlgwb2YVPGNpakvU2v5CT27T/C/LlPMGRwvyuqf8Ow64Luw6CBfer2vdJdxb33T6Fb13hSUnoyc8aES24ruc/dfPLRWyQldeXgwWxmpaaRkBhPlacKgOLiMobd9BA7t63Cbrfxxd8ymTV7KRmfvQ3A41PmY7GYqXR7KCgs4a03FxATHaUTS0SUpIhciUAgwMaNn7Pq/TQOZWWz/sPNTH3yYQC2fplJfn4RGze8Ubf95i3bG5RVVVWTOmcZa1YvwxUbzd69WUx7+mXmvjDliup/8tFbQffhQtU1NRw/nsOaVenY7bYrasvn8zHlqReZP/cpRgwfwp49WTw2IbXJGK5YPgeDwQDA87PTWPn+RiZNHKeTS0TaHN3ukVYlc9cB4uNjiXU6GHn7Taxbv6Xuuy7xLnLPFLB9xzeNlmXuOkCP7om4YqMBiIuL4eSpM1it1iuqX1hUEnT7psZzuW3t2ZuFt9bHiOFDLimGBoOBQ4eO8+4f1nLkyLcUFhTrxBIRXUkRuVLr1m/Gbrex8v2NeH1ejh07ycGD2fTp053evZNYsmgG8+Yvx+WKYeniGUHLSorLyc4+yXMzlxAIBIh1OVgwbyrXDeh1RfUjwsNx9nY02P7i50cudCVt5eYW4Ix1XFL8vF4f0379Ml27uvj5mDs4dTqP2lqvTiwR0ZUUkSvh9/tZv2ELd95xM/ZIGzGOKG68YSDrP9xct83IkTex9i/LMRqNdW//XFwW44wi0m5j4StP8+rC3zDjmeGb/XcAAB62SURBVPGMGzuK8HDLFdcPtQ+hXElbdntnigpLg1wpCd3fxx9vpbi4jNRZj9O/f892tQiiiChJEblqduzch8PRmXFjRzF69AhGjx7BuLGjWL/+bJLi8/nO/ZI2EGGz4vcHgpYNGtiHosJStm3fW9e2z+e74vqh9qExV9LWkMH9cFd62LGz/u0gmy0Cs9nEseyTDfqrrqnR68si0m7odo+0Gn9dl8Gou4bXK/vpT25gxszF7N9/lJycfNLS38FoNGI0Gpj7whQyMrY3KLNYzKQvS2XW7KXExTnx+XwkJMRzz923XlH9xYueDbp9Y66krfBwC8vTU0mdk05y8jUU5BfTPanb2TeBpj7K5CcWMHhQH7KyjpOSkgzAXXcOZ82fP2bi5Hl0T0pg69ZMxj44SieXiLRJhkAgUPfn25jpq3F7zk6bXXJsE6VHM0gaOVdREgC6OG1EW81X3M6v7ruGoX0Nl1W3qqoaj6ea6Gh7o2Xn5eUXYTGbiYrq3CL1m9q+MZfbViAQIL+gGLPJhMMRWVde6a6iqKSUaIcdmy28Xp2yMjeVlR6cTgcmU9N/iwQwMm3hsSs+tinJLgy6kCONGDqwK36vThIJrVdPJ44oq66kSNtjtVqwWi1Nlp0X54pp0fpNbd+Yy23LYDAErRthsxJhswatY7fbsNttOmFEpE3TMykiIiKiJEVERERESYrIOXv2ZOH1+r73fjyeavYfOHrZ9X1eP3v2ZNW99SMioiRFpA3zen28vPBNSksrQv7iv//BqRT8ALOuHj58gkd+9fxl1y8rr+D+B6fidlfpwIqIKEmRti4QCOD1etvs3CDLXn+X9/64TgdSRERJirQXJSXl5OQWYDKF8cLsSfWmkz+dk095ufuy2i0qLiUvr7BBeWlpBadO51FdXRO0ntvtwd9EolRTU0tubgF+/3fb7dt3lMogV07cbk/Q2z5er4+c3AJ8F73CeT4eIiLtiV5Bljal0l3FvfdPoVvXeFJSejJzxgSS+9zNJx+9RbduLh4bf3aVYJMpjOnTHmFA/151dX0+H4/+8yzuHj2Ch//p3gZtPz5lPhaLmUq3h4LCEt56cwEWs5n7H5hKt24uXK4Ytu/Yx5RJD9VNkHbwYDazUtNISIynyhP6Ns2HGz/n9eXv0bdvDw4cOMaS157jwMGjZGbu51j2Kbw+Hw+NHQ3A7Dn/B7/Pz779R5n21MOMue92ADZlbGNJ2tv0Sk5i3/4jzJ/7BAP692oQDxERJSkiV0F1TQ3Hj+ewZlV6g3lAtn6ZSX5+ERs3vPH/t3fv8VFVh9rHfzPJZCYZMplkMrmQVO4QCaKIqKcIVlGBtlasBXt6evOVF5GqoJWIGCGolSoCOcSccnx7/PRU5VjUD1YKiC9SI/iC3AwXEUHut5Db5DaZSTKX949IJJmZEAUlhOf7l1mzZu21157BZ/Zee6+vgskZZxwW5v+VHj3SwwYUgMWFszB8uTDO40/ks/SN1dw9fgwHDh7jzaX52GxWtm77lEmT8xj/s9H4/X6mPPgUc2Y/yA3Dh7Bz5z7umZgb0q6n3svM3HzeWfYimZlp/P2dtczKK+D1JS+wctU6rhmazcR778LlqgHgD09NxWazsmnzTqY88Azj7rgZr7eB3FmLWPbWIpzJiezatY+pj8zlzb/lRxwPEZGLnS73SJeRluqk5FQ5W7Z+GvLa+//cyJatnzJn9gMR328wGNi79zCvvrac/fuPUhFmsm2yI6llku7OXfvwNfm5YfiQdvtVvGMPSUkJZGamATBixFC2btuNp779CbKpKclUVTUHl+Lte+jVMxNnciIAKSlJHDt+ioqKKh14EdGZFJHOrn//HiyYl0PenEKcziQWzs8hvlvzI+hfW/IP/u0XP474iHifz8/Uh+eSnu7kp+Nu4fiJUpqafO1ur6SkHEey/az9qnLVYrXGtfwd381KMBikuqauw/tW5arl0KFjPDZjAcFgkGSnnafzHiKuzePwRUQUUkQ6qVGjrufmm69j4qTZLH5pKdMf+V8APPPUQzw0bS5Dr84ma0CvkPetWbMBl6uGwoLmyzXvvvfRWUOKzdaNyorqs/bJnhhPTc1XE3lr69wYjUYSEuI7vF9JjgTibVae++MjrcpPXyISEemKdLlHuozTd8MYDAbirBYCgZa1M+menkLerCn87sGnWwWG0xoaG7/2bcxDrrocd72Hrds+bbfeVYOzqK6uYf+Bo0DzBNhh1wwiNtaM2Wyizn32O5GuHDyAyopqNm/ZFbK/IiJdlc6kSJdRVLSF/IJXMBqNGI0GZj85pdXrt4z6Fz7+eAe/n/48Ly3Oa5kkC3DbrcNZ9vYaJt2fR88eGWzYUNxyB08ksbFmCgtyyZ1VQN++l1Fe5qJnj+6h9eIsPPvMNCbfP4devTM5cuQkBfkzAZgwfiyPTn+eKGM0v/y3H0fcltkcQ8GiXGY+sZCUFAd+v5+MjFRyZ96nAy8iXZYhGAy2/NwcN+0t3J4mAKoOfkD1gSJ6jJqtURIA0hxWEi0x59zOb+64jKFZhm+lj15vAx5PA4mJtm/0/poaN/X1HhwOe8T5K20Fg0HKyl3EmEzY7ZEv4TQ1+XBV1ZDssGM0fnUS0+8LEAgGOry90rJKzDExJCR0O2/jFsTI1OcOnnM72X2dGAL6rkhkQwenE/DpQyKR9evjwJ5g0ZkU6XosFjMWi/kbv99ms37tW3kNBgMpzqSz1jOZosPWi4o2EvU1rrx2ZFsiIl2B5qSIiIiIQoqIiIiIQopIB9W7vRw7fkoDISKikCLSeezatY/RP/zfrF+/TYMhIqKQItJ5vPLqcsaNu4Wf3z32a7930YuvsuT1FRpEERGFFJHzr7qmjgRb61t5K13VlJZWhNRtbGziZEk5gUDz7ZO7dx+g3u0NqVNyRp3TqqpqOVlS3vL3iZNl1Na6dQBERNqhW5DlkvXO8n9SXPwZBw8dx+f3M3nSBO6bMgezOYZ6t4fyiipe/vPTJCUmsPafm5idV8CgQf1wOOxcO+yKkPe+u3o9LxYuISurF3v2HGTBC4+RmZHK7XdOoXt6KtnZffj9w7/lnnubH71vMkUzbeqvuHLwAB0MERGFFJGv/OT2m1i5ah3XDM1m4r13AbC4cFbLk2gffyKfpW+s5re/voOcGS/w0uI8rh4ysOX9Z77XU+9lZm4+7yx7kczMNP7+zlpm5RXwp8JZHD58kmVvFmCzWflw3RbKyipZveolHQARkbPQ5R6RMxgMBvbuPcyrry1n//6jVJS7KN6+B7PZ3CqgtFW8Yw9JSQlkZqYBMGLEULZu2029p/XloLRUJyWnytmy9VMNtojIWehMisiXfD4/Ux+eS3q6k5+Ou4XjJ0ppavJR5arFbm//EfRVrlqs1riWv+O7WQkGg9RU17Wq179/DxbMyyFvTiFOZxIL5+dgt9s0+CIiYehMisiX1qzZgMtVQ+7M+xg4sA8mkwmAxCQbZaWudt9rT4xvtbpybZ0bo9FIQpi1fEaNup7lfy/EaDSy+KWlGngREYUUkfY1NDYSDIYufHbVlVkECfJB0eZW5WaziTp3czC5anAW1dU17D9wFIAPijYz7JpBxLZZR8jv9wPNl5XirBYCgaAGXkQkAl3uEfnSbbcOZ9nba5h0fx49e2SwYUMx4382GrM5hgUv5PDY4wvp1TODtLRk5s+bzoTxY3l0+vNEGaN58IFf8Owz05h8/xx69c7kyJGTFOTPDNlGUdEW8gtewWg0YjQamP3kFA28iEgEhmAw2PJTbty0t3B7mgCoOvgB1QeK6DFqtkZJAEhzWEm0xJxzO7+54zKGZhk67X7W1Lipr/fgcNgxmb7K8T6fn8rKKpzOpJY7gPy+AIFgoKVeU5MPV1UNyQ47RmP4E5VebwMeTwOJiZ1nLkoQI1OfO3jO7WT3dWII6LsikQ0dnE7Apw+JRNavjwN7ggXQmRSREDabFZvNGlIeHR1FSoqjVVlUtJGoM66amkzRpDiT2m3fYjFjaXMZSEREQmlOioiIiCikiIiIiCikiIiIyEVNc1LkO1de1Uh9Q/xFvQ/19R4MRgOxFkuXOCY+v26FFhGFFBFWFJWwoqjkot6HjSvmEZ+YSfb3/1UHVETkW6LLPSIiIqKQIiIiIqKQIiIiIgopIiIiIgopIiIiopAiIiIiopAiIiIiopAiIiIiCikiIiIiCikiIiKikCIiIiKikCIiIiIKKSISVl31KQJ+X0h5U2M9nrpKDZCIyHmmVZBFOsjrrmDjihdI7p6Fp66CpsYGNq3+dypL9jHyrjkaIBERhRSRC8ORloXBGMWJA5ubC9xV1LogKbUfcd0cGiARkfNMl3tEOshgNJLRZ1hIeUbf6zQ4IiIKKSIXVvc+rQOJMcpEWq+rNTAiIgopIheWLSkTW2JGy98pl12BKSZOAyMiopAicuF173t9y39n9rleAyIiopAi0jlk9BmGwWAgxtINZ2a2BkRE5Fuiu3tEviZznB1H9yysCakYjFEaEBERhRSRziOjz/VY7akaCBERhRTpSm79fgojhtgu6n1obLyMmJiYLnNMfH54avEX+nCKiEKKXNq6Oy3YuzVd5HthAJq6zDEJanqaiHRC+pdJREREFFJEREREFFJEREREIUVEOsbjaeCzPQc0ECIiCikincsXXxzhV795XAMhIqKQItK+H/3kfha/tFQDISKikCLSeezYsReAd5av/cZtVLqqKS2tCCmvqqrlZEl5qzK320MgGGhVduJkGbW1bh0MEZEw9JwUuWStWPUhv/7lHfzpP//GF18coW/fy1jy+gpWrPiQ1155DoB581/m00+/4C8vPwvAM8/+J87kJO6bNJ77pszBbI6h3u2hvKKKl//8NJYYM7ffOYXu6alkZ/dhRs5EPv/8EDNz88nITMXr8QLQ1OTjnntzATCZopk29VdcOXiADoqIiEKKXOqCwSCrV6/nzTfy2bvvECvf/ZCHHvglN44cxrNz/w9NTT5Mpmg2btxBebmLhoZGzOYYNm7czvx5OQAsLpyFwWAA4PEn8ln6xmruHj+Gw4dPsuzNAmw2K36/nykPPsWc2Q9yw/Ah7Ny5j3sm5rJhYzFlZZWsXvWSDoaISAS63COXpOLte0hNTSbZYWfUzdezYuU6ADK6p5DRPYUdOz+ntLSC+Pg4rroqi81bdlFVVUN1dS0DBvQEwGAwsHfvYV59bTn79x+lotwVsp2du/bha/Jzw/AhrcrTUp2UnCpny9ZPdTBERCLQmRS5JK1Y+SE2m5Wlb6zG5/dx8OAxPv/8EAMG9GTkyGvYvHkXBw4e48aRw7AldGPd+m243R5GjBgKgM/nZ+rDc0lPd/LTcbdw/EQpTU2+kO2UlJTjSLaHlPfv34MF83LIm1OI05nEwvk52O02HRgRkTPoTIpccgKBACtXrePWW76PLd5Kkj2B664dzMp3PwTgxpHXsGnzLj5ct5UbbxzGiBuG8tFH29j48XZuHDkMgDVrNuBy1ZA78z4GDuyDyWQKuy2brRuVFdVhXxs16nqW/70Qo9GoO4xERBRSRGDrtt3Y7d2YMH40Y8bcwJgxNzBh/GhWrmwOKdcOu4LP9x7ixPFSevfKJMWZhMFo4P9t2M7w7zdftmlobCTY5k6dcIZcdTnueg9bt7W+rOP3+4HmS0ZxVguBQFAHRkSkDV3ukUvOP1YUMfq24a3KbvrBteTMmM9nnx3g8st7M/Dy3mRkpLa8PnLEUD75ZA/dusUBcNutw1n29hom3Z9Hzx4ZbNhQzPifjQ7ZVmysmcKCXHJnFdC372WUl7no2aM7RUVbyC94BaPRiNFoYPaTU3RgRETaMASDwZafcOOmvYXb07z8fNXBD6g+UESPUbM1SgJAmsNKoiXmnNv5zR2XMTTL0CXGpKbGTX29B4fDjskUOfMHg0HKyl3EmEzY7fEAeL0NeDwNJCZe+LkoQYxMfe7gObeT3deJIaDvikQ2dHA6AZ8+JBJZvz4O7AkWQGdSRM6JzWbFZrOe/deAwUCKM6lVmcVixmIxaxBFRCLQnBQRERFRSBHpKrSasYiIQopIp3R6NWOfz8/c5/5MdXXdN27rfLQhIqKQIiKtBINBfD5fy+3Ii158lSWvrzjr+86s17YNERFRSJEuItJKxI2NTZwsKScQCLRb1nbFYp/Pz8mScvwR7kA4czVjkymaJ5+Y3PK02N27D1Dv9p61f2fWa9vG6X6WtOnnadXVdRw/UUpDQ6MOvoh0abq7Ry5q4VYiTkpMYO0/NzE7r4BBg/rhcNh55qmHQspmPjYpZMXiD4o2syD/v+nXtwe7P9vPnNm/49phVwCEXc0YoO+Asbz/3sts37GH4uLPOHjoOD6/n8mTJoTt3/r120LqnW6jR4903l29nhcLl5CV1Ys9ew6y4IXH6N+/B263hzvveoju3Z04nUls2bqbKZPvDvt8FhERhRSRCyzcSsS//fUd5Mx4gZcW53H1kIFA8zNJ2pa5XDWtViz2ehvInbWIZW8twpmcyK5d+5j6yFzef+/liKsZn+knt9/EylXruGZoNhPvvSti/yZPmhBS7zRPvZeZufm8s+xFMjPT+Ps7a5mVV8DrS16gsbGJAweP8ebSfGw2K1u3fcqkyXkKKSKikCLSGZ1eiXjT5h3s33+UbtZYirfvwWw2t4QRIGxZW8Xb99CrZybO5EQAUlKSOHb8FBWVVRw9WhJ2NeNv0r/2FO/YQ1JSApmZaQCMGDGUR3NewFPvDamb7EjSZFsRUUgR6YwirURc5arFbu/Wqm64sraqXLUcOnSMx2YsIBgMkuy083TeQ8TFxkZczfib9O9sfbBa41r+ju9mJRgMUl1Th9kco4MuIgopIheD0ysRFxY0X3Z5972PaGrykZhko6zU1apuuLK2khwJxNusPPfHR0Jea28146/bv/bYE+OpqXG3/F1b58ZoNJKQEI/X26CDLiKXFN3dIxetSCsRX3VlFkGCfFC0ud2ytq4cPIDKimo2b9nVUnZ6teJIqxm3ZTabqHO72+1f23qt+j44i+rqGvYfOArAB0WbGXbNIGJj9fh8Ebn06EyKXLQirURsNsew4IUcHnt8Ib16ZpCWlsz8edNDynJn3tcmOMRQsCiXmU8sJCXFgd/vJyMjlfnzpkdczbitCePH8uj054kyRjPx3rsirpR8Zr0HH/hFy/tj4yw8+8w0Jt8/h169Mzly5CQF+TN1sEXkkqRVkKXDOusqyJFWIvb5/FRWVuF0JrXcYROuLJzSskrMMTEkJLSexxJuNeO2/L4AgWCgpS+R+te23pmamny4qmpIdtgxGr/9E55aBVm+K1oFWc5GqyBLlxJpJeLo6ChSUhxnLQun7YrFLak+zGrGbUVFG4k640pqpP61rXcmkyn6rNsREenqNCdFREREFFJEREREFFJERETkonbe56SkOiz84GqnRraTee/jU7hqOseCdOVVjdQ3xOugdCI+f1CDICJdP6Rcl53MxNsdGtlO5nhZA+uLSztFX1YUlbCiqOSiHs/Pt7zNif2buOnuZ/XhEhH5luhyj4iIiCikiIiIiCikiIiIiEKKiIiIiEKKiIiIKKSIiIiIKKSIiIiIKKSIiIiIQopIV/ziREVpEEREFFJEOmNIMWkQREQUUkREREQh5TvW2NiEz+fXURAREZEQ0Rdio9XVdeQ8Pp8TJ0ppavIx5KrLeSrvAUymb787i158leTkRH7x8x9d8MHvTH0RERHpbC7ImZRZeQV0T3ey/O1CVi7/E6dOVVBQuKRVnbJyF6VllSHv9fn8nCwpx+8LhLxWVVXLyZLylr8rXdWUlla0qrN79wHq3d4OtXniZBm1te5296UjdSLV/Tp9cblqOHGyrKXc72+u5/E06FMsIiJd0nd+JqWmxs27qz/i/f/7X80pyWjknt+OI+ex+Twy7de43R5+dPv9DB2aTYzJxL4vDjPv+Ufp1TODD4o2syD/v+nXtwe7P9vPnNm/49phV1Dv9nL7nVPonp5KdnYfZuRM5L4pczCbY6h3eyivqOLlPz/N+vXbKC7+jIOHjuPz+5k8aULYNodcdTn33JsLgMkUzbSpv+LKwQNa7UdTky+kzqZNO1m3fit//ctcALbv+JzHHl/A8rcLQ+oePnyiQ33JHtiXn9z5O76XmY7DYWfnzr2MGTOCzZt30L17Kps27eD3j9zDuDtuPudj42/yYDQaMUSZ9c0QEZFLL6R8sf8wMWYTmRmpLWUD+vekrNxFRWUVRoORY8dPsXL5YuKsFlatWsej0+fx2ivPkTtrEcveWoQzOZFdu/Yx9ZG5vP/eyzQ0NnL48EmWvVmAzWYFYHHhLAwGAwCPP5HP0jdWM3nSBFauWsc1Q7OZeO9deL0NYduc/eQUysoqWb3qpYj7sWFjcUgdh8POwn//K/VuL3FWC++v/ZixY24IW/fKwQM61Jc3/5bfat82frydX/56Brt3vkNMjIm1az9mztP/8c1DSjBAfdkeak9+QlNNCZnDH9a3QkREOoXv/HJPba2bOIulVVlcXCwAdbWekPqjRl3Pzl37WP3eR/TqmYkzORGAlJQkjh0/RUVlVdjtGAwG9u49zKuvLWf//qNUlLtC6hRv3xO2TYvFQsmpcrZs/TTifqSlOkPqZGakkpXVi482fALA2rUbGXPbiLB1O9qXiorW+5eelgJATEzzLbBOZxI1HbzcdKaGqiNUfPYOR/75B0598gr1JbuIS7kcjLrhS0RELoIzKQGfl6oDRV+rwYPOgcCtEV+3WuOo97aeh+HxNs+riLNaQurHxJiwxMZw4OAxDh06xmMzFhAMBkl22nk67yHiYmPxelvPy/D5/Ex9eC7p6U5+Ou4Wjn85QbetKldt2DavGNSPBfNyyJtTiNOZxML5Odjttlbv7d+/R9g6Pxwzkg+KNpGd3ZfGxiYGDOgJcNb2IvUlzhp73g62r76CupPbqTu5jSZ3Rejrnup2j7f/VAyV0XqIGcCBHe8RCDRpIERELkRIMUY3/8+x9vimr9Xg0QO0G1L69vkeXk8Dx0+UktG9+azAvn2HsdttOJMTcblqWtWvq6vHU9/A5QN6E2+z8twfHwlps21IWbNmAy5XDYUFzfNA3n3vo7AhJcmRELHNUaOu5+abr2PipNksfmkpM3ImdqjO2LEj+Pm//p6sAb0ZPfqGDrcXqS9tx+ObavDUUXNkA3Uni/E3hj/z4infg7dyX8Q2ag0GvryCdslraqwnzubUQIiIXIiQYvveddi+d93XbnDkyMx2X7fbbdz0g2H8+b/eZPaTUwgEAvzlr29zZ4Q5FW+8uZrv/8uV3HTTteQ9VcjmLbsYds2g5l/2fj9RYR5P3tDYSDAYCNue2Wyizt38P+krBw+gsqI6pE2AqKgoDAYDcVYLgUAw9KzCl9tuWyejewopKQ5e+59/sGBeTrt1O9qX88Ec242krB+TNOCH1Jfvpe7ENurL9hD0f3U2IKH3jdh7R57bkuawkmiJ0bdGREQubEj5Nj3z9FQefOhZRv/wPhobm8ga0JNHHv5tqzozn8zH422guqqW/AUzMJtjKFiUy8wnFpKS4sDv95ORkcr8edND2r/t1uEse3sNk+7Po2ePDDZsKGb8z0YDMGH8WB6d/jxRxmgefOAXYdv80diR5Be8gtFoxGg0MPvJKSHbKCraErHOD8eO4LX/WcnAgX3arduRvuTOvO/8Dr7BSJwzizhnFgGfl/qSndSe+ASv6xD1ZXvbDSkiIiLfJUMwGGw5TTBu2lu4Ped2nf0nIzN58GfJHapbVVVDVFQU8fHWljKXq4Zh19/Nho+WEGMykZDQLeR9pWWVmGNiwr52ppoaN/X1HhwOe6sHxfl9AQLBQKuytm16vQ14PA0kJtoith+pTsGLS/B4PeQ8eu9Z63akL+fDnJdPsL64NOLrPm8VdSc+wXbZv2CMtuhMinwj2X2dGAIaB4ls6OB0Aj59SCSyfn0c2BMsF+5MymltJ4+eyRobG3YiLUCKM6lD7dts1pZbks8UFW0kqs2NTW3btFjMWCztPy8kXB2/L8DrS1fxpxef7FB7HenLdyHaYsfe+yZ9O0REpNPodPebRkdHMWhQP4xRF+cMze0799Cv72UMHtxfny4REZFzyQSdrUPx8VbefmvRRTugVw8ZyF9e/oM+WSIiIudIT+4SERERhRQRERERhRQRERFRSBERERFRSBERERGFFBERERGFFBERERGFFBEREVFIEREREfkGzvsTZ9cVl+L2+jSyncz2vS4NgoiIXNohxVXTyPubSjSyIiIick50uUdEREQUUkREREQUUkREREQhRUREREQhRURERBRSRERERBRSRERERBRSRERERCFFRERERCFFREREFFJEREREFFJEREREIUVERESkE2i1CnK3uBgMBoNGRcKKs5iIs5g0EBKRyWQkKqh/Q6SdX8YGA8Yo/T6WyM7MIYZgMBjUkIiIiEinC7UaAhEREVFIEREREVFIEREREYUUERERkfPs/wNgF+jyvCXFDwAAAABJRU5ErkJggg==				
							</image>

            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Certification</title>
            <content>
              <para>
                Certification (described in the Conducting Certifications section of this chapter) provides the accreditation authority with information on the security posture of a system. This allows the accreditation authority to make an informed decision on whether the residual security risk of allowing the system to operate is acceptable.
              </para>
            </content>
            <controls>
              <block>
                <ID>0795</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Certification</title>
                <content>
                  <para>
                    All systems must be certified as part of the accreditation process; unless the accreditation authority is satisfied that if the system is not immediately operational it would have a devastating and potentially long lasting effect on operations.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Accreditation decision</title>
            <content>
              <para>
                The purpose of conducting an accreditation of a system is to determine the security posture of the system and the security risk that it poses to information. In giving approval for the system to operate, the accreditation authority is accepting the residual security risk to information that is processed, stored or communicated by the system.
              </para>
              <list>
                <head>To assist in making an accreditation decision, the accreditation authority may review:</head>
                <item>
                  the SRMP for the system
                </item>
                <item>
                  the report of compliance from the audit
                </item>
                <item>
                  the certification report from the certification authority
                </item>
                <item>
                  any decisions to be non-compliant with any controls specified in this manual
                </item>
                <item>
                  any additional security risk reduction strategies that have been implemented.
                </item>
              </list>
              <para>
                To assist in making an informed accreditation decision, the accreditation authority may also seek advice from technical experts on the technical components of information presented to them during the accreditation process.
              </para>
            </content>
            <controls>
              <block>
                <ID>0808</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accreditation decision</title>
                <content>
                  <para>
                    The accreditation authority must accept the residual security risk relating to the operation of a system in order to award accreditation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Conducting Certifications</title>
        <objective>
          <block>
            <content>
              <para>
                The effectiveness of security measures for systems is accepted.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes conducting a certification as part of the accreditation process for a system.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Certification aim</title>
            <content>
              <para>
                The aim of certification is to ensure the audit for a system was conducted in an appropriate manner and to a sufficiently high standard.
              </para>
            </content>
          </block>
          <block>
            <title>Certification outcome</title>
            <content>

              <para>
                The outcome of certification is a certificate to the system owner acknowledging that the system has been appropriately audited and that the controls identified by the system owner have been implemented effectively.
              </para>
            </content>
          </block>
          <block>
            <title>Certification authorities</title>
            <content>
              <para>
                For TOP SECRET systems the certification authority is the Defence Signals Directorate (DSD).
              </para>
              <para>
                For SECRET or below systems the certification authority is the Information Technology Security Advisor (ITSA).
              </para>
              <para>
                For systems that process, store or communicate caveated or compartmented information there may be a mandated certification authority external to the agency operating the system.
              </para>
              <para>
                For multi-national and multi-agency systems the certification authority is determined by a formal agreement between the parties involved.
              </para>
              <para>
                For commercial providers of gateway services intended for use by multiple agencies across government, DSD performs the role of the certification authority as an independent third party.
              </para>
              <para>
                For commercial providers supporting agencies the certification authority is the ITSA of the agency sponsoring the organisation.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Audit</title>
            <content>
              <para>
                The aim of an audit is to assess the actual implementation and effectiveness of controls for a system. The process of conducting an audit is described in the Conducting Audits section of this chapter.
              </para>
            </content>
            <controls>
              <block>
                <ID>1141</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Audit</title>
                <content>
                  <para>
                    All systems must undergo an audit as part of the certification process.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Certification decision</title>
            <content>
              <para>
                To award certification for a system the certification authority needs to be satisfied that the controls identified by the system owner have been implemented and are operating effectively. However, certification only acknowledges that the identified controls were implemented and are operating effectively and not that the residual security risk is acceptable or an approval to operate has been awarded.
              </para>
            </content>
            <controls>
              <block>
                <ID>1142</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Certification decision</title>
                <content>
                  <para>
                    The certification authority must accept the effectiveness of controls for the system in order to award certification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Assessment of residual security risks</title>
            <content>
              <para>
                Before the certification authority can make a recommendation to the accreditation authority, an assessment of the residual security risk must be done. The purpose of the assessment is to assess the residual security risk relating to the operation of a system following the audit.
              </para>
              <para>
                Even if, after the audit, the system is non-conformant, the certification authority may be able to recommend to the accreditation authority that accreditation be awarded. For example, since the audit, the system owner may have taken corrective actions to address areas of non-compliance, or the residual security risk may not be great enough to preclude accreditation.
              </para>
            </content>
            <controls>
              <block>
                <ID>0807</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Assessment of residual security risks</title>
                <content>
                  <para>
                    Following the audit, the certification authority should produce a certification report for the accreditation authority containing an assessment of the residual security risks relating to the operation of the system and a recommendation on whether to award accreditation or not.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Certification of gateway services</title>
            <content>
              <para>
                Commercial providers of gateway services may be used by multiple agencies across government, agencies must ensure gateway services of commercial providers have undergone an audit conducted by an infosec-registered assessor and received certification from DSD. Even though DSD may certify a gateway service from a commercial provider, agencies using the service still need to decide whether accreditation should be awarded or not.
              </para>
            </content>
            <controls>
              <block>
                <ID>0100</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Certification of gateway services</title>
                <content>
                  <para>
                    Agencies must ensure that gateway services of commercial providers, intended for use by multiple agencies, have undergone an audit by an infosec-registered assessor and received certification from DSD.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Conducting Audits</title>
        <objective>
          <block>
            <content>
              <para>
                The effectiveness of security measures for systems is assessed.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes conducting an audit as part of the certification process for a system.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Audit aim</title>
            <content>
              <para>
                The aim of an audit is to review the system architecture (including the information security documentation) and assess the actual implementation and effectiveness of controls for a system.
              </para>
            </content>
          </block>
          <block>
            <title>Audit outcome</title>
            <content>

              <para>
                The outcome of an audit is a report to the certification authority describing areas of compliance and non-compliance for a system and any suggested remediation actions.
              </para>
            </content>
          </block>
          <block>
            <title>Who can conduct an audit</title>
            <content>
              <para>
                Audits for TOP SECRET systems can only be undertaken by DSD and infosec-registered assessors.
              </para>
              <para>
                Audits for SECRET and below systems can be undertaken by Information Technology Security Managers (ITSMs) and infosec-registered assessors.
              </para>
            </content>
          </block>
          <block>
            <title>Who can assist with an audit</title>
            <content>
              <para>
                A number of agencies and personnel are often consulted during an audit.
              </para>
              <list>
                <head>Agencies or personnel who can be consulted on physical security aspects of information security include:</head>
                <item>
                  the Australian Security Intelligence Organisation for TOP SECRET sites
                </item>
                <item>
                  the Department of Foreign Affairs and Trade for systems located at overseas posts and missions
                </item>
                <item>
                  the Agency Security Advisor (ASA) for all other systems.
                </item>
              </list>
              <para>
                The ASA can be consulted on personnel security aspects of information security.
              </para>
              <para>
                An ITSM or communications security officer can be consulted on communications security aspects of information security.
              </para>
            </content>
          </block>
          <block>
            <title>Independent audits</title>
            <content>
              <para>
                An audit can be conducted by agency assessors; however, the agency may choose to add an extra level of objectivity by engaging the services of an infosec-registered assessor to undertake the audit.
              </para>
              <para>
                Connections to certain inter-agency systems could require an independent audit from an infosec-registered assessor as a prerequisite to certification of the system. Such requirements can be obtained from the inter-agency system owners.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Independence of assessors</title>
            <content>
              <para>
                As there can be a perceived conflict of interest in the system owner assessing the security of their own system, the assessor should be independent of the system owner and certification authority. This does not preclude an appropriately qualified system owner from assessing the security of a system that they are not responsible for.
              </para>
            </content>
            <controls>
              <block>
                <ID>0902</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Independence of assessors</title>
                <content>
                  <para>
                    Agencies should ensure that assessors conducting audits are not also the system owner or certification authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Audit preparation</title>
            <content>
              <para>
                Ensuring that the system owner has approved the system architecture and associated information security documentation assists assessors in determining the scope of work for the first stage of the audit.
              </para>
            </content>
            <controls>
              <block>
                <ID>0797</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Audit preparation</title>
                <content>
                  <para>
                    Before undertaking the audit, the system owner must approve the system architecture and associated information security documentation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Audit (first stage)</title>
            <content>
              <para>
                The purpose of the first stage of the audit is to determine that the system architecture (including information security documentation) is based on sound security principles and has addressed all applicable controls from this manual. During this stage, the statement of applicability for the system will also be assessed along with any justification for non-compliance with applicable controls from this manual.
              </para>
            </content>
            <controls>
              <block>
                <ID>0798</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Audit (first stage)</title>
                <content>
                  <para>
                    The system architecture should be reviewed by the assessor to ensure that it is based on sound security principles and meets security requirements.
                  </para>
                </content>
              </block>
              <block>
                <ID>0799</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Audit (first stage)</title>
                <content>
                  <para>
                    The Information Security Policy should be reviewed by the assessor to ensure that policies have been developed or identified to protect information that is processed, stored or communicated by systems.
                  </para>
                </content>
              </block>
              <block>
                <ID>0800</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Audit (first stage)</title>
                <content>
                  <para>
                    The SRMP, SSP, Standard Operating Procedures and Incident Response Plan must be reviewed by the assessor to ensure that they are comprehensive and appropriate for the environment the system is to operate in.
                  </para>
                </content>
              </block>
              <block>
                <ID>0802</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Audit (first stage)</title>
                <content>
                  <para>
                    The SSP must be reviewed by the assessor to ensure that all relevant controls specified in this manual are addressed.
                  </para>
                </content>
              </block>
              <block>
                <ID>0904</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Audit (first stage)</title>
                <content>
                  <list>
                    <head>The system owner should provide a statement of applicability for the system which includes the following topics:</head>
                    <item>
                      the baseline of this manual used for determining controls
                    </item>
                    <item>
                      controls that are, and are not, applicable to the system
                    </item>
                    <item>
                      controls that are applicable but are not being complied with
                    </item>
                    <item>
                      any additional controls implemented as a result of the SRMP.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Implementing controls</title>
            <content>
              <para>
                Without implementing the controls for a system, their effectiveness cannot be assessed during the second stage of the audit.
              </para>
            </content>
            <controls>
              <block>
                <ID>0084</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Implementing controls</title>
                <content>
                  <para>
                    Before undertaking the second stage of the audit the system owner must implement the controls for the system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Audit (second stage)</title>
            <content>
              <para>
                The purpose of the second stage of the audit is to determine whether the controls, as approved by the system owner and reviewed during the first stage of the audit, have been implemented and are operating effectively.
              </para>
            </content>
            <controls>
              <block>
                <ID>0805</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Audit (second stage)</title>
                <content>
                  <para>
                    The implementation of controls must be assessed to determine whether they have been implemented and are operating effectively.
                  </para>
                </content>
              </block>
              <block>
                <ID>0806</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Audit (second stage)</title>
                <content>
                  <para>
                    The assessor must ensure that, where applicable, a physical security certification has been awarded by an appropriate physical security certification authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0905</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Audit (second stage)</title>
                <content>
                  <para>
                    The physical security certification should be less than 5 years old at the time of the audit.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Report of compliance</title>
            <content>
              <para>
                The report of compliance helps the certification authority assess the residual security risk relating to the operation of a system following the audit and any remediation activities the system owner may have undertaken.
              </para>
            </content>
            <controls>
              <block>
                <ID>1140</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Report of compliance</title>
                <content>
                  <para>
                    The assessor must produce a report of compliance for the certification authority outlining areas of non-compliance for a system and any suggested remediation actions.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Policy and Procedures for the InfoSec-Registered Assessor Program contains a definition of the range of activities infosec-registered assessors are authorised to perform. It can be obtained from DSD’s website at http://www.dsd.gov.au/infosec/irap.htm.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Information Security Monitoring</title>
      <section>
        <title>Vulnerability Management</title>
        <objective>
          <block>
            <content>
              <para>
                Vulnerability management activities contribute to the security of systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes agencies’ requirements for conducting vulnerability management activities for their systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information security monitoring practices can help ensure that new vulnerabilities are addressed and security is maintained through unforeseen events and changes, whether internal to the system or in the system’s operating environment. Such practices allow agencies to be proactive in identifying, prioritising and responding to security risks. Measures to monitor and manage vulnerabilities in, and changes to, a system can provide an agency with a wealth of valuable information about its level of exposure to threats, as well as assisting agencies in keeping up to date with industry and product advances.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Vulnerability management strategy</title>
            <content>

              <para>
                Agencies should maintain vulnerability management activities such as regular vulnerability assessments, analysis and mitigation as threat environments change over time. Vulnerability assessments allow agencies to identify security weaknesses caused by misconfigurations, bugs or flaws.
              </para>
            </content>
            <controls>
              <block>
                <ID>1163</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Vulnerability management strategy</title>
                <content>
                  <list>
                    <head>Agencies should implement a vulnerability management strategy by:</head>
                    <item>
                      conducting vulnerability assessments on systems throughout their lifecycle to identify vulnerabilities and risks
                    </item>
                    <item>
                      analysing identified vulnerabilities to determine their potential impact and appropriate mitigations or treatments based on effectiveness, cost and existing security controls
                    </item>
                    <item>
                      using a risk-based approach to prioritise the implementation of identified mitigations or treatments
                    </item>
                    <item>
                      monitoring new information on vulnerabilities in operating systems, software and devices as well as other elements which may adversely impact on the security risks associated with a system.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Conducting vulnerability assessments</title>
            <content>
              <para>
                Conducting vulnerability assessments prior to systems being used, and after significant changes, can allow the agency to establish a baseline for further information security monitoring activities.
              </para>
              <para>
                Conducting vulnerability assessments annually can help ensure that the latest threat environment is being addressed and that systems are configured in accordance with associated information security documentation.
              </para>
              <para>
                It is recommended that vulnerability assessments are conducted by personnel independent of the target or by an independent third party. This ensures that there is no conflict of interest, perceived or otherwise, and that the assessment is undertaken in an objective manner.
              </para>
              <list>
                <head>An agency may choose to undertake a vulnerability assessment either:</head>
                <item>
                  as a result of a specific cyber security incident
                </item>
                <item>
                  after a change to a system or its environment that significantly impacts on the agreed and implemented system architecture and information security policy
                </item>
                <item>
                  as part of a regular scheduled assessment.
                </item>
              </list>
              <para>
                Agencies will find it useful to gather appropriate information before they start a vulnerability assessment. This will help to ensure that the assessment is undertaken to a degree that is commensurate with the threat environment, and if applicable, the sensitivity or classification of information that is involved.
              </para>
              <list>
                <head>Depending on the scope and subject of the vulnerability assessment, agencies may gather information on areas such as:</head>
                <item>
                  agency priorities and business requirements
                </item>
                <item>
                  threat data
                </item>
                <item>
                  likelihood and consequence estimates
                </item>
                <item>
                  effectiveness of existing counter-measures
                </item>
                <item>
                  other possible counter-measures
                </item>
                <item>
                  best practices.
                </item>
              </list>
              <list>
                <head>
                  Vulnerability assessments can consist of:
                </head>
                <item>
                  conducting threat and risk assessments and high level security reviews of planned systems
                </item>
                <item>
                  manual testing to provide a detailed, in-depth assessment
                </item>
                <item>
                  supplementing manual testing with automated tools to perform routine, repeatable security testing.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0911</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Conducting vulnerability assessments</title>
                <content>
                  <list>
                    <head>Agencies should conduct vulnerability assessments on systems:</head>
                    <item>
                      before the system is deployed, this includes conducting assessments during the system design and development stages
                    </item>
                    <item>
                      after a significant change to the system
                    </item>
                    <item>
                      after significant changes to the threats or risks faced by a system, for example, a software vendor announces a critical vulnerability in a product used by the agency
                    </item>
                    <item>
                      at least annually, or as specified by an Information Technology Security Manager or the system owner.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0909</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Conducting vulnerability assessments</title>
                <content>
                  <para>
                    Agencies should have vulnerability assessments conducted by personnel independent to the target of the assessment or by an independent third party.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Analysing and mitigating vulnerabilities</title>
            <content>
              <para>
                Agencies are encouraged to monitor information about new vulnerabilities that could affect their systems. However, they should not be complacent if no vulnerabilities are disclosed in specific products used in their systems.
              </para>
              <para>
                Vulnerabilities can be introduced as a result of poor security practices or accidental activities. Therefore, even if no new vulnerabilities in deployed products have been disclosed there is still value to be gained from conducting regular vulnerability analyses.
              </para>
              <para>
                Furthermore, by monitoring vulnerabilities, conducting vulnerability analyses, keeping up to date with industry and product advances, and keeping up to date with changes to this manual, agencies will become aware of factors which may adversely impact the security risk profile of their systems.
              </para>
              <para>
                Agencies may wish to consider that discovered vulnerabilities could be a result of their security practices, accidental activities or malicious activities and not just as the result of a technical issue.
              </para>
              <para>
                To determine the potential impact and possible mitigations to a system, comprehensive documentation and an understanding of the system are required. External sources that can be monitored for information on new vulnerabilities are vendor published vulnerability information, other open sources and subscription services.
              </para>
              <para>
                Mitigation efforts are best prioritised using a risk-based approach in order to address the most significant vulnerabilities first. Where two or more vulnerabilities are of similar importance, the mitigations with lower cost (in time, staff and capital) can be implemented first.
              </para>
            </content>
            <controls>
              <block>
                <ID>0112</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Analysing and mitigating vulnerabilities</title>
                <content>
                  <para>
                    Agencies must analyse any vulnerabilities to determine their potential impact on the agency and determine appropriate mitigations or other treatments.
                  </para>
                </content>
              </block>
              <block>
                <ID>0113</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Analysing and mitigating vulnerabilities</title>
                <content>
                  <para>
                    Agencies must mitigate or otherwise treat identified vulnerabilities as soon as possible.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Change Management</title>
        <objective>
          <block>
            <content>
              <para>
                Information security is an integral part of the change management process.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the importance of maintaining the security of systems when implementing routine and urgent changes.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Identifying the need for change</title>
            <content>
              <list>
                <head>The need for change can be identified in various ways, including:</head>
                <item>
                  identification of security vulnerabilities, new attacks and associated mitigations
                </item>
                <item>
                  system users identifying problems or enhancements
                </item>
                <item>
                  vendors notifying upgrades to software or Information and Communications Technology (ICT) equipment
                </item>
                <item>
                  vendors notifying the end of life to software or ICT equipment
                </item>
                <item>
                  advances in technology in general
                </item>
                <item>
                  implementing new systems that necessitate changes to existing systems
                </item>
                <item>
                  identifying new tasks requiring updates or new systems
                </item>
                <item>
                  organisational change
                </item>
                <item>
                  business process change
                </item>
                <item>
                  standards evolution
                </item>
                <item>
                  government policy or Cabinet directives
                </item>
                <item>
                  other incidents or continuous improvement activities.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>Types of system change</title>
            <content>
              <list>
                <head>A proposed change to a system could involve either:</head>
                <item>
                  an upgrade to, or introduction of, ICT equipment
                </item>
                <item>
                  an upgrade to, or introduction of, software
                </item>
                <item>
                  major changes to security controls.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Change management process</title>
            <content>
              <para>
                As part of any change process it is important that all stakeholders are consulted before the change is implemented. In the case of changes that will affect the security of a system, the accreditation authority will need to be consulted and approval sought.
              </para>
              <para>
                The change management process ensures that changes to systems are made in an accountable manner with due consideration and with appropriate approval. Furthermore, the change management process provides an opportunity for the security impact of the change to be considered and, if necessary, reaccreditation processes initiated.
              </para>
              <para>
                The most likely scenario for bypassing change management processes is when an urgent change needs to be made to a system. Before and after an urgent change is implemented, it is essential that the change management process strongly enforces appropriate actions to be taken.
              </para>
            </content>
            <controls>
              <block>
                <ID>0115</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Change management process</title>
                <content>
                  <list>
                    <head>Agencies must ensure that for routine and urgent changes:</head>
                    <item>
                      the change management process, as defined in the relevant information security documentation, is followed
                    </item>
                    <item>
                      the proposed change is approved by the relevant authority
                    </item>
                    <item>
                      any proposed change that could impact the security of a system is submitted to the accreditation authority for approval
                    </item>
                    <item>
                      all associated information security documentation is updated to reflect the change.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0117</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Change management process</title>
                <content>
                  <para>
                    The change management process must define appropriate actions to be followed before and after urgent changes are implemented.
                  </para>
                </content>
              </block>
              <block>
                <ID>0912</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Change management process</title>
                <content>
                  <list>
                    <head>Agencies should ensure their change management process includes:</head>
                    <item>
                      documenting the changes to be implemented
                    </item>
                    <item>
                      formal approval of the change request
                    </item>
                    <item>
                      conducting vulnerability management activities when significant changes have been made to the system
                    </item>
                    <item>
                      testing and implementing the approved changes
                    </item>
                    <item>
                      updating the relevant information security documentation including the Security Risk Management Plan, System Security Plan and Standard Operating Procedures
                    </item>
                    <item>
                      notifying and educating system users of the changes that have been implemented as close as possible to the time the change is applied
                    </item>
                    <item>
                      continually educating system users in regard to changes.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Changes impacting the security of a system</title>
            <content>
              <para>
                The accreditation for a system is the acceptance of the residual security risk relating to the operation of the system. It is important therefore that, when a change occurs that impacts the overall security risk for the system, the accreditation authority is consulted on whether that residual security risk is still acceptable.
              </para>
            </content>
            <controls>
              <block>
                <ID>0809</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Changes impacting the security of a system</title>
                <content>
                  <para>
                    When a configuration change impacts the security of a system, and is subsequently assessed as having changed the overall security risk for the system, the system must undergo reaccreditation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Business Continuity and Disaster Recovery</title>
        <objective>
          <block>
            <content>
              <para>
                Business continuity minimises the disruption to the availability of information and systems after a disaster.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the role of business continuity and disaster recovery plans in ensuring continuing operation of agencies’ critical systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Business continuity and disaster recovery plans work to maintain security in the face of unexpected events and changes.
              </para>
              <para>
                Additional information relating to business continuity can be found in the Ensuring Service Continuity section of the Network Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Availability requirements</title>
            <content>
              <para>
                As availability requirements will vary based on business requirements they cannot be stipulated in this manual. Agencies will need to determine their own availability requirements and implement appropriate security measures to achieve them.
              </para>
            </content>
            <controls>
              <block>
                <ID>0118</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Availability requirements</title>
                <content>
                  <para>
                    Agencies must determine availability requirements for their systems and implement appropriate security measures to support these requirements.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Backup strategy</title>
            <content>
              <para>
                Having a backup strategy in place is an important part of business continuity planning. The backup strategy ensures that critical business information is not accidentally lost.
              </para>
            </content>
            <controls>
              <block>
                <ID>0119</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Availability requirements</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      back up all information identified as critical to their business
                    </item>
                    <item>
                      store backups of critical information, with associated documented recovery procedures, at a remote location secured in accordance with the requirements for the sensitivity or classification of the information
                    </item>
                    <item>
                      test backup and restoration processes regularly to confirm their effectiveness.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Business continuity plan</title>
            <content>
              <para>
                Developing a business continuity plan can help ensure that critical functions of systems continue to operate when the system is in a degraded state. For example, when limited bandwidth is available on networks agencies may choose to strip all large attachments from emails.
              </para>
            </content>
            <controls>
              <block>
                <ID>0913</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Business continuity plan</title>
                <content>
                  <para>
                    Agencies should develop a business continuity plan.
                  </para>
								</content>
							</block>
						</controls>
					</block>
					<block>
						<title>Disaster recovery plan</title>
							<content>
								<para>
									Developing a disaster recovery plan will reduce the time between a disaster occurring and critical functions of systems being restored.
								</para>
							</content>
						<controls>
							<block>
								<ID>0914</ID>
								<revision>2</revision>
								<updated>Sep-11</updated>
								<classification>G</classification>
								<classification>P</classification>
								<classification>C</classification>
								<classification>S</classification>
								<classification>TS</classification>
								<compliance>should</compliance>
								<authority>AA</authority>
								<title>Disaster recovery plan</title>
								<content>
									<para>
										Agencies should develop a disaster recovery plan.
									</para>
								</content>
							</block>
						</controls>
					</block>
			</controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Additional information relating to business continuity is contained in HB 221:2004, Business Continuity Management.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Cyber Security Incidents</title>
      <section>
        <title>Detecting Cyber Security Incidents</title>
        <objective>
          <block>
            <content>
              <para>
                Tools and appropriate procedures are in place to detect cyber security incidents.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes controls aimed at detecting cyber security incidents. It does not cover detecting physical and personnel security incidents.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <list>
                <head>Additional information relating to detecting cyber security incidents can be found in the following chapters and sections:</head>
                <item>
                  Information Security Monitoring: Vulnerability Management
                </item>
                <item>
                  Personnel Security for Systems: Information Security Awareness and Training
                </item>
                <item>
                  Access Control: Event Logging and Auditing
                </item>
                <item>
                  Network Security: Intrusion Detection and Prevention.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Preventing and detecting cyber security incidents</title>
            <content>
              <para>
                The activities listed for assisting in detecting cyber security incidents will assist in mitigating the most common methods of attack used to exploit systems.
              </para>
              <para>
                Many potential cyber security incidents are noticed by personnel rather than software tools. However, for this to happen, personnel must be well trained and aware of information security issues and know how to recognise possible cyber security incidents.
              </para>
              <para>
                Automated tools are only as good as the quality of the analysis they provide. If tools are not adequately configured to assess potential security risks, it will not be evident when a weakness emerges. Additionally, if the tools are not regularly updated to include knowledge of new vulnerabilities their effectiveness will be reduced.
              </para>
              <para>
                Agencies may consider some of the tools described below for detecting potential cyber security incidents.
              </para>
              <table>
                  <header>
                      <cell>Tool</cell>
                      <cell>Description</cell>
                  </header>
                    <row>
                      <cell>Anomaly detection systems</cell>
                      <cell>Monitor network and host activities that do not conform to normal system activity.</cell>
                    </row>
                    <row>
                      <cell>Intrusion prevention systems</cell>
                      <cell>Some Intrusion Detection Systems (IDSs) are combined with functionality to repel detected attacks. Caution and assessment of the potential impact need to be exercised if this capability is to be used.</cell>
                    </row>
                    <row>
                      <cell>Log analysis</cell>
                      <cell>Involves collecting and analysing event logs using pattern recognition to detect anomalous activities.</cell>
                    </row>
                    <row>
                      <cell>Network and host IDSs</cell>
                      <cell>Monitor and analyse network and host activity, usually relying on a list of known attack signatures to recognise potential cyber security incidents.</cell>
                    </row>
                    <row>
                      <cell>System integrity verification</cell>
                      <cell>Used to detect changes to critical system components such as files, directories or services. These changes may alert a system administrator to unauthorised changes that could signify an attack on the system and inadvertent system changes that render the system open to attack.</cell>
                    </row>
              </table>

            </content>
            <controls>
              <block>
                <ID>0120</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Preventing and detecting cyber security incidents</title>
                <content>
                  <list>
                    <head>Agencies must develop, implement and maintain tools and procedures covering the detection of potential cyber security incidents, incorporating:</head>
                    <item>
                      counter-measures against malicious code
                    </item>
                    <item>
                      intrusion detection strategies
                    </item>
                    <item>
                      audit analysis
                    </item>
                    <item>
                      system integrity checking
                    </item>
                    <item>
                      vulnerability assessments.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0121</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Preventing and detecting cyber security incidents</title>
                <content>
                  <para>
                    Agencies should use the results of the security risk assessment to determine the appropriate balance of resources allocated to prevention as opposed to detection of cyber security incidents.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Reporting Cyber Security Incidents</title>
        <objective>
          <block>
            <content>
              <para>
                Reported cyber security incidents assist in maintaining an accurate threat environment picture for government systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes agencies’ responsibilities for reporting cyber security incidents. It does not cover reporting physical or personnel security incidents.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Cyber security incidents and outsourcing</title>
            <content>
              <para>
                The requirement to lodge a cyber security incident report applies even when an agency has outsourced some or all of its information technology functions and services.
              </para>
            </content>
          </block>
          <block>
            <title>Categories of cyber security incidents</title>
            <content>
              <para>
                The Cyber Security Incident Reporting (CSIR) scheme defines cyber security incidents that should be reported to the Defence Signals Directorate (DSD).
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Reporting cyber security incidents</title>
            <content>
              <para>
                Reporting cyber security incidents to an Information Technology Security Manager (ITSM) as soon as possible after it occurs provides management with a means to assess the overall damage to a system and to take remedial action, including seeking advice from DSD if necessary.
              </para>
            </content>
            <controls>
              <block>
                <ID>0123</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reporting cyber security incidents</title>
                <content>
                  <para>
                    Agencies must direct personnel to report cyber security incidents to an ITSM as soon as possible after the cyber security incident is discovered.
                  </para>
                </content>
              </block>
              <block>
                <ID>0124</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Reporting cyber security incidents</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      encourage personnel to note and report any observed or suspected security weaknesses in, or threats to, systems or services
                    </item>
                    <item>
                      establish and follow procedures for reporting software malfunctions
                    </item>
                    <item>
                      put mechanisms in place to enable the types, volumes and costs of cyber security incidents and malfunctions to be quantified and monitored
                    </item>
                    <item>
                      deal with the violation of information security policies and procedures by personnel through a formal disciplinary process.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Reporting cyber security incidents to the Defence Signals Directorate</title>
            <content>

              <para>
                DSD uses cyber security incident reports as the basis for identifying and responding to cyber security events across government. Cyber security incidents are also used for developing new policies, procedures, techniques and training measures to prevent the recurrence of similar cyber security incidents across government. Agencies are recommended to coordinate their reporting of cyber security incidents to DSD e.g. through their Information Technology Security Advisor (ITSA).
              </para>
              <para>
                Where agencies have outsourced information technology services and functions, they may request that the service provider report cyber security incidents directly to DSD. This could be specified in either a Memorandum of Understanding or as part of the contract of services. In such cases it is recommended that the agency’s ITSA be made aware of all reporting of cyber security incidents to DSD by the service provider.
              </para>
            </content>
            <controls>
              <block>
                <ID>0139</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reporting cyber security incidents to the Defence Signals Directorate</title>
                <content>
                  <para>
                    Agencies must report cyber security incidents to DSD.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>How to report cyber security incidents to the Defence Signals Directorate</title>
            <content>

              <para>
                Reporting cyber security incidents to DSD through the appropriate channels ensures that appropriate and timely assistance can be provided. In addition, it allows DSD to maintain an accurate threat environment picture for government systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0140</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>How to report cyber security incidents to the Defence Signals Directorate</title>
                <content>
                  <para>
                    Agencies should formally report cyber security incidents using the CSIR scheme.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Outsourcing and cyber security incidents</title>
            <content>
              <para>
                When an agency outsources information technology services and functions, they are still responsible for the reporting of cyber security incidents. The agency must ensure that the service provider informs them of all cyber security incidents to allow them to formally report these to DSD.
              </para>
            </content>
            <controls>
              <block>
                <ID>0141</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Outsourcing and cyber security incidents</title>
                <content>
                  <para>
                    Agencies that outsource their information technology services and functions must ensure that the service provider consults with the agency when a cyber security incident occurs.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cryptographic keying material</title>
            <content>

              <para>
                Reporting any cyber security incident involving the loss or misuse of cryptographic keying material is particularly important. Systems users rely on the use of cryptographic keying material for the confidentiality and integrity of their secure communications.
              </para>
            </content>
            <controls>
              <block>
                <ID>0142</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cryptographic keying material</title>
                <content>
                  <para>
                    Agencies must notify all communications security custodians of any suspected loss or compromise of keying material.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>High grade cryptographic keying material</title>
            <content>
              <para>
                Australian Communications Security Instruction (ACSI) 107 applies to all agencies including contractors. Its requirements cover all High Grade Cryptographic Equipment (HGCE) used to process classified information.
              </para>
              <para>
                For cyber security incidents involving the suspected loss or compromise of HGCE keying material, DSD will investigate the possibility of compromise and, where possible, initiate action to reduce the impact of the compromise.
              </para>
            </content>
            <controls>
              <block>
                <ID>0143</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>High grade cryptographic keying material</title>
                <content>
                  <para>
                    Agencies must notify DSD of any suspected loss or compromise of keying material associated with HGCE in accordance with ACSI 107.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on reporting cyber security incidents is located on the DSD website at http://www.dsd.gov.au/infosec/reportincident.htm.
              </para>
              <para>
                Further information on the categories of cyber security incidents can be found in http://www.dsd.gov.au/publications/Cyber_Security_Incident_Report.pdf.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Managing Cyber Security Incidents</title>
        <objective>
          <block>
            <content>
              <para>
                Appropriate remedies assist in preventing future cyber security incidents.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes agencies’ responsibilities for managing cyber security incidents. It does not cover managing physical or personnel security incidents.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                The management of physical and personnel security incidents is not covered in this section unless it directly impacts on the protection of systems (for example, breaching physical protection for a server room).
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Cyber security incident management documentation</title>
            <content>

              <para>
                Documenting responsibilities and procedures for cyber security incidents in relevant System Security Plans (SSPs), Standard Operating Procedures (SOPs) and the Incident Response Plan (IRP) ensures that when a cyber security incident does occur, personnel can respond in an appropriate manner. In addition, ensuring that system users are aware of reporting procedures assists in capturing any cyber security incidents that an ITSM, Information Technology Security Officer or system owner fail to notice.
              </para>
            </content>
            <controls>
              <block>
                <ID>0122</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cyber security incident management documentation</title>
                <content>
                  <para>
                    Agencies must detail cyber security incident responsibilities and procedures for each system in the relevant SSP, SOPs and IRP.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Recording cyber security incidents</title>
            <content>
              <para>
                The purpose of recording cyber security incidents in a register is to highlight the nature and frequency of the cyber security incidents so that corrective action can be taken. This information can subsequently be used as an input into future security risk assessments of systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0125</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Recording cyber security incidents</title>
                <content>
                  <para>
                    Agencies should ensure that all cyber security incidents are recorded in a register.
                  </para>
                </content>
              </block>
              <block>
                <ID>0126</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Recording cyber security incidents</title>
                <content>
                  <list>
                    <head>Agencies should include, at a minimum, the following information in their register:</head>
                    <item>
                      the date the cyber security incident was discovered
                    </item>
                    <item>
                      the date the cyber security incident occurred
                    </item>
                    <item>
                      a description of the cyber security incident, including the personnel and locations involved
                    </item>
                    <item>
                      the action taken
                    </item>
                    <item>
                      to whom the cyber security incident was reported
                    </item>
                    <item>
                      the file reference.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0916</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Recording cyber security incidents</title>
                <content>
                  <para>
                    Agencies should use their register as a reference for future security risk assessments.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Handling data spills</title>
            <content>
              <para>
                Assuming that information is compromised as a result of a cyber security incident allows an agency to apply procedures in response to a worst case scenario.
              </para>
            </content>
            <controls>
              <block>
                <ID>0129</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Handling data spills</title>
                <content>
                  <para>
                    When a data spill occurs agencies must assume that the information has been compromised.
                  </para>
                </content>
              </block>
              <block>
                <ID>0130</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Handling data spills</title>
                <content>
                  <para>
                    Agencies must include in standard procedures for all personnel with access to systems a requirement that they notify an ITSM of any data spillage and access to any data which they are not authorised to access.
                  </para>
                </content>
              </block>
              <block>
                <ID>0131</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Handling data spills</title>
                <content>
                  <para>
                    Agencies must document procedures for dealing with data spills in their IRP.
                  </para>
                </content>
              </block>
              <block>
                <ID>0132</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Handling data spills</title>
                <content>
                  <para>
                    Agencies must treat any data spill as a cyber security incident and follow the IRP to deal with it.
                  </para>
                </content>
              </block>
              <block>
                <ID>0133</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Handling data spills</title>
                <content>
                  <para>
                    When a data spill occurs, agencies must report the details of the data spill to the information owner.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Containing data spills</title>
            <content>
              <para>
                The spillage of information onto a system not accredited to handle it is considered a cyber security incident under the DSD CSIR scheme.
              </para>
              <para>
                An affected system can be segregated by powering off the system, removing network connectivity to the device or applying access controls on information associated with the data spill to prevent access. However it should be noted that powering off the system could destroy information that would be useful for forensics activities at a later date.
              </para>
            </content>
            <controls>
              <block>
                <ID>0134</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Containing data spills</title>
                <content>
                  <para>
                    When information is introduced onto a system not accredited to handle the information, personnel must not delete the information until advice is sought from an ITSM.
                  </para>
                </content>
              </block>
              <block>
                <ID>0135</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Containing data spills</title>
                <content>
                  <para>
                    When information is introduced onto a system not accredited to handle the information, personnel should not copy, view, print or email the information.
                  </para>
                </content>
              </block>
              <block>
                <ID>0136</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Containing data spills</title>
                <content>
                  <para>
                    When information is introduced onto a system not accredited to handle the information, agencies should segregate the affected system from the network.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Handling malicious code infection</title>
            <content>

              <para>
                The guidance for handling malicious code infections is provided to help prevent the spread of the infection and to prevent reinfecting the system. An important consideration is the infection date of the machine. However, when determining the infection date, it is important to bear in mind that the record could be inaccurate as a result of the infection.
              </para>
              <para>
                A complete operating system reinstallation, or an extensive comparison of characterisation information, is the only reliable way to ensure that malicious code is eradicated.
              </para>
            </content>
            <controls>
              <block>
                <ID>0917</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Handling malicious code infection</title>
                <content>
                  <list>
                    <head>Agencies should follow the steps described below when malicious code is detected:</head>
                    <item>
                      isolate the infected system
                    </item>
                    <item>
                      decide whether to request assistance from DSD, and if such assistance is requested and agreed to, delay any further action until advised by DSD to continue
                    </item>
                    <item>
                      scan all previously connected systems, and any media used in a set period leading up to the cyber security incident, for malicious code
                    </item>
                    <item>
                      isolate all infected systems and media to prevent reinfecting the system
                    </item>
                    <item>
                      change all passwords and key material stored or potentially accessed from compromised systems
                    </item>
                    <item>
                      advise system users of any relevant aspects of the compromise, including changing all passphrases on the compromised systems and any other system that uses the same passphrase
                    </item>
                    <item>
                      use current antivirus or other Internet security software to remove the infection from the systems or media
                    </item>
                    <item>
                      report the cyber security incident and perform any other activities specified in the IRP.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Allowing continued attacks</title>
            <content>
              <para>
                Agencies allowing an attacker to continue an attack against a system in order to seek further information or evidence will need to establish with their legal advisors whether the actions are breaching the Telecommunications (Interception and Access) Act 1979 (the TIA Act).
              </para>
            </content>
            <controls>
              <block>
                <ID>0137</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Allowing continued attacks</title>
                <content>
                  <para>
                    Agencies considering allowing an attacker to continue some actions under controlled conditions for the purpose of seeking further information or evidence should seek legal advice.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Integrity of evidence</title>
            <content>
              <para>
                While gathering evidence it is important to maintain the integrity of the information, this includes maintaining metadata about the information, who used it, and how it was used. Even though in most cases an investigation does not directly lead to a police prosecution, it is important that the integrity of evidence such as manual logs, automatic audit trails and intrusion detection tool outputs be protected.
              </para>
              <para>
                When storing raw audit trails onto meet it is important that it is done in accordance with relevant retention requirements as documented in the National Archives of Australia’s Administrative Functions Disposal Authority.
              </para>
            </content>
            <controls>
              <block>
                <ID>0138</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Integrity of evidence</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      transfer a copy of raw audit trails onto media for secure archiving, as well as securing manual log records for retention
                    </item>
                    <item>
                      ensure that all personnel involved in the investigation maintain a record of actions undertaken to support the investigation.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Seeking assistance</title>
            <content>

              <para>
                If the integrity of evidence of a cyber security incident is compromised, it reduces DSD’s ability to assist agencies. DSD therefore requests that no actions which could affect the integrity of the evidence be carried out before DSD’s involvement.
              </para>
            </content>
            <controls>
              <block>
                <ID>0915</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Seeking assistance</title>
                <content>
                  <para>
                    Agencies should ensure that any requests for DSD assistance are made as soon as possible after the cyber security incident is detected and that no actions, which could affect the integrity of the evidence, are carried out before DSD’s involvement.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information relating to the management of Information and Communications Technology evidence is contained in HB 171:2003, Guidelines for the management of information technology evidence.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
  </part>
  <part>
    <title>Physical Security</title>
    <chapter>
      <title>Physical Security for Systems</title>
      <section>
        <title>Facilities and Network Infrastructure</title>
        <objective>
          <block>
            <content>
              <para>
                Physical security measures are applied to facilities and network infrastructure to protect systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the requirements for the physical security of facilities and network infrastructure.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information on servers, network devices, Information and Communications Technology (ICT) equipment and media can be found in other sections of this chapter. Information on encryption requirements can be found in the Cryptographic Fundamentals section of the Cryptography chapter.
              </para>
            </content>
          </block>
          <block>
            <title>Facilities</title>
            <content>
              <para>
                In the context of this manual a facility is an area that facilitates government business. For example, a facility can be a building, a floor of a building or a designated space on the floor of a building.
              </para>
            </content>
          </block>
          <block>
            <title>Physical security certification authorities</title>
            <content>
              <list>
                <head>The certification of physical security measures is undertaken by:</head>
                <item>
                  the Agency Security Advisor (ASA) for Zone Two to Zone Four security areas
                </item>
                <item>
                  the Australian Security Intelligence Organisation (ASIO) for Zone Five security areas.
                </item>
              </list>
              <para>
                For facilities that process or store caveated or compartmented information there may be a certification authority external to the agency operating the facility.
              </para>
              <para>
                For multi-national and multi-agency facilities the certification authority is determined by a formal agreement between the parties involved.
              </para>
              <para>
                For commercial providers of gateway services intended for use by multiple agencies across government, ASIO performs the role of the certification authority as an independent third party.
              </para>
              <para>
                For commercial providers supporting agencies the certification authority is the ASA of the agency sponsoring the organisation.
              </para>
			  </content>
			</block>
			<block>
			  <title>Physical security accreditation authorities</title>
			  <content>
              <para>
                The accreditation of physical security measures for Zone Two to Zone Five security areas is undertaken by the ASA.
              </para>
              <para>
                For facilities that process or store caveated or compartmented information there may be an accreditation authority external to the agency operating the facility.
              </para>
              <para>
                For multi-national and multi-agency facilities the accreditation authority is determined by a formal agreement between the parties involved.
              </para>
              <para>
                For gateway services of commercial providers the accreditation authority is the ASA.
              </para>
              <para>
                For commercial providers supporting agencies the accreditation authority is the ASA.
              </para>
            </content>
          </block>
          <block>
            <title>Facilities located outside of Australia</title>
            <content>

              <para>
                Agencies operating sites in posts or missions located outside of Australia should contact the Department of Foreign Affairs and Trade to determine requirements.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Facility and network infrastructure physical security</title>
            <content>
              <para>
                The application of defence-in-depth to the protection of systems is enhanced through the use of successive layers of physical security. The first layer of security is the use of Security Zones for the facility, the second layer is the use of a higher Security Zone or security room for the server room and the final layer is the use of security containers or lockable commercial cabinets. All layers are designed to limit access to those with the appropriate authorisation to access the system and infrastructure.
              </para>
              <para>
                Deployable platforms need to meet physical security certification requirements as per any other system. Physical security certification authorities dealing with deployable platforms can have specific requirements that supersede the requirements of this manual and as such security personnel should contact their appropriate physical security certification authority to seek guidance.
              </para>
              <para>
                In the case of deployable platforms, physical security requirements may also include perimeter controls, building standards and manning levels.
              </para>
            </content>
            <controls>
              <block>
                <ID>0810</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Facility and network infrastructure physical security</title>
                <content>
                  <para>
                    Agencies must ensure that any facility containing a system, including deployable systems, is certified and accredited against the requirements in the Australian Government Physical Security Management Protocol.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Network infrastructure in unsecured spaces</title>
            <content>
              <para>
                Agencies do not have control over sensitive or classified information when it is communicated over public network infrastructure or over infrastructure in unsecured spaces (Zone One security areas). They must ensure information is encrypted to a sufficient level that if it was captured it would not be cost-effective to retrieve the original information.
              </para>
            </content>
            <controls>
              <block>
                <ID>0157</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Network infrastructure in unsecured spaces</title>
                <content>
                  <para>
                    Agencies communicating sensitive or classified information over public network infrastructure or over infrastructure in unsecured spaces (Zone One security areas) must use encryption approved for communicating such information over public network infrastructure.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Preventing observation by unauthorised people</title>
            <content>
              <para>
                Facilities without sufficient perimeter security are often exposed to the potential for observation through windows. Ensuring information on workstation screens is not visible will assist in reducing this security risk. This can be achieved by using blinds or drapes on the inside of the windows.
              </para>
            </content>
            <controls>
              <block>
                <ID>0164</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Preventing observation by unauthorised people</title>
                <content>
                  <para>
                    Agencies should prevent unauthorised people from observing systems, in particular, displays and keyboards.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Servers and Network Devices</title>
        <objective>
          <block>
            <content>
              <para>
                Server and communication rooms protect servers and network devices.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the requirements for the physical security of servers and network devices.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information relating to the physical security of facilities, network infrastructure and ICT equipment and media can be found in other sections of this chapter.
              </para>
            </content>
          </block>
          <block>
            <title>Server and communications rooms</title>
            <content>
              <para>
                Agencies must certify and accredit the physical security of a facility and server or communications room against the requirements in the Australian Government Physical Security Management Protocol. In such cases, because of the additional layer of security described in this manual, the requirements for physical storage of server and communications equipment in the Australian Government Physical Security Management Protocol can be lowered according to the Physical security of ICT equipment systems and facilities guideline.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Securing server rooms, communications rooms and security containers</title>
            <content>
              <para>
                If personnel leave server rooms, communications rooms and security containers or rooms unlocked, with keys in the locks or with security functions disabled, it negates the purpose of providing security. Such activities will compromise the security efforts and must not be permitted.
              </para>
            </content>
            <controls>
              <block>
                <ID>1053</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Securing server rooms, communications rooms and security containers</title>
                <content>
                  <para>
                    Agencies must ensure that servers and network devices are secured in either security containers or rooms as specified in the Australian Government Physical Security Management Protocol.
                  </para>
                </content>
              </block>
              <block>
                <ID>0813</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Securing server rooms, communications rooms and security containers</title>
                <content>
                  <para>
                    Agencies must not leave server rooms, communications rooms and security containers or rooms in an unsecured state.
                  </para>
                </content>
              </block>
              <block>
                <ID>1074</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Securing server rooms, communications rooms and security containers</title>
                <content>
                  <para>
                    Agencies must ensure that keys or equivalent access mechanisms to server rooms, communications rooms and security containers or rooms are appropriately controlled.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>No-lone zones</title>
            <content>
              <para>
                Areas containing particularly sensitive materials or ICT equipment can be provided with additional security through the use of a designated no-lone zone. The aim of this designation is to enforce two-person integrity, where all actions are witnessed by at least one other person.
              </para>
            </content>
            <controls>
              <block>
                <ID>0150</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>No-lone zones</title>
                <content>
                  <para>
                    Agencies operating no-lone zones must suitably signpost the area and have all entry and exit points appropriately secured.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>ICT Equipment and Media</title>
        <objective>
          <block>
            <content>
              <para>
                ICT equipment and media is physically secured during operational and non-operational hours.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the physical security of ICT equipment and media. This includes but is not limited to workstations, printers, photocopiers, scanners, Multifunction Devices, optical media, flash drives, portable hard drives and memory cards.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Additional information relating to ICT equipment and media can be found in the Fax Machines and Multifunction Devices section of the Communications Systems and Devices chapter as well as in the Product Security and Media Security chapters. Sanitisation information can be found in the Media Sanitisation section of the Media Security chapter while information on the encryption of media can be found in the Cryptographic Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Accounting for Information and Communications Technology equipment and media</title>
            <content>

              <para>
                Ensuring that ICT equipment and media is accounted for by using a register and regular audits will assist in preventing theft and alerting appropriate authorities if theft occurs. Individual media not contained in ICT equipment needs to be individually tracked while media in ICT equipment can be tracked at the equipment level.
              </para>
            </content>
            <controls>
              <block>
                <ID>0159</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accounting for Information and Communications Technology equipment and media</title>
                <content>
                  <para>
                    Agencies must account for all sensitive and classified ICT equipment and media.
                  </para>
                </content>
              </block>
              <block>
                <ID>0336</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Accounting for Information and Communications Technology equipment and media</title>
                <content>
                  <para>
                    Agencies must register all ICT equipment and media with a unique identifier in an appropriate register.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Securing Information and Communications Technology equipment and media</title>
            <content>
              <para>
                During operational and non-operational hours, ICT equipment and media needs to be stored in accordance with the Australian Government Physical Security Management Protocol.
              </para>
              <list>
                <head>The physical security requirements of the Australian Government Physical Security Management Protocol can be achieved by:</head>
                <item>
                  ensuring ICT equipment and media always resides in an appropriate Security Zone
                </item>
                <item>
                  storing ICT equipment and media during non-operational hours in an appropriate security container or room
                </item>
                <item>
                  using ICT equipment with a removable hard drive which is stored during non-operational hours in an appropriate security container or room as well as sanitising the ICT equipment’s Random Access Memory (RAM)
                </item>
                <item>
                  using ICT equipment without a hard drive as well as sanitising the ICT equipment’s RAM
                </item>
                <item>
                  using an encryption product to reduce the physical storage requirements of the hard drive in ICT equipment to an unclassified level as well as sanitising the ICT equipment’s RAM.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0161</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Securing Information and Communications Technology equipment and media</title>
                <content>
                  <para>
                    Agencies must ensure that ICT equipment and media with sensitive or classified information is secured in accordance with the requirements for storing sensitive or classified information in the Australian Government Physical Security Management Protocol.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Reducing the physical storage requirements for Information and Communications Technology equipment</title>
            <content>
              <para>
                In some circumstances it may not be feasible to secure ICT equipment during non-operational hours by storing it in a security container or room, using a removable hard drive, using ICT equipment without a hard drive or using approved encryption. In such cases the Australian Government Physical Security Management Protocol allows for the reduction of physical storage requirements for ICT equipment if appropriate logical controls are applied. This can be achieved by configuring systems to prevent the storage of sensitive or classified information on the hard drive (e.g. storing profiles and work documents on network shares) and enforcing scrubbing of the operating system swap file and other temporary data at logoff or shutdown in addition to the standard practice of sanitising the ICT equipment’s RAM.
              </para>
              <para>
                The security measures described in the previous paragraph do not constitute sanitisation of the hard drive in the ICT equipment. Therefore, the hard drive retains its classification for the purposes of reuse, reclassification, declassification, sanitisation, destruction and disposal as specified in this manual.
              </para>
              <para>
                As hybrid hard drives and solid state drives cannot be sanitised in the same manner as standard magnetic hard drives, refer to the Media Sanitisation section of the Media Security chapter, the logical controls described above are not approved as a method of lowering the physical storage requirements of the ICT equipment.
              </para>
              <para>
                There is no guarantee that techniques such as preventing the storage of sensitive or classified information on hard drives and scrubbing the operating system swap file and other temporary data at logoff or shutdown will always work effectively or will not be bypassed due to unexpected circumstances such as an unexpected loss of power to the workstation. As such these security risks need to be considered when implementing such a solution and documented in the System Security Plan (SSP).
              </para>
            </content>
            <controls>
              <block>
                <ID>0162</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Reducing the physical storage requirements for Information and Communications Technology equipment</title>
                <content>
                  <list>
                    <head>Agencies preventing the storage of sensitive or classified information on hard drives and enforcing scrubbing of the operating systems swap files and other temporary data at logoff or shutdown should:</head>
                    <item>
                      assess the security risks associated with such a practice
                    </item>
                    <item>
                      in the SSP specify the processes and conditions for their application.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                For further information on physical security and media security see the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
  </part>
  <part>
    <title>Personnel Security</title>
    <chapter>
      <title>Personnel Security for Systems</title>
      <section>
        <title>Information Security Awareness and Training</title>
        <objective>
          <block>
            <content>
              <para>
                A security culture is fostered through continual information security awareness and training tailored to roles and responsibilities.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes information security awareness and training that should be provided to personnel.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                The following sections of this chapter contain information on areas that specifically need to be covered by the training provided.
              </para>
              <para>
                Additional information that should be included in information security awareness and training is provided in the Web Content and Connections and Email Applications sections of the Software Security chapter and the Internet Protocol Telephony section of the Network Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Information security awareness and training</title>
            <content>
              <list>
                <head>Information security awareness and training programs are designed to help personnel to:</head>
                <item>
                  become familiar with their roles and responsibilities
                </item>
                <item>
                  understand and support security requirements
                </item>
                <item>
                  learn how to fulfil their security responsibilities.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0252</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Information security awareness and training</title>
                <content>
                  <para>
                    Agencies must provide ongoing information security awareness and training for personnel on information security policies including topics such as responsibilities, consequences of non-compliance, and potential security risks and counter-measures.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Information security awareness and training responsibility</title>
            <content>
              <para>
                Agencies are responsible for ensuring that an appropriate information security awareness and training program is provided to personnel. Without management support, security personnel might not have sufficient resources to facilitate awareness and training for other personnel.
              </para>
              <para>
                Personnel will naturally lose awareness or forget training over time. Providing ongoing information security awareness and training helps keep personnel aware of issues and their responsibilities.
              </para>
              <para>
                Methods that can be used to continually promote awareness include logon banners, system access forms and departmental bulletins or memoranda.
              </para>
            </content>
            <controls>
              <block>
                <ID>0251</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Information security awareness and training responsibility</title>
                <content>
                  <para>
                    Agencies must ensure that all personnel who have access to a system have sufficient information security awareness and training.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Degree and content of information security awareness and training</title>
            <content>

              <para>
                The exact degree and content of information security awareness and training depends on the objectives of the agency. Personnel with responsibilities beyond that of a general user should have tailored training to meet their needs.
              </para>
              <para>
                Guidance provided to personnel should include sufficient emphasis on activities that are not allowed on systems. The minimum list of content given below ensures that personnel are sufficiently exposed to issues that, if they are ignorant of them, could cause a cyber security incident.
              </para>
            </content>
            <controls>
              <block>
                <ID>0253</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Degree and content of information security awareness and training</title>
                <content>
                  <para>
                    Agencies should align the exact degree and content of information security awareness and training to a person’s roles and responsibilities.
                  </para>
                </content>
              </block>
              <block>
                <ID>0922</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Degree and content of information security awareness and training</title>
                <content>
                  <list>
                    <head>Agencies should ensure that information security awareness and training includes:</head>
                    <item>
                      the purpose of the training or awareness program
                    </item>
                    <item>
                      security appointments and contacts
                    </item>
                    <item>
                      the legitimate use of system accounts, software and information
                    </item>
                    <item>
                      the security of accounts, including shared passphrases
                    </item>
                    <item>
                      security risks associated with unnecessarily exposing email addresses and other personal details
                    </item>
                    <item>
                      authorisation requirements for applications, databases and data
                    </item>
                    <item>
                      the security risks associated with non-agency systems, particularly the Internet
                    </item>
                    <item>
                      reporting any suspected compromises or anomalies
                    </item>
                    <item>
                      reporting requirements for cyber security incidents, suspected compromises or anomalies
                    </item>
                    <item>
                      classifying, marking, controlling, storing and sanitising media
                    </item>
                    <item>
                      protecting workstations from unauthorised access
                    </item>
                    <item>
                      informing the support section when access to a system is no longer needed
                    </item>
                    <item>
                      observing rules and regulations governing the secure operation and authorised use of systems.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0255</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Degree and content of information security awareness and training</title>
                <content>
                  <list>
                    <head>Agencies should ensure that information security awareness and training includes advice to personnel not to attempt to:</head>
                    <item>
                      physically damage systems
                    </item>
                    <item>
                      bypass, strain or test security measures
                    </item>
                    <item>
                      introduce or use unauthorised Information and Communications Technology (ICT) equipment or software on a system
                    </item>
                    <item>
                      assume the roles and privileges of others
                    </item>
                    <item>
                      attempt to gain access to information for which they have no authorisation
                    </item>
                    <item>
                      relocate ICT equipment without proper authorisation.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System familiarisation training</title>
            <content>
              <para>
                A TOP SECRET system needs increased awareness by personnel. Ensuring familiarisation with information security policies and procedures, the secure operation of the system and basic information security training, provides them with specific knowledge relating to these types of systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0256</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System familiarisation training</title>
                <content>
                  <para>
                    Agencies must provide all system users with familiarisation training on the information security policies and procedures and the secure operation of the system before being granted unsupervised access to the system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Disclosure of information while on courses</title>
            <content>
              <para>
                Government personnel attending courses with non-government personnel may not be aware of the consequences of disclosing information relating to the security of their systems. Raising awareness of such consequences should prevent any disclosure that could lead to a targeted attack being launched against their systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0257</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Disclosure of information while on courses</title>
                <content>
                  <para>
                    Agencies should advise personnel attending courses along with non-government personnel not to disclose any details that could be used to compromise security.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Authorisations, Security Clearances and Briefings</title>
        <objective>
          <block>
            <content>
              <para>
                Only appropriately authorised, cleared and briefed personnel are allowed access to systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the authorisations, security clearances and briefings required by personnel to access systems. Information on the technical implementation of access controls for systems can be found in the System Access section of the Access Control chapter.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Security clearances – Australian and foreign</title>
            <content>

              <para>
                Where this manual refers to security clearances, the reference applies to Australian security clearances or security clearances from a foreign government which are recognised by Australia under a security of information arrangement.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Documenting authorisations, security clearance and briefing requirements</title>
            <content>
              <para>
                Ensuring that the requirements for access to a system are documented and agreed upon helps determine if personnel have appropriate authorisations, security clearances and need-to-know to access the system.
              </para>
              <para>
                Types of system accounts for which access requirements need to be documented include general users, privileged users, contractors and visitors.
              </para>
            </content>
            <controls>
              <block>
                <ID>0432</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Documenting authorisations, security clearance and briefing requirements</title>
                <content>
                  <para>
                    Agencies must specify in the System Security Plan any authorisations, security clearances and briefings necessary for system access.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Authorisation and system access</title>
            <content>
              <para>
                Personnel seeking access to a system need to have a genuine business requirement to access the system as verified by their manager. Once a requirement to access a system is established, personnel should only be given the privileges that they need to undertake their duties. Providing all personnel with privileged access when there is no requirement for privileged access can be a significant threat to a system.
              </para>
            </content>
            <controls>
              <block>
                <ID>0405</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Authorisation and system access</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      limit system access on a need-to-know basis
                    </item>
                    <item>
                      have any requests for access to a system authorised by the person’s manager
                    </item>
                    <item>
                      provide personnel with the least amount of privileges needed to undertake their duties
                    </item>
                    <item>
                      review system access and privileges at least annually and when personnel change roles
                    </item>
                    <item>
                      when reviewing access, ensure a response from the person’s manager confirming the need to access the system is still valid, otherwise access will be removed.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Recording authorisation for personnel to access systems</title>
            <content>
              <para>
                A record of a completed system account request form signed by the person’s manager should be retained. This is required to ensure there is a record of all personnel authorised to access a system, their user identification, who provided the authorisation, when the authorisation was granted and when the access was reviewed.
              </para>
            </content>
            <controls>
              <block>
                <ID>0407</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Recording authorisation for personnel to access systems</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      maintain a secure record of:
                    </item>
                    <item>
                      all personnel authorised to a system
                    </item>
                    <item>
                      their user identification
                    </item>
                    <item>
                      who provided the authorisation to access the system
                    </item>
                    <item>
                      when the authorisation was granted
                    </item>
                    <item>
                      when the access was reviewed
                    </item>
                    <item>
                      maintain the record for the life of the system to which access is granted.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Security clearance for system access</title>
            <content>

              <para>
                A security clearance provides assurance that personnel can be trusted with access to sensitive or classified information that is processed, stored or communicated by a system.
              </para>
            </content>
            <controls>
              <block>
                <ID>0434</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Security clearance for system access</title>
                <content>
                  <para>
                    Agencies must ensure that personnel hold an appropriate security clearance according to the requirements in the Australian Government Personnel Security Management Protocol before being granted access to a system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System access briefings</title>
            <content>
              <para>
                Some systems may contain caveated or compartmented information. There may be unique briefings that personnel need before being granted access to such systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0435</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System access briefings</title>
                <content>
                  <para>
                    All personnel must have received any necessary briefings before being granted access to a system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Access by foreign nationals to particularly sensitive systems</title>
            <content>
              <para>
                Australian Eyes Only (AUSTEO) information is restricted to Australian nationals.
              </para>
              <para>
                Australian Government Access Only (AGAO) information is restricted to Australian nationals, with the exception of seconded foreign nationals, who may access such information to undertake their assigned duties.
              </para>
            </content>
            <controls>
              <block>
                <ID>0409</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Access by foreign nationals to particularly sensitive systems</title>
                <content>
                  <para>
                    Agencies must not allow foreign nationals, including seconded foreign nationals, to have access to systems that process, store or communicate AUSTEO information unless effective controls and procedures are in place to ensure AUSTEO information is not passed to, or made accessible by, foreign nationals, including seconded foreign nationals.
                  </para>
                </content>
              </block>
              <block>
                <ID>0411</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Access by foreign nationals to particularly sensitive systems</title>
                <content>
                  <para>
                    Agencies must not allow foreign nationals, excluding seconded foreign nationals, to have access to systems that process, store or communicate AGAO information unless effective controls and procedures are in place to ensure AGAO information is not passed to, or made accessible by, foreign nationals, excluding seconded foreign nationals.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Access by foreign nationals to Australian systems</title>
            <content>

              <para>
                When information from foreign nations is entrusted to the Australian Government, care needs to be taken to ensure that foreign nationals do not have access to such information unless it has also been released to their country.
              </para>
            </content>
            <controls>
              <block>
                <ID>0816</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Access by foreign nationals to Australian systems</title>
                <content>
                  <para>
                    Where systems process, store or communicate information with nationality releasability markings, agencies must not allow foreign nationals, including seconded foreign nationals, to have access to such information that is not marked as releasable to their nation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Temporary access to classified information</title>
            <content>
              <para>
                Under strict circumstances access to systems may be granted to personnel who lack the appropriate security clearance.
              </para>
            </content>
            <controls>
              <block>
                <ID>0440</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Temporary access to classified information</title>
                <content>
                  <para>
                    Agencies must follow the Temporary access to classified information requirements in the Australian Government Personnel Security Management Protocol before granting personnel temporary access to a system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Controlling temporary access</title>
            <content>
              <para>
                When personnel are granted access to a system under the provisions of temporary access they need to be closely supervised or have their access controlled in such a way that they only have access to information they require to undertake their duties.
              </para>
            </content>
            <controls>
              <block>
                <ID>0441</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Controlling temporary access</title>
                <content>
                  <list>
                    <head>Agencies granting personnel temporary access to a system must ensure that either:</head>
                    <item>
                      effective controls are in place to restrict access to only information that is necessary to undertake their duties
                    </item>
                    <item>
                      they are continually supervised by another system user who has the appropriate security clearances to access the system.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Granting emergency access</title>
            <content>
              <para>
                Emergency access to a system may be granted where there is an immediate and critical need to access information for which personnel do not have the appropriate security clearance.
              </para>
            </content>
            <controls>
              <block>
                <ID>0442</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Granting emergency access</title>
                <content>
                  <para>
                    Agencies must follow the Temporary access to classified information requirements in the Australian Government Personnel Security Management Protocol before granting personnel emergency access to a system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Accessing systems without necessary security clearances and briefings</title>
            <content>
              <para>
                Temporary or emergency access to systems processing, storing or communicating caveated or compartmented information is not permitted.
              </para>
            </content>
            <controls>
              <block>
                <ID>0443</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Accessing systems without necessary security clearances and briefings</title>
                <content>
                  <para>
                    Agencies must not grant personnel temporary access or emergency access to systems that process, store or communicate caveated or compartmented information.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                The Australian Government Personnel Security Management Protocol contains Australian government policy on security clearances.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Using the Internet</title>
        <objective>
          <block>
            <content>
              <para>
                Personnel use Internet services in a responsible and security conscience manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the policy and awareness considerations that personnel using Internet services need to know and why personnel should not use web-based email and peer-to-peer applications over the Internet.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                This section applies to services utilising the Internet such as web browsing, Instant Messaging (IM), Internet Relay Chat (IRC), Internet Protocol (IP) telephony, video conferencing and peer-to-peer applications. Agencies need to be aware and educate personnel that unless applications using these communications methods are evaluated and approved by the Defence Signals Directorate they must not be used for communicating sensitive or classified information over the Internet.
              </para>
              <para>
                Additional technical information and controls are in the Web Content and Connections and Email Applications sections of the Software Security chapter and the Internet Protocol Telephony section of the Network Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using the Internet</title>
            <content>

              <para>
                Agencies need to determine what constitutes suspicious contact in their own work environment such as being contacted by an unknown source and ensure personnel know how to report these events. Suspicious contact may relate to questions regarding the work duties of personnel or the specifics of projects being undertaken by personnel.
              </para>
            </content>
            <controls>
              <block>
                <ID>0817</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Using the Internet</title>
                <content>
                  <para>
                    Agencies must ensure personnel know how to report any suspicious contact and what suspicious contact is, especially contact from external sources using Internet services.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Awareness of web usage policies</title>
            <content>
              <para>
                There is little value in having web usage policies if personnel are not made aware of their existence.
              </para>
            </content>
            <controls>
              <block>
                <ID>0818</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Awareness of web usage policies</title>
                <content>
                  <para>
                    Agencies must make personnel aware of their web usage policies.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Monitoring web usage</title>
            <content>
              <para>
                Agencies should monitor breaches of web usage policies — for example, attempts to access blocked websites such as pornographic and gambling websites — as well as compiling a list of personnel who excessively download or upload data without a legitimate business requirement.
              </para>
            </content>
            <controls>
              <block>
                <ID>0819</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Monitoring web usage</title>
                <content>
                  <para>
                    Agencies should implement measures to monitor their personnel’s compliance with their web usage policies.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Posting official information on websites</title>
            <content>
              <para>
                Personnel need to take special care not to accidentally post sensitive or classified information on public websites, especially in forums, blogs and social networking sites. Even unclassified information that appears to be benign in isolation, such as the Global Positioning System information in a picture, could, along with other information, have a considerable security impact on the government.
              </para>
              <para>
                To ensure that personal opinions of personnel are not interpreted as official policy, personnel will need to maintain separate professional and personal accounts when using websites, especially when using online social networks.
              </para>
            </content>
            <controls>
              <block>
                <ID>0820</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Posting official information on websites</title>
                <content>
                  <para>
                    Agencies must ensure personnel are instructed to take special care not to post sensitive or classified information on public websites and how to report cases where such information is posted.
                  </para>
                </content>
              </block>
              <block>
                <ID>1146</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Posting official information on websites</title>
                <content>
                  <para>
                    Agencies must ensure personnel posting information on websites maintain separate professional accounts from any personal accounts they have for websites.
                  </para>
                </content>
              </block>
              <block>
                <ID>1147</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Posting official information on websites</title>
                <content>
                  <para>
                    Agencies should ensure personnel are aware of the approved websites on which personnel can post information authorised for release into the public domain.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Posting personal information on websites</title>
            <content>
              <para>
                Personnel need to be aware that any personal information they post on websites could be used to develop a detailed profile of their lifestyle and hobbies in order to attempt to build a trust relationship with them or others. This relationship could then be used to attempt to elicit sensitive or classified information from them or implant malicious software on systems by having them, for example, open emails or visit websites with malicious content.
              </para>
              <para>
                Personnel should use the privacy settings on websites to restrict who can view their information and not allow public access. The privacy settings should be regularly reviewed for changes to the website policy and ensure the settings maintain privacy.
              </para>
            </content>
            <controls>
              <block>
                <ID>0821</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Posting personal information on websites</title>
                <content>
                  <para>
                    Agencies should ensure that personnel are informed of the security risks associated with posting personal information on websites, especially for those personnel holding higher level security clearances.
                  </para>
                </content>
              </block>
              <block>
                <ID>0924</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Posting personal information on websites</title>
                <content>
                  <list>
                    <head>Personnel should avoid posting personal information, such as the following, on websites:</head>
                    <item>
                      past and present employment details
                    </item>
                    <item>
                      personal details
                    </item>
                    <item>
                      schools/institutions
                    </item>
                    <item>
                      clubs/hobbies
                    </item>
                    <item>
                      educational qualifications
                    </item>
                    <item>
                      current work duties
                    </item>
                    <item>
                      work contact details.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1148</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Posting personal information on websites</title>
                <content>
                  <para>
                    Personnel should use the privacy settings on websites to restrict access to personal information they post to only those they authorise to view it.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Awareness of email usage policies</title>
            <content>
              <para>
                There is little value in having email usage policies for personnel if they are not made aware of their existence.
              </para>
            </content>
            <controls>
              <block>
                <ID>0266</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Awareness of email usage policies</title>
                <content>
                  <para>
                    Agencies must make personnel aware of their email usage policies.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Monitoring email usage</title>
            <content>

              <para>
                Agencies should monitor breaches of email usage policies—for example, attempts to send prohibited file types or executables, attempts to send excessively sized attachments or attempts to send sensitive or classified information without appropriate protective markings.
              </para>
            </content>
            <controls>
              <block>
                <ID>0822</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Monitoring email usage</title>
                <content>
                  <para>
                    Agencies should implement measures to monitor their personnel’s compliance with email usage policies.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Public web-based email services</title>
            <content>
              <para>
                Using public web-based email services allows personnel to bypass security measures that agencies have put in place to protect against malicious code or phishing attempts distributed via email. Web-based email is email accessed using a web browser; examples of web-based email services include Gmail, Hotmail and email portals provided by Internet service providers.
              </para>
            </content>
            <controls>
              <block>
                <ID>0267</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Public web-based email services</title>
                <content>
                  <para>
                    Agencies must not allow personnel to send and receive emails using public web-based email services.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Peer-to-peer applications</title>
            <content>

              <para>
                Personnel using peer-to-peer file sharing applications are often unaware of the extent of files that are being shared from their workstation. In most cases peer-to-peer file sharing applications will scan workstations for common file types and share them automatically for public consumption. Examples of peer-to-peer file sharing applications include Shareaza, KaZaA, eMule and uTorrent.
              </para>
              <para>
                Some peer-to-peer IP telephony applications, such as Skype, use proprietary protocols and make heavy use of encrypted tunnels to bypass firewalls. Because of this their use cannot be regulated or monitored. It is important that agencies implementing an IP telephony solution over the Internet choose applications that use protocols that are open to inspection by Intrusion Detection Systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0823</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Peer-to-peer applications</title>
                <content>
                  <para>
                    Agencies should not allow personnel to use peer-to-peer applications over the Internet.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sending and receiving files via peer-to-peer applications</title>
            <content>
              <para>
                When personnel send or receive files via peer-to-peer file sharing, including IM and IRC applications, they bypass security measures put in place to detect and quarantine malicious code. Personnel should be encouraged to send and receive files via agency established methods such as email to ensure they are appropriately marked and scanned for malicious code.
              </para>
            </content>
            <controls>
              <block>
                <ID>0824</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Sending and receiving files via peer-to-peer applications</title>
                <content>
                  <para>
                    Agencies should not allow personnel to send or receive files via peer-to-peer applications.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
  </part>
  <part>
    <title>Communications Security</title>
    <chapter>
      <title>Communications Infrastructure</title>
      <section>
        <title>Cable Management Fundamentals</title>
        <objective>
          <block>
            <content>
              <para>
                Cable management systems are implemented to allow easy integration of systems across government.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes cable distribution systems used in facilities in Australia. When designing cable management systems, the Cable Labelling and Registration and Cable Patching sections of this chapter also apply.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Applicability of controls in this section</title>
            <content>
              <para>
                The controls in this section only apply to new cable installations or upgrades. Agencies are not required to retro-fit existing cabling infrastructure to align with changes to controls in this manual. The controls are applicable to all facilities. For deployable platforms or facilities outside of Australia, consult the Emanation Security Threat Assessments section of this chapter.
              </para>
            </content>
          </block>
          <block>
            <title>Common implementation scenarios</title>
            <content>
              <para>
                This section provides common requirements for non-shared government facilities, shared government facilities and shared non-government facilities. Further specific requirements for each scenario can be found in the other sections of this chapter.
              </para>
            </content>
          </block>
          <block>
            <title>Cabling</title>
            <content>

              <para>
                For cabling, the cable’s protective sheath is not considered to be a conduit. For fibre optic cables with subunits, the cable’s outer protective sheath is considered to be a conduit.
              </para>
            </content>
          </block>
          <block>
            <title>Government systems</title>
            <content>
              <para>
                All references to ‘Government’ systems in the tables relate to systems containing unclassified but sensitive information not intended for public release, such as Dissemination Limiting Marker information. ‘Government’ is not a classification under the Australian Government Security Classification System as mandated by the Attorney-General’s Department.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Cabling standards</title>
            <content>
              <para>
                All cabling must be installed by an endorsed cable installer to the relevant Australian Standards to ensure personnel safety and system availability.
              </para>
            </content>
            <controls>
              <block>
                <ID>0181</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cabling standards</title>
                <content>
                  <para>
                    Agencies must install all cabling in accordance with the relevant Australian Standards as directed by the Australian Communications and Media Authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cable colours</title>
            <content>
              <para>
                The use of defined cable colours provides an easily recognisable cable management system.
              </para>
            </content>
            <controls>
              <block>
                <ID>0926</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabling standards</title>
                <content>
                  <para>
                    Agencies should comply with the cable colours specified in the following table.
                  </para>
                  <table>
                        <header>
                          <cell>System</cell>
                          <cell>Cable colour</cell>
                        </header>
                        <row>
                          <cell>SECRET</cell>
                          <cell>Pink</cell>
                        </row>
                        <row>
                          <cell>CONFIDENTIAL</cell>
                          <cell>Green</cell>
                        </row>
                        <row>
                          <cell>PROTECTED</cell>
                          <cell>Blue</cell>
                        </row>
                        <row>
                          <cell>Government</cell>
                          <cell>Black or grey</cell>
                        </row>
                  </table>

                </content>
              </block>
              <block>
                <ID>0186</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cabling standards</title>
                <content>
                  <para>
                    In TOP SECRET areas, agencies must comply with the cable colours specified in the following table.
                  </para>
                  <table>
                        <header>
                          <cell>System</cell>
                          <cell>Cable colour</cell>
                        </header>
                        <row>
                          <cell>TOP SECRET</cell>
                          <cell>Red</cell>
                        </row>
                        <row>
                          <cell>SECRET</cell>
                          <cell>Pink</cell>
                        </row>
                        <row>
                          <cell>CONFIDENTIAL</cell>
                          <cell>Green</cell>
                        </row>
                        <row>
                          <cell>PROTECTED</cell>
                          <cell>Blue</cell>
                        </row>
                        <row>
                          <cell>Government</cell>
                          <cell>Black or grey</cell>
                        </row>
                  </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cable colours for foreign systems in Australian facilities</title>
            <content>

              <para>
                Different cable colours for foreign systems in Australian facilities helps prevent unintended patching of Australian and foreign systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0825</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Cable colours for foreign systems in Australian facilities</title>
                <content>
                  <para>
                    Agencies should not allow cable colours for foreign systems installed in Australian facilities to be the same colour as cables used for Australian systems.
                  </para>
                </content>
              </block>
              <block>
                <ID>0827</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Cable colours for foreign systems in Australian facilities</title>
                <content>
                  <para>
                    Agencies must not allow cable colours for foreign systems installed in Australian facilities to be the same colour as cables used for Australian systems.
                  </para>
                </content>
              </block>
              <block>
                <ID>0826</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cable colours for foreign systems in Australian facilities</title>
                <content>
                  <para>
                    The cable colour to be used for foreign systems should be agreed between the host agency, the foreign system owner and the accreditation authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0828</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cable colours for foreign systems in Australian facilities</title>
                <content>
                  <para>
                    The cable colour to be used for foreign systems must be agreed between the host agency, the foreign system owner and the accreditation authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cable groupings</title>
            <content>
              <para>
                Grouping cables provides a method of sharing conduits and cable reticulation systems in the most efficient manner.
              </para>
            </content>
            <controls>
              <block>
                <ID>0187</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Cable groupings</title>
                <content>
                  <para>
                    Agencies must not deviate from the approved group combinations for cables as indicated below.
                  </para>
                  <table>
                        <header>
                          <cell>Group</cell>
                          <cell>Approved combination</cell>
                        </header>
                        <row>
                          <cell rowspan="2">1</cell>
                          <cell>Government</cell>
                        </row>
                        <row>
                          <cell>PROTECTED</cell>
                        </row>
                        <row>
                          <cell rowspan="2">2</cell>
                          <cell>CONFIDENTIAL</cell>
                        </row>
                        <row>
                          <cell>SECRET</cell>
                        </row>
                        <row>
                          <cell>3</cell>
                          <cell>TOP SECRET</cell>
                        </row>
                  </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Fibre optic cables sharing a common conduit</title>
            <content>
              <para>
                Fibre optic cables of various cable groups can share a common conduit to reduce installation costs.
              </para>
            </content>
            <controls>
              <block>
                <ID>0189</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Fibre optic cables sharing a common conduit</title>
                <content>
                  <para>
                    With fibre optic cables the fibres in the sheath, as shown below, must only carry a single group.
                  </para>
									              <image>
iVBORw0KGgoAAAANSUhEUgAAAmAAAAGjCAIAAAAEnT4AAAAABGdBTUEAALGPC/xhBQAAxJtJREFUeF7t/QvUXkd554l2J9C9Zs2ZtXJ6zZnTM4vTpodenZgzhjhAFj2H
ZuZM3LQxwXYzxz0QQkKCSEPTCTgGOh0TQyBOYpO2sWwDBmzLgJEh2FaMMZYvyBfF8k2WJdlYkmVLlvRJ1v3+SbKRfX57/9+3vvr2par2e78839rL6/On2rVrP1W7/vX8
n9s/fPXVV/+B/ZgETAImAZOAScAkUJAAAGk/JgGTgEnAJGASMAkUJPAPTCImAZOAScAkYBIwCZQlYABpq8IkYBIwCZgETAIVEjCAtGVhEjAJmARMAiYBA0hbAyYBk4BJ
wCRgEkiTgGmQaXKyViYBk4BJwCQwZRIwgJyyCbfXNQmYBEwCJoE0CRhApsnJWpkETAImAZPAlEnAAHLKJtxe1yRgEjAJmATSJGAAmSYna2USMAmYBEwCUyYBA8gpm3B7
XZOAScAkYBJIk4ABZJqcrJVJwCRgEjAJTJkEDCCnbMLtdfsigZOHN9x1+Ufe/oZTXv+GMy/8zsodJ7OnHNtw/QffcOpFyw7m/9flz8l1i85+42kXLjvYZT92u0mgXxKY
wK/AALJfi8X6nR4JnJy59eOnvj5DR12nfmrJzIneAOTBZZ879Z2fW7b7VQPI6VlP4/mmE/kVGECO52K0UY+QBHJN8ZSzP79sBlXx5I57Pn+mVL1eaJAGkCM00TaUgAQm
8yswgLRFbxLoUgInDy676LQ5KnX3sgvf+Yazr99wUgB54ZJ7Ljsr0yxbCJo97PCGey9bcFrGx160ZEOLND2546GFGUn7xrMu+s6i//zODGIzdJRW+s7P3fNATrH+4N7L
3pcTuX+xbAdKqv2YBEZEApP5FRhAjsjysmGMswROziy76IMfveIh2R7bPwLIM846441t6lX2yP0rBXK6zly48vDJVw8/evmZ7Wb536sB8sx3v6t9o9kjx3nFTOLYJ/Er
MICcxJVq79QLCezdu/fiiy9+7T/6x3XX/IfgoXD/kpsXfu6ia5cs23A4+zefdDoxc+unTkMRxJqY6YVv//itL2Rg2mJQd2Y6aEvFPHl43Xc+emoOkHMNWjbIluJ48oUl
H3t7z9x/eiEr62NSJTDlX4EB5KQubHuvriSwdevWt73t1wPoyD+1H3Bix8qfLLmt5br6anaOft9Zlz16eL4N8uSG68/NATL/xfPoOeWN516/ap3v7+r741TbIHth3exK
PHbzVEjAvgIDyKlY6PaSjSQwOzu7YMECoSO/3FzzM59KdeEcDr2O+mEeBpCNpsAaD10C9hUwBQaQQ1+HNoCRk8BnPvtZoeOVV16VMrgc/N7+0eufypjVw08twtcm89mp
BkiPYj15eOXCs0754KINR3OK9X2Xr9xPB3KXr6RY23ZH0yBTpsXadCUBZ1+Y5q/AALKrNWQ3T54EbrjhBqc7cohOekEZBT3itBzm4TTIgpNOC/PmOem886wzTzeATJK8
NeqPBCBN7CswDbI/i8t6HVsJLF++XPsCBkjcExq8x+F1Sy48O8fIt3/0srs24JhaY4PM+myHeZz2ke+sy1pmeuPhDbd+LnNkRRO9Z8mFeZgHfzYbZIM5sKa9kYB9BU6O
pkH2ZklZLxMgAd8lYf369RPwRvYKJoGmErCvwJeYAWTT9WPtJ1MCsKnnnHOu1MelS5dO5kvaW5kEghKwr6AgHgNI+2JMApkEmjrmmNRMApMnAfsKDCAnb1XbG3UrgU4c
c7p9pt1vEhgtCdhXUJ4P0yBHa43aaAYvAd8lIdVtdfCjtCeaBPopgc4dc/o5qqH3bQA59CmwAQxTAr5LAr8Pcyj2bJPAkCRgjjl1gjeAHNKStMeOgATQF10+OU7QIzAi
G4JJYNASMMecgMQNIAe9HO15oyMBl08uMVfI6IzcRmIS6JUEzDHHALJXa8n6mRwJAIouV8jkvJW9iUmgiQTMMScsLdMgm6wmazspEjDHnEmZSXuPziVgX0FUdgaQURFZ
g0mTAC4Jro6VOeZM2uza+6RJwNzTUuRkAJkiJWszORIwx5zJmUt7k04lYF9BouQMIBMFZc0mRALmmDMhE2mv0YUE7CtIFJ4BZKKgrNkkSMA55uC5NwnvY+9gEmguAXNP
S5eZAWS6rKzleEuAFOQyPZKU3DLmjPdc2ug7lYA55jSSnAFkI3FZ43GVAOWrXKFHc8wZ11m0cXcnAXNPayo/A8imErP24ycBSh9bxpzxmzYbcU8lYI45HYjTALIDodkt
4yQB9gXnkkBY9DgN3cZqEuidBMwxpwNZGkB2IDS7ZZwkMImOOScPLrvotFNe/wZ3nX39hpO7l134ztMuXHbw1WMbrv/gG069aNnBk+M0TzbWfkpgEh1zBvEVGED2c1Va
38OWwIQ65gxiaxj21NnzeyaBCXXMGcRXMIEAefjYy9v3HVvzwoFHN+67/5nd33tom66v3rv5r3+8sXBd/8CW7z88s3hF1oD2XOtnDnH7iZft9N2z77NXHe09dHz9zIGl
q2ZufviF65Zt/KPvrtJ15sIV/+DPlxWu3/7mY7/zN0vkmPMv3vjmb9z28PJndnL77ImXezWe4fWjreGDizYcqxqDaZDDm5nSk7fuOcKqY8VyXXbHuvCidf/6ye+u0i2r
nt/T5aKdXMecQXwFYw+QIBl4BrAteXzHdQ9scfh3xV3P3/jQtusf3HL7kzvdteK5/f61estBbrz7qV00+MGj22nM5SMoqAnEgrV7Dp0YoW9uOoYCkmln+cItT/3etY87
/DvtkgcXLFrJdeXdz7pr6doXuTL4zH9ZsnL7X9/y2Cm//CYB5HsvvI72PoJ+6sZVQCxYy/41huKs3BoKFOunF938xbPgYM+8aMmGg9k7nly36OzTz73sxus+8s5zr193
8vCGey9bkPG0rsEYCmLUhuwW7Z/PX7S/ccVDhUV77f2btGLXbtmvRbt4xRa3nv/slqdof97XH3WL9i2XPgh8smg556Uv2ol2zBnEVzCWAAkobtp1BOhyiHjVPZuAQ3Du
wQ17n999lM9mz5GX1u88Grho8PLJV2YOnii3eXr74RXPHfjpM3vuWL3zphXbvrL0eaGmtEzweNQ+y4kZD/sLR2Z2AfQ/bQ3vvnLFxUue+vYDm5asnLl//Z6qCZ3ljy8e
OgGbumXfcTVY/cKe8z74YaHjldd9L/9j1mzbvmNPbdl/x6oZdiI2ILBWT2HrAYnZrYYoSfYyqLCb63+8ipUp5NIZZ53xxpaRUvbIHCDfdeYZp53yxnOvf+ixy943Z8I8
c+HKw0aZdDj5LFpA64qfrGOtajn9/nWPs2iv+elGYK9y0W7YdYzVePTEz4+zle3JVmbdNXPg+P6jJ1Zv3gegXnL7OnfOe/MlD15089roCW/s3NNG7SsYJ4CEO0WZgw4V
XF2z7IVbV+4AEcEzt7y0xsPQyL+qGbuqVmrddfj4z/PeZle+cAi8RMsEiXn05Uuf/8lq+LpDxsR2uKnMvw3ulE/9kzeu0v7CwZm9AEQEz2h48PjPwxNKA5qddvpbH1m3
VS3P/9MvCB35pX3vrJ7ZPjm1diX2L07uHNg54/No9p3L71jHfjdgJhZYdIEoLpF64Rcv+08CQJ7yvstX7kdtPLzuOx89FURcdzIDyDe+4cy/WLbjxKsHl33u1Ld//NYX
MlTMfn/n55bt7slUTk8nqHEcqtxJTpTGXU/t0spJ2YJAx3Az0LFyQ2PRgpfnL16tE96vXvog8MzJsiD8sXNPG8GvYAwAUrh4Q05+Xnbn86AUWOWDoltk2ij3HHm5btkJ
DtkiaXb856+kLOJnSwj65NZDS9fucmQs1C5IOT37Qg/fVLioLYZPHZQCq1ZvO9TBceeRx1cCJxf91WXci8ooaEGJRJVUb5v3tvT+DbvqDuyzjzy/n33nM4ufFE5D7YKU
PXzfyq78KJQ6aNTfSwBZsEHWeLHmuJh5t7pfgM0N15/rO8FmOuU6UyFT5ppFCy5KWdSi5SSXL9psXbGrJKIjzcC/KMtFs+AhfhawvOmhLQuuy2wQHO8wcwopx8s9bWS/
gpEGSHjUWx7fDi5iUPzRqhdRFuvX0+y+2ezgFmRWsxVMg5OvvLLzMARs7UbpQHTr/pCKCUivfuHA7U/skE5515qdZqpM2WJowzcMQeRvMYWZ1SGGOa2fpgz24FQ16UCj
UOSrN/xAv6BQ3v/khvz22c17j6Prx1j3WT300PGfs98B1ZzQtelwPE+3+iRKwDVzJBgaJCRqWg68FOtLO8zDALLplFS1F48KFa9FC8MxnztljR3DZMOtW/aFSCnHrMbQ
MVuNcLCO/yhvfQDnxt2zYrnWPDfzo4ee5ngns+Wpn22dEVlUY5E3amS/glEESPYyTH1yOkVRQz+LkWyz0h0D8Jn/U4tky9ExZJ7Umtu4O7LQ+Rz4JOhKOqXYV+yUplDW
7UjsMpy+z8pP31BSgFBhIvjmuQRUwUlvHW7c+Ro4FC7+t/+3/06/LLl3hXrbcTDrjT7DdHolryCdUuzrh771WM8VSj86LQ0aJdoEgKyhWPNASdGqolhPHl658Kxah9he
YMuY94HKeP19GzknsQY4M6Evzl+0raUodAxsLFp+tAkzqzTzmNXaQ7zWtkRLt9d+/0fXfv82Pf3uJ57/f/3LlnvaeZ+/vky9jtqEjPJXMFoACZuKHoY2BpWKfRHgiSmF
2YLQeorpBz6zGrKKaz9NQUeaYcX0PwlcZPEVAiZBd2hhs1C6T5FdZuFP1uGJ99YvZ6dvgCewlcTQMZv0Np2enXUW/+jeAjl53m9/+IEnNzomILxzaSTZzlXPuuNtIYXy
N69aAS3cEwtlFyRYAkCe8e6zTm1nEjj1U0tmTuROOjnXms3K/pWek077j6O2cw55PCzar/xknVRG7IuBReuAKnzyVrOY7ngUBI2t2GwH8x+KNeGMd/8mf/Td0z5+0eVy
6nnvVSt6frbr1dy4GM3mJQQG8RWMCkAKGoEW9DCcUZ/efgSmInraEjpydgvYHUWyST/I8SyEjtIdt+2P2Ab2zvVWoYmC6xhKeRfcX1GFpxwm2WWgKPlKz756xaL7n/dN
jOXdpEVyHqu1IusW5tFfG84lpwCT7zrrvdjtHl39s/C25ZjVYLNZVgXvcsmPnpFbBKpwNzDZXfL0hK3h7K/de/OnsiiOUxcsfHRHtuPOA8hXX22HeZz2ke+sMxfW+fs9
E40FWtBS5jn8dfJC26e9R8xqho5HT/jOO4X9KvtfmFWNF16XDQ3fNOew7WwNCz5xPi0haX+2df9FtzzNuxAuPGowOfpfwfABEvwgYEPQiPeNW3xN1YjK3c33yiloe3W7
c1R3lLtHeM/lX4H8u9fuknlyOklX8IOADfdlJqr4MTq9pe1J/swvR+Y63xYMG488+XQKOiZ6bGltoEngmiGY7GzHseTpvdI/et4P0IifC5OLISDLLBG0xfCvUWZ1jp+I
+az6SqEY1NLTM3Tk723v+tbpHHK18AmgTfJdIBzZgPxFq/fqudw66HAsvoIhAyQKlghVtEa3GjwHjYClMMUrJ7tdXjn16JitOTCPZrMvnax3cZRLyLFXMkNDkh1+/+zL
uw+/5LTJr/1081QFUKJgYbaBm7ruvueQfwo6ZmGpaX59Lt6RSSnzq2wWp7/lbRCYKQ8Nro3Mbr1hV4uc37Z/Hv3gYJIdp1EApSVP72AzHcAtnOd+sGIz0HjGFQ/d8eR2
z0GmeheSV06s2axjwoLxjrOsfLoKMmGt3Qx0bD+0pVy6kF/B5D/9n153998/LnTMVcxWELBgUpYCvI3653eWMlnj8hUMDSBBCzADBQtbox+zIXQMH9w4Q8W8clprWlOF
V07AQSMhAKDVG+iYqGqAjv4rPL75gMJCiAlBs0xZQOPbBrSQGw62xv2zLQeZFDUujI7MYKVtpsyvXnzxxXx+0bO/JBzlFZhKmpWjfdQ/rowy83zx1qdQPlJmbeyi01Je
atzb4MkCH6DznN4lugWlNJNSGCNFWj6G4fOcc14rjM3xqwUl8o8//RnindpZMuZhPAZ1ObvifNSNmaCbSR+Xr2AIAAmnKnMjmIGCVViI0aVJe99BI7COPb/EuN2xbgd0
/Tuf1fCXo0WDkaDcjDAVaGQ0Zvx3ullbI3svH5vMjWAGZ1XJPzihc86osU2kNemFg06BX838FNav54kpuiPNgsedFrWQz2Yl3zW36ax8bg8W1tMvfRD/nfDsdOGYM7LT
Pt4D41hz/o1Z5OsfL17Dog1Qpv7aiy3sjAgVOjbJBhDYplpeOeUVW+ZXHVJihnSpM/ztSPEhrFU85qB5Bu/mOkZfwaABktBGcaq+uVGT11NmNfPKiTF7rbDIKLMKySY1
om2Hr13HUB9omTCrdSCKrvx3T7zI4YAM6ROmSvKZiVOVUwOaWUz+c5N+KPPKCR1ixFO1tb25lo5fJczjqutv2nkoVWFtM6uhh2pBbo15bG3Pnai37TuOxsw+Sz6gOlWy
O5eE8cah0Rw9IMGiJYwHpQrzyt6jL/MJt2nJMrPaOjM1infc1CI5a61FObMaCMvOCNLndmd2x0o6t8CvCh3f/Gtv5dOo2YWyt6CrvUdeXjNzWIwrHkkDUyXH6ysYHEA6
xZFAiPl5cFpAlcBFVKsR5XWgrzEa76gdcENwa6Zz2R1TKDtahoPtWOh0Bb08SaqkUxz52NbMHEFQyicSUON856mo7qiTeKVgxa/+8Z/+OSdlxedEp8nzZ67bs+YWZO6V
EwJR57Gl4bHPstuy55ZVSeK1XTK5VatWjSZgTM+oWLRSHDnW4FkNOkaVQi2tBK+ctraX5pUT88DPHlrwynGLvJJfveTKb7oEUqXPIUtowJtyFHAfFJGdnGsHo0qOhWOO
/xUMCCBJMfO1ezdXKo7agBLQMYmpd5pozkXUhtnSTPtpzqyGdsA8/De+7UqmEBc1ANn6uzRRns4RAeOrrJJjHQeCqZ+0W1Ic9e6KwQgLzRFQMXRsrY1KrGUXgFO9a8Ua
HqrPPsqstlivWJZB9cbayMdZuzy0NgoPZbeVKumfyn2XBBJOTg8OjeabYiaXxTGrp5HDHoAR+8yzZZCWSa6FtQGbutZ/B/GOBcADC33T46c/85k8e1StturiQzQAt1mx
aKVK4nbevykbx69gEABJkINyi5csjlmEotizaBRRLJNcaxcTsxrMJJdFEelElrNnIXQ8cuLnnidYiCQB+dp2x3KH2V/gXWlTIEmwSnJo4Ogwpjnq8Bfno8Lg/8jzB/RZ
JjCrc/pZnkkupMa1J726WX5Mzk4eUgqj6JgW73i0RZlmPqsaW/UKYW1AGNSRYzqVc3SQryB+Q9rI+KV/G5D1nCIBuapiJldILitWzGrNRLdmX0kNYztVi70E+cIeZ/xr
Kd6x8CFkeyMbFE9kC/Ldtv1PhgOi1tVb3vq2O+69v54czjpngzr2UpZwse1vkT3C742kUUjmw9c+luhuliJtv804fgV9B0j54xA4X7cVIsFENSJwMnIaSfpGGfXK8eMd
A8QpagQbpX8cK4/THdzKzjscGjg6jGOspPxxiAh079tmViNh/gnOO3M+Du21UUsGiAlgjwsvD89jq/ag41ZRo7VR91wODR+57nGSB1288DrtYsRlNskn13T/sfYRCUCr
KgMwaXE0a45Z5WMPG0fErIbbtPiJOLM6R+fWEU7aT+qYVQ0eZVHr6oYbbjh0JBAR1zrnZZ/JkTlmtXLdLt+w55yrH2bRNopcSll5ECfj+BX0ESBhDhflsQ1lfxw3N0g2
0csr0Qc6MQyjzZ7Vrqr5lF0dcdpyLJJXTuDjEbMaON8p884Dz4xHySE2mt/9VlaCw08yksKsat69I1FIfZ9/1qluSRZyfZxhdGRqspUWY1Y1tjDW6iSejy201/BEVgXN
/vPVS7QvjEva6JTNbhzboMqTTdenVZlKMaucscJMUhqz2sr9hnYYxlE/ki1gkYna1OFXz/vg7ykXeTRaqeVvUVvKZi6Sja97waIn+Lp7mE8Ao/uYfgX9Akg4Q6oZwx8S
Ali1ecGsZltbrF5oFj+bZ5ILpBfPiAJ2K/klpizNxExyKZQdlMXurLpW7Ub/7K7ZMrNaFggJq1ZtPgBGonCP+O7DRkOBKjaadjWD7N0TmNUGjspi3dvyr5RtNukcOBJq
dLQOMdToCIAo/8SqEDqGk0UAe+Kpwr2xIOEVVq/b5LKof/bqWwfmKDjiS2jww2PRYnTEFuCX4GgzqyHdK61GR7YaVf04yqyycurpXPH5GbMq3TE3PNXuLUsfWk1XbHxh
dOQ8xxbU9tWv7U1ZUFwKAuWKgiXqfrLG2j2tLwAJOsIZVhkd59aip0bULtBCvGMd+CX4Jc55gkUzyTXyysErNbxROq+ccDOtQlRtjhSo3SPrtuM2Gj9xs3THBMyI1ujI
pqlRCggemnIkku4YaCnCIHFtBJE7e4oW5FNb9zoX/PP/6hscKVC7DSO733Cb9oAmhIsm6OjyADNHCV452VRG+QlHiiQyYfPZjmq48h4aoVhcJrk6HPW8ckJd8RagI1uf
/5nAD3WPkePomOMvsN4DpEPHyprGTEAins3fdmtnN6G37F5OZKiYYeWAeEdFdCgFcADSFO+Yo2NtMx3c0DbC0Kit2aUnRuEeWYx06OgnHG+kO0Yzycmvr51Tvlp3ZNvS
sSPKhcpjK8o+qbecVyi6Lfhzpwz17SDXWpsojAJrg9l3KX5UxhndxTCyKbZ1315+ZL6lHPMKuMIZtP7DzCa3/WFGiIc0JixTDdtMWN0aa5EivDKbVXhsolg8dKzUMbK3
YP9pfyahncrTHed1JYwktLfjg904Oub0ESBBx8uWPk+KnDA6xrxyeqNGsCXhxo1rFkUkbrjvuY9/+4mPffuJj397Ff/1Lyz2XDR7/Lm9uG+F8Yx/dV45gZYBr5zCXe2w
qrnlO5oYCTq+6ZIHne+f3iIa76hmOsQ0ss0EZItthsFoZpm4L/94XWFC9b+fWfwk+WDJHEYzGtfVKtLYorpjWob6WdEPgKjzv0eJdEFphpHdA16jHsro6HvlhL/0hHjH
Zgb1NVsOsA6121Qu2k98Z5UW7ZV3bwSZAosWIfTKoC5LufTaSoqlm0U7po45/QJIsuQEHFbTQ9/azGpjv0Tmkt3wC7c+/YFvZJkGdZEDjGXHBUay+AoXf9S/knXJ3cL2
+vlbnmaNlndVyS6QK0dfXdQrR8uxzvg/ahhJlhzQsX0Mb2F5R145IXsPgq1jQd3M4mfRo5ltmcaFjuF4R99jq26EObOaaaJgpJ/fp5DrixdBkr937eMdH8kbIcQ0Ny6j
Ix9dmFl1k5vmlZP5agWYVZ3hPn3TmgXXPe4WLT6i2nDKe1EGjXeur9yOAFS3HUV1R97CHdCj3oheFpRaUuSB9XvZHpsuWlfoEfc08gOM6VLsGcUq3bEmnCMTvY7qwdC3
bPeMxTu2XJZdvOPqbYdZOp++aTVGeFYhE6nFx57eQbp6buFGbqcTrWmKqIG4hLXBK8KsZjU6Mq+c2o1ezGosx39G4IQTVo0ORkp39EkqXj+BWW0w6cLaQrAXAmdmEX6f
ZpbSx+xHS9e8GC5RSbwjY6uLd8xXQutNM4+twy/hfO8cc3Cj8JeKkpkhT0xiZo/s645ZqTumeOWwCJtlktszD1c4UrNoP3PTGi1a4PDiJU+xnxA10UFwIXfxIjrEazui
Q2L573hyR3gLErMaNs+zVkHHIycoYRQwFbXi1J/edlAGgsRZ8x1zlB55TH96A5DO7lg5bc5tIcpepjtocAD/0RMzLEStG1Yhyb06QMTwtGVU3qoZtzoJogIpK5cdf+RS
JjnxFeErpdkTWw5dcdfzNwzVZ8fZHfU6evcUZtVNepBOzzaXwqQLFwc8sxywmNnylKXQ6dyl2eRspOQ+8mgni3ShQ6kvSKYb2mpMN5pBDruMjglsRwvnEj7MrGVBd2TR
oiy+/5qMuOKMznbEGDpAxLCUwEuwVvooAKyDe2GNObajvU1V64ViVnOvnIjzDs0Un6ZFS7HM6FTimHPOOefqKyAvebT9KDfoAUBGvXK0nqIR32rmOUNWzByzDpXPwf9t
OSOqhTgAtopH8CAhJUsTxqPSppXCrDqACZ/vWtLI9fLFK7YNZQ0VvHI04IS9pnU48PaaiDOeeCq+QJhtHb1HYWbbe00tYSCBeHvNUeonaF+QY077asXRIhAMqLpL2w3u
D0OZ2Ql+qBT0AuHhxTvWnVyzJZrGrM6Ld4RHBaiEi+xLg6mMAfRycBdSQnFh1HQsiGY2ml9aO1VYd0QghQMieJzi1/qZz35WXwE1rcZ9pXULkDiDEe9IREelVw4TIIer
XjCrs6xF6nyKZ2B9DAAXy7PL0uQQh12TYfBhuFyO6I7yWa0sdOX2So9ZjXgD4deKMxvt4VqHEh+JeDH4+c7xHrOalCsnlkmuxd5wJFq6dud/uCGLTR6dmV2+PkvaEI1d
EU8lm3SlY45O6NqgKTbin/fByJTtZty3mEGOv0B45JyHX6Oj2i9aMbVRZlUnGxfvCM8hXweAajDH9MrtCAJW/hNsR1v3HiVXTji/9Pycl7V2R+3brO1CElD5td7xRJad
oPKHtD7jmDGn7nW6BUiUm/psAAUvr0i8Y4CTBIdwnGFi0OEGc0aLftV8EuzmDOkPbnji7qda0f1RZjXFNQ6fEZ7uu3oTHwlGDriKJMqNlw2gsc9q1FFZKvIozyyYfddT
u+rntJUwTOhY55jjQu7ydC3FT0DbTbSKZHQ1WgMkUDjS5VYPl9StNhmWJiXlw3TMKrP2roXZERmeo+cp2TqYSvFb2o6AScitOnbK+awG6CvnTVmX+QuFlQdV5tmZDMcc
fwq6AkjlWa3LlZPmlTMrr5y6ZOWcskEgQeMorMXC8mVIIjou/dEzdYEE+gJxceQjDDvvsDS37s/cVUDHXBOdO9/d/mQmavyEO/h+OrhFeVb9tCNkoknQqLIynLxmON6R
Cnlwqhz2/+O3Mz5gxGdWO04J28iccjLz2MrR0XfM8csptNWXUCystpsROfZ1sFRG5xZcBPwjHbYA0sfEknBlzoPRDzOvqZAlWlq7Zf9v5VojbGrPTYzdS9LBJDagsutZ
i+0I+hhqp2IkpOwPHPdhsDGFFHw+fMccJcCbgJ/OAVI1OuryrAodczUibgTWTBQONUww0yzabQSh0Z971qUKyl9998bKVdXIblepatAtdTTJTzSAMsvycfDzrDayzUSz
22zbdwxeaKxn1rfN4Jjj3FbnV6ltqS/hGgvM7Od+uJb00CO44Y7RBqcaHc7kId1RNExAW0r/MNHSPp8nOh/N85w/UxASkK4AGH5DbjtqlEBYKXXqLuT51PYjKAZnXbnC
2blwzHHlTtEjx2jlhIfaIUDKMacqqGPOGSxGsrWcwSrrhbLQ/+3CFUzzuLBPLBRsk3w/mCV8xSuZwGlJw/ukiwcLrLyUWSYRXV8XX9nHoVEmOcYW5pmZWU484zuz7A7i
qVwsrMsnJ8cc5/iQ4BjSIq5ZPJRZTveh7+sCGMfOOUBnWl1Wo6P11Uj4dUcTB5kJzGrWoSCHa1wUfVaUzqCYCcR/tHNeBtSVjIVGaPXo2KKpZQPasuco+jpFT7VgqFQz
MY45/ifQCUDimHN9vWNOGrNaG+/oFEf4/bE7UzNgebo6VVLG/2hYpAq/tZnVWke7n+3IUjHc37eiH2XHnIR4x1aunDazWvsFMrNX371BlpvxndkbHnjeeeWw7wCK2heA
yfbJgH0kcwzhMwnnLPQdQ+Sw09dyteOIfCljZtGiLVHvt01Etbxywge1xA9zw4tHWK5MDXgzFK/AFAnUteHcoNpVd66aiW1BLY858ikG5Ta7LbcBscmjksqpldMD3qrO
MaebAY/gvZ0AJBt0pWNOWuhbdsRW6FuZ+mCbQAPjpNbDSiuDF7pUSYKiHt10MOGISvmk7ERWx6y69Sqh/f2GvWDk9tzHrOc/bNCcCkmcoYc2incM2x3p8/evfZzgnAmY
WZx7dSr3HXNcPjn+3k7XEjEuFNaGytWOuDWh50uu+w7lTSaTGw6c6rB+l29NSsKHmbnNs2K5xndSnCpJpO+amSOVYlEMd0Dh9njarJm/b19y+7p/8R+/6kpZTV6508YA
ydbMBr10bbV3H+KLMquFGh1O+hi9MONBbY+delH+yCEqRSTyaYVPsr6xJG9ZHf0J/LS//FlS3cJv97zih3gqZ7fY6SVpDL9CdNIXr9j6li9P1Myistx4T6vEHbuDc8xh
79BxJxrkWmnWJdUtn8DYaSrdg1zHPaC++KbHBNhLrdGx6IHsvAIhNAHTATPMXoTRqmz90aeN/OFgU3aqgkXMFW3mK5gYxxx/NTYDSDblr927mQ26LMr5zGokvKZsd5Q/
Dr5hHX8qo3Yj35XIGeChZuVlUlK8Yzt6slbngCFx2c4wRqLB37ZyRw9fmdG++8oVbNAaajqzyhjC7M1EzuwXfrDyta/7FR2cnWMO0dn6CgrxjuXZ35UfPsqe26hBKENf
urVl1+nh/E5kV5ykyQmAEpObfn1au9bBJCXekVkgYQVfLlTQxMgNWaF7cPyan3wnqz2JyaAc71hYtKjmuAQXbEC+e9qXrvnhxMiqc4AUufrk1ozN8C/PZzXk+1SXSU7L
cazJt7rFIVM5L1iJkdwVLG3TcsCjWcFb/cFeE60iV+GEE5lVmqU4Kk/kzPol7s766IX57pyRVD0pTy+7zvhyeoPcJSFXcW4Cz7x4x0iKx6iKSW8YR6BVx8UfJ13gHILR
QNoO6nPelFGfVReZXeBFnHvaef/p83Tb80yf6a/Wv5YNNMgacrXlfhljVlspNwu6o5bjGLmHdTATipooYWQ8BkDLUSUSy/iKHv+1n27uCdHqk6sJju9JjsoTPLPOJeG3
PvIJN7NRQ3JrNn+eFcQKJ+hBj3+P50DfwZKbhlv0WSmTQ0r1Y3fyCxCJWOmEjhO512tV6Mj+5R+vb8Sslrcg555GekW6IuXWBd97cvIWXgOAxHO1TK4qfjaWSa6VDaCw
L7g9dIKXo1ZMASM58IqvCEfIYXcEHesITPR4tPmHn+1BHRm8TnJydbYRsxqYdHcMn7yZJfmymFXSMaNKamYvvf2ZnDKNpA9MS7Zw9NkXD+N5+LcrNk/edtOrN3Keq6zY
vEZHuCx5FuYfzSTHov3gNx7DdWDyFm1B7Fq0aJPYHakSHzgxaKcql7IhEb++AlLzQ7QyCz/bun8iWcBUgFRagHLSHEQf1R11VCnnAZDuOPHLsYCRchirVAoLKzXaTOl1
ukwdoK8F632Kz6pjVgPjn+BzD4V7nMOec0mQAP/qtp/VbzSZzi0VM+wHwb/KDEGJb/qcAG+1XiFioR/SAmARWDNzWH+vP2im+qwKHbHSTYBLTorMa2iteWBZznmp1UsR
N30Fbzr9rTjpOM5J6XUmTIBJAAmPV04LkBbv2ErRVPZHmCp09DGSg1ss3jFbhW2vnND5bseB49cs2/x3XXjr6CTOyk5UbpSXK1gc8eikklQUfa3LFRLeblIcQ7T1MOks
FcwQ7NdY11wUdsqWNz1tODdwerjq7o25cvNyONiU7bsdiByK0JXuOGGbe3hJaNFWJv/iEL+tJjKbAuB+3iifcyL2iVMLZ5dJWopJAAmPB5uneh3yR0jwysmWY128Iwa5
6dEd/eWiRYljZ30Gvtm6MJhKxyhp9h2HReokvn82c6oMMi2ZNVQvEoh3ZGEwsxNpwvEdc6hXUN4CvJktnmmijiFaDPTpl6dXHnPz1imLmpKEZ1zxUH6SCES1ZyJNMahP
g92xDrEUJOMnldQmUMd2wKY6xxxq17Q5p7n4EJIZ4Vc8ScxHHCClPsLm+RsoEo8yq3UbPWeWiWSrE89N7UynFbEfAMzMwSxRRQ5X8Ry2mgJqjX3/4ZnEp/vNOC+zmq+7
77nYXtPKlROd9AmeWeeYQ627OlGXc9imOIbos6o8fOD4cP6NE+j40MFadbdgkWH3uOPJ7eEjnaSacDQ5OqlHukQhy6/V5bBl2xE6VmYA9R1zvMPH3E6lOCVKHSQ+ffSb
xQHSVx+dCerQsUhUaTuBZ7GZ1fdhTWhRloJ2s3XWJjBDzKqSBrgpWPHc/s6USNRH+NUjx1+KVj0UYRDOlTPBM+scc0g4Gc4VUpjZqGOI9nGmslK8bFumRBb2UE4MZ1+1
glN7+7xefY58IU81FcuvdvSbP81cOicvoqMR8BCuzT6g5FCOWS3zSb5jzgu7Dp58RaaW6gpuE6NERgCyoD4mMKstebnzne+bAyQQqTpJ2QAaLUS/MRk6WJReSRqXur1V
cb6O8PRS6swtTbyLKczZaDCoj7926YOEQieiY7gZM4vj5UTO7KpVrYw5GCBTcoW4mU1RX5zuWDfdeBcT7ddoZie4sdRHNPVogZQU4ev8MUnZADqberYCvJNwHaBGBz2Q
87KcB8o55mCAfG5zVi8hsCFgPp8YJTICkAX10SPZQgRgpfgAA/KsTo+fWHixsiixwpJr3+2Mah8wBPpcXKFZB0okUQQMgGGkPDFctmyCZ9YvcQdSpmxAmtkLFmfUaIps
6+gs3WtKpC/zy+9YlxW/q6/EpH9Kqc7GosVYjvKUMqcT34aTB4uWEMnKvCV+udN7lj8a3amUVXgylMgQQPrqY6LPqqofVx4u8EyZTsecuq/LheejFKYwq5qCOnKbSlg/
Wb0z8UtmE0fhI5YgvNckTvpXfrJ+4h1zbr755kTZZriYZ7X97vLNYfFCADLxOXEdKkJECsCvTJBRJ12MhZZyXi17lPhcK8xqGq09+4Vb1rJop8ptNSx5WdDnJ6LLThu+
Y8513/1+HbPqL3UKvrLVT0Ygbwgg5SGJ82ois1rns+oOwuNS3LHjb7jpjRzZ4Dn58uv4Csd1RKeAytXpMZH6GGR1KF96aPSJunHlpn2ZkX9VJ15CTcU14PYXX3yx4r34
pemjmVmsCXUSFrPq+6zWQSnNNFmTcR5vKka//fX3bYS7C585osqNziLy3jQP4cJ0yBjp2X2yD/z8P/2CvoI//fyX6pQff1K0b3x3+abJiIkMASR5yVUSOWHZtTzxKn2f
kDiJ5LHNdPN5TOq9cM5ZjfJg3fOMNapJOOctzVlCcR5IKxX53qtWEPvY9V5zlJmF8prImUVldCXuOiviw8z6FLqkrcOHDMmVH0t5r+HciWfglJeKRNXL3Beyksi1/msp
zCq30xW6IyeYSd1SOn4vWQf8pJhXXvc9V+700JEMCIKbRsuRgmZkdZ6MUIVagFTm1bXbDvG27aRitUQQeQDmf/DzWuL9j9ztCFy5cEXH1RNHRzftmQ0knHPrlSl4dOO+
r9z1fPTz0BPrCt843bHN5YYmHQeHiZzZpo45jWZWR+w2Z1ArXuDT1aAGGDiPR2d2ghsEOY/ZRqkYvnjrU9OWEyB9YUjOivpYcu8KoePpb3nr5he2RF2ChQL5vpGtao7g
5LBMf/RotqwFSAxaBNgx6Fi8Yyuwve5kActkrmLhucf5s8xsOHm21fd4WOT2A8c500CMhx9HnDUBdnXzlcCszkoNkk1o8pwAO3DMqRN4eWbVsj5gpjXLmgU3R/qIJrLc
TeK2yFZbxXmkZpJzqRjWbskkOeVxHWGZQwjhTek75sg9LUw4iWj0wUL+ZeOeSbQaIHHPYatd88KBYBbybHXKK6c+TfPsp29aw3kt8TOYzmZiNso5n8JeOe31SjK/7OCm
ZH7Ee9zyeBZDXffDs1i1riqyz9BKd2xrLXVE1iwarQb2Jz+YwJn1M+YQ/tjlgvRmVrU/nVdOpXgdOpJ9O0sB4V/nL1590c1ruxzPmN6uo1jZfyRfsZmeHVRukGrrG4GJ
+a1vPDqRFoEeziyQ9g8/d+f/cfYHpD7+8Oabc1tAyI+szpsPm/G4mwaqAVLuOV40bq0rR/tkUS0+itFM+ck3ceGih/leM1lKndxMlYs3pDsq9bk7uMlVJ1ADSxRKwQ6v
jViPC8c7uiyD8s2ZPJ2GRDnaF0idkzh34WZuZuuKoRaAUL2VVUzlYZhOr0vshZXuOZXJXCoVHUnVsvclLun3fvh89xUkxkm3gWAeUkyAaaAaIMl/jSKSL7XEeMfqZjgp
jMJ5jTMRpApbFZQX43EXHx5/5J+Gbh9l4zv76hW+eTzBK6eFar4zJC7HYZYVLQRdpLyJ6AwYxWNHpPzBJM4sSVa7dMwpb0CaWaVQSPDKyfiYyqhTzjST6i0c3bXPXLji
kttJX9xBktt53wiughOZyyIqwEYN3Fdwxjnvh1BJYVbpv5xbgBtlGhhrQrsCIMWvoovUi6ZFWYSTBS9dmykrQ/SlZmL4HvBYYxhcwkUQ0V38L66G+ld4YBoPcS6dGwJS
TfPKyVRMWsJ5+jN140Pb6lhW8atlh6AEZnUuHSt0+kTO7PLly10pKwp3NNpTwo01s1R5DO81zAJUYSAskpPNp6Yvq46y53g+Zdlql1dOzG1kjlnlG5H6OPSjcA/XVT+6
cl/BKb/8pjd94cfRFcsYAmY4UBN3h7HOqlMBkC78sU46BbKo8uzAveDNUKyPfANAoHCRyB5inqKGYhrQTGDJmLl98FyW7FU3PNByQ005uFW2CbCslfxqSp5VmScdi/KF
W5+esJn1HXMo+tjbrUczm5dwqbXsttX3UA7e6WRZ+RgL/CobTkomuYLbCI4npj6GF7b/FTz6xNqwd32CN1+2mK97YDM5SXr7QQ2ytwqAXPL4DrSQmo/ZFWMKpShjBXNe
HryNip1IJh/QkV86OC1yC7wrt6uHQc4EzxKuY1kJouNc1tbKZgGWlfqCPr+qk02b0wtsza1JV/uheFT2dWbhkc4551ypj9075lSuGWa2ylG52me1alozz+FNu48N/psa
8CdQftxvf7Plv+oO4imHCWxD4lckTMvYF53H8lfAeQJSurwaS/tGBQ2rNqhSIgCiKkp0eMNqUAGQFLdaunZX5ebbjnd8Kaf1dJU3VsKSjl/7043s9YN8K9hRB2xd6n9u
O84SP84cGNhbeBRoJOS0zKz6E4Ev651VaecobuX7r+oMmPNUIUuDJt3Fwipl4MBkwoP6PbM9d8wpC6eO3EbyKfz2xt2zJMmk24/d8ARROoMU/nCfVfBfbRTvyDfivOvh
POCHhvsuI/708lcgbPMqYbW2+va+4QqqVJ+tEb7OKP/miocGr2z0StpFgNxz6AQGyCe3HqoESJ5aR6i228+SDJ5mqhTRq1FG+0HtE6HaJTT6D+LjxEg54FA/Tm1wQZXC
T1f4Hli3t5wxQMvdJT9LZEikYvqTjiY0yCwk/Z7ZfjjmVC7XyplVS4qAhhl1oSNtON9MVcYAGQXcAS6dWfU91+Tf1JnHtZz72Ac4K8tZwV0gbqIFJ7p9ddOAbYpXk/th
YYQoDPyRL4gG4Y2x7ivgHTlbuL3dmVqC1Qtap22tWLYOAlj/6LurunnHId5bBEiysZD2uvC5btp7TPtpfbyjDhGzqCM0W/b04LJHqlYLS6GzDyAqeqVtZP31EHoDD+WD
9GHMnwhNQYyAPbrz0Es65fBf/0G+LSdFa3Efgz/pxKINzNNhADP7ix+50jnmdJZPLrp+XIPyzB49cTLqQ4/OBDq2vVFm8VUZa8IqXVxqibpMwS+WIss+5pWT7ctiOwr8
CqcKFa5Jfzq8ke/fJyz0/ftAHbDHOQDKcaEDm076kAoteR12POdjKCdExuwPsoCavELlJhlwTyt4LSTvGwqOz1hWLm0ajeTfsVh6fmMRICkrqPyr/qkhIeSgZRhjEXPj
wAgNt4eGOW4dsr5577OsJ65/fdlykpHqdxY6O1d48vha+BIGVqiLqICyU3shtUqdiin1nX8lLyt5HvzlQlnBPBdJZpvhJ1D9WPpi5aRP0szikiB05Hr2+c09/7TKHWYz
++P1jglIQEcXCzvHYpGXdSJTw1fKnwAPYum8GKRaS3mAX2nknsPH7lQxACaqe7G3OP++gZ2knRMiwMwOFrXw+f783OLDpO+YUy536psGot58dfuGNPhB2qp6+C0XAbLS
AMnz2qHodcaqFrOqbx4WaADfcAo6shTO+9ojBeah8n8/e9PqgA7KEhRG9lD0dV2x4su2cW8KQo6ONNt7NPOfwgxZqH4lA2TTeEcRAw6PJ2Zm0RcpgCx0PPUTXx3wzBIQ
mZ1RkplVfwpws5oSM6R2Z2xg6cyqToe+RSA9FI/HgYjOxa+pxuOQlY2if7sfTxHZy4rtgDPjFt3OIYA9zf8K0CMrdyT0zs/ctEamlly8rUyTdWd07VQFSxx+yIO0uPVw
l54HkKLmHt98oL0tujRmgZJ12e4JrceYhI4DY+FEcdSdnlgKaIop0Oi3+Y2v/H3dSUcYOQBPcSUTd8bC+T4ytXECmgKhI9ftT+786r1zWpEMkGu2HEgvPJlzufPOQ+M+
s36Q64IFC1yukIHNrGYBB+9YPr+j8sqpjPNDo0Kv6uEWMLJdiZSOMavZaq9kVvUhiF+NviNTI+To0pjCxyvas7f+EBq/c9HvABp9Cbh+3vv/+2A0b5RYVo4LdZVoHVJq
FiptQONrhpwHkIqA9I8GOpEVDmXzzw4tys79ES/HAZzHFYxRiY6QHh+7YWVTaPTbf+4HayrPj/pi+3c8dIuYT9q5m6bojmJWN+4+poMb/13x3H4/55xWeaa1HDgedrPy
udxCy4mZWdLIuYw5kvnAZlbqRfCDyj63tldOxWldEQtN9ZsoQoxgA/Zx7SSVykphm6qrqYD2A1aF305fB1MTzhOCzME/XeEO5VnWQ6OM027RCsJTz5aoEYYNojT7X3+7
lVWRw2LgdaTHL19XHdfgZkE5LwuEk/tXdjMYrBFcY9EhzQNIPHSg5vSSygYQSI6FRPLMnBlZxK7qNlPowX57OUrHqgQqJv7Uv3qgG3Tk3v/2i8v+98v/vhJ9dfiKkv5R
uYcbZNb1Nq0RLauLH0d5phQNSc0yd/bk0woWZpnzPatD0MmY2dP/6OuVjjkDntnApu8MyZVtxtqi0+i7uOB7mddJQFDO7hj4RrLN/ZmdgecKHQGzutM2C+MPv/NEeUs5
7a8f+MLNa+uMlA50uz/KyJYk7bbyRWRihP0qD/ID1zxaaaR0jjmvfd2vXHbb6vC88PS6NBd+cGrApq5T3SCdmBqttEDjeQD5vYe23bpyBytSWYDby67W7qit2depB/D1
slwgQypPhSzKf3bx/V2io7sdoK38ZlTiuFcTUNkPL0KcjDcFoSh+3Pscs+rvJr6fzh9/78mvZHtNKN5RXjnt2Sy2HO7MsgX8817M7C9c8APnmFN2SRjMzFL4t27Td/GO
uedw7WRNiZ/Oe67MPHQCAClOjx/c7CubRfdlMQeVqh6n8PNvXJWymbBRVObectDbJUbKMlqJjplrehUulod91sIV7qDgu6d96bvZhhk2EAKxdbFnrFIPLELbC0+Jat59
3VQ763weQGK1UooA+goQcfonnXN93dEZIDsbSuJd8uAqH0YAs57sof7aqsRI6a9dmgHCLytj1TPbD4bJJU3B3qwYTQWCQgbc/8xuPeisK1dUlbiauysaFikDZOIcddas
3zNLER/OywLI13/s6vLpZ2AzW1et2sU7hued89n1923sTMhjdFfGEuWVe+su3iVcrRZ8xXO47pVley4XTwbP8HgXk5QCkGqDQlneE4SR3ZynRWyU0ZG1+q4rHkofnloC
+TM79zv3NDnmyGs3QC/rGFFZAkhgEasZnIGFImHGaPlpqPMAElIO25Vgr20mKR4KhI7kytH9hbXLiuyrAZK1W5kEjr93z6xWrjacYMsHwAGkmeU1w5DmpmDDruqDG2QA
lEBrmhP2Gk1l5cGIP15198axm1nCHN2cgo6vect7hI6ved9/4e/DmlnfwOx/Po5ZDRuJmVBO9J8a28jrxC2y4KpWxkj6iVofwgZI8ZaFcxL/Cy3ZFHhc+8t+/EzhBYVw
nTkuSAhlfBXuJl7+V8At/+TXf7PgmCNOrlLr0Ls4d+LKWfDAovooI6KRtxjH2pBzAIm9CoA8fOzlhKI8L0HrVTLOH/v2E33185SSUUYsjAS/1OS4l7i2dIrkOFlY9MqA
1VclkvVUn96aZH7H8il4uQ4dWco4sn7tp5kjayGHzvxV7jsqhwJIyIUxXjMrfdFN9Gve88kWOr7j/frjyMzsrMesiiqsparwa8Wr87r7npt4R1ZhQ5XumAlHpacLdWwK
jfFHI9y5TmupxC2+lDdf8kAjxbG8k5QxUplMOrDACbcK250Y18Sr7iv4rY98wt/TJO2AN1NWsm0+3a1McrFYXrdTvURs9zjm0ykCZJjbcWHmdXLpd5ycAmMLcCUGoK9X
mY7LwoP6aYnkA+a0UTkdjtxu/2v1fvpM7qeTafk1ew2aSloV38xRua/RXfTf85lVlhwdn3/xd77cMj2e+g62DH+plO0ig5/ZRGYVKSkRh0xriarYmDbzEz8VvoIU3ZEY
04wfq7F7iYgqMCIAWPfoqKVVwEidUJueL5XDq6B6NtIds5Vf/xUUVr48b+vMhOx1Xs65LAt5mT6s1C8diIKv5J0fu9U4B5AkXkHhqAfIYrxjZcuAiLsXjdZZ+SCWaKbu
BkHRUCtRuYNTYaIc+BI4bZSEPLv9QHZw87xyqtGRE4woARRNvjHcOsrzJbtjoJybVBlFWI7dzL7mjDzS8dR3/MJ/vLaFjq/7FZx0CstguDM7P5NcrQbvvFGU9m8aIj2y
GI88yZx/uXjHPI1ZyCUEFfORjXsrtwsWs9THAhh8+NrHutkiCvcWgE1qX6PtQvZRf7vQBtjoCnwFGE193VSHhrpDv39eV+RCcN/IZs0PjmeyBuDEkLi1Nmo2B5CK8aix
f2TxWGHvc/fdNloEjcbKGadsBhuA+qgVWVYi+6pUVap9Lt4xSMS1IlO37s8AEpis3GsC8Y5uS3KTHvUGbDSP5cY9n9mMWWqnkXvtf/d/1+8FY4zbaIY1s7LN5Cfx0F7P
dGQ6088z3VFG4gF4FHc5od3fftHNa/3SbHp3uo2l9Go1Y3kHduQyEggye3j9v//6AX8nlFEmXYmUplgw4uCJ2miE0a+AMBV/pgKRTu68LnQMGwL417JBfUxpjyJAlvWM
gs9qgIPttwiUOrXw7ZEirtGi6bhx2RLJco/GIHe8U+iL8r34wj6rbpMV8uX76WwAIGmT7qg8lJklXUPHk+WykDuYfM3/9qG63oY1s02ZVf/T66tC3/Gi7eGNmc17zujV
SvUc9coRiOrMUecwWMYelCfUqY4XW92NBaKVvSK9AqDShPnybEquOn517qSIe1rpK/DVaO05lVHs7rzeRsdQ4FnJBpQ1HtM8+3MAicfj/DTlrQIdMokjl5g99uii+5/v
X6F5eVIVWBH9cTAXiesK3z9LNn3Fd7B3+AA5n6+o8+PIiguefOUVF5kqgGSvydOUZxPqFWapDh2TjsJ/98+2UkDwe9hdvoNX82/px8y2mCWnROqX1/0Krjq/+P4vFojW
oczsqk37KjPJlRlF7I7omoUz+1QBpKssGPTKmcUrx8+kyKKtJAzLQNVz9dHtSL4SKYQLJ+vRd6EvogBUHQR1RL8C3JEKSiTCqdzDnXnL1eio05T8faPQZhwX7TyAxO+x
/Nrzab1QTBLrrH9+KzrCFBy69MeBXQX2WE/vH6VM59BEjlx6NsetwFU+uF2z7AWYc/8wHo13VP+FSa/ba7qExtZhv9czO49ZKmFkJdFa9vXv98yyUYZn0ylDlYr+eV9/
dByjytIXzIe+9ZjTINtKYWjxt4jol+eq+H76ptWVBA+H2sLfO8CexD3Ht0RWwl6lQASlvjLQgSEp/SvwdzB5BlUmSOHvKzftS9mC6tpMFED68Y5R3VHb7k0Pbe4fQDJz
ZXWtf0e/yg+gHNfR1ynPCrxlLFNmU6zMleMWYp7zL5uCAgGCUdkBZKkeUKQwi//EvgJkz2d2zmd1PjoS/lhwYXWzPKSZDe34YVTAgWWyAdKdDjN7gQd7NZvvXEZod57A
CbwsImlCPm514PmSiI40+9A3H/UhkC86JZhYDqX+jfpLo6tsZXBBwIWvwF/8Zfm4YfiEVuUstHNeZjH0lVdfd8v0s1ejlnUaZOaVQyh6Xbyj//6O1uvrNlqpnl5y288a
LZouG5e/t/4VamYW+Zy+fm/mhkqunA3VfhyAXIZzmoLyOcYHSCFosOR1raPyeM2sSwgwZ4B8x/vL/qv+Yhj8zF5597yqAIUNRfGObWa1YruZBoC875ldQsecWY34rHrR
262WlQApVcxXzqQz9e8q41x0gy7jaAe5C17zjvf71scsP0bNV1BwHSqzuxpwDpAVFKOWbjsyW+hYPVkTApBO1UAoibqjjF6f/f6adDet6CopNKgESL+gdv+WuOu5vI2y
lPt3kFfnYd0xR8fMWFhZZcYBJOZhp1zWOSo7ZrV8+iMjybjM7C/8yd/N2xde9yt1zqthgOz3zAayjDJTines22iYwWkASGAsmsOsXVOhQmupBEhxTl0qZ422Gh+M9fRo
atZyrulGT6Rxo6+A2ke+QOoyEgc0yEqvnPI2MhkA2UpUESwc2DogAJ+zL51sJ3OZrVyRTYGwrv0oACR+lYXh9XsbXXT/pjDpX/DKKTQWQP7xjau+tzwQ4ZptxF6kXUWE
2RjNrM+vBjjVwo4z+JmtBEjNQlt3rNWZOK1T6aJ/J7NefbPd9MMEPfbc3uDinyUULz/EV+ciTgRIZSLt3+UDZMsXNFYti8EUJrfp8OZ9Be/5ZJ1lwXVb4IErLWVVAJlp
9okunOxUkwCQKfGOzm2koLiM0TbadMGpfTkeoN8AGaxm0LK7BLT86x/cmgHk95785rLnVJ6sasfJ6HSFHFBRsnJLGqOZFb/Kf3/hj76TPssjMrPapwK6o/v0LugnddEN
sPXq3oC+4pZomBT5+LdXlc8QZQ1y9AGyA1fEpl9BpwBZEe9YuYE4knbsCnoUbZCVNTrK7+wF282ltyYXUf+cdEZBgyx/b9AR/TvIt510qi3elV45lRrk/JCyit6iKSA+
f8t4zGzGLMGp/s6X06FRLUdhZj1mNe68s2BRhQdKr8BpFPoJW7zksxo2AE2MBtnUjaiDr6AzgPSZ1UBQtQOLsdcg7306q46UYnf0g+3cpjx4Vw5VpRnYVd5G+zrl9QDZ
infcebjWYUyTcuND2wphHvMRNGNIFGEZDm8al5mFSoqySZWrpXJmU0LWOsOSwszOZ1YjycqxSWPUmAYbZE2tq1nyrELrxbap2U9+d+Q0yLKLUOX66ZJibfoVkCShOUC2
9o3YLLT8B+Uh0dfdsrMvMXrXnAb5/Ydn2EzDFi8d3ArM6mAAUmur8D54oHWZer8RuFamKegfaYCt3qdY/eLdyCGKjkTs/vCRbE5rNMhWdhLHUwWmvq8RrjazTIHLJFc3
C608Skdb9raJB0jKlVSWe2t75VTbHZGePhM2bk4h5aQwZTeZfoeK+TGFZYK3coMuu8k02qaaNi6kI64rR98mvRvsGwWwGHuAXPaz3TXf55xXDu9cF7HeVz2jMlN5U/Kh
6dIptK9MUxA9g3TcoNIM45PbAUhTTBKZdNbPHCoDZFNH5b4C5JTPbAqz6rK2uupmZJ/va7W1jhdtr26sXLTkylH/9Su/tVPR5lvLNpYtPmU3mQ5SuDXaRnyB4AqeknuL
YRfS2YBhjR7aqHHhGFFpcfBKQsZdHzQ75Z1qvAHyztU7cXoM7Llhh0luXLxia1nJ69UHQz90Xt4UyBPWaDV03Jj6uoV3ATb6l1pP71tgmRTRUU9ruHNM1mzvkZeUau6y
O9aVCyOUctfVWjqh029bmcWK9XAqC11N58w6ZjUYnJrNC4wizKrPGYzjXtNo/VTSHjmz6nTHspdv9heit/E4o2XleV3pRn1GXX/p01VI5MZ2keKlMWA11zcl6ABRNi7o
72TJb7RveLFns2OaYT+erLzOZ7UMpf1OaZ1Zbu5cX/jMBmOG/KUv3leuCV45nka7QKBxqcpx6+BWGe/oz4UObugcqIlVycqTCrMUJt1mtlfTSj9uZlOYVRk1yrGw0wCQ
lNhtL+wWrReweLUzf7kCKUdhaCnzW564Mkr1Tz/zD/RlbK5bVDI6lO/tB4pTdcQfhlL2lNNnCiCj3nwBsBjTGm3zAJLUnZUaZCKttyIvwFaZx68n+0tlTrK+HgDdivwX
f3l/gV8V59A/P45CuavEKWCbEDoyj49vPgBA7jl0ggMpqTvdXpMY1es/sd+Z+KdwZuczq7Uhj/pwHLOqSez3dPTka+2yk+uWbXS0RwKz2jI96qGSUt2pTqUZ/c+5Tyxr
oeBiIM1pWVaMsKAM9AnFC0/h9FCZDI895N1XZqeNFK8c/+TnPCf6fcjucr3V3T4HkJt2HclMVqU0esoGEFZcNuxqFX/oK2YIC8uY1O+Ec/gBLV6+qSDByj29h5PEisRP
wc8kF50CQRoVlTWJK57bz4Tyl5bvXJb/iajek4mrvOCobDPbq8llZt971YpwJjlmSrm75LNa+CrHdK9pJECklAOkX6OjNnswzWR9gFzNZZW1fOT5/ZXndR09C4RQ01KL
KcpcwTUa4Em3yJRRvINoyJRB+spipWQ0a2iWEGYp6FgZ4MB0oNC/+ZJ5BbwarYdhNZ4DSBWg9z/FPAV2bRqzMq1HmPkHvtHfIgNMUpnE77cSeepfzSu9ranKXExLfG8P
Z5HOCeTKbSqZUpiwNLOZOvnKnP/CT5/ZI4DUuncpIAJVQZRMQG9RwGOb2V5NLjPLGtbnE4ge43HthHNF8/DiFVv6ahLu1Zt200+rokUx3rEaI7E76lmFk0TdqY6Pt4BV
PYcfKoT4Sqr6T4+ZrmyPRTMF89LbFMYjVK4sT8SKvfquDflyrWU7dED37Y7+dGASxq7czZIYyr1zAMlxlf0UtcO9VdQrJ//CM91RCecQH0k7+1dDGAFJGSpPYV99tcs6
q77e/hW64k05b5LPWmsuanqhwbGXTu6eHxZJ8TJqfHJ7iw3etI/fo+XclCa7rK1OyczWLbAefpzM7DU/5SQazr6d6Y5OGSrs+2O61zSSoRDCW/yV4spIkflpsucdJuoy
QJVrJvOgDipmBKCoEP2lAsjRLKy+iMq3cPubL+lZYecPX/uY/ziZxusO/W/98oMcyyoNcPpjFCzOX7z6opvXNloDo9B4DiAZDQCJ2lFlaK39mFUe07FAfa2sK3nVeYJ9
9qbVPY+JxDenUBY8PIYezqg7/CZ45WRTsHF3dkDxVzBZAm55fLuGJJt/3Ybr7qKlp7XMm3Sb2V5NLnPhynxW7jg8KJyhnr3m82O41zQSoBdXEM8rxO5cqYsHMkCxjZQR
C8xIV78CLQvO9jp1pauPEpSOCIUYDGAMQqvLQbJPArQFtFbKvcpDv7ATy3cdQGrA7Z2qGizGNHJ3HkCicKhmcoJLiDyqMzrOZ4pkHemralWX8Jf5pihMDzGSrgDd8lct
Y/sA3pFHROPHfa+cwvJVtWSNn3SswbSu2R40f5UXdyWb2Ub7e11jrd5Hnj9QudeU4x0rm018tWR3qgtoLXU1UH2JBbhoTUSB7mIP6R4jC+hInyAxeNxIfZQEGB6DLCij
wshuNjrQseBKqT2tDsId3V25GivTjpZb6ozek49okJ3MA8if5KGQUpbLrgGFd5buuHV/yyXE/esABMG6qVxwvcVI0LG8pgEtlns5Q0dv50wRlvmJLETEaQqId6w8PsMH
4HilgV1eFQrpT6iY1XB2HpvZ7me57XtVrRVh5mAWXHmcyv0IqqDOtNb98Eaqh3AOYR0mwvxKnZ+OXlMmtzKeQRp1pqIRMlHGAGlmneXbEriWNV3gDRtnZ4PkBFDY1uiN
RwQqOSOo/3BD5g9RvqLMqm7ZsifLM9e/AIf+rdt5AInC8Y1lm8PLzmVyohleOeWtGd6/r94rPFfrptLYyT9RuqizpePfVS7voDlgGXF1cBhsNIV8VJf+6JkaQqNFpcp/
yvfK8du7GA89l335N654KMCQ1PmD6BbNcl/jPjXO8Mz2xF156DNLTv/OmFXuAh3Fd43jXtPoE6CxH+nhSyyv5Z7oufYSB806xYjFpoKyZWFCiv7GV/6+0TZy/o2ryqyS
MLgpueoLSvRsec9h8E2Npuid5ZE4DA6sKMJJK9P+aZwJNqCXKtNJNl0PQ2k/DyDlyHqo5SpdS/1rddY5Q9bF5/b29STxcvC+nsLf/+Vf3d8BC4HR8X+//O/rohuVKarf
e5OsLwEzlfM1DVScdy6sEohLhFF5Bkxc5UgVW31v57HcW8DXfDJmtpI2lBxSaBvxXf2ehVHon/VGRr3CitVZTdXZ6g587u+0+cpP1gV0IxFClR81nyEDSFHUcC6tVBCF
jt1rC5rxynM549dTwheqLdBYxm/+oiNCQMGtM0AWzHBhf+yr79n429+c5xM0CgssZQzzAFKOrA9uqK1T+uyuWdF62/aL/asgAAcWxSzevI7XZn0TvEiAP5gXXUBqoBNW
nXao89oAaHR9D2Rmqvv+2/GOWYL8uusHj26/aUXmwqqfOtBNYUg06bMnTj64vr+JINxop2pmOeUok1wYHXFRZhYIY/2zW54aR3f5lM2o0Ka0NWe7jRY/Egujo9L4cdbn
oMnXFKB8RDAGPm0asC3AVwlLuFAuP3bDSpCJT7XSF4HH9QodJROHkXWP40zPBkUyATJiapD8glLLyOuO+9EX16MrjQIp+wZsh84x2/Yfx0Pnip+s62ANDP2WeQDJaK57
YIv8dCovoaOj3epODdAa/bbSSXCVVgRfpqxU1harOYyRmBvDyBd9UA8nkk+RmIrwFAR0R934neVZqWR/VJzgCn46+tcoQ+I7Kv/bhStGamaZuC5ndmDnHkRdntlCjY46
kzPoqMliZs+7pr+hxj1cyd13xeQ6hdt55UQ915ASjxbFpRSg4a8bqBD4sRi6t5643rrXHX0BCiPB8p5k79IZlN6ixlEkgzOwvx0l7ht+DfboFHS/VPrUQxEg739md1XK
8rkc+ZV2R1987N2ss/ScEV2+WDrLz1JgkXEgchdLLYUvHSQ6StWrYuHmpqDO7uhm4dldR30PHUnYWXR8K3K+14T8gLTXMOnqnPSYlfktu5zEytsnembnZpN3T6lcRjO+
LG33Pdki+zFlPe8TXRmN2S3RdGbVt6lj9A2wrBoz351cRtm4OhYvnSggG+DpB9XEDiZll6F27EVPJ/IbQibR3U9KvF8ywWNWk/YNdpsBOMD3fOG5DosAqYRzT28/PN8q
3mI2cp/VamZV7Y+cyHTqZ1/MxNrxOmv6tjpbMevdn/4KjxZH36flXvmaNfzqHLmEz2ou6trVSao5TSKEuf8IWW3ZYXUSr8sI5c+7Pob2pGfzK7dAm9mmS5T25ZlNYVbh
qXJmFUYx++6ihGEHAxvlW9rOZWQDaNXoSGFWC2n8JLQURGFhC4HYTBohHJ0zVHdvyrM6E7vvm8MJMopw/lOARh0CGGei3xCqTp7wskUoNto3YFZ1I8QVnXT2vkO/qwiQ
lWZIkWy5GhE6NaDZvJKnOmMLJjNZbxmGsKSYe0X+NlrW4T614lPOWT2cRR5X6eXoanSENwj5T2GAVA4d/8eZIfXHRGa1POk2s51Nt5tZ5euik3A2ACYadNSz3KRPjwFS
Ly4NZs2Wg205xLWWSgL2Vy9NDc2SFiio478BQ2M2LzMH4CqFOoLVKGPZ2eIp3OX75rCuGHDdc3kdmSfZHjVI3igdv3HKc3aZUia5shkumx2fWdW6xQBJxb2evPjgOykC
JCPADMkO2zY0ZpnkOMCGPQgwiQONXHllu0xMCtFNn4nu39ydrVgxXao4oKzWU+I5q/vBt75/pVFe++J8FCQRc5ZJju0ygI5Mgc4x/HLVPZsKBkj1jxmSGK/KTHJ+z9Ja
lD6w/ESb2Q6mu+Wam83sXBbyMBOA3ZEPqpBlkFidAa/JDl62t7ecfumDP1m1LZdDaP1r+25nWyy2vPrujU0dsNkEHPIJWthYlAtaBY2d8VtpmRspcz0RkdRW5zokRHcj
FI/qLpqB5Y04NnEekEYsVILKopyTvHIK+0aKDbgn0uhTJxUAyd7KDitFUMsukN5aG6jnvDO3NDm1Df5jZplqZbBqWRCNEFoLTku/0TmrV3PDQ981R2i0JCkHjUKe1TJu
aQrQIAsRkP7YeDvqSIR1UCk3/ASORDazTWecmcW/Sd8U97YtZLU7vnRH5tSfrIH5hzd9u762x/vxD7+zKrxoo5m/ZBrojF6SmqhyFu4CO/ma6HDwuFiWNhsXKgHjUR58
d/G/Ui4b4aLrH0z99E2rkbz+ErWUKzJbSbndfOk83dkA+rquEjuvAEgqCGLBYp+VaFKYVZqVV7BObUMRjSgI8SRMM4u7zh9Hnjs00EFM/reNYDVR0NFmqkniuee01hk3
Rr1yxKzKtfXWlTu+em+W7aH8E82pmB8VMzx2XjmVG5PNbHQ2/Qb+zEYPH6UT5xyRhYfU+NpyGknMbxyNetI2FXVtxXIxMM/Bjl92dG50nEdCJrl5LpyFHQOjwCdvXDU6
79V0JBUASRfssHev3cUv7XjH2ng7vHJyZlXmyXknYpRr6JHBK5G+CMS/F9gGn3lwxoMAj99Upp21B9E9e7i8clqZ5MLHZ7xyeKIr04H2jyty3Rh4hFeofd60orXwMcCQ
5IRBrXLDg3YcyMKrbWYTJ9rNbEOvnOJHB7+KK3LiQyemWb1fd6uIBG8azG2SrWS+ER1TOlMiJ0aY6S/CnklOtBSvHO0bOVgU044ieVI91KVzSR/MEFtWAyQ7LDnnosyq
88qp20+HqGqUZcoXwrGocA1FWawcm68+ukqcuVIYMr24fPEC0QC/qoeyw1bmnHP+IBtiUR+ch/i5+p7nhkUPjOPM3rZyhmF7XjnVc+rHOxaCjKeTX9Vcf+GWp/LiycUT
Q5RZ1S0u85cpkYlI4xeEiHrz+V45hUU7eH+FxBdMb1YNkGJZH66pOaBlBzrys/vIPDNJYRGvmTnylmErkemyGGJLTBqyUbmLwUSzAWgKfD+OAL+qtysHNgmAmzoqM7ND
pweGOF/pj2Zm331ly8c9mklOh49KwmA6+VXJWRFK8hYpfCOxQ3zmEqVvhL27G0tk+oxPQEvsTcrWFCWulemiziLzx4vXjGMNSH8GqwGSFr4va/mLFa0HB5j/U52Kg+r9
8g9XZJGzI6Kojeba1Xkttz5mNDVCY6OEu05hVgE2ala7lpfd+Xyl/6r/4viy5sHXc3dlzOqJap9V10yVsTOI9cKbbGbDK0oze8+aHeiOYR8HF+/4XDsnQ2H2oaqGy2kP
99vBL8zPA+UyyQW/kVk123vkZceLkBRmdJiP4Yq07uky+j6zbX+0mlCAWWVeJuM4UguQa144UM4Y4OuO/F6Xak5/1wTAGqEbVVbeGM31MfhRcV5z1WS05hK9cgq7gxKU
Hz6WwVjgR1mmlDEgt3R27qjMzGKrGLzExuWJCgzoIN6xMLMTQFV1OWUF00CCctPSHQuZv+QYMZh0iV2+8lBuV3EPrOZRZjXqzceB5s2XDMdJs4eiqwVIZQxYunaX/626
eMdyGUivWaZQ4o+AwqHQPaUa6jI2sYfvPFJdKTdVXq07Kd7RaXLOK8dJnhyBi70E5XWvKa8Hiq7MxTvmmmvdcUeTTprsMlVgMxs9iKzdejDIshzlBEmQazjODwsciadH
at0OeDBysSEnjvblaMUhUVxe5q85louVT1ejEJ4xYBmmPI6jAxr25j0Rv4dyvGNZlX/XwocW3jmu+QGcrGoBkhbUT1ZApLvYKNvKTS2tqkivQggX8TTGbJQXKJ89YsGV
ySnc4WwANKszUz259VA5/2rdJ0Fs2RlXPKR/jVlxsifmk1494zazlUJWHaWv3fNcmCcvW5HL7Qec3i9lGx1KG6IFCIjk0eEYJAToea5VL1qyQUWzsw7lHYf7UFkEKks/
alm6SpyMs96gnsk8Pb3fcF85+vQQQMpVx1W/KjhM1n35Leedw0oZ2rpgNrAiGNFamA++Ur5VpCT3xQAOSZJ+vGNB/iQ/qgt/LC8Cueqg00fRMTrp4qxsZssz+/vXPR5G
R+c5XGd31O0X3fL0b141rqksoxtQegPZxrbvnwtCrxJvtjvTZ2Z39MLVCy3lEjzNNt2y2CGWiBNNzMkQPaNgM7rge5NgfAkBJEKEsoO4c2nM/LzVpdWZcXQwqygclWlf
dKawOCS3NB25Kq+ccK4cx6xWBhtJfVw/cyh9u2H5fnTRE4EdfL5XTogweGj9LptZX/Ka2Qcy2rw2gBh0bDOrtW2yM/uOwyZbJ9v3XLmi4F9WkDBfR4aOFNcMRivxrf3o
8a0IdjCpU9O/yiG25Iz7a5c+2HYVLn/viszO4qTDztjsG48/lxWOnQzZRgBy+75j7Lwzuat0+Disg1uBWS3c8uUfr4NRNPY/E2bOZlz3wOa2rTtE+iNGvxJneSKI7rh8
6fOF8h3hj83LDlq9QQdCDvwB8BRa2sw6aUd5KqQn3bGQZ7U8rezjYC2BUkNJRzXEzbru0X520LK4xHa0lZvaD8rR2mg5ZveRqCVYdJjKTV66uOIdU0KVcEw7qx3aNIKr
qNGQIgBJX99/eOZvH3GCq9Uk9NSoCe13vvUYivyUf/AyPWK9k722aTaAwiKmNllKdEd5WRDqVBl/Tf/aRNoPiky6dN/3X/OozaxMj59u1buu3aPd4SNAAyJSPhPWiTGB
/tIlFVSlEil0jDoMe7aMo8TyYvcxY6QMLpxxA6vRj3cMNMuMRPnRf2KYwjhASolc8RxRurUfPC6OfPP16JjdiLmLHM079s+yKKc5NoBdT6bHrftyOqhV37GWZ9t+4ATN
KplVAVgH6qN2nEolEoZE23fbS7Zy0jOv18KkQ87YzGpmscvW0S18I4gXcjXMxyiA7xv3PotIp/w0WTjYVSmRs45ZzaVau01J+L4tA2MkvOIgC/M1Ul8G0FhHujzMrFZu
0h0DW5AWM1sZzT52wxMToz7yOnGApBHFBbFE1nzSGVmkMpCBC3TUZHPQk4V8ahclhwN2vdV5ibtuvHIkbVkfo8kB6r60shIZ5nK1AXGE9LIMzs27zSwz+8D6vQF0bB1N
gh8Lt2f7+MEssMHUx/LSLSuROXcVdt5pObiJ1i6XmxjrfKEd46g7rAeOdF68Yzzn5eTFfSUBpJRI4tALX75LGRotxgT1wSy6danA5ynESF6ZEyt7aBsdQ6cKsUZhsy7O
q1/7aXXtjpTPxkviM+clG2ZWhY78VE76lM9sHs9aO6cJh49s79bhAyJxCmt3pCxaKZF52dRWNoDMK2fXsQD1F0hyy3wteiCLjJwYVjBFhrQROnKkCy/aRocPTDbKUTcx
P0kAydsueXwHMZGYu/zdM6WQL0Zdli/erQUVXjvpVB3cQEde+Y5V25FnArOqZH7zomUKmy+8d1Pn1fLCJRM06cs3vHhEzGrYUZkBBByVNbypnVmvVFkRI9mgVXg8yqyq
8Ph9z+yewi07fVf90LceYy9WNoDc7hhSblzp6XoEnSUF3VQJfD46VkhP1Y8Rb5RZJSmmdip9+JPhvOqWYipAksAMP8nbn9zpvnB1EfXKKeiO/gbx/YczT+spIZHa6JhV
dUA1DJx2XTRueDPlX7+zfCsuVOnbSmVLjBBkhCJlbjS/HU+MarT5QX5WZ/ypmtkwOkry4X1c4tUsnPf1RyfsJN7lKi3c7jxB2nxpxGc1SnGxv+sLnQY9MkV39Gt0lDci
t32J7eB/IWlJF3zZHWOfOqew0lIBktsefnYv+sqTWzMlUmUgw8sOuyPoSOxBfVWKWWHkxHOt+vZ+/MRMVGgu+pDTcRggH3luH9NBMofut56/XbGZ4T26SUnRKq8s77OU
m3KKO++WVpZBvq4fPjpFMxtARxfvGD5KSstRhnrLhZaypMkGxcEuYDxDku2aCtAwtZ7YNJPw+e806JFR3RGBePGOtSeP+TkvZ6k2w3RMXlGKBgDJqsXchbcOv4S9cqRG
aJVHazbd/3SWqXVSMVLLEbujTqZ8hGHPfpmpwkLLTb8vXXHX84HCyClbjN8Gx7O6kA/hn5dlsBZEcZSgT9DR51onfmYD6NiutRQqCZdt0HllbOmOOANzEp/CwshNVyxf
FjsyaYbqTnXzQ5VqDcN6rjvrCyMnNZs5ABa1O0og0XhH7VTazeSbM5H2smYAKW8dCn3E0r5kumPOKYWcUPhX6o3RjC2GdGXM3IR5tBNgpOW4Zs5nNe6VkyK0Hz4y8/Wf
bm6UGSC8AQXD2xs7KrtXmPiZDTg4uExybRqwdur9wwfHFOpHTtiH0BT8EturLk3urVNh9KUTclSFbRmVxXOco9mEzQLbEREdhCGpNELlPhOofuy3L8RJYxH43W89ljhr
49WsGUDybmgtly19nuiCun287ZUTj/QiLJIO5RXCnAEkk5Rnh0ynvA7L8dkXDxP3FmbYAjU6CnJmBasSGYeV3i41tBZ0l1JZ2izekdNimFll0slBxX60eW+RGZ7ImdVG
Uy7h6ybLOYaEjzvaoI9klVKyLV7k6oS5OfR2lRZ6I4M5LmYForVFmQZruedE4st1HyY5ZZRDYGLSfsktgHjHGlJ6Vl450UxyZVML5Co9T4ygCgusMUCitXzt3s3XLHuh
8sv34x3DW4PQ0W/DzDF/k6GqQ9HwIuTK2ZqHakjhDhxmU5hVKdx4S5E3p4fkqlsQnJfRXTgMFo6K0SBX2vvManneJ3Jmw9kAEEg4PkemL8esGrnaGY7Kxez8xavdqnO0
dlh3lPADTBgHuw984zFOQuNep4/vmjyrypUTcBPTWS2RWXXSnmByVQuyMUBmxEVe5cP3aHVrUcwqeYnC6ChmtbINtZ+Yy6zM7KHMh3vsfkSr8gqqGpNgugvV6PBFJKFd
98CW6x/Y0kNy1Zewkk61S7fPBuIdfbznJE4nUWPzD3JXoAmY2ZtWvJBiSI5S5YW1wdEES/CE0XoD+H4BMNaVLMEerR3wLsl8yAMfpgupfGr7EbnXATBjOi+wESSAhMpa
snJ7zYLMBKWcl3myhXg2ANcPZ0TUd5T4AczysB7RCUAyVnm05vnnxP7PymeVSK9wZlH+VbpjgLLjVEKpes5uY2f1VRkHsfycyNp+iaE1J0e7aLARFWJptnTNzl55rtYt
OMEYUxCNd3STHnRUbuUfYNLpUDPL5zqmM4uhJVqjIz3eMfdZba2Nyeap+r274dGKdWD1Cwf44qIp4Nu0diAmNcukuG1/5h/O5wm0yPozXqokiC4eiwpWAVsARwoJJLoF
KZNcvm+3Fi2K+8SnQuwQIJEUlbDg+mSMdD6rgQOIDt1lZrV0rsmkz+x+66eZKok2NhYmGZ3UGPDVeY1cKVXRyMJotUUdPqQ7LnsmO5RggOz3dvP5m9eyHew5GIkzSXdU
9iedUydUzzjO7LcfmFc8vHwe99O1hNXHwtqYwtQKvV3DbBe/d+3jmclwb7bJ1On3LvNXlO2QP7brh0WLuWSM+A8sjigYXLAdYeNOON7RLeOySzA80zTYyzsHSGeMJL1O
IBuAv1Poq4hRT634kJkDx9HDPvbtzCoJ0TGyjCu0JLQhg/yDG57gpCZ+JoVybBtLInT0i3mk48adRzmO3LUmixXp9w/bzXuvWvHvr6lNuq139CY9pCJX0unjNbOihWWe
CZCrXoGwkECYPsVW60NAFGg/6ED9ntbJ7p/PkLpgvjGycp9J+TCFjpxxCz3Af7xr4QoFgYws48pJXdsRe+b+2cje4tfoCOg2800t2dpWcV/YpsleVLxd5wCZraFDJ0iv
86NVLyaSbG0NPRTqABF3/OWToKNbnZyvSUo5gjDJNykTBZ/N0rXkGMqWjh/xHTgKqP4AdBz+q/XNZkFH6qTsOHCcPH+LHuyX6bG8ynk1fB8CxWmhZVImncLugUkfi5ld
vXkfGjATEZhNeCoxq2Ff5S37jheSLciKA3M7shvuGO2AMkZCVlfN1CzBpi4VQ/DDzM6j6FV1U4lvgRhX7CkjNWsOGsnB9My2/WWAL7z1fGa19kjnJVto7VQ60pGicozW
RsdD7QogM3VwJqsm8aNVcynoKhdfIrNKh6Cjs2v6Xfmb6dBJVz5FHdOARhcnjk7gR3wHPkLpjjGep8Ws7jhwAp/hpvWQO14Q7kb5hRe2G97Rc1SOcLAJk559cjxI7DSn
jVGbWaShRNhhdEyjRloeWz5xh2POxFtxul+K6T0oMtJP3SBpV8Y7zp/TrEaNdEf0qpgTVlbImuwfI3Jq5wvSdgTfpi/IO89VI59XoyM9MjvratqOdN0CpMPIcq0PrT95
5aSkaRY6btoTSgq15PFtv5/7iGJv4GMY8AkOno0PQ7s5ESntAtytAcsrJ3ccj+dnipnEZ+WVwzHwxoe2gY49SSmXvtGopTBy/naTxTtyvg6jO99n00nnKTg3jc7MqiJj
tABvO5NcJFeO57E1tx/BB6KmT2oAWdPF1qv2kNWsova3mUlbNRWCuU2yD1YmgzwsO4QZ7Q/zJaACbVLkFvjExzL47QiyF12WAWAilWNdlO3gy/UyydW+qeIdc/pnTiC8
8rQd6XoAkAgR21hlPSyWWoIaka1OOjnYSlFWiy40yDHjJZbCF259mqO3PLBZmn21UNI5YKzgDR5KMqpS/pSW3TSauj2l4BHScHY7qln1IydA+mak7SbHSEKJZZtJMppm
J6f6jUYn9PKkj8jMNrLNlEsMVnJZBY8t6Otp8HFIX2k9bEnKbDhA5YtRt7E0Hc0yfxXmFzCWC4/bjvqKlJyo3HYEPBMXJydVXpPNNozu4q74STGot1dsa0N26DhVR7re
AGQVRmZiDcQ7+hMp3TE8tVoB/rbLhLFxu6UJgHGegvzsyeoEFOmKDqUvgotAsn8s9XngQsR34EUYf4xZbQmNbVfoCIndw72jg64cRureQOp5vXhilkEddypltXrb4aHM
rCPWtNckMqvRU1E55E7oOA2FIzpYb93fwg6AWVeBH/QWdSbX3hKI3tZK0G5Wd0DUdvSZm9YIKdEpYZsgPHu1HbFasEGcfXWmsOqYXtCS87EFmIxsQxazyos0infUR8qi
nULCo2cAWcDIlHhHyV1eOZty/+yaKwtLollAd2GtEDzAV6HVyTLSAmVVsUajRx4a0IxzGbdwo1gLrgu+9+Si+59Xadaqsc155cSS0x6V7hit0eGY1RFBR+1Wwsi71+yI
Mqvt2p8hkkrsJT8+e1MpXib9kWd3L1y6Xuxr9zOL47v6wVqDn3plGk8eyluE3zS1RkeVY4ihY/cQGO0BWPrwtY/xIYORQSYjq1ZLbzsPRXgRx6yGz/HsUYeOvbTs6V0A
GCG/WmwcsiG63HYUpbvYi7QdcUD3tyMt2nL6Xx6KK1/b7ljLwKUwq17OyywDqHtZFu2bptIc0EuA9DFSzGrwDN5iVgO6o27HozVwcHNTqMMRq4Rdj2WEwsd6Eg3rX3wz
rDnZtAsXjbnl87f+DNPC36/fE3zonN2RZtFqc+mZ5CS0kUJHbUYL73RcazX4KRyFn+BBJ7uXNm06vaIrX43zj0Sc0LuZWWb88p+sY2YrQTEfc+amwdjadsfajUbpWqJU
cyWvYOgYxbZeNRBGtrnW8kqbszsmZv4KMwqO4vI98N2ihehSxFr6dkRaJRYt534WbSAnvsQV8LJuuymp+EYoAIlX8EKVWhLjFaZ50fYYIB1GQgwi7vCS0tT666mwt7aY
jZdP5ttuZGoD2y7Li22R666ndqFT3vDAJhAUPkR/5CpkmiDjdnSvd1a0KIHTKBvA6DCr5X3Ks0dWAFuCsbmFjmE63QlWkx5eQuu2H8zO2vkkMqFMa+XM0pVnnqlYSP5D
o5tIoiGZh7I2/PFP80bTK9hr1I/jWqsApmVTV1BvQC90zGq4mQ7ogZOf28EyI2K+F/FfwE+LFg7M345kBY8ewpSQJKdMA/Tb0fk29Vp2p5wNQHbHKWRW3TLrPUDS9d1r
M5+dpWt3BVANIiuIjq1djM006gGrE/2hYxFPQjF7iXbsevfF1sAU0UH6pTDlonjHmM/qURE4xDviszoKdse6bUgYqTSz3jWb4rOKf7K6rXdUbvVJ/ZCoTZpjB8600bXh
6NwXshRZmZpYR+Pjd5vbHdWguhkrjSM2LpHhSddDVf1YFxsNPqtmd2wEbz1pDEaSLLTtaDY3s1vbmeTCJ+/5zGqIvQyf9bUMWNU0C8fU0kwnsAR0zEB0Z14Ioc4AxN+V
KyfsXU8zL5NcS0rT6ZVTWHV9AUieQbkJNnqowsrJy049Qa+cRmqEVkB4zxJ7FjxqZctCR62Ac78G1lOvnFa84892HFW8Y8/rWPVko3GdUBWL7cbPIaBsAJJ/4JStHsLT
JJ5KayPQlXPGS+EV2g8NMRApJyeXCDvZK2ee+x/H8KFHefZ2JYxRb97Bbl68Y3j9pPsYpuNZrmKGlqK2oET6TVgb+FI6infMPmR0blJYYHWKOnCM0TLoYKj9AshsjvMc
Atc/uIVcdO1tcVaH65hXTmZ3RI2InaFaaXYT1Yi2pbB2dWKon7/QCy1bukWr2lztwU04keKVkzkf6Yj61MxhMskNK96x6bpRfCSlfTfvieqOmdA06bxpeGvAZ0fyD3ps
ZZG1aHuxtdFy2MsfGvcYSrE7ojhGH1rOo6S0I7bRNF1jPW+vLPwX3fJ0I6+cYBnUOR/DejuRc1bIEi0Fl2KrIiMv3n5o7U6VEu/Is1K8cniWFFb/TeF7WbSW4Amx9BEg
6R1liE0fxejxzQdKoW+125aLdwxvbQmkf+sRjCSv5FL7RMbmDm4Bhk1qKD898cqhNx1RybEAOg4yk1z3uw/K0OntirIpSqFsM4GjrmQb7SrZNuPc2eN6bXhtMCQ/a270
tJ7bpFtbG2ZR22i6X2y96oGDnRbtmpkjvdAdM5NBXeYvbyW3LAvRtZ3ChIliCRvU3YqlZUq8Y/u7ay1aZSEnk1xPAlR6NXfD6qe/AMlbUeCXrR8AAAbmr6dquJLPaniv
TMdarSc4wPDq1BPr9YN5Pqs98srJwqrQhH70xIvo2YPJQt7bRYa3OiUUAAA/1U5ZzimTrmkK62dMuseshpTCFk8b8lzIbo/S6XqXzmp0ON8/y0Le21XXZW8QhlQFZ9EG
nJnD8Y5uheuAHvAxVEvZHcO6o1ZsrFnLx41mUStmeo0Ovxy6s5RPQxbyxIXUd4BkHMCAUu3cuXoncfzBs1sk3lHrrJGDBqetcEybmNUoyZbCrIrWoLdwvCN7/e4jL5E9
jurHaNhDTwWQuFbKzThjyrqDSZKva/4ukNHp2h3y9F0Bu0s26VHW3WNWQyYcyT+ns0LNnMdW23mnGnEV7wgH9VyQgWgnwm4570CryvfPUgF0vLT6d6Nz22kXBp839enx
jvmRjpN3ZDWy/8wcxFIYihoSnsXCgrOQcXprnyNDHkPkg6x33plnA3LMKicGjI5mKS8svEEAZOtwNHMIMKAqhVdmubgrpagR2gETT1sxr5yWGlF/vmutwvkFX2rVl/R4
R8o6olVf/8CWoSRZ7e3uAwzwXfF1FU7lDaYplkcpsTRYYqIQHdhhVsOO+4kPLXhs4eKLgvKhbz025d4NvV1jPe9Nac05x7QjQLIvvZFXTlR31GrsD7NauwVJUE1DlUSr
4u5rtOrQAJIHQ7dSZhlV8taVO3zPHfapFGZVRqz0bTecadpRdkFmL/tsvB0wdFpMrNHB4374yAxCwNEX3brnX/5QOoRulTM91T+kSjKMaAqIdGYp3TwTPRK1WPejEdbd
+ayGVQRWkcskRzQtjksIAUdf22iGsg4bPZQTDOcY5kuqZCNmNTHTRRQd57s+1MKey4IS7rCRz6pOh2I7EAKJfhpJb0oaD06DdAJFefJUyQxyQEePOoiskn2zSfGO2B03
xNiP+c6QlT6rUKZZGbnETHLReMcH1+254q7nv/7TzSMey9HZ6udUjir5roUP4cITLMzSmuIER+VmdHrUZ5VDjDLJhTcapjvFZ5X9yJUYZJNFccS+ZbEcnS2eYd0l71Y8
Npm4GGWauc1nlKlXrbZgVuB/CfNV/H7UA7bsPlq5LOdnkpsL5fQatzxgYVbDuqNXo+MYB1mOs3p3Yzvqlt8QAFKq5PcfzrQo4uKf3Jol44460A/RQQMLU8rBLWzpfPj5
A9DLvPLDz+6dGMWxvKpQJUlgy1dHXHwhP1FBhmEV0xmb0wmDFDqLNtFMEdId81rWIc9nZYrgR8YbXpmt1hTHYeFcN88FHnA3qzGlz53X9YjoTpXoXZ+oOzZ6aNR5x9mA
Fq/YynmO4yyH2m5EN/H3DgcgJdZNu4587d7NYMajG/fBuIb3o3SSLboDFmq+BDg0x56Fx8a7BNCREwDBoFnahIdnOBlM/JLiBSmEgi4l8qrkvJMdgSUETuKJkx6Vv0PH
aKaCxE0kJRvA7oPHxalCL0czUE/DvI/1O4r/ADYqnXc814eQnUU2oGjlPhetlC/XSIIez2pQ25KHJkYrcZ7ToqUomC3a6IodJkAyOHQp0BHGFY+V25/c6Rkm5w5u0AJp
ScWy+JBYHYbZaJi5y5Xj2LOA+oi3Kg+t81kFGpV2/JqfbuY0EJ2MSWqALoVVw+04PkyqMEvYx8FzVE53Rg21hM5lbYQJKECRI3YsoDvLe7Dn4PH/+uOMniKjNKeBSZq4
aX4XFq0SRUEJ+MFLMWa1FeArEM2dUUNLsZSQpNqoVGJWy82yp4jOjRp32KNQlD92Q5Yw/Y++u8oMAYnrfMgAqVECk0pNVwmTahM1d3tnqNrVWQozr24p9syP+K58esAr
x0HjV+/dPL5RHIlrKNDM7Tg6mBOgTeMoSeXT6VHdsQ9eOaGEBvDGlOVjl6FWrUVxdL9CRrAH9Cq0KweTGmGCz+pcwsXAZtWIWY1mkvPjHQNfyjPbDlBvS+c5W7SNltxI
AKRGDP1IuKS0SdxcwRhV1cizkMfViKAfTXb7/HjHylNb7rOao2NirpzywY0gFiUcn3Jo9FchOw7hkqRbo9bYt37aKoBes4mg4h9vO0/F4x3ZIPJ+altKxY+y7spCjvoY
2Nrgpi7827XsMu+xXabRHjOejR1Msmi/uey5KkvB3B6CS1p7jdUuRUJpJYmUeEeaRes7svgpAxkmRf7uiRmV9rNF29kyHCGA1As40hWMuf2JHTCTiu4I7FzcJTUi0Gx+
wZfaRezHO0aTivl2R8hhUgWRVC9LP/vAlmnWGusWokhXVejEhcevh+4m11fxo/LnQSm8QlvFrJ10Kax16KhK8XKFx5XDDuCdbTRjehcwCemKpUAuPFX5d+YM6uHV6HlR
hE5+Kec5Fx8FOlZ+Jixa4nHlO4bTnFkBOl5+IweQ7k3AmBty3xacP1EoyeZauf689RTZAQMVrJzdkd6imeS0Oh06PrhhL4ZGtF6G+pPVOycyfqPj5VV5Ixij+DM+YBzN
Xa2+po7K4WOTpika0eHFOxZJBSCcPRFyWB4NZrbp7TIYo9442+HCI78zFi3Yk3toywTosgGEYK8DZjUAt4F4RxatCqsB6tA2Fr/R5TIbXYDUi8G7Yp6ErsxcXZa9gCOP
Q0plCyPeMRxfUfLKqYx3nE3JJOfX6PBxkYxxBHdOcPBGl4us8nadzbHkKaHJ1+/d+PyLh6LmSW0N0XjH1tqIxTsqk1zhoT4u/vY3H2NntOCNfiyAcewTvAF1pFCyaP/2
4S1b94bTApdrdNS2L9XoqEBcdrNyjQ70RX/R4lPNGdQWbU8W2KgDpHtJuFYslEJKdMqs0uTMobVZVv7AAm3Vd4xmIddTwMiwUrJp91GAcHEewcklXJySyI2erLbKTuB/
2HR+86rW8RylDUqzMobSyyQX2pUa1U/PY8OzfCKoBTp6cwkXzQm+f5M+7j2zaL/yk3Vvye0FIkKAqLKdslHmr6ilvBCfpkWrmA3F+9ui7fm6GhuAdG9O8lIiQ5RnwIHl
0rW7yileE+Md/XINBYDEski3qK343YhExYfo1sczbDZc7Pla5HiOkRIfdH3w7DuAJVuAM/zoiToSheMd2WvCZ52nqFE6c4DHXXDTGpGoqAUX3byWo7fhYs9ndoI7ZBXd
cN9znKi0aFErdcLTom1U/dg7x1eztc++eBhgvumhzQsWPaFFi0Uf8t/0xf4tsPEDSF8WGPwAy+89tA3ccnhJVD6QdueaXS/sPvrM9iOrt7lyzb7awRJs5VlVJjmAkAtH
G+5FPaUTISIX2QyoQ4KyOAGJxfu3knrbs9ALsBSdxXXO1Q9/6sZVHNUJF2H34SprmY5Z9Wt0qDEHfG5k8+LE/aZ2n1iVqHvHudtMNb2dvinsDUoT9CosWmpPEnrIwgss
2srqx1q0AK1btPoKRG8IFG3RDmCZjTdA+gJCpRNeYrMkJbocfMoXhkzAz8e/Qhvglot+QETzuBnAEow+ApVOeInNEsh0p3W3ZbjDOx7tH20frgv/yv9yLxf9gIjmcRMV
uzXoRgJu0QJmrDrZ2ssXCHrB4ic5tEkjrFy0EBssWhDRFm03M9LZvZMDkHXvj9oHzrkL5NMl/HOXUaadLaAh3sUJmi3DXWwiuoR/7jLKdIhzZI8uSMBfmdI4dQn/bNGO
2oKZfIAcNYnbeEwCJgGTgElgLCRgADkW02SDNAmYBEwCJoFBS8AActASt+eZBEwCJgGTwFhIwAByLKbJBmkSMAmYBEwCg5aAAeSgJW7PMwmYBEwCJoGxkIAB5FhMkw3S
JGASMAmYBAYtAQPIQUvcnmcSGGEJnDy84a7LP/L2N5zy+jeceeF3Vu44mY/15Ibrzz3lnZ9btrsXIz+24foPvuHUi5YdVN/2YxIYXQkYQI7u3NjITAIDlsDJmVs/furr
M3TUdeqnlsyc6BFA7l524TtPu3DZwVcNIAc8q/a4ziVgANm57OxOk8BkSSCHrlPO/vyyGZS7kzvu+fyZb8whrScapAHkZC2W6XgbA8jpmGd7S5NAXAInDy676LQ58jOD
tDecff2Gk22AvPW2y8984xtOeeNZF93T4l5fPbjhnoUfzZTOsz9367rDesTJHY9dseC0jKT94i3XfzrvcGfWVa6Vnnbhjx/LKNYLl9xz2VnZX1p4HB+dtTAJDFwCBpAD
F7k90CQwshI4ObPsog9+9IqH2vjXGmhugzz9rDNbIPeGlj3y5OGVC3OQ0/W+y1fuf/XV/Ssve98cSZvxtJUAecZZZ4C1InLNHjmyC2LaB2YAOe0rwN5/4iUwOzt75ZVX
ve1tv/7af/SPK6+bb77ZEwJ+OvcvuXnh5y66dsmyDVIKc4BsKY6yU+bUa86afuzWjJDV7/zx4LLPndpWMQ8/tQh/nxb+zadYW4rjiZlbP3Vaz9x/Jn4m7QUHLQEDyEFL
3J5nEhikBEDHBQsW1EGj/t4GyBM7Vv5kyW3OdRVt8n1nXfYoGDnPi/XkukVn57bJ/Jd5yuLZ169b5/u7+v441TbInvrHDlKu9qypkIAB5FRMs73kdErAR8dzzjn3hhtu
AAvLP+vXr8/lU/AvnftfA8jpXD/21gaQtgZMAhMrgYsvvlg6IkokYBl9zxwI3/7R65/KmFWPIK0GSJ9iPfzo5Weefu716/DzySjWXO989eQLSz5WQ7G27Y6mQUYnxRoM
UQIGkEMUvj3aJNBHCWB3bISO2VAEaXN+N7I11lCsr8530mlhnu+k88Z3nXlG2y3WKNY+zrV13ScJGED2SbDWrUlgmBKARxU64puzd+/eBkM5vG7JhWfnGPn2j15214bD
mQdOjQbJv7TDPE792KJ1IGn+0+7htI9c/8itFxpANhC+NR0xCRhAjtiE2HBMAl1LYPny5Q4dt27d2nV/1oFJYEolYAA5pRNvrz2pEli1apXzWW1730zqu9p7mQT6KwED
yP7K13o3CQxSAuiLLt4RPXKQj7ZnmQQmTwIGkJM3p/ZGUyoBHx2XLl06pVKw1zYJ9E4CBpC9k6X1ZBIYngT8kEf8V4c3EHuySWByJGAAOTlzaW8ytRIwdJzaqbcX76sE
DCD7Kl7r3CQwCAk0TQgwiDHZM0wC4y8BA8jxn0N7g+mWQCcJAaZbYvb2JoFECRhAJgrKmpkERlECnScEGMW3sTGZBEZLAgaQozUfNhqTQLoELCFAuqyspUmgAwkYQHYg
NLvFJDB8CVhCgOHPgY1g0iVgADnpM2zvN4kSsIQAkzir9k4jJwEDyJGbEhuQSSAsAUsIYCvEJDAYCRhADkbO9hSTQG8kYCGPvZGj9WISSJCAAWSCkKyJSWA0JGDoOBrz
YKOYFgkYQE7LTNt7ToAELCHABEyivcIYScAAcowmy4Y61RKwhABTPf328sOQgAHkMKRuzzQJNJSAJQRoKDBrbhLogQQMIHsgROvCJNBXCUxuQoCTB5dddNopr3+Du86+
fsPJ3csufOdpFy47+OqxDdd/8A2nXrTs4Mm+itc6NwnUScAA0taGSWCkJTDRCQEMIEd67dngDCBtDZgERksC62cOuOv+x3922q/+2mv/0T/muvWOe0ZroD0YjQDyg4s2
HKvqzDTIHojYuuhGAgaQ3UjP7jUJdCKBrXuOAIE3P/wC12cWP/lH3131a5c++A/+fFnh+oULfvDa1/2K0PEXf+fL/r9+6FuPnX/jkxcveYoelq6aobfZEy93MpQh31MJ
kAWK9dOLbv7iWXCwZ160ZMPBbLwn1y06+/RzL7vxuo+889zr15189eCGexZ+9FR42rM/d+u6w0N+I3v8REnAAHKiptNeZjQlAIABY1feuf73rn28gILnff3RBYtW/tkt
T11597P5tXHJypknnt+7+rkXz/n3HxI6fuJP/3Lp2hevvX9Tu82z3MJ12iXzYBWUBTVvuO+5Vc/v2Xvo+BBFAS2MV1Hgpz22FIr1jLPOeGPLSCl7ZA6Q7zrzjNNOeeO5
1//s4MqFGXy2rvddvnL/EF/cHj1hEjCAnLAJtdcZFQlIRwSxHCICYAsWPXHJ7euAOgBv9bZD63ceLV+8AAkBzvvgh4WOF/3VZZXNNuw6xt9p/Mz2g/QGdoKywK173FlX
rkDFXP7MzkGC5dKlS9/2tl/XyANXA4A8RZh38vC673z0VBBx3ckMIN/4hjP/YtmOE6++mqubH7t1JvPjcarnqKwBG8e4S8AActxn0MY/QhKA5wSQvnTrU6e3KVMQC0S8
Y9V2UGrz3gzSwtfB4z/nfS78/JeELsDk6hf21N2iNy//q9TN8xevdirmb161Qppl/4QFqLs8Bg0BsmCDrPFizXEx8251v/AyAsuiH2z/3tJ6ni4JGEBO13zb2/ZDAsLF
L9zylLQ3YAllbvGKrY88v//FQyf2Hn356Imfb957vA7nFv/oXv0TzRjeX//XK2LoOEu3tDz+8slNe2bDiPvIc/uWPLYVS6fGBnLD9PYDKR06okFCru7duzdB1Ck2yHaY
hwFkgkCtSW8lYADZW3lab9MlAZAGfVHY8xtXPISyiPbmEGvDzlmJI6A7oiCedvpb+a90xyuv+57QkT8+sm5rQHek/dyDcrq18jqcd7tx9zEY3cUrtqBWarTvuTLTKXvF
vrosP+eccy7FRpIXQQJA1lCseaAkPx7FevjRy888PXfbsR+TQG8kYADZGzlaL1MlAXAF+yJGPqcv+ri4fmdLq3v55CuIZcfBlwJKHuojcHjHPffRkv86dLz/yQ2Vd80c
bOmOUbZWFkqho99YSOmslRcsfhL1t5vp6yKPQQJAnvHuszIP1fw69VNLZk6IVm0D5MnDvpOOZRXoZiLt3pIEDCBtUZgEGkgAaISilBIGxoA0lb42YlZPvHwyaneUM85b
3/a2pcuWO9Pd0odW1+EfNGwCszq7Zd8x6Y7b9ovarWBiYYBReWWnfO9VK/Cz7SBWpAt0ZHQJAHn21+69+VNZtp1TFyx8dEemHc4DSP6/HeZx6scWrcu1SvsxCfRIAgaQ
PRKkdTPpEsAr9dNtSx4mxvkqo+jNFght2BVnVmmPGypqogPFf/Lf/w/63Zkk52Nk1jkyBh0DuiN9yrvVMauV0Oj3sG3fMTTIc65+GJjEzxbNOB0m/dLNIOWkLwF7v6mT
gAHk1E25vXBTCQCN8JDgx1u/nHnfoHiF6U2PWY140Dh/HAeTf/mVr4d9VmcO1Dr7uBshdT1mNTKGDHR//gr3AvnEVsqRJwUmccNxER1EdzSVqrU3CYy+BAwgR3+ObIRD
kwCE6hU/WSdC9XvLN63edrgGveZ0x71HkphV+tm2+yDMajkiAtL12u/fBsvqB3iIWd1zJGTORFlEfdx5KEPHrRmzGoHGPUey5Dvomr7662ASbRLStU70Vrp5aIvSHjxA
CRhADlDY9qjxkQA0I1qUoBGjI0gZxRuFXvATbSmy1FnvyhiJCyvurAJIebeGmVUH2xpAwSunEtTBWqc7lhsAk/LiIYASBbo8bwsWLNCwie4Yn1m1kZoEmknAALKZvKz1
NEiA4A0lR/3D76wCGtHeopgHOs6eOIk2FvPKybS6Q8cy1e0PP3VBZUB9GxqzlunxjqiMsjum6Y4vnXzllZg+ehQXpDflLjwYX/2AECvdPA1fgb0jEjCAtGVgEpiTADAg
cyNBjcuebgU/yKGmUg/T3+WV0+Yqk3LlEONYRkeyyrVjHzOyVIqmH+9YNYYWj5rgldNqKd2R/9a9lHsKYI8mfd2yjc4wyY1+6WaIVls9JoEJloAB5ARPrr1aMwlgclOK
OPKaPrX9iG5OCTeUV05Md8yAU30CTpdc+U0fIBd84vxyWgBaJjCrLe9WGj9bny7Af4us29wrJwyQG3e3wA/4v3/9HvnvnPVfrtWwcc9pkhCg2URYa5PAiEjAAHJEJsKG
MUwJoCdJccTwBhhIxzp6IhRQIdLVi3cMO5fOMasiNrEyCmmAxvlRj1lLohiFjrFMcrPAmBfvWOeVM093zDXdiP8O3R576SQOR7ygA9e//O5PHaivX79+mBNmzzYJDEQC
BpADEbM9ZIQl4CyOV929ETAgwJ/BuvQ3ATXL88qJ0KpOdxTYKHvOGe/+zSX3rihrqPLKiTGrrScmqLnz0FG6Y/jafTg7HyAHvxkhmw7Uf/EjV3KeSA+XHOHJt6GZBEIS
MIC09THVEiAfqSyOLvA/DDk+XhagNGCkdGY/tcHWWJMNoEXDJjCrWcv58Y4R2BOzGrU70u3+2eyIALPq3gh/WuBc6iPkMBS0sgpUOrhO9Xqyl58sCRhATtZ82tskSwAF
6Pevy8oXk79b6eIEeCk+q4AHdkcyyeV4E6YrZwntp9uoyyj9JPusZsyqXnTbfijQaLxjphEmMqugI+64Po6CjuXilJwnZK8NxEomT4U1NAmMqAQMIEd0YmxYfZXA1j1H
FMhB3USBgdCRn3r6sYVDjlkNe+U4N9Q0dGzpjo2Y1WC8Y5lZjdsdJYGCs8/5f/oFV37LCQe3JE4Yv/3Nx5AhuRSMbu3rcrXOhyUBA8hhSd6eOzQJkHr0Vy99kCTdOa3a
go0YOs6lWk1hVgUk0h2DoDvHi9IsjVmdTWNW09+rNQYxqwUjJWxwuTiljJR6L3LvgZEfvvZxw8ihLWh7cN8kYADZN9FaxyMpAShB560qGPOY1YgZj/qOYlZz3TGikCUz
qxn0qlRyzGc1aykYC9TocEqeDJ9HsiwH1dU8XEsIW7oldQAv6L+XnIlUnNKV3wIdX3nlVdo7GpZ8AjJJopeP5JzboEwCHUrAALJDwdlt4ygBVaoilsPVqBKK5MpQAPDm
ktrQMiHesWUgTLE7ysE1QXfMxpCuO4Yzyfk0sh/v6P8dD9syOuYBnxX2VHRxNHKskoaR4/hd2JjrJGAAaWtjWiSgtONQgp7mlIUbhgsau8bKBhDVxmjggW5EJVX1Y35S
anSoZQLotl1hWxEdEU0XdZCfgt3RD+pwDrd6L8RQ6QpL/CgYCXfdZfnlaVmO9p7jIAEDyHGYJRtj1xIooyM5S+k1lg0gAxtURkLmYUETdMcWOibAWObdqhod/EIJLZQw
LiIoKq9vP7CJ5Ok/fGSLmlVWaRaWK8nAobRsAJnP6ksnC+hITh8X8khdEXXLGwGl4fcCIwmY4RRiGNn1grUORkICBpAjMQ02iL5KoIyOIjbbGmFEz5ORcvPeeCFGxfhH
0RF4A+QAvD+/5akPfCMrmtHZ9R9ueAKFGEdcv3pz4nvVMauVQR0lZrVWK12348iCPHjGMLKvS9o6H4wEDCAHI2d7ytAk4KFja1sveeWUt/u5+o6eV04ER1Wjow4dAcUl
K2cuuX3d+6+ZQ8S3ffnBzyx+kmQFgCVB91x+0YyyyLDw0YbUP7THnsq9PrJ+6FuP0dWqTfuiDkTKJMer+dkApCmS+s7lwNNfcPNhJPjm1AfASDKzuA5lSvnxl8/L39Ew
cmiL3h7cIwkYQPZIkNbNSEqgrDsmxDu2gNCLd4zrjnV6G7iIhnfB4tUOyVCwMhh7fk8YC9PFST9AEX1KdeN68yUP8kScSyuZWOmOhUxyAr9yUId0xyg0iojO9ewsqJTn
qpykpdpJn0drOYISMIAcwUmxIfVGAvJZ9b1yHLOakAHnKHZHxpHiwlMZ0QE+OVxEU2QwgGK/gwUFlhcvyWITuXCZ4fV9AhYJKFDEy0LeUpepQ+ncVlWrWejoRXSE/H1o
iZHSQSlWVfnsmF9rb1az9TIMCRhADkPq9sz+S0Dxjj46ygmT7b6egWxFAQIe0I+5V05Ud5wt5FkFGPCyQYfj6Q4X+/+6xSeAxD5S/psrHgKwt+49Jq+cMrNaDnnk9aNe
OZLk9gOZLy494x/k65rya7X4yMHPvj2xVxIwgOyVJK2fEZIA2KB4R7dfp4deECyvN0nxWVVL2R2BRqWV4YLtZAz91hdTJI5OicHynKsfFmDz+5qZwxKLi9YgqMPVsVKB
EemONIiq2mJWaV9Jwwojf/dbj42CKFLEZW1MAr4EDCBtPUyaBOD0YPb8bADkLNVL1tnS/MA+L96x1itHyOFA14dG6M3RNLwB2HLqQTjouM48WQ551HvhlRMo/aF/kjkz
V8rrZDV708NbeSjlsSZtndn7TIEEDCCnYJKn6RXRVOD00FrQXUQAtqsfK+Na6PKqH8czydEtULpt3zHVfuLCytgrv5v+zRjgLZiEBMZ7qFDHCvkok9yeIwHMa8lQrrBl
ZrUs5K/fu1Hy6d97Wc8mgX5IwACyH1K1PocmAVWwclnIGzCru5KYVWlOine8Y9WMbI1AzmhqjXXTgLsQpOs//Nyd//M7zhG5iv+qY1ajcZw6edC575UTOHxwkpDDlAV+
DO3DsAd3JAEDyI7EZjeNpARU/RjFSJu1Y1aDVYJbnpliVnOf1ZCvpphVNEXpYcAMYDNEYSh6kqsDZ9EFn/6i0PHX/+15j27c6dfoCHDRSMAlGeCXqF5OeRDks2bmCKS3
ObUOcanYozuQgAFkB0KzW0ZRAgAViEX143zLnlUmuaB5rEUV7jyckaX4rUb3ehG2+MeqliQOLym+J7ThFmyT8pTRxe8oVZ1pVMAzHSrqkf8C1VzqnKck9nnllVcJHd/6
b/5PVMmzrlwByubZACL1n8WsojumoCMZ75gFebeaw84ofjY2pqAEDCBtgUyCBGR6JBGofE+kO8bUwXk1OoJaZitTDE9RiCGwlKKx0V5KrXDLvwU0EsjhWcoviXNAh6Cy
7HllzVWhHQLLsF67fPlyoePb3vbrW7dupTHDoFsS/QROCYhIPqsJx45MttIdfT9YFcZCJonva81MAsOVgAHkcOVvT++NBHCSbJseW7Us6DdFI/SqH0fYwjVbDkhLY39P
URyBQ1AHaAx77oCUwCRXtE/6kb4YdQWSiREQrexz1apVLqgDdNQE0FKk8b+/Zq4WWEGAjllNSDvXQsfDx39eOHmg4vOU4fLSvVlz1ssUSMAAcgomedJfUTkB8CZ1zKqj
9aowcg4I05nVJY9vUxxh4s6uQEyf7eTGS257mojAc69+mP9efsczvl8PYEbnAa1UcOs7gt67Zvt/+vYT/+Iv7xdn++tffvDPfrjG9QngCXcLkw8iojUKINEjC/8q9RTP
o9wHeJ7HbxNmdVbMKuhYlj8qPoo+6n70QDDpy9bebwwkYAA5BpNkQwxIAHWKOr3KCRCNd/T3a3nlJOTKOfrXP/pZOq1KnwIzh44gGTD2//jSfc4AqV/+x7+4719fttxB
GuCH2lcJG0I7h45gLXD4T/+i2KH6BH0FtIW7+MvevXsdOi5durRSqoxHdCt0qBNXMrOaYapjVutYa3yM6f9Ltz5lC9skMOISMIAc8Qmy4UUkwD7LbovG0453DPjatHTH
LN7xyMt45aTkyrkkR0fox0SNh2bgnDMrMjxAqwCN/v/+0y/dB4LqJeFjucovDKnLAPR3GpexttD/P7v4foeRTuudnZ1dsGCBdEc8dAJi5V55AOVK+VHV6EiJd3xh3zEd
O0g+F+a3MXbS/3jFxtinOIUSMICcwkmfnFeW5yq7rWdKjGQDwGdV7x9z18xKUrRwokmEOyylAzPQMQpmjJ82wkjAFTwrwAYqMm1kd3x4/a6UDmkPRuoWFFkAm18+89nP
Ch35JboCpH3Sz58veZrGsZPEvFCZBHenozP7j/Omv3nVisRjR3TA1sAk0A8JGED2Q6rW5yAkwN5KcII8V9uYF0FH1Bov3jHUmD4pryh/0UYv4xAO8P6lL4Z0R1/te91f
3Cc8A18LSiTqo8bA+/7zi1sWx4BK6v7JGSAByD/5wiWtKo8LFqBKpryRc9nl6SnuTmJWU1qCoLTU4Yb3TRmMtTEJDEUCBpBDEbs9tAcSkEfJfT/bRV/BGh1ZWCQbNyUs
2l45EYfV1dsOCx0TYwrdy7DpO1j6V3+zPAXGXBvZ5IAl/uLrVcCb+NLbHstiJNIvdE3deNF//ZYL6khER/dGlSXDCiiIftliVg9GmFVulK6vQJEFi1Y65bgHC8K6MAn0
WgIGkL2WqPU3EAmgb5GW5Q+/u8rXHQPknqt+nKLiiF1MD090b4y2J5UIZAqbHss4BymqfmBoHTDL30d/P3PhQ+noqJZXL11fCHnsYHKiGJmS3l1iV4lNfvS/JHk3b50O
ZsRuGZgEDCAHJmp7UC8lcMVPMi8PaUiBvGjO0JhipBS+Xvx3mVdOU2bVYZssiIuXb2oKZqdcfL/uBWId8ajc4uq8aYe0P/eS213II+GPHU+AQiQ9v9Y5FVzMaqys9Kxk
66OjZk0Fwsxbp+OpsRv7KgEDyL6K1zrviwTktwKGHT0hn9Vg9tSdLWY19zSJkKtfyXNqd4aOvKrLWi6tq+mlIEvQ0eWaUdFj/sgru5DHxG5/4YIf/JPXv1EA+YsfubKb
mXA+O37sB5JXvGPusxoRrHRHijAXTjPYeim9YsWwupkdu7d/EjCA7J9sred+SUChHWBGVHd0zGrYD1Pp0BTd7zS2DkbfJUCK1HWg6P+OrkxASCI00oz0qq95y3tcUAd/
6eB1/FsUvgKt/cD6vRJ7mldOpjt6zGoFjqpemCmRXU6Q3d4PCRhA9kOq1mcfJQBUsJ/+zY+fieqOzmc1pSWZ5Og2JeVb4N0cQH7jnlaRyHRII/C/VxRrAR0ZcPcASSdI
/q1ffvBdmdswSXIyZjWhbOTss7nPapuDrQBIKZHn32gVlfv41VjXnUnAALIzudldQ5PAwjsz6+OarQfD7jZyrYTTS4nho+4x6lE42VvKC7tiGmiBlZluAniJgqhID+hZ
5x/EXzpw0nnNez4p3fH/8+7zcFsF2BQK2f2PYjM+deOqHB0p/RGOq5ndus/VVAlwsLOmRHY/NdZDPyRgANkPqVqf/ZKArI8X3fJ0/dbc2ojllZOSSY5mqtHRNKij/JIA
m4tZTNcd1fK9V61Qhy6uo/C/iWEer3nffxE6/jenvuPZbbvpxI0qPCvIFvyTi5AuBFJOjN4qurns+Rg6NsgajxKJbvrptjtSv1aP9WsSaCgBA8iGArPmQ5WAnF8IDwh7
haSZx7IdXPUdu3HM8eUhhU9RjJfclnnDJl7EhCiZDixrQdvzEwVE/XRwxmm5rb7uVz7wX+9wEBvOsS5fWdlffYDk3MDrMJ7C0UFhMOWE5j5kNsqLe/zlk4pqTSkiNtQF
aA+fLgkYQE7XfI/12yqIvl0SuUzuZbojhKp0x52H4gQg6LjzwDEqS9RlCe9AXMIYbmS0UTxz8OnSC7jb3aPTU8394se/6YI6/tl//mEh1Vzlu6jKlVKr12V9458Ynq/X
0jMK3/91TZYgvnRls6Bq1fyoVHLg2rT3GLMAGf70zMFeHVM6mDW7xSRQKQEDSFsYYyMBqXp3PbUr4LyaHrSu5OakGuitC6WqYQic0IcI/48qkZCrAicVLi4DVUqycoI6
Xvu6XxFA/j//4OpysvLyNLsSWv4TGb+7/L9L+E6V9EqMFfHPq1Ydz/yH7pjpzVmeo2OKibTsrGPzQU7BQA0gp2CSJ+UV35NnXq1SWTKthYiO3CuHGh214R/OnVXouOzp
LK4jXOA+CybJMSNdinTovGEBITLg1GUYJ1nr+TeuEiQIriq50ELhKgZDuSu/T9xWHTr+f//jpYLncrkr/xUKNbm4hXKSSOOX/6qF6FJ/f+sbj7p3L9wiVjanuwWE2Sz4
meTCuuPMgeOgI15U/KKWKoPVQQKj9KmxliaBRhIwgGwkLms8NAmwTbN7FgLV3RbsxTuG0XHOcwTP1XctXFFJrgItbNMCAFnmZHWjcZa5OwEssd75ESPYF1ET6eFNlzwA
tgl7KHdcwJ5A5m5ZN/0MBihzKpjsB3Vc9Bdf1gzVFUz2/9U9Luz+AxITeCoUl34s9VTxNh9d9ISbBR07pBFKKazESP4OKKplGx1brlUcgDgGDW2R2YNNAvMlYABpK2I8
JKDccrg7uj3X339TmFW1d5u4QgvKnqvABhighKgFug9I4F+BSRfvGJCdCiD7aEpvjr30bwSMeWJUcwIjAV2ugidLuY6VqNpAPiC/Jhf5WqNVR8DID1zzqMbs3yuP1qVr
dyLYzpjVAoJee3+Woi/lCDIeq9ZGOeYSMIAc8wmcjuHLPQcb1fz9tMWsQuvl8Y5x3VHoyH8hBkkKU0ia4xAoukEL0qKlmtQsoHSCwYyhgKPhKRV+o6GKjKX0satjNbNz
v3OoCbitqupk0wKTYCRQKt3UDVhd/ZsrHmpXqy5mkitrkKiMNPaZVb8NByBz1ZmOb3o83tIAcjzmacpHqSRwS1bOFDbcDTtbpQ1j2QAyxu9gnjhU4e3lHNnOY8WJmodi
IDzjK1kNDZhMrHEghIsLVPR9NGsrECKlU1qpgijkdEO3qIONgi9VrEoMMPf+4u98Wej4P77hf3n3pXfRoctUEFgw3OtKTsL3Rn2I/AZ6fb8HhWfoLcJGR/2rBubsjuVb
8FI+/dJWAZMpX/b2+kOXgAHk0KfABhCXADYwspGVydXE6seQq755TFWWfPWx0gvml75YEcVIvhtnkJMuFaVG9XoAqh+Gj5JajsFXS/5JNKa7AFTu3Xvg0A033DCH38uX
Cx1P+9Vfu//xn6VHELpyWqBanfdQHWqqaKUiT9xIEEKmU4bCOVomRvmsclKpD2OdxcxM5+HAzfiKsRYmgV5IwACyF1K0PvopgUp+9YV9WSY5/Fad/2Rgg3bMqtqU1ceU
OAofM/C48R1V0sEpICenawI2QkQZLAWr6Iu//NHL3vS/ntFyed26teM6Vi6UAv24kfpIYzROvYJPC0u/r/Ofkszls8qURbVMY1n7+TFZ380kYADZTF7WevASmM+vtnSR
FK8cYacG7BKHsv8WrI9yEG1qk3PBi77TSsfCEWEb9v056z3vBRRP/cRX73xozdve9usCSOohN32oU/7OvfrhpgDp7i0MVZbIKvDL5sv5rIZdWx0HCwNM9oam72XtTQI9
l4ABZM9Fah32WALY+Xx+lW3UK9IbKUNYCDzg3nJebPpXKCTK2T9PiOt3oOKcVrrMcq4TgE/Vgpf8LyVBGBsAjB65ta0y/i9vOv2/f8uZro5VU1nTlcva0wE61gGkLJEE
MpYwMit35TGrkdQBmi8JJOoq1fTdrb1JoKkEDCCbSszaD1oCuGz46eWkO25vR5fXUHYZcBaYVbVU7KP/Dk59VNBCo8vV3whnGwiITJGFDgwgVNFNC6ZBMrW+/t+d7zhV
/fKJP7m4g5kQX60b5X/U9NK9BQ1S3V6weLU3HUxBNguJzGo+X1mopXyM6a1jkXYgFrvFJFApAQNIWxgjLQFFozv7lsesJumOhZJM+MEWdDU/Ofi/+pvlTdGCEHvEB6p1
VmZZYRLOkRUXmLqQRJcoZy7b6tl/iG9OB5PnAPJ3v/VY0/dFw9YTUUMLGp6XR76lJjrdMWp3dN6tzJfCVc/7+qMfvvbxDt7ObjEJ9FACBpA9FKZ11XsJiLtTPrP5pXcj
ZJ1L8unvzqg4zkVFYwWcFPMgHajphZ+Lu7eDlwdUXKAI6FjnUzpXoyPXHf3rnHPO9V1bU8bgsC2xfpYvE3L3uPctZFFQqiMi/X2B0zj3WY1MVtlIecntWV4Iy8uaMqHW
pn8SMIDsn2yt5x5I4ILFT5J+TNWP6W77gROx3Xa2Lmi90j1SgYn0rASnTQHyvK89opd0aln6OytYQhiwePmmQMTFa97x/gIutsIf3/y/fe3GH6U/US1d/SwNIP2C6ZXW
qHQE5efCXeclPmY37ZnVAYUUgIH58nMbVer6FuzRdHKtfW8lYADZW3labz2WAAZIojIS4x2d3TEDvJLWUhlg1yVA4gjaMUD6hR4DRT9+4U/+royOxD7efPPN9656wYX8
p8vdL1rJGNJDIaFk9RQXSVl4qIy4qPtNvXIK6Mjc6TRjZsj0abWW/ZCAAWQ/pGp99kYCMkDe8cS2PN4xYnSkQaVXjkNK+FUMfoWR4SwqkhPYIAlAujqlllKkfM+X9Dfn
XmlIYarzF9//xQJAvuY9n/zTb/99x88Vwjns+XdfTQr2wPoojyTGXPBycq+s+bp95daUeMc6Lyo3X5ghz7/xyXR5WkuTQM8lYADZc5Fahz2TgNz92XZjtOpcDrOyLuLu
patyZjg/7KFRjIcAUjDjd5L+8o6VxbAXAObXnvoOB5BwrdR9pDGp7/SgsrNMygCkRIovVRahsB6J+1JKgUl6AzuzIdWX8mhPRzE+tTzFMkOmvI61MQn0SQIGkH0SrHXb
AwmIsttxMMueWncVanTUNZP/amXiU/4u3Qg3mUYaJBqnbmScTclAQZRkFLB9/sIffaeFjqe+g9/94enelLoilTOBKPzwTbRYQPeU+WGgQk3CPWUoDReY1FM0ZX7RlcoZ
Kcen1lHiPclS1IO1aF1MpQQMIKdy2sfkpS/43pMLsnKDYXI1Y1bh9HLdsbZlwCsSM578dJo6rciFlZ9G5Th0C9qbiwwJoDJsKgEeeLGW23QJkNwujPQdYfid7AS8F1og
v/gFvwAq/hhNzk4PDLWcVt6Pj0yZL9qrfnKjZO5jsq5tmGMjAQPIsZmqKRwo+2OpxNWcKindUWIJMKvamvGurHS8FFaBE1KSUKQqc5SX8cnZ5LBi1tnkAlPm5/sOBOxj
gKQeciWCdg+Q9KDKkRwR6jKn00ZJYhlDtLyXGtOS40idKp84X7o98aFT+GnYKw9GAgaQg5GzPaWxBAQhZIYLkKspTJ3bagMsKMqcH49IPEOYa8XpVNSfb8xr+oY8Qqgc
tkFWjsQlDe/MBukPlTEoxh+YBOxVZkS1ndHe3D+lU50M6f1ZsIfPimcJ5+b7GEdcrgjsYZB0RZxPU8Fae5NAryRgANkrSVo/PZaAAs+r0nu2dt6wz6q/QT+4PuP9AmRd
IaMNemRd3AXYidun81hhB29qfXRicl6s967Z/k9jkFyAycqyU91MABIQHHJWQKfkcfwiyAwol5VPlBmyfKxJny/QkYrKxIp8/NtPfKgdW9LN29m9JoHOJGAA2Znc7K6+
S4CtmX32/vV7ylutq+8YZVZllVRXYR1IBZMdiAIYbPRnLpzLVooPC6qe3wCE6yzDnGQHYym1lWcF4iDLGiTOQXJA9QsX930+kh/Qyr0+P3G57k6Yr5ZDMujIxCmzfPKT
raFJoMcSMIDssUCtu15JQHavsCkrGv4xc/AE4xFPGB2YMBK1KZrhTBlcox4r4SeKQ5Z+lm775JbL73hGPTOGEcw1o2hIP+ecspDzE50vMav8kHyOxnTiRBSdPmtgEui5
BAwgey5S67A3EgCoClWutL3WZZIrb75ssmLq/tN3ViWqejLIAZOoj2WNUzykSMieeFfyLJcKJ5CL1VciXR1K1Mc6t6PeTEAXveTG443+fKXojo5ZFTqi/cuR1epedTEV
dmtXEjCA7Ep8dnP/JEAWlQWLVhZgT+iY57+OeHlId9S+nO3XOZmZ+INWJ5jkAg51gUb0w39BpqiKmfiggu0T1TAQsI97LU/Xo6WlpTvOJI6nV80Y50ez+JxWBas24IVS
lhPt6ubLTboBZK9mxPrpTAIGkJ3Jze7quwT+6LurygCpp0aZOqdoamvuOFoApER9cVevcNGXnaDO6aM867e+8ejr5vvsgJrkssGXRzcWzKV9n4nmD+A88YFvZI6s6fOl
lgUoVUbWlPCS5mO0O0wCcQkYQMZlZC2GIoFCOF06s4py2S7Sm3vojHy8uYIRfRgAmIFMJVLnF19TVOOeELz9m1Y5stI/FHdU12eOyLUrr5zyZQDZv2mynqMSMICMisga
DEcCfhBkeryjqyzodJG7nto1+nYs5alxgR+VElfynULum97ODegLJGMWFasMzwyf3AGRKwerFF1fXjl16NiN9t9byVhv0ykBA8jpnPcxeOs2QEZqdHg6x6zzyvGZOmVh
HQtHD/RCHFPlH6uYfUXro5DxR2mZ5TLFtJSuWVY3E6dZMS30r7BOnqhHq9QJf+fpjXTWQIiOryM6rxzqR9bR5lQD7aCkV+KLWzOTQFgCBpC2QkZUAgJIDS7FB1IWr7Iu
oli6fpgPOxAcqOPATL+UkRuNTSGSUuOUKrbQzLkRCU1dnzQWnqV7EikjK50EEgIIuRlMYtIAJXlAdw9bi735qgVI7NCJHsgdTIfdYhIwgLQ1MH4SaFWCXDWjoYf3WfIG
lJlVd0s3webKuOZUNKVh60CaDs+kojk8c6phGJ8KTxSBGbgFphRQSYmSlILooy+Sd+9LP/77SstMYVyjWZAK8Y6B+TWA7GC92S29koBpkL2SpPXTSwloh+W/KRECbK9U
86izY3UGkOhMaGOK65AOBzzIBAjwlKnOwMvTOKyiATkCqqi7JoCtgBMfpXxXW19RLvv+FAbJG9GVg0C8ZEnxWqh4hQR+91uPOQQtFMmqe+soQAa8cgpgSbSPaZC9/LSs
ryYSMIBsIi1rOygJaId9ZGNFnrnCBkpMZM7BvlynhTQFSPnLyOpWScxKPwPP0LTC8lDagQKeZfWf26EjPs7xezg7jyvH6KozLl6+ifAPMs8plSvJ8PgvUSLOXqiAkMps
saph4pLKkmA2EILJI1wnql4SpqwDAFkZ71g3d4gXUX/yu6sGte7sOSaBeRIwgLQFMYoSiKogbKl+uauAotkIIJVHtKDJSUUrUIsu21wAKlA9XWg/zRyeucw4AA8Ix99T
KhJL4dNsMRi0vboU52RU91MKVDq+Or8bHk12Hj9ZT+XvwKcypAu0wspuYPrUQwoxICj9w++uIiJ2FNeojWkKJGAAOQWTPIavmAKQjlkN77bpACn+0NGJ/PJnP1xD3Udg
DDSSfgaWuIB9qXR1BCAQ4qNUpurVlOzg7/yrXyGkDD9S+FwanZTk5i4pnbhWH8iVME/rQhmCUi4w8uH1uwTPhQ4LS6xu+sSspqDj/tksYdDeIy9jg7SKV2P4BU/IkA0g
J2QiJ+w1ogApr5xA/FxTJx0/eRtYQtY3cLESNkj5RpWPcMUrJSJXG/6bgmeuxqRGUvAGAs/E6PJ3MDsFz2Q+rNT5AEXRsMg5WvzSf5arQ8l4AoEf5emTOpgyXy7/zsbd
WQlJc9KZsE97vF7HAHK85mtaRgtE+YkCyjYqttpsf6/KvVL4owtaD8tOoRG0EeUYMMgJMMI1kxV6od4AlUQ8o6X0PFcJS2OWxqbfUWoTe6MZ4Cd9V4SwehB46/emtZrp
UPVD5MRUJ9ICQDqf1ZT5Up8E9ohCN4Cclm9+JN/TAHIkp8UG9eqrdQCJ7gg6ksMshamjmQAyHJ6hOD9JPbGqBn2iyTk884lWobueqKRr6Zd8YYRhjhR1eKm/N7oAe70X
LyiNFvRyo23UlRrLEuljdnm1+gAJOsKsAniJ8yV0dFBqAGmbwRAlYAA5ROHbo0MSqAHIWd2TsNu2Wt6dkGrOpxyjuqMPKuhzDEZFOZwXj69dpZCrfoeArl7Q5zD53elt
HUCaoFrZefhFISsCORlWG114yWqETg0tz6IOJaQar8veUKlKqh8xq84Ji34qvXDt4zEJDEACBpADELI9ohMJlAAyS7bSjncM17rK/lVeHlv3H4+WTAI/HIHZlHJ0mqLj
VHmoUgHwC4pUOawwjEa0l5eQgzF+B7/1R1V+bnThAeQ61KiUpkDDS6d/3UPPbavaUYBkFhLjHTfubp1mmK8cHefml6dEw0M7WV52j0kgQQIGkAlCsibDkMBZV644f/Hq
tqoxq3jHRl4euveR5/ezyQZiFp1Lp6jRppd6VnCk5MQvDpOa9ubwwO/QQVG6x6n/3DJAdqNBnve1R/SaAYAUkHc2XwXl0gByGB+fPbMlAQNIWwojKoFCPUiN0mNWa5VI
OUzuPTqXOiC8yfoaVVOFj57FsirMvwCQ37gnSwPb9HLqnUNcZz5s5KHjnlsAyC5tkHpfX+0uLyBlkZ0/X7XVkjVfbWZ13rTev34Pb9EoT/qIrmYb1nhKwAByPOdtCkbN
Dnve17OiuzMHIepe6djLgx7etXBFIF2ZD5BNwYz2LnjfaVROgyQDQAcdlgHSddjU5YenA/kyjrrX9L1Y/2DRykYjxEAruAp7sUJZX/i3axPsxEfxosqOFyVmVXpklB6f
gu/AXnGYEjCAHKb07dkBCQgMysyqvP9TvDxcm48uesLBWPmJPQdI5w4DTVqXHKAOlmgvfxyVmtJonYETqGsUtshTnNePX2zS/Q7ONerQxUES41HHWkdDdNy86O2kO1ZO
6+IVW3gFl7rBvheTwIAlYAA5YIHb41IlIE9IhTqkVKVXv5WFsS65fV3Yo6Qbmxw8ajbCmQMOgx22dWbU1Cs7lOV3INN1Ts6dRjrfJbf9jB4KcSOM0KnUJBNI7PCXvtjK
pCN+tS7HnmI8KMMZjnpsz5eY8GrC/Kq7NwYmLnUlWTuTQKcSMIDsVHJ2X58lACqwOZKvPMXuKKaujY7F3TasiPjYlp6kRqAC5egUPhc478cInn/jqkT4UTNZ+PgBgfzY
TZcDj8elB6L4kZpOH6VzxaVo5Pz+L/8qHuyRnos1pVpyeL4csv7ZLU//2qWtDAl9Xm7WvUmgQgIGkLYsRlQCUkTAtjpFJCflZvnvfC+PCvZVvh5hSlBohL7VCM+II5T4
QEffl8QFVjYN7dcw/Fyp6h992ul8iakMXOpUKXwFolIJWvU4/ks+gQAbTFfk3tNIotU85MIaUB81X8/WU+VOp1yw6IkLvtfyDR7RZWrDmmgJGEBO9PSO+cuxz0KypTF1
c7lXKtu/+ZIHA6nRnJGvUaZTkrLe9tgWAYxjgyVy4MfVhCLZW4rORxulhfPVOzeB/NElw+OPYCSEZxjLXVJ1kLUy1l6luBxTShs0zoJJkoS0ZAZw4JpSD5JxYvQN24kr
mfD5t2Q0AC/oK75jvpxt+OMnAQPI8Zuz6RkxoZBkGgtokK2aD15ER13j//z9NS4bQFmAfq2MRDzz/VeB3vI+Diy5P9JnVDF1eMZdlT63Ym6dnkphDVxmyi42AC1mRZfW
p4CChXdXoWZfueR3ZbbDtsqzfJpXlZ8LZb8KHeqsQAWVyolwNTo21Bgdne64Zd9xdWVZAqbnex/BNzWAHMFJsSG1JADw/MYVD5W3Wr8SZFi/1L/C6ckwFtjcgQSnYoJV
daU8nOnR6V7lYlIavXQ+h5E8GlWsrEryF/7u41mgHLGA3OeKeTpIxmC4sHcSWOK6cuWaw8WN6Y0+GWcgXa3MtIXKz5XLVAU1Cc8ozAtTpvaJ80XLtVuyDA/mwmrbwRAl
YAA5ROHboyMS8FN6FjZWODpupl5gYMN1kQO03LzrcMAMKTwDAByesS//68uWV4ZAkF4VHNLQpdXJ26X8o3+lTwdR/AVW9pLbnuZZ/JffC3gWVdGUkcBFRtZJUOnXaRZG
R90ONMpwyKiQOe+ui07gXenHVVeOLlkOGbDZ5UlpPejoy4EoHT/8g8hXFfJMGX90VNbAJNCZBAwgO5Ob3TUICdQFDLTQMYFZ3Z6XjWS3paYE6QIC0ZAO7XyyFOTDOQUN
jwSkXKhoKJduy5buGM7zQmNQKgowjfCMPsV28jrof07HAuf4vQ7S+FcGrKBPLn4vqIx0K0RUHhwu0I6WYU61sA4Y1QVzCQJbDlPyWfVzG1UdazKjoz9fsOtw7INYZ/YM
k0CNBAwgbWmMrgQqQ8413LCXh9SUVpHen7+i7fjPbnkqqpFIj3TJwetEI5UroDsWbhT+cQE/IJMrO8XvTVU017PwTCZGZ+CUP46v0QpNeTSj5V8dQPI7f5HjT6+0NEXm
FByPNeC6VAA+Uhbm67SgX9Xorlob2QRJwABygiZzEl8FfxPfT0deHgk+kEe37MuMXoeO/9wFoRO6HmZZnfxklpN+5utPAAkYIDayYLQr6GdS0QrAIziUQkkPokALeNbb
OZTTqauWVe5cKdEZSR1L3Gg8koyqXOlq1VTZpxodoUusQD5fWbNwZE6jUVljk0DHEjCA7Fh0duMgJKCEc9o0nS4StTvWRdpFWdaCfgbHKDDzVTRQ0ycnFbNIA18/ExDy
R3oYlptJ2UM10+Ta9kV/8sQVd1l2UdEpPr+aMl+aysN5qRZXCZK/XHt/lsa2Ebs7iOVoz5gyCRhATtmEj9vrirXDK1IDD9uxfK8c7I5lHFXOuYC7ZiPxsH07+2IlS+mM
hYnOMo2eHm5ciO4AxUkFwLu/6ZIHCA7hv/xOpnJnQEUmvo9SByOR/6rjV1vzFfSi8r1yjv/8Fd9/h0pnp1sOnQ6mwW7pqQQMIHsqTuus1xKQGfIb92b5TmNeHllKT+fl
8cK+ipzmqg3ZparUUozyiItClJ7Tz3ytUeEWUffUHkrOT3YD8v27rz5MToPKQEzcdCGxhe5SATuuLcUhwPmvpnnlzM2XY1YdZJoBsofrwbrqWAIGkB2Lzm4ckAR+/9rc
ayZixMp8IAteHpW3/MENTwQSbSe+ktxrHZagSqpS4y+3k5qSgo6sNOS7cdpqSg6axKeHmym+XuQk/yUopRIa/T8S0CKM9BMmNBoMD6JDFHTHhKeEc3jzNS99rqpcdQzV
jUZujU0CAQkYQNryGHUJKBoS5a8OI6PMqn+jEpd3s/kqtanr4eql68NZBZSOjh95k/bKZbRu2tBWFanCg85c+FAUHdUAAlYdutsbLQu55zBHusvT9WvrWgtKA0x4vwXV
6AWt8XRKwAByOud9nN5a2gleGwElcj6zGtqUN+w6qoiLjkWA340jaVPyhpM0lWZ6XF1a1I4HU7hRjLTUVgaZXo2ShD7KfiD4bzQe6ayfv+Xp+Zn/QrNQYsLnNSZ90oev
fbzRGKyxSaAfEjCA7IdUrc8eS+A9V6447+uPBgCS5+HlEaNhM4fJV17JamV0rEQqOY6UGxAlJQs5z/ILa/TQS6gsZV7NJcxrWrrLFUP2SyunTGSrfMfMARq3tfk6dGz9
PTBfFuCRInNrMxgJGEAORs72lK4koGCPSpZVdqwE/50MHU++kg2DX4j36EyJBAykPqI2pZj3HMOJVVKwSg91hbe6klF+M2OT3xDWxFMSrI8+AUt7WS5dJynjkfqo7Ope
fGqt+ujmq85I2VtP45RXsDYmgToJGEDa2hgDCdSxrH5msrD6SN6AVtD6foLWZzu2RDpnVGF2+gXbqXodBK6EM951Mx8uRyvabfrYXEsht6+GRgfj1Mc9cxEdteiYMl/G
r0Zlbg0GJgEDyIGJ2h7UlQQwSpUre9BjIrMqdPRD0d91xUNN3Vl9+1y6/4uDn//07ScYg8yEXcmi/mYHkMKtppfTPivrbZUfq4MLz/IFW3VSiTOrumvp2s7Z7z6J1Lqd
ZgkYQE7z7I/Tu6telaujRPJxRl/pA1neoMWsFjZxZZ5rVG4Q3tIhR1Psob0z8sHu9ilHjANIamB1MMKmAKlsQc++eLgt8wizGp2vlHy547RqbaxjLgEDyDGfwKkZvhQv
NlD2YtCRUHTV6EhkVrdlzGoxFyiF7+kzHau6BEinOEaLVXU8q3joKP5EjkiNLkhgZWRVweToGPSIRfc/H/ONInvDCZ1mAvOFSXL1tqwk2cI710UfbQ1MAoORgAHkYORs
T+mBBK74SZYojlzYnu4YiiVg4y4zq/5ursQ6iXQiD+0VQEarhYiJ5XGB6lSVAqW98yEKR2dWYme6G5HS7lCOas3MEUQaTgvAUB0THmip/KvDSl3bgwVqXUycBAwgJ25K
J/eFlL8GDMBnNUV3JKIDRXPDrtnApqyqvIlupQzA+b7ildpIP6MxdSU1OWEbJJqZKlgpaFIY6apT8Xsggl7llPUUHtdohFS71I0pWfFQVX3Gu8bu2NIddx9+KaBlanZo
w8hdvoLJXcX2ZuMkAQPIcZotGytp59hDY5zeXKEl0DHaGDRKgQSHbcInYv8bwQ+NybnDjT6GFSZUAByorqzqVIw2gOiudhW9JYZp6kVENQuewytNGeQvuGlNVLaJuuPG
3bPdBKfad2ES6JMEDCD7JFjrti8SKJSMqHOYdPGOrhhk3VZO6J5cMaOooPdxRj7ghxQ5jTDSJbiptPCpCGUB+RibEqD70hSO1pkJfYQDklMwkhdRPjywPwDPGoNcefEB
9us+OvGiDvrVqtteOZFjCro+wP9rVr6jLx+Nddq5BAwgO5ed3TkUCWD3Ksd7uA26EO8YVnFAR7ZmyD1ZvxI9UxyHKSI08br8jmeEQKBL2cwmdHTuQjQgJoSeIXJddSpU
Z0VSqp9AdSr+yXnnRpPhgaDfzIul8IMEohZZvbVzJ66UcEq8o84umq81L2TG4EYexUNZe/bQaZOAAeS0zfjYv29YiQx75fi7ObiILMBIaTxU+mWPTkli7nQsUCrREgm2
iZiVNbEwB6pXLHSkGbbAOt2UqlXUrnItfSD0+1Q+PPcuD6/fBcpS2aqA5fyFvzu0Vr2RcLFMhVdiuA2fPBhMLD61pVNqvnAn/tVLWwn8xn6B2gtMkAQMICdoMqfmVaqU
yGzDFbP6bJvli27itHdtIAzff03m1RKN+hCeCUho/K/+ZnlAiUQ/c+goLrfQv3RKxVfwu8oahy9S3LlqVnUDFkb6hC2PQIul+uO5Vz/Mf/ldD9UPyB01xOpowkkiIFhl
kgvHOzqfKc3Xsp/tMvVxar7dMXtRA8gxmzAbLhIoK5EwdZClGWJVxTsWNnRpLUdO/LxgoSRNNiV/o1oU9+Jcivbm6gxj6itDGtAIkrm6HwWtzkcmp1Omc7Zofk4lddnJ
C2tD3kB0HoZ8xa7w6Ggz3pEzRKXpURJ2zOqGnD4NXFv2Hdd8EZ+6YNFKrI9W3Mo+7RGUgAHkCE6KDSkuAep7yBIpdUS7bb4jJ0VG+rqjv4+rVK8Dv8A4IBv9hDjs78D2
Jbc9zb1c/ML/uk1fhYgrbZx0IpIT+2KZBQ2okvKJ9etblUfLv0o1BAIZjw+B/I5+KQ/eqPFP6M7poaYq51y16ljOuRZqar6YuyUrt5v6GF/u1mJIEjCAHJLg7bHdSUBK
pIxhSjsHsxqNOqABLUHHHFaroVR5zFMwUpWcw4GJMLHgom8R9N/bD/lIIVd9vEQ9FQCjQYbjOAXeNAOMXQ/8Lo/cqOomdMRGiIYdkDAjgVmNlbvKAFLzxX9pzCkHwjw6
hu4Wi91tEuhQAgaQHQrObhu6BM6/8cnTLnnw6PEMJHJmNaI7yiunzayGGn//4a2JGAl4KDARFPRVNJRCYZKcY+s8X1xSNxo0TXwDhSsjIuhYx7J2P0dCR96iBh0zMZaq
H1eSq1lLqlU7ZpX/VZaGFMeo7l/EejAJdCABA8gOhGa3jIQElFgH+EnRHfFWle4YwFFpPwSt01IaaooeSWPgDZQCKZ2Kxo1S7MJOocqSQw96l6YXGcl1bzQ2o7MJc+iI
Vl2nO8orB5/VcLY5nwnPsyDNwtZyvuGU09nY7C6TwAAkYAA5ACHbI/olAUUdhGPytLN7RsqQ8wgt5cLDJp7OtXb8egCbyw/eFB11OOgfQHrouDXKrLYbhPRyx6zKVHx+
HldjmVc7Xjx24wAkYAA5ACHbI/olAWxXOEBix6pzrYTTk+5Y9lmdv+lnOzscLOh47KWTKJH6V4eR0diPzt7QmQ87KL7RV4CUV1HY7gjgnXj5JHlxX9gXsv6iO/o+qxKs
ao05F9/OpGd3mQT6LQEDyH5L2PrvrwR8b52youMxqxHF8bndmecIPw4dfYysTH/T/Yv5FOspFzfOfr54+aZ+aJASKT6rKV45klKYX5X6LmaVxpxmONNYaEf368d66LcE
DCD7LWHrv+8SuCAv21vezVEHlUku5t06CyjSkvYFdNSNio/MuNxVM719GaCo4wrMAKr0WlfiqidjE2tNvGNlRIeA0HnlBAULFlJHJSO3Ucr9lqqK7Kcp6MnIrROTQM8l
YADZc5Fah4OWAI4wZaJVuqPQMajfzCqfC+gY2O5Bi/8rz7MDKdrDmARGTp/q8M9+uKaRGZIMPhI0DkE9ARsGo0wF5MoJZANwXjkyJYYPH2XTr8hVMsQOepXY80wCzSVg
ANlcZnbH6ElABZhQTdx+zdYc9lnV5l7HrPr7vvCVeveX5xWbXWh/T8SABinFVGCZeJGsVaAoY2H3I1EiVp5O3vZKzFPkKP/lWYmZ5OZ75WS6OLiL5ypJHnp4yOj+3a0H
k0CdBAwgbW1MiASuyNELtxrFOx49cTJsGGO/hlCF/atjVgs4gZsP3d6xakZ0azT7TKJYhXACDJLppFSnoo3TwMDXLkfCoxWvSQWrnKauVQpLNTrqWs4+uyujrPnhFl+M
ZJUzz9XEhWHNRkECBpCjMAs2hh5IgI2eHNynX5qVxYjpjpk2o3jHMLPq8sIQ55epa7lJErqV6hM9VCXBJ5eFLoqRpKNz6IjqiTrbjTbmFMdLbl9X7wmcKdDzmdU6j6cW
ZHpeOXMtlRagSzjvwUKxLkwCyRIwgEwWlTUceQkAjW+59MGPXPf4mpkjMcecVmRkpVdOgV/dcyRT7zBq+n+HipQqCbyFswFExaaCHg450Cn/9WXLy3lZURyprqXKxvwI
2zqOP1F6Acb/7itXRANJhY5EdISlqvOEV616Dh1lesSdKioNa2ASGB0JGECOzlzYSHogAYUoEIQe2MrL8Y71jWfBxZOvvFJAR7VH5fr8LU/LahjOyBp9MUXl+9nM/epU
v/WNR3Hh8VOy6TU7S9Km9LDczhMX3b+p3h+npQ6KWY3GOyIQV1OFGh2+SGFuzfQYXQPWYAQlYAA5gpNiQ+pKAoSfZ0H0paK+6DdcKV45zvFVzCoaZABuUb/EuEoL7Jjw
lBMpVzi5DM3QWTvTHR00ZvK5c/3jmw9G9WwaIIFG1Y+Vhdz1DACf9/VHyTnQsbLb1Wqwm00CXUjAALIL4dmtoyoBRUZWZhCtNI+VcYItXoEi/ERRZMOuWVDt/BtXCSYD
2cmjAlN1KmAS+6KPKGCby37OCaApDDM8aY1cn/vhWnrj7aJOTCnVj51wKplV/hV07FjZjYrLGpgE+ioBA8i+itc6H44E5LDDvuxZ12bRHQuZ5ALI12ZW0R0joX6g4+xL
Jw8f/zkEo9MmebRKMHbw/pXVqVTTEdRsBI3qytVhhhB+9sXDuU4cTZ4wlw0gz4ATrn6cCZZutx84UWipnAA9T7DQgVTtFpNABxIwgOxAaHbLGEhAaVoxfWEAQ1VS7EeK
OggiqmUKioiDBR0LJjeAAVLRKZQ9CeRPF7qDWKmM71q4AsIZ51v18OKhIoyV8U+6Y0r1Y2Rblwhe6FhZJjr9XaylSWCIEjCAHKLw7dH9lQAUpcNIV6MjypeCH1EoFTmJ
7qiWlToWtjc4XrLSCKVczcguXV4DIuN9VRtST+RCZcR9VK/sMcYRnVgB/l714wr10dGzYlbLEiBuhAEQnNrfObbeTQL9lIABZD+la30PWwJgBpoc4LRxx6FYREcGG0LH
sFeO8MYxq1EGEqS8a/V2H7cIXkSvAswwDTaiTAviBGvpAbOl3HYEigSfoLqBi757qtAxQXfMhECNjgwdW9xyCE2VPGFbxqzOa6YqKBbUMezlb8/vVgIGkN1K0O4fcQko
OPJNsdoUctfM0TFun4N7pGWBWa3TTQ8ez1BE/4qRErbzD27IvF7dJfsiIKfiHlgNgb3yBaCqAY0VwuguQBFVldDMyvob7feq9cV16qCLd4z67/AudV45Qsffv+7xbrB/
xBeVDW9KJGAAOSUTPdWvKT1S9sgqGMu0H9AuUXckyE/oiFdOkLCd3bRn9vjLJ2lc2ZLBoOeBl0Rt/ocbnoAN9jEv8PuZC1dc8L0n//pHP/vmsudA3MqyG25gR3Mlr436
WYWNOgm4THLB+o5ZOlZeR5R1Id6RnsWsGjpO9fc2QS9vADlBk2mvUi+BMEb6meTCRspn82zdTiMMNxY6okFGDZ+iQAVjACewV74EhDIQ0nO0T6cTt31tIqbHrNufv9Im
kEPY7xl05/UprxyYVdMd7VucDAkYQE7GPNpbxCXgfHYK8ZFRBtJBUcfMan2sSAtgUkBXtKc03XR09OypFQCpPpPjHbMe6rxyhI7mlRNfiNZifCRgADk+c2Uj7VoCYKTi
I9sYOdtmVuN2x115oAjtY84+RzflSh4/MQ5WzqUZV3noWCTNqXRHng5lmoKOYlbbXjl1zGo2gJ2HsvdK8crZsu+4IjpgVsu5ciyio+vlaR2MnAQMIEduSmxAfZUA7B8W
MnZzNJ4UvU1oJN0RTSsFnFy39a4uLWVOzGqUg6WfzXszw2e67hgO0sjfIhtDWrxj1rIu3hFCWLlyLBtAX9etdT4UCRhADkXs9tBhSgCMVPFIUsxs2zcvrXYl/qlKsHxW
w+6d/KvvsxpFUw/zIgZCabpRKM1V0jlzZtiHSEbKcPVjB6WVzCpORrg+4QDVWc6gYS4Ce7ZJIEECBpAJQrImkygBNB4wst61VdHxs4QDzp7IfG3IVOfQohJ4wj6r7Vuc
7tiMWU2AsblsAHuD2dWlO5IWzkPHEDxv2NUqDVbwWVV9x/dcucKykE/i92HvlEnAANLWwfRKgFhDBVeUS38Iz+Sz2o53jCh58lkNg6gU0ERmVXbHZGa1QYa8xOrHGm05
kxz+tAsWrTSH1en9cqbmzQ0gp2aq7UWrJEAyGpX+YMcvBBS6THIpqQPErLYp0HhARRtKQ0nAnc9qOrNKt4B6CrXrqaSh0Qqh/WxBolWRmKvwbCvLJDCpEjCAnNSZtfdq
IAH2etGtLnMp/p8wq+iOOTZEAA8fVB6Gk2cAmXzdsaHPauTpDM+r6hxuPMvrkEmO6sexDHmz5erH5K4jp4HRqg0WljUdcwkYQI75BNrweyQBDGmY09j9wQAqCXvMakTJ
87xyIkimiI4U3bEJszqXIS+aH64Q7xhuXyic6RTHDqpR9miKrBuTwKAlYAA5aInb80ZWAni3svuDkW/98oO48IBSQEgYRfQuYQ7W9UDLFLLUMatRptSZM/MMOHXwnCWH
882ZUMdRKPXzrMI8O8URq+3ITp8NzCTQcwkYQPZcpNbheEsAVfL3rs0CJQnv8+otV+iR+/J8pDELZYZbsK+0zJnVeKkpZQOYORCPP0mO6MicfegTZjWhoMfRVo2O/Qxg
9sq7N8riaIrjeC9rG31HEjCA7EhsdtOkSwANUg6uKE+V2cA7jXcMEbaOWU1BR81ALKKj9ThaJtZ3dF45JBv6jSsekquqBXJM+nq396uWgAGkrQyTQLUEHOOqtDttmMy8
VwI1OjxeNEvwJiUPXTNFd8R9JtdHo145R1EHATxPea3lV5VJLsErJ1NzZXe875ndSo5z1pUrLAOAfR7TLAEDyGmefXv3uASIA1HaHQeTXrxjxH9H6MhP2JqYZ5LLoili
bO2cOkjjqB3RZZLDQpnSGHTExEjhLd4U7dmiOOKLw1pMugQMICd9hu39eiEBkEPhkkrJHS7B6FRAngwTGwUnGqTX6BDoJpgSZ1314xRnnwd/tvOcqx920Gj1qnqxaqyP
sZeAAeTYT6G9wMAkgDa58M6WNkliARc0WUagDmp0pNgd2/GOgdIfLa7VMasvBKMzQfprfvqcoJEoF7RGg8aBLSd70OhLwABy9OfIRjhaEgAmcek8PXfhwY3lktvXOfOk
kLIps8rrpaCjpNCu71htdPRDSlz140oN8u+e2KHgDa7fv/ZxszWO1iKz0YyGBAwgR2MebBTjJgE0LUDlw3lAiGJCrr1/E0ip0h99inek50LS8zL4yZyJV04ltUt1KhBd
kRtU4YAuNg/VcVt6Nt7BScAAcnCytidNpASkUCoLj0po3froFnAobPlz1Y9TdMd2vCOYJ8Wx1s1V8Y44uBYyycEG44irsA2uL936FOhubOpELkh7qR5KwACyh8K0rqZa
AqhiIOV7r2ohJWgEJhFNWPbo8TLJxSM6JFPPK6c2osN55Uh3JMsBSq3KbjhcJL4TRJ/qebKXNwkkS8AAMllU1tAkkCYBkBIccl6vMlVi8KOoFqBFyu+mPquOWQ04xAK6
PHfV83uuu+85HxSJZYRH5e+mL6bNnrUyCcxJwADSVoNJoI8SID4E11AoTeXl0UWuVzAM/RLIRMUENStz2nkRHfO0RiBWt6AgkgqOrt5/TRbX767f/dZjgCIkqimLfZxa
63oKJGAAOQWTbK84GhIAroSXoNcnb1zlQ6YPb3jQgHmfWfwk1ye+s4rfuZTapvLC/PnpxU/C7qK2WjLx0ZhqG8WESMAAckIm0l5jTCUApHGh7QGcuoBPoWPhcg34RXeZ
gjimk27DHhcJGECOy0zZOE0CJgGTgElgoBIwgByouO1hJgGTgEnAJDAuEjCAHJeZsnGaBEwCJgGTwEAlYAA5UHHbw0wCJgGTgElgXCTw/weF7q2ZdctnKgAAAABJRU5E
rkJggg==
              </image>

                </content>
              </block>
              <block>
                <ID>0190</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Fibre optic cables sharing a common conduit</title>
                <content>
                  <para>
                    If a fibre optic cable contains subunits, as shown below, each subunit must only carry a single group; however, each subunit in the cable can carry a different group.
                  </para>
              <image>
iVBORw0KGgoAAAANSUhEUgAAAacAAAEjCAIAAAAZrFkBAAAABGdBTUEAALGPC/xhBQAAmGNJREFUeF7tvXvYXUWd5ztzpuecf+ePc5nzPNPDdOvpaWhxtBXH7pmxu0dE
QAUeZ7w3rY2goGMrjXZrg9CtREEQJAn3S8I1CIREQAISOuRC7vcQyI0kEJIQQggh5IWIwfNZ67t2vbWralXV3u9+72s/68nzZu9atapqVX3r+7vWv/ztb3/7L5pPMwLN
CDQjMH5GANRrPs0INCPQjMD4GYF/MX662vS0GYFmBJoRKKTbZhSaEWhGoBmBcTUCDeqNq9fddLYZgWYEGq7XzIFmBJoRGGcj0HC9cfbCm+42IzDuR6BBvXE/BZoBaEZg
nI1Ag3rj7IU33W1GYNyPQIN6434KNAPQjMA4G4EG9cbZC2+624zAuB+BBvXG/RRoBqAZgXE2Ag3qjZQXvnHnq+Za8Mye6Yufi1yrtr5slx8pfWja0YzAaBiBBvWG7i3t
e+1NoEqINumRjd+etvpv71r9L/5pTg+vv7lj1XnTVt/6xLM8ggfxuL7Dbw1dD5snNSMwGkagQb3BektgHIwM9Jkw86nTb1rmQNv7L5v/nWmrv377qkt/uXHSY1smPbZ5
5oqdj657UdfcjS9v3HNI156Dv+47fOTgm7/Zvu/NjXv69KUpyR/TFj3P7Vzfv/8pKqRaH0a/eecqcJbGNDjY/r4PbJo98ayj/8M7jjrm5PPvXLH7cPHrkQ1TTznm2PPn
HOjJ1OhtbT1p0rivpEG9nk0BWJVg7tw7V//xT+Yb6Dn20vlnTl1x6UMbACYh2ltH3uapuw/82kBb3R+bX3qDkkDeppfe4DKoFyxPAXXGRkahIQ2gGaZJNO+HM54a9yB4
eOeMbx17FJBXXceePWPnkZ6g3pEDcy489ugL5xw40mMM7dlsHdcVNag3oNcPoUOQhEZ9YvIigymfum4pQHPz3G1g3JoXXrMQqmBqb/6mgDx9WQJZxen8P/hV+AjLi5fk
3gNv/oaSb751JFLhkq37aRI4eO60Nadevdg0+Is3LUMoBrLHlzhcsrB3nHjxnILiHd495+KTj/rQBXP29gKnGtQb0LIa7Jsb1OtmhAEIYOJjk/qR7hu3r5pcUrl2mGtD
tO37KhTb9Sqyai3YlT/1vfja4X2H3jr81hHuKileJduGbiwKC/K2FYXjNR96+fVfU/i1N96iqTNX7IKEwgQNAn7p5uV0DUG4m3EZYfdsrPns2LGjbOneOed/qF+SPTDn
gqOPOW3KhiOVTHrP41d8sqCBFSwWou/BTb+68ssfLMXhGZsOQgtLgXj3won68sLbp/49Fc7eAdETf4Tu7X+6lJf92kbYYI2n5jSol/u2ResQDA1AnDl15X2LCk3Z/r63
klhDgXzBdtNLfWpWCXlBFGsDQUrC9XLaIMgzZNO+BcUiCAhRVQff+5P5cFi6POoIYF9f36233vqv//f/o+76zt/9XQuwZl90ytkTl+6uAKz6ttTrnXjSCUbylY7v4NIr
TzymJQ4fc/IVSw+6XxZIF0Y9v7bcedeU6/0INKiXGFPA7tFVO2FAwgK0Y9+/fz0AAVHae7AWQXwAsgXbJDxZ+NgXl213vvqmWF6yThXIwUcE4bsX7zj/3nXHXVapAsH6
0QJ/QN6ZZ54ZgTx+MqhXvvsDm+Y8cP8VF140ZcacTaUBw5Z8jzw38+wPFpTtwFulqu5bM3dCq40AW3551CkXzUEfeOTghtsxjJTk0ZVwK8LYX1sbzPZ+WTc1RkegQb3w
8EBwWOfYJQR2H75qITzINq0CeW+//Vuo05a9EdlTNK3vtVLpliHYHmoXbBMsD8g7dPhIIdi+nGxDv2CrJsVRkn4defvtl19/C3xHR2ksIcAf0v1IXlMgmiDv1FNPe/TR
R4MybiXhHtm94oEZD66oiN6R3bMvOvGzV67Y367Xe2PTlC+UqHeo+MMyfbzjqC9M3bS/9WuJYv3m2jq9nqmtQb3hnEQN6rmjj8R61awNdWAnsChtDL/NEGz7zRdJiy2c
ThZbPgi2SfOFiFsmy4sItj78qQ1AXuunohc2/En43fHy68M5c0PPnjRpsiAPugfpSzTP8Skx/237vkG9kfaSe9CeBvWqQYTc4clhDBQQHNZ5kBDZgm0SmyTYAjo5Eqgt
2MbLS7Dls/PA4ZyaKdmR4o9mq1q/g7gHYgLWrnDGzctHjuRrIO+44z6Qhrxi8IRoZ0/dgGBryadh1LMl3P0rMHScMmXTkZLTHfXJgiFSxc4Z59RIuC2bScP1eoBZA6+i
Qb3fwllgLlrG6PJZ1SE7bCUSZgu2RXkJtjlS8HOvvNmy2Pa7ItfBmRFscyDv+VcK/ojFNgccjWBrs7zgjej+7lqwTe4vUD/MvihABz4du67BhryWiTZdmXDKklt9zxUL
p9qsGWVJPu1fnnzie4N6vQb10i9jCEuMa9SzNXeQO/xOogbTvmzBtmBJYnktwTamR4NPAXkUrrfYGgVfUQ8lMwVbFeaTVORRQCVzaKlxh96y9w0YsXF8Qes3LC4vCxYs
kGALy8uHvLK7OKPMuECW2aPPvHL2psIsG+Z6hftyy3Plg2dNeaoo2VYDX86eWbnCNHq9IcSwzh81TlEPvPt46VeMmRLOAnOpp0ICrL7XDxfEraXLi6HYc6/YfnlxV7tC
hESwbfnlJewM/X55HZsvEk58h8reEf2WpIQij3x27O+npQwg24b4MiagocS+AUBe58uluWNMjMC4Qz3w7uTSu/ikSYv4+/U3Y6JfS6tV8aAkIqiA1HM5hUEZzaIyxjYB
eYq+6Eg9l1NYxI02pxpcAb0aHCyMZoDADxl88fVheAd7jRjIg+jx92A/rql/bIzAOEI9g3fHX7UQ5R1+J5nYJPNFhsXWF2xj0WZGsEUKNvBaBz3Cps4F20TQG4+TeZd/
k5YZIy8j2EYg0sa+UyYvGjzeh1eK8ctrIG9s4NHQ9GJcoB54J+Msbnfg3d7XCyUaMl1Kqi3IlwoDfEkq1EnAWeGXZwm2Ce+57gLOUg0uEFmQR/2pwn3Pv1IZK0rBNiEv
M2iH3nxr2pPbxfsGQ+ZFf4cWT6jXQN7QgMWYecoYRz2IhsIqhHdmnSODJpeuoTZAXg4PyhRsqUooVgq2hV9ePJlKR4ItZNBIwck2qw0ZkFcFdeRS43KfKAv32byPxH+9
svPakDd9+vQxsxqbjgzNCIxZ1GOBKWYWuoGyyWBcXLC1AaiLgLMcV2Sj+IsW7md/3Qm2SUy3/JbTcR2ai3HB1hlhuzDYR2SLbB34uAwwsNeGPBxWhmadNE8ZSyMwBlFP
/sZaYyy20vmuWNhCsahg229PUOEMwbbgQR0FnEmw5a4kF6PZFM4MOBPLe6XIg5BEsb5swbboncy7mYItm0rfrxUU7DYDO6/cm8nuR2hzd6vIDrNtIK+7MWzuGmuoR5So
VHg4kRl/FPBF6zwq2LbRq0zIo+bMtAK2YJuhT8zKl2fAxRZskyxPkz7HScXI+Mk6zaaSlIJxilRaF+I6Oo1payCvAayejMDYQT0j0qLCaw8mK9KWdGqxTa5eIY4gj1zH
SVwwKUIti23MJqC3SxhGsmZhU46TilFrlr0rUD7ON9UGPKhTbSiq0giXgm2CbD679w24Hjn0OxJ4bcjLCrPtyfpoKhmLIzBGUI9VRFyUJdL2BzPIqzYl2Fbl2wXbxOqV
YNuCvLTfsgTboPTXDiuVYJsDeTKMlIJtViYVClvmi1ibJdjm2Dow71qCbcq8W+aqwQ1o+fZXJfDCzXO8W0wylQbyxiIQDWmfRj3qQfEwDiqE1s4EZYhMi4PUrvCWFTU/
k0qxsJUfpUXcUgFnpVkznknF0C69/xS9qsAlv3BF3PozqaSZZssiUde76nsgjMrJhJpsMyNASd6IKQkrl3cLodARK0dnyVSGdAU1Dxt9IzC6Uc9QPNtKa1aUMgW8USnX
I4u8WK6vHy6sAZmuyHJS2fOanPhiqx1wbPnlFfFbUYmy3yeuw3x5abghDV+7rFoLZO0BZ3Hi1kduQbG8HMjbV6pWGeHN7fiIuSlO+jpPpjL61mHT4qEcgdGKevACOaZ4
FK9SV8m7OE6aTESE0gokqYoK5Cc6tgPOMiy2HavnMnV5GodUA6pxSw6avam0ak7DrkY4kl7BkD5cW+wF0F0ylaFcQs2zRt0IjErUQw2koxdxTKmDKgm2GVlMKo+WTJaH
0Ee1mX55yqQSL2zk6zxs6liwlfE6wyLR74qc8strE2wzzRc5PNqQPmPebTILjDpAGRUNHn2oJ188lEF1iaFkkcgQbMuAs5ZyPYfotQu2MenPEmwVsupnXmnjR5JAOxRs
E3YDY7Hdl6HLyxNsqza3C7YJoqfCbCqbXkrIyxSgmLQWXNfe+WC3+aNGxdJrGjlsIzCaUA+pVoYLfPHqEn925JcnsSsno1y7YJuAGyvgrPA7ievy5HeCw11KAu0Pm+1I
sM3s3eAIth1kJFyyYYesItBzrFL//e9ubDILDBsqjPUHjxrUw6NVUm3QcGGYWhd+eRnH/TgpQhOoZwm2MR4EcD+6bg/SOux16tyt5KcDzc++bSWXAkvi1+duWEpJbsEU
wJhwoRozB/KagLOWnSHSkiqPVkqwrXotbKJwEqYZWC0fHPTiVHrNcy9/9Rt/S0m5kT+6cK2BvJO/d3OvonfH+lpu+pc7AqMD9UiaEpdqESGVFCSVSaVa/NmCbVFefnkt
i23MFgzE1GVSKTHuRbCJgyW/emsA18hv+p1pq3Wh0QcK45cprDTuzsWvF9y3btJjW4DCaM7UzICzYhyMYIv8nlIIVOZdIDK1qfRh0p3+wMPA3M69B3iPc1dvOva97xfq
/dP19yuCLcehL3fKN+XG/QiMAtTToRbYauOr1zCF1IKs/PIk+iUJS2bAGVU5mVQKzlLC3HnT1vyn0iVNl9BNuEb8HOs54qcGw6WAfwVjuVSMaqmcR5jTbHkoDThr6koa
Y8igRilTsGWUTC4GkD05aB2l2gcZOcURjJt0y13zVm95dwvy+C8tRNqVQ1/Xobvjfo03A+COwIhGPeDgjFuKPFFIfyFFXn+cQ77riVm9KQ5SVN5RwJkE2yc3vgy4fMVi
c3CxCTOfAoziAEdnKXDn/G3fu2fd/ywjVbn+/YS5H75q0Z/9rP86767V37h9lTmg9tRrlvzNHau5K1i56gQv2DlsSvjZ65di/tbJti3zbsIoYQTb5KZiBNucEUaLt2rV
KjG7P3zXu7n094U/vsI8iFev0F160azgZgQGPgIjF/WgM1+6eVlSkWeyXWKFrF+QWtIdWWyro7tzYmzX7jw4d/2LP7j/qfeUmsfC3nLLcggXsJLUSYFKEx/Z+NGJRcaE
D1z+5KnXLPvKbWt+sXznRTM3Xvrws8713Mt9Cza9Yr68+MHN37nn6S9PXf3pG5Z/bHIh51LPZQ89U3dQNyDITzSM5hnuCRW9eW7dySGF6RnTqlyRS8E2HWMri21cl6eM
XhyLzgz+xrfOM1o8H/L0Tnn0pQ8+Q5sxZw0wUdXA10xTw2gfgRGKerJdwGiUCjRyDYZg62VSCS91OAjN+/bda43oChlBBZlEOtpMBy+euf73fzT3jy6ZD2Z9c9pTQBhw
dtWvtvFrgWuztjqQx/c25Jlf1zz3WnXLw89SD7VRJzVfND12YpkQ0OaAn7l+qQ9/JnFDTvRFR4KtotNWb9npQJ6IHiZd89LN4ejXPb6Fof7iTcsa4BvtuDO87R+JqMdq
xF0LyHPiah3se/n1t6AV8bQCrSyh1Qln5ekQCQuslwg+AHmAHRRJYIfkKFqX8yJZro+t2fVnVz4JpgNP/zB9gw1tP31kq8EvB/LAu7qfgt9T8/n3PfXxSYs+ePmCmUuf
j8MEEEwXjAgM/OlQYNl8Og04S41wQR4lLxOjBsD5qKdvPvWFL1066UbQlgbAuKWHpWGyb3SapSrn7TRlxskIjDjUk7mWbFERyLOV63EmKL17MhzKrsQKOHPxkSahYZRp
AlsBRCl/7YE7t8zZAgX73A3L7lu8w5degbyFm1+5ZX7gJyDvuX19/i3Tl+0Osj9KFre8XNwC+0Mt+HsT5vL0JEVy4I8OIoDnsDwRt5xIGIZakMdLwWHFmGsd7Dv+pI/f
/dA/82jf3oJBhh2RfTF/8MfJYm66mTkCIwv1BHmoriO2C4VwZQi2LSeVMiA3w1m3KN9use1neVAMY6DANNHRmYdgDdYGcAf0kQeGj1/9gq2ny9OL9G/hm8j3zk+o/4R9
HP6bxD7ulfArMvuR8siR+jeSH9JXjKe9A0178HGf6IF3fK99qO5wdBl20aI2Hi2Z67wpZo/ACEK9DMir4hOSgq1RuktG60qwLZ6lw25OKE0NkDvssDk6O3t8gY/jLlsA
4oA7CzaHpVQJtg+u2uNDWyXYejq+CORFZGEwAovwO380Fyk7ZxmAj9h/JfnCcBkK33mILA8E/2UEnB3C3GQEWxmXjj/pEzbq2XgHywPyyEjY2q5cPYPxaOloB8rpdVNm
zI/ASEE945QX4RQsleQJPpYrWQfhUNTsCLbCO9lksXh2sbSADHxKfnfC3HPuWCuRc9vegJQqwTZI5eoEW9VWe0sp2PrX6ucO8CzJvJg7/vLGZfkIDnbjACjqh4xvsE+C
bTJxg16KCTgTj3t04RoDee14B5evBNs4Q1+67YA8Wrp4O2N+YTcdjIzAiEC9JOTZGTfjhzqakkl8tHV5tmBr4x1LvTsZ6skNL6HC++ikJbLM8gJIs+cj0e5Xi0zI7vcl
s6sTbG2LrW/kDcq8sEjne1qFLQWB94mnducvD4bCiL1g36YXX9e9OX557arVgrid+w//COqh15M3sn3lhPTpReMzJC+cBvjy32NTcvhRD+thwaemrojaJQg4K86+yEwE
D0eQYJuxICu/PHzHeoJ3TCk85qB4UCqhErwsCHmVxTYkvXZqsdVTgpB3y7wdfP+zX23zMXfa4h3v+8l8HFxyNH1mqcAQDfb95KFnSASf9FtWPlFG2JTEMUV4h0HDvt0T
bH2De7+oK/PuS68d/uwNDeNroKyDERhm1MvR5cl8kZ9WINtrrN98QQo8XNVknO2a3zHqwMfJkxbhbGx8jLsUbENSasxiu7my2DrQBuTRAAm2vivM5j2HIH3oHGlzvrSr
yWWwDyUAqoAavUQxwkHzLmDn4B0lLcG29nwiw+WV6JCP1K+NqNvBoh/3RYcT9XIgT0SA12QfthAhF3amqWS4qATbJVtexkwpz7vu5FnNIhwpMBQQXCGpVlLqm2+9HXRS
CfKyiGDbkcVWTxTLC0KeGmwaRpuRdrtwBGG4pO/D4BP0J3d2oPgbyUnCqldv8NH4ygB8eDsBwV30YtyDwLgbgGFDvUzI4/Bp8I4rI+DskBFsUzJXlUkFwkJiEtlnB6gY
YrEBHKffvNJACbaLoM0h4pdXBJyFLBsRlufEqJmnR1geFM9vGCYXFJHdDQK2Dtl5SXBge1magzJSfssFirUstpFTKCvZthBsD/f7LZt3bdxZGuAbdzDWYYeHB/XgCC2/
vINxhMoQbDv1y6vSCuCGooR9KBY7Umz5IyzIk63WsLwg5MX98swtJsD2Oz9f9/kbl8OnTr9pua7/ce3S065ZwvcgLMP48JqAv4uIYR3LCzasQMnSWTLTqcUfBMZTR9yS
3grm5Qi2EZaXabHVPLEFW3/mCPiayI0OQWDcFR8G1AMjFHAWdVKpMgVgvohaJNrSCmT65a3bcUCGP/4dOC8IQl5QgI345WneYQD54s0riFdTtClGA6AEMHIyTcGtTDop
SlL+zCkrwVxbsgZefcnaEWztAvzELVQyEOCDO0vg1RG3cL0U6S5Yng7erfPLs2rog/irCxHiL+BrYnXHHZJ10uGhRj0WhtIKxGNszQlnGUbYzs6xvXXeNom0PcnX5kMe
IucTG/YFdXl1fnlPrN/zD/euO/bSeX9983IlpOrkDRb6RPpCBir69Vc3LZ86d1uQ5dXJwpNmb1+29VXTYAHfQDaD0jG7Ostp7c7X48CnnrbKJBK6qHBSXatY3S/fsnyA
FL6jt9AUHkUjMKSoxyxkE2ZGxmNsWQMZgm3l05Dvl4dvLbAiK22nJsvgG6USdGEkesoUbJEiHTQ8d9o6NGKfmLwIKXvgTaIG4A+eVbC/qasM9ZPAW+fY7MvCAF93xg0z
Srxo4vZk5Qi+ayGXzBcZwYLVmesWPiZSSEhav2rWhlG0FJumDtkIDCnq6QTbePIoxZBFBFt7q4cSZvrl3bd0h7R4PaF4vB45qWD9tCEv3y8PYfa/XfEkkNedASE+P2CL
UL9jLpn39TvWROzCsDzq8Wkp34DCJ1y1cIBcCdLX0vRtdhgfgq2s7STOSUrBOYKtYYtUy9FLzB/8qKW0HbK11DxotIzA0KGevJHrT7AtpJuOEh1n+uWhPbzo/vW90uKZ
94pzL355SYvtI+v2OoItrnyYI4DgOrzLly6Nvi842/gVFknk2bRFgTwuk2dvX/Ls/qAsXFifN79CYAkRdQOcx0bTh3nXVuOq2jjL0/amTBOZLG9nmabUFOYcpSZsY4Bv
cEzePkSoJ4mDWTgQi20rWV4h3WQKtohXZEsvDIuPbBwgc7FfP4ZOoi9s60Ghy/OiLHyLLeTr3ZfO963GtM1kuJNSLBL8azyEKYO0DmFU2qtgB1EUvufS+V+7vV8MN658
BWSHcpdKL0nvjrlkPrn5Bj7vdYQxTuDzNu4zgm0cyFqQF8g0FZpClULQwUd5LzdOfAN/g2OshqFAPcgLMy+aP4qEHIVfXspi26/LyxFsOR6MlTZwXzznlQM6R02YSw4V
Eb26UDAnRWgR+nr9suBxX4wPjUQRZrM8xENAjcvBMtkKjB5Q2kD+5Xa+D/JEvkShSXJ5wTQsj1uCRl4nxQupSQdo2TBDB/EUmj+8ukj3kqPLM+bdqKtmNSWMYOtgoky6
6Dp7uOeNMQgYh90ZdNRjtjHnIkZb7eoyX/TQYkuYFGsMHpQvMGa+fmRGQvcN5OVkUgFuTpq0CF7mrz1BnvLOw9cEDTQbfkRhvgH4TMNMYf4wSVAoD+RxO5Vwe93ypqp3
XTLvhw9sQrAN6vKCwXN4BZ44cVHmyMSL0UI5DF3y4NNJXd5ABFuncjY/HsqBGz3pRVPJGBiBQUc9WTCYeXUTvaP5nSPYGkVeEGUG+M6Q+JD7TCYVavMRRIKtyYoMY8Kw
UHe+F40E4ARnDJR9ieipgJodKSyiB/xFDhITLP7t3evzXfmwO59x8/K75hc9GvhHOE4fP319MHFsf/SFnpVBCYtbVDiCpNoCzTAOvCNNDaN6BAYX9TCYRi0YRaZJBZy9
sL8/IUed4ibHYgvksaKkyOv5i2HR4qqiZCqJTCqtIA0gD0e8OkuiwI52Bk/yVi8kG1JGhWlDXWF55HBXRJqTgtUOI6nty6ytMvIiy+PIMnDHGvM6NCvQt4adWvY4fssx
JxXmD9XmZOIhqQ8P7dQXsudTqKlwJIzAIKIeq5R5hjovuAlnZlJRMWO+iCewxCNPtovBcAfhbXGEIxlKBBM6lcK50OWRvNN8ibkWoTKCv7AP4ZrD8uz/ChPligyVixeW
FBlf2wwOQGwOKqrrC5C3cnvVFxx0OKW3h/OVNuDUgta1HfiyiFs5naqTyJMsz8w9zmhnzyCzVqPg6+F7HKVVDRbqGXWen3NcE1GyasYuXXq0lH55cchj/ShV1CBBnmgU
QEazg355zqGO0uXFKSeopyuCelLhAWQqGUc9JUFJMhoDfHV9mVLma7Hhmxb2kO4Z6oqZi9N/NCU68csrMk3kzZ+i5tfeLILeSK5DL1C5jNK12jS7VyMwWKgn7zxPnVdA
GNwN31Q6kJcVuUoEH1fxCPKgDz23XZiBhuxAecJxXbO23rN018Zdr9vUj6wBULP4exKQSeKru6TaE+oxqnHUMxCZnB9UdfqNyx5fv9dnrL9Y+eKqFsszv2LWGLj7ntMq
o828e/GOeFoBW1wo508BeXySVhGj9ZPEgLso49wrT/XkIDcFRuYIDArq4V3B3Ip453URcBYx7wJ5UIY6v42ejLuIHv/W+eU58V745eEhnBSm4Fwyv9ZBHrItlUhVB97p
v77dQ7fzK53lV4eUKVIN1gl6AnY8VA3jvzjTOKinFFU+FEJde073aIMx7IqhJ2NsVSAf8uS3rC1T96JyIflFb3lr2xw7smHqKce845Qpm470ZOolKzm8e8WdF10x90Cy
YFngyKYppx31oQvm7M0rHix15MCcC489+sI5B6weHtlw+4WTH98UacWBTbMnnnX0f3jHUcecfP6dK3YXZyf8thyrY8+fk9n4RJuza+s96rGi8EojxWMwpUq2YFvobhSd
lhRsBxvyGGsOk5WsGtTlOd/nu7kJ0eRtFwQ+9g8AC3jS+1be0zqJ2CmsW1SY+qlH91KbfGX0pv7+3n6Trlz5gn4tfM8IEJEygNUSvpVmyKPl/mU7otytEBQ6EmxbkGeC
3ooa2CN51hmWP1CPezSkqHd495yLTz7qg+fMeC4TY3uNenvnnP+hErb2r7jik+84+uypG4IIdnjnjG8dexSQV13Hnj1jJy3Oxqn6d2RBcHZtvUc9uaoYZU1rHvdP2ahg
2591QwFnScF2CCCPZmCUuOPJ54OQ52dSQZ3nOEkodCwofVOSNb/vYAD4ACbJgEZPJxdlYMIBPqGYU1g4VVT+2pv8ZKRp/iu7MLdQIV2TIw7mizpXPsn16DTjBuKu4cMA
XyRGu0PB1jllrS2bC6cF0JHBcmQZOtQ7cnDFxJOPOuWiOQWAZH56gXr2owzq8eWBDVPOPvbob83cWfI4+6MxOfHiOQXFE1KXfDMbp0Y06km2rQu2HXWCrcYadPjY5MVJ
vzwVII0Ksq1ulAMdA2KHjsn92H6LisEQGPnY5CxOeTIX2etKt2Ql4KNCAaJtyRGeGhc5m0vaEEkLz5iyUunmAb6gK5/J8IwJuycxav4kzgE+3ZWjy3MCcv1b5MgyKHJu
P+q9sWnKF95xyrVzZrPI4TgteCoKvPe0m3/1+IWnFNynwgJ6duTgpl9d+eUPljLgjE0HCygrQeqzV06/9qyjvzB1UxWSXI1eWc/JVyw9WPz/wKYZF+opF8zYUHzTBihl
S0qZVKj33Sm3X3TiMf2Ff9tfoPVQg0p+Uw292gPRE32rpNQjz808+4MhidUGRxo754KjjzltyoYjVSPveRyemBqKomG7F07U+Fx4+9S/h2PO3oGsLf5I7/Y/XcrLfm3u
dOsl16uXbTnhrFCvpCy2razIeYKtos0Gz3xhhuq7P19rp5MSLjgBZ/ry4oe24JAsaibPOAfjZGMVxpn6FYRLYRBNOUQl1dbF0vErP1GJIFIBvFwAn12nBkc1+5cRh43K
sk6wpU7zE45+ZJqp33gH9IsBPt+Pr1vBtjZhn+TcnICNjRs3Tpgw4bjjPmAfWO78PX369P6eO6h3/EknF8qs1spEF1ai1QknHm8kvgomDi69skAiFT5GcCaQOvnE977j
KAf1BD0VsSqLGfnxk1eu2B9FvfeefGKFVu+odHwx1POaWo96ADf001H5lUNzZPfsi045e+LS3W20VKh34kknGMlXOr7QULR/KagNoZ5fmzcre4l6NXbb6rifuMXW7Ma2
YFun20ZjONgWWxs+WB52rjpBnu2XZ0CBrHbfLnVwEiEBHf6Q0kqXcgRI8HQYH+gDhMG8wDvBnwpQAwPLl7oUgStyZxxfbLxTyxXGm2MnUSQc2Zh91PMN1owDMciDQpHK
ZktIR2thA18XFltLMVILfArYiNhz9+3b952/+7sI2JmfYqhXUTwptvrFuorileSoZGFvWSjWr6sq4QxqM7sdLRgqEcnKZlIWK2HRsK0Y16sg9bcHn5oKdSoqiaBeSzJ1
myprRjuJK0gnPK7OWnJg05wH7r/iwoumzJgju4ct+SaGohyfajCPHNxwO4aRcrdw9XrewAak/56hnjwqPLttMecEZDmCSU6mKSBPrshJr7QBEY/WzaCPPJPN5fjl2T8Z
HRzMi+UkuudcfpxZXTuBNuUUkMMKF1gmCTeZNk6AGGyAaQ/gJZ8Y44po96WgqyFj7nfvWfvLFYU4PEgfgE8OzMbTUw/KmT8hwbYW9TgOlNdU57e8Y8cOm99B94C2ug98
sH80HK7XIj79CrUwHh0qUMzS94vc1avhHLjBkjt96pTpFZq0AKUlbLoSbsuGa74vn57bVAF0DepJfkd6tefHkd0rHpjx4IoKugved+Jn6wlpcCj22y20mGydNaMNx525
2jPU+9LNy/2jMCTY8kmdcFYl10tabJn6CjgbJFdkfyWffevKfvF21tagYCuwoEnKFKAzwyIuJnacWQQ7qA3Uox5qlt+JbpS3x8D9n22XZmpDu2dQT60KWm9ozGeuXzpI
kKdqFdXD3rbpxcJJJaUYUchan+WkkshET3kcA6hZfsv+SNqQd+aZZ0L6OujvMKAeCsG5Mx8AVErN4PmXzIRJRfV6Q4567R4qpm0dbAAjD/XkZ4tpzNmQiy3n7axdWizP
9qsK7u1KkDtY1rfQ1Cbw1hzpXR3q6CWCBx0QBj993VJhsXRtcZ5FsbhS0tgi7Nwqtpgcz8MsB72cWDdRZoAGY65gru6EDXVfjntJV8QOYCJUVKMnl50clqc6MrIVVPoW
U+33y4yzttzQ19cH0kl6nTRpcscd6RL1bAm39AIppdd6rudJuJXXSIsDVsLjxBVYRSTJ9lszaiTco0qFoEyxARurYU9RrheWcHWv/Fos+TSMesGhKDld1cLfHtk545wa
Cdent/4b7AHXM0YMa3b2KYbsjV8fyZmyJuAsfnCqHA4GI61A3cwusODS+cKC+KGOnNBosCAnzownRkLHxBOlcQvaIhSaJrfk4CeZqoCaTe4D1YDpmcQK/BEUbH9WJpLR
UJBEegjUC/LOYZ9LTqFXSuJG4vhISemIn937xsEyOo2wXBVGYYKMcu6dlUfkQCGv2OeNl3JMWRZYnG0q/Eo1Vo96bdYMqfP6veEKhVf59JZtpLBIWDbc0jwi60fl69dm
DyksML5nSQ7q1VszSpyyRPhI/cC0bdhpaQnbv6QLQb3eEKGejBjGQY/plZMPyjFfxF2RKUz9cgHpeO8dwA14aZBI3VhsH1zpHT47a6sycRKMYeLPcuLMuCWSJiBpizCZ
WiIm7I5yWNEe6CFHtRlos8Xb6kzLVvdJL4jb9gDGNfdWgX78oBXVlURGoZ4gTxKxsZXJrFGYjyyWB93jv7kNtct1jXr9nisfPGvKU6U/SjSUos1zpTSSFiZgK/JBFK/w
CPnB/VO+baHeF26ZfWeJQR8866qFLTuJKF7pYTP95u92h3q1nitFVw5umnGBjNRHn3nl7E0R9xrLiad/KKwa+HL2zMo7ejj0elKEt4wYlT5FfnmcAx2ci85xP5ow8Xyi
KLblpzLYgpUzy4m9RaknyS7o2FEkLNlXJF9B22hUjck4M5MSqm5R9STRgJ2C1MR+MIZ1dmTKE6rhd/Nyr/v4r5BatRtE6PCeiC+LppZ0eXGWJ4zjX8wXFD7w5m/8aUko
0UeveOJLZ5whwbZ7yOuwgwMr3o2X8sCeGL+73kt5MJ/aRd0DlXAViVGa2/otEinBtgO/PE1Q1Oc8ZQhc85wRJOv6+dOf4UsXC8rjJlRYP9mqLsmnEV85eSPHM1BJhg2K
t/rStkXUvXgBn4RZUwYiKZ9BfwvBF89koFK/dr9a+Nk73afMcZct6GK2dXEL2ypd4MA2L8DRNl9UuFbD+PrYUy3Btp/lmfKkyfid4ytd3iiBPI1lxxFpXbyCvFviEWl5
dQxVqQGhnpal0bwkBVub5eUEnGlSDmOeDHq3xsqXZy9+W+VP3k3O+bVfmbFFOE7CLGBAR+MW8XqDLQJMMmXWXWCWwnLjU0XugTyXS4YRk57evxFKaPtjk0im7hRd6hmq
KVrYxHncee1HTenpOQdLtgu24RylF/74CrE86F6Xgu2QDYf7oM6yDwxWM9PZBwbryV3UOyDUw7W95a1S0Le4YGvvwzl+eSqvQw+SKZu66HnyFgnvBdKFDhKz4QCk8Imb
XJFBLqU8AQdZvWCQIivinjcmXsI34Bozrhyhk70wBRTxFlcRFGDd8l+B5UUODj95chpw89uWLKnNwzgJWH55SSeVvohgqzlmIO9f/7s/vPVXa5KNaQqM9hHoHvVEWNAE
I9vqhLOUYNt2wlnSfCH7Gpom+b4N/UDTwb9o908W11NLbN73jTvWBJ1p+BJgArKd0LEkQaN+QFNJqPx88RJOFZHW22GhYZ+/ocg9FTdY81A8t3N60cPmKcSFmA07eZTR
2dXJtnteK3R5xmLrFzOQ95/++P1nTnokzsF72J2mqmEcge5RD2M/RG/tzteRW/PTCmQLtsUe/rd3FRLZEK8u8zJ4rhOVUfmyeZaN/3Ht0rpGysc4EjpW9+4lwMrywO0K
y+VfqKKJaev5vAFkiSN+4pl9dSzPyPUkWB3i3Jy0jZgNGfEzBNt+80UEGS+ddKMEWyAPz+RqIx+EE1d6/qaaCgcyAl2inkX0qoCzOotta3etEsGrrTknQE6Ztx3I6zmd
yR8sHs3azgnSOv2mxFEV+Q+1SyoGg8vE5CrPCmjY0fFvdnSHcWepa1LhwxEKRBPJNT+RWvnOHh2clj84coYv7DytFKH1TgKVYBsx70578HFB3rHvff+GZ4vEgm/+5u1B
zMWS38+m5CCPQJeoJ6JHwJBYXvSEM/Cug4Czah7vPqi0IoPc/Vj1rC7WdjJIyzHgDrDBfk4BWTaMTQOxVyCoVCv2934OAhqjDFQiiYrk5UbJ3UG9QaXK9A5CUr/MaDAy
Vz7c+1PokqOnoQgertbidMVkk2DbgryA7s9AHqgH5B15+20OHedGuYUOpSd8sstNgZ6PQDeoZ4hehmDbclIpD8rIDBhiy9XkHnpXFXt84TIG9QrJrt5lL2LQhJ2BMtJJ
2SKq/yIVvctFeUnE3CWbr1NYQGb7o4jNca+DZXypGoxFxRhVKBl0Xvn8DUsxSTuuKn6M2nChnuRcPJlqFHmF7ljmi0gBG/IemzOPwoI8XdA9kr4Miyq558u7qTA4At2g
HqZbpsWhN98iLDwqq2omVYnggbx4wBmFEZP3HSpyKA2vbKuRgssI9fg7KPStee410Z861FNMleJh127ft2XXARE3nfRovw8DT0YPKEInQ62dYUXuLPyqeDV+5b/gl/R9
SligmmUIprwqtz1ghHeU9I3jX7ttpYN6we4zMtfPHorwDH/WSs4tzWiOG0qfH3DmY58DeX2/PuLYOkT3hlG10kDVYI9Ax6intSQRIEc9J/NFjsWWCQrksRo5zGW47Lb2
cBN0xdrWN8HADPN9EPUkSG7edeD7962lwDt/NPff/vCJD1w2f9qCbXJeMcAn7ubDE19SUp7GhvEph5XQ0AYy+ffIBiK3GN5RxNVZmkE/A4KDenXd/87Pn5r6RGXOHuw5
6tcvUcA6dLQ6e0+uyGX0RdijZe7qTWjxpM5bsKBwtA6ad6F7OA80dG/o3+zQPLFj1FNoZOH85e60Af/PpN+yXQmCLX2e+OimYbTb2oMOZEBngixv+rLd9vc+6gmV1j33
yu9NmOtg0//1wycIaJEAq8cJp+pytOgnJRpI5rBSTj3VrPwFdecQ0Spl63NIzXsunW/CM+qSr9D9CQ88Myx6PY2YCO9ZU1fatjJbsA3mo7UhT4Lt5jI417/kJTpk2cyG
Zqk3TzEj0BnqsfsxG6745TN1LM+JsUXxh2CbQwmFj6u3Fz6Aw+KT7M8J4IC1HWd5+hVvD0dilY8eARsO5Om//+/FTzy+dpdyvpvEJz53U2G5Iksolr4vksNK4KhtSTcG
G6AvVZUz2nxv3BIjcj0s+OpfbR7GhSTtgQ5cdgLOgkBmQ95Pr5zYd9gVbJ27iMz9eOv8k2HsZvPowRiBzlBPU807/yywW3Yk2IrlsVeze6OrHrwE5R2NIIjg++tJzedA
oe+5wiihxUOkrQMdjAYMptLwgTvJkFtImQ7TkJE3gmU0r1Dzrd4pxhdHPQXz2sMi1NM3EcQH9YZX8yXx/ISrFoFWlmBbHXrrQJgNeUqZh2AbP3tXac2Gy1e0o4naFO50
BDpDPVKwcYhyxElKP3Ui2PYJ8pi4I02LHPRSfnrnQR8LTrtmiSMNacFEEEcF5D2nBPGRwspWUHDP0m0liXoihpK7/dAO8yBVZZtKii5f+WSdYEvHTffZD4KOMp3Ov4GU
F+eVs3RE37LmuZeNLg+WR+E6wdau5KldB9mAL57R+/N/B9Ll5t6ejEAHqCfTajzZmSAvW7Dte61UP0sK/shVC9m9R44KGQjAJ9HxUg7SH0GSw5gyUU8ZUOKJBviVMgIp
SJ9eRPAyJwSJ8UUgUkPtnKymxkS8lE33/3zII9KC013OPdtfrrwFfOwD8j71hS/JfFEItp7FNgiXzEb8E66atUG6gp6stKaSkTMCHaAeOnj/ZAxn0nQn2FIJYDoC9cdG
yfXIupciQVrXPl6cYeagHhLuv7s4LeHKJg4A1SUaMEdwUFLaukhhsUKp6mQDMSnqHJTUyZBONmbu/enDG31k97s/QuDAjhGKQx6nnUmwTVrhcJ+i5FtH3tbpkcMryI8c
pBhLLclFPS3OeDrvLgRb47d8wsRFkXzowzXiuJvIoBkP0uJgDUyfdiPzrRncRWHETJk1HGySZwkLz6CqnOyCWAbMiTMa04pxRZbJmJ8UlUEBEUZHb8WxliSR91HP6b6O
zhiul+I8l5HBe9TLvnfIZnlf/Osvkz9qy96wxdbGQVie6hc+os8ZvPN/R8gAjsNm5KKeXENrIoGqGNvuBFuUyiOT6DEbyBisoyTq9PrmJ8eMazxX/uDHrufKv/nBHMdz
RQxOmGUzPkm+8jE2QCa8U1YCI/MCakokpXrMPJYrsjxjjOqAquTe7Htm8Iqdk39Xtzyx7RHAjZmECyNktdTRPSPYAnn7Dryew/KAPPIG4TTaKtynmTnsGswRMtRjphm5
qPexSQE7BoAlQ5hYXqYrsrHYcqNuH5lEjx7dMHvL+fcFuE+VfMWK0ictnZODBCRyvJRZP39y+YIHlj3veCnzIJP0WFokUTATfeG4xUjCVcwGJbkU8iEgU0SHVI38IXAU
0dOlaDZfXcXa/sTkxTa61cn1GHB/OGP9yFkDPt0z+aPE8nIgzwi2NvWDQjJiKPhGTmeblgx8BLJQT3KTf/BjlVagPA4tB/KYWKhLaPSuV/udnEcs0aOdAEHAeWXWVn5y
hD4o4V/f7OZKqGKnyog0gjS4BE+ysRp44lfp7OQBDkIpwzt/B+FJb10Z6inJJdvuvoNvCmq5l58U/8t/MzVTPMs+Epd4u7BcP2urHjfwyderGhy6ZyDv45849fVD7KzJ
zKOHmJA0hslpuz3rbx1GOnKMbL0atPFcTxbqKZOtEwAkpqYdMgfyKI/sQGH88uztFNPtCNToaU7IK9sRb/WTL/Mee+k8n0Ap+4DkVgBIplgDcAIs0TT+FcUTfevUU0yS
L5UIQFWD/la6quS6JRCw/9CMEtnr5HpKDm9iCH/F0nHOk4KaXfjjK2WxPe64D5Ayb8/BtskWMmUUmEiFiCBBQ0cTpzH28DEL9U6atKh1Clp1zrzjl5cTfWELtmZ6jfwp
xYFBtoK/zpftsaf2cqyi7ftWN1ckzFIS6se/MKwbZm+WRTWoa8uccyx7c/iZbRLRl8FEA3bNYDFvWTC39NlXaw3W+/pumLN9yI4Kyuy7tgp6/YVv/ZMg733vPw7IqwMy
33wRZHmmGK4LqGLzG9OUHOEjkEa9dje9SljQobeofmF5OZAnxR9Zz5zt9Cu3rhxRPnr+25r4yEaTW5Rf6+Bg8Zb9ECVIUJxSGcPFlQ8/Y0duEKNG+Bo4aCcayJ86rPmI
k4qIHjVH+CPi+bnT1gn14gZrDsO9aPpIhIA/+V9XCfLe+77jnnv++RxdnvzygLx4TtwBC7nlma3VqdvlSdinTNl0ZO+c6kTXtsPC8196U7LrEUijnsRbxzOgI8EWjwFf
sAX+RoU/FNTsj0pf5TrB9pZ5O4wwyKm4cSUazIsLyCMHge9mTOiLSTTQ0RuFykEVI/G5/ESBumSZoCE2aPp437LdEcFWP/3RJYGUfx21djAKk0BFkHf0se+F5WVAXiXY
tlheTPc3YImkQb3BeOfd15lGPfyV2sXb/oCzHJZnAs58pYm20JHv+45AN2tV7RmJHBDOMeFiSbh0xDMU0V+8l3280zdAoclK0NErlXmkzs+ZmhXqW5eb+ry7Vp85dVWE
5Rm5Hj77+z+a21HbhqCwgTxQ74uX/LwUbBMWDOOXl6H4K7Q6MOUBRKcJ9b4wdVOx/XufhusNwRxpe0QC9XzrrQLOMgTbYtq9VAq2xNj6+Ah5xLl0hKRXiY86ejdw31ft
P7iysGMayFMBHNnq6J5wR4bduuvcO1cpl3JHE0E+wxHUk5Nz0LW4SLJw5ZNLtuyPsDyTR3oEirc25F0w+Z7S7PZqPADDCLYZlPDQ868Uh2GRZyhoyd23b9/G+k/rJQZR
z5Fwvz11+g9ORvg98cKZmw4UNx7ZMPWU9552xZ23fPlDp03ZcOS3BzbNnnjW0QjIp1wwY8PBjuZHU7h9BBKo17Leahr1dRRwRow3z2pZbN29dxT5f8JG//2EuY77rmRe
TlB00BA2VEdglW5A7il112lXL/ajevXKZJYN6g3F9SKp9Oq4HrXhiYlGLwJ59k+/O2Fup8blQV1xAI4EW2UJVQQRx8bHUY8mxc0X9u06JkFCrnFXBuxuvfVWzMTm6cE/
2lGv1OjpCuj1jj/5+GOqX4++cM6BI0K9E048/tijjjltytMHVkwsMLG6PnnlimKXaj7djUAC9VCxmyQrnQScHfIEWxf1OPpgxDqs+ENJaznq2wDcLfN32IKtDXwIg/80
Yz0yo1+JuB5eyhHUY8AdrmfcXHQ0GveabMnmEcpDFdfrKXOB0yqexQG4yXMg1cFz7lj7X376ZHfzbDDuQn9ncEeJkfnIhaUO9ZyAs2RMLhWCeiom90m+4VlJvBMIdoB6
RwnIjhzccPtZRwNzG44UqHfMO068eM7uw7/9bUkMz56x8whVGpI4GIM6LuqMoZ61c/affZGjyzOCLecYBDUso8KOYb9/Nnm0+Abd+Onyli7PhrxiSWx6BVZIkIMvpcr7
L5J3799e/ASYCDIaTiEgU8CZaQ+/Oi54ikWrSzQAEARtuNTzrksKH8M6vzwHDY+5ZP5ja3aNkGVhQ9706dNNqzRiyjbqXF0ItkAeEq7qQcuBjtsWqE899TQevWrVqjoZ
tx31HL1ejQ23BLtjz4fttf6gFiGgawUeIa9i9DUjhnpV/rJ1L3YUcFZnsbWnIDLIqLBj2O8TmgPZwS8PJxUfJu5aXGR5e2TdXv0kOdcXBiEL0Cucv+psuIs3FlG3eq45
T0OisRiiYi1AMaqyrRMmK4EjQfO4oL8eYPe+n8y/4Z8rO4zdI/WFNPFO7O3IcdOzIU9ZQs2HzpIX77xpa3zUo0yngm0ZMdmnuElik/7VlycZSfbRRx/NXu45er1Sqm0B
XIN62WPbTcEY6rF+ikNvXyq0uXyS4gAFbMFWMyZ41wlXLRzes267GCr2AOheEPKk43OgEGWZH8Mgf73H1+7+u7vX/Jsf9DuvkJIAt5Wlm/fa/nqR8zTkgqcMeuqL/ssl
3Z9RAkqsdmIzKICD3nfvqRz0/OATH9Y/cPmTI4ToRSBPQyHct32tOhJs5ZUlwdbOt3zv48ttHWInUygD9Wok3AL+iidZEu7BpVee+N7SvtF8uhyBGOrB58+/dx2vP3UC
ZCVKiBIGLbY29km8dWL1u2z+0N524sSFtnbPFngNy7Px4qu3rfJDwcTg4GucFYnjHgU4RA3wUm4VE90hMVaSaVAPSA06PMgeAxOHK8fAujhcxa7VCbYOyxtRGj1SCZx5
5plCH4flmXFw0t96gm3F3YL7MefZC/J27G87D8s/XK2TqZeBesefdHJhny2vo781c+dhSbUt1Dty0LZmyNzRfLodgVrUk8+KsClHl5cj2GqejUbxVsMLb8KI6Rhz62LU
7l22G2L4xZtXwKocw6t865TqTkYGnf9tZzSSJTdioJAgHHSnoJ28OB0g6U8MHvfp65b6JmnQLdgXSn7g8gXw027nWM/uy4E8PYzBQcgVU+O/lmAbOOPFhj8K46jgAKIN
eb//VxM6708G6p1y7ePTv1XEbxx95sSluwtIa0M9/t/yXDn67KkbSv7XfLodgVrUk1vZ+hcO5Ai2dQFn/r0kwDhl8qJRJ96a4f2bO1abADUJtkEDKAEb5vsg8HEj0q4S
5OnQW+cNAos5BwOZnAU5E0Apquogr+jL5ld8AvgP967/8i0rcuof1DI25EH3+G/kcUbIJWgyGXCmWYoLKhW+fviIo5YhO+nxJ31c7PKvz/shi2KkZV4Y1GEfk5XXoh7z
BrVUDuQF0wqE8O4NnEJtCjkaBxSo4ohbYjAEeXx8mJhSxqjZ3ssAHzEbHa0WBZllHgyUM5LS5bHfBFlebV/mFn42HbU8pzGdlukI8qhcQi7/ZrI8QR4szzk4zU7ITAIr
0g6NUuVMpwM+tsvXoh7KdeuU5Vq5QIIturwUPhbKFDJNiUKO/Ci0yFufufR5fDg27joYZHkItnzv+7V8/Y417/9JIH1x3YMUNhs5RQhYlG0kZ4Ii6mKxrTNf1AnpM1e+
+LHJi2+ZU+F7zoMGqcyECRPEtpIszzRA7nUmK3LSb9kXbLnFJGTmDxCQOQwVGBUBRYP0IsZGtWHUk2fZpMc2x+dKJODMuXHTnj523cNvHTnntpWjyDm57h1/4/ZVwRg1
BNvKyDvL9QihqmmLd+Afp1MvkrNHzpL8WxdxAZDJZJGsCsL47kvDTioRIZ14uwunrz+l3VqSfNZgFMBq0Snk0QzGDXNcajM+JPPF64e1bbe5HJjspII8CqDJoVqiWQaj
m02dQzYCYdSTgFB/2ncxOTIFW5n/lUJ5w+7CwT0nCd2Q9b+7BwFbBOHjvuf7fDhhuSpg5Eeky8/fuBxpNycXsZIhy9vONuPKu0WeyXHWTBk4OykC4Yx1FlvaFvyJR/ze
j+YOOys3kEc4BHFg+e8retJLJbvISUUsz5FtDeRxlm4JeZUacercraNdWMkfw7FaMox6Uif5506ZnVMxthJs42fI86sx7zrBjKN6TJXG0iQf/sXKFxeFvJdlGH1iwz4b
WUhTSsA/UWvxmFbjggf06KQ0WXX5PpmClFswXEAtL/3lxsyAM9NCPLEfWLEba/WTG14a3ndkQx5ueh01pv7Yg351DRWagDObFd788wfELoE8DLhieXq6zqpvzg/q6F2M
tMJh1Dtv2uoPX7WwTjrQ0d1AXhlw5soF9l0SbClc5hPtk89Kjnw30oYp2B68doEGjoW0LbY++3MgTwW45ZIHN5DVDuyL8D7GSgkgTKQtwCc3lzrE5Hu4Iensv3b7ajKp
RFKE+n55NAzB9vGn96K4vGXOluF9C4T327ngu2gMoxQM0mCKGr+8519p88vjp2kPPt4OeUU4Jk/nX37V+UGdJsXpovHNLYM3AmHUQwRzcuoZLGsXbGNZzIxgW6ZdKawZ
n71+6ej1WQm+A7IK/8lPnwSb6uTHN9962/9p0uztkisReAnh+G9XPImqSEfiBp8CcZNxA/om52S/mMpQD0gK3lEzoFYnvRqJ22kbWExfCMMY9mzJJtxVx190twBA/2Am
AiPY+mLKzMcXmQAM/mbac2SzgTytAggBtKC7JjV3jYQRCKBexJQRSRHqmi8swdYEM44NpZ7z2i6euf4/X/6k7w6ybW9fkGdNnr19ybP7AT4nyhXvFjALS6toXU5CJ52W
S3luRJg957ZV5ogPsiLXsbyndx4M+uUBeY+v30tfzpoyzN55doR/15BXSKM1hzhLsDXnmpqpa3sjw/iEiX44ptIQjITV27ShuxEIoJ40Vr4pwwi2Lam2juj1OYKtTGNj
WCECM4If2cDHy6jzXo7wL25BUYiPCxYPFH+8hfdcOv9bd6wyxz/qD4Tij05cyK9IcF+esgJmJ/9B+4o/xaefCLbsdkAe63l4VRA25Jn8Ud1Nbqn2yORocM0SbN0gcRvy
bv75g4Uu7/XC1E44prOj49swlhQ13Y3tqL4rgHraIa1zIAtW7wScxS0YOgGSjz1dNFeG3SY4SG/LAB8JS1BlBiEPiwffOywPAFKOk7D335Kd0xbtANS4CAHWH1w/faRQ
ugUpGxHBwaoiT8EvD10ekPfJa5YMMeQ5IRY9hDy9aKYcBxWYeSji5s9eOwAD661tvvDDMWWUyyHjgzTZmmoHOAIB1JP63AasjgLOBHn+oVPIBSPQUw86wPRFWXb1rzZf
/tCGs29decbNy4lhMNfFM5++YfYWClAsHqIA8P27CXMLHxHPWY9vCNiIGBaCakESNXd6Cw/q9BZYHhbbYdHl4Ylip8ZDmO02qUntKoAao002KNYibm1iihOAofP/Igfb
K31Gju/RABdnc/sgjUAA9dDUmvzJHfrlVT5NQJ6/nZ4wcZFObxjej6Jfv3fPOrzYmLukhv+zny0itBaLKgGnhkyZPyY88ExhNr1mGcUozC3cyO06zNvpyy9X7PiPP553
zh1uBqebyxg1n+UBUnUsD8jjpzojSafQVvcU6sc2Qr84ADPyXsyx4vKeufJhjnmrrjvnb5OBhV2hUyKPlZZYCz03mBh54FNFW7gsEn7AWWGTfe5lOwCDb/RQbqnzYeD7
xow78FczjDUEUM8+FM32y4tMAv0UFGzNXcM7UaBgV/9q0/+8dgnNAL9Ov3kluGY0cYAITmo+xCAtbn7xkP09t3Ajt3/+xmVU9cHLF4AXNgcsnHsnzOVUHXOXBFu/8ojI
ec/S8JFskVseWfdSp0+hy2D9URPm+onzZCcB3Dn8SA7SZ9yy4rM3LKNf9N2+vnTLqu9Pf4oh/fPWrvDhq4pdgbi9ODVGtlUedhIR25AHFPZwPShpzYYXitwzQS8rOwBj
7fOvGL+8eJ4hzLgjYQvv4UCNq6oCqFd4hxWxaH0dBJy91Fcn2Ar1hsuUAfu4e+F2sAlfHGydxsTpKP4fXLXHRyXNgzq2tea51/iJCqGBeO3xCBzcRHb4l50DmRHTBILt
yu0HApWULC9Y+c9+tW3jrtpQiuAtacHWE7pxM/zE1YsVtmFmPJCNnE7OZNjfRyctMXtDnJBi/DWt0q6AChKvEbJPE8GC0kCe1c66Ihex5NnPfe5z5hiKupR5Xa9JmeZm
r90d3LMN5JFVBdIn84X88uLXmVNXcJpd161qbhzeEXBRT+GfJMvuyC8vDnlMICqk2qFM3cGzYByFQDppyU1PbAtDTKkFQ7EVZHl1qMQtgjwn3OIrt67kcTxU3QQERW9r
pdRQWicgLwK1QTZHY2K31CSPIooeliowAhrwv8FeDFKDdCbgRC3noUQU+r0g9i7yXP0EtoKAVMtQCP7MdOfQCedcsZ5Dnp7V2sVdIJt0y122N7IK50Ae8/mm8uUO79Jt
nt71CLiop73xsaeKUCSiL3yfJn8PlBRcLJ76HXLSY0M3S+gCtgjYSnF468yNhEbgOheEHtZzkIjx/Wayn7bjmoGApc++6v/ELfjB8TgeyqNpgKwfkD7iHByOWeQ4CYHR
E8/s6zR6rE6wpYVBvzyIGG7VuMUo0TyyLSyV3AQX3b+exgf7FRw9IG/1cyEOW5OalMq/e9/6j161EL0n+8Hipf3Z2AU9f/qnf4qo2/U8jtyIDQ1q5kxOOwBj3uotYnnR
OdyfgRlCoJDNwWhtU+cQjICLetKDsFxbieCj0Rd7KsGW9GRJiWAIojIgqlAtQAfCIp0dkBfhI52yPKryWZ7YkP0UHk0DaAaNoUkgyzt/VNhMTFa+ILTB8orvfftvfe5S
GhMxazg/8XTaAOg8sKwIwMAKoVZNfixw6Ifgj04FWV53lha1R834Nx/6XPAAWQgger0Buuk5ywYF3OduKMy45jKQRxseXbjGDjhLyrbyWiVCuXFeGQJ4GqRHuKinTUxH
dyfTCuwrd0gFnMWnC9NusLW/LGPMCGjZbM6C61wQRxyc6uc4s7YefOM3dSwvCHkUfvHVwOGKNANnHeLDaBgoA8Ep0pGWGZL9+vtxJJSiKgzc9ZpBzRXzFAENT6cN4nc2
CofVjiWUB8PpcgTboJJ0+vIX9f1FP19Rd3g2Cj58WeJ5kjtdCZrSZn7a3sh3P/TPL2fo8rQQ+FdqH6Onblz2On0XI6R8GPVSO16BcfJbjgu25lQ9pt3gJZiCmZIGDuWR
HaIAywPyMHoGpbY6iy3dqbslKNgq1rXuFsRPmkTDaB6NBHGmLdiGrYCz1tB2GQsyTe1csA27ItPZ5/ZVkXDUz1OQr8E44R2r1Ja4eS6QV9f4OsGW489t84UZXvPc4IAb
yOPXU8/5Rx/1BgPvND/tBEJOzBnTuLvz/xqXvRGCX901w0W94lyF0qszcnH2hcwXpWALAiaIHtvp4Lmt/GJZkeIcidJebHVUTjwlaLGtZX+hUx+Nji8iPtvtoXk0EmcO
vSTUCKj2ZWn51l3rHl4TMKdIwKxDw4hgSywtif+omfo/c/1SGRCAPGwXkv3VMJMBIcjLeijYFrhjHa2L2eR3/+A/2aj3/7zjXf/n53/4tVsGKyzERFhipSVzlB6N9VaC
rR9wFpz57eGYxeoYvCnd3Upu7sofARf1zr1zta/6deaBkkdJCo6CY3VClaZdz1OSsZL/6f6n8Brxo1ALwbbGFhHQ5ZVCZR1+BS22ReX1AmbwFhpJU79/7zrjw8EfDy3f
8b2fr2Vw4IOYQTB6GPFcr9DvRdBiy13cC5smsERgB8Ian2FoJh4qCLmu7F8zREHIw3UxMkSZ6E93vnzxVAN5wN/pF1wDDkJLgWncXHo+SQpZpJx+DyzfbryRgTzjt5wz
hyXYOgqfBvXyUWaklXRR72/uWBVBPU4hgOWRCL7ec72N9x06fOTNt44s2VJE8PRWCcKS/uS1S1jJTrITECco2MLyClfk9QFXZL5Hl9eRYMst6PLqbsEUG5TygLmPX70E
GdOJYeB7VjtCKGjFQMHIvoI72LQ18DI79lbhtwrL5Xt+tSNGSJTys1kbqcfxjJu9dpfDhWF5Edn/2ZcCxmtGD8G2biPBJB38CSOy//0f/clHQL2j3/3Hwju7wD/OfAbv
mcmPburtImFA/uUFj/zpSZ+u0tB//VxmL4JtPPrCoKFY3q5XScPXNrdxVG4O0Ojtmxqy2lzUw5vXjtY2756Nznio+DG29oZptkT1gZ9IetFbZz3Iyzt/NM8+oVHkqzOL
bUnxIhSGxudYbO11W1DgVw+7S730CjRsiGZDaiKuiwr/UmgwVmCcYEDDU69Z8sWblv/ljcs+c/0yvuF7YsKS0cG4HDtcuBqiGktxpyyvjpDWcedvTn4Q/d2Eybc5eKcR
48gRXAWhvXSzt0kQfuf46uDwT/3lX79+qIibzIE8Y74IijWQg8E20A0ZCoy3B7moV+fSCXhZgm1CkWcOGdhZ7JCHlG2lVyMLXuB+AdlxwAUPuDq/PHT2QQW875eHDKgI
3IdX75702FbHX5cnyi8vSG1gQ2BokOU5bIjGY1EdVJ9tnQNZ5BRo98J76ze1sn8Q8gRGdSwvX7BVDUSeYZ8N1kZVGj1JuzDiXo2PSUOPhPvC3uL87OBxaP7OLcEWrXTQ
mQHU+2YTntGrVT209WSh3nOvvCnBdvs+l+cH1SISbM122kPUYyUEj+lhxUZWYBDyXny1OJwXADpzysrP31AE1XIhYX3ttpXs4ZyCxh/8V99TgGI6rju+aJ1f69gQBgcq
79XCduYMkPeJyYsd8R+Wt6reYhsUbIEhIK9OkK8TbNkYgrnp686fZMT8DSPJiDOXiUlD/3///rvWbtzWqWAL5NUF5IJ6qIMym9EUG1EjkEY9nWNLo+OCbQl/BQc0gq3Z
IXuFemAECcH9k8kigm3AMjtrK4r/8+5ei8u+zjaVnBjJFyKfD+Vwh4OQtRgEtMMtoJkBwdbzXrYBkYY9sHznYDA+WksjHfE/PkRxvzwIL3vDN+5YQyaCU68uTMPORaQH
dn/G5Mypqxioul0hYncOcmSMM3/443kD2RhMtr7/9x3v+urVjyYFW8cvD8E24rIK6jUZlUcUluU3JoF6jmoj7rfsCLaGBvYksx6znzUQhLxIwJntl4foRNphliiHJUYO
qUiOHS3RCRXA3xlTVuJ3MqfGfBFhQ7J40J3eAl8d5JGzvk5KDbI88sRc9/izf3XTcvrI2tbeoHRSvsZNOQq1K3zp5oI1nzRpEeeBGOE6zPJmbYVFcrCcD3l8T/4FUHIg
42MnKD3zil/A35OCrXZuTYCk4q9Xe3lyvjUFej4CbajnZNwuBNvSc7084Sx2FppYHq5PtmBrUG/gel9W2ucKjf4yZ+n2C7bRkAadQstqZPX20JSsc7ipFprjqM/wj4lI
3BUxLNtMp3qVtL1TlkcLfV1ekUfrpmKsUAsCZJ2mzKNOmqHTPBDhT5q0mL9xIfQtPHxTFwZjDx3jg5d1p8YNJ0EpkPfNO1Zl+N73cRy4dHnxTFNUdd3jQxda3vNlP84r
bEM9+8QMI9haPD9ixKh2yODEGjjqkdwNDbezcuJSm/HLQ+zimEQWYRcLOGdyUK2wTyeTyeJRB3n8RLyt0xG6hqtKzrPiZfzjO3hQJODMgTyI1Z/+tDitDVrXk7ES/BF/
bY5tc+zdQcGWF+fIwp1uDH6CUlDv7NtWplCvOtg+WUwF7lm0vYc2uoG//aaG/BEIo54t2OqEs/hUkM+nLLb+NUDUu23uVucsHiFLXciU8cuDtnDootKfOCMiKdU+Vzsy
ZEh2SMQ6qYdbgpomnbqN+Iw/XVKwdVAPKvTp65YO8PxZon0JPrO9F+MxebZgy0Ahk4J3g5QVnfHnhCOwj4OQ6DsCLCwPH0BnHKqcqSHHQPwcL7h3Xc60Jiu9ydZnEpTC
8UnlHZ3DuYKt1kKTdiXnXYzYMgHUe+KZvTJf6OjuKOQVvwJ5OLVE9CBfvbWwinY3BKKfjgdJ2GLbCrEQy4N5cSPQ5uMdjTnusiLJqFCPJVEXJgzA6chtabUEf9xLDUGZ
i8fx61dvdb1qaA/NIMWAr1xTX+ggzsldS9/ciF+ePUq1fnllSIkxaoOSnEiJVSd4rDXV6kqaFETr4rsI9aBRBV45pqPO4hH8ni/nPvMymG5C+urmEm4xpKSXN7Kdrc9J
QNAOfwWKkWEoR5dHSWx6cuG6aU6Rm767Wd3cNbwjEEC9pc8W2ZmiAWf91E+tj6t+ES66Qz3WErH6jmveExtrk0fB8oixZSWfds0SKJ6/VvkGVGINyCzLH1JdcSGIcdlY
psIUsJe0gh9ATH4KioF8yaNZ2zbtomFBI6+NTXSTznaqwGLwucX35snxy4Piwb8AfT9WhJGhgwyIGK6g399C9HQJ+CLCXPyhXSTYFwGQSJ8j8MaNvGB63NfdhrwJEybY
6yqKep0JtsZrtbFmDC9yDeTpAdR76vn9JYqlXZExXyQhj+2xa9QjYB6nM3ttABN18iOeZVhssSqAOKxkf8mVGDofSiIGZ7tfqDzL1SSGsQtzl10YLKAGlnoEyvkVQBH5
YjFzDobPYvy+0NnLHnqm09f5N3estpWeccEWm6laAu5gbfCBjI4L7GSuFdejSfzLoNEvu3kqLNyUJVc+QFx86ewi5kZKQvqwL5mNoc6VD5mX12rUfwThkQO1bmMA6aqY
szPPdHJVRVCvCjg7cDipzjPhmHLhalCv04k6csoHUI+w2eQMsP3ykoXPmtoN15NB2baNJgPOQBk8LZyVacZawiwL0kExIZqEVsPgxFnqCitDKigQiZYHULCi0IsYy2vn
O3S2UzmX9JbItnbSKhpWl5rU+OUh1YI7QbmVXjOAhsFpcAxBpuN2xjBTWPzOXBrMyMbAr7wL9ie6TIPrWJ5v5GVjCB7nZgIwkHD99Hz+YaeatO3HJERTabQ8WozXaoN6
IwfFOm1J0JqxJwlkOYKtqURSUqctI/jUzh8VSQSvgLM45AmkjK+J72rLN/pVGi6WN4gm2S14wRnloRbpF2UAPj+sLdKXSx7a8Lnrl2WOlWRb2186kmxGFlvw8dNlJG+Q
MdFgRkkMzu+17OBmY4gXFtGLbwxSFHQU7gJK+nKugTzsGFgz/NEL2nBNwFlqthdCj59nqEG9zFk6AosFUI+j3evnQWG+aBdsY4Lw868UmUe7QD1WFKk3DYWJ++XBFC5+
aAvEIY5B0j0HiZ5WuEwWAmgVDi5+FZbrXxLNfeCLB889uu4lOp5pS7U1AJmC7Z9fubAO8ugvnRKa12E9XYY3ie5RmJKRwqoqnpiEV+ZvDHVG3jsW7QR9OKGY9ARmLRlv
ZCAPn5XgGvNRT4ItmpykXx7kDq/VMhyzEGyN5qdBvREIZ5lNSkekCQH9TCqpHbK4S43ownMF9Y0Jw0gKtlAY8sfFIc8AWd16FuoZIEtCpDRfSdTjuTTMGDfifZFplY5j
1ki+P51mJw1A3HXR+OUh2EYgT0MkF5y6UaIvptfwOGhapDA/SYUa7wt1Hv3jebbxp857ufA9nLWVkmZjsAMw6iBP++45t60yczhfsGUOy1GfCHQnMKlBveQUHbEFOkM9
dQO/vFRoWj/kMW8u/WUhleQPARwBNwUp3SPCICpwwQSeIvHFrEfTBslcdUsa1OPR4iaS4yJLGr5jiGGya9SJ8j7SF3wPSXtnLB50P0n3SDZlglXqBNvKS7n06SF4LjlK
ek2RIbKxXoXjqGc2myTwmY2Bkpd7rny0H+w26j82hv98+QLOVDMJSuMHDNFI3KfE1OKZVJy93MJHV6YhzpK0bMlX3xQYgSOQi3rMhvZMKmnBlt4i4TLPOt0VidAS0Yv7
5Qny0GrhbpYTS4C4Kp+yOtST5VFmTUWe6sS44KWQDMcGCg+S958xAkgXJrSlcJ2fmg15onscoR2ZLoboSeirS4vCTxSgQqJiGaWk2502hnyu5/TXGSgpATLPxgORv377
alheMGAD07Nj8fiD793/H9/1HqFe8kw1elTmyu3LE2yLuV0Itm1eq66to8m5MgLhLLNJ6ewDonWqLofi+ebdjlBPDrcFy6v3y6MlOvsCYQcHkcy043Htu8RbKJ7U/Obv
oEGDquzCGhzp5vnJGArk4KIvKV8cO+udOcuNwURYf/DjeRGnZUP0wn55ZR5TUy0PRXeWM0qgQ3xj4Fej15PlJ7IxqCrf2cX49MnfWx6RXO//yXzQOejI7Rwf/A+3Pclp
G4I8zlRLznUeRK7czgTbEvIiXqsN6iWHfcQWCKDepQ9tcHi+Ts+rCzhzCqurLVVgsW0K9TL9b1nPmG4jfnkcPm3WM4oqW1luQsfE1HwCCO/w3TJkZzQ+yeZVUVKGSAWT
isjItqvCthAaLCyyI3xU23Cftlc1iiqH5elX+M71s7fgiBecN4boFUJfMLH7rK22zEuGqMwD6uIbg3HuMR582iSC3FAukBSwsZv6FRXDaMitT1oCFePC8cjZGHy+Tx7m
D5z4merQn4svy1lavLi7F26nZDKTSr5HSxfa6pymNmWGYARc1PPPzWgFnCXO+Wa6yGLLpxRs+yWCR9e9yLSLMBfTT9YJJXftL+qpEwYN5OERgp+toE0+tCZ0TDk/tMBs
tJVPBpcaA3jpdq1GHxp8+kZ5xS3YkJckhqztQlF48E00QeZso4IeWrq8or+lAg7/Pn6Si0ZwqyBiF++TotkhyIPlAaZXPFpFueKNjGueqYf2m9Ax/5AN6jQbg4NlGkm+
tLcZg/UK1DNyvaJfVJV5uRpkuTHLlY+LG9UkzRD+iwLUvHqChR3B1oa8Pz39uxw1l7NIZKrKyaRiAs5aeYZqnfg+dd2gH/Gc07WmTBcj4KIeSbGt04LyQ7LbzBdOXEc+
6nFA9edLp4QA5JVSm33CGbxJvnVaTk7oGEtIrrB+hAB3CSK18FgSUtJr+FiE4h1G1FUZymthU6ejIIsrAY1hhHZykddEARtTSr2kcwFkpvtEXDAg/kvFwrt8S+AocVVr
Z1JBAwB7UteM47Fay8XIyP3YfoQdbmGGQqEXftCecNDsIho3bUIK8LDRVpDnS8TaQvQS7Y3hjV/3my/MKP3Z//yKWB507/x71sjoHJ/3cnd/YMXOHP1M/vl/QtIullxz
y7CPgIt6Lb1vgWLyy8sRbMXy6o4W1ZHJwShOp///645V9y0OYIHWs500CcYE0WNRyW9WqQEcXzytOhZ50GXMjqBSMyTfSdkkpJM8q18NMfTfWdLhQ35tagapTa59/FkT
GWajHoLtZkzeLSjEpoGrtvM4gOPjkxbVmS/IBmpXSAoG+dZIJJfUaXe8DsukzeReFjb8K4iPpmF0zd5FgkG7VEKdAiD/MhuDBorUNaCPH7Bhjg//4Emf0XlDbAzJlASM
WDH91r0Y97Xac7BIooFfXo5LFmUa1Bt28Oq6AS7qKXaHXZEaSRGaOQP0+Ejobs4UkXjrnPSoNUzlzjm2JPLUTstaiiwno4qKMwLDWYRxsroKByUmx8eXZlMguJ71pe3S
TJ042fosT4+wv2cofCH3sgef5uTc4O1Ovjxux4gh8iVh0/fFKQTMg0XmBV+6ZwQYDbFCIwsb+4wRZlWtgFVcL2gpFh8MmoZUlQwjwmhw85w7XLOGgTxO0TVHrLExJNO4
i12y9UYmMzG2rTkci0tTDQfe/I1Uqzkbedcrs7lx8EbART05duh5marfnOnCeRdJ7GBpkUcvIPSVmVTs76Xz0mITTbD9RRz00WKLCyNGEJbOTjXI14TKWbHx2zViDtO0
mwGm0AwtadAEJxInTK3ugEoGxHHce99lC4IntxXqzvaE0obo0QuD/j40G7ND0q9Fg2ObiaTlzFn/GqK4c58ZIrqM+579xs+5/B4JtkAeBlzzkzaG+JamFsb3b1uwTQrC
xQZf8sccVfXgLd2m5q5HwEU9BRgxjfIFW579/CvhfKJmquWk2CMVsB14q5ntCLb6Eg29pEVZCeM8yyYRwWGSJaTOFqkTNuJLS1EKEeS1HT5oA3VifTZL1z+gUj+Rd5Po
K4bFNJunyK3Hvrg9KC9/5KqFhujJglzHRmVGiNt5lTpQhM70VBzWt2j749wR6jkbg4G8dxzzHhvyGITLZj170fR1zsbgPJ09j023DvWeKxShRrCNZQuXKENhZKD5G/c2
qNc16Az7jS7qZSpBNIcslpdIS3XJg08LniIfosqMfbNfsG1nefr+izctkygqwEqiniERwafLMznid5Zki3GllYnDN9QAmMDIoL7IYuszXMn11z2+zY5OQ4fVdnhIu1+e
XcnVs7eaUDAhTiSmOBlnIoGOZgejbhm65MbQkYRrbwwcHG4CMIA/Z6DwaiYvId5OkXllBWa40iu0TixP8znO8hBsKSm1T0fOWMO+yJsGOCPgop6m77RFzyc1ehbkpVUh
kjIiLntS6tlzGttFMAHRsq37jQwuvOPfSBCVMsVH5GvxuIjwlQMKsqhID2hTKla7dGESb80HmwYQj+2iLsmSObncHjccNfpPiUOenbW17liMKx/eYLROGqI6osf3MmE7
LbRbK1jXjhi8tDFE2GK8BtuaoedqY4DZIdIK9XzIY8PA5I28Hw9bpnJclIPz2Q44q4e8PttRfzAOtm9QaYhHwEU9LQ+2sgjqWX556UPB5eG8eFNCImDZ2Eo9bnEjFkql
FUd3YwC1bbLxODNmvFwxIkLQwEGB1grv+JfHCWclWctfRM2wXy1fTnmi8MWpY3mm+wyLIYmcFmaUepL9FXBmX6gIYUDvvnSe0XYJNwfC9ZJMTY7HEdyUqT3puWKP0od/
+Ivf/YN3C/JOv+Aau49TF7xAtlEzehH9g3ZTfz4bv7xdNYe9tM//Pgm2O1vJR/HuOv2m3IRgQ7ykm8clRyCAenjS1u2NnmCbYHk6RYhP0nml8H4oD35EmUV5x2JrdHz8
hPXWtp3Fwwn4ldUYT/uRBAXRnMiSrmhvKW4DEDRP1kwIjrwCfZIrjPAhz+8+w6L+Ssw0QxGMY5NVBBYJlzTvngfJMznO1CIWGw1R3BYhfIlMOOOlbMiv7aX8Ly945NH5
Ra5WfcgM+sf/9SOCPKy3vmBrf0Oq0bp4O09jU6licgRbUTzIHe1x/BlwUT6v85SRydXYFBiaEQig3rl3KlQ7jGjVCq/5NRidtmVvMXtYEhEJ6MqHN8qUYSQ7n8LIlw1n
Lsd2poABVp3cj7W2JbVJ0R4PQZVTXkTZL1tE0gatkaGwHXhQZ+azIcyR6x04Y1gunvk0NVOV8unj3lwn2FKMAlhv7aGObwxyPYmba4wEWoebjLbYXHzWGk8gucLYEWnX
3HqvOdLMPgHDhbxZWwvBtp0j48pTd8KcsH7J1v32zOwoIDd4/l98Mg/N0m2e0vUIBFBPTlU+6hnBdtvLOjgtZsHQXOk7LI+/omTcjEvKDbKncEuQwqh7QgefUIiGgHe2
GGucKuIGPqqNO3bIFiHprOtRDt6Il7Xtg8IJasHuMyxfv62Iu+LsR5a3E3BmEHPW2kKwvWtxcUAHgbdOr4MByHJDkfAbd80RW4xsDPxkvO3io6T3Ymgjfyio5tRTT+PS
veacs99538ccwZY++moBDBrfurNNbWra4BhwOxRsD0HxYIWOPwMYyiRsnPV6uxyGsrYA6ml7XPPCaz5xw4yVtHJQwAi2dmGSGkQkoFOvWQKsOH55mvG2Lxuy2+dvcMMV
DMmS6op/xfiMA218QIslV7rmKVDBpjMSTn1bRE/eUBEBcs/TZlVTZ1Cu54Ddr5XRpjC+n/5yY3BXqM4db/nrkYfGcWETtPFE+sjfEsCpU+J/ksZqYxCb8+metJZCxu5G
xmTKI4GKfQLG569ZYA9RXbZRynBOfPDR9I5jW8w8tAXb+EyWYMvHd+HKj7DsbjSauwZ7BAKo5zuvtAecJZxU2E5pNLnJNr1UlZR+BLswC6bOFZaF+vCaNldko8Da/GJ/
kBbzO65f05JOOtw6wypBGMKi28F9gaD8n/1I3uRbUQRrvBiPk1CPLq9Ori988Tbv024BHZ628Pmg9cOGAznu+o+WBoBuCv7Ejh2CXNdgbQzyUHGAT058CkqL2OjjQ2GQ
zjipwPuQcxl8Y7P2BdtqKGZtpQFHXzIv2GVjyti0p7BIWIngEyrpKhwzdHaa3FaS8b/JSdIUGK4RCKCetDw3z91mNkM1LoflqSSQ1yrcD5Fxg4bR09ur2vdlAyaSxKS7
oZTziuLPZIGVLy7/ZTFrYZvwrLpHUIkstgIXEc86BkRt37yrSJ5KbX5khb7nY4T6v7pp+ffue8ZBPR0xYYflRuhw9R6zz/a2uym8kzTKvwoENP8V9nU38qCbATv98c53
/n9KB88QoaOky+t3Hgzau+n4xl2v81MQ6LV//2LlbhNwZk44C05mbc/GL6/OlwVbX5NFubt3PULuCqAeLWOuGDOuBXlZLI/yYnn+pInEpbWhXumJFgzSAvXiGigTDcqM
j1AP4EkGVslr/KGUR9wuaBPd0zcOGioU31fryM/ZDthiKGRJCJpxC/XWzwv32qBgO33ZbkGeQb0PX+V6cfOTL/Ql6XDXM4+hMJkFJCObvAOCPH3JFedB0gCakf/6j25x
UK+w2556WiHt3vPEN+5cU8vyyo2hTtsr0JSuRmdflClCY3O4nLH9eYbqUA8DLha/roexuXHYRyCMerxUXm1dvrzgPlkJtq8bwTYwvc6btqbOicThekBe8LRvYKIO9Vhs
dsYUUS0xNWeUBU/yRzH0RxzN4WUiOFL5a5FrSfOv7AOmZmV8cQK2aI/uDWoGqe0f738qqKebvvxFu/siMj4dDsIBImEwx4w9COpCUiBlNKhK4jB/yP3QNlLTL30p2dkk
79LfvulcmlNpAPV0vvnAh07wUU/fHP/Rj51+2UwDbQ7PLTaVljE3yPV40GevX9oSbOO+pf0eLYVfXtSJj2fFo/eGfVU3DYiPQBj1ZK3LZ3kyX1iCbVhpgtRcpxCxl7Se
G1RgiYX5XaLBBrMEPSxsaeUc4UvOEwaetKSFgFw28El5L2WWE/shDaBt+tQiF546l4lIcyCVxzmpldVlv/s+6uGma695e6wI3a3bGGwBXGxLuOyPp0/rRNB8NyDfTiLe
Z5xUTOUaT20DMuNynXvNL4OQB9fjNAyGCDOFPxMQbKnW3jCOvTQgYtNBebSwJadyCvTZAWcRZc6j64pX3LXdpsGjkTACYdTT6i2AIBWcqPlxsAxRdMwX/tSJqPYM6kWC
tJ7eefAHM5/2V6kBMv1hQEdmRznxiVlEIgQ0lQV8KizVla+/V/3KSqDC3GgcXHzUk9irMvYr58tv3LGmbUnP2kofiwzJ7dlTfNSr2xVIQ/AP966vAzJpLW0FnJylHXON
o8IT3ZO8rxG2SVydT4zKyziuXlOJGTQzSr/zsW86qMexto8++mi149ZsDOjyHChE/HfMRzSSp/Bv5OwLe4rqiSb6og74tHN3rcQcCWu+aUMY9WTQuGPB9qQFQ4Jt36+P
YCNLFt7fVzi+BeUvoV7BEYIHQZQ/oery9XrGmS4YGG+cKgQEyXhSsSEV5l6xxSCQibRK7qNa6QHrSpoUCQ7qIbDbq7eOvtmoh18exeSX51yIe489tTeo+hSQibeaHgkE
JYDbwGf8eHxzLTVIltfGYOA+GO5mbwxmh7BL/m/f/YUNeUcf+94PnHUJxg0zSj4dlo+Of9jIe3+ywEEiySvPvdx2dHfdFK0CzhLRacUM/+HM9e9rDoQc5cAZRj06hZXq
b6etjQOZ8cvbXBq/4qpiDdRFM9azZvxBY4LGs4+see41Fjn+qA5oauEJpoOX4WuiGyxauWEHL5NoQCIet9SV5HtZdbmFauXvEilMVYpmNX03Bso6wdaAmkG9yi/Pwzs7
ji2o16OFPC7IW4V3KiAgEzV2IM90zd4YFNYS6bg2BpMAQvzLXP/qsz8wqPfOL04A77SX1KGec4SADfoaIvtDL75w47LkThwMOKu7CzGZar/dxKKNVdT74YynPkyCtmjk
mQTbFuQFdXkVATROfHcv3iG5wxm3v/jZQtxxg7o8hD5Ynn7CQHneXW3mM2NvjSOOiBtltMLrCkso5lfgSY6BkWoltxpNfxL11AbTccAXEFe/CsG2JhPBjOW7OGqDuyTE
BYcIgmwMwb4NV2BHDY520nRNak2VEXuN8FYK8/okrQtr6qrlVw2ROanDGaJ/ffR/BfUQciF9qkr7h70x9CsBZm2tBNt28Z8BYUd0UE8vMZ5EQ5q+YMBZ3bRn8qhTo3zV
j/fm13I9zXsngNHMhn7BtuWKXI+Pff1+y3v6cCOgWt8EhjOak1zPMCADeXyjc9Hsl5bJs1QsE/UET0KBJNcT7Ao46gqz7E2FpvHfumOVulwwrPrkK5Me20qEGWW+OnXF
Tx/Z4qAeaTUl2JrvqfMbt6+yhyjZPANewnr9G9kYDN4ZElpXmEerNo2SjXr/6pwbDd7p9iDqyV9Pfnn+aSE3PvH8i6++6fvrafbGs8YzY6uAs5Arcvt87iNvLs0TV3UU
iOMdQkZh/2tRT2s4mGjPCLY5ujyNiW3eDfqvcParIT5mAXOjBFtHlrFdLpI6NS0n2W0l4WbGk0JhGISIOAyQyQlZiBZhkarH8a+mYaTCp4M0L8jg1H0kVh2Mq1BlX5fn
uPv5sRk+4vggZeNdp6hXJwsbridjiFQNdfho9An2yzWxGb75QuMA5GkvJAeXvfp4LydEJZVIwJnvYM83VI6RNx5VOQqX/zhtci3qMR4c7+CnnDJOKi2LbSzpNuYLB/KY
QEErGB4GTvp4W7C1lzp5zezNVgJURK9n86xkPCn1aInSbHlX1Gm4jMFXE4clrbwvDkuSDUHyoy3esv4JwsMpr47l0X31mmG5+lebeQRxuH6G/Q27qmL2EDlxuEK9oFeN
wSB1XHgn+0yEtxqlZ3JjENzz9OTGwJj7Zm6SZn/n3mfquDBbgkYPeis6XG2xSsnlHWZv6BuQR8BZyy8vnjWeU54LlvfaG0W4UeOfPDZgMoZ6vmrPJ24RNyg8BiivNFO2
oUMpKxwhlxmvNEpBwdZ8z0T/YbvzilCJdRhcqPoJPBLPUmGe5fi40B6+Z4nqe9EN/lVkvmPJlWuelGVGQSm3NQGfLBsCGv7LetZD7RlTKATvXhM3WKvXDIvuVc4VMxSk
1YQBTXpsm8P+UAiI0prHJQ0+Ml9I/DcbQx3q0TuTd0sbgxDNL6+h43vBPYOj8fENvjIlOz4x3FKIk7te9x25b5xbCbbqO1KC6LA+SfGWMkBeyoOvyimvOpnDUs40Sr0x
AHwx1HNmj5VJJRxw5ns/1fktI+Q6llxABEdTA3m+YMtPsmAi5SHr2UPPRJQh0lGWs5ip1gYy7pJqRmKpFq3tjOZobURqxBYFZ3KPCAKZXEDkDiJ+p4aJEDlzRZbNiGBr
fnpXy/+WSszGAFw+sKLt6FuVVxybk18vvjHQZdlhZb0xnkBBbihDsAEys4so6MIGPuPIbbY34Z0ATgydJ0ofqtsdDQDf82VwiCTYmsvJrxcUb+0UoXQz5zAsCbYmn6jS
ZzRKvTGOeprfSkMgyOPfDMH2kBFs6xR/mkCOJVd6LqDNNl+Ymc33EvqCp8SyYAQuwiYtJOGg6J79qiRvSpRTYZlig/BEJQr8MKlKdK9uVKiZLumtBKZa0vKDCc4SfL7o
rL+kne7rDEzVIN7ELWTiC+u5ZhVpqCnAxoBsGNwYfDWlnPhEdXWLPPLUQTqiOD/+0Kjyt8139I0wTnsMt9NUAZmQ1HykAZA/oOo3mlOfQ1HnudOK7Axt16ythWDb7sht
51KuRikg3vbhgWwJtvGcK5X5AsgjLlOSCtoedD5jYM03XYhxPUaHROTkVa50ea+bTCqBGWPkhTrB1maCa144yAJ29vbPXF/kwiQE1ccCvSfzPQZfP/hf/IuVJvuGYtEk
fxlmYbxMOPqa8n6QaWRCmFUq3qf6eZb5XuCYE6EJLvy3K7yTf0vMchAf/GJYTKvQ2c9YsYs177vpApcwIGPlNHTM3CtXZOGRBHCFT2gP8AVwkVazYeguB/IMHDOwQkbV
zINUUrROewP/KkeLXCbNbqG8D/7In+FZb+idLLbODLE7K0WH7XugnAIOcUv68ak9djFkEXQ+DWSMgRFIoJ6ogfRcyYli8lUkA3KZiOycpmaN4x3ztp05dZUPeb4vG2ZN
R8g1b8LWqRnGYZML0TpfhdTRuzQqPFtSkxZPP8Vro8C509qiMljPQZLLoRl3zCvQUJ9z71r9k4c2BRmivStQILgxCBEkXBsBXEPBWMmXWBe/8o0YtORWgWAQngz2mRqU
IF77kNxWqFDbTBA3/eHiQcdeWh2eafpbCLaes55zRhoNZp9w5iosT4/IEWyDAbkKpnT2ho7mTFN45IxAAvWkBZu9dreJsY0EYCQFWzMXkRqWP1sky7QpGwvjjy6pVHu2
WcPf2y9+aAtLwpFb/TE14phWoJid7IlS9nU3iY0a0Xdqk9IK4POpqGmeRLB+8bY6+61NUWW6//FJbeGlDy7f0XYerqS/WVsdPRdf1m0MQjdRLUCw0G8eLJJuiXoL8vgv
2EEvkiMcmcdScQo9DRqafcih+X49xSBPKVKumstYbB3Qx5RxyQPFuSJ8NF0td6uC4rVbbBPJRJWJryXY9heWz0oE9EfOkm5akhyBBOpxPxqoC+9fnyJ6fe2Cbd3cqrwE
hI8nTFwkLy3z+X3r5EMmd8SXzZgRIz1UQhE/DEt4J+1Vp/NY+nvxoKCVUzKvY6uxG+mvZ34NqjJpueOSzTe/O2GuveyVfcR336UM9yZV78Jo6QGM5CtdpJhad8Bnxtax
LzFi0gDaWQmCb1DnBZue1sWu0PHv3bPW7F5sbORwdA4/EIolJ7AKUBiu55t3iVP6UrsNLbm0mgIjdgTSqHfVrA1oNOKTJjPTlCopD5svPFpumbfdMYpdNP0p45zx3L6w
L5uyB//wgU3xvZeVEI8nZT2DXDlqOPvlKRhLfK3u0qoOIg4/AUZmPUtRFTRT4sp3/n1PMSDO1HnfZQvsM4bqbocg//iBZ5KUyniT+G6Gvvk7fxLTfca/LqxNAm9kY+Be
gvCSLI8CcrjR1hW0Y4B3/NS1YKsZmzzXNH9kmpIjYQTSqCcPhpkrdtYBH5DHcQTFQRmptCsItmJ5L+wnxWPhAPWenxR6HzMQYIqE3Dpxhp9M9uDP3xjToEl7FY8nZe05
ZDP5SiQAcmME9fjV8Zgz1XKvnVOvDrMItwC2GArfBGxvDFRb5+RMzbL/RsisWLDsqn53DKXtdGNQtbSNfyMbg5OLwR75T0xeZPSe+j64MfD9hAc2ntw6+Vfs29gxQDpm
pn/CmRNqpv8awbY8/8+VVBrxNrkuRleBNOoV9KT2XPBKsC3PBpI3cuwS5MHyTGHZNOyVedxlRS7JyEQnv4jWAC4saPfqhDg5l5isSv7ys+Pn89+ZUfbHUU8x/E61jkYv
0kd+gg8yFH7DpP3ETbcO8mTMJUCVIWJjiNA9IbiTB8Xul2y4nW4MAv3kxiBTu99Bxo0jj6WvXLr11aAjt+R61AIfnbRk5tJiKJil779svo5D0+xSzcl8eSpPycj5f414
m79ARkXJNOrRDQm5/lmRwYAzD/jk0nzo7beLNHxOghbFadgr8/Z5W8+d1p5rs6XSJuEomeXtbf/rd6yBFwQHWgsvyGK0sE3gp3O7XHZt3w67AL9KCxaXcINEhhvPaGno
6+LtOCxN9A2rRd3J1qAhzQjSH+5dbUUuJzeGeJ4oUTZ62tFUzkQ9jbBTM+CFRq8geqUfT13sijiyTWalQOTMRk2/Kl9eOq1AxfJe6av1ymrE247e/qgonIV6nmmsmFgy
X3CMfJLiUUD4uOcgx7W4ZPCi+9fbdM81cVoxag7kadnLQc8fazkh+9p0g1bQMYfISODlEg2R058U8KZ+o0iqw1MFG/hKK2RtKAwwpPUcNF9U9G3W1rhweteCbZ+5YVnQ
f2Xps24qKpyBcHyLbAyRIRLe+agnnzt5/Plcm2+Sqk9GPkiHqZOI2irgLJRfVvE5YrJEJZ9dnhQsE9NXboXoVX55fGlIX838rCRZjUzEM6ERb0cFkHXUyCzUo0a80qFg
ZgIJ8uSXl5RtlWmqFZDrop72Upvufe+edY5/BreTc9Rf53zP+nl3yFjZUTxpATelL4vcaAWXsv+CwqxhicP6AIJ18aQKjONfh8UoysXklQrG26ly9RGTDoNQ9yKDGwOF
K5bX7tEGTPjtUc1SfUZQz8TnmpbQO6nP5AMkhz6Nm11G21jdxqBR8g3oGiVsNcU4eH55DAt9sYcOSV+YK9WzHFbUjHzBNmneRcppTkTrCFNGfuFc1LNc3vuMYBs5XVRQ
iGCrwntfD7A8g6GoYyJ0D8HW6PJs4DMJSxCIAGVHba91BSUJxpNKY2UWHvfKuUwuF7b0WgThHiyALxhPKmzVJS9lhUDYL54vEcPlgG0yqTgIbidfgQ/++wlz4y41bRvD
rK0OHFSVl8BB7Bo4Qo98UiaH7Yi0Dq5RxnRHI6aoZAV1cNE7cWR73+JvFfMNGvKGYTD9YDVGCZVFxJBlG39wSPwvZbJVPjz9I6Rc3dOngDOMGBH5QzNT5//5fnnOjRjx
GLru/DpH/uIfty3MRT3twySndQTbONET5CWlYNQxdXSP24OCbbHDWxLQF29eQbSGYkjMx8STykklEk8qF5Y6BbwWsI3LJp608PJtuU2AgDyCxew0A9SgeQAQDYsJti1Z
Hp4bIXrqnU33gLzgEEkYlCsfaMKRAE7DtDHQ6+DGIEYmHxTq0d8Kz3BIHODoMFzVLJ9tuStrI9HtotUOrDPIn72hiB0OWqXl4oPka3aLYy6Z/9iaXcWQlho9iJ5GJil5
GPMFhZPKGeQbf9zGLViMmY7noh4dxktTFoC4YGumXVywdSbc96ev8+keC4NI+6BgSzOc74PApwUmZqd3FownjUtk/Co9lBNxoXA0LWmRIJ8U8OiTJi2CvvkNVvvVKtOX
pLuJmXmie3Usj+xMzhMj40Pv5IcobKIvRQTLwcIT2zAyvhGgB/1RBGf2G5TOVDYl02YNo+/8zJbzicmLt790KGii4UvHxQeiJwO32vORqxbqETl+eZKCk4ItxZZuO+Bs
xmNm2Y/zjnSAemIETzz9UnSHrCy2lWBbmC8SZ6dt2VuIzC8fKA86sM7VvvaxTZ+6PqCzr8vECbJ8/oalPuNjNSrEyixpGwSFg8aea8u29t9S8yWdfp3JZCCvzmLr94X0
IROtQYjMTqHMw2v2BJBCyVc81dhHJy7yY4S1MYivmccJBG3eyhApa0DdEIlQOwo+qtXIK/bZfxBPpAGKLwz7HnrGH140Gj1tMCJ6a7a/Ugq2sewY5Ty0M6kUHqPxa2pz
COQYRccOUI9VgfosenBaW8BZUrBlzgF5Gti9B38t3z1DyngcKUacnOnFIqk/YuKSX2752OQlPvDF3508LShTt575ntUln5XMaSAROMnynL7QWbrsyKGRJ1732OaPTlrs
oJ5YXjBG7fH1e9kYfOw2jo1COvprBFvzdL7kb7N5+GMlJWBwiKT7C2oqBXlz1r9U55cHy3PUAphuT7+xkIWpEB89PTEJYSqg7uQURjlIZ+vM35nToCk2MkegA9SjA477
uz17fME2qWGhgCihrCL47jmhGk9ueImw08LboxQGjS+bs84Vo2YsHohy6MXzA0hFmmhGJJbAWHVz3iIVgrzEYExdsMNftHV9oZt0duGGl3IeoTKgCZHL9sYgXV5QTuT7
F189zFPAYl/5WMFBaaAIwpOGKL4xmP0jswsQwxjL8wRb46Onl6vZyEMzBNv+TFPJaalZLcmmsWNkvsrRVawz1AuGOhrs67fYZgu2b/z6CCzPSMFYS5hqdhgWmcHxv5f+
q47lkUvdWeco76knkvjEeUkS32Sn9i+FbalM8u1SBkb81VtXI2BGaGnxU7sESjftNOjJB6mAszHUQR5MqnD9KZ8I8IHI4HLcTOw0IJPrJbNsmWrBLM73EH7VwbRv/EED
cPWjm7hFpif85+shr1+1orMvkhZbzWQFlZ975yrsGJlvoSk2ukagM9Sjb+dNW+3EaZjN07LYpnV5GqYS8vrVK4R/cLSV3MRUoFRXLxB+1a2NoAVz7fP7pU3PWdtIZ8bV
zkc9BdInA7NoKmv+XZfM+/t718cttn5fSJfUkWxrTzJtDMDoxt2BsxPl5ra+dfaQGUMYMdl0cnBcz+pCr1e3EsSFoZwrt78asdj6kIeL0n//2ULNDSkK1+98Lemkki/Y
MpMFefJYCAbMja7l3bQ2OAIdo572WP98ZWOxNalrI9PREmxdfJSHlD3hjPOqL9jC8oKQ9+xLh2A3kBo4FzlOHFV9cCBAPd/TQiZI+anFAQJYhOIR98pD5WYRdFIJCul1
/nSZUxYUOPrH84Dm4K5QhuUGHLzJxswtYLRSPyWfZWy4QdUeleg1JfcYDRTvhScGIK8+26BGSdxQSSXuWFCcbZCSWAvFcY7F1ij+CMj1w8OT49MUGEUj0DHq0bePT15E
PHY5SyrM2vVqIUHEXZE1q2SxbQm2YSOanJZtxRwR5ui8nEycJvmKs9rfeOuIrRonIuLT1y8lulNexHXvRh5nTvwsa1hWwoh+h59QI5IZyeSPqsukElznUuf9ckVhguj6
AzRTiZ2ByoxJ3Sit2n5AajKkXQ1O/OkaH99fz5hl6yJATLW80PPuWk1YHgMVPwXY3zAYpf98+YIHlhWjJG+VL9y4LOkewHw7dPhIR4ItJ0D6seFdv5fmxpE5At2gnh0A
xMQSyystttmCbdTJgGlHbkgnwoEMSx+4vIxjbbm5Xd5KvmKjnkbZZz0/fnATxA2WUXdKg26UpwWLisLyX1O4rv/yBIjgBXjXnw6+dV5Ppo8h3aFTlz1YpQIeyBTh3Egc
d834SLAF8qYueMFpDCyP4HzbyItIDhgBSXUJbNQwufg4sRl878dmOB1hrGR54PA2WhjJnFjHkb948/K///laVavgaJNooEakaAvITc5M+/y/hugNZB6Oinu7QT06xmqH
7rWbLxLeT7A8KB6ZV/gj6Tpw55NFwlFHsXLeXWvACAyjtsXWXtKFYBvya2GFI1qy2mEZ6LOwG6JXQkqqs/OacCv/FXILN55RAiJnU9j5fiOCbdDHkPX/Fz9b+I3bV/Vq
otgbA+NQOHh7LntPbNhX7AqhKFdG+5TJi+GtEVKsWAv6rhA9AEj5GuqoovGJQfYXVefpdX55dcYfnvjJa5aIpysRRuSEb00tmS/4BPPlOdNPkCeriIhecypQr+bkyKyn
S9QT3XtkdRESVKYVyGJ5yLZJLQwFRB6/XTqO2cDEvCeF5ClXL7EZjUG9ajn563nWViDPBkdux7mfYxlYrtjpFEhPjxRYar8nfSO3FYqhIoQGcmQPt/ttSFhs2084FMv7
5LXVYu7J5ND4KHFDWLCdtRWWV6f+QzPAT/BW7Az0FKzRoT9+2+R/ZwYtuDeAiWyNUEjxO8PQC8x1DntskfegJpRm0Bg1Q7It9i4/6VkLyPozqUTy5dmoZ0Me34voxTlv
T15WU8kwjkCXqCe6B2rkuCIzmaxQjQQllMUNShiUc5n3H5u02BZ1tYRYsZHlNHn2dn+l4cnBLRAQ/N1YmZCRz9+w7NSrl9g2XP7Ll2i+vnnXWpCuUzcLURu/YYK8L9yw
NMeM0NHkoEJo0bfvXusLtrA80D/ovQxeQ5PtIWJYgL9PXbeU0UDy1blCyjUQbI9i2rQ3sJHAYeHUjod5nWArYTwIebfM3faHP+4/FipHtlWKUD5JecKYL8rCfdwoooeX
Qkdj3hQedSPQPeo52r26SSbzRaZgS2Z5QR4SChVyALkv57LwkE9t4KsTbFlOS57dz2r3IY88LkFqhq4QaCC8wb+l7sCayKINrnNB3meu6z3kafLZjM/0ohJsQySLcShY
nseR2SqojdZqVwD67S0BzkWYh9kh4HSYjL5+e5F4Jni6OVVlBpyZNgO1NuTJblsv2xYsT5lU+Gwr/d7jl1ge5gtTrCF6ow6/umtw96jH8yxjbniGmYCzHF2eBFvOErIn
q+y5vsSBDgvlPVbLwmJbH6Pmn5bNooLlRW4JQl7tos3OpKLFTINpdk/MF5H3LeDDoVeiJZAH+tcJtg7LU7EnNtbeIiinI7ZOk1vuWbqL74OjFzFfBFkehPT79z2FO46d
M4LgM/+gW3uqJBPB+4KtpGBpXRqNXncIMhrvGhDqie75vntmekmwdYDM34HNQQewPEfxhwYHe66iI5zxJaUwNtlrH+8/MtUsbJkvfJZ31+JdKLyCkHf3kl2kovMXrWwU
HTnTcgtV+bcgIxNANm3BtiGYKIYRP7D6RR5Xp0qTLs+5/HwtrvLUuwXLSUdqTVHLoIsPSI0kC2rbEdkYT4hWJAGtN3n6Fcoa1STFaxds+3frxnQ7BNNyhDxiQKhHH0g/
FTxS49m9RYwtKMYfyYlozLulYFvkxrBvUfa9YFg7uiRwBP29Y1twzBdm0dY5r7EIwakgNNQ539UtWunynKpoHo2kqfmxED2ZHyUjnueQMrUtLtjWoWQQQFEL8H0dR45g
rq/Lg0KSH/TLt6ywNzlZja2zvV3Bot9i25lg2z/N/AyPPRn/ppKROQIDRT2FajjalkzBVlEcEmzBxwg4Kj43eD4GXiZ/eeMyxEaztqktoMubtbULwTaS15enTF/+oo8O
OtTR/p6G0TwamYxbGIwpMnvtboaOPCV2k3zzhX5FIbBtb18Q8uoSfJH04cnQARdUEvfL85/y44c2YQm55ldFmK35SJ7gcJX26dEPWEipFO7IYusXPnPqCrjksLygwXjp
TZ3xERgo6lE7Ni/mpTmH1Fhsk4ItJWGCat/e1xNOLedNKxIK1PmFEbxx1IS5X7pl5aLNr/i6PAyaPKJOSg0KtjfOLcIA8tMfsYZ1XKH9FCgeJ2DQsF+UQQXD9UFUJLMe
aj7jMffmWwH/lYRgG4K2n/1qW8XyPGNIeMCNYNtenoEilPiPLpnncGFFuaHOq3dVyU0eZR8X6eyvfhDkcL2p5rlDMwI9QD0lYmG3ZDK1W2zTTnztfsux8lhdUe74aXjN
MBWZze9eQ2CWw2uCIqeIBtqoOsGWaoOUR7JhnQBof09CARrTaWqTQXrrCIwkK+U4jgkPPBOw2M7aivmirsv0N/iTBNuOZOHgu0DdyUCdf89aR3Ur7zy0uvaG6jA+nQCZ
74rcsti2zTT87VEj9tyLaJBeZVPtwEegB6hHI5SjCeVIRdxCJ0D6AiyFffNFnbqa+c3OX2fZMAOBxM0MJtcua0kLsgvBto7l5RzqyBN5NA2gGSPN2ZX24BeNuO140sWN
vMi2PrSR9GFhnWD7cmHk9W+BCzsWW2R/GCg5dZZs2utMZYX9BiPPjL1LtyS1xiaTSrCwlCfJMOSBr7SmhpEzAr1BPeYoGhmCmQ69+ZaTPCo0Kfssv7y0rePF1wp3YsLI
qerRdYWWR1mhIoPIJAZ0YBBXP7aZBML+Cqyz2FKyzi/PX7SmWimwENOgmeAdZ3eN5FXEITtktQJupAmNsDyNsD96cOQIy8sJOEPWxrzzexPmctJ58FXKIbnGglElgqcN
+SyvPDjNFSZgkdjiGrfkkYNHQ9OS3qBeQY5SXiwG/oJ+eXU7thUWXlnuWAmsh5zslVCbb91Z6BzRGTnsJiLYdpT+SCLblHnbeQQP4lDqkcbvgtMIoCFbgbCP+IeglIpO
MwhtmC8ikBf5SRZb8Tvw7ke/WF+3dcloGwm25Sk55gvD8urOikQt40Q9Ds2qa54yvCPQM9SjG4qcDTlVtbkaUFIW21RMbnEXgm1LMOnfqHUcfebZPej77l64HXU+1A9s
OueOdXxTuFl4CviO0h/BVpBkT79pBST3g5cv4BGjzgII6Dzx1O7/+tMn4adYXeyYCqA/KNgCeShYOzLyShNK5Sg6Ea6B2jp+p5Wg1F6e0VazpT+TSs7kiUenyYgRdAwY
3jXZPH2wR6CXqMeyx/wvs0bwcgLOaopV6NYSbPGeD1g55FOaCXwaRJpHgrYzbym293ddOh8JC4EU6qHVnnSzoBiFuYUbuZ1KzpqyggpHHdj5Uwp+imcf/ItQOTpYF24s
i22d+SIo2F70i01Ekn34qkUiwknBXxIDwW3BudFFJhXOBS+rcqcQRmFkW2LJGyPGYEPMCKy/l6hnNmriZ/1Zawu2yY3aFmzrCkMHut6rWec4u3Ck7P+4tgomRRn3Fz8r
3Duc6ytTyExVHWJNYW7hxlEhxnYx23AcuXjm+o9OXIi1F16sXUEe4Jgv6iDPloUpzC3QOu0NpEsR2OWAi4E8z0+lLZNKcvIw93zFiDMhm5DbLqbHmLmlx6jHuChaw/c2
kGCbM2XbBduYIKwo3SSDyHlbEBzllfKv/OPWch40KsoUp9M+s8feFT57wzL2AwTh4mBG68IV5oqHN/DTn/9sEVjJ64DZaW/oaNwEeZ+tcc3rNpNKgOUxuyTbdiQojIq3
1jQycwR6j3ryLDVyrmBOfnnKpBK/LME2UrLa/Le/3Cf/hp4AX+aQjcNiSqinnHpcVz68UdfUJ579+ZPbdVhw3ZGSOcNVA3nVW+7PpPJyMh9tn1heS7ANTKFGts15I2O7
TO9Rz8i5ykrQHnCWmLVJwcSygVTHh7/wyhuogZqte/RO0xyWl2OxbRdsa2fauWWQz1jVUYzeaTCULR8U1KMDClPDnqvOZDjxORbbBCXcc7DY0vkw19m9Jeo2MstQTp2e
PEuQVx9zVu1tSRFBBcyUqCsvt6fGbtuTdzd6Kxks1MOySRoo4rHy/JYrShgRTOx5LCnY8TuVcaMBvlE0FxXSA1WvC7NlPtCd/BSh5fypZXnySf7iTctyTCujaBibpnY6
AoOFerRD2zjGsuRGzckbyV26VUm1+Qf9TmWYIydVM607nQdDX16uyJD0IOTJfJF5jm2OxZ/5o4T4HdlYhn5YmicOwQgMIurR+qtmFe7EkcxoRheTyfIOlmmF6lztqU1h
lcmQtSEY2eYRdSPAnsTOVO+KXCWC7+gc22DAmb3dyrMd58HmvTQjMLiox/xGoECsqAvYsM8hNc73dd7LnEwkRV78ku4mkp2leevDOAKoPmR2r0vB3ZGTiuYP/8Y9ouSq
cvGMp4ax482jR84IDC7q0U8EChR8CBe+IJMv2CYDKg0OVrN/56ugHictNB4tI2eqFTtW+V7i9D9fsJX5ImneZcdl3yU1RqP3GFGTYRgbM+ioZxR8eAwY3VyHgm3hhIW/
X1KKoVp8u5CMeOiq7ftxeW0MdsM4t5xH65AzcoXVHH9RZVIpBdu0X6d/wllQAmCvZcclVrpR542cmTDsLRkK1KOTstYZoSbHL89MYgm2EV2eDaaCPH3DjFcGZkSqMRAt
O+xzpesGQLKUOSpirs3xOzFTIn/+yDuvofxdv7sxeeMQoR5jJw8+lG5GsM2JTrMVfymNXti3S4fqIlgN8Uk9Y3K6dNEpSBanxfMK4kfZSrDNmRKZgq0xbTXeeV28tbF9
y9Chniwb6PhYBimLbeVy9fLrJJqSYJuwYFCA5OC8KiRcvzAi1QlXLZS02yh3hnJCK20UUi32hPb30u9Vp0wqHVlsg4ngnfcuoxbZz4ayv82zRsUIDB3qybLxvp8Uh9vW
n4TQn2sgW7AtAFEHZUXA0ZZ2GxXPEEzN4hiTkt3jkRd83b1NBO+8evY5Ho2TfLPJDcG7HnWPGFLUK4CpPEkyaNItJ24/y9NQ5rA8lcyhhOz/GHZpABxk1L2qUdRgDBey
1U5+bEv0DRZKiUxX5HzBFshDpOBFN8rcUTRnhrKpQ4169E0xGwBf3XrIFmwLiJRgmwN5O199kwW2Y1/f124rgnYxcTQh6D2faobiEVqbzKrNWShdCbYxdQek/qRJixAp
Gkbf85c7ZiocBtRj7OTEEAxWM4JtjmI7KdgaYAXy9M74gy8xcaBsajR9PZzHyJLS4kU8kG1ru8Xl8zPxJEoCeXKBbixXPXyzY6+q4UE9xlFhmA7wvdYKOONc3XrJqPiJ
w7HkpEImAls0Dt4F0mE/obwgz/FrQRZrPBsGOLNBGRlqv3HHqojSViNv8uUFTU/OGzTRF0ldB5B3+k3LGj+VAb7K8XD7sKEeg6soXQN8Ynm7DySiizT7BXlJv3xz4n2d
8ogzfD9Smncbgbe76Y4gKasFqBcPuO7UfMFbRteRqb6g8NduW9VAXncvcbzdNZyoZwOf8uXlqOdyLLY2LxA+2izPZw1G4GUBNyrwzDXAQImwE/mAbPtsjJ5X/LqjGFuZ
L/hg40qqO9SSxjUv892N82LDjHqM/g9nFF77Ex/ZwMYeFWyLleMJtjHFNkgHjOLyF4e80nDct/WlQwogKdRSj2xssC+yMAzeFb7HDz6959U3crYrCbYdBZyl/Dqrt/+T
h57RWxvni7npfuYIDD/qoQX/cqmBvvD+9UndjSXYpo9Q0BCkIK9ylykW5G/eRielJH0N9gUnkI13OOJpb2C7Sr64jlheJwE5h8TyGsjLXPBNMUZg+FGPRgB8Z5TAV5eC
VAJOvsU2U/GnanWyB5TQiFE29hFA2ji4MD4O3qEPFTZFVav9O5NYXhIcVaAl2KYDci558OkG8hog63QERgTqqdGOccNZIa/0FYrtlsU2KtgeOMwCyxBsizgQIA8xisLP
eaFsNvZh6xi3dl7ss7JXcJGmvzTRFllwGLSS5aVJtwzoeRbb4i3HE8EbE/xf3lhYbBuW1+mab8qPINSLAJ9YXkkrEmvM8ctLkguxvIjvC/4QpIqRcx8+Luj+xonKj27i
Vil/FLpP7gDjkqJlM5iCbYLlGb+8JsamgbAuRmBkoR4dkJqGBEEmC6kgL0dfbgTbpMlPLE/jlcMf8aeB6513V0V54D78d6zGeELulBiKixAL/FHKd2GCBY1gm2R5laya
VK0aByNeR3KjojFieeOWfXexzptb7BEYcahH42RLVayuBFsgD+ttfD3IvItwZK2xulv6tu8r/JZheTmQt6uM63i9OH/rEHwH1iPqJ/FqzIQB0BG6o/hZOoiO1Q8pswTb
OB0rzOISbHO2K/vo7viOpRjbBvIaFBvICIxE1KM/itX9q5uW4QSbdEW2/ZbjtMJ2lJVgm2SFUq5j3nUwl9RJ4MJ7yhXIBTkajewPumqDHR0hD6vvbKwjTVqCbSzxV6eu
yOZsgByWhwmFnALE2Db2pYGs+ebeEYp6Aj7mN7Dy6Lo9cZa3s2W+SAlHBQHZ9Wpxli6Qh4RbX74iiTqSjTi5SM2CP8P+sHugbBrhy5Lm0UhjozBgV3MubUXcGAqGOjnI
ypfHJ0nPy+gL452e4PLKlwfqNWkFGtga4AiMXNSjY8xv/P6Z65FQJ2O+iBg6IBTiIKjnRNxS57EV4psgz2d5wWVPyad3FMKvDuvQBawALpCpYdcA0gAf6bBUTHx008wV
u+oIr03cOvI7yaHn+SdAMeByojyjyZc3wOXe3F6OwIhGPdrHcv3SzTFXvpyAXINxYnkptlJprDIhj8r3tsLpBBMwJmDaQUAgxoDgEDBBNgzQFsxF9JYdVtcJExeBID9f
vAMTLXtAzlDkxP/bI8y45egNMv2WC3Pt1BW0nOidYd88GtAYGyMw0lFPwCdXPicXqfLl5aFYv2Dr++VZK78Q5QzLiwu25i5BnmUVaZPUWLRoo/B9wSp90sRFBn34QziI
AQFsklCsK39iAW26BRcTaqAqKrQxTjBHEAUNQBKXAMuI8Yg9r2VBXk4Us4aiC8G2FXBWK9tiu/hwmRui8VDJnxVNyeQIjALUUx+Uko+DTQER1pgl2MYsEuIg7YJtrfFR
DKVTwdaCvIRmipIADu2HCQoHv3rrSqMQtAGx67/Pvm0lzIjKeQQP8vV0grwclteJ52PRcapFsM1heZknnNEFXje63TFjJU+uxqbA0IzAqEE9hgNSIzUfeclzBNsWHSuM
j3mUsAqHaunyEigmllc0LOMwoxJtakU/HGIAKew2MDIw675FBfu77vEt/B25wIWFm15mWJ5/OcsYrdPpkpAn5LICzpJ+eeHT6eqGxRq0cM2AtRR5HHzR2C6GBgjG1VNG
E+pJ2uXUq9LmuHrNCwejcFOtqMOlFBwVbKsEBDkW2/KJRc2WYJsEhUOIcjS+DMlKI+nbb//2jV/nhKz2IVZzhhzNzoHdPMG2al4V0hez2PZ3RL3Lt9jGM6kg1aLKkC9k
o8gbV2A0ZJ0dZaincVGmcsQf77zBfukVwiLB1k4rEEEHS7BNo5iakePhLNEPIMuxGmeSR3GxVqr9t3KEyq4F23jlskhkmndzyKMOL8YPuYm7GDIIGIcPGpWoJ2n3Y5MK
4wCm0hovsyocCmzKwYVi9VYeLYkg0ExsEsJKsGXBp9pQJM4EHPlEHQmrttEpTdacwptLbEoKtmpwDjbZqgP1LodsqsF1JZHxZavFZD9OIp3HIdyMkC6PVtRj+BB/lJEU
M59MHLqAD7BAgm0OHVPAWVcW2wQrlOgHShq5uG7NYwDNEGyrxxnBNoWkhTD+Uql8LC228dYWv2bmqlEv1LtkjG1p3i1gtzy6O9wGKB7MvbHVjhBQGPPNGMWop3eDgU8m
DkP6jGArBIzTEGPezWcrOUhqBNtktWqhWF6ysCXYZtErcxRJcig6sdgWo1pQ407y5clv2X8dNsVrDBdjHm5GSAdHPerZpO/4qxY+tnY337QCzmqzD9jSXGkNSOvyyD5A
zfsyMspBbYRiL+znSLYEwyJpvlhe8lg4Y0KhwclU+xSmqbRhf18yBV7RwjziVpTs5ISzIg0fbagzXzQUb4SgwHhrxlhAPUP6Pj650PT904ynlm47UM+bKhjSgpSTSpIS
6hE5XMwQN5kvIjWboA5qzkExm7glW7LvUAF5mbo8EbfkIGig8ofCTgTvVI5GQoZatHgNxRtvoDPs/R07qCfSpyxVKIlwc4tDg4Y+aaM0DAscycEFmS9SRoYKeSFiGYUL
JZpc7TKdVFQ4CdO2X15PLBLOgAfbYHzxMNTieT7sC6BpwDgcgTGFenp/cAe8+WTlCLq2iINkIogXcFZr4W0XbCOG4MrdL0OwrSpRG3IF25LllYJtMgVeZbHNy6RSISmG
l1TNVbV+Ingj0mKGagy14xBuRkiXxyDqaWRx+Dq5dG3BH6K08PqCbUzjJh6kqjLNF/kWCeP70nPBNtMvz+5dvRG2bXxyyKOtLXWYJtuPImoRaTuKNR4h66RpxlgagTGL
erwkBF78mZX48/vVMTdZ528JFCy/vPQp1HmCbaVAzPfLk6tdJi3NFGylnjNKt7jmUUCWCXlU5Sv+2HLkiIepvfE9HkvYMXr7MpZRT28F7NNZHApyen6f5L50ZFg+y5N5
94VX0xk3QdIMvzzjeNingLMcSpgXcFbVLMgrBduk8ZpE8EconHfCmW2x7TN4hwqP7acJLxu9MDHGWj72UU8vDC0SCdqEfUS2m+O+HBWVL9gmLRhieUlVV2GxLV1JcgoD
RrLYZrC8ArZyBFvTEbUhQ5fXGcuzM6kYvINoN3g3xiBjDHRnvKCewT6l6otgnx1wlgl5Mh0kC+cLtpteqrKYpGzBBTC1B5zVCuO2xbZE3ly1ZiucLp1Hi2pLvFvJ8IJ3
MOvGZDEGMGLsdWF8oZ7BPiPztmwdbdbS0nyRFP0OSbDNsZbmBZy5gm0O5HUUcFYJtq8mfacVcFYIthkBZ33yW569drdc8Bp+N/ZgYoz1aDyinsE+nPtk68C8SK46KZ5k
sU0St3bBNgGRGebdVoqnlmCbbACNtPyWk8StIo85KCbzRWbAGf53yLBK4IzRvJFnxxhAjMnujF/U0+sE6fCVVfoWzt+65MGn/UNgHZ1dRwFnMl/guVZvkQCwKszK98uD
Bir6IpVWQDV3cDStEsEDeUnzBcIswyV1Af4ojX12TALEmOzUeEc981LJYqAMLlxIalC/ugRWlnouZQhumS9yjLCZiY4FwZ0GnJWKvJjTsmPriDBNDEE4G8v5Tmbxxv9u
TELDGO5Ug3ptLxftOzKaqJ8sHk50h0kErzDbOijpNJOK8uVlWGwL5OooINdyUknkDYxnUtHBb5z1YcgdHLlxRhnD0DCGu9agXvjlQv1gMdL6EdUL/M1as9vKpJLOPJoS
bPtrAPL6fn0kxy+vXbBNtAF8BPJwasmJsZVFohRs2wLOHLDD8w5laJMvYAwjwnjoWoN6sbcMl0FdZSTf4y6b/52710aEXyeoI1+wzWR5mYKteKg69nKRGiuL5dlSsMRY
w+wAO/aA5qyy8YAI46GPDeplvWXBHyuf9W90f6R1sXM4G3DJsNh2kwg+U7C1/fKUy7Pm6hfPxfKgdYjzJGc1Ojtssg3YZc2PptCoGoEG9Tp+XSjvkfK+eNMywZ8SHAgB
Myy2/Ri05+CvJdhu35fIYtKhYFvk8iwF22Q+0UOcM7do40s3/fOWz95QuNoZnR3KzUaM7XhmNDeMkhFoUK/7F4XpQwRQyV0qBLxl+WW/3IAUHPeAyQ44Ky22pS04P0Vo
XLAFnZFe0VR+6vp+pAPEgXJk2MZA0f2EaO4cJSPQoF5vXhQICGQAHOfeWaT2MxdOMGjHYIIIj0Yc7uSEsyogNwV5LSfnt4qAilKwrb7hoUAwDaAZRnSleYjqnCwMp2uQ
rjczoKll9IxAg3qD8q4QD6GBgCD5TXWYkbmwCwM359+77rrHtxg0BJuC7oFWwFltuAiWB26fv/Hlh1ftvGfR9qlztyFxK7mTfUFIaYxgrgmPHZS33lQ6SkagQb0helFo
A8FBQAeJ+Ly7VttCsQNPRld41tSV35m2+mu3rSKeX0BmruAt5svTb1oGwIG5wrjGi3iI3nHzmFEyAg3qDfOLApJ0gVDmArDAu8glRNOFt7BqaOwPw/wum8ePkhFoUG+U
vKimmc0INCPQoxFoUK9HA9lU04xAMwKjZAQa1BslL6ppZjMCzQj0aAQa1OvRQDbVNCPQjMAoGYEG9UbJi2qa2YxAMwI9GoEG9Xo0kE01zQg0IzBKRuD/B7Vf04b42DWN
AAAAAElFTkSuQmCC
              </image>									
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Terminating cabling in cabinets</title>
            <content>

              <para>
                Having individual or divided cabinets for each classification prevents accidental or deliberate cross patching and makes visual inspection of cabling and patching easier.
              </para>
            </content>
            <controls>
              <block>
                <ID>1098</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Terminating cabling in cabinets</title>
                <content>
                  <list>
                    <head>Cabling should terminate in either:</head>
                    <item>
                      individual cabinets
                    </item>
                    <item>
                      one cabinet with a division plate to delineate classifications for small systems.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1099</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Terminating cabling in cabinets</title>
                <content>
                  <list>
                    <head>In TOP SECRET areas, cabling must terminate in either:</head>
                    <item>
                      individual cabinets
                    </item>
                    <item>
                      one cabinet with a division plate to delineate classifications for small systems.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1100</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Terminating cabling in cabinets</title>
                <content>
                  <para>
                    TOP SECRET cabling must terminate in an individual TOP SECRET cabinet.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Connecting cable reticulation systems to cabinets</title>
            <content>

              <para>
                Strictly controlling the routing from cable management systems to cabinets prevents unauthorised modifications and tampering and provides easy inspection of cabling.
              </para>
            </content>
            <controls>
              <block>
                <ID>1101</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Connecting cable reticulation systems to cabinets</title>
                <content>
                  <para>
                    Reticulation systems leading into cabinets in secured communications and server rooms should terminate as close as possible to the cabinet.
                  </para>
                </content>
              </block>
              <block>
                <ID>1102</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Connecting cable reticulation systems to cabinets</title>
                <content>
                  <para>
                    Reticulation systems leading into cabinets not in a secure communications or server room should terminate as close as possible to the cabinet.
                  </para>
                </content>
              </block>
              <block>
                <ID>1103</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Connecting cable reticulation systems to cabinets</title>
                <content>
                  <para>
                    In TOP SECRET areas, reticulation systems leading into cabinets not in a secure communications or server room must terminate at the boundary of the cabinet.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Audio secure spaces</title>
            <content>
              <para>
                Audio secure spaces are designed to prevent audio conversations from being heard outside the walls. Penetrating an audio secure space in an unapproved manner can degrade this. Consultation with the Australian Security Intelligence Organisation (ASIO) needs to be undertaken before any modifications are done to audio secure spaces. For physical security measures regarding Security Zone requirements, refer to the Australian Government Physical Security Management Protocol.
              </para>
            </content>
            <controls>
              <block>
                <ID>0198</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Audio secure spaces</title>
                <content>
                  <para>
                    When penetrating an audio secured space, agencies must consult with ASIO and comply with all directions provided.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Wall outlet terminations</title>
            <content>
              <para>
                Wall outlet boxes are the main method of connecting cable infrastructure to workstations. They allow the management of cabling and the type of connectors allocated to various systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>1104</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Wall outlet terminations</title>
                <content>
                  <list>
                    <head>Cable groups sharing a wall outlet must:</head>
                    <item>
                      use fibre optic cabling
                    </item>
                    <item>
                      use different connectors on opposite sides of the wall outlet for each group.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1105</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Wall outlet terminations</title>
                <content>
                  <para>
                    TOP SECRET cabling must not share a wall outlet with another classification.
                  </para>
                </content>
              </block>
              <block>
                <ID>1106</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Wall outlet terminations</title>
                <content>
                  <para>
                    In areas containing outlets for both TOP SECRET systems and systems of other classifications, agencies must ensure that the connectors for the TOP SECRET systems are different from those of the other systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Wall outlet colours</title>
            <content>
              <para>
                The colouring of wall outlets makes it easy to identify TOP SECRET infrastructure.
              </para>
            </content>
            <controls>
              <block>
                <ID>1107</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Wall outlet colours</title>
                <content>
                  <para>
                    Wall outlets must not be coloured red.
                  </para>
                </content>
              </block>
              <block>
                <ID>1108</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Wall outlet colours</title>
                <content>
                  <para>
                    Wall outlets must be coloured red.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Wall outlet covers</title>
            <content>
              <para>
                Transparent covers on wall outlets allows for inspection of cabling for cross patching and tampering.
              </para>
            </content>
            <controls>
              <block>
                <ID>1109</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Wall outlet covers</title>
                <content>
                  <para>
                    Faceplates on wall outlets should be clear plastic.
                  </para>
                </content>
              </block>
              <block>
                <ID>1110</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Wall outlet covers</title>
                <content>
                  <para>
                    In TOP SECRET areas, faceplates on wall outlets must be clear plastic.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Australian Standards for cabling can be obtained from http://www.acma.gov.au/WEB/STANDARD/pc=PC_2459.
              </para>
              <para>
                Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Cable Management for Non-Shared Government Facilities</title>
        <objective>
          <block>
            <content>
              <para>
                Cable management systems are implemented in non-shared government facilities.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes cabling installed in facilities where the entire facility and personnel are cleared to the highest level of information processed in the facility. This section is to be applied in addition to common requirements for cabling as outlined in the Cable Management Fundamentals section of this chapter.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Applicability of controls in this section</title>
            <content>
              <para>
                The controls in this section only apply to new cable installations or upgrades. Agencies are not required to retro-fit existing cabling infrastructure to align with changes to controls in this manual. The controls are applicable to all facilities that process sensitive or classified information. For deployable platforms or facilities outside of Australia, consult the Emanation Security Threat Assessments section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Use of fibre optic cabling</title>
            <content>
              <para>
                Fibre optic cabling does not produce, and is not influenced by, electromagnetic emanations, and therefore offers the highest degree of protection from electromagnetic emanation effects.
              </para>
              <para>
                Fibre cabling is more difficult to tap than copper cabling.
              </para>
              <para>
                Many more fibres can be run per cable diameter than wired cables, reducing cable infrastructure costs.
              </para>
              <para>
                Fibre cable is the best method to future proof cabling infrastructure — it protects against unforeseen threats and facilitates upgrading secure cabling to higher classifications in the future.
              </para>
            </content>
            <controls>
              <block>
                <ID>1111</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Use of fibre optic cabling</title>
                <content>
                  <para>
                    Agencies should use fibre optic cabling.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabling inspectability</title>
            <content>

              <para>
                Regular inspections of cable installations are necessary to detect any illicit tampering or degradation.
              </para>
            </content>
            <controls>
              <block>
                <ID>1112</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabling inspectability</title>
                <content>
                  <para>
                    Agency cabling should be inspectable at a minimum of five-metre intervals.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cables sharing a common reticulation system</title>
            <content>

              <para>
                Laying cabling in a neat and controlled manner that allows for inspections reduces the need for individual cable trays for each classification.
              </para>
            </content>
            <controls>
              <block>
                <ID>1114</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cables sharing a common reticulation system</title>
                <content>
                  <para>
                    Approved cable groups can share a common reticulation system but should have either a dividing partition or a visible gap between the differing cable groups.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabling in walls</title>
            <content>

              <para>
                Cabling run correctly in walls allows for neater installations while maintaining separation and inspectability requirements.
              </para>
            </content>
            <controls>
              <block>
                <ID>1115</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabling in walls</title>
                <content>
                  <para>
                    Agencies should use flexible or plastic conduit in walls to run cabling from cable trays to wall outlets.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabinet separation</title>
            <content>
              <para>
                Having a definite gap between cabinets allows for ease of inspections for any illicit cabling or cross patching.
              </para>
            </content>
            <controls>
              <block>
                <ID>1116</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabinet separation</title>
                <content>
                  <para>
                    Agencies should ensure there is a visible gap between TOP SECRET cabinets and cabinets of a lower classification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Cable Management for Shared Government Facilities</title>
        <objective>
          <block>
            <content>
              <para>
                Cable management systems are implemented in shared government facilities.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes cabling installed in facilities where the facility and personnel are cleared at different levels. This section is to be applied in addition to common requirements for cabling as outlined in the Cable Management Fundamentals section of this chapter.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Applicability of controls in this section</title>
            <content>
              <para>
                The controls in this section only apply to new cable installations or upgrades. Agencies are not required to retro-fit existing cabling infrastructure to align with changes to controls in this manual. The controls are applicable to all facilities that process sensitive or classified information. For deployable platforms or facilities outside of Australia, consult the Emanation Security Threat Assessments section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Use of fibre optic cabling</title>
            <content>
              <para>
                Fibre optic cabling does not produce, and is not influenced by, electromagnetic emanations, and therefore offers the highest degree of protection from electromagnetic emanation effects.
              </para>
              <para>
                Fibre cabling is more difficult to tap than copper cabling.
              </para>
              <para>
                Many more fibres can be run per cable diameter than wired cables, reducing cable infrastructure costs.
              </para>
              <para>
                Fibre cable is the best method to future proof cabling infrastructure—it protects against unforseen threats and facilitates upgrading secure cabling to higher classifications in the future.
              </para>
            </content>
            <controls>
              <block>
                <ID>1117</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Use of fibre optic cabling</title>
                <content>
                  <para>
                    Agencies should use fibre optic cabling.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabling inspectability</title>
            <content>
              <para>
                In a shared government facility it is important that cabling systems be inspected for illicit tampering and damage on a regular basis and that they have tighter controls than in a non-shared government facility.
              </para>
            </content>
            <controls>
              <block>
                <ID>1118</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabling inspectability</title>
                <content>
                  <para>
                    Cabling should be inspectable at a minimum of five-metre intervals.
                  </para>
                </content>
              </block>
              <block>
                <ID>1119</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabling inspectability</title>
                <content>
                  <para>
                    In TOP SECRET areas, cables should be fully inspectable for their entire length.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cables sharing a common reticulation system</title>
            <content>
              <para>
                In a shared government facility, tighter controls are placed on sharing reticulation systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>1120</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cables sharing a common reticulation system</title>
                <content>
                  <para>
                    Approved cable groups can share a common reticulation system but should have either a dividing partition or a visible gap between the individual cable groups.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabling in walls</title>
            <content>

              <para>
                In a shared government facility, cabling run correctly in walls allows for neater installations while maintaining separation and inspectability requirements.
              </para>
            </content>
            <controls>
              <block>
                <ID>1121</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabling in walls</title>
                <content>
                  <para>
                    Cabling from cable trays to wall outlets should run in flexible or plastic conduit.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Wall penetrations</title>
            <content>

              <para>
                Penetrating a wall into a lesser-classified space by cabling requires the integrity of the classified space to be maintained. All cabling is encased in conduit with no gaps in the wall around the conduit. This prevents any visual access to the secure space. For physical security measures regarding Security Zone requirements refer to the Australian Government Physical Security Management Protocol.
              </para>
            </content>
            <controls>
              <block>
                <ID>1122</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Wall penetrations</title>
                <content>
                  <para>
                    For wall penetrations that exit into a lower classified space, cabling should be encased in conduit with all gaps between the conduit and the wall filled with an appropriate sealing compound.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Power reticulation</title>
            <content>
              <para>
                In a shared government facility with lesser-classified systems, it is important that TOP SECRET systems have control over the power system to prevent denial of service by deliberate or accidental means.
              </para>
            </content>
            <controls>
              <block>
                <ID>1123</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Power reticulation</title>
                <content>
                  <para>
                    TOP SECRET facilities should have a power distribution board located in the TOP SECRET area with a feed from an Uninterruptible Power Supply (UPS) to power all Information and Communications Technology (ICT) equipment.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabinet separation</title>
            <content>

              <para>
                Having a definite gap between cabinets allows for ease of inspections for any illicit cabling or cross patching.
              </para>
            </content>
            <controls>
              <block>
                <ID>1124</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabinet separation</title>
                <content>
                  <para>
                    Agencies should ensure there is a visible gap between TOP SECRET cabinets and cabinets of a lower classification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Cable Management for Shared Non-Government Facilities</title>
        <objective>
          <block>
            <content>
              <para>
                Cable management systems are implemented in shared non-government facilities.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes cabling installed in facilities shared by agencies and non-government organisations. This section is to be applied in addition to common requirements for cabling as outlined in the Cable Management Fundamentals section of this chapter.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Applicability of controls in this section</title>
            <content>
              <para>
                The controls in this section only apply to new cable installations or upgrades. Agencies are not required to retro-fit existing cabling infrastructure to align with changes to controls in this manual. The controls are applicable to all facilities that process sensitive or classified information. For deployable platforms or facilities outside of Australia, consult the Emanation Security Threat Assessments section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Use of fibre optic cabling</title>
            <content>
              <para>
                Due to the higher degree of associated risk, greater consideration should be applied to the use of fibre optic cabling in shared non-government facilities. Fibre optic cabling does not produce, and is not influenced by, electromagnetic emanations, and therefore offers the highest degree of protection from electromagnetic emanation effects.
              </para>
            </content>
          </block>
          <block>
            <title>Fibre cabling is more difficult to tap than copper cabling</title>
            <content>

              <para>
                Many more fibres can be run per cable diameter than wired cables, reducing cable infrastructure costs.
              </para>
              <para>
                Fibre cable is the best method to future proof cabling infrastructure — it protects against unforeseen threats and facilitates upgrading secure cabling to higher classifications in the future.
              </para>
            </content>
            <controls>
              <block>
                <ID>1125</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Fibre cabling is more difficult to tap than copper cabling</title>
                <content>
                  <para>
                    Agencies should use fibre optic cabling.
                  </para>
                </content>
              </block>
              <block>
                <ID>0182</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Fibre cabling is more difficult to tap than copper cabling</title>
                <content>
                  <para>
                    In TOP SECRET areas, agencies must use fibre optic cabling.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabling inspectability</title>
            <content>

              <para>
                In a shared non-government facility it is imperative that cabling systems be inspected for illicit tampering and damage on a regular basis and that they have tighter controls where the threats are closer and unknown.
              </para>
            </content>
            <controls>
              <block>
                <ID>1126</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cabling inspectability</title>
                <content>
                  <para>
                    Cabling should be inspectable at a minimum of five-metre intervals.
                  </para>
                </content>
              </block>
              <block>
                <ID>0184</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cabling inspectability</title>
                <content>
                  <para>
                    In TOP SECRET areas, cables must be fully inspectable for their entire length.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cables sharing a common reticulation system</title>
            <content>

              <para>
                In a shared non-government facility, tighter controls are placed on sharing reticulation systems as the threats to tampering and damage are increased.
              </para>
            </content>
            <controls>
              <block>
                <ID>1127</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cables sharing a common reticulation system</title>
                <content>
                  <para>
                    Approved cable groups can share a common reticulation system but should have either a dividing partition or a visible gap between the differing cable groups.
                  </para>
                </content>
              </block>
              <block>
                <ID>1128</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cables sharing a common reticulation system</title>
                <content>
                  <para>
                    In TOP SECRET areas, approved cable groups can share a common reticulation system but must have either a dividing partition or a visible gap between the differing cable groups.
                  </para>
                </content>
              </block>
              <block>
                <ID>1129</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Cables sharing a common reticulation system</title>
                <content>
                  <para>
                    TOP SECRET cabling must not share a common reticulation system unless it is in an enclosed reticulation system and has dividing partitions or visible gaps between the differing cable groups.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Enclosed cable reticulation systems</title>
            <content>

              <para>
                In a shared non-government facility, TOP SECRET cabling is enclosed in a sealed reticulation system to prevent access and enhance cable management.
              </para>
            </content>
            <controls>
              <block>
                <ID>1130</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Enclosed cable reticulation systems</title>
                <content>
                  <para>
                    Cables should be run in an enclosed cable reticulation system.
                  </para>
                </content>
              </block>
              <block>
                <ID>1131</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Enclosed cable reticulation systems</title>
                <content>
                  <para>
                    In TOP SECRET areas, cables must be run in an enclosed cable reticulation system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Covers for enclosed cable reticulation systems</title>
            <content>

              <para>
                Clear covers on enclosed reticulation systems are a convenient method of maintaining inspectability and control requirements. Having clear covers face inwards increases their inspectability.
              </para>
            </content>
            <controls>
              <block>
                <ID>1164</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Covers for enclosed cable reticulation systems</title>
                <content>
                  <para>
                    Conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings should be clear plastic.
                  </para>
                </content>
              </block>
              <block>
                <ID>1165</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Covers for enclosed cable reticulation systems</title>
                <content>
                  <para>
                    Conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings must be clear plastic.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabling in walls</title>
            <content>
              <para>
                In a shared non-government facility, cabling run correctly in walls allows for neater installations while maintaining separation and inspectability requirements. Controls are more stringent than in a non-shared government facility or a shared government facility.
              </para>
            </content>
            <controls>
              <block>
                <ID>1132</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cabling in walls</title>
                <content>
                  <para>
                    Cabling from cable trays to wall outlets must run in flexible or plastic conduit.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabling in party walls</title>
            <content>
              <para>
                In a shared non-government facility, cabling is not allowed in a party wall. A party wall is a wall shared with an unsecured space where there is no control over access. An inner wall can be used to run cabling where the space is sufficient for inspection of the cabling.
              </para>
            </content>
            <controls>
              <block>
                <ID>1133</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Cabling in party walls</title>
                <content>
                  <para>
                    Cabling must not run in a party wall.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sealing conduits</title>
            <content>
              <para>
                In a shared non-government facility, where the threat of access to cabling is increased, all conduits are sealed with a visible smear of glue to prevent access to cabling.
              </para>
            </content>
            <controls>
              <block>
                <ID>0194</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sealing conduits</title>
                <content>
                  <list>
                    <head>Agencies must use a visible smear of conduit glue to seal:</head>
                    <item>
                      all plastic conduit joints
                    </item>
                    <item>
                      conduit runs connected by threaded lock nuts.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sealing reticulation systems</title>
            <content>
              <para>
                In a shared non-government facility, where the threats of access to cable reticulation systems is increased, Security Construction and Equipment Committee (SCEC) endorsed seals are required to provide evidence of any tampering or illicit access.
              </para>
            </content>
            <controls>
              <block>
                <ID>0195</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sealing reticulation systems</title>
                <content>
                  <list>
                    <head>Agencies must use SCEC endorsed tamper evident seals to seal all removable covers on reticulation systems, including:</head>
                    <item>
                      box section front covers
                    </item>
                    <item>
                      conduit inspection boxes
                    </item>
                    <item>
                      outlet and junction boxes
                    </item>
                    <item>
                      T-pieces.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0196</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sealing reticulation systems</title>
                <content>
                  <para>
                    Tamper evident seals must be uniquely identifiable.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Wall penetrations</title>
            <content>
              <para>
                Penetrating a wall to a lesser-classified space by cabling requires the integrity of the classified space be maintained. All cabling is encased in conduit with no gaps in the wall around the conduit. This prevents any visual access to the secure space. For physical security measures regarding Security Zone requirements refer to the Australian Government Physical Security Management Protocol.
              </para>
            </content>
            <controls>
              <block>
                <ID>1134</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Wall penetrations</title>
                <content>
                  <para>
                    For wall penetrations that exit into a lower classified space, cabling must be encased in conduit with all gaps between the conduit and the wall filled with an appropriate sealing compound.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Power reticulation</title>
            <content>
              <para>
                In a shared non-government facility, it is important that TOP SECRET systems have control over the power system to prevent denial of service by deliberate or accidental means. The addition of a UPS is required to maintain availability of the TOP SECRET systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>1135</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Power reticulation</title>
                <content>
                  <para>
                    TOP SECRET facilities must have a power distribution board located in the TOP SECRET area with a feed from a UPS to power all ICT equipment.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cabinet separation</title>
            <content>
              <para>
                Having a definite gap between cabinets allows for ease of inspections for any illicit cabling or cross patching.
              </para>
            </content>
            <controls>
              <block>
                <ID>1136</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cabinet separation</title>
                <content>
                  <para>
                    Agencies must ensure there is a visible gap between TOP SECRET cabinets and cabinets of a lower classification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                The SCEC endorses seals to be used for various sealing requirements. Further information on endorsed seals is available in the Security Equipment Catalogue produced by SCEC at http://www.scec.gov.au/.
              </para>
              <para>
                Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Cable Labelling and Registration</title>
        <objective>
          <block>
            <content>
              <para>
                Cable registers are used to record cables and labels.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the labelling of cabling infrastructure installed in secured spaces.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Applicability of controls in this section</title>
            <content>
              <para>
                The controls are applicable to all facilities that process sensitive or classified information. For deployable platforms or facilities outside of Australia, consult the Emanation Security Threat Assessments section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Conduit label specifications</title>
            <content>
              <para>
                Conduit labels must be a specific size and colour to allow easy identification of secure conduits carrying cables.
              </para>
            </content>
            <controls>
              <block>
                <ID>0201</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Conduit label specifications</title>
                <content>
                  <list>
                    <head>Labels for TOP SECRET conduits must be:</head>
                    <item>
                      a minimum size of 2.5cm x 1cm
                    </item>
                    <item>
                      attached at 5m intervals
                    </item>
                    <item>
                      marked as ‘TS RUN’.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0202</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Conduit label specifications</title>
                <content>
                  <para>
                    Conduit labels in areas where uncleared personnel could frequently visit must have red text on a clear background.
                  </para>
                </content>
              </block>
              <block>
                <ID>0203</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Conduit label specifications</title>
                <content>
                  <para>
                    Conduit labels in areas that are not clearly observable must have red text on a white background.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Installing conduit labelling</title>
            <content>
              <para>
                Conduit labelling in public or reception areas could draw unwanted attention to the level of classified processing and lead to a disclosure of capabilities.
              </para>
            </content>
            <controls>
              <block>
                <ID>0204</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Installing conduit labelling</title>
                <content>
                  <para>
                    Conduit labels installed in public or visitor areas should not draw undue attention from people who do not have a need-to-know of the existence of such cabling.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Labelling wall outlet boxes</title>
            <content>
              <para>
                Clear labelling of wall outlet boxes diminishes the possibility of incorrectly attaching ICT equipment of a lesser classification to the wrong outlet.
              </para>
            </content>
            <controls>
              <block>
                <ID>1095</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Labelling wall outlet boxes</title>
                <content>
                  <para>
                    Wall outlet boxes should denote the classification, cable number and outlet number.
                  </para>
                </content>
              </block>
              <block>
                <ID>0205</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Labelling wall outlet boxes</title>
                <content>
                  <para>
                    Wall outlet boxes must denote the classification, cable number and outlet number.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Standard Operating Procedures</title>
            <content>
              <para>
                Recording labelling conventions in Standard Operating Procedures (SOPs) makes cabling and fault finding easier.
              </para>
            </content>
            <controls>
              <block>
                <ID>0206</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Standard Operating Procedures</title>
                <content>
                  <para>
                    The SOPs should record the site conventions for labelling and registration.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Labelling cables</title>
            <content>
              <para>
                Labelling cables with the correct source and destination information minimises the likelihood of cross patching and aids in fault finding and configuration management.
              </para>
            </content>
            <controls>
              <block>
                <ID>1096</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Labelling cables</title>
                <content>
                  <para>
                    Agencies should label cables at each end, with sufficient source and destination details to enable the physical identification and inspection of the cable.
                  </para>
                </content>
              </block>
              <block>
                <ID>0207</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Labelling cables</title>
                <content>
                  <para>
                    Agencies must label cables at each end, with sufficient source and destination details to enable the physical identification and inspection of the cable.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cable register</title>
            <content>
              <para>
                Cable registers provide a source of information that assessors can view to verify compliance.
              </para>
            </content>
            <controls>
              <block>
                <ID>0208</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cable register</title>
                <content>
                  <para>
                    Agencies should maintain a register of cables.
                  </para>
                </content>
              </block>
              <block>
                <ID>0210</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cable register</title>
                <content>
                  <para>
                    Agencies must maintain a register of cables.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cable register contents</title>
            <content>
              <para>
                Cable registers allow installers and assessors to trace cabling for inspections, malice or accidental damage. It tracks all cable management changes through the life of the system.
              </para>
            </content>
            <controls>
              <block>
                <ID>0209</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cable register contents</title>
                <content>
                  <list>
                    <head>The cable register should record at least the following information:</head>
                    <item>
                      cable identification number
                    </item>
                    <item>
                      classification
                    </item>
                    <item>
                      source
                    </item>
                    <item>
                      destination
                    </item>
                    <item>
                      site/floor plan diagram
                    </item>
                    <item>
                      seal numbers if applicable.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1097</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Cable register contents</title>
                <content>
                  <list>
                    <head>For cables in TOP SECRET areas, the cable register must record at least the following information:</head>
                    <item>
                      cable identification number
                    </item>
                    <item>
                      classification
                    </item>
                    <item>
                      source
                    </item>
                    <item>
                      destination
                    </item>
                    <item>
                      site/floor plan diagram
                    </item>
                    <item>
                      seal numbers if applicable.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cable inspections</title>
            <content>
              <para>
                Cable inspections, at pre-defined periods, are a method of checking the cable management system with the cable register.
              </para>
            </content>
            <controls>
              <block>
                <ID>0211</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Cable inspections</title>
                <content>
                  <para>
                    Agencies should inspect cables for inconsistencies with the cable register in accordance with the frequency defined in the System Security Plan.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Cable Patching</title>
        <objective>
          <block>
            <content>
              <para>
                Communications systems are designed to prevent patching between different classifications and security domains.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the configuration and installation of patch panels, patch cables and fly leads associated with communications systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Applicability of controls in this section</title>
            <content>
              <para>
                The controls in this section only apply to new cable installations or upgrades. Agencies are not required to retro-fit existing cabling infrastructure to align with changes to controls in this manual. The controls are applicable to all facilities that process sensitive or classified information. For deployable platforms or facilities outside of Australia, consult the Emanation Security Threat Assessments section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Terminations to patch panels</title>
            <content>
              <list>
                <head>Connecting a system to another system of a lesser classification will result in a data spill. A data spill could result in the following issues:</head>
                <item>
                  inadvertent or deliberate access by non-cleared personnel
                </item>
                <item>
                  the lesser system not meeting the appropriate requirements to secure the classified information from unauthorised access or tampering.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0213</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Terminations to patch panels</title>
                <content>
                  <para>
                    Agencies must ensure that only approved cable groups terminate on a patch panel.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Patch cable and fly lead connectors</title>
            <content>

              <para>
                Ensuring that cables are equipped with connectors of a different configuration to all other cables prevents inadvertent connection to systems of lower classifications.
              </para>
            </content>
            <controls>
              <block>
                <ID>1093</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Patch cable and fly lead connectors</title>
                <content>
                  <para>
                    In areas containing cabling for systems of different classifications, agencies should ensure that the connectors for each system are different from those of the other systems; unless the length of the higher classified patch cables is less than the distance between the higher classified patch panel and any patch panel of a lower classification.
                  </para>
                </content>
              </block>
              <block>
                <ID>0214</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Patch cable and fly lead connectors</title>
                <content>
                  <para>
                    In areas containing cabling for both TOP SECRET systems and systems of other classifications, agencies must ensure that the connectors for the TOP SECRET systems are different from those of the other systems.
                  </para>
                </content>
              </block>
              <block>
                <ID>1094</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Patch cable and fly lead connectors</title>
                <content>
                  <para>
                    In areas containing cabling for systems of different classifications, agencies should document the selection of connector types.
                  </para>
                </content>
              </block>
              <block>
                <ID>0215</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Patch cable and fly lead connectors</title>
                <content>
                  <para>
                    In areas containing cabling for both TOP SECRET systems and systems of other classifications, agencies must document the selection of connector types for TOP SECRET systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Physical separation of patch panels</title>
            <content>
              <list>
                <head>Appropriate physical separation between a TOP SECRET system and a system of a lesser classification:</head>
                <item>
                  reduces or eliminates the chances of cross patching between the systems
                </item>
                <item>
                  reduces or eliminates the possibility of unauthorised personnel gaining access to TOP SECRET system elements.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0216</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Physical separation of patch panels</title>
                <content>
                  <para>
                    Agencies should physically separate TOP SECRET and non-TOP SECRET patch panels by installing them in separate cabinets.
                  </para>
                </content>
              </block>
              <block>
                <ID>0217</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Physical separation of patch panels</title>
                <content>
                  <list>
                    <head>Where spatial constraints demand patch panels of a lower classification than TOP SECRET be located in the same cabinet, agencies must:</head>
                    <item>
                      provide a physical barrier in the cabinet to separate patch panels
                    </item>
                    <item>
                      ensure that only personnel cleared to TOP SECRET have access to the cabinet
                    </item>
                    <item>
                      obtain approval from the relevant accreditation authority prior to installation.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Fly lead installation</title>
            <content>
              <para>
                Keeping the lengths of fly leads to a minimum prevents clutter around desks, prevents damage to fibre optic cabling and reduces the chance of cross patching and tampering. If lengths become excessive, cabling needs to be treated as infrastructure and run it in conduit or fixed infrastructure such as desk partitioning.
              </para>
            </content>
            <controls>
              <block>
                <ID>0218</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Fly lead installation</title>
                <content>
				  <list>
					<head>Agencies should ensure that the fibre optic fly leads used to connect wall outlets to ICT equipment either:</head>
					<item>do not exceed 5m in length</item>
					<list>
					  <head>if they exceed 5m in length:</head>
					  <item>are run in the facility’s fixed infrastructure in a protective and easily inspected pathway</item>
					  <item>are clearly labelled at the equipment end with the wall outlet designator</item>
					  <item>are approved by the accreditation authority.</item>
					</list>
				  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Emanation Security Threat Assessments</title>
        <objective>
          <block>
            <content>
              <para>
                A valid threat assessment is used to determine the appropriate counter-measures to minimise compromising emanations.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes emanation security threat assessment advice, so agencies can implement appropriate counter-measures to minimise the loss of sensitive or classified information through compromising emanations.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <list>
                <head> This section is only applicable to:</head>
                <item>
                  agencies located outside of Australia
                </item>
                <item>
                  facilities in Australia that have transmitters
                </item>
                <item>
                  mobile platforms and deployable assets that process sensitive or classified information.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Emanation security threat assessments in Australia</title>
            <content>
              <para>
                Obtaining the current threat advice from the Defence Signals Directorate (DSD) on potential adversaries and applying the appropriate counter-measures is vital in maintaining the confidentiality of sensitive and classified systems from an emanation security attack.
              </para>
              <para>
                Failing to implement required counter-measures against an emanation security attack can lead to compromise. Having a good cable infrastructure and installation methodology will provide a strong backbone that will not need updating if the threat increases. Infrastructure costs are very expensive and time consuming to retro-fit.
              </para>
            </content>
            <controls>
              <block>
                <ID>0247</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Emanation security threat assessments in Australia</title>
                <content>
                  <list>
                    <head>Agencies designing and installing systems with Radio Frequency transmitters inside or co-located with their facility must:</head>
                    <item>
                      contact DSD for an emanation security threat assessment in accordance with the latest version of Australian Communications Security Instruction (ACSI) 71
                    </item>
                    <item>
                      install cabling and ICT equipment in accordance with this manual plus any specific installation criteria derived from the emanation security threat assessment.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0248</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Emanation security threat assessments in Australia</title>
                <content>
                  <list>
                    <head>Agencies designing and installing systems with Radio Frequency (RF) transmitters that co-locate with systems of a higher classification must:</head>
                    <item>
                      contact DSD for an emanation security threat assessment in accordance with the latest version of ACSI 71
                    </item>
                    <item>
                      install cabling and ICT equipment in accordance with this manual plus any specific installation criteria derived from the emanation security threat assessment.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1137</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Emanation security threat assessments in Australia</title>
                <content>
                  <list>
                    <head>Agencies designing and installing systems in shared facilities with non-Australian government entities must:</head>
                    <item>
                      contact DSD for an emanation security threat assessment in accordance with the latest version of ACSI 71
                    </item>
                    <item>
                      install cabling and ICT equipment in accordance with this manual plus any specific installation criteria derived from the emanation security threat assessment.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Emanation security threat assessments outside Australia</title>
            <content>
              <para>
                Fixed sites and deployed military platforms are more vulnerable to emanation security attack and require a current threat assessment and counter-measure implementation. Failing to implement recommended counter-measures and SOPs to reduce threats could result in the platform emanating compromising signals, which if intercepted and analysed, could lead to platform compromise with serious consequences.
              </para>
            </content>
            <controls>
              <block>
                <ID>0932</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Emanation security threat assessments outside Australia</title>
                <content>
                  <list>
                    <head>Agencies deploying systems overseas should: </head>
                    <item>
                      contact DSD for emanation security threat advice
                    </item>
                    <item>
                      install cabling and ICT equipment in accordance with this manual plus any specific installation criteria derived from the emanation security threat assessment.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0249</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Emanation security threat assessments outside Australia</title>
                <content>
                  <list>
                    <head>Agencies deploying systems overseas in military and fixed locations must:</head>
                    <item>
                      contact DSD for an emanation security threat assessment in accordance with the latest version of ACSI 71
                    </item>
                    <item>
                      install cabling and ICT equipment in accordance with this manual plus any specific installation criteria derived from the emanation security threat assessment.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Early identification of emanation security issues</title>
            <content>
              <para>
                It is important to identify the need for emanation security controls for a system early in the project lifecycle as this can reduce costs for the project. Costs are much greater if changes have to be made once the system has been designed and deployed.
              </para>
            </content>
            <controls>
              <block>
                <ID>0246</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Early identification of emanation security issues</title>
                <content>
                  <para>
                    Agencies needing an emanation security threat assessment should do so as early as possible in project lifecycles as emanation security controls can have significant cost implications.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Information and Communications Technology equipment in highly sensitive areas</title>
            <content>
              <para>
                While ICT equipment in a TOP SECRET area in Australia may not need certification to TEMPEST standards, the equipment still needs to meet applicable industry and government standards.
              </para>
            </content>
            <controls>
              <block>
                <ID>0250</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Information and Communications Technology equipment in highly sensitive areas</title>
                <content>
                  <para>
                    Agencies must ensure that ICT equipment in TOP SECRET areas meets industry and government standards relating to electromagnetic interference/electromagnetic compatibility.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Additional information on cabling and separation standards, as well as the potential dangers of operating RF transmitters near systems is documented in the latest version of ACSI 61.
              </para>
              <para>
                Additional information on conducting an emanation security threat assessment is found in the latest version of ACSI 71.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Communications Systems and Devices</title>
      <section>
        <title>Radio Frequency, Infrared and Bluetooth Devices</title>
        <objective>
          <block>
            <content>
              <para>
                Only approved RF, infrared and Bluetooth devices are brought into secured areas.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the use of RF, infrared and Bluetooth devices in secured spaces. Information on the use of RF devices outside secured spaces can be found in the Working Off-Site chapter.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Exemptions for the use of infrared devices</title>
            <content>
              <para>
                An infrared device can be used in a secured space provided it does not communicate sensitive or classified information.
              </para>
            </content>
          </block>
          <block>
            <title>Exemptions for the use of Radio Frequency devices</title>
            <content>
              <list>
                <head>The following devices, at the discretion of the accreditation authority, can be exempted from the controls associated with RF transmitters:</head>
                <item>
                  pagers that can only receive messages
                </item>
                <item>
                  garage door openers
                </item>
                <item>
                  car lock/alarm keypads
                </item>
                <item>
                  medical and exercise equipment that uses RF to communicate between sub-components
                </item>
                <item>
                  communications radios that are secured by approved cryptography.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Pointing devices</title>
            <content>
              <para>
                Since wireless RF pointing devices can pose an emanation security risk they are not to be used in TOP SECRET areas unless in a RF screened building.
              </para>
            </content>
            <controls>
              <block>
                <ID>0221</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Pointing devices</title>
                <content>
                  <para>
                    Wireless RF pointing devices must not be used in TOP SECRET areas unless used in a RF screened building.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Infrared keyboards</title>
            <content>
              <para>
                When using infrared keyboards with CONFIDENTIAL or SECRET systems, drawn curtains that block infrared transmissions are an acceptable method of protection.
              </para>
              <para>
                When using infrared keyboards with a TOP SECRET system, windows with curtains that can be opened are not acceptable as a method of permanently blocking infrared transmissions.
              </para>
            </content>
            <controls>
              <block>
                <ID>0222</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Infrared keyboards</title>
                <content>
                  <para>
                    Agencies using infrared keyboards should ensure that infrared ports are positioned to prevent line of sight and reflected communications travelling into an unsecured space.
                  </para>
                </content>
              </block>
              <block>
                <ID>0223</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Infrared keyboards</title>
                <content>
                  <list>
                    <head>Agencies using infrared keyboards must not allow:</head>
                    <item>
                      line of sight and reflected communications travelling into an unsecured space
                    </item>
                    <item>
                      multiple infrared keyboards for different systems in the same area
                    </item>
                    <item>
                      other infrared devices in the same area
                    </item>
                    <item>
                      infrared keyboards to be operated in areas with unprotected windows.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0224</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Infrared keyboards</title>
                <content>
                  <list>
                    <head>Agencies using infrared keyboards must not allow:</head>
                    <item>
                      line of sight and reflected communications travelling into an unsecured space
                    </item>
                    <item>
                      multiple infrared keyboards for different systems in the same area
                    </item>
                    <item>
                      other infrared devices in the same area
                    </item>
                    <item>
                      infrared keyboards in areas with windows that have not had a permanent method of blocking infrared transmissions applied to them.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Bluetooth and wireless keyboards</title>
            <content>
              <para>
                Bluetooth has a number of known weaknesses in the protocol that potentially enable attacker exploitation. While there have been a number of revisions to the protocol that have made incremental improvements to security, there have been trade-offs that have limited the improvements. These include maintaining backward compatibility to earlier versions of the protocol and limits to the capabilities of some devices.
              </para>
              <para>
                Though newer revisions of the Bluetooth protocol have addressed many of the historical security concerns, it is still very important that agencies consider the security risks posed by enabling Bluetooth technology.
              </para>
              <list>
                <head>As part of an agency’s security risk assessment, things to consider are:</head>
                <item>
                  using the strongest security modes available
                </item>
                <item>
                  educating system users of the known weaknesses of the technology and their responsibilities in complying with policy in the absence of strong technical controls
                </item>
                <item>
                  man in the middle pairing
                </item>
                <item>
                  maintaining an inventory of all Bluetooth devices addresses (BD_ADDRs).
                </item>
              </list>
              <para>
                Agencies must use Bluetooth version 2.1 or later as secure simple pairing and extended inquiry response was introduced. Secure simple pairing improves the pairing experience for Bluetooth devices, while increasing the strength as it uses a form of public key cryptography. Extended inquiry response provides more information during the inquiry procedure to allow better filtering of devices before connecting.
              </para>
              <para>
                The device class can be used to restrict the range that the Bluetooth communications will operate over. Typically Bluetooth class 1 devices can communicate up to 100 metres, class 2 devices can communicate up to 10 metres and class 3 devices can communicate up to 5 metres.
              </para>
            </content>
            <controls>
              <block>
                <ID>1058</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Bluetooth and wireless keyboards</title>
                <content>
                  <para>
                    Agencies should not use Bluetooth and wireless keyboards unless in a RF screened building.
                  </para>
                </content>
              </block>
              <block>
                <ID>1155</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Bluetooth and wireless keyboards</title>
                <content>
                  <para>
                    Agencies must not use Bluetooth and wireless keyboards unless in a RF screened building.
                  </para>
                </content>
              </block>
              <block>
                <ID>1166</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Bluetooth and wireless keyboards</title>
                <content>
                  <para>
                    Agencies must use Bluetooth version 2.1 or later if Bluetooth keyboards are used.
                  </para>
                </content>
              </block>
              <block>
                <ID>1167</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Bluetooth and wireless keyboards</title>
                <content>
                  <para>
                    Agencies should restrict the range of Bluetooth keyboards to less than 10 metres by only using class 2 or class 3 devices.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Radio Frequency devices in secured spaces</title>
            <content>
              <para>
                RF devices with voice capability pose an audio security threat to secured spaces as they are capable of picking up and transmitting sensitive or classified background conversations. Furthermore, many RF devices can connect to ICT equipment and act as unauthorised data storage devices.
              </para>
            </content>
            <controls>
              <block>
                <ID>0830</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Radio Frequency devices in secured spaces</title>
                <content>
                  <para>
                    Agencies should prevent RF devices from being brought into secured spaces unless authorised by the accreditation authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0225</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Radio Frequency devices in secured spaces</title>
                <content>
                  <para>
                    Agencies must prevent RF devices from being brought into TOP SECRET areas unless authorised by the accreditation authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Detecting Radio Frequency devices in secured spaces</title>
            <content>
              <para>
                As RF devices are prohibited in highly classified environments, agencies are encouraged to deploy security measures that detect and respond to the unauthorised use of such devices.
              </para>
            </content>
            <controls>
              <block>
                <ID>0829</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Detecting Radio Frequency devices in secured spaces</title>
                <content>
                  <para>
                    Agencies should deploy security measures to detect and respond to active RF devices in secured spaces.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Radio Frequency controls</title>
            <content>
              <para>
                Minimising the output power of wireless devices and using RF shielding on facilities will assist in limiting the wireless communications to areas under the control of the agency.
              </para>
            </content>
            <controls>
              <block>
                <ID>0929</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>

                <title>Radio Frequency controls</title>
                <content>
                  <list>
                    <head>Agencies should limit the effective range of communications outside their area of control by either:</head>
                    <item>
                      minimising the output power level of wireless devices
                    </item>
                    <item>
                      RF shielding.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Fax Machines and Multifunction Devices</title>
        <objective>
          <block>
            <content>
              <para>
                Fax machines and Multifunction Devices (MFDs) are used in a secure manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes fax machines and MFDs connected to the Public Switched Telephone Network (PSTN), High Grade Cryptographic Equipment (HGCE) or computer networks.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Further information on MFDs communicating via network gateways can be found in the Data Import and Export section of the Gateway Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Fax machine and Multifunction Device usage policy</title>
            <content>
              <para>
                As fax machines and MFDs are capable of communicating sensitive or classified information, and are a potential source of cyber security incidents, it is important that agencies develop a policy governing their use.
              </para>
            </content>
            <controls>
              <block>
                <ID>0588</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Fax machine and Multifunction Device usage policy</title>
                <content>
                  <para>
                    Agencies must develop a policy governing the use of fax machines and MFDs.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sending fax messages</title>
            <content>
              <para>
                Once a fax machine or MFD has been connected to cryptographic equipment and used to send a sensitive or classified fax message, it can no longer be trusted when connected directly to unsecured telecommunications infrastructure or the PSTN. For example, if a fax machine fails to send a sensitive or classified fax message, the device will continue attempting to send the fax message even if it has been disconnected from the cryptographic device and connected directly to the PSTN. In such cases, the fax machine could then send the sensitive or classified fax message in the clear, causing a cyber security incident.
              </para>
            </content>
            <controls>
              <block>
                <ID>1092</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sending fax messages</title>
                <content>
                  <para>
                    Agencies must have separate fax machines or MFDs for sending sensitive or classified and unclassified fax messages.
                  </para>
                </content>
              </block>
              <block>
                <ID>0241</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sending fax messages</title>
                <content>
                  <para>
                    Agencies sending sensitive or classified fax messages must ensure that the fax message is encrypted to an appropriate level when communicated over unsecured telecommunications infrastructure or the PSTN.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sending fax messages using High Grade Cryptographic Equipment</title>
            <content>
              <para>
                Using the correct procedure for sending a classified fax message will ensure that it is sent securely to the correct recipient.
              </para>
              <para>
                Using the correct memory erase procedure will prevent a classified fax message being communicated in the clear.
              </para>
              <para>
                Implementing the correct procedure for establishing a secure call will prevent sending a classified fax message in the clear.
              </para>
              <para>
                Witnessing the receiving of a fax message and powering down the receiving machine or clearing the memory after transmission will prevent someone without a need-to-know from accessing the fax message.
              </para>
              <para>
                Ensuring fax machines and MFDs are not connected to unsecured phone lines will prevent accidentally sending classified messages stored in memory.
              </para>
            </content>
            <controls>
              <block>
                <ID>0242</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Sending fax messages using High Grade Cryptographic Equipment</title>
                <content>
                  <para>
                    Agencies intending to use fax machines or MFDs to send classified information must comply with additional requirements in ACSI 129 and ACSI 131.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Receiving fax messages</title>
            <content>
              <para>
                While the communications path between fax machines and MFDs may be appropriately protected, personnel need to be aware of the need-to-know of the information that is being communicated. It is therefore important that fax messages are collected from the receiving fax machine or MFD as soon as possible. Furthermore, if an expected fax message is not received it may indicate that there was a problem with the original transmission or the fax message has been taken by an unauthorised person.
              </para>
            </content>
            <controls>
              <block>
                <ID>1075</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Receiving fax messages</title>
                <content>
                  <list>
                    <head>The sender of a fax message should make arrangements for the receiver to:</head>
                    <item>
                      collect the fax message as soon as possible after it is received
                    </item>
                    <item>
                      notify the sender if the fax message does not arrive in an agreed amount of time.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Connecting Multifunction Devices to telephone networks</title>
            <content>
              <para>
                When a MFD is connected to a computer network and a digital telephone network the device can act as a bridge between the two. The telephone network therefore needs to be accredited to the same level as the computer network.
              </para>
            </content>
            <controls>
              <block>
                <ID>0244</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Connecting Multifunction Devices to telephone networks</title>
                <content>
                  <para>
                    Agencies should not enable a direct connection from a MFD to a digital telephone network unless the telephone network is accredited to at least the same level as the computer network to which the device is connected.
                  </para>
                </content>
              </block>
              <block>
                <ID>0245</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Connecting Multifunction Devices to telephone networks</title>
                <content>
                  <para>
                    Agencies must not enable a direct connection from a MFD to a digital telephone network unless the telephone network is accredited to at least the same level as the computer network to which the device is connected.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Connecting Multifunction Devices to computer networks</title>
            <content>
              <para>
                As network connected MFDs are considered to be devices that reside on a computer network, they need to have the same security measures as other devices on the computer network.
              </para>
            </content>
            <controls>
              <block>
                <ID>0590</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Connecting Multifunction Devices to computer networks</title>
                <content>
                  <list>
                    <head>Where MFDs connected to computer networks have the ability to communicate via a gateway to another network, agencies must ensure that:</head>
                    <item>
                      each MFD applies user identification, authentication and audit functions for all information communicated by that device
                    </item>
                    <item>
                      these mechanisms are of similar strength to those specified for workstations on that network
                    </item>
                    <item>
                      each gateway can identify and filter the information in accordance with the requirements for the export of data via a gateway.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Copying documents on Multifunction Devices</title>
            <content>
              <para>
                As networked MFDs are capable of sending scanned or copied documents across a connected network, personnel need to be aware that if they scan or copy documents at a level higher than that of the network the device is connected to they could be causing a data spill.
              </para>
            </content>
            <controls>
              <block>
                <ID>0589</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Copying documents on Multifunction Devices</title>
                <content>
                  <para>
                    Agencies must not permit MFDs connected to computer networks to be used to copy documents above the sensitivity or classification of the connected network.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Observing fax machine and Multifunction Device use</title>
            <content>
              <para>
                Placing fax machines and MFDs in public areas can help reduce the likelihood of any suspicious use going unnoticed.
              </para>
            </content>
            <controls>
              <block>
                <ID>1036</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Observing fax machine and Multifunction Device use</title>
                <content>
                  <para>
                    Agencies should ensure that fax machines and MFDs are located in an area where their use can be observed.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Specific information regarding the procedures for fax machines and MFDs attached to HGCE is found in ACSI 129 and ACSI 131.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Telephones and Telephone Systems</title>
        <objective>
          <block>
            <content>
              <para>
                Telephone systems are prevented from communicating unauthorised information.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the secure use of fixed telephones, including cordless telephones, as well as the systems they use to communicate information.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information regarding mobile phones and smartphones is covered in the Mobile Devices section of the Working Off-Site chapter while information regarding Internet Protocol telephony, including Voice over Internet Protocol, and encryption of data in transit is covered in the Internet Protocol Telephony section of the Network Security chapter and the Cryptographic Fundamentals section of the Cryptography chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Telephones and telephone systems usage policy</title>
            <content>
              <para>
                All non-secure telephone networks are subject to interception. Accidentally or maliciously revealing sensitive or classified information over a public telephone network can lead to interception.
              </para>
            </content>
            <controls>
              <block>
                <ID>1078</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Telephones and telephone systems usage policy</title>
                <content>
                  <para>
                    Agencies must develop a policy governing the use of telephones and telephone systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Personnel awareness</title>
            <content>
              <para>
                As there is a high risk of unintended disclosure of sensitive or classified information when using telephones, it is important that personnel are made aware of what they can discuss on particular telephone systems, as well as the audio security risk associated with the use of telephones.
              </para>
            </content>
            <controls>
              <block>
                <ID>0229</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Personnel awareness</title>
                <content>
                  <para>
                    Agencies must advise personnel of the permitted sensitive or classified information that can be discussed on both internal and external telephone connections.
                  </para>
                </content>
              </block>
              <block>
                <ID>0230</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Personnel awareness</title>
                <content>
                  <para>
                    Agencies should advise personnel of the audio security risk posed by using telephones in areas where sensitive or classified conversations can occur.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Visual indication</title>
            <content>
              <para>
                When single telephone systems are approved to hold conversations at different levels, alerting the user to the sensitive or classified information that can be discussed will assist in reducing the risk of unintended disclosure of sensitive or classified information.
              </para>
            </content>
            <controls>
              <block>
                <ID>0231</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Visual indication</title>
                <content>
                  <para>
                    Agencies permitting different levels of conversation for different kinds of connections should use telephones that give a visual indication of what kind of connection has been made.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Use of telephone systems</title>
            <content>
              <para>
                When sensitive or classified conversations are to be held using telephone systems, the conversation needs to be appropriately protected through the use of encryption measures.
              </para>
            </content>
            <controls>
              <block>
                <ID>0232</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Use of telephone systems</title>
                <content>
                  <list>
                    <head>Agencies intending to use telephone systems for the transmission of sensitive or classified information must ensure that:</head>
                    <item>
                      the system has been accredited for the purpose
                    </item>
                    <item>
                      all sensitive or classified traffic that passes over external systems is appropriately encrypted.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cordless telephones</title>
            <content>
              <para>
                Cordless telephones have minimal transmission security; therefore they must not be used for sensitive or classified communications.
              </para>
            </content>
            <controls>
              <block>
                <ID>0233</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Cordless telephones</title>
                <content>
                  <para>
                    Agencies must not use cordless telephones for sensitive or classified conversations.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Cordless telephones with secure telephony devices</title>
            <content>
              <para>
                As the data between cordless handsets and base stations is not appropriately secured, cordless telephones must not be used for sensitive or classified communications even if the device is connected to a secure telephony device.
              </para>
            </content>
            <controls>
              <block>
                <ID>0234</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Cordless telephones with secure telephony devices</title>
                <content>
                  <para>
                    Agencies must not use cordless telephones in conjunction with secure telephony devices.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Speakerphones</title>
            <content>
              <para>
                As speakerphones are designed to pick up and transmit conversations in the vicinity of the device, they must not be used in TOP SECRET areas as the audio security risk is too high. However, if the agency is able to reduce the audio security risk through the use of an audio secure room that is secured during conversations, then they may be used. For physical security measures regarding Security Zone requirements refer to the Australian Government Physical Security Management Protocol.
              </para>
            </content>
            <controls>
              <block>
                <ID>0235</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Speakerphones</title>
                <content>
                  <list>
                    <head>Agencies must not use speakerphones on telephones in TOP SECRET areas unless:</head>
                    <item>
                      it is located in a room rated as audio secure
                    </item>
                    <item>
                      the room is audio secure during any conversations
                    </item>
                    <item>
                      only personnel involved in discussions are present in the room.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Off-hook audio protection</title>
            <content>
              <para>
                Providing off-hook security minimises the chance of sensitive and classified conversations being accidentally coupled into handsets and speakerphones. Limiting the time an active microphone is open limits this threat.
              </para>
              <para>
                Simply providing an off-hook audio protection feature is not sufficient to meet the requirement for its use. To ensure that the protection feature is used appropriately, personnel need to be made aware of the protection feature and trained in its proper use.
              </para>
            </content>
            <controls>
              <block>
                <ID>0236</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Off-hook audio protection</title>
                <content>
                  <para>
                    Agencies should ensure that off-hook audio protection features are used on all telephones that are not accredited for the transmission of sensitive or classified information in areas where such information could be discussed.
                  </para>
                </content>
              </block>
              <block>
                <ID>0931</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Off-hook audio protection</title>
                <content>
                  <para>
                    Agencies should use push-to-talk handsets in open areas, and where telephones are shared.
                  </para>
                </content>
              </block>
              <block>
                <ID>0237</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Off-hook audio protection</title>
                <content>
                  <para>
                    Agencies must ensure that off-hook audio protection features are used on all telephones that are not accredited for the transmission of classified information in areas where such information could be discussed.
                  </para>
                </content>
              </block>
              <block>
                <ID>0238</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Off-hook audio protection</title>
                <content>
                  <para>
                    Agencies should use push-to-talk handsets to meet the requirement for off-hook audio protection.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
  </part>
  <part>
    <title>Information Technology Security</title>
    <chapter>
      <title>Product Security</title>
      <section>
        <title>Product Selection and Acquisition</title>
        <objective>
          <block>
            <content>
              <para>
                Products providing security functions for the protection of information are formally evaluated.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes selecting and acquiring products that provide security functionality. It does not describe selecting or acquiring products that do not provide security functionality or physical security products.
              </para>
              <para>
                Agencies selecting products that do not provide a security function, or selecting products whose security functions will not be used and are disabled, do not need to comply with these requirements.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Agencies need confidence that products perform as claimed by the vendor. This confidence is best achieved through a formal, and impartial, assessment of the product by an independent entity. The Defence Signals Directorate (DSD) publishes and maintains a list of products that have been formally, and independently, evaluated on their Evaluated Products List (EPL) on the DSD website.
              </para>
              <para>
                Agencies can select products from any of DSD’s recognised evaluation programs. The Australasian Information Security Evaluation Program (AISEP) is DSD’s Common Criteria scheme that uses licensed commercial evaluation facilities to perform evaluations. Through the AISEP, DSD recognises evaluations from foreign Common Criteria schemes. Other DSD evaluation programs include a DSD Cryptographic Evaluation (DCE), high assurance evaluation and cross domain evaluation.
              </para>
              <para>
                The scope of an evaluation and recommendations for the secure use of a product is provided in each of DSD’s different evaluation programs. However, many products require third party hardware and software to operate, which can introduce new vulnerabilities that are not tested in the evaluation. This is a natural outcome of greater product convergence and inter-network connectivity. Therefore, agencies must read documentation associated with each evaluation to determine what the evaluation included and any recommendations for the product’s secure use.
              </para>
            </content>
          </block>
          <block>
            <title>Product specific requirements</title>
            <content>
              <para>
                For DSD evaluated products, a consumer guide is made available on the EPL. Where consumer guides exist for evaluated products, the requirements in the consumer guides take precedence over those in this manual.
              </para>
              <para>
                Agencies must comply with specific guidance on high assurance products and High Grade Cryptographic Equipment (HGCE) for handling CONFIDENTIAL and above information. Such guidance is published in Australian Communications Security Instructions (ACSIs) by DSD. The requirements in ACSIs take precedence over those in this manual.
              </para>
            </content>
          </block>
          <block>
            <title>Convergence</title>
            <content>
              <para>
                Convergence is the integration of a number of discrete technologies into one product, such as mobile devices that integrate voice and data services. Converged solutions can include the advantages of each discrete technology but also present the vulnerabilities of each discrete technology at the same time. Furthermore, some vulnerabilities may be unique to converged products due to a combination of technologies present in the product and their interaction with each other. When products have converged elements, the relevant areas of this manual for each of the discrete elements are applicable.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Product selection preference order</title>
            <content>
              <para>
                Products evaluated in the AISEP under the international Common Criteria standard are the most commonly listed products on the EPL. Common Criteria evaluations have an Evaluation Assurance Level (EAL) number from 1-7, of which 1-4 inclusive are internationally recognised under the Common Criteria Mutual Recognition Arrangement. Product vendors select an EAL number based on their customer demands. Product vendors also determine the scope of any evaluation activities, which may or may not include the security functionality an agency requires. The scope of the evaluation is not related to the EAL number. Agencies can read the Security Target and Certification Report for a product to understand what security functionality was included in an evaluation. This will allow the agency to determine if the security functionality evaluated in the product meets their needs.
              </para>
              <para>
                To assist agencies is selecting appropriate products; DSD has introduced approved Protection Profiles for specific technologies. A Protection Profile is a document that stipulates the security functionality that must be included in a Common Criteria evaluation. Agencies can have confidence that the scope of an evaluation against a DSD approved Protection Profile covers the necessary security functionality expected of the evaluated product and known security vulnerabilities will have been addressed.
              </para>
              <para>
                Products entered into the AISEP for evaluation against a DSD approved Protection Profile will be given the highest priority for evaluation. These evaluations are expected to be faster than traditional evaluations, which will enable the AISEP to keep pace with evaluating updates to products. Cryptographic security functionality is also included in scope of products evaluated against a DSD approved Protection Profile; however, DSD will continue to require a DCE for products intended for use with PROTECTED information.
              </para>
              <para>
                DSD is currently establishing cryptographic testing as part of AISEP Common Criteria evaluations. When this is established, evaluations against a DSD approved Protection Profile will not require a separate DCE and evaluations will be completed much faster.
              </para>
              <para>
                The Network Device Protection Profile (NDPP) is the first DSD approved Protection Profile and is to be used for layer 3 network infrastructure devices such as routers and firewalls. Specific security functionality will be added to the NDPP, such as firewall traffic filtering, as part of maintaining technical currency of the Protection Profile. All DSD approved Protection Profiles are published on the EPL.
              </para>
              <para>
                Other technology Protection Profiles may be developed in the Common Criteria that are recognised by DSD through the Common Criteria Recognition Arrangement. However, Protection Profiles that are not marked as DSD approved Protection Profiles will not be given any priority for evaluation in the AISEP.
              </para>
              <para>
                While products evaluated against a DSD approved Protection Profile will fulfil the Common Criteria EAL requirements, the EAL number will not be published on the EPL. This is due to requirements for EAL numbers being gradually replaced by DSD approved Protection Profiles in this manual.
              </para>
              <para>
                An agency may find that a product they wish to use is not available through the product selection preference order. If it is a technology gap, agencies should recommend DSD evaluate the product through sponsorship. If agencies select a product that has not completed an evaluation, the decision must be documented and the security risks accepted by the agency.
              </para>
            </content>
            <controls>
              <block>
                <ID>0280</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Product selection preference order</title>
                <content>
                  <list>
                    <head>Agencies must select products in the following order of preference, depending on their needs:</head>
                    <item>
                      first preference – products that have completed either:

                      <list>
                        <item>
                          a DSD high grade or high assurance evaluation
                        </item>
                        <item>
                          a Common Criteria evaluation against a DSD approved Protection Profile
                        </item>
                        <item>
                          a Common Criteria evaluation through the AISEP or a Common Criteria scheme recognised under the Common Criteria Recognition Arrangement
                        </item>
                      </list>
                    </item>
                    <item>
                      second preference – products that are currently in evaluation in the AISEP or DSD
                    </item>
                    <item>
                      third preference – products in evaluation in a scheme where the outcome will be recognised by DSD when the evaluation is completed and published on the EPL or Common Criteria portal.
                    </item>
                    <item>
                      fourth preference – products that are neither in evaluation or have completed an evaluation.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0282</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Product selection preference order</title>
                <content>
                  <para>
                    Agencies must document the justification for selecting a product that has not completed an evaluation and accept any security risk introduced by the use of such a product.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Product selection</title>
            <content>
              <para>
                Agencies can determine that an evaluated product from the EPL is suitable by reviewing its evaluation documentation. This documentation includes the Security Target, Certification Report and Consumer Guide. In particular, agencies need to determine if the scope or target of evaluation (including security functionality and the operational environment) is suitable for their needs.
              </para>
              <para>
                When selecting a product with security functionality, whether it has or has not been evaluated, agencies must implement best practice security measures. The EPL cannot include all products and versions and even an evaluated product from the EPL will need to have its security managed continuously as new vulnerabilities are constantly being discovered in products.
              </para>
              <para>
                A product listed on the EPL might not meet an agency’s security requirements if the scope of the evaluation does not include its intended use or the operational environment differs from that assumed in the evaluation.
              </para>
              <para>
                Products that are in evaluation will not have a Certification Report and may not have a published Security Target. A draft Security Target can be obtained from DSD for products that are in evaluation through the AISEP. For products that are in evaluation through a foreign scheme, the product vendor can be contacted directly for further information.
              </para>
            </content>
            <controls>
              <block>
                <ID>0279</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Product selection</title>
                <content>
                  <para>
                    Agencies should select products that have their desired security functionality in the scope of the product’s evaluation and are applicable to the intended environment.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Product specific requirements</title>
            <content>
              <para>
                A Consumer Guide is provided on the EPL which gives specific guidance on the evaluated products use. Additionally product specific requirements may also be produced for high assurance products and HGCE
              </para>
            </content>
            <controls>
              <block>
                <ID>0463</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Product specific requirements</title>
                <content>
                  <para>
                    Agencies must check consumer guides for products, where available, to determine any product specific requirements.
                  </para>
                </content>
              </block>
              <block>
                <ID>0464</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Product specific requirements</title>
                <content>
                  <para>
                    Where product specific requirements exist in a consumer guide for a product, agencies must comply with the requirements outlined in the consumer guide.
                  </para>
                </content>
              </block>
              <block>
                <ID>0283</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Product specific requirements</title>
                <content>
                  <para>
                    Agencies selecting high assurance products and HGCE must contact DSD and comply with any product specific requirements.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Delivery of products</title>
            <content>
              <para>
                It is important that agencies ensure that the product that is intended for use is the actual product that is received. For evaluated products, if the product received differs from the evaluated version, then the assurance gained from any evaluation may not necessarily apply. For unevaluated products that do not have evaluated delivery procedures, it is recommended agencies assess whether the vendor’s delivery procedures are sufficient to maintain the integrity of the product.
              </para>
              <list>
                <head>Other factors to consider when assessing delivery procedures include:</head>
                <item>
                  the intended environment of the product
                </item>
                <item>
                  the types of attackers that the product will defend against
                </item>
                <item>
                  the resources of any potential attackers
                </item>
                <item>
                  the likelihood of an attack
                </item>
                <item>
                  the importance of maintaining confidentiality of the product purchase
                </item>
                <item>
                  the importance of ensuring adherence to delivery timeframes.
                </item>
              </list>
              <para>
                Delivery procedures can vary greatly from product to product. For most products the standard commercial practice for packaging and delivery could be sufficient for agencies’ requirements. Examples of other secure delivery procedures can include tamper evident seals, cryptographic checksums and signatures, and secure transportation.
              </para>
              <para>
                Agencies will also need to confirm the integrity of the software that has been delivered before deploying it on an operational system to ensure that no unintended software is installed at the same time. Software delivered on physical media, and software delivered over the Internet, could contain malicious code or malicious content that is installed along with the legitimate software.
              </para>
            </content>
            <controls>
              <block>
                <ID>0285</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Delivery of products</title>
                <content>
                  <para>
                    Agencies should ensure that products are delivered in a manner consistent with any delivery procedures defined in associated documentation.
                  </para>
                </content>
              </block>
              <block>
                <ID>0286</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Delivery of products</title>
                <content>
                  <para>
                    Agencies procuring high assurance products and HGCE must contact DSD and comply with any product specific delivery procedures.
                  </para>
                </content>
              </block>
              <block>
                <ID>0937</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Delivery of products</title>
                <content>
                  <para>
                    Agencies should ensure that products purchased without the delivery assurances provided through the use of formally evaluated procedures are delivered in a manner that provides confidence that they receive the product that they expect to receive in an unaltered state.
                  </para>
                </content>
              </block>
              <block>
                <ID>0284</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Delivery of products</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      verify the integrity of software using vendor supplied checksums when available
                    </item>
                    <item>
                      validate the software’s interaction with the operating system and network in a test environment prior to use on operational systems.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Leasing arrangements</title>
            <content>
              <para>
                Agencies should consider security and policy requirements when entering into a leasing agreement for products in order to avoid potential cyber security incidents during maintenance, repairs or disposal processes.
              </para>
            </content>
            <controls>
              <block>
                <ID>0287</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Leasing arrangements</title>
                <content>
                  <list>
                    <head>Agencies should ensure that leasing agreements for products take into account the:</head>
                    <item>
                      difficulties that could be encountered when the product needs maintenance
                    </item>
                    <item>
                      difficulties that could be encountered in sanitising a product before returning it
                    </item>
                    <item>
                      the possible requirement for destruction if sanitisation cannot be performed.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Ongoing maintenance of assurance</title>
            <content>
              <para>
                Developers that have demonstrated a commitment to continuous evaluation of product versions are more likely to ensure that security updates and changes are independently assessed.
              </para>
              <para>
                A developer’s commitment to continuity of assurance can be gauged through the number of evaluations undertaken and whether assurance maintenance has been performed on previous evaluations.
              </para>
            </content>
            <controls>
              <block>
                <ID>0938</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Ongoing maintenance of assurance</title>
                <content>
                  <para>
                    Agencies should choose products from developers that have made a commitment to the continuing maintenance of the assurance of their product.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <list>
                <head>Additional information on the EPL, AISEP, Protection Profiles and the Common Criteria can be found at:</head>
                <item>
                  http://www.dsd.gov.au/infosec/epl.htm
                </item>
                <item>
                  http://www.dsd.gov.au/infosec/aisep.htm
                </item>
                <item>
                  http://www.commoncriteriaportal.org/
                </item>
                <item>
                  http://www.commoncriteriaportal.org/schemes.html
                </item>
                <item>
                  http://www.commoncriteriaportal.org/ccra/.
                </item>
              </list>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Product Installation and Configuration</title>
        <objective>
          <block>
            <content>
              <para>
                Products are installed and configured using best practice security.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes installing and configuring evaluated products that provide security functionality. It does not describe installing and configuring general products or physical security products.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Evaluated configuration</title>
            <content>
              <list>
                <head>An evaluated product is considered to be operating in its evaluated configuration if:</head>
                <item>
                  functionality that it uses was in the scope or target of evaluation and implemented in the specified manner
                </item>
                <item>
                  only product updates that have been assessed through a formal assurance continuity process have been applied
                </item>
                <item>
                  the environment complies with assumptions or organisational security policies stated in the product’s Security Target or similar document.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>Unevaluated configuration</title>
            <content>
              <para>
                An evaluated product is considered to be operating in an unevaluated configuration when it does not meet the requirements of the evaluated configuration and guidance provided from the Certification Report.
              </para>
            </content>
          </block>
          <block>
            <title>Patching evaluated products</title>
            <content>
              <para>
                Agencies need to consider that evaluated products may have had patches applied since the time they were evaluated. In the majority of cases, the latest patched product version is more secure than the older evaluated product version. While the application of security patches will normally not place a product in an unevaluated configuration, some product vendors incorporate new functionality with security patches, which have not been evaluated. In such cases agencies will need to use their judgement to determine whether the product remains in an evaluated configuration or whether sufficiently new functionality has been incorporated into the product such that it no longer remains in an evaluated configuration.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Installation and configuration of evaluated products</title>
            <content>

              <para>
                Evaluation of products provides assurance that the product will work as expected in a clearly defined configuration. The scope or target of evaluation specifies the security functionality that can be used and how the product is configured and operated.
              </para>
              <para>
                Using an evaluated product in a manner for which it was not intended could result in the introduction of new vulnerabilities that were not considered as part of the evaluation.
              </para>
              <para>
                For products evaluated under the Common Criteria, information is available from the product vendor in the product’s installation, administrator and user guidance documentation. Further information is also available in the Security Target and Certification Report. For high assurance products and HGCE configuration guidance, documents can be obtained from DSD.
              </para>
            </content>
            <controls>
              <block>
                <ID>0289</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Installation and configuration of evaluated products</title>
                <content>
                  <para>
                    Agencies should install, configure, operate and administer evaluated products in accordance with available documentation resulting from the product’s evaluation.
                  </para>
                </content>
              </block>
              <block>
                <ID>0290</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Installation and configuration of evaluated products</title>
                <content>
                  <para>
                    Agencies must ensure that high assurance products and HGCE are installed, configured, operated and administered in accordance with all product specific guidance produced by DSD.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Use of evaluated products in unevaluated configurations</title>
            <content>
              <para>
                When using a product in a manner for which it was not intended, a security risk assessment must be conducted upon the unevaluated configuration. The further a product deviates from its evaluated configuration, the less assurance can be gained from the evaluation.
              </para>
              <para>
                Given the potential threat vectors and the value of the information being protected, high assurance products and HGCE must be configured in accordance with DSD’s guidance.
              </para>
            </content>
            <controls>
              <block>
                <ID>0291</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Use of evaluated products in unevaluated configurations</title>
                <content>
                  <list>
                    <head>Agencies wishing to use an evaluated product in an unevaluated configuration must undertake a security risk assessment including:</head>
                    <item>
                      the necessity of the unevaluated configuration
                    </item>
                    <item>
                      testing of the unevaluated configuration in the agency’s environment
                    </item>
                    <item>
                      new vulnerabilities introduced due to the product being used outside of its evaluated configuration.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0292</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>DSD</authority>
                <title>Use of evaluated products in unevaluated configurations</title>
                <content>
                  <para>
                    High assurance products and HGCE must not be used in an unevaluated configuration.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Product Classifying and Labelling</title>
        <objective>
          <block>
            <content>
              <para>
                Products and Information and Communications Technology (ICT) equipment are classified and appropriately labelled.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes classifying and labelling of both evaluated products and general ICT equipment.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Non-essential labels</title>
            <content>
              <para>
                Non-essential labels are labels other than protective marking and asset labels.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Classifying Information and Communications Technology equipment</title>
            <content>
              <para>
                When media is used in ICT equipment there is no guarantee that the equipment has not automatically accessed information from the media and stored it locally without the knowledge of the system user. The ICT equipment therefore needs to be afforded the same degree of protection as that of the associated media.
              </para>
            </content>
            <controls>
              <block>
                <ID>0293</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Classifying Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies must classify ICT equipment based on the sensitivity or classification of information for which the equipment and any associated media in the equipment are approved for processing, storing or communicating.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Labelling Information and Communications Technology equipment</title>
            <content>
              <para>
                The purpose of applying protective markings to all ICT equipment in an area is to reduce the likelihood that a system user will accidentally input sensitive or classified information into another system residing in the same area that is not accredited to handle that information.
              </para>
              <para>
                Applying protective markings to assets helps determine the appropriate sanitisation, disposal or destruction requirements of the ICT equipment based on its sensitivity or classification.
              </para>
            </content>
            <controls>
              <block>
                <ID>0294</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Labelling Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies must clearly label all ICT equipment capable of storing information, with the exception of HGCE, with the appropriate protective marking.
                  </para>
                </content>
              </block>
              <block>
                <ID>1168</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Labelling Information and Communications Technology equipment</title>
                <content>
                  <para>
                    When using non-textual protective markings for ICT equipment due to operational security reasons, agencies must document the labelling scheme and train personnel appropriately.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Labelling high assurance products</title>
            <content>
              <para>
                High assurance products often have tamper-evident seals placed on their external surfaces. To assist system users in noticing changes to the seals, and to prevent functionality being degraded, agencies must limit the use of non-essential labels.
              </para>
            </content>
            <controls>
              <block>
                <ID>0295</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Labelling high assurance products</title>
                <content>
                  <para>
                    Agencies must not have any non-essential labels applied to external surfaces of high assurance products.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Labelling High Grade Cryptographic Equipment</title>
            <content>
              <para>
                HGCE often have tamper-evident seals placed on their external surfaces. To assist system users in noticing changes to the seals, and to prevent functionality being degraded, agencies must only place seals on equipment when approved by DSD to do so.
              </para>
            </content>
            <controls>
              <block>
                <ID>0296</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Labelling high assurance products</title>
                <content>
                  <para>
                    Agencies must seek DSD authorisation before applying labels to external surfaces of HGCE.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Product Maintenance and Repairs</title>
        <objective>
          <block>
            <content>
              <para>
                Products and ICT equipment are repaired by cleared or appropriately escorted personnel.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes maintaining and repairing of both evaluated products and general ICT equipment.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information relating to the sanitisation of ICT equipment and media can be found in the Product Sanitisation and Disposal section of this chapter and the Media Sanitisation section of the Media Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Maintenance and repairs</title>
            <content>
              <para>
                Making unauthorised repairs to products and ICT equipment could impact the integrity of the product or equipment.
              </para>
              <para>
                Using cleared technicians on-site is considered the most desired approach to maintaining and repairing ICT equipment. This ensures that if sensitive or classified information is disclosed during the course of maintenance or repairs the technicians are aware of the protection requirements for the information.
              </para>
            </content>
            <controls>
              <block>
                <ID>1079</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Maintenance and repairs</title>
                <content>
                  <para>
                    Agencies must seek DSD approval before undertaking any repairs to high assurance products and HGCE.
                  </para>
                </content>
              </block>
              <block>
                <ID>0305</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Maintenance and repairs</title>
                <content>
                  <para>
                    Where possible, maintenance and repairs for ICT equipment should be carried out on-site by an appropriately cleared technician.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Maintenance and repairs by an uncleared technician</title>
            <content>
              <para>
                Agencies choosing to use uncleared technicians to maintain or repair ICT equipment need to be aware of the requirement for cleared personnel to escort the uncleared technicians during maintenance or repair activities.
              </para>
            </content>
            <controls>
              <block>
                <ID>0307</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Maintenance and repairs by an uncleared technician</title>
                <content>
                  <para>
                    If an uncleared technician is used to undertake maintenance or repairs of ICT equipment, agencies should sanitise and reclassify or declassify the equipment and associated media before maintenance or repair work is undertaken.
                  </para>
                </content>
              </block>
              <block>
                <ID>0306</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Maintenance and repairs by an uncleared technician</title>
                <content>
                  <list>
                    <head>If an uncleared technician is used to undertake maintenance or repairs of ICT equipment, the technician must be escorted by someone who:</head>
                    <item>
                      is appropriately cleared and briefed
                    </item>
                    <item>
                      takes due care to ensure that sensitive or classified information is not disclosed
                    </item>
                    <item>
                      takes all responsible measures to ensure the integrity of the equipment
                    </item>
                    <item>
                      has the authority to direct the technician.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0308</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Maintenance and repairs by an uncleared technician</title>
                <content>
                  <para>
                    Agencies should ensure that the ratio of escorts to uncleared technicians allows for appropriate oversight of all activities.
                  </para>
                </content>
              </block>
              <block>
                <ID>0943</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Maintenance and repairs by an uncleared technician</title>
                <content>
                  <para>
                    If an uncleared technician is used to undertake maintenance or repairs of ICT equipment, the technician should be escorted by someone who is sufficiently familiar with the equipment to understand the work being performed.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Off-site maintenance and repairs</title>
            <content>
              <para>
                Agencies choosing to have ICT equipment maintained or repaired off-site need to be aware of requirements for the company’s off-site facilities to be approved to process and store the products at an appropriate level as specified by the Australian Government Physical Security Management Protocol.
              </para>
              <para>
                Agencies choosing to have ICT equipment maintained or repaired off-site can sanitise and reclassify or declassify the equipment prior to transport and subsequent maintenance or repair activities to lower the physical transfer, processing and storage requirements specified by the Australian Government Information Security Management Protocol and Australian Government Physical Security Management Protocol.
              </para>
            </content>
            <controls>
              <block>
                <ID>0310</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Off-site maintenance and repairs</title>
                <content>
                  <para>
                    Agencies having ICT equipment maintained or repaired off-site must ensure that the physical transfer, processing and storage requirements are appropriate for the sensitivity or classification of the equipment and that procedures are complied with at all times.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Maintenance and repair of Information and Communications Technology equipment from secured spaces</title>
            <content>
              <para>
                When ICT equipment resides in an area that also contains ICT equipment of a higher classification, a technician could modify the lower classified ICT equipment in an attempt to compromise co-located ICT equipment of a higher classification.
              </para>
            </content>
            <controls>
              <block>
                <ID>0944</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Maintenance and repair of Information and Communications Technology equipment from secured spaces</title>
                <content>
                  <para>
                    Agencies having ICT equipment maintained or repaired off-site should treat the equipment as per the requirements for the highest classification processed, stored or communicated in the area that the equipment will be returned to.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Product Sanitisation and Disposal</title>
        <objective>
          <block>
            <content>
              <para>
                Products and ICT equipment are sanitised and disposed of in an approved manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes sanitising and disposing of both evaluated products and general ICT equipment.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Additional information on the sanitisation, destruction and disposal of media can be found in the Media Security chapter.
              </para>
              <para>
                With the convergence of technology, for example some televisions and even electronic whiteboards now contain non-volatile media, sanitisation requirements are becoming increasingly more complex.
              </para>
              <list>
                <head>Media typically found in ICT equipment includes:</head>
                <item>
                  electrostatic memory devices such as laser printer cartridges and photocopier drums
                </item>
                <item>
                  non-volatile magnetic memory such as hard disks
                </item>
                <item>
                  non-volatile semi-conductor memory such as flash cards
                </item>
                <item>
                  volatile memory such as Random Access Memory sticks.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Disposal of Information and Communications Technology equipment</title>
            <content>
              <para>
                When disposing of ICT equipment, agencies need to sanitise any media in the equipment that is capable of storing sensitive or classified information, remove the media from the equipment and dispose of it separately or destroy the equipment in its entirety. Once the media in ICT equipment has been sanitised or removed, the equipment can be considered sanitised. Following subsequent declassification approval from the owner of the information previously processed by the ICT equipment, it can be disposed of into the public domain.
              </para>
              <para>
                DSD provides specific advice on how to securely dispose of high assurance products, HGCE and TEMPEST rated ICT equipment. There are a number of security risks that can occur due to improper disposal including providing an attacker with an opportunity to gain insight into government capabilities.
              </para>
            </content>
            <controls>
              <block>
                <ID>0313</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal of Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies must have a documented process for the disposal of ICT equipment.
                  </para>
                </content>
              </block>
              <block>
                <ID>0311</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal of Information and Communications Technology equipment</title>
                <content>
                  <list>
                    <head>When disposing of ICT equipment containing sensitive or classified media, agencies must sanitise the equipment by either:</head>
                    <item>
                      sanitising the media within the equipment
                    </item>
                    <item>
                      removing the media from the equipment and disposing of it separately
                    </item>
                    <item>
                      destroying the equipment in its entirety.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0314</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal of Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies must contact DSD and comply with any requirements for the disposal of high assurance products.
                  </para>
                </content>
              </block>
              <block>
                <ID>0315</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Disposal of Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies must contact DSD and comply with any requirements for the disposal of HGCE.
                  </para>
                </content>
              </block>
              <block>
                <ID>0321</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Disposal of Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies must contact DSD and comply with any requirements for disposing of TEMPEST rated ICT equipment.
                  </para>
                </content>
              </block>
              <block>
                <ID>0312</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Disposal of Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies should return ICT equipment and associated media that have processed or stored Australian Eyes Only or Australian Government Access Only information to Australia for disposal.
                  </para>
                </content>
              </block>
              <block>
                <ID>0316</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal of Information and Communications Technology equipment</title>
                <content>
                  <para>
                    Agencies must formally authorise the disposal of ICT equipment, or waste, into the public domain.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sanitising printer cartridges and copier drums</title>
            <content>
              <para>
                Printing random text with no blank areas on each colour printer cartridge or drum ensures that no residual information will be kept on the printer or copier. DSD is able to provide a suitable sanitisation file to use upon request.
              </para>
            </content>
            <controls>
              <block>
                <ID>0317</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sanitising printer cartridges and copier drums</title>
                <content>
                  <para>
                    Agencies must print at least three pages of random text with no blank areas on each colour printer cartridge or copier drum.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Destroying printer cartridges and copier drums</title>
            <content>
              <para>
                When printer cartridges and copier drums cannot be sanitised due to a hardware failure, or when they are empty, there is no other option available but to destroy them.
              </para>
            </content>
            <controls>
              <block>
                <ID>0318</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Destroying printer cartridges and copier drums</title>
                <content>
                  <para>
                    Agencies unable to sanitise printer cartridges or copier drums must destroy the cartridge or drum in accordance with the requirements for electrostatic memory devices.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Disposal of televisions and computer monitors</title>
            <content>
              <para>
                Turning up the brightness to the maximum level on televisions and computer monitors will allow agencies to easily determine if information has been burnt in or persists upon the screen.
              </para>
            </content>
            <controls>
              <block>
                <ID>0319</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal of televisions and computer monitors</title>
                <content>
                  <para>
                    Agencies must visually inspect televisions and computer monitors by turning up the brightness to the maximum level to determine if any information has been burnt into or persists on the screen.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sanitising televisions and computer monitors</title>
            <content>
              <para>
                All types of televisions and computer monitors are capable of retaining information on the screen if appropriate mitigation measures are not taken during the lifetime of the screen. Cathode ray tube monitors and plasma screens can be affected by burn-in while liquid crystal display screens can be affected by image persistence.
              </para>
            </content>
            <controls>
              <block>
                <ID>1076</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sanitising televisions and computer monitors</title>
                <content>
                  <para>
                    Agencies must attempt to sanitise televisions and computer monitors with minor burn-in or image persistence by displaying a solid white image on the screen for an extended period of time.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Media Security</title>
      <section>
        <title>Media Handling</title>
        <objective>
          <block>
            <content>
              <para>
                Media is classified and labelled.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes classifying and labelling media.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information relating to classifying and labelling Information and Communications Technology (ICT) equipment can be found in the Product Classifying and Labelling section of the Product Security chapter. Information on accounting for ICT media can be found in the ICT Equipment and Media section of the Physical Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Reclassification and declassification procedures</title>
						<content>
							<list>
								<head>When reclassifying or declassifying media, the process is based on an assessment of relevant issues, including:</head>
								<item>
									the consequences of damage from unauthorised disclosure or misuse
								</item>
								<item>
									the effectiveness of any sanitisation or destruction procedure used
								</item>
								<item>
									the intended destination of the media.
								</item>
							</list>
            </content>
            <controls>
              <block>
                <ID>0322</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reclassification and declassification procedures</title>
                <content>
                  <para>
                    Agencies must document procedures for the reclassification and declassification of media.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Classifying media storing information</title>
            <content>
              <para>
                Media that is not correctly classified can be stored, identified and handled inappropriately or accessed by a person who does not have the appropriate security clearance.
              </para>
            </content>
          <controls>
            <block>
              <ID>0323</ID>
              <revision>3</revision>
              <updated>Sep-11</updated>
              <classification>G</classification>
              <classification>P</classification>
              <classification>C</classification>
              <classification>S</classification>
              <classification>TS</classification>
              <compliance>must</compliance>
              <authority>AH</authority>
              <title>Classifying media storing information</title>
              <content>
                <para>
                  Agencies must classify media to the highest sensitivity or classification stored on the media since any previous reclassification.
                </para>
              </content>
            </block>
          </controls>
		  </block>
          <block>
            <title>Classifying media connected to systems</title>
            <content>
              <para>
                There is no guarantee that sensitive or classified information has not been copied to media while connected to a system unless either read-only devices or read-only media are used.
              </para>
            </content>
          <controls>
            <block>
              <ID>0325</ID>
              <revision>3</revision>
              <updated>Sep-11</updated>
              <classification>G</classification>
              <classification>P</classification>
              <classification>C</classification>
              <classification>S</classification>
              <classification>TS</classification>
              <compliance>must</compliance>
              <authority>AH</authority>
              <title>Classifying media connected to systems</title>
              <content>
                <list>
                  <head>Agencies must classify any media connected to a system the same sensitivity or classification as the system, unless either:</head>
                  <item>
                    the media is read-only
                  </item>
                  <item>
                    the media is inserted into a read-only device
                  </item>
                  <item>
                    the system has a mechanism through which read-only access can be assured.
                  </item>
                </list>
              </content>
            </block>
          </controls>
					</block>
          <block>
            <title>Reclassifying media</title>
            <content>
              <para>
                The media will always need to be protected according to the sensitivity or classification of the information it stores. If the sensitivity or classification of the information on the media changes, then so will the protection afforded to the media.
              </para>
              <para>
                The following diagram shows an overview of the mandated reclassification process.
              </para>
              <image>
iVBORw0KGgoAAAANSUhEUgAAAmkAAAFVCAIAAAA7Q+/OAAAABGdBTUEAALGPC/xhBQAAT2RJREFUeF7tnX1wFNeZ7nP/26qt2tra2tra1G6twGMXFmRsCAkolZjggH2F
XKurJTZxFjtrW5YjkkC4kFgkkgG7kGP8IZVkWw7kWpIhJgaMNICIP/gYY1uAEIMkwLYiX5Lri7HsaztElr2E4Nm5b/eZ6emZ6Zk53dN95pzpZ2rKJQ+nzzn9vKfPr9/3
fP23WCz2BXygABSAAlAACkABfgWInfhAASgABaAAFIAC/Ap8gT8pUkIBKAAFoAAUgAJavBYqQAEoAAWgABSAArYUADttyYXEUAAKQAEoAAXgd6INQAEoAAWgABSwqQD8
TpuCITkUgAJQAAr4XgGw0/dNAAJAASgABaCATQXATpuCITkUgAJQAAr4XgGw0/dNAAJAASgABaCATQXATpuCIXmpKvBff4ld+iD26Ujsk8HYH1/A1ysFSF4SmaQmwfGB
AsoqAHYqazpU3BUFPv809tlbsY9Csfc34ytaAXpHuXgWEHWlISMTwQqAnYIFR3HSKECuz0S/aFqA0JkKfPCM5onCDZXmyUBFeBQAO3lUQprSUoC6aVBTNop/uF0L5OID
BRRRAOxUxFCoplsK/PlcjBwd2ciB+jAFKISLDxRQQQGwUwUroY5uKUBdMygluQI0mQgfKCC9AmCn9CZCBd1SgOYESY4NVA/ep1utHfl4rADY6bHAyF4SBeBxqgXmyxck
aTioBhSwVADsRMPwgQK0EAVjnGqxk1YN4QMFJFYA7JTYOKiaWwrQOkK1yIHakgK0cAUfKCCrAmCnrJZBvdxSgFY+AEUqKkChAiz6dOspQD5uKwB2uq0o8pNNgQuHwE5V
FcCSFdmeJtQnoQDYibZQ0grQSKeKLhfqzBTAqGdJP51K3xzYqbT5UPl8CmB6reoYprcffKCAfAqAnfLZBDVyUQEEbFVnJ63KxQcKyKcA2CmfTVAjFxWgXVJVh4fP609v
P/hAAfkUADvlswlq5KICPgdPCdw+vf3gAwXkUwDslM8mqJFbCtDeNDzweO/RyBPVVWVTAmVTgkuXHjzabnVVa3hlMLjypxNZM8ybIMv5oG//tOnqYFNPq0WhZ5sPPnB9
UKvYnKbuDZOs6BzpeW42PZNNk/11dVdPCVTeObizJnh1TfjtTVyiZZblSsUsb8Gt9oB8oIB7CoCd7mmJnGRTgGtlZ1vkgQqiZvJ7dWVouCODH3nRmDeBTXa+91DoP2aY
KjZnXc8jUffZqVVbK8UhOzdN9CSI6x07cTaZbE8W6hOLgZ1oBaWrAAc7o0dra8qurFr5o7Gz5G91jPd8mxzQnP5lFgTy+3xpKbMgJ16x1avH39scO3t/99IZgcraMfrb
ZUQ5RX78LkzsdKxA3gvBztJ9RtW9M7BTXduh5vkUyM/OjrG26wIpgcrkLzq9vt7a+b26q6/rPvqwKWbbPtZdo8V4r17Y/dsfJiKuBoT0HCq/F96pYZjCrXF/kQjx3qOD
zXoMdsHinraqeIDUmoXpFdMrQ9XoSGVnx/iLVD29lM4718Rjv4nqGZHesxtCK+dozuWCmhCLSMcLfSDudGb6nUa42Ljk/c3RUz9rJ4TTq8bquu7lFMFefY6cTuayk4Yn
VyeDz8kw+Iy6B1bp7yWb2S109qxYt+BKPRP9tSAvOCkB2JmvpePfxSsAdorXHCWKUiA/O/WIJfPnzI6UTim9rw9WLZgW0P7XYOemyf1L2eCo9v3m7Ko4sVLZqf2eSBNn
c2ZwWB9ctGZnRsW0ZFfWtG2IJtOn1kSrjzZuqlfbCEFXtO5/VGO58cuCpREiWR52plaV6XO2sVVjXjK4nZ2dOvhTUmrjxCY9WSZZRnkzaQp2inpiUA6/AmAnv1ZIqZoC
edn53obuyitTI7R6EDIJIcM9MtCoU40R6P2O892VLHHs/VR2xt1NUwIdfnFni8VgGVMt2WlRsQTdk+lZTb4dPkWjs+2jbQtN1dY9VH3ENLjyx4OaH6zxLzr8o2WM9KmZ
6AqkjVxeWfVA4+T7bCYRXfKYLgvzoePTi6yuMjI3dNMrpt+pOQqt14Q7Ng52qvbk+aG+YKcfrOzXe8zLTh14uf3OxAzYBBpTqcZ8KQt2JuLARgJTSqKgKSTr2O/MWpOO
8f0/7G77YdiYMEwR1I7a7s57Wew0dbKugfwkO1OqqpUyraZt7ag5uJ0s2mKuUOqdxt3NhEOc8DVzvBzA7/Tr86rWfYOdatkLtbWjQH525h3vNOKKgtlpOd6Z6jJas/Ox
yaP3hrbcN/7epsmjq1pXLgkdfXisZ8Xe/Y9G328f23lb02p9VlROvzODneSa686rMTAMdtpphkhbkgqAnSVpVtyUrkB+djKvyHqebar/lBazTY+UpsdsM/xOHVcsEEqT
hvT1JzlitvHRwUTk871HwqvnZKS3jh5r1aZJTP00J4jVWcNecGndqBmZPDFbfS5PIszLYrY0etqmzfpJRlyt1qiYo9MsmJyM2cLvxLNZIgqAnSViSNyGhQJ0+mP+aZxZ
13dmYWfKDJ3ggtk38sVsY++bC7ryxgWzcs6zTfA1OeNmxrLuh1LXd2aZtZS6MJRGJS/oqEtM3uEY70ypKs3O1Qd3U+YKaVOoso53soh0lrlC8Rg4YrZ4YhVXAOxU3ICo
fm4F6PzkvPjMsq9QFnbSaOI965YvvJNodHVlz87vcY53atVIrBUJLq0d6K7Ow04tfd59hSxXy9BiktXxdSAr74loM4ni61a1/YmeaNRWhuT2O81FJ9eoUBD4R03aVNsZ
dW2rQ/FdlrLsjZB1jYojvxMnYOMxl08BsFM+m6BGLirwxxfyszMvXFMS6E5VfHYr8/z0Sa32MuFb14g8mQL4QAH5FAA75bMJauSiAp+OuE41Ntpn2sOvgD1gQce8CtDb
Dz5QQD4FwE75bIIauagA53bweXvwVNeTwrZ69NK0U4+9HOB3citAbz/4QAH5FAA75bMJauSuAjjCU2mu09sPPlBAPgXATvlsghq5q8Ang66HbZGhIAVweKe7zwJyc08B
sNM9LZGTnAp8/qmgjl5p907Oyl88K2ebQq2gANiJNuADBSb6gU/1FIDT6YNHU91bBDvVtR1qzq0AuZ48Cz3l9L18W6s/n+M2MBJCAdEKgJ2iFUd5xVHgs7fUc7x8S026
cQoV4AMFJFYA7JTYOKiauwpcOAR8qqHAR6EY9hJyt/EjN7cVADvdVhT5SasAdcfUKfvZmVPi3gFOaZ8gVMykANiJ5uAnBYBPyfFJoVp4nH56ItW9V7BTXduh5k4VwIpP
CQlKk7loTBofKKCIAmCnIoZCNd1VgI72xH5DkhCUqEkb78HddLeFIzePFQA7PRYY2cusAC29d/+gFe6dWiVBVxGrQUOb5GuCmjI/I6hbFgXATjQN3ytAqz8JojTSphRH
zYdL09/KzIEikUlqEpxkxwcKKKsA2Kms6VBxfyuQzk5/q4G7hwKCFQA7BQuO4qCAOwqAne7oiFyggCMFwE5HsuEiKFBsBcDOYlsA5ftaAbDT1+bHzaurANipru1Q8xJQ
AOwsASPiFvyoANjpR6vjnqVRAOyUxhSoCBSwowDYaUctpIUCLisAdrosKLKDAmIUADvF6IxSoIClAmAnGkaKAh9//HGotxdf+RVIY6f8FUYNSQF6vtDjlIYCYGdp2NG1
uxgbG0vrlPG/UAAKuKUAPV+uPavIqKgKgJ1FlV++wsFOt3pJ5AMFMhUAO+Xr8xzWCOx0KFypXgZ2oseHAt4pAHaWTM8JdpaMKd25ETM73ckRuXijAOYKeaOrJ7kaxgI7
PdG3GJmCncVQXeIywU6JjZNSNbBTFUtRPcFOhYzFWVWwk1MovyQDO1WxNNipiqXAToUsxV9VsJNfK1+kBDtVMTPYqYqlwE6FLMVfVbCTXytfpAQ7VTEz2KmKpcBOhSzF
X1Wwk18rX6QEO1UxM9ipiqXAToUsxV9VsJNfK1+kBDtVMTPYqYqlwE6FLMVfVWt2njr9Br7+VKBv3wtGp+xPBVS56zR2qlJtf9bTMBY9X/5UoOh3ffrNsd+9/fv3xt//
6KOPL178Mz8js6WUnZ2tPcfxFalA05O7jOdcZLkoy64Caey0eznSi1TAMBY9XyLLRVmGAnsPD9PXQPiZN39HHP3LX/7iGKKys/ML94fxFanA3/7418ZzLrJclGVXgTR2
2r0c6UUqYBiLni+R5aKsTAW+/fhrzdsHDhwZYRx9++wfnLmhYCfYnKIA2KlKdwN2qmIpqifYKaGxvvXYq1tejDCCkg/6+edRWz4o2Al2gp1KtgGwU8LuOFuVwE5pjUUE
3XnwJOHzjdG3bYVwwU4l+03vGiL8Tu+0dTdnsNNdPT3NDez0VN7CM//5r48RPk+/8RZ//BbsBDvhdyrZBsDOwntMYTmAncKkdlwQjYOeGDrDj0+wU8l+03H7yHsh/M68
EhUxwd/f8+Tf/GQnq4AlO8l8/3DnY0WsIYq2VADsVKJhMHxS8JZn7BPsBDvhdyrTBv56zR7qhf9xafNf3fdSGjvpn/6pZhX9SH8o0U/5qpKGsch2xo2TEX0lghI3u6Lz
CAVvf/+Hd/LOGwI7lek3xbQ8+J1idHZcStnXF1NHfMX0r6Sxk/0v/avjnHGhiwpQeMCMyUx2/t0Pn6Z3HRdLRFZuKbBp7wnC5yeffJIbn2An2Am/U6U2QGFbS2qyHxGw
dasDLTyfqbMX/suC77EFnWZ2Elb/eVE9/UL4LLwU5OC6AsFfvPLacaLnKNipUs/oejuwmyH8TruKCU6fGa01oxRhQMHmyFEc+Z3MNARRw0ZTr72O/U2RA3mqipqkKcCm
3V648Kcc+ITfCbLC71SsDTCvJfNLv6MTlEcBNjid7YuArTyWsqwJuZ60bx/YqVjnWMRWBb+ziOJzFk2xPssemcK5nDkgmRgFKGabjZ3YnE+MCRyXwlzPTz/7TNW94B3f
OS50pgDY6Uw3wVdlzhVCDFCwCXiKyzY4TVFcnsuRpogK0KgnsfPdd8+DnXA9uRQAO4v4uPIXzZajmL+IAfKrJyxltsHpLy5pElYHFORYAW2vvjNvgp1c5HCscslcCHYq
YUqaq5nGTsQA5TRc5lsOGc7Y4ELOOqNWTAEWts22Sx/mCoGpmCukZBtImb2JGKCshxVmDk5jDa4qbKZt4omddFa2pevpBjsHn19/6y233Jz3e+f6HQN2Tw9XReWSqSf8
TlVMaSyBID8GMUCZrWZ+y8EaXJktlVm3waEz2YY83WDnse76aVmnYpsiS3PrO/vBTsmbDtgpuYGM6pmXQGAfPpmtRm825gA7jCWzsdLqtvfw8Ju/O+uZ36mfHZrxPT0Y
fr694a6qOdMCZdO+tmRN+47woHVKy8vjPyqkcmlUFexUyI5sfz7EACU3mfkth1atSF5bVM+sADscWyA7T4S3t6/5ztyCqMlgDEMKVgDsFCx4IcWxJRDYh68QDcVcy95y
6Is1uGIEd6uU1h5tdz4h7HSPmmCnW+a3lQ/YaUuu4iZmSyCwD19xrcBTOr3fMHbCWDxyyZNGBDuHjvy2s3lZ5YwrConQZsZ+5RHRJzUBO9UyNPwYJezF3nKwaaISxjJX
0mN2Dr2yLU7NKVfNuemuhse3vxg+FD6c8X2tP3Iac4Ukbz1gp+QGQvUUVYDAiYNTlLOdx+zEPFtZ15Y5aKlgpwPR6JKaJ4898dLveo69M3b+TyX/pdukm63rOuFMq+Je
NfeR1+99boRuof+tD4Ra6tzHQovT2yHdI90p3W9xNVe3dI/ZObi3fc2ahoa837Xtu7VxV1tfdUVXtOZgpy3DET9eHj7/8eSf854yX5IJ6Mbp9um9wZZoRUlMyHzm8FnC
SUkaguemhn//Mb3xFEV8dQv1mJ02cQh2ytySwE5O61A39O5Hn/L0WX5IQ0ySlqBUMXK//GAFnnuk1x0QlPMZp2Rgp5KbrvEb2MWUYGdeMcnX9LP7kqODpvBgXvVEJiBf
k6rEQxS/pZH5XUdkC8lbljh2Dg0c7ut5rrPjifb2x9vbN3Vu6+0LDw4V4JjmvTckcFcBsDO3nuiLc2OGAoNELHfbpLPc6BXHt7F0nleBi5c+V3TE2ll7cHaVCHYO9e95
suG7X5uauTkfbSr0syd3H3FGUGc3jKscKwB25pAOoT+eTplC2UXH54OhN4gNPLX1cxrgM28/6Tk7T4Y7V8wvD5Rdc/3S1Rtaftm5bef2Hc9v3/Gbzo7WDatuu54WfU69
cUVn+KR9BzTvvSGBuwqAndn0BDj5MUPep7vN0lZuNK2Uv6o+Twl85m5aHrPz1KGO2+cGgv9+//ZXLek41L+reclXA8G7O8IjtiYKYU8+W12GK4nBTksZaTapzztZu7df
rLFPikPC47RlLIpsFz1O4Erf5UUmHrPz1V/eHphxU/PeHG7lyb5f3DT1y7d3hMFOLwzsYp5gZ6aY8GNs9cVG4qLMvMXkZwfGoldDF/uQUsrKW3YO73vwhrJ854tp+ydM
u6F537DNsG0pmUGJewE7M82EKScOumO6hCZzCm7zmMnlzFJ0VVFedAQ3DwfFecvOU5rfWb6wcdfxrFw8c3zX2oXwO1XYfgjsTHvAaDGc4/4IF4rc0YYCj4jWOm5yNJzv
AC0lf4nH7Dz9Wmf9NwJTb6hv2/36cOa2QSOv726vp5lE1y6no68Rs5W8tYGdaQaC0+m4O6YLRfbItG1QIVXFtXA9Mztnr9n5xqmB0IM0G6iM9oKv+f6q+5pbaHEnfVua
G1d//18rrqLDd4JLH9w9YBecmCskHrRgp1lzmniCLrVABYTNQ8FIZ4GWopcP8R2O5CV6z06K1g69tqv9Z7fPv4YdU5f8zlh4e8MTu14ddgBOsFN8wwI7zZpjem2B3TFd
LmYHOPKZCq+qz3Oglw/xHY7kJQphZ3ywc2TgtUN9PbS4k76hvgP9AxZRXBvbwUuubOlVD+w02xSuTOE4EbPWE8PShVsKM4aKEbO1OXuW3wctPThJfkdgp9lArvRHPs+E
5u8IaPOIELjSzMQECQS0B7eK8NjvxPmdKkyg5WxMYKchFAY7XemOxXgz2J3fFWMVa0cLzt5JfDKP2Tn4/Ppbb7nl5rzfO9fvsD1dSLxYPi8R7DQagMdbIkQnx15ura1g
MwOCte0Hxybsd3+TkZZFs1sil2Ox6Hhk757IeDQWuxxpnbmoNTJpPzevrhCwUsXj6Prl8d7l5mkcwdqWkC62rU/SRrYuE5hY/JJcyftbj9npWcAWc4XENyyw09Cc9hP3
sNeaPN5aOatq7QGtA46eD6+tDlS2Rybt9sbJCl6OtMyeqVNUvo+ACZwe3zRj5/LQONN3Yqx3bVXZ4tbIBVvlymwjdiOYLpTW5YKdOL8zlwL/cOdjf3XfS6zRWLLzb36y
k34XD/LilujpJjXRsa6asqXdYxdZn6X/b0HOosz9soBIoC2G2U+cxk7K4EKkZXGgumvMztuOzDYyNCnuQydb6R6zk8Vsl/1y/ykbE2g5pwvJJmVJ1ufv73my7OuLGR0z
2UlkvWL6V/56zZ6SvPccN+U9O+c1hT+M91mTY+HeFyLjl2KxS+ORZ5sqp2sRwsqG1sbqQG3veEyLzQYqVzbFY7zVTb2jekyWxWyPnUtGFBe1HgsnYraXxo8/VVeuLxgr
v7v1wBgL40bHj7Sn52OfJnauKEV2stcd9vZj0rlybUiPvZtErqhreXls8pIp6rtoY0vj7PI7mhqqA+yFaXI0RIaOR++fGhy/ZPVqlXzTsqO97bR+e8xz36/H7GRzhRY8
2DcCdqrq4BId6dH950X1X7x1vTGu88UlTVNnL6T/JbL68InylJ3xOG1ZdVPXPh2Z8U/0fO+y8oq6rjOT1COHN1RRf2qws6x6Xfh8NP4760mT451Jn8YY75wIN8Wzik5G
2qtYRx99J1S/qK7tyHg0Ojm6ta7cduDRdmcci5UkO2PjvXVls+p6z2kmm3l3+3GKvk+MdtUHtdj7B+HGecHaraMUhNeD8zVdo/pIdDyurv1RNj0esY99qCfWkBmbPNNN
rzXkzl4e7a6OXxWLXRzrWmrXx3VgJnaJD5/0HLcMdqqKNGHt+J9qVqVvamHa4IIcU2E1kacgb9mpdVMT5Gx2M4ejsnGrNvdEjw0mI4Far5pkp/G7Rket187DTq1zT7i2
NE1lz57w2ITm0JSvDU+wUKOWP5tq5OmnNNkZt8IYgS3YGI5P9NLeV8iVfDNUOyvxIwUSXgiFNac/lZ0JP9JspmT0/sNktlEzRz01FNiZTgoh7EzbTsjif/OdtWI150ie
nrS0a2IO1WZC1BgNLW0R0u7Oe3Ym+sF4yI460w+12KzmaLKPHqo1/E7jd052MjeojGKGz4V6D49pE5GiE+G1wdRnE+zkwFHmeGcs4XdGtPebFEmJnRO6T0/Tp1t6erVX
FlZEKjvjM490H9SYhcSmSevubOItJy1+y1HbgpL46hnPe7NC2Dnjm/8jzzIVrFGR2v1l4dnMLwVy87awkkzgJTtpgcrhEFtSwj5x32Jw0E12Mv6Sc7tL827L67tHL2js
TPqdBXWy/BeXpN+ZQNo5LeJq+J0polBcYU+oq7GKXl+0ILw9dupNYmFT+APNZDYnJfGbJjNlST7Ljm9KCDsx3qn4Dgk0umnJzr/74dOOW57SF3q5vpP5fyZvI87OM+dz
xGxt+p0pqwm1/KeTi3kpZX5v6cRsPT59LMc829TBSBazPT4W2cNmftFHT6AvH7L0O3X/NTlrzDTjWrsw2PhsT+NCNlwq5qP0M+t65eVg53BkIHKac3qtkcx1LZBhNgVo
Jm0mO2kOkW8V85KdNNZJnawxW4StF9QGwHLNFbLLTg2TFct634nG2LQg/W9trlCFPo3lcinNFfJ4X6Fc6ztNJkvMFZp4k95UgvW9NLOLTf9hf1uz03KukI5KnaMUChI0
w5ZKxPrOtO7OY3YO7m1fs6bhgV8fslijcvpE/4FdXY9vWHVH1Zxv1NMBnjY3UvBtx12UG6f5tGn4pDlERamJJIV6+aaftq+QsU+NeWGJvozB+XinKSua0LtFmwmq9cjG
GhXTwhUv7zQmYF8hOijUy1vIva9QUmdjfyjTGpXpVY3PMh80CzuJr+lrVEyR/OnCZthSodhXSCw7M3E4PHio77lNDzfV3zz/GjaENnVu1R0/2/RiBOyUhAqW1aD5tGns
pF0RZK6w13XDwdeuAIl2BvbaUqV58LXYGbZka9pS32tLqZW/x35nnJ1mF3Naogu+YubNa9q6evcPjNilJkuvltCq15bm05rZSbOHVL+jAuvvsTfjCpgUyKRAK/BcXpIb
9wueYUstCeeoiPU7hw49+4jJxZwx/5b6pkc2/WZnS+30smk3NO8bthmnNVOW57FBGhcVoFm1Bj7/cWmzizmrmBVOhSyczGLO76TW5fF0ocKVsJuDk23/7JaRlp6OEFfx
OfWuzh77ncYZZBSYvWf9pt1HhjRYnj7a+QOw0zujepQzzao12OnDffjSVJ37yOsFdka4XMBG8MxqCBIU2NhohMKjXkXdbD1m59Ar21vXr7jjpoqpbHXgNdcv/fH6lqe7
m28HO1VsNGx/Pn/uw5dpL/TIBfbI9P4h5ikoybBtgeLbulzAMlwxLcHFUjxmZyIkOzRwuG/b5kfW/fi2+dckxzv/dcWG9u7t+14/4Shy66IKyIpTAbY/nz/34cuUyNuV
Krb6NgUT05sHZ6tzJZnHK1UUNAB3lSniLewtxxVbi8lEEDtN45QjA+Hfbtv02PrlS6+fcQXj6FVzvruh57jdGUNiBEIpZgVobi3Zy5/78Fm2BPTI3D1wekLB42d40XFs
KTidls++eHaaDlQZPr5/9zZ9vUrNcqzvVGTvIdpjCO8ThgIIBjrrkYvSHeNFx4GxaKQTTqd87HQUqsW+QpbBQ3qtLsmv/Jz2cm9bB32dApcUa4ca8nRLbsKt5+YWsHmF
/M94UdkZOfLS7ue3/OqZ3UdO6fA7uX/bpsd/9ewup4Odfl7fSa+BtECClir75z2aelsaHqO7Fhzo43yq/WOIwrvq4voxWFlky4JY05mjBxAQsx3oe/wn/zaHbYlQ3bxv
SGdnf+f35+q/TPvakrVbwuxHe1/Ofq2UklFTpiVxtlp/6SUmUD0YkmtnDHqbIbqXntSu3xGpJGAjodyPPPDJaVaAM3dD8pqdg30bb5tJs4Hm3rJ83aNPdvbsH2B7vg+/
2vebze0PN921iHbmu+pba3cNngE7c5iK2jE2gTM/89QLSxVNAj7z9sj00iPJyBnwmdtYFNmW7fVUQhfIY3Ye27r82itnLtkYiiMz07McOtjx/Vll1y3fcgTstGwf9J4O
nybbo16UKSfZHmMCAwXS8yLEhwmoL5bKUmRBYgPGPi2bIr3iyDkyIhs+vWXn8L4Hbyj78u0d4Vxc1PYecrI/n2xSelEfekHGE54bNoKXCea1MnnDiBCYTUYGkrMvpncd
7G5hthRRU6pYTt5nrbgJvGXnyP7WxVOvvbX94Ej2scyRQ4/fGvjS4paXc6SxRG9xhRNQOiJLnC6abPiktoGRaQqW0JZ7kgRpczytxHWKFvj5DZXunZ4gUNNul+4tO0+d
OtRx+9xA8N/v3xYetMDn6cHwb+5f8tVA8O6OsO3TVOzeqlrpAU5OcLJkch6QZJ4RXfLOKHXB5LiQIaSdDp27ByB4UGCZ5uL5YYiE7pHulO4XyHTMBY/ZefqNk+HOFfPL
A2VXXDPvlvpV9zW3PN7eTt+W5sbV8SM8p964ojN80uYk29Jeo4I9UGyBkyVGL2D0AmknrTruHXChAAXMxhJQHIpwSwHP2amFWwde6tr4E9NOtmxf+CmBGQtvW/Vw14u2
d+Mr7fM7yVnJ76NMhJvKpwTK14YnolaYmYy0LArU9o5zIUhLPLslcjlr4jwJouORvXsi45YVycyTUu95ITJ+KRbLWy5X7Y1ExV046NYD6Uo+YKcrMorJBOwUo7PrpQhh
Z9ynHOp/5WBfz/Pbd9A31Hfg1f4IW6/i8Ou6FpJkyLNPjX7yLb1/zGsKf1gwO+0hKjP15UjL7Jm52JtyyeVI68xFrZHJQku1ul62yZzFalFgZ7GUd1Au2OlANBkuEclO
h4zMBlcZ5HO9DuR0ckxbuDjWtTRQ+0R347xgY3jCgiK2/M5CKSYPO3HgA2uQYKfrD6Z3GYKd3mnrac4es9M4+5oFabN+59ZjL3i916OpiRwoOxeqrajpOnO+d3mgumss
Hiy9NB55tqlyui7yvKrKWXrMVodo5cqm2grt9/K72w8c6Gms1tNMr2rsHZuki5OxU42CZdVrGu8IZkkQi44Ptt2t/+uUYG37wbGPx6kOcbMu2tjSOLv8jqYGyl/zLKPj
x7fGy6puammoKlseOrGjLtEGZreEB/RY8SXNh056onodlnaPXYyOH2ln1S6rbuod5XRUsRkK2Olpj+l65mCn65KKydBjdg4+v/7WW265Oe/3zvU7BuwGb8UIJLgUrjl+
2mCnDieNOhpmCLfR873Lyivqus5MxqKTkfYqQo7BzrLqdeHz0djEaFd9kJC59gCNTerpWcg3jZ2JBOMH1lXOqukajSYTRCfCa4Pl9d2j5OteiLQsZuQ2/E4de/HLY9F3
QvUVwdqto5PRqJYVQX15aPwypU7EbBPlRke7q1lB9NFdasr2Ml2+qK7tyHg0Ojm6ta58cWvkAsdbRYymego2mYTFwe+U0CjZqgR2KmQsc1U9ZqfTsUwejiqqeI5qU8CW
Aw8MYPosIY1D03XqXNb8v6QP+mG4cV6SnYlJQ2bWxmLkvM7SpwilsTMOY8ZUIxM9pV5KYoKSNkWo9zB5rqnsTFw+3luX4DqRXatzNnYavCR4Jjh6mV4LkjOhtNvJOZsp
RTb51xR63XTBTq8VdjF/sNNFMUVmBXZqkVJJvrRPGAc72WAnm0OrQUUf8kwb4EzBXnLCrcYz3fnTPtnYaSTIZCfx9Ew3xVHL727d1RsKj7E4aio745frPqiRlZ4mKztj
BtQTf3ymszYlyM/PTmzFCXZK8kTzVAPs5FFJwjQes3Nwb/uaNQ0P/PrQKTZRaOTQlocaGta273a4LsXsj0qoZoFV4plhq3tmbFAz8dX8s4nURSmesVNjZXRy7HCo92ka
W2Uh2cLZqd9URV3vWDxgGzX51hxvE2lJ5NwnocC2YetysNOWXMVNDHYWV3/HpXvMTjZXaMGDfSOMnUN9zTSRxMnMoMworuN7lvZCnvPFUuOuzGOjsc8LPDHbWKF+J01H
emFvYiVnouhJS3bqZRnh39wxW8OB3typzYHSBj5Tb9NezBZDnmCntM94ZsXAToWMJXC8E+y0ExDmOEJZh1ByXNM0QJhjrpCxSUKh7NTDxeUrQ+dpZwN95pH+tzU7+ecK
6b5sIkibwG3y8su25gpp040ufa7o0+hWtcFOt5QUkA/YKUBkL4qA3ynLYCdZl4OdmR5YYmJq9NL48afqaLMhiuVWNrTS4hBjnq1r7CTGJdeoBCobt+o+qDU7tbTGIpOK
usaV2hoVy3m2LOTKdkoyvRYkL6fh1QPxsVXOCK4Xj4pCeYKdihpLoWqjqkLY+a37th06fChM3wPbGm8KlH31rva9+v8a39cc7DFUesbjYCcnO/yerPTahq07AjttyVXc
xPA7i6u/49KFsDPPxgjkKjkZAXV8z9JeCHa6xXxpTSymYmCnGJ1dKQXsdEVG8Zl4zE42z7Yh79fJzFvxYnldItgJdrrSxsBOV2QUkwnYKUZn10vxmJ3YG8HluUJuwaXE
83H9OVErQ7BTIXuBnQoZy1xVsFOtuUIlzjy3bk/Rp9GtaoOdbikpIB+wU4DIXhThMTuxFzz8Trd4aCcfLx4VhfIEOxU1lkLVRlU9Zif2gi8+O7W990ydaUVdS69+9LSt
T+5zql0+xdpWzSwT+/zBBjsVagDwOxUyFmK2EsVpzcagzeQKx0ZGDjo7jSWek6MhWvpZ2U6nsHhQlixZKvo0ulVtsNMtJQXkA3YKENmLIjz2OzFXyI7fyXd4p10+pbKT
rp483ho/XMxuVmqkp3PcvHhUFMoT7FTUWApVG1UVws7hoy/ueOaX2w6djKP09GC4Z/PDD6xp+FlT8xNb9h0dcoTY0jNeXdcJD+iUwc6UM7+MfYKMo7DNmwdZnI+dsltQ
y8tpp2frO8X3Jo7grtAP4NRwnXIEt52zrB0IQtsCl17bsHVHYKctuYqbGH5ncfV3XLrn7DwZ7l5deS21j+nf7z6qMfL0sd0bvxO8Itlipi64+8mXElhlW8ZzfR3fs8wX
0l6sDmiR85JMdurHcGo75H12vnfl7NqnBmn4UztcbF5Vy/HJ2CX6kW1Uq59ZPUv/0RjR1E89049PMfmvpvFObWs9hkx2ZjU7XlRnZ/wI7kvj4Q1VyW3i3b7dWIzcd5lN
LKBuYKcAkd0qAux0S0nB+XjMzlOHOm6fG5i64K71HVv7+jVAngytX1BO2/J9Z/0zfQde2d/3zPolXw1M/W7L/mFOZBrJBCslpjieo1Rs0iaTnYnTNN890129sCn8oZ6h
vhv7TDrhmtLHDzOhbdUTh4IZdNRy008MpY92rIp+iqfxrymHY8cv1/LU2WnsVasd2T2rrveczRvhTU7uuxhjSVsK2CmtaTIrBnYqZCxzVT1m56u/vD0w46bmvYZbGem5
77qyKVct+kXfUNy5HNnfunjqlxa3vDzC526WNjv5jr/mpYieLrvfOfqytv26ecdE4txFS7AZdGTe5JRgbUtP757wmM7QJDvTjuA2jry+kHK8qJfs/Hjyz4o+ii5WG+x0
UUyvswI7vVbYo/y9ZefwvgdvSNmrdmB7ww2Bsi/f3hFOepnaGtBpNzTvGwY79YlFbodts493XqD46ryE35ngsTXY0lahTIyF94S6GqvKKuq6zpj8zuKzk84P9+hRkTzb
v/nJTqOG2dhpTiP57ZR29bIZy7hrWEr+BuAtO09pfmf5wsZdx3UujoSf+h6NdAbrN796KsHOM8d3rV04NZWmfBCVX1xnNaTe35ZfmS9x9nm20dHu6lnsrOksMVsjkJtg
Z3Q8sueFxPJQPaKbCMnOptBsLGfM1lgn45nfSa8dcx953Znsql/1dz98+l8WfO+v7nuJbiSTnX+9Zg/969/f86Tqt1ka9S/7+mKyF7uXTL/zH+58jBKUxp2W8F14zM7T
r3XWfyMw9RvfuXdjW9tDq/7HVwJlBkoH9/c819nWeNvcaak05ZooROgtVatQ7++q65ljfSebFlTfPTphmivEDrhO+9FgJ+F2erC+9zzxVpteVKH/zTdXyHt2+tbpZM/C
FdO/Qt9/XNqcxs5/qllFv9A/leojo9x9ER3JIvQ2QwQ1G4t+nzp7If1Cfyh3U36rsNfsfOPUwJ6WuxZcFR9UK59/V+vugdOa0zmyr3nBNK3dBL+9ZksY82zNLe+Jl36X
z5vk//ec+wolz7Km/YbYghP+NSq0guVZ3Qc1R3Szr1HxmJ1Y1skYme1L/+q33k3a+6UwQA5L0T9RAmkrj4oxBbxnpxaAHTl2YO+OHT27XzpyIhmPPbr7V09t3rpn/8CI
3Rm2LH1pm9CDCbf8uFUvJXnqmF5Lg2Q5euS//fGvS/uRUevuyOnMZqx/XlSv1r34s7ZC2Im9EezsLsQaIkVuyZFSD2LFqDHAaXReLOKX+aXf/dnBSXvXNPacjZ0YlpbW
auaKec5O7I3guB0AnzwgBjjNDSxzsJN10F9c0uS4HeJCLxSgWV2W7KRhaTbhC1/JFfCYndgbobBnAPjMjU9yzRGqNXcx2QbSMH4mYUdsOT6NYWkJLWVZJY/Zib0RCmMn
s5k356vwOHXypiF30+ezarN1MbS8Ic2hwYIHObvjtEm2zGrG2hU564xaGQp4y07sjeBWUyPvauz8n+RFmcCaMWr6dh1n3haVOZCGBQ95RStWAorQml90MCxdLEM4KNdb
dmJvBAcmyXFJzZPHyAelbecEokqWogiZ/W99QHsWuitp6eWWOZCG8TNprUzj0GZ2YlhaWktlVsxjdmJvBDditplmI4je+9wIuV/0JX9UzPdt00dMiQRLukFa7YpBTVt9
Ci1yMHpkLHiwJZ3gxGnLirAVn2D9CynOa3Zib4TSmS+HTasLedJEXmseSMOCB5HKOyjLWFaEYWkH6hXxEu/Zib0RvHE9xTcasFO85o5LZANp2IfPsYDCLmT782EfPmGC
u1WQGHbm26J2ODIQ0Tfqs/N1SwLkw6kA2MkplAzJ2PoHLHiQwRa562AsK8I6IvmNZa5hEdl5+kT/gV1dj29YdUfVnG/Ud/bbAmfJ78knYTMCOyU0SrYqsYE07MOnhMlo
fz4MSythqaKyc3jwUN9zmx5uqr95/jVs87Cpc6vu+NmmFyNgp+StB+yU3EBp1aMeWa0K+7a2NCaNYWnlrC/G7zS7mPrZKdr3ipk3r2nr6sVe8Ko0GrDTsaVoNSrNi37m
8Fk2NVrQt/9tQQUl7ohukG5T9aW3NKmblkIJle7o73voK6xh6AWRpTB93fETTRd6zM6hQ88+YnIxZ8y/pb7pkU2/2dlSO71s2g3N+4btDHCmOaaF3DaudaAA2GlXNOqC
aZmND9fj0i2rtRiXFn0R+P25/Qgd2UT3rvobj91ns/D0HrPzWHf9tERg9p71m3YfGdJgefpo5w/AzsKNJzgHsJNTcOqG6L3e1QPMZdmhwm49CKK0PJdTt6Iko+r5E5mZ
pqTXHXqHKIoVVCzUY3YOvbK9df2KO26qmMritNdcv/TH61ue7m6+HexUrrmAnXlNBmpawlXOLfspaIlj/tLshW2i8z7jRgKP2ZkIyQ4NHO7btvmRdT++bf41yfHOf12x
ob17+77XTQdi21imwn+TSOmKAmBnbhlp9MiH4Vl+T1QeB5RecXC+Qg7DkSOOEG7ePlMQO01DlSMD4d9u2/TY+uVLr59xBeuOr5rz3Q09xzHPNq+1ipsA7MyhP4GBnyK+
TUnEKm4bptJxrh9P8yOPHPjM3VbFs9PkWQ4f3797m75epWY51ndKv/0Q2JntWQI4ebpjlqa43ifAyW8p4FNidhYwyRZ7I4h/fwc7LTWnybT8/RFSkgI00Ci+9cLjdND2
aApuUSylRKFF9Ts1dg7v71h5y813rt8xgJit5C0G7Mw0EM1LxHxau50yjQoXJR5I80jtVhXpixsnkLlLLDo7h/qaqwNlc7Enn8ythNUN7My0Ecfyhg/DjfMCZfOawh9a
dsSXIy2zy5aHxi9zddOXI60zF7VGJrMmzp0gOh7Z80Jk/BJXWbFL45EX9kbGo7GYVsmZLRG+OvJkLn7gk5zdfBWLToTXBsumBBvDE1lM1TpzVl3vuXz5sH+fjLQsmp1L
szwJyFZ79+jqc3xMifOWy5GdKQm9GhblRUf+/hDsLJ0zwrxubWBnmsIc3XEsFh3trp5O0mXrke2x016/l5E6L3pTrnC5F06rjeClhBxToC+OdS3VGnn52vCEFbI09fjZ
WaCp7L2vuP5yY649LVb2um9RMX+wE+zkVQDsTHvCOZzOWHSsq6asvrOrIZilR/YtO0W6nlxj0tpbTkXd05ubyrMECfzKTrielmj3mp1D/a8cPhTO8T2wrfEmxGyVeO0C
O81mIreJw7O4PN67PFDdNXa+t65saffYRXZJdPz41kYaqqAFWtNvrFwY1GO2OkSr1zTeQWHDQFlFXdu+8K61VWzz58q1oTE9jmg4jtof06saGurKsySgiOvxp+L/Wn53
64GxyXGqA9uiZMrsh1o2zqyoa1xJ+WtxRQr5bWnUy5pe1fhQU2VFXe9rodpZcYvPbBk4psdsL2k+dDIOqdehpms0ai7LqGo+dahHFtbsac5LvurEYpo+ZKOxUG2FflNx
UyWUmRJYuKiqXPc7U8UP1j5xMPxcU6UWXQiUVTf1juohdcNr1/4IVK5sqq3IkoDaw5H2+L9W1LW8PDZ5SWs2cWMt2tjSOLv8jqYGajAUrv94PPJsvKzKhlZqRbU7IqbE
rZFxFiu+pL20JcP7euvSWqCpLKOq+bXBqGdmW/WYncaefImH1tz/mv7GeCev8yesu8ksCOw0a0JbgObvcmLaYKcOJ6LOrHiPHH0nVF8RrN06OhmNTR5v1fpcg53Tq9Ye
GI9GJ0e3atir3BCmsUmWng3CpbDTSHA+vLZaI7Q+MhkfEJ0IN5VX1HWdmYxFJyPtVYzclpfHLp3vXRksr+8enYhF9azKWGQyGbNNhAT1qCYriN4AtN5Z747P9y6beXf7
cRqbmxjtqg9Wtkfo1jg+5A4KaM80XMdRF32wUxvTNd+jSZnYhUjL4rgymowJ8SfPdGvYq14XPk/vELqSLOSbys5EgvHwhrgtkgm0RmJqD/F2YoRhdeyxhkH26V0WN+sl
Paspgdre8ZQB6US55iYXS9zUZWpLi+rajiTa2OLWyAUOcWKYcCucnYN729esaWjI+13bvht7I8iOT7DT/PzwBGxjGsBYAFB3Phh14v4N80HZ/BSDnYlJQykdn+68sqk6
qX6n4R4lA79GAq2UROxRmyK0J0yeq/Xl51I8La3O2diZ5GXM6I6jWr+cHM3VLs85m8nUVdPEVwHs5ArY6m857C4MFy0Wy6JMSvA25X1CNy67/VR2Jl44dBOkyUulzEoI
qM3PCoXH6PpUdrKgRSKMEX8z0aehZWNn0kBs0F1D8mV63UmOHSRe7HjgGYthxlBaW/XY7yxsBWfuVSsCnjoUYVYA7DSrwdPh6J4Zw6HOSL3bShvgNP439XfqT+clpnRm
Y2dy3ooFO5kLSLHfludCvYfHmCOYws7E5WnDeBadu2neigH1JN3ZROJ4NFj/g5edNH9HwCNGU13yG4sNdrI5tMYbTzZlUn7XraMDTPtkY6eRwELeeJghWNvS06u/4uif
VHayVqS/gRlZmf7XNFcoGS1IBgbiEYLP2ERis7FyzgROka1Yq3IFtBBnRYhiZ+TIS7uf3/KrZ3YfOaUT8eT+bZse/9Wzu5xuZou9EZzZu5CrwE5DPb7BzsS8zWRvpTmC
otipd3yTY+HeXd00KsZCsoWzk3kztb3nEwHbmMljy4+ojBQCvBmeCIGOmRSoaI6gIHYyUSbGwntCXTTqzCLtLrBTdzfphWAsEWlPvsA5sBRm24r3Owf6Hv/Jv81hR15X
N+8b0tnZ3/n9ufov0762ZO2WMPvR3rcQDOBaBwqAnYZo3KtTEmOcWnQ2MdGGJ2arRQsL8jtTVgcaRVuyM1tk0mK8MxFkLm/ofro+MfCZGrS0E7Ol7AR4MxzsTL0F9n6g
Bcl5YrYF+50pi26Noi3ZaStmS+qyQPTmzsTsJ8MT1dlpL2aLIU/B7Bzs23jbTNrtfe4ty9c9+mRnz/6B0zojh1/t+83m9oeb7lp0Df3rt9buGjwDdjrgmchLwE577NQo
kpxbmxwg1OZrZJsrZGySUDA7NUeqYlnvOzS/RJ95pP9tzU7+uULMQaL70mbkGqOtpgks9uYKUWYCJnBy+FhEkYXJubXJaVATyVlU6XOFjIB54ezUXqqC9b001yimzzxi
f1vFbO3MFdJuO77bQ8CY452cp3ZZbxW8c4UoL3oFEdnbyF+WxzHbY1uXX3vlzCUbQ3FkZnqWQwc7vj+r7LrlW46AnZI3F7DTMBDHEJoxbzPZdSfHn5JrEqqbWhqqMucK
Fex3xszrRmjhxBZtFqx1zFbrY8cH2+5mI2HB2oY12hoVy3m27F7YAKf5tSC5HiZY234wMWLHAa2YgEhg/mpk+srJYV1DGWP1Dluj4h47NfmNNSpUyrNs4ydLdqaYlS1c
yTpXyPSiY8xUMpfFVi7lVyeZQvIOSnD1vGXn8L4Hbyj78u0d4Vxc1NaxTLuhed8wYrZyH6UCdtphp50+ycdppWCnj/W3deuC4SR5cd6yc2R/6+Kp197afnAkOxdHDj1+
a+BLi1tezpHGEr2SK1t61QM7wU5bXS1PYrCTRyVJ0pRen1bIHXnLzlOnDnXcPjcQ/Pf7t4UHLfB5ejD8m/uXfDUQvLsjPIKYbSGGFHAt2Al2ut6Jg52uS+pdhgI6GYWK
8Jidp984Ge5cMb88UHbFNfNuqV91X3PL4+3t9G1pblxdf/N8migUmHrjis7wSZsBW6xREd/IwE6w0/V+Gex0XVLvMhTf58hcoufs1LzJgZe6Nv7ktvnXpG/IN2Phbase
7nrR9o5CzEOVWdaSrBvYCXa63i+Dna5L6l2GJdmtOb4pIeyM+5S0L/zBvp7nt++gb6jvwKv9EbZexeHX8T3jQmcKgJ2GbnzbvNntxPTVDqYV+rTRTIj3AMdkWXmOo7J3
DJndW7CdXll2ahvpmYxF+zf1ch+MmlApjy28PQPOtqliMWf9RqleJZKdDhmZDa6lahJp7wvsNEzDtTeC7c6JsdNY4jkx1kvnqNhYgWe7QAkuEMBOjr0RHAihs9PYHm9y
NESbN3Fvgu+gvKJfImYDRWl7v8yKFYedQwP9h145dsKpx4mYbVFaGNhpyM63J5/d7i6NnXS5fnaHaXGe3RzlTy/gKBWuA8hsK5XKTrpcOxLHtI2U7QxlvwB7I6T1ukVh
51Bfc3Vg2g86jyFmK/vZKebmAnaa1aDjJ93u7TLZaT63xHQeZ/KMTIsfkzHblB0PElsWmOOEzFuKb4nw1KCxJD95jCgt1e+N7yPv9t2y/ATsycexkYWDe8tgZ8q5JeYd
FeICWhycabJFxhGe5lPMqHosCKHvuFvOjntjO11YneHq4G44LhFz6E1RvAJnhYKdKtHLmY3dugrsNCvpgTdjwU79XA5tCxvLMzLZZnjaZnvs3E09ZphgJ9v4W98C3uy/
Jvtrdmykjkx2CKXu4KacFjl+YJ3HvpRbjTNHPt4E2DPZaZjvM9rJb3ZS2HlVLccn2WZ42mZ77NxNPRSfbgvjSFfmvxrjncyUphNSk6exWp3hygFCB0kERNcFNAYXiwA7
wU5eBcBO84PHd/a1rT7Kip3x7d+0ozAyzsi8oI2PZpxEnWCnnlvisEZta3h2EpnlAZ/xHVy1s8NMp1dqgcjUQ69s3U7+xO9+9KmLfVmOrPJXxXaKTHay147loXfPdFcv
1A9tpU9ia8Zz9A6U2MXQ2PAvyU7LIzwNdpr/1XSogO53WpzhavteuC4QECEQ0xjcKgXs5CWHW4qrmw/YabadB0OeOfzOiNUZmeOWYEvGbJk3SduW7uplxylrn0R/nXYU
mrFHa+rv3rLz5eHzYh4HD4IE2f3O0Zf1vfJN35ktA8d0rGpncJo+SXZaHuGZYGfaUWjGC03q7+kG5QIibyIaoRBjKYVKKQo738BcIYWaiFFVsDPNam5P4Mwx3nlOP0wq
HD8WOd7jWYMtdY1KdHLscKj36abK6cFaPSQoEzvruk6IeRDotBZeSvCmyz7eeYHOmdEOak2lZG52srRpR3hKxE4Mdsoyz9bxmk7zhWKeOpQCdmZrA273yDnm2VqekZkS
s9WPBksEXbWzJy+NR17Ym1geqh/hov0rX8zW8JA89DsFz9ukJRa8WORKl32erRGSzRazNQ7ONPxO6yM8eWK2xnEuiYhxmmvLdS/5Ewl7y1Gov/XY79TOSJkSWPBg3whb
3KnPsC2bW9/Zn6Bg5i+8y0AVUrk0qgq/M9OOrvbIudZ3Wp6RqROxoq7rzGQseXBmwu/UcVu+MnSeDrTS/5X9zTVXSAQ7BY+fuT3bNsf6TtN5qFrYnM0V0g/p1Fx/08GZ
SXZaHuHJM1dIBDsFv+Wo0luCnRjv5FUA7Mx8ql3dYCj3vkKWZ2TyrlEJVDZuZT4o1xoVz9lZlO7Y1RednPsKJVcH0X5DL7NFPtxrVIwjPM37CmVboyKCnTS0rwrPRNYT
7OQlh0iryFkW2GlpF7dHPfMH0FRPQRNP5j7yuvhG7s1iFdWtkaf+NJ9cvKWUKBHsBDt5FQA7LR9pwoAH+ySUco8sOFprthrN7C1lZd2+N0wRykFxIez81n3bDh0+FKbv
gW2NNwXKvnpX+179f41fzCOgGO/khZngtzOwM5vgNJMC+OTst2mCleB2m1acB+tVOG9dsWQAZ+6GKoSd5qVO1n+DnZLy0tx6wM4czxLwmZcM9HpRRI/TsB3FCRBmz2ss
gDPvG57H7Bzc275mTUND3u/a9t22T/HMe29I4K4CYGduPQmfrs5Gydu/qZSAcCXVlBMEb7O1HnrFKXpswN2Oy6PcPGZnYSel5F4G6pEiyDabAmBn3rZBPg065bROmd4n
5OyLaY403nXSjEXuZlGmceV9siRMIAk7Tw8Nn7G7YYKEapZ2lcBOTvuSg0V9kEpeoTd1JV9TTmqa7Ug1BEFJAXrnkyowwPmsFTGZIHYODYR373h++469L/UPpTNy+Eio
7d41XcZuCZgrJOnYJ9hp60Gl93fqlwmivuqa6WZpMg4tbFCrI6Z4O8HDb+OgdL901zIMQtt6siRJLICdA32Pr6yacUWi5722avmTfQPxkztPvrpz410LrkrZaQjsBDsl
VaCQh5Z6KGHfpsZG81dYuYXoI8+1RH1hilFBRbGUWm828rQNc028Zuep17c1XD91SmBGVf36lva2jfcu+cZVZeXXr3r29VMn9m9Zd0uQmPqVf2v4Xy8kaMofuZVT0BKu
FfxOVYybcohH2RRVqu3PeuKxUtTuHrPz1MstNV8KTK1as/1oHIqDu5q+VR649rv/c+XimWVTrpp3z8Ydr550NKVIUcXVrTYeclVsB3aqYimqJx4rhYwl0O9ke8F//b5d
J41I7OCuxv+uNxeH7qbhmCqquLrVxkOuiu3ATlUsBXYqZKm0qnrsd6afoxI/SqUQdxPsLFZrAzuLpbzdcsFOu4oVMT0eqyKKX0jRQtiZ3JOPNuE7uL3lgUe2vZjYk4/t
zPdafyQ+ewjjnYWY09Nr8ZB7Kq+LmYOdLorpdVZ4rLxW2KP8hbATe/LdXwoTR/GQe/QQup4t2Om6pN5liMfKO209zXnT3hPk6Vkujf6C5a/8fqGWEnvylQQ1WRPEQ+7p
o+hi5mCni2J6nRUeK68V9ij/vYeHz4z+b8/Y6WgCLSeePVIE2WZTAA+5Km0D7FTFUnglVchSaVV97fipd945B3aWQkzV61YIdnqtsFv5g51uKSkgHzxWAkR2vYhvPfYq
+Xgf/L8PwU6wM78CeMhdfwI9yhDs9EhYL7LFY+WFql7n+fNfHyN2fvrZZ2BnfnJ4bQz588dDLr+NMkemyWqqVNuf9cRjpaLddx48eerMm9nOUHBjrhDGOzFXqIQUUOUh
h9+piqUw3qmQpYyqBn/xCjmd7757HuyE08mlAF6QVXnOwU5VLAV2KmQpo6psZWe2gC0BFX4nF1FUtL2zOoOdznQTfxXYKV5zxyXisXIsXVEuJKdzcOjM797+fY5Db8FO
sDNFATzkRXlWHRQKdjoQrViX4LEqlvLOymVbIuRwOuF3ApzpCuAhd/awib8K7BSvueMS8Vg5lk78hSs6jxA4f/+Hd3I4nWAn2Al2qtoGwE7xvarjEsFOx9IJvvDbj792
YujMmTd/9/nnUbBT1c5RcKNhxeEhL4rsDgoFOx2IVqxL8FgVS3lb5RI4aZhz5PSbFy/+OTc44XcCq/A7VW0DYKetbrG4icHO4urPU/qdm/r5wQl2qtpv8jQFZ2nwkDvT
TfxVYKd4zR2XiMfKsXRiLmQrUk6/8RaPx8lcUsyzBT4xz1bJNgB2iulVXSkF7HRFRi8yIXeTNnwncL599g95xzjNgVywU8l+04s2hPFO71T1Imew0wtVPcoT7PRI2EKy
pe1qDxwZ0U70OvPWhQt/yjvAmZYA7AQ74Xcq2QbAzkL6TcHXgp2CBc9WHB2NQsjc8mKEhjb1IO0oHZNiy900CCo7OykMja9IBcwPuchyUZZdBdLYafdypBepAB4rkWpn
lkV7HdAp1iw2S1+aSft//u+7n3zyiV1fU6WYLecR2UjmlgLmh9ytPJGPFwqksdOLIpCnWwrgsXJLScf5nH5zjE6xJi8z925B/DS19jv5r0fKElPA/JCX2K2V2O2ksbPE
7q7EbgePVYkZNOs829K7T9wRpwJ4yDmFKnoysLPoJuCvAB4rfq1USQm/UxVLCaonHnJBQhdcDNhZsITiMsBjJU5rUSWBnaKUVqQcPOSKGCoGdqpiKaonHiuFjMVZVbCT
Uyi/JMNDroqlwU5VLAV2KmQp/qqCnfxa+SIl2KmKmcFOVSwFdipkKf6qgp38WvkiJdipipnBTlUsBXYqZCn+qoKd/Fr5IiXYqYqZwU5VLAV2KmQp/qqCnfxa+SJlWo+M
/4UCUMBdBXzRj/jgJsFOHxjZzi26200gNygABRAhsNMDKZMW7FTGVGIqip4OCkABTxUQ8yCjFK8VADu9Vlix/D3tNZA5FIACivUIqG4WBcBONA0ooKQCiAQqaTZUulQU
ADtLxZK4D58pAHb6zOC4XbkUADvlsgdqAwU4FQA7OYVCMijghQJgpxeqIk8o4LkCYKfnEqMAKJBdAbATrQMKKKkA2Kmk2VDpUlEA7CwVS+I+fKYA2Okzg+N25VIA7JTL
HqgNFOBUAOzkFArJoIAXCoCdXqiKPKGAJwrs37//yJEjLGtLdlIC+nhSNjKFAlDApADYieYABZRR4OOPPyZkPrxxI/vD/B0eHm78+c/pF/onZe4HFYUCyioAdiprOlTc
lwoQOHNszUP/6ktVcNNQQLQCYKdoxVEeFChEAYrZ5mCnEdEtpAhcCwWgQF4FwM68EiEBFJBIgf/8z/+8/pvftMQn/U7/KlFdURUoULoKgJ2la1vcWYkq8FTHU5bspN9L
9I5xW1BAOgXATulMggpBgdwK0LQgS3bS75AOCkABMQqAnWJ0RilQwE0Fbl2yJA2f9IubBSAvKAAFcioAdqKBQAH1FPj11q1p7KRf1LsN1BgKKKsA2Kms6VBxHyuQub7z
3Xff9bEeuHUoIFoBsFO04igPCriiwA+WLTNcT/rblTyRCRSAApwKgJ2cQiEZFJBLAdp7z2An9uGTyzaojQ8UADt9YGTcYikqQEs5DXZiH75StDDuSWoFwE6pzYPKQYEc
CrD9+bAPHxoJFBCvANgpXnOUCAXcUYDtz4d9+NxRE7lAATsKgJ121EJaKCCZArSsE/vwSWYTVMcXCoCdvjAzbpJLgUsfxD57K/bpSOyPL6jyHTvxtCpVjdeT5CWRSWp8
oIDKCoCdKlsPdS9cgf/6i9aVEyzf34yvaAUuHIpdPFu4DZEDFBCvANgpXnOUKIcCn38am+gXTQsQOlOBD57RfH18oIBSCoCdSpkLlXVFAfI1QU3ZKP7h9tjlC66YF5lA
AQEKgJ0CREYRMilAI23k6MhGDtSHKYAQrkzPCuqSQwGwE83DTwpQ1wxKSa4A8OmnJ1LdewU71bUdam5TAYBTcmoa1QM+bTZtJBevANgpXnOUWAwFAE5VwMnqibHPYjwl
KJNfAbCTXyukVFYBmlKLMU612PlRSNnWhor7QgGw0xdm9vtNYvmmWuBktaV1t/hAAVkVADtltQzq5ZYCNLFWRXKgzhQqwAcKyKoA2CmrZVAvtxSgzWvAIUUVwKQht54C
5OO2AmCn24oiP6kUoJFORbGBapMCGPWU6mlCZUwKgJ1oDiWtAKbXqs5gevvBBwrIpwDYKZ9NUCMXFUDAVnV2YsaQi48DsnJPAbDTPS2Rk4QK0C6pqsPD5/Wntx98oIB8
CoCd8tkENXJRAZ+DpwRun95+8IEC8ikAdspnE9TILQVob5oC4fHehu7KKwOVtWPvsdM9O8bargtcXRN+e1OhOWu5bZo8uqp16YxA2ZTAgprQ0fZ4nm//tOnqYFNPa0FF
JDPZNNlfV3f1lEDlnYM7a4KFVN6VijmwiFvtAflAAfcUADvd0xI5yaZA4Ss7GTvLDJK5yc7o8I+WEdIInOy74NvhUx0aL11BVDKT1vDKoJa/Q3ZqlwdX/nTCrYo5YCfZ
ER8oIJkCYKdkBkF1XFTANXYSeJjr6SI79azK5qzreSRKDqjmGl5Z07Yh6j6iTPBzwK33C7yc+euFfcFOFx8KZOWSAmCnS0IiGwkVcIed02rWfWdNPIiays6zzQcfuD6Y
jLiaMZPt7wRFdI827s8Z0WBGaLPf+d6jg82siMU9bVXxiOvZDaGVc1IivZm/xDN5IO50pvudRrj4yqqVPxo7Gw9BR0/9rF2LIV9Ztbquezm5m/f0MJ+1bIpW1dSKRZ6o
rtL+aUbdA6tYDtGjtTVl13X2rFi3gJx1ymT1eDzWDXZK+HigSgUpAHYWJB8ulloBt9jZtnaUfEQNbGZ2tkUeqDBFXJdGzj410VMTTPJvSnxkVMPkrPTxS41DCUdTH/vU
ri27rvtoh4mdqUUQqLTRyid0h9WI9FK5mb9sSmSShZ1nG1s1vLFMEtVI+ZHxMhs7mdOcDDizlwCdncGqBdMS/1TwqC1zWOF3Sv2Y+bRyYKdPDe+L23aNnRuicZfr4eRc
Ie2XGcu6HzJHWTV46JNx6I+bNfDcmGChDkVT6JJhxnpCkOHe6XyNe29n7+8mj9Bgp05ofcSUMtFrlfJLqwnAhges41nLQWd8WUXr/rbY++2jbQtNP5pjyLqvaY7ZWlYs
mYN21zUJd5ON5poc6wJcT7DTF4+rYjcJdipmMFTXhgIuspONdFbeFmqNz7PVOWGa6cO8N40uhMknJnoW36x5qzcSHQ2gpgz7cfidqXw1ubzvPRrpqO3uvNeItcYyf0md
K6QzzGCn7qcmJtyyQGv30baUKcTJkLLFXKE08Bv/m/J7elAa7LTRcpFUfgXATvlthBo6VcBNdrJhyNl1S2cz6lizU/PSKpp6KFJK/32M3LvZK1ef0/6rz1M1fy3HOxnP
EtjLws62sZ4Ve/c/Gn2/fWznbU2rabQy85dkJrGk45iDnQnn1VjBAnY6bXS4zicKgJ0+MbQvb9NddjLXMz7oyODEYrabJvcvrWJDlVqa+TWtyzor59P/avDTXNX58Qm0
Kfg0z7PdHD21mubXpC8FYTHbBxon6cL3Hgr9RzJmG1xaN0rTc0yR5NRfeGK2LDzbcb67MiOQy6LBzmK2iUA0/E5fPnP+uWmw0z+29t+d/tdfCl0doQFgmkG++IrMuHOW
MpHHGNjTRjoXzL7RNGO2asH1aYOdrFbp6zuvrgwNp63vNBdx5Y0LZrF5tqkXaqzK/CXneOemWOpcoTieU37UpvxkHe80XiMSUWvzXKH4IC7Y6b8Hzld3DHb6ytz+u9kC
VxamsjP2vg4zI7CZWKMS9/lYWZovaMyR0fclyLqVD8e+QonFJ8GltQPd1YldgTrGe76trw+Z0/REo74OJOOXXOOdtJ7Eco0K/fijJm3+7Yy6ttWh+JYIWfZGoBFW6zUq
Hvid9A6EDxSQTAGwUzKDoDruKvDHFwp1PQukLy4vXAF3mwRygwJuKAB2uqEi8pBWgU9HwE61FaC3H3yggHwKgJ3y2QQ1clGBwqcLFe42IYdCFKC3H3yggHwKgJ3y2QQ1
cleBD55R2/EqBDwlcC0dhoMPFJBPAbBTPpugRu4q8Mkg2KmqAji8091nAbm5pwDY6Z6WyElOBT7/VFVylIDXWOAtfPaWnG0KtYICYCfagA8UmOgHPtVTgJxOrE7xwdOp
6C2CnYoaDtW2owC5nhj1LNAFFH/5n8/ZsTHSQgGhCoCdQuVGYUVTgKJ/4nt/lOhYAQoV4AMFJFYA7JTYOKiauwpcOAR8qqHARyFEa91t+8jNdQXATtclRYayKkCDZ9Qp
O/aEcKEYBQBOWR8g1MusANiJ9uAnBYBPMfxzXArFBjA/yE9PpLr3CnaqazvU3JEC1DVj2q1jtnl3IU3mwooURy0aFxVFAbCzKLKj0GIrQHv10RII70iAnG0pQG8zcDeL
/UygfFsKgJ225ELi0lLg4lmMgBbzBYJeX8jXBDVL66nyyd2AnT4xNG4zuwK0+pN6cHJ9MJPIlrPoLDGJTFKT4CQ7PlBAWQXATmVNh4p7pwB16xTUxdddBbyzF3KGAsIV
ADuFS44CoQAUgAJQQHEFwE7FDYjqQwEoAAWggHAFwE7hkqNAKAAFoAAUUFwBsFNxA6L6UAAKQAEoIFwBsFO45CgQCkABKAAFFFcA7FTcgKg+FIACUAAKCFcA7BQuOQqE
AlAACkABxRUAOxU3IKoPBaAAFIACwhX4/+18cnfeVChwAAAAAElFTkSuQmCC
              </image>
            </content>
            <controls>
              <block>
                <ID>0330</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reclassifying media</title>
                <content>
                  <list>
                    <head>Agencies wishing to reclassify media to a lower classification must ensure that:</head>
                    <item>
                      the reclassification of all information on the media has been approved by the originator, or the media has been appropriately sanitised or destroyed.
                    </item>
                    <item>
                      a formal administrative decision is made to reclassify the media.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0331</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reclassifying media</title>
                <content>
                  <list>
                    <head>Agencies must reclassify media if either:</head>
                    <item>
                      information copied onto the media is of a higher classification than the sensitivity or classification of the information already on the media
                    </item>
                    <item>
                      information contained on the media is subjected to a classification upgrade.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Labelling media</title>
            <content>
              <para>
                Labelling helps personnel to identify the sensitivity or classification of media and ensure that they afford the media the correct security measures.
              </para>
            </content>
          <controls>
            <block>
              <ID>0332</ID>
              <revision>3</revision>
              <updated>Sep-11</updated>
              <classification>G</classification>
              <classification>P</classification>
              <classification>C</classification>
              <classification>S</classification>
              <classification>TS</classification>
              <compliance>should</compliance>
              <authority>AA</authority>
              <title>Labelling media</title>
              <content>
                <para>
                  Agencies should label media with a marking that indicates the sensitivity or classification applicable to the information it stores; unless it is internally mounted fixed media and the ICT equipment containing the media is labelled.
                </para>
              </content>
            </block>

            <block>
              <ID>0333</ID>
              <revision>3</revision>
              <updated>Sep-11</updated>
              <classification>G</classification>
              <classification>P</classification>
              <classification>C</classification>
              <classification>S</classification>
              <classification>TS</classification>
              <compliance>must</compliance>
              <authority>AH</authority>
              <title>Labelling media</title>
              <content>
                <para>
                  Agencies must ensure that the sensitivity or classification of all media is easily visually identifiable.
                </para>
              </content>
            </block>
            <block>
              <ID>0334</ID>
              <revision>3</revision>
              <updated>Sep-11</updated>
              <classification>G</classification>
              <classification>P</classification>
              <classification>C</classification>
              <classification>S</classification>
              <classification>TS</classification>
              <compliance>must</compliance>
              <authority>AH</authority>
              <title>Labelling media</title>
              <content>
                <para>
                  When using non-textual protective markings for media due to operational security reasons, agencies must document the labelling scheme and train personnel appropriately.
                </para>
              </content>
            </block>
          </controls>
					</block>
          <block>
            <title>Labelling sanitised media</title>
            <content>
              <para>
                It is not possible to apply the sanitisation and reclassification process to non-volatile media in a cascaded manner. Therefore, SECRET media that has been sanitised and reclassified to a CONFIDENTIAL level must be labelled as to avoid inadvertently being reclassified to a lower classification a second time.
              </para>
              <para>
                The sanitisation of TOP SECRET non-volatile media does not allow for the reduction of its classification. The classification of TOP SECRET non-volatile media can only be reduced via destruction.
              </para>
            </content>
            <controls>
              <block>
                <ID>0335</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>Applicability: S;
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Labelling sanitised media</title>
                <content>
                  <para>
                    Agencies must label non-volatile media that has been sanitised and reclassified with a notice similar to: ‘Warning: media has been sanitised and reclassified from SECRET to CONFIDENTIAL. Further lowering of classification only via destruction.’ 
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                For further information on media security see the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Media Usage</title>

        <objective>
          <block>
            <content>
              <para>
                Media is used with systems in a controlled and accountable manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the requirements needed to use media with sensitive or classified information. This section includes information on connecting media to systems, using media to transfer information and storage of media. The controls are equally applicable to all devices containing media, such as external hard drives, cameras, mobile phones, digital audio players and portable media players.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content><para>
                Further information on using media to transfer data between systems can be found in the Data Transfer section of the Network Security chapter. More information on reducing storage and physical transfer requirements can be found in the Cryptographic Fundamentals section of the Cryptography chapter.
              </para></content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using media with systems</title>
            <content>
              <para>
                To prevent data spills agencies need to prevent sensitive or classified media from being connected to, or used with, systems not accredited to process, store or communicate the information on the media.
              </para>
            </content>
            <controls>
              <block>
                <ID>0337</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Using media with systems</title>
                <content>
                  <para>
                    Agencies must not use media with a system that is not accredited to process, store or communicate the information on the media.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Storage of media</title>
            <content>
              <para>
                The requirements for the storage and physical transfer of sensitive or classified information media are specified in the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
            <controls>
              <block>
                <ID>0338</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Storage of media</title>
                <content>
                  <para>
                    Agencies must ensure that sensitive or classified media meets the minimum physical security storage requirements in the Australian Government Physical Security Management Protocol.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Connecting media to systems</title>
            <content>
              <para>
                Some operating systems provide the functionality to automatically execute certain types of programs that reside on optical media and flash drives. While this functionality was designed with a legitimate purpose in mind—such as automatically loading a graphical user interface for the system user to browse the contents of the media, or to install software residing on the media—it can also be used for malicious purposes.
              </para>
              <para>
                An attacker can create a file on media that the operating system believes it should automatically execute. When the operating system executes the file, it can have the same effect as when a system user explicitly executes malicious code. However, in this case the system user is taken out of the equation as the operating system executes the file without explicitly asking the system user for permission.
              </para>
              <para>
                Some operating systems will cache information on media to improve performance. Using media with a system could therefore cause data to be read from the media without user intervention.
              </para>
              <para>
                Device access control and data loss prevention software allows greater control over media that can be connected to a system and the manner in which it can be used. This assists in preventing unauthorised media being connected to a system and, if desired, preventing information from being written to it.
              </para>
              <para>
                Media can also be prevented from connecting to a system by physical means including, but not limited to, using wafer seals or applying epoxy to the connection ports. If physical means are used to prevent media connecting to a system, then procedures covering detection and reporting processes are needed in order to respond to attempts to bypass these controls.
              </para>
            </content>
            <controls>
              <block>
                <ID>0341</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Connecting media to systems</title>
                <content>
                  <para>
                    Agencies must disable any automatic execution features in operating systems for connectable media.
                  </para>
                </content>
              </block>
              <block>
                <ID>0342</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Connecting media to systems</title>
                <content>
                  <list>
                    <head>Agencies must prevent unauthorised media from connecting to a system via the use of either:</head>
                    <item>
                      device access control or data loss prevention software
                    </item>
                    <item>
                      physical means.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0343</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Connecting media to systems</title>
                <content>
                  <para>
                    Agencies should prevent media being written to, via the use of device access control or data loss prevention software, if there is no business need.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>External interface connections that allow Direct Memory Access</title>
            <content>
              <para>
                Known vulnerabilities have been demonstrated where attackers can connect media to a locked workstation via a communications port that allows Direct Memory Access (DMA) and subsequently gain access to encryption keys in memory. Furthermore, with DMA an attacker can read or write any content to memory that they desire. The best defence against this vulnerability is to disable access to communication ports using either software controls or physically preventing access to the communication ports so that media cannot be connected. Communication ports that can connect media that utilise DMA are IEEE 1394 (FireWire), ExpressCard and Thunderbolt.
              </para>
            </content>
            <controls>
              <block>
                <ID>0344</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>External interface connections that allow Direct Memory Access</title>
                <content>
                  <para>
                    Agencies should disable external interfaces on a system that allows DMA, if there is no business need.
                  </para>
                </content>
              </block>
              <block>
                <ID>0345</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>External interface connections that allow Direct Memory Access</title>
                <content>
                  <para>
                    Agencies must disable external interfaces on a system that allows DMA, if there is no business need.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Transferring media</title>
            <content>
              <para>
                As media is often transferred through areas not certified and accredited to process the sensitive or classified information on the media, protection mechanisms need to be put in place to protect the information. When applying encryption to media it may reduce the requirements for storage and physical transfer in the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol. Any reduction in requirements is based on the original sensitivity or classification of information residing on the media and the level of assurance in the cryptographic product being used to encrypt the media.
              </para>
              <para>
                Further information on reducing storage and physical transfer requirements can be found in the Cryptographic Fundamentals section of the Cryptography chapter.
              </para>
            </content>
            <controls>
              <block>
                <ID>0831</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Transferring media</title>
                <content>
                  <para>
                    Agencies must ensure that media containing sensitive or classified information meets the minimum physical transfer requirements as specified in the Australian Government Information Security Management Protocol.
                  </para>
                </content>
              </block>
              <block>
                <ID>0832</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Transferring media</title>
                <content>
                  <para>
                    Agencies must encrypt media with at least a DSD Approved Cryptographic Algorithm (DACA) if it is to be transferred through an area not certified and accredited to process the sensitivity or classification of the information on the media.
                  </para>
                </content>
              </block>
              <block>
                <ID>1059</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Transferring media</title>
                <content>
                  <para>
                    Agencies should encrypt media with at least a DACA even if being transferred through an area certified and accredited to process the sensitivity or classification of the information on the media.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Using media for data transfers</title>
						<content>
							<para>
								Agencies transferring data between systems of different security domains, sensitivities or classifications are strongly encouraged to use write-once optical media. This will ensure that information from the one of the systems cannot be accidently transferred onto the media then onto another system when the media is reused for the next transfer.
							</para>
						</content>
            <controls>
              <block>
                <ID>0347</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Using media for data transfers</title>
                <content>
                  <para>
                    Agencies transferring data manually between two systems of different security domains, sensitivities or classifications should not use rewriteable media.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Media in secured areas</title>
            <content>
              <para>
                Ensuring certain types of media—including Universal Serial Bus, FireWire, Thunderbolt and eSATA capable media—must be explicitly approved in a TOP SECRET environment provides an additional level of system user awareness. This practice should be used in addition to device access control software on workstations in case system users are unaware of, or choose to ignore, security requirements for media.
              </para>
            </content>
            <controls>
              <block>
                <ID>1169</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>Applicability: S; <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Media in secured areas</title>
                <content>
                  <para>
                    Agencies should not permit any media that uses external interface connections in a SECRET area without prior written approval from the accreditation authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0346</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Media in secured areas</title>
                <content>
                  <para>
                    Agencies must not permit any media that uses external interface connections in a TOP SECRET area without prior written approval from the accreditation authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                For further information on media security see the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Media Sanitisation</title>
        <objective>
          <block>
            <content>
              <para>
                Media that is no longer required is sanitised.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes sanitising media.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<title></title>
						<content>
							<para>
								Additional information relating to sanitising ICT equipment can be found in the Product Sanitisation and Disposal section of the Product Security chapter.
							</para>
						</content>
					</block>
					<block>
						<title>Sanitising media</title>
						<content>
							<para>Sanitisation is the process of removing information from media. It does not automatically change the sensitivity or classification of the media, nor does it involve the destruction of media.</para>
						</content>
					</block>  
					<block>
						<title>Product selection</title>
						<content>
							<para>Agencies are permitted to use non-evaluated products to sanitise media. However, the product still needs to conform to the requirements for sanitising media as outlined in this section.</para>
						</content>
					</block>  
					<block>
						<title>Hybrid hard drives</title>
						<content>
							<para>When sanitising hybrid hard drives, the sanitisation and post sanitisation treatment requirements for flash memory devices apply.</para>
						</content>
					</block>  
					<block>
						<title>Solid state drives</title>
						<content>
							<para>When sanitising solid state drives, the sanitisation and post sanitisation treatment requirements for flash memory devices apply.</para>
						</content>
					</block>  
					<block>
						<title>Government systems</title>
						<content>
							<para>
								All references to ‘Government’ in the tables relate to media containing unclassified but sensitive information not intended for public release, such as Dissemination Limiting Marker information. ‘Government’ is not a classification under the Australian Government Security Classification System as mandated by the Attorney-General’s Department.
							</para>
						</content>
					</block>
        </context>
        <controlsTitle>
          <block>
            <title>Sanitisation procedures</title>
            <content>
              <para>
                Sanitising media prior to reuse in a different environment ensures that information is not inadvertently accessed by unauthorised personnel or protected by insufficient security measures.
              </para>
              <para>
                Using approved sanitisation methods provides a high level of assurance that no remnant data is left on the media.
              </para>
              <para>
                The procedures used in this manual are designed not only to prevent common attacks that are currently feasible but also to protect from attacks that could emerge in the future.
              </para>
              <para>
                When sanitising media, it is necessary to read back the contents of the media to verify that the overwrite process completed successfully.
              </para>
            </content>
            <controls>
              <block>
                <ID>0348</ID>
                <revision>0</revision>
<updated>Sep-08</updated>
 <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sanitisation procedures</title>
                <content>
                  <para>
                    Agencies must document procedures for the sanitisation of media.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Media that cannot be sanitised</title>
						<content>
							<para>
								Some types of media cannot be sanitised and therefore must be destroyed. It is not possible to use these types of media while maintaining a high level of assurance that no previous data can be recovered.
							</para>
						</content>
            <controls>
              <block>
                <ID>0350</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sanitisation procedures</title>
                <content>
                  <list>
                    <head>Agencies must destroy the following media types prior to disposal, as they cannot be sanitised:</head>
                    <item>
                      microfiche
                    </item>
                    <item>
                      microfilm
                    </item>
                    <item>
                      optical discs
                    </item>
                    <item>
                      printer ribbons and the impact surface facing the platen
                    </item>
                    <item>
                      programmable read-only memory
                    </item>
                    <item>
                      read-only memory
                    </item>
                    <item>
                      faulty media that cannot be successfully sanitised.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Volatile media sanitisation</title>
            <content>
							<para>
								When sanitising volatile media, the specified time to wait following removal of power is based on applying a safety factor to times recommended in research on recovering the contents of volatile media.
							</para>
						</content>
            <controls>
              <block>
                <ID>0351</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Volatile media sanitisation</title>
                <content>
                  <list>
                    <head>Agencies must sanitise volatile media by either:</head>
                    <item>
                      removing power from the media for at least 10 minutes
                    </item>
                    <item>
                      overwriting all locations of the media with an random pattern followed by a read back for verification.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0352</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Volatile media sanitisation</title>
                <content>
                  <para>
                    Agencies must sanitise volatile media by overwriting the media at least once in its entirety with a random pattern, followed by a read back for verification, followed by removing power from the media for at least 10 minutes.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Treatment of volatile media following sanitisation</title>
						<content>
							<para>
								Published literature supports short-term remenance effects (residual information that remains on media after erasure) in volatile media. Data retention times are reported to be in the magnitude of minutes (at normal room temperatures) to hours (in extreme cold). Further, published literature has shown that some volatile media can suffer from long-term remenance effects resulting from physical changes to the media due to continuous storage of static data for an extended period of time. It is for these reasons that under certain circumstances TOP SECRET volatile media must always remain at this classification, even after sanitisation.
							</para>
						</content>
            <controls>
              <block>
                <ID>0353</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Treatment of volatile media following sanitisation</title>
                <content>
                  <para>
                    Following sanitisation, volatile media must be treated no less than as indicated below.
                  </para>
					<table>
						  <header>
							<cell>Pre-sanitisation handling</cell>
							<cell>Post-sanitisation handling</cell>
						  </header>
						  <row>
							<cell>TOP SECRET</cell>
							<cell>Unclassified (under certain circumstances)</cell>
						  </row>
						  <row>
							<cell>SECRET</cell>
							<cell>Unclassified</cell>
						  </row>
						  <row>
							<cell>CONFIDENTIAL</cell>
							<cell>Unclassified</cell>
						  </row>
						  <row>
							<cell>PROTECTED</cell>
							<cell>Unclassified</cell>
						  </row>
						  <row>
							<cell>Government</cell>
							<cell>Unclassified</cell>
						  </row>
					</table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Circumstances preventing reclassification of volatile media</title>
            <content>
							<para>
								Typical circumstances preventing the reclassification of TOP SECRET volatile media include a static cryptographic key being stored in the same memory location during every boot of a device and a static image being displayed on a device and stored in volatile media for a period of months.
							</para>
						</content>
            <controls>
              <block>
                <ID>0835</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Circumstances preventing reclassification of volatile media</title>
                <content>
                  <list>
                    <head>Volatile media must not be reclassified below TOP SECRET if the volatile media either:</head>
                    <item>
                      stored sensitive, static, data for an extended period of time
                    </item>
                    <item>
                      sensitive data was repeatedly stored or written to the same memory location for an extended period of time.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Non-volatile magnetic media sanitisation</title>
            <content>
							<para>
								Both the host protected area and device configuration overlay table of non-volatile magnetic hard disks are normally not visible to the operating system or the computer’s basic input/output system. Hence any sanitisation of the readable sectors on the media will not overwrite these hidden sectors leaving any information contained in these locations untouched. Some sanitisation programs include the ability to reset devices to their default state removing any host protected areas or device configuration overlays. This allows the sanitisation program to see the entire contents of the media during the subsequent sanitisation process.
							</para>
							<para>
								Modern non-volatile magnetic hard disks automatically reallocate space for bad sectors at a hardware level. These bad sectors are maintained in what is known as the growth defects table or ‘g-list’. If information was stored in a sector that is subsequently added to the g-list, sanitising the media will not overwrite these non-addressable bad sectors. While these sectors may be considered bad by the device, quite often this is due to the sectors no longer meeting expected performance norms for the device and not due to an inability to read/write to the sector. The Advanced Technology Attachment (ATA) secure erase command was built into the firmware of post-2001 devices and is able to access sectors that have been added to the g-list. Modern non-volatile magnetic hard disks also contain a primary defects table or ‘p-list’. The p-list contains a list of bad sectors found during post-production processes. No information is ever stored in sectors on the p-list for a device as they are inaccessible before the media is used for the first time.
							</para>
						</content>
            <controls>
              <block>
                <ID>0354</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Non-volatile magnetic media sanitisation</title>
                <content>
                  <list>
                    <head>Agencies must sanitise non-volatile magnetic media by:</head>
                    <item>
                      if pre-2001 or under 15 Gigabytes: overwriting the media at least three times in its entirety with an random pattern followed by a read back for verification
                    </item>
                    <item>
                      if post-2001 or over 15 Gigabytes: overwriting the media at least once in its entirety with an random pattern followed by a read back for verification.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1065</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Non-volatile magnetic media sanitisation</title>
                <content>
                  <para>
                    Agencies should reset the host protected area and device configuration overlay table of non-volatile magnetic hard disks prior to overwriting the media.
                  </para>
                </content>
              </block>
              <block>
                <ID>1066</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Non-volatile magnetic media sanitisation</title>
                <content>
                  <para>
                    Agencies should attempt to overwrite the growth defects table (g-list) on non-volatile magnetic hard disks.
                  </para>
                </content>
              </block>
              <block>
                <ID>1067</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Non-volatile magnetic media sanitisation</title>
                <content>
                  <para>
                    Agencies should use the ATA secure erase command, where available, for sanitising non-volatile magnetic hard disks instead of using block overwriting software.
                  </para>
                </content>
              </block>
              <block>
                <ID>1068</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Non-volatile magnetic media sanitisation</title>
                <content>
                  <para>
                    Agencies must boot from separate media to the media being sanitised to undertake the sanitisation process.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Treatment of non-volatile magnetic media following sanitisation</title>
            <content>
							<para>
								Highly classified non-volatile magnetic media cannot be sanitised below its original classification due to concerns with the sanitisation of the host protected area, device configuration overlay table and growth defects table.
							</para>
						</content>
            <controls>
              <block>
                <ID>0356</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Treatment of non-volatile magnetic media following sanitisation</title>
                <content>
                  <para>
                    Following sanitisation, non-volatile magnetic media must be treated no less than as indicated below.
                  </para>
                    <table>
                          <header>
                            <cell>Pre-sanitisation handling</cell>
                            <cell>Post-sanitisation handling</cell>
                          </header>
                          <row>
                            <cell>TOP SECRET</cell>
                            <cell>TOP SECRET</cell>
                          </row>
                          <row>
                            <cell>SECRET</cell>
                            <cell>CONFIDENTIAL</cell>
                          </row>
                          <row>
                            <cell>CONFIDENTIAL</cell>
                            <cell>Unclassified</cell>
                          </row>
                          <row>
                            <cell>PROTECTED</cell>
                            <cell>Unclassified</cell>
                          </row>
                          <row>
                            <cell>Government</cell>
                            <cell>Unclassified</cell>
                          </row>
                    </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Non-volatile Erasable Programmable Read-only Memory media sanitisation</title>
            <content>
              <para>
                When erasing non-volatile Erasable Programmable Read-only Memory (EPROM), the manufacturer’s specification for ultraviolet erasure time is multiplied by a factor of three to provide an additional level of certainty in the process.
              </para>
            </content>
            <controls>
              <block>
                <ID>0357</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Non-volatile Erasable Programmable Read-only Memory media sanitisation</title>
                <content>
                  <para>
                    Agencies must sanitise non-volatile EPROM media by erasing in accordance with the manufacturer’s specification, increasing the specified ultraviolet erasure time by a factor of three, then overwriting the media at least once in its entirety with a random pattern, followed by a read back for verification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Non-volatile Electrically Erasable Programmable Read-only Memory media sanitisation</title>
            <content>
              <para>
                A single overwrite with a random pattern is considered best practice for sanitising non-volatile Electrically Erasable Programmable Read-only Memory (EEPROM) media.
              </para>
            </content>
            <controls>
              <block>
                <ID>0836</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Non-volatile Electrically Erasable Programmable Read-only Memory media sanitisation</title>
                <content>
                  <para>
                    Agencies must sanitise non-volatile EEPROM media by overwriting the media at least once in its entirety with a random pattern, followed by a read back for verification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Treatment of non-volatile Erasable Programmable Read-only Memory and Electrically Erasable Programmable Read-only Memory media following sanitisation</title>
            <content>
              <para>
                As little research has been conducted on the ability to recover data on non-volatile EPROM or EEPROM media after sanitisation, highly classified media retains its original classification.
              </para>
            </content>
            <controls>
              <block>
                <ID>0358</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Treatment of non-volatile Erasable Programmable Read-only Memory and Electrically Erasable Programmable Read-only Memory media following sanitisation</title>
                <content>
                  <para>
                    Following sanitisation, non-volatile EPROM and EEPROM media must be treated no less than as indicated below.
                  </para>
                  <para>
                    <table>
                          <header>
                            <cell>Pre-sanitisation handling</cell>
                            <cell>Post-sanitisation handling</cell>
                          </header>
                          <row>
                            <cell>TOP SECRET</cell>
                            <cell>TOP SECRET</cell>
                          </row>
                          <row>
                            <cell>SECRET</cell>
                            <cell>CONFIDENTIAL</cell>
                          </row>
                          <row>
                            <cell>CONFIDENTIAL</cell>
                            <cell>Unclassified</cell>
                          </row>
                          <row>
                            <cell>PROTECTED</cell>
                            <cell>Unclassified</cell>
                          </row>
                          <row>
                            <cell>Government</cell>
                            <cell>Unclassified</cell>
                          </row>
                    </table>
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Non-volatile flash memory media sanitisation</title>
            <content>
              <para>
                In flash memory media, a technique called wear levelling ensures that writes are distributed evenly across each memory block in flash memory. This feature necessitates flash memory being overwritten with a random pattern twice, rather than once, as this helps ensure that all memory blocks are overwritten during sanitisation.
              </para>
            </content>
            <controls>
              <block>
                <ID>0359</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Non-volatile flash memory media sanitisation</title>
                <content>
                  <para>
                    Agencies must sanitise non-volatile flash memory media by overwriting the media at least twice in its entirety with a random pattern, followed by a read back for verification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Treatment of non-volatile flash memory media following sanitisation</title>
            <content>
              <para>
                Due to the use of wear levelling in flash memory, it is possible that not all physical memory locations are written to when attempting to overwrite the media. Information can therefore remain on the media. This is why TOP SECRET, SECRET and CONFIDENTIAL flash memory media must always remain at their respective classification, even after sanitisation.
              </para>
            </content>
            <controls>
              <block>
                <ID>0360</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Treatment of non-volatile flash memory media following sanitisation</title>
                <content>
                  <para>
                    Following sanitisation, non-volatile flash memory media must be treated no less than as indicated below.
                  </para>
                    <table>
                          <header>
                            <cell>Pre-sanitisation handling</cell>
                            <cell>Post-sanitisation handling</cell>
                          </header>
                          <row>
                            <cell>TOP SECRET</cell>
                            <cell>TOP SECRET</cell>
                          </row>
                          <row>
                            <cell>SECRET</cell>
                            <cell>SECRET</cell>
                          </row>
                          <row>
                            <cell>CONFIDENTIAL</cell>
                            <cell>CONFIDENTIAL</cell>
                          </row>
                          <row>
                            <cell>PROTECTED</cell>
                            <cell>Unclassified</cell>
                          </row>
                          <row>
                            <cell>Government</cell>
                            <cell>Unclassified</cell>
                          </row>
                    </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sanitising media prior to reuse</title>
            <content>
              <para>
                Sanitising media prior to reuse assists with enforcing the need-to-know principle.
              </para>
            </content>
            <controls>
              <block>
                <ID>0947</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Sanitising media prior to reuse</title>
                <content>
                  <para>
                    Agencies should sanitise all media prior to reuse.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on recoverability of information from volatile media can be found in the paper Data Remenance in Semiconductor Devices at http://www.usenix.org/events/sec01/full_papers/gutmann/gutmann.pdf.
              </para>
              <para>
                The Random Access Memory (RAM) testing tool memtest86+ can be obtained from http://memtest.org/.
              </para>
              <para>
                The graphics card RAM testing tool MemtestG80 can be obtained from https://simtk.org/home/memtest.
              </para>
              <para>
                HDDerase is a freeware tool developed by the Center for Magnetic Recording Research at the University of California San Diego. It is capable of calling the ATA secure erase command for non-volatile magnetic hard disks. It is also capable of resetting host protected area and device configuration overlay table information on the media. The tool is available for download from http://cmrr.ucsd.edu/people/Hughes/SecureErase.shtml.
              </para>
              <para>
                Information on Reliably Erasing Data From Flash-Based Solid State Drives can be found at http://cseweb.ucsd.edu/users/swanson/papers/Fast2011SecErase.pdf.
              </para>
              <para>
                For further information on media security see the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Media Destruction</title>
        <objective>
          <block>
            <content>
              <para>
                Media that cannot be sanitised is destroyed.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the destruction of media.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
		   <title></title>
		   <content>
            <para>Additional information relating to the destruction of ICT equipment can be found in the Product Sanitisation and Disposal section of the Product Security chapter.</para>
		   </content>
		  </block>
		  <block>
		    <title>Government systems</title>
			<content>
            <para>All references to 'Government' in the tables relate to media containing unclassified but sensitive information not intended for public release, such as Dissemination Limiting Marker information. 'Government' is not a classification under the Australian Government Security Classification System as mandated by the Attorney-General's Department.</para>
		   </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Destruction procedures</title>
            <content>
              <para>
                Documenting procedures for media destruction will ensure that agencies carry out media destruction in an appropriate and consistent manner.
              </para>
            </content>
            <controls>
              <block>
                <ID>0363</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Destruction procedures</title>
                <content>
                  <para>
                    Agencies must document procedures for the destruction of media.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Media destruction</title>
            <content>
              <para>
                The destruction methods given are designed to ensure that recovery of information is impossible or impractical.
              </para>
            </content>
            <controls>
              <block>
                <ID>0364</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Destruction procedures</title>
                <content>
                  <list>
                    <head>To destroy media, agencies must either:</head>
                    <item>
                      break up the media
                    </item>
                    <item>
                      heat the media until it has either burnt to ash or melted
                    </item>
                    <item>
                      degauss the media.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0366</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Destruction procedures</title>
                <content>
                  <para>
                    Agencies must use one of the methods shown in the table below.
                  </para>

                    <table>
                        <header>
                            <cell rowspan="2">Item</cell>
                            <cell colspan="6">Destruction methods</cell>
                        </header> 
												<header>
                            <cell>Furnace/Incinerator</cell>
                            <cell>Hammer mill</cell>
                            <cell>Disintegrator</cell>
                            <cell>Grinder/Sander</cell>
                            <cell>Cutting</cell>
                            <cell>Degausser</cell>
                         </header>
                        
                          <row>
                            <cell>Electrostatic memory devices</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>No</cell>
                            <cell>No</cell>
                          </row>
                          <row>
                            <cell>Magneticfloppy disks</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>No</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                          </row>
                          <row>
                            <cell>Magnetic hard disks</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>No</cell>
                            <cell>Yes</cell>
                          </row>
                          <row>
                            <cell>Magnetic tapes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>No</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                          </row>
                          <row>
                            <cell>Optical disks</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>No</cell>
                          </row>
                          <row>
                            <cell>Semi-conductor memory</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>Yes</cell>
                            <cell>No</cell>
                            <cell>No</cell>
                            <cell>No</cell>
                          </row>
                    </table>

                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Media destruction equipment</title>
            <content>
              <para>
                Australian Security Intelligence Organisation (ASIO) T4 Protective Security evaluates security equipment for the purpose of destroying media. Approved security equipment is listed in the Security Equipment Catalogue published by the Security Construction and Equipment Committee (SCEC).
              </para>
              <para>
                The National Security Agency/Central Security Service’s Evaluated Products List – Degausser (EPLD) contains a list of certified degaussers.
              </para>
              <para>
                The Government Communications Headquarters/Communications-Electronics Security Group’s certified data erasure products list contains a list of certified degaussers.
              </para>
            </content>
            <controls>
              <block>
                <ID>0365</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Media destruction equipment</title>
                <content>
                  <para>
                    Agencies must employ security equipment approved by the SCEC, and published in the Security Equipment Catalogue, for the purpose of media destruction.
                  </para>
                </content>
              </block>
              <block>
                <ID>1160</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Media destruction equipment</title>
                <content>
                  <para>
                    Agencies must employ degaussers certified by the National Security Agency/Central Security Service or the Government Communications Headquarters/Communications-Electronics Security Group for the purpose of degaussing media. 
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Storage and handling of media waste particles</title>
            <content>
              <para>
                Following destruction, normal accounting and auditing procedures do not apply for media. It is therefore essential that when media is recorded as being destroyed, destruction is assured.
              </para>
            </content>
            <controls>
              <block>
                <ID>0368</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Storage and handling of media waste particles</title>
                <content>
                  <para>
                    Agencies must, at minimum, store and handle the resulting media waste for all methods, except for furnace/incinerator and degausser, as indicated below.
                  </para>
                    <table>
                          <header>
                            <cell>Initial media handling</cell>
                            <cell colspan="4">Screen aperture size particles can pass through</cell>
                          </header>
                          <header>
                            <cell> </cell>
							<cell>Less than or equal to 3mm</cell>
                            <cell>Less than or equal to 6mm</cell>
                            <cell>Less than or equal to 9mm</cell>
                            <cell>Less than or equal to 12mm</cell>
                          </header>
                          <row>
                            <cell>TOP SECRET</cell>
                            <cell>Unclassified</cell>
                            <cell>PROTECTED</cell>
                            <cell>CONFIDENTIAL</cell>
                            <cell>SECRET</cell>
                          </row>
                          <row>
                            <cell>SECRET</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                            <cell>PROTECTED</cell>
                            <cell>CONFIDENTIAL</cell>
                          </row>
                          <row>
                            <cell>CONFIDENTIAL</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                            <cell>PROTECTED</cell>
                          </row>
                          <row>
                            <cell>PROTECTED</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                          </row>
                          <row>
                            <cell>Government</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                            <cell>Unclassified</cell>
                          </row>
                    </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Degaussers</title>
            <content>
              <para>
                Coercivity varies between media types and between brands and models of the same type of media. Care is needed when determining the desired coercivity since a degausser of insufficient strength will not be effective. The National Security Agency/Central Security Service’s EPLD contains a list of common types of media and their associated coercivity ratings.
              </para>
              <para>
                Since 2006 perpendicular magnetic media have become available. Some degaussers are only capable of sanitising longitudinal magnetic media. Care therefore needs to be taken to ensure that a suitable degausser is used when sanitising perpendicular magnetic media.
              </para>
              <para>
                Agencies will need to comply with any product specific directions provided by product manufacturers and certification authorities to ensure that degaussers are being used in the correct manner to achieve an effective destruction outcome.
              </para>
            </content>
            <controls>
              <block>
                <ID>0361</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Degaussers</title>
                <content>
                  <para>
                    Agencies must use a degausser of sufficient field strength for the coercivity of the media.
                  </para>
                </content>
              </block>
              <block>
                <ID>0838</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Degaussers</title>
                <content>
                  <para>
                    Agencies must use a degausser capable of the magnetic orientation (longitudinal or perpendicular) of the media.
                  </para>
                </content>
              </block>
              <block>
                <ID>0362</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Degaussers</title>
                <content>
                  <para>
                    Agencies must comply with any product specific directions provided by product manufacturers and certification authorities.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Supervision of destruction</title>
            <content>
              <para>
                To ensure that media is appropriately destroyed it needs to be supervised to the point of destruction and have its destruction overseen by at least one person cleared to the sensitivity or classification of the media being destroyed.
              </para>
            </content>
            <controls>
              <block>
                <ID>0370</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Supervision of destruction</title>
                <content>
                  <para>
                    Agencies must perform the destruction of media under the supervision of at least one person cleared to the sensitivity or classification of the media being destroyed.
                  </para>
                </content>
              </block>
              <block>
                <ID>0371</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Supervision of destruction</title>
                <content>
                  <list>
                    <head>Personnel supervising the destruction of media must:</head>
                    <item>
                      supervise the handling of the media to the point of destruction
                    </item>
                    <item>
                      ensure that the destruction is completed successfully.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Supervision of accountable materiel destruction</title>
            <content>
              <para>
                Since accountable materiel is more sensitive than standard classified media, it needs to be supervised by at least two personnel and have a destruction certificate signed by the personnel supervising the process.
              </para>
            </content>
            <controls>
              <block>
                <ID>0372</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Supervision of accountable materiel destruction</title>
                <content>
                  <para>
                    Agencies must perform the destruction of accountable materiel under the supervision of at least two personnel cleared to the sensitivity or classification of the media being destroyed.
                  </para>
                </content>
              </block>
              <block>
                <ID>0373</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Supervision of accountable materiel destruction</title>
                <content>
                  <list>
                    <head>Personnel supervising the destruction of accountable media must:</head>
                    <item>
                      supervise the handling of the material to the point of destruction
                    </item>
                    <item>
                      ensure that the destruction is completed successfully
                    </item>
                    <item>
                      sign a destruction certificate.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Outsourcing media destruction</title>
            <content>
              <para>
                ASIO T4 Protective Security maintains a list of commercial providers that are accredited to destroy media in an approved manner.
              </para>
            </content>
            <controls>
              <block>
                <ID>0839</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Outsourcing media destruction</title>
                <content>
                  <para>
                    Agencies should not outsource the destruction of TOP SECRET media or accountable materiel.
                  </para>
                </content>
              </block>
              <block>
                <ID>0840</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Outsourcing media destruction</title>
                <content>
                  <para>
                    Agencies outsourcing the destruction of media to a commercial facility must use a facility that has been approved by ASIO T4 Protective Security.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Transporting media for off-site destruction</title>
            <content>
              <para>
                Requirements for the physical transfer of media between agencies and commercial facilities can be found in the Australian Government Information Security Management Protocol.
              </para>
            </content>
            <controls>
              <block>
                <ID>1069</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Transporting media for off-site destruction</title>
                <content>
                  <para>
                    Agencies should sanitise media, if possible, prior to transporting it to an off-site location for destruction.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on the Security Equipment Catalogue and the SCEC can be found at http://scec.gov.au/.
              </para>
              <para>
                The National Security Agency/Central Security Service’s EPLD can be found at http://www.nsa.gov/ia/guidance/media_destruction_guidance/index.shtml.
              </para>
              <para>
                The Government Communications Headquarters/Communications-Electronics Security Group’s certified data erasure products list can be found at http://www.cesg.gov.uk/find_a/cert_products/index.php.
              </para>
              <para>
                Information on the ASIO T4 protective security requirements can be found at http://www.asio.gov.au/ASIO-and-National-Security/Units/T4-Protective-Security.html.
              </para>
              <para>
                For further information on media security see the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>


      <section>
        <title>Media Disposal</title>
        <objective>
          <block>
            <content>
              <para>
                Media is declassified and approved for release before disposal into the public domain.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the disposal of media.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								Additional information relating to the disposal of ICT equipment can be found in the Product Sanitisation and Disposal section of the Product Security chapter.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Disposal procedures</title>
            <content>
              <para>
                The following diagram shows an overview of the typical disposal process. In the diagram there are two starting points, one for classified media and one for sensitive media. Also note that declassification is the entire process, including any reclassifications and administrative decisions, that must be completed before media and media waste can be released into the public domain.
              </para>
              <image>
iVBORw0KGgoAAAANSUhEUgAAAmwAAAJfCAIAAABNGR1xAAAABGdBTUEAALGPC/xhBQAAuKdJREFUeF7t/Ql8FVX67432e7nvfc/r/97T5573f/73fwb/CQReZIhK042x
nUBQQ7oJtC1od9AWYjQo2AitwU5kakILSiJhHhMD0gySgUGmwGYKZNqZgRhERYaAqBijjRBi7rNqVdWu2rv23jWsGnbtJ5/68AmVqlVr/daq9a3nWc9a63/r7u7+Gf6g
AqgAKoAKoAKogA4FAKL4gwqgAqgAKoAKoAI6FPiZjnvwFlQAFUAFUAFUABUgrlxUARVABVABVAAVQAX0KYAQ1acb3oUKoAKoACqACqAlim0AFUAFUAFUABXQqwBaonqV
w/tQAVQAFUAFol4BhGjUNwEUABVABVABVECvAghRvcrhfagAKoAKoAJRrwBCNOqbAApAFfjpVvePF7q/b+j+Zg8eqAAqwEABeJvgnXL7D0LU7TWM5QurwM2r3e3l3VdW
44EKoALsFbj6Pnm/4CPVpT8IUZdWLBZLjQLwYl8/xL7XQB6jAqiAnwKA0hvn1LyUEXcNQjTiqgwzzEiBzuvd8GJjZ4cKoAKWKQAmqet+EKKuq1IskBoFwIVrWceBD0IF
UAFRARgoddcPQtRd9YmlUaPA7e/RBsVvCFTANgXgE9ZFPwhRF1UmFkWlAhB/i5YBKoAK2KXAtS0q39SIuAwhGhHVhJlkpwA6cu3qOvG5qICogIuCjBCi7HpnTCkiFMBw
XOzKUQHbFfiqJCJ6CzWZRIiqUQmvcZECtncfmAFUABUABSA0wRU/CFFXVCMWQqUC6ny5XY1vlcwdFh8TGxcTG5+ScvBkXveVVe1FY+gZ8Yif+no76Q2FPyWmtl7mV2zo
Opk6Rnrx8DElYRKRLPVw9vWsu4SnSNIMOY67quPktNyUASRv/LO4BElS8VlFuQbGgLnS3TXGc3YVlLSjPC0N8pY4oXqbeDLMIhWcFIF5UBCt+/K8gsTecTG9xyye1xUe
M8tbFz8URzOmrZjcjTEPFZxcTmUJksNg5aI5991uQFsj63v4NcghWUsz24TmZzRL2vT0lUKbkm7x6CJEVfa+eJkrFPjhTPj+5fLbJX/iaCQew1O851YEh2iuZ2o8d7Ff
vywjbtxdiSX1y4InYgiiXfWTJ4ncJRz9vaeRI4Te3lCikhSiQkkZQlRKI/7rwRqIxgrfQO6AKDS23klzMzvCf3yoILfeZqMNot9Vu6JPwf1E3VGNWAqVCsActXC9jGBE
JuQeWNzNA1U0pKgRA6aYz+gU7CfSi4kmlJAId+O5OQXERhT/qpSIf66UDLWgOacJDplV9E4XbywKz9LbGwZRiUBUZE9YJUPaeaIhJcoSeCZ0dy+xRMPVqTyrgv4Cv7V1
/bzjwSGWqNAyz80rmTpE+hmnsnbYXqZNSQiSd8UPWqKuqEYshEoFwkNU6MqJ4ci7+8CN+cO5pZyDUYF/lJfxzwybQPycPFxlEL0iGnD0r6whynlBJWzj0qc5kUL08rvV
2ZyPeviTRYuTeA8t3/lKnMD+Z0RLdJFgcPu5c0VPcu+kqZNbz4HXl5Sxbe9zxPF717Dc3OSkoO7cwWkpgwXROEITGUWs5rVuSyGJxAzJKpjH21hCKeJTnl4P2Ah05yoW
U0ZZqs+TuVP4DwJ517+87cCLWcPBqyx68v1YHsSde/ld71IoKeR2QNrcaVQHLuWH1he9Oosk2Dtp+nTB45rXWjCGXHzXiIKPXvG53M9lH6TjCIJPnkvhgdz1IKYftmk2
xM876X8VawROTqblihuemJUygDQYWctRdI9TrZ4uyh0RT1qUUo2Er+sgH0MIUZW9Fl6GCjhIgfAQpeChntghWYsne8hYptgLBPKPnuk9JnfSehjP48cOae9J+9P0koIJ
fKfMj6HqhSifsQAbiJyXukAlvbwPoou9cxNkPmqS1aW8YU0d18RrHXiG82OTi4NA9FxmLu2ayUE9iqs6DqRwOBGPYGOiD60vGD+GikY69L5jZj09gy+LXyKcY+CKYimk
Y6JBLlCAaGpLOSEcjIxKIeo/mC1UqL9/239MVLRu+SLTbxqactLwvoIUVAd50R4ZnMSPW8szT6pjlSSF0BBdfqkgkR+pVaiR1d2yk9xgv3qIkhySLyfvXmm10hpRU9cI
UQd1gZgVVMCYAmogCv2C+M1OwSAxsALcudTKhM5xrvALieLx74tJOiF9wmrcuUEgGsqHJkKUAy1vCVH3sghRzmblRlUhhwtFK1Y4s0gSWCS6c0XzlCKWWu1ym5Ufl81r
WTxCYjCJ/alA+vKZBYmDAC3UaCvY+2fhg4B71p8mXyK2u/Bc5VJIIBrsAiWItl7mk/3WF/rE1SafcxpFFRT/YlySMPYsGppckTn6coXiz9Nxaw6u9CmEkWCyc/DjnkIy
P2BSwdvE5yFUnDQFueuVCki/0l4pIL5c6gihteBXI3REn2KP1rUWiPIjBUo1wpeFjsEHq2uEqLFeC+9GBRykgCqI0nce3HqvFfExusGHM31gW0z5KjFBCDgFK2RA2uI5
QtCHXks02MifCkvUz2Ppi2sFJ+Ty1IL1bwhu2NXd/mf8A4u4Aoon5ZYrja46Dlz0uZdDRueCdbWQG2edfgF6eWBAq2BV85G6EnM2MbXluDTQV8H9GLSYyhAV3K1gDVOM
+TnG/f3ktGEouHP9yij+V3ZeTE2erPxiqflOWl2ncmyzmI34rG2ZNA4uPuW5akIyf5uYGyjlGqdoVSvnJLg71+cqEF0OXD6hvi7KhhJwTNRBfR1mBRUwRYHwEAUz9I2S
gsklRdkc8/yA5/dfhXkvdIRPsEQ5dyV0cLxFxeNZITpJjSUaDKKKY6LywcIgdFncWvTqzgPvdl2Bsa7xWdNhRDPwjOjOBbMp0BI1DtGlxEgSRyjFDwJLIMqVaFBSylB+
1DYSIQpGPFiWd4tD+AhRU3qOEIliYJHViuPz7FRABUT5WSjUISZMdxHCdoIwVTb+Jw6z0Ukv73KDkYKbLkh0UkCQpO7o3NVdjdMhjIXPsJ87l06BoIUS3LnxKWkt4Ffk
ryTuXPkZ9e5cbkiPfEMEcVfKPgL8Bm4Fd7fPqpY4D8l4Xl8S+Uy9tf6lCHDnBl4QxBKVON6p29YMd67gEPYRWvoUiQvU586lA43+47VK7lyaOOcT5v3DUneuWCNUbRq/
7e/O5R3LPie/dIxZGgKtVCPBXNNq4qUxsMjOrhCfjQroU0DNPNGAEIw4YTDJ3zDlrSVx2IyOj4peOH7mKD+JE+Iwy2mMkl53brDAIqFb9AXyiKHFyoFFvR8fPogftJNN
MCUFkU85hTOhIbpKHrESOnBGOjYmgSgvIxc444OoPGKFd0VKQ298pZAEIQe5IDhE/WYxqQ4skvpdBX9pwEIcyu5ceTBO/PDBj/Pj5bLAImloktJyGfLoXPJhFC+MeUtD
vcQ5MJKTdw1KeoR+ZknNVkU9pRBVrJFgQVIqZqMiRPV1YngXKmCnAqpWLAKP7ut8pAYZavpDCXF4Knhi+Q7XF8DpMx+50Ttx+QWhc+QjVthDlARJhl2xSJi7Ep+SWlmQ
LCxCtLyt6PdcJK245I3fmdBjotwyRvyjpeO+QaZw+GAmHVn0m5MTMMXF9/0BUaZ0QiTUi6QU0pk8ysWU9umSx3FjnJzZ5wv7UjfFxQ+i4LQINsUl0BIls2hmTRlB5kTd
lVi07Tnfik7CFBfeGRBqNSW/KS7UvhyQlv1m22XFGgEXxZt5ZL7ykFnbpkEkOe+r4Ccxyyc++fT0m4wrTHGR1giMBShO1wlrjMIq1q74QXeuK6oRC6FegbDvNl6ACpir
AEcmMQZY8NyyXfcgVGrKAVMqbEe2srhld26EqPreF690hQK4iwvbrhBT066A/zKNCrNRzUSaQyDaed0VHQou++eOasRSqFcAlr3W3uvhLagAUwV86yLJNgywpmU6AaIu
2pcbLVH1vS9e6RYF4AW2prfCp6ACqICiAm7ZwgX6RISoW8CA5VCvABqj2LOjAjYq4KIduRGi6vtdvNJdCkB4vY2dCD4aFYhaBa6+3+2W0VDaJ6Il6i42YGlUKvDTrW74
HI7ajgwLjgrYooDrCIoQVdnj4mVuVAA5aks3ig+NWgUgFsFdNihaom4EA5ZJqwLhFwI0c7JB1PanWPCoUgAMUHjR4LPVjT/oznVjrWKZNClw+/vu76q7MWQ3qrp1LKw1
CsCgCay16VJ8oiWqqaPFi6NAAaDpjxfIJzMeTlVAuq84VpOjFYAlNl3NTrFDREs0CtiARUQF3KKADKJuKRSWI6IVQIhGdPVh5lGB6FIAIRpd9R0JpUWIRkItYR5RAVSA
UwAhig3BaQogRJ1WI5gfVAAVCKoAQhQbh9MUQIg6rUYwP6gAKoAQxTYQMQogRCOmqjCjqAAqgJYotgGnKYAQdVqNYH5QAVQALVFsAxGjAEI0YqoKM2qjAiXFxXg4QQGp
JeqE/GAeTpw4YeOL6YRHI0SdUAuYB6crIO278XdUABUQFcj861+d/vaanD+EqMkCY/KuUAA7TVQAFVBUACGKEHVFH4+FMFkBsft4edIk6DXwsEsBaT9uVx7wuaDAM+PG
0bpAiCJETe59MXlXKCD23a2tra4oUKQWAqNzHVJzMBiMEKV1gRB1SJvEbDhaAYSoQ6oHIeqQikCIihWBEHVIm8RsOFoBhKhDqgch6pCKQIgiRB3SFDEbkaEAQtQh9YQQ
dUhFIEQRog5pipiNyFAAIeqQekKIOqQiEKIIUYc0RcxGZCiAEHVIPSFEHVIRCFGzIPqzOR4mh0Mair5s3Ljx4/c//ICHmxQQ++6GxkY3lSviyiKFaMRl3k0Z3rxlC62L
N15/3eHlunXrlr6eXOVdjAOLmBAUElGZ+7CXNTadwgMVMK6A2Hfv2r3HeGqYgm4FpBDVnQjeaFyBvLwltC5eevEl46lZlELzmdMfn7vcduX69W8ZkhUhah1lJ6wqxyNC
FRD77rHztkRoEdyRbSlE3VGiCC1F4isLaF0kjHre4UXI3lKZW1QFR+Fe784j9SKwz3z8CdD09u2usMZY6AsQotZBlJWZjulYr4DYd/+XP2+0/un4RFEBKURRFhsV+PeU
bFoX/zH8ORuzoe/RQP1VO2uOVTUSoDaf+eqrr41wFCGKEGUzjK2vNUfKXQhRh9QUQtQhFRHREBU1/OvGCopSsEohlkUfShGiCFGEaHgFEKIO6bsRog6pCBGivfr/0iFZ
0p0N8PfW1DU3NJ0G764OjiJEEaLhEaK7dbrmRoSoQ6oSIeqQihAhCjXikCwZycbvlxwrO9EAJqkOjiJEEaII0fAKIESN9FBG7v1Pb+2T3q4IUb9rjDwO71WpgMsgCqWO
//thfRxFiCJEwyNE5Xvl4ssQonZV7r/M2PE/x0wTMRkIUQj1isTYFrv0ZPXcYBCN6A8akaMw81W9XxchihBFiIZXACHKqvPVkQ4wsufgEf/64jK4VwrR//yXbcBXOEP/
hIfZCvz3cVmgOX1KIEQBn/9rZLp4gdmZMSl94Gh1XXPTqRb1U18QoghR7H3CK4AQNanPUpMsMJLqDzEsUoiKv0e09aNGAYdcQysC8AmCi5UCZ+h/oXbgW8chWTWSDZgA
A4OjsCaDSmMUIYoQDY8QIy3SHfciRG2sR+ijFdlJT4L1Y2Peou3R4ndMzANPipUingS+ukMQWJYBOKpyVSOEKEIUIRpeAYSovZ0jddsqHv/1lXX25i2qnh6iIqB2YADb
HWo8uugoQPTzLy6qMUYRoqca60+ULJ+VnvL02KfGyo5xmYXlTQwXdXRH84rOUiBE7a13IKUiQV0wSdFeYbU+HYY8g33NgG2qNTUnX6/eGEWI1u/P+WNfxY/cnhOWH+XW
hWJ0OLnFYN5CK4AQtb2FKA6IgmFke8aiLQNSR64UqP82YZGbpKDG6NUvr4U1RhGih/KeGhg39M0NR2tZwTJYOm5qYdFWFoSo7TUOoaGBNlCkx4LarqqODAAsFY1R1/hy
RU1g2mjz6Y8RomHtyBOFkx+Ke3RuaV3YK41eoKO94i0OUQAhantFBDoS3RELaruwWjOgGOflyvAuWA4QLKKwa+qiJVqzZ9mUYT37JoxKm5YxI0N2LN5eiWOi4YNutL6E
kXg9QtQJtQbUlNpArokFdYK2mvIAyPQzRl05VZd6dMPu8YIQ5dy5yoF/4/M8OCaKECUKIEQ1dbImXeznSHSf/9Ak3ZgnGxjn5dapurDwwvnzF3A/0dBu2KaaE8cOeY4o
HIcrahiFFNFRUuZNGRO0TAGEqGVSh3gQUFOsCJfFgjpBXk15kMZ5udKXS9WATbybTrciRNWNZdZXH9pdsmXrh1u27txXXmdGkJGmNooXO0oBhKhDqgOWAKR14Ur/oUNE
VpMNaZyXi+sit6gKWIAQDQvRukOFM5++r6/EqXtPYvriUqYDomiJqnkzHXsNQtQhVSOuNudW/6FDdA6bDTHOy91TdWlsUeili3BMtPH4poxhPXvd/fjEjOycvLwleYvf
mT157P09e937dO4epiG7YdslXuBYBRCiDqkaGhrqYv+hQ3RWkw06YdTdU3XpOrqhN3VBiB5dPeGXcQ+8tb1WarA2Hlk+sW9M0uxSsoIiq0NNu8RrnKkAQtQ59QK9Ni71
54TqoHFe7q4LhGi3Cv5x0bkj39nbKIVlc1XhnwfEPJKxtVpFCmop64R2j3nQpwBCVJ9uZtyFCyyYoaqONMEr4G5fLmiCEFUD0bo9C57q03P4xHlrtuw+yMXo7i8pXDx9
9C/j7plaWIHzRHGKC05xwTaACigrADui66BvBN2CEFUD0VONdZ71Ux7v4zdVND5lfikZUmZ4RFDTwaz6KYCWaGCTeGNzQ1HF+dZL31786vuwS6NF+gVQzPpPv37/yLm0
/BqnvR1jllUs3ffx/vpLkMkbN29HutSh8/91x49QTCgsFPm+d46bXRcIUXUQJaT0Hip6Py/7LW7FornvrNqy50QDQ3ziPFGz27rZ6SNERYXnl5wqP3PV9Z11iK4c+nH4
erCgBw/dqiEDAPVo+IIJURfwZQM0Ne/1R4iGgmh9WcHMjLdyivZvz6HsDDxw2T/0YvEKIEShn4LeCvjhbkNHfengM8IulAI+4TtGfVZdfyU0S/CLmIFShGgoiNZtnXF3
zMCxeRtx2T8zGp/L0oxyiIIPM8otnmAcgu7bYgcvWJ/R7AYI8UEAHxbM3QMI0ZDu3Prqo55j5d5GXPbPZcAzozjRDFEwQF1vyhgpICDNVI+i2J6BEDAcaCSrrr8XPvXY
chQhqmZMtALcuTNyiiuYxhApjqea0bljmtYoELUQRbehSvCYzVFgAzoD1NQFW44iRENDlOAzI+OVsUN6xw0ZOwXHRLkFl/FQVCA6IQoxkGq6LbyGKmCeXxcJqqmNAUdZ
9WMI0dAQDbEJGlnhOi4Gt0JDpkZvYBF6cTV13HAxjI+y9SWKJEAvrta6gO8/JhxFiIaGKN0E7cPsUQPiRs3fHrgbGm6FhoapoEC0WaIw9RCjV7R23HA9q75bCgCIAdaR
E7yFiWMAIapmTJSsndtnyBNPPTV2rN8xLrOwHFcsQmM0Glcsgul32AvrUwC+P5jYQDQR/JrRVwtwF5jvxisCIaoGoscLp42822+5Iu6/fe57DSFqvBW6I4WoskThE153
z4U3QigWwzaPgV1GWpTxyaMIUTUQrSmZParPPS/klB6rEQJ0607syJnw67h7pqwvb2S4bhHDVwuTsliBqIIodtxGOm64l5UxCiOs6FQ3UhfgUDHYUSBE1UCUCy8anXtA
NsWl8VDe+Dj/XVxqd+VM8nf5yj3AT2dsPB58qozB6sTbbVQgqiCKHbeRjhvuhfUQmLRVjO0yWBFwu8FQL4SoGohWb898Iq7nY+kL1vO7uJTt2V6Y+2riwLief8g5UC+x
RGu2Zz4mdqZKv/S9f3IhQpRJ9+G0RKIHorA0rvGeK8pTYDXFAkemjTckg/N3EaJqIHqqsbJkwfiH/Hdx6fnQs4t2VSualXV7cp7+VZ/EzMIDVXX8BQ0Ve5ak3tN7UHoB
QtRp/GOSn+iBKMaCGu+4jRtAtNGiS8B4XRj06CJE1UEUQFhfdUCyi8uCZYVFHm/Q0VDPkrExsfHTNotjqNyVnFt4wIwt9UF3T2PSm2MitigQPRDFKYnGO25IwXhICwys
MslJlCcCk3eN9BgIUdUQrfFsXbNoTi5Z/K++7P2/ZS8t3H1SsDIDoFhblPVA77j4Z7JWbdtVdpjs4723tHDx1KS42D5jcg80IkRdOCsmeiBq7j4tHa0Hc16Ip8Hw/V7I
LWvt0N7Hd3pzBt+b4+3s7u5q8+7Y42272d3d4c0ZOZg755AfMOiN9N1wL2DY3LK0FadJZyVAdRR727o0PtNXBRpvtPByI8OiCFFVEG04+v6rQ/uRt/qpJYeaTnG7u8BL
/qunF+xUduc2NVWUvvvsfX39hkX73DcRHMAhonkNvlR4u40KRA9EzezcrntznoxLnOch2LvZ5pmXFPNkrve6/id2enPvHZnr1QFi/c9UeadBLyI0ddOjighEB6UVX+BK
1NXRWpyVOCgpp0qbmg6uArGmjHgFEKJqIFqxadojcTEPpy74YNexWoJA4tpdnfXUrwICi2QmZu3RbQvTh9K+9f4Hf5E4ZemuyjArM9jIAHy0QQUQoirhEeqyrpaC5EFj
8lt4a4f8t78h89HBPbjxmf6mD07LIMpx1JuXFJNS0HpDQ107uArEUkCsnO7XHyGqBqKKY5kNB3KeCZjiIkJUbokOSM8gGO57//h3S0JyVHdF4o3WK/CvLy77z3/ZJj43
EKLw1/8+Lsv6jJn9RA0dqNZLOWrGZ3ra+RvbWz07dnIexK62qg2ZyZzIyVk5GUkxU0raOonbNiZ5RubznPu3f1JmcWsH4S/vzr3g80YOzvFUCu7crrYTeakJXFIJaTn7
6S3wgOrF1I3sS0dr9jVdH4EQBZV8XzkSGZOzils48/RmW9WKtH4SV7zEITz47ZwF9yakZU5NionlPozaW4tnwu/Ub59XBbV8ozU/JS45v5X/hvL7ryZ1tV1sxLWOEFUD
UW6xhZgHx89ezU9x8ewvKVyUDg7euInLjyottsCNifYZmp696v1VGb+NG/CX9XvhjpeH9eyF0blmd/GWpf8vM3bA+//vKdn/6a198FApROEMnIczUspaljGzH6Stf9J2
NXXhAsbWUXbyP13nS9IT4lM3tHR0dbWVzUrsH+eDaP+kmWVwKXeet2J9Y6I+M0gcE73myXyYJtXdUZXL33LzUvHUwakrqsGN3NFckPqwZqeltmKSqyMSot0XSlIHxaUW
t5EaGZm2+ERbV1dHy4a0fpzXvd2T1S8hLb+5Q2qzilVAfokVfPVd7Z6Z8Tw721vy0+M5A7erNX+MaOn6uSW0K6z+DoSoeq0UrlS13pDiFJcBo6av99QqTnEh0bkDx+Yd
amzi1mTgI3IxOtdt8UT/Mfw5IGWv/r/8n2OmiRD9j2Ep9Peeg0eYzTNb0jf0voW/GcbejpTkZ3I2SnJWIbFQuolBI3oRuf7XB1HxPMEk6d9FSxSCiBQgSjAgGLs327x7
Sjxgi4KBNSLLc43LHZc+jUsy8ycyIcqLfAlo12+mp51+55DvEmJckmp6mJeRxBPt8LS2+6qA1EV/wVcvrQVq4HJ+e0lFyIBqZkVA2ghRQwKrgighpfdQUeGyBXNnwK6i
mfNz12zZc6Ih6L2cJdp31JurivZsz34qrv+rq/ft/oCLzu07fuURXLHILXu/gEc3xNoaYIzaAjmzH2rofdNwM3X3kW73JnHbEv8tvZvz4oruXPG8SohSyyk2PjWnqJjr
5eGHmFB0c0PhQIiCLP5jonCKWqIftpDvGJli1EPL2ZTgJN9cUnyE95PLLFEhTImcFEOWIFmx7ogLl/vEsc6XixDV8FIqXqoaokHnpSiloBid2+vuxDfWe+owOtfsXt6y
9MFtGwKi4O+1LCdWPsjoKxfi/o5WTzGdkUJ/+J70dBVDiNKUyWgrZ+9y7kcCUcGEMrF4sqQj0hLlXaynrxNnrGiJyiUjlbi9AAaw+6UXtPhZomEh2k0MUJLyVU/mCF+I
mcmVEmmW6NzDP2NxsFI1BNLqit66L+ae8cu3LE+5R7mv7DlBeUyUszXrKg9tz1+SnflmRsaMGbMXrdq056gXo3Pd5tGVOnKljSTmgSetBJuVz2L16imkQ2AmNVAEc+Ri
CHeuRktUNm2RSx+MzpvSqGB05wo1Ezw6V+5r5d254BzfuUMYyhY9tIqWKGfR+iLIpGHY1KO7/YOsfhrDgA20S4SoAfG6QwUW1e/Off6pZzMKdxRmPKu8rDzuJ+oWx6xu
CP3XV9YpfmCBp1d3mg6/0dD7FuZm0h2LsSd0YiIxR0IFFmmFKBcAnF58CYbzSAxRAvc7CSyKp5ZT5AQW2TlP1FcjnWJgEUfWhEnF5yHMizvJ/a4MUeXAIp/7AXzFvjBd
M1sclzZC1JDEISxRDqKTcnYfBIiG3n1FSIRbgB7M05Kl43vKh1iE8YM+KTgm6jZjFAKLAjlKQ3ZdeVi6YpGwRI5sXgqZJqF7TBTieMUpLhAG/AHvPfZNcZHMezHUtYS5
2bg7194Vi3wy+haWkkxxEYPClCHKedT9p7jwinEwFkOQzKwDIe1IW2yBhS8XHMKspA3lziUrEw1MnPDi2CG944aMnQIhRf7H4u2yeZ/cVmhgnu55P2PcWEXjFbdCcx9X
YDKoH0T/18h09xVTLBHuHMKk8zG+NTcsVsckJ05LxMq4XFp2hKihNhAqsKhm54JxvwoRORIXMz7PI50nykH0T7m7jm3MGAd+4ONao5Zc3PO6uGgwGdSvkYCP18XlNX2h
HEMvdMTcbMSFKLYuc70C9mhpaVwuLaKRt9WOxRYixxLlVvirPur5MHvUgLhR87fDOvJ+x+EK+T4t1VsyHomLe2Liy2MTYnonPPVKgOU6Y0YOWcI+GFyN1CXea6MCMCVU
5Ch4d23MiQWPNt2LaE/fbfVTjVg/Yi2DOWt1vs1+nm8FDLOfxKcfgbu4RA5E68sKZma8lVO0d1Pmn56e8Oob4d25zdW73n06vlco45Vbwh4hakFfb+Uj/m3CIrHSIV7X
ykfb8izcxtJ4B8+k4kyPLTJeTsenYNCvjpZoqOhcbrcWWHhoI9kHVD6zWPivnzuXzmwpP1Q0f3TMgNHZH/pbrp4jnhM4T9SF4TZ0CUB6uHKpP78e34UGkLV9vfEtXGiN
uHVY1MraMLL6PFQBQjTk2rnEl3us3NtYc+JYIA7JGX93rmhi1pUfhhvDzAoNtEeZfJxiIrYoQJcAdOtSf36SokfXYC9vsOOWVgd+0BipC4O+XIQoEV9d7E/doU2Lpk18
q7C8qbHOUzjnlfFP/WHitEWb/Jcfqj+wPjsjY/H2Q0U5Cr5fEtyLY6K2EM6Ch9IlAN261F+ggDBDw0jnFc33Gu+4pdWRll8TzWIaLLvx8C60RNVAtPH4poxhMO+TrE90
cnvmb/qIkz4fnbm9ulmCYS6wCEJ2t+aOVXb/8tt645ioBVSz+BEwMRRCity61F+gmGiM6u6+GZqhtF5w0pG+uoCvGfCHG+wo7IDo3w7/jMWhT7XAu1RYokdXT/hlXN/n
c/fXNFYUpPftNeiltUfqKrdn/SYu5rGsohppCmRAFHy8jeDODQjl5SJ7cUzUYJN18u0uXqVIUXY0RnX0QqxGQ6U1MmZZBYZ66agLJl8zCFE1luhhsnbuXa+sP1mzP2d8
35hHpm2qaGyqKZ3920CI+oBad3jTgr+kZmw83nSq1rNxTvqzY8elTluw+VBdqIXsnUyIiMsb9CxgLcEBHhv3HbRoTKZJ6K5Z7Lu1dtyAOuOmj2J9vX/knNbMRPn1++sv
6W750hsRomog2nBo+Qv3ii7ckX/fVXescNrIu2Ni+5DfFaFY/sG0J8DrSxb5q96e9Wg/IXSz34jM7VU4xcW09fBgfAh4GW0WEnilILoEZjuY1EGH6GvgWz7K+2L1xQeC
Qvtk0nErJoIRRurrwuC0FtsheuRnf2NwqNcr9JUq3LmAycpdyzNTxz09Pj27kAQTHV4+fsToyYu2HK1Xvr187cS42P7jF4MD+OT6l/vHPJi+xlNbXZT1aN+4X761vR7n
iTKe5QLwAHa6cfUWbc0cumnoHcBANK+nDkwZpyqqqSSzCQr1Am/Bxa++V5OZKL+GIUFtis5lQVDAMKt2oA6iKqNzBToeXQkL0A9ILzhRty9n3D1xg/6yCeKP6kpnI0RZ
26AUnzgg5Pc6GI851IRh5Gjo7gjYZs2XDbwOaI+Grgvmr4Yt7lwGZqi1EFUfnStAtPHQ8mfvE1y4A36TvbO2fMO0oXfHxXC/ozuXEUphRBCtz2BdhmUdN8UtOCrRDAqs
C/i8Y95rh/2+wfFRxZcC2qcZMQQIUTVjohqic312bfm6cdww6ug5G/Yf2DDncbqczbQPa6RTYvz9umFfD7xAVACtn7DOGAtciH4NEr0CYqVQfFo/Sk1rBAxfNEnFuoBP
beguTOo8EaJqIKojOhcDixiPevq9ANhBhCUovQC6cmsciWIFATagw4pmqxQmsdgS5BUICah6iEGNWm8NDbgzw/rEwCJZ/6NiTFR7dC4GFjFy2Cp+PKINqpKg9DLgmS32
EDwUYnfBGgOoQLy0uw/orKGkZvfXum0pcLbDW0MD111/QDGhsKYGQiNEtUJUe3QuBhaZBlFcKEcTQenFrKbE6e7ErbxRuleElc/FZ/kp4Ldph1v1QXeuGnduqOURlA1Z
DCwyDaLhfVPtnqx+sXH9Znrau5R40+HNGRmXWtymjkWd3pzB9+Z4O4NeHfqCrjbvzh3eNsWMBCYJV+/Y42272d1NMjk41GPV5V5ylWUf5rb3lQhR26uAZgAhKr5/P9P8
voa84X+bd4TJwSpXKty5xwsznh371FiFY1wmWZJeMdq2cvfyjLSnn3o2fc5GskrR0ZXP3ve7KQu3HcEViwzwFRw1Yeu9qzV/DInhejjLc804RMM+LvQFYRksu73Tm3vv
yFxvh8GHKt4OTjyH9K1mZwMharbCKtNHiCJERQP0OF2fKHBL0T73vRYUosHnsYTAtsrWGbWXqZgPeqM1PyUudWlB5sPxmZ52BZ5os0QN8sw5EIWCRIkxihB1SP+AEEWI
ihCtKZk9qs89L+SUHqsR0Fh3YkfOhF/H3TNlfXmjAhTLN2aMU7Jcnxr7NLeaLu7iouM9VxdPdKEkNWFMfvOl4ilxyfmtvB/1Zpv3g6zE/txb/XBS4iDOncvRNHFqVmoC
Od/vhbyysqLMZO6a/kmZxa0d5GaRguSXmOQZmc/HB7mgu6utevEL3F9j41PzDrZ+3QZ54L+9RuZWeHLvTUjLnJoUEwt+2pttVRv4ZyVn5WQkxUwpqdmaJnyoDc7xVFJ3
bldLQXJ/n1+XmKr9x+S3dPme5ctqWN6zXahFRw1acwtC1Bqdwz4FIWoWRP8f844wOcJ2GSovUOHOPZT31MC40bkHZPBrPJQ3Pi7mkYyt1UoQpUsrBBqvfe+fXIgQDfv6
KV6gar8nMiBKPKKcUzeloPUGNIOuS8WT+iWk5Td3dHd1ePMAYz6IxiTP8lzq6m5vyU+PB3bOLIPxS+563hssh6hwQVvZrMRBBGY+yna1e2bG90svaAHr97o350mKcJ8l
SvgXG5c4zwNDnl3nS9IT4lM3tHQADSEpoPuUkrZOuFpw54pjopxhLXwNCIVqv1Q8dXDqimpIqqO5IPXhpJwqNS5gsOP1KR9ZdyFEHVJfCFGEqGgvVm/PfCKu52PpC9Zv
2X0QtjM7VLZne2Huq4kD43r+IeeA0vK5tSWzhw8YNCG35FitgNiG8l3vTbyn96D0AoSovpdcxVcRJRkXUiQabd2dxCL0WaXXPJkP+yAqRBhJodvdDebsIGr/ySHKU5kG
/tDoJOEC7ilCNBOJJyo+ArasHKKcEQnFaCtOEwAPiCd5DgrRbknGBKB2gnk6Qhjx5W4PGfok1Y3J3k/6qs+yuxCilkkd+kEIUYSoxOlaWbJg/EPiXtx84+j50LOLdlUr
+mY9S8bGDPhdzgG5kcpZtANmbMEF6LXHFqmb2UIHRGnkLYElNyzqNwgq/ld+noCNMwfJTzCIihcEQhTACkZhAriFc7cXl3haqWkoh+igtOIL/Enfs7hrgkO0m3h0OatX
/IWGH0v9HKohGg1zXRCiCFErFbBhikuP7KNMDhV2iapLVLhzOZrWVx0oej8v+62MjBkZGXMXLCss8niD3ltblPVA7z5DJy1Y/+GussOHPIcP7C4qXDw1KS62z5jcA404
Jqp5PSNVA6LcCKKMLsQ0bJfPaTENoqS5dXW0HikpXgfjr9RbywCi3fyXwSXRQU0gGiz2OEybj4YYXYSolQgJ8Sy0RM2yRJkQFBJRRUgVF4WAaH1ZwUyCzBDH4u2VilNc
mipK3332vr5+zajPfRPBdsXoXB0vuerJLaLHlTpCYXz0uhp3LudiNWKJQuzSnp3CjFDh0R2KENXkzuX9vf0yCtal805p0STlsK3JnQs36BA/sm5BiDqkvhCiCNFTdVtn
KM5skTSO8XkepehczsdbV3loe/6S7Mw3AcMzZr+7LL/kUE2QSaWCT9ghrd+B2QA/ZLgvIg4nvrFP4AvvCO0MEVgkrrpgFKKcvdhvasklWCqBC1PifleGqIbAIq7QvP9W
GFLtvgmBRXwQk5bAIiqgLUsAWtmiEKJWqo2WKLpzQ65YVF99FMKIQhyHK8RJL5x9WX9gfXZIy3XGjJziCpzion1MFPyQ4SBKBkHlq/yIoa0wo2RFGh1HTMzIhbkl4hQX
ZhAFZvumuMQlZm7grFJliJJrT+TRqTUxdN5LsOhcWmguGMoXiyR9VkJazn46G0flj2PXd2XV9SNEWSlpMB20RM2yRP+f2UeZHCq7jLCXqR0TrfFsXbNoTi5BYH3Z+3/L
Xlq4+2SdPw6rt2Q8ojSzRRIG8tSSQwhRUyAatqrxAqIAQtQgG/B2lQogRBGivvCfhqPvvzq0H2kTHAIFN++vnl6w0y86t66yPJTl6jniOVGHY6IqX0LpZSosUWSkKgUQ
ojqaH96iQwGEKEJUhGjFpmlgXz6cuuCDXXTeJ4nUXZ311K+CzhMltmZd+bFqaqoCWUOzU8SqjpYaJbcgRFURUsVFCNEoeWVsLyZC1CyI/u/ZR5kcKroLVZeocOcqzu9s
OJDzjOKKRbVHP8yZNn7YgF7ClFDq4+2bMGrK/E2Ha0OuqWt7u3dsBhCiqlqziosQoo5t5C7LGELUNIjOP/q/szhUdBeqLlEBUW7t3JgHx89eza9Y5NlfUrgoHRy8cROX
H5VF59Z61nOO3153P/y7iX9Zf6CBRhvNSv/jyISesXE9n5i+qRzduTo6C4Soqtas4iKEqI7mh7foUAAhihANt2LRgFHT13vkliVdIHDUjEJPwEpGTdWH1r16f+8+4zCw
SPNKC/ACq1o4VwVC5Jdwa/VJlv6JT80pUb37p5BUmL0/tW3korkImm9AiOrgAd6iQwGEqFkQ/X/NP8rk0Nx5BLlBhSVKaeo9VFS4bMHcGbD2Qub83DVb9pxoCLhXcal6
3xq8xK+Ly/5pD82FF1jNYgvamwSFqLjGQntr8cykmCdhfQbtSUXMHe6D6L/M2PGf/7JN7OUVp7j811fW6cAA3qJVgf/y543/6a199C5FiMJf4RqtyTr5ehvmiTIhKCTC
qtNSDVGOhTX7C5esKNxbE+Su8vUv3Rd3/xubKpQWVajbs2D0wLjh83cRH6/y4eS2Ym/e3j9yjlWNS9Lxgyj8xbcBiwmPc0SSrlxsoefgEf82YVFg3w1nALH/a2T6/xwz
zd4GHCVPh4+VmAeepN80gRAFfEJNIUSNdgSRDVGysvzAsXmHglCwubp0XlLP2D4P/ykzZ/2m0v3cdBdu4dzl2VNG/TIu5tcvrDncgPNEtRuj6hag19o4AyEq3TVFukTD
zJJWbodvhY08Je5c/y1FyS0Sdy6srFssbGuakLb4BFmOwW9b05jkrOIWNfuaaS2qz7OkXXznAwAYCV32fwx/7l9fXCbtu+l5OFzWcTu5Rnr1h44uVlRerA6oHfgdIOrk
zOvImw2W6P8x/yiTQ3cn4nejNks0DETJzJZDm+aND1g1l7SkAb99dcmuEMsVQU50VGH03MKqxkNaonSfMrLdCtlV9N4X8qqAdNwyfol53o4b3Hp7ZD0/bh/QQdxGniJE
w20pSlbvo+zs6mjZkNaPLuPHLYjPb2t6s80zL0m6MhHrMrt1AXowfUIscuK+jtvJb/1/H5cVoi7gr07OvI68IURDLvsXaDKGhyjnp/Ue37VpXR4dQM14Mys7d3l+8YHK
wDFUf6eujiqMnltMCNBVsES5jUgBoq2wFi63kxr3w+/1fbokNYHfE5RurkKW6hUhGnpLUdlfu+ntZAszDqLikr/808mOaWb8uHgrNCBlsL7bfR23k9/60B804F13cuZ1
5M0OiP792P/B4mDVxWizRMOMiQaOdDZX7/1gyZIP9tY0q3mQjiqMnltMGBZVgihviXq55Wql23aOzK3wcHz1I5zEnRtqS1G/bU3FbURhFJbf35s0aZMh6uJNuf89JTsY
RN3XcTv8rQ/2QQPDpQ7PuY7sIUTVW6K1R3d/uH750ry8dR+WfrhGnWXZ2NR4KG98XEyozV6kcNVRhdFzy5hlFay+nIR0QoyJXhD29JZ6f6mRGhyi3KhpkC1F7YfojZu3
XdxagJSKEHVlx+3weoQgL8W6EIO/HJ5/TdmzAaL/6e/HmBys+lM1BmJjZcmC8Q/14e2SR6ZlpMMWaX3um7CgtDLc7QhRPbNCgzVi1rNFQ0Tnit7aYO5ccSNP0RINvaVo
SHeuuJmMmZaoi325tMEALwP7bld23Jp6eesvDvZBI85+sT5L5j0RIarGEqVLKDyWnr2qcNWMxJhH3li/cztdseieKevLg+4nyvEVIcoSoqxjdEPNEyWBRRAHlN/c4Qss
+oHbNDS9oKW927eRpwjRcFuKhggssgSiYMqb15U4IWW/0FwKVFd23E5QO3QeaCyu9ICJRs7Pto4cIkTVQJRbQoFuYUYCix7J2Fot0JH+HnTeZ2MTjomyhCg0cabhRaFX
LPJNcYlPzTuocYqLwpaixNMbZIqL+RCF1Sp0dBCRdQvwMko6bufXS+AHDZxxfrZ15NAGiP6ffz/G5LDQnctZonG/y1hVtHf7/NExD05Zs2vXpvdeTRwYuHZuOO9uCNyS
P+mowmi7BcwpGNtjVftRks7Fr7535RoLgY0fzB0pR93acTv/rff7oIHJo87Ps74cIkTVWKKn5GOigo9CYe1cHyPryncsz3p5/FNjx8qPpzM2HsfFFozN91+67+MogR+T
YsI3R1p+jb4OIuLughVzRIi6uOOOiHqRrrfg4hWjEKLqIMrvIfp+XvZbGWTq59x3Vm3m9xZVJGLD/pzf3a0Yn9YnZeURhKgxiEIPUn7mKhPAuD6RqCIoRQtdMYcumhMR
sHFrJqUfNC5eMcoOiL597P9kcbDq/gw4YJsqdnxYWqm0TC4ZOu07LGPjEa/SXxGihiGKHFXT/qOQoNAwxBVzXNxxRwp36QeNu1eMQoiGs0TrDm/KnjJ6SN+4nvclTchc
vkuY01Jfvn3RS0N7BpkAWrFhyj39RswuDb0FdyC/I+XdcEg+zdnaRQ2eIuAaiMCKknFQv9ZIV8xxd8ftkBcwbDboB427V4xCiIaGaNX2zN+Q6aEDHhn9+yfIrtrxz+Xs
9dZ6Ns1OgWmjve5OnLlF0RKt2bss/bE+PRNGvziNc//6jhk5xSGWzw3bKPECPwVg0svXHT9GANMszCIIAsPG0dxUgKCwgFE0K+CQstMPGnevGGUDRO94+xiTg1WnFMqd
W752Ylxsn8TZ2wkpmyq2z07q2Tvh938YHd8rrudD42dvOFATxFtL3LmyOVK+8VE6VQa3QmPh0RV7CmAGohTeCIjCdSY+IaYaPncsO95cXpxRaOkToWiRYvdbVgv0QX9d
uMriJ1ocRocQDWWJ1m2dcXfMgN/lHOCZ17A7e3jfOGKATs0rPVEXanpoXflhugnaNm6lwCV5qzeV7PXAzmieE3UhsO2Q78cIzQYsDAsBR1FIU/Dcgmfb4r4jbCOB6oA1
kpjO62X15WxWOjAIDeWFRZ4dta4FZAY+raLt1YB+AIoMBTf74wYhGhai0t1DYdWFh36XsXaPogvXj6l1nsLMP94PHmDRJB2QlJ67A7dCC9v5Gr8AXhv4+IX3B9Di4gPK
6DRwQt1Blw2dF87ldYJXAF4B1itlmvX9YWq60CDN+6yxBaLH73ibwcFK9BB2IWeJ9k546hV+UPONl36X+OxrsjHOxZynN9A9W/7BtCf6xNyTOCEjO2cJWKKLF8ya8tSD
fWJ+9UzOnhDRRsb5gSmgAnYpQPHJ6sV0RzqAUls+dMANEIUumdBtBvwiZlilNkD0X94+zuRg9Y6Fg2iQoU3evgwSnUsGU3s/lFnklfHVs3z8L+IenFvagGOijNcCtAsb
+FxRAfBhovUZrFMCcSxrKsCJqHKhawIBfFgw/6ZBiIaMzq2vPuqBoc3gx+GKGsWRURJY1O83C/Y2yP56snDyr+MGzNhSjxBFiLpHAei10WcYtisHG90CjgIh8FMmdF0w
nzxtB0QXHP8XFkfYVqvyAgOLLQRfCLdhz4KkAX0efmHemm27yg4TDO8tLVz8l9/F9x40ecNJjM5lGpprQd+EjwimABAUPJYq37Uov8xsjsIIKBJUTRtjy1EbIPr/XnCc
yaFGLDXXmALRplO1nvWvwl5psokuve4dt6AkZFASdtaoQGQpgARV08mI15g3AQltUE0VARxlNT6KEA23YlGoeSxhtmRprDlclL8kO/NNiEuaMXvRqk37yoM7cinLI6sD
xdxGuQIQqaGp58KLQQHmY3LQCIEHaINqbV0wcszk/UWImglR7QBmUqmYCCpggQIqNkjvavfMjI+Jjc/0tCv2cJ3e3HsHpRVfUNf9iZufB7s89AU327x7dnrbutQ9rKvN
u3MHdzXJ5Mhcb4e6+8JfxarvllaxijHpa57Mh+NiHs7yXAtSFTmDY6aUtHWGLwCRJGfwvTne4NeGuQDE3bHH23ZTzbO6u30VF/a56hL0XcXEMWADRP8/C44zObTqFex6
le7cuspyMrR5rJpfY8Fb4YH/+gcWNVWW7diy9cMQx9bd5TjFxYIuHh9htgIqZlDcaM1PISMa/WZ62pXgpQ2iBt/4sAyWpc+8v5amDt8fDGtHxddMd3dXS0Fyf6iLYB80
pLyqIWqwJjR+l2irOE15gzZsvCIQoiot0bpd2cmkOxg+fxeZoNJ0cv3L/eG/fV9eXyGdJ1q9JeMRxR3QcNk/440VU3COAqq2dCUdd0LautVZ/YIYQNEKUbbGqJoJLV2t
+WNi0tfnZ8QH+aCJTogCcY0bowhRlRCtP7B8Ktlee9LKA40A0eaqrfP+AP99Zt6W6maJLdtwtGgdWeRPeixe8MY4WGaBzDftc98fMlbtq8boXIzOjXAFVPgPu7vbitNi
UgpaW0tSE8bkt/CmKLjyCjOTaMDdiJFJ/Th3LqFp/6SMjLR+5Hx86tKDns1ZicRyiotJzipu4XypokVCfolLnJqVmhDkgu6uthN5/F8T0nL2t3Z8XpI6iP+QvTcz9+2R
8akZMyB94pMEb+EH/LMSM3Izk+NSt3qLpwhfvSNzKzycO/casap9PkwuD8n5rV3SZ4lZDW8OsRoZhQUuwj+su7MNSgS5vURr5Aa9pautagOUl4jc//HEEfGcJcrRNHlG
5vPgh4+LSUhbvNuzfSZfX4kzS1qJY95npssrLi7wAnDGVq2g1RrX74XcstYO0ir4yfeD385ZcG9CWuZUSH8wVIWvbfRPynw7KzEhrfiYpOJyKis4N/JNYlWT62kxuDxw
DUzyLCEnYcWByDiD36Y2QPQ/LzjO5AirjsoLVLpz9VxWf3LX+oWvkYWKOHzmfXgo2IL1AlYNVifejgpYoACEsah4ubgBUUIdzqnL8QbGty4VT43vl17QAn3xdW/Ok3Ex
IkRj4xLneWCcrKO5gPAveZbnEnSL3PXUGyyHqHBBm2deEg8G8QIy/hefuqGlo6u7oyo3cRDXwyre3t11qXhSv4S0/OYO6IJJUrFxqcVt/pwgY6KcMScQiBjZXLJd50vS
R6YtPtHW1dXRsiGt35O53usqxOmGmCwmNQXLOKh4HBGEo5SQbYJQyHmCRCX4ZBEh2j9pZplQIqFe6PXc8LYcouIFlzwzk2lF+y5o92Tx8nZ1ePP4mhKHmckvwu3SttHF
JUXbhq/ixGSlLapbrBdSlfe+kFcFA9ntLfnp8Yl5UGkqxOk2uCIgQlSlJRouENfPuCT4nJ/++D289akCnxidy6RPwUQsUECVL7ebI5nY5/L4uSCzSkkPK0JUjDCSdZGc
OUvjeuQU5KlMDRG/3haeMkgY/CNhKSWe1g7l2wUTje9sueibIBDlhhUpjyUdN5DV5yAVWKWi52YyGgd1rcaX2010ph51nwEt+AmoVUpDwESIChFGUuhSc5azxf0sUdHN
IPqEfReQ6hOc+SSeaIcHbFkZRKkRCT9B2oYCRH36d3eLrYX84hvxJUVWGw5mcD0phChriNZ4tuS9+ezQu7XiEyFqQe+Pj2CigKqZLXRAlEbeip243yCo+F/Zea6z5khG
foJBVLxAAaLUKAS3cE5RMddrkx85g/nbOaiISVHGBIOovL/mTC4+/FgaBuFzM4ZDqUEDiFZluIdwhCQ2NOUil2GO+n6DoDL++SKMAGwPC+HTwSDqi69WgCg1CsEtnLO5
pPhIKzUNZRAVbg/WNpQg6vug8WGehh9LV2lVC1GDQ9QI0VAQbfBsnCvfUttvh+2MGctKZWOiNdszHxMq8u6ho54iw6jy4+mMjcdxTDTCRwSZoChyE1Fj/XAdt2zdaWIl
WARRSpb2Vs+OknwYf6XeWuMQFWh0qVkwSX1MUgMzv2uMh7TAwKqK5wox0r7qIKahVRClHzCtnuLtBTD+Sj35xiFKP2hSiy/5fOw+z4cKTfwvMfIy2gDRny88zuTQoZTi
LSEGO+t3z38s2N7a9Lx/dK4Uosor1/dJWXkEIYoQjWQFVMzrl7tkaZdHPIFq3LmGLVHZNETx0YoQ1eLOFU3q/KVieI5soJTzYKu3RGGTPiN9N9yrenIL74XmzFIhKocP
+wrpziUuVkOWqG+6rfTRihDV4s4VTOqMgnXpwnC7vMlpcedC1ox4BeyA6DvlP2dxWAfR+1/N2xJs6ueeo3Uah0tDrsBg8KXC21EBCxRQ8eoBTkb4InJ9g4jtwQOLRK+g
cYgSTsSnF0NgEg1T4n5XhKiGwCKu1ILPUByR9YXndGoKLIK0DHoRoaJVRRURnPgicn2DiJ0hAovEVRcMQ5RYigmTis9DFDOnD/e7MkQlQWdhAouoowHKReKKxWYmiRHT
FlgEiRmZuYsQDeXO5S1Rfm4oS1gGM38t6AHxEaiAQQXCQzTQDvCFs7ZVL36Bmz4hTmOgU1zYQZRM3hCnuMBTPuAWx1GGKFkQxzcH4/msDJjiohydy5WaDoL6Om5ySnwW
ncIRXh3+CuMQBVs23NPEGGnfhb5wVp9KyVk5GUmBgUWGLVGZvDBbqZDEziq7czkphbYB49kwB4mOqfsWW5CvgEE/aKTfB76qjE/NO8iPhYdTiPu7kdgihCjrwCLtS/1J
gWqwd8PbUQELFFDVLeFF4RSwBKLhMoF/5xQw4lpHiCJE3bOxpQX8wEeojAjFzjmsAgjRsBJZdgFC1JDUelZRMGZuhngi9tGogPMVMPS+4c2CAghR57SFCIPof3mnnMnB
qgJMhWhd5ZFdRSQoaWtp2XGvdJVd5RFW53egmENUgNWrF+XpIESd0wAQoobqwiyI1nkKM/94f0/JRJcBSem5OyowOjeSZ3cgQdGda6i7kdyMEGWlpPF0EKKGNDQHouUf
THuiT8w9iRMysnPIevSLF8yaQhbR/dUzOXtwKzREUUQrYOh9w5vRneu8NoAQNVQnpkC0fO3EuN4PZRZ5ZXanZ/n4X8Q9OLeUbKaG7lwMaIpUBQy9b8Fulmzuwe/4Uax6
B20xzTAbaJu4M6UOTYxbovNLTul4brhbuHm6kkVmYPXEEj1VEWrjblO3aw1XQIW/G1k9yobo3P/vO+VMDh1KKd4SDqKVu5ZnTky8r09M34TEiTOW7w7tj+VT8ywZG9Pv
Nwv2NshgebJw8q/jBszYUo8QjVR+RLQFySrzapb90/x6EoiKU0W7OlqLsxIHJeVUqZ92qfmJdt9gHKKqVizSXEwKUXG9hfbWYtgKTe3uNJqf5owbImyxBSYEhURYiR8S
otW7Foy/V7by36+eXrAzxIagfGoNexYkDejz8Avz1mzbVXb4kOfIob2lhYv/8rv43oMmbziJy/7hsGgkK1B+5iqrt8+XjgyicFqycxb7hzkiRSMuRPF7yISS+EEUnsBt
Wicu0mTCI21P0sj2rmiJhpwnWrFhyj294mJ+NTZz1aat/1iV+QwB6j1TCyvCx9nWeta/OrSffFeBXveOW1BSGepeVrYCpoMKmKeAqtXmtPaL/hClq7wKW49J19bh9+hW
2g3b584N2Aua5EfqzqUGFr9ZNLcJJb+9s7g3uLjFtNaiqLzeyCo5YuXCntIqH6f6skCISrceU9z4WuGkz2ErW4eIX0hI5s7taCnh9waHhYpWVJPlpbjd1nx7g8OyU8X8
DjCqi6HpQiMviw0Q/a/vljM5NGkU4uLwC9CLq8xXFKT3hbcuOXt3XRgncGVxTsZbizbtKMpfkp35Juz9MmP2olWb9pUHd+TiVmhG2jHea6UC6jYP0fiCBkKUrDk3iCzC
p7jxNV20liyKSzfT5vyNIkQV94L2QZTuviLZwJmuHifdI5ou32qm+WXE+hGrW9W2dNqqQgGi3IZ0xNmuuPE1XbSWLIpLReN2wxYwSaWWbMPut2s33XeWspPuxy5eAAtD
kr3B4WupbBa/s7q2kqi82qBfHSGqYu3cuGdmv78N5npueX/u2DiA6PApef8g/yVHwAL0BJ8zMiaPTYjpnfDUK/5bpwFNc4pDjKpa2RXis1AB3QrAntIqeyi1lylAlN/d
k2x3FbjxtXQTEtFmFSGquBe0D6LSXbslG5uQ233r4vptFqa2IOquY7UptwmxRUoQ5Rc3blXa+Po6GUMVvjbEhXkFiHKpCdVHNnXhdhVV3rWb36iA7APKiS+ui+u37as6
iVVfZdCvjhBVAdEQu6H5b4V2qpGEFClvgsa7dp9acgjHRCN5RFA3eNx0I3sDKKgl+mELWfNd9k7BdmM3SCcrBr8I/aXPnau0F7QIUb9tTcW9uOXnTYUoCMiqPbD+oAlh
iXqVNr5uk29szteFD5PUvoTV+bcXl3j4BfrFv/qLLFSB/Ly5EDXoErABov/XuyeYHKq/M8JcGN6dqwmiTXXlh48cKpo/OmbA6OwPSUiR/PCcCOUKZvVeYTqogKkKwP6L
rF5APp2gY6KnrxN/4ExPOxm1FH+UCec3xcVvL2gnQdRgxy2tXBV7uWiqqxBjoheI6xU2V5elp0w4+SQWCLc+UlK8Liuxf3zqhhaJJWo7RA36cqEiEKImLUAPKD1WrmKd
Pz+Em9rxYeKoAEMFGMfoBo/OVd74WrantLAbtgBR5b2gVblzxWk2NLYlwNjVxKMgFxvvuKX1eN87x1Vsk64+3yGicxU3vpa5c7ltPgV/LNmG/Wabd89OYZopV5XSv3Zz
o60PZ3mu0fzJLvCJb6IlCv5wgy8FQtQkiOrcfNRgdeLtqIBlCjA2RkPME1Xc+JqMg1KzRrIbtghRxb2gVQUWWQFRhmYorW6mxmioeaKKG19z5EtIy2/u6Pbthi1Yohx3
+00tuQQxt9xfud8ldmqIwCLxC8YsiDL5mkGIhoToiZ1r8pbkLd18oA6geLJ0zbK8vFWbymqJ+Sj7k05kBnqSLesB8UGogHEFWPbdIVcsUtz4WrLzdnIWnfeiOMVF3Ata
1RQX0yFqMIxFsdbAGGU3Mhp6xSLFja/VTnGJS8zcwFml6qa4mAtRMN/hQ9D4W2ADRP/13RNMDvXuidBXhh8TpdFDDbuzh/eNi7kvfX053FK/e/5jMFYaGFhkbJc04zWK
KaACVipgwjxFVm+2E9NhYvoo1q85qxc5UUNWeTKy1J+0ChCiKqJzEaIYTIsKBFEAvuWZDsix6iGdmA58cIDJaN4nDlDBicV2ZJ5YEdSewCImZigkwqpqwluidJ7olrwp
9/eOi7ln7Oz1MEN0c96rD6IlimhBBeZ4YIQPORq2OwIb1FSCUjYjR8NWBFzAkKA2QXTRiX9lcagRS8014SGqbYqLofFR875SMWVUwDwFgKPo1w3R25gxDhqsNpGjISoC
Ro6NrDWvqLkd7lwWBAUMqwGkmmsQoub1rZhy9CgAZhb7FRjUvMDOvgYMUOaxuGEbFX7TKDYK+JQxwxmAEMUpLrgrGSrATAHovus//drZXLMod6ADc6MnLD6lF4BJyi5k
1yLRzHgMjDXA5x2TQFynWKL/bdEJJgcruUMtJV95qEhxgVxjIbghnqjpJcGLUQFnKgAdFmxREp0OXmAnlN28LltrjcNiArAsRhTSFIoMBTe+lkJYwW2wRJkQFBKxAKIm
zWNBiIZtl3iBaxQAaww6MvCkWXaUlpSIh2UPhTJa77bV1EiA61AXAHjLNLGlIqCAUEwz3LbB1EaIqpjiEjdm2rtL8mDVhcCDX4fBUDCRlKma3gq8GBVABQIVkG7ii/rY
qECUVIQNEP23RSd8x+LWmttqTMrOmn3VshuttEQxOhcncqACkaNAlPTdNtJR5aOjpCIQoios0Z73Jf5+7NinlI5n5m2pbg6zQbeWAVSVrRMvQwVQgWAKREnf7fwGECUV
YQdEc07+m3i81/Bu9cVir99xaf9n/7zhM1C7rrddeff9St9d3O1qDFg114Sf4sJ6bT8cE3X++485jFwFoqTvdn4FRUlF2A1RKVDJ75WjSz7b/4VA0Ns3z529+O6m6v/h
f5lFEG3wbJybMSNjxrJSpuYmQtT57z/mMHIViJK+2/kVFCUVYQNE/385JxWOPO8r+y/WXO/8iTMef7r1z5rac9PXVypfzKWgxspUc004Z6z30Nbls2cWlDWS6KFaT2HW
hN8k9IztM+R3UxZuO0J2d2F5OP/FwByiAg5XIEr6bofXAmQvSioie0slUODWrVshcPMzNShSf40fF//n8sZ3K79s/YFuW//Tje/aDx1reWZ5RQh80j+pf2LoK0NSsHxT
RvLdEFg0fP6uhlON5R9MH9pP0jL6jcjcXoUQjZyQE+f3O5hD4wpESd9tXCizU4iSisgtqgKIhKaMmRBd3HLsR2p88gbo6c++qVE4rm38sMoPqxZAtOFA7pM9Y+N6Dp+4
oKi8qf5Azh/6AFB7/mbaso2Fi14eBn+6Z2oh7JLGjqNmN2tMHxVwvQJR0nc7vx6jpCJ2HqlvOtViKUT/Peek78g7q3aKy/4a2Y1WWKJNJ9e/3D8mtu/4lUcAk437c8YM
jIvpNSi94Dj8l99eNDl7dx1C1PnvM+YwehSIkr7b+RUaJRVxrKrx08/O2wfRxS37vv5n2/WwR8e+ndWWQ7S5atNffhkT2ydx9vbKhpNbMkeA6RnzyLRNFYSa5QXp9/SK
6/mHnAP1CFHnv8+Yw+hRIEr6budXaDRUxO+XHIP+/6uvwqwXzdid+++5J5kcFrhzeVJKFlvo8+jM7dV1B5a/PHRAL2gifYbPLanFwCJmy5c7v1/AHDpfgWjou51fC1ES
WESjim7c+NFSS/S/555kclgB0aamitJ3n72vL30t+9w3YUEpSFa3KzuZnIlPmU/+ixBFiKICDlJAClH83SEKRAT1dWQSfLnNpz8OCyPGlmgwgg5c0/DmnnPrq+jCCxfW
H/r4zU01A4MTN2y+VV4QnoLeE/tKi7Zs3XmgsoG7uLG8tGD5+g/3nqD/ZXnoqEW8BRVABaQKOAQbmA3XuwToDNGwvlwgkekQvXvD2b0Xb0iWKPKF69747tu9+xvuVkKp
SkaGvYwtBQ2mhr0hKoAKGFQA6eVABQzWqTNvh7jcxuYzt2/T+ZmhfsyF6N1bL34RZg362194TwVyNFy21f7dIPbY3u7MtoK5QgUiSAEHIgSzFEHtR2VW6Wjo1S+vqSEN
Y4j+j9yTvuO9xo1XKUK7rl/9ar/3/KoDZxfth+OTVScv7v+k4zr94+3vNm6olN2Ya81iCyxdtWpwq7L+8DJUABUIpgASy4EKuKy5QlBuTV3zmY8/UUNQ9u5cGQvXfd5K
1lr46ZtPzj7xngSuPGgrnth77RuOoq3H6xCiLmuIWBxUABVQVMD1o4kRXe/xfz9cdqKhoel02KBcEbFmWqKbLraR53TW7K/xYyT/3yV0NYaf2rxNCNGIbnmYeVQAFVCp
AEJUpVDWX0YJCm7F69e/VWmGsrdE/9d7J33H6k9Pc4OyN9q+SFsqOc9fU5V2sp0LOLp9+kit7Mb30J3roEkF1jdlfCIq4GIFEKLOrNxHFx3VQVCTIfpe7ZIv+MXvO2/8
cPqza/trL5aQ49L+j785/fWtTsr6W98sWVuBEHVmw8JcoQKoAFsFEKJs9WSS2qvrT8A4KHhxNdmglGCM3bl+LIwpOFfzfcgQ4ds/1hyqi5Har9zv6k3p0Feqifex7Bom
lY2JoAKoQEQrgBB1VPVBGBGZzdJ06lTLWfXjoFLumAtRwGHMyqaVzde/uBGA0tu3vviibeXWmkCCIkQd1cgwM6gAKsBQAYQoQzGNJAXWJ8UnGKAqZ7Mo2myMIfof750M
clQmbmj6696zOQfg+PivW+sSlwa7kpxHS9RI48B7UQFUwLEKIERtrBoIHQJ2rtpZA0v6UXxebruiZkWFEEhiDNE736tgcrgSorC/Kx6oACoQ5QpIIRrlUlhZfDA6adwQ
Pc6e+xyGPw3i05QxURlBl37iDbNcEc1Dp/eA1w+9roSoZYOv+CBUABVwrAJSiDo2k+7LGOytffbcZ+C2/e6775iw06x5ojHvVfgOLRCV3fheBSuIYjqoACqACjhKASlE
HZUxzIw+BRi7c2UsXNKy/+sbbd+GPTr274LwIgl9EaL6KhPvQgVQAccrgBB1fBVpy6CZEJVz0Q+Tof+rrRB4NSqACqACEaIAQjRCKkptNhlDtOfiCiaH2uzjdagAKoAK
RJQCCNGIqq7wmTUToktb9n8DvtwfGsobtZI1fMbxClQAFUAFIlABhGgEVlqoLJsJ0WWfeMkSCz+11TYjRF3WbrA4qAAqoE8BhKg+3Rx7lxUQ7Wj7EtbLDX5cyNlc7UdZ
x+qFGUMFUAFUwIgCCFEj6jnwXsYQjVtc6Tt4SzRsqWGeaK3sxsWVYe/BC1ABVAAViEQFEKKRWGsh8owQdVmFYnFQAVTA0QogRB1dPdozZwFEf/r2swu5Bz4Jfpx9vaAa
LVHtdYd3oAKoQOQpgBCNvDoLmWPGEO2dV+k7lguBRXXNsvPSa4L87jKVsTioACqAClAFEKIuawlmQnTZ6U2ffuP9/OsDZQ2hILqkZuiqKr8LXKYyFgcVQAVQAYSoK9uA
mRANaXH2Xd2YWXb+o9b2CzduestqEaKubF5YKFQAFfBTAC1RlzUJxhD9v/MqQx7Voz5sXV191Xvlxxs+ITsBon53uUxlLA4qgAqgAmiJurINWAHRu1bX/2Xf56Ut3164
QRZf8PvpvNFRWlLjZoje/r775tXu7xvwQAVQAZsV+OEMeRlt/UFL1Fb52T/cTIguqf9bxZXKthvfK6CTK8kPXy3bXPsrJeOVfUGtTxHY+V1197Ut3VdW44EKoALOUuD6
oe4fL1jfK8ATEaK2yG7eQ82EKB+dSzN/+9tvvmtovbK9/NMFO1o2Xeok57699FIQ9695BbYiZcBne7mzugwEOSqACgQq8FVJd+d1K/oEyTMQohYLbvbjGEP0rrxK37H8
k1qJDdr5448Xrlwvb774vudcqQDRdOn1kt/NLraJ6d841331fSQoKoAKRIwC8M5a+IMQtVBsKx5lJkSX1L91/NLhzzu+uvWTclF+bC8ta0lfVy1DL4dSK4puxjPgbcTv
fVQAFYg4BSzkKELUjK7XxjTNhKhoWS6p+dOOT96v+7Lx2k1JUK5Y6luV+7x+HLVREf2PRoJGXNeJGUYFRAWs8usiRPX3sY68kzFE+y+pDH0krG+aefD8nrMwPVR09XbW
Hqz1u8uRWoXMFIyDohcXe2RUIHIVgPFRS34QopbIbN1DrIaoBJbVyVtalldB+O53h/dFPkQxkihye0/MOSpAFbDEqYsQtY5vljzJRoiGslktKTu7h/x0C4dCUQFUIOIV
sMQYRYiy63kdkRJriC6t6q9w1CT/4/S8g2czCmu4v9ZO2vPJvJKm5JWKF5OTjtBGfSZgBjd+y6MCqIALFIBxGZN/EKImC2x18owhOnBplfyoHrPrYu3121x4Lox91nF/
PbXjW3Lip1v/rKpsGb3M7xbyX6tlMPg8mLjtgu4Di4AKoALwQWzyD0LUZIGtTt5ciD5U2nb5tlgkf4hyf+i63NjykD96Iw2iwZYluvyut+APaXfFktfmrmG527I7oJM6
+3oWPSMed43xnF1FMMz/6aGCk8t5Kl+eV5DYW3LxkKyCeWES8fWDy9sOTM5NGcDdPiRraWbb5TBrJ3WdTB0T03vM4nldNBHu6fFTX29n0Leu6jg5jc/M8DElJ/P4ApIi
x2cV5Rr6CvElsqqjPI0InjihetuYeFHYkPnnSh2Yh1XtRWPiQbrE1FZRN746JBKpTFlbMZe3Ln4oLsbXDILkMFht0pxLWhGD6tOx6pYgIN/OVbVA1c0g1zM1XkfLDK8k
fBCb/IMQNVlgq5M3E6LLmj/8mobgdn177dvyUxcXb/Vylmj9zJNXyr/4/lv6x5++//AfNX4mrNUyGHyecie1/FJBIumFfUdC7oHFwSEqdjr+GJMRN2bApIK3u0KQWMhM
V/3kSTJa906am0kAHPzguhjgvQB1dhD1z8zw33sauQ8FbXQJknlfIqRvJXIxhKiURrzs1kA0VoRE+K5fVqfOhCi8COFboP0QNX9YFCFqsLt12u2MIXr30irf8f75s8Rr
29XWeAZsTdmfuP8+VNTWRi64ffZEo99fnSZTmPwoYkmwWjh08UCVd4vQrUjNBWp/cNAVrR/BEuVuzGtZPEJqG/HMU7Y5hNRIUgLOw1lmQoICJJhBlGZmyKyid7quUGNR
eAQTiPr012OghLFEfaa50ldO+I8SHXa22BL45hHJEBWKf25eydQh8gavw7o1eosqJU3ufRCiJgtsdfJmQnTr5SukOJ1Nh+sDCUrOrPm0iRijP12pO+VCiPJWC2c4il3t
Z0s6ON+gAv8oL+96IO0ZcMAKcJVBVOzEpX2rH4nFXgZ8ua+VFEzeeeBdeHpI3Po6Ju6yB96Zm8g7QuUQ7WrM3ED6QYlr+grX3Sc+59n2+yTOacxhMqCn84cxvYtzk0oh
evnd6uxh5Cth+JNFi5P4PPCdL5wUnMCBZ/hE5vJmqL8lKnqSeydNndx6jvOcX1netvc54vgFN3tuclJQd+7gtJTBwjcNR+hnhk0QvwCu5LVuS+Hc9YKbPVjKsm8F4dEg
1/oJMxS82VSfJ3On8B5LedcPNfti1nDi5I9PSTkoOsZ9sgexRGFwYSmUFHI7IG3uNKoDl/JD64tenUUS7J00fbrg889rLRhDLr5rRMFHr/hc7ueyD86ldcRXB20zuetB
TD8HMs2G+A0h/a9ijcDJybRcccMTs1IGcB+OnBTCx59EB/FriWr1dFHuiHjSolTXSIivH5M7YYSoyQJbnbyZEOUt0e5b1y7/Nb/an6PL6v7a8P0tUl6XWqJXBNci9E1T
J5QUcQOioq+VOk79x73ABh1fkgtGm9D1iBBN+UNRwSsFPMN4d6tKNHaLJizfGdGMKfgkaZdaUD6zILEvGRmVws9/dJbmkOvCHhmcJPqNFY1dghDp4yS9vI8ui71zEwKG
ipf6rHPSt6Z4zwWeWSWQOAhEz2Xm0q6ZHNSjuKrjQAqHE/EINib60PqC8WNooYgCfcfMenoGXxa/RDhffbCUpaO24R/Nf2S0lHPVcXK5FKJCpQs5VxBcEaISPwdXauoU
oSknDe8rSEF1kBeN1C89L68jUh2rJCmEhih1h3DXKNTIavlJMYfqIEpbYOIE715ptYasEYSo1axx7fMYQ/TepVWSo2EdXWie+HRvXbj09ZHGyzvr4Gg78qlkxaLb7esK
quU3RlpgUbAXUrSZaGctCagJ4B9vZcZPnX6Bi2fhHb/+6PJ1f8rmrEJOlrcVUTNRHGMLB9GTS4kNAb1z61whsIhmTzA0z80pkBoK/HnaSyp4L0P50ES6cKDlLSEufc7+
4JDJ2azcqCokvjDgTK7EnBUNFC7DJIUV3C+JJfUwBCueXEQ+I/hxWeokDwpR7pNiECCE/8LY+2fhg4B71p8mXyKuBfG5nLaBKfuN2oZ5tGip88l+6wt9kqZPHePBcy6G
p/Fjz6KhyRWZoy8NJaOy03FrruHRpxBGwneSr1pJKQTPilAiaQryEU3aZsDqTS8Rv/9IVdJa8KsRrppiKPakOVEHUb4FaqkRhKhroWZ1wUyFaNUv/3H+9I0gq8/zJb11
+njTL2XoJRi2WgaDzws9MNb41s71QoyuMNgZAFEf2Dql0T3CwOrjwwfRGKX4lLQW3iGpxknrI6jQJ4YNLOJsBWp15U5az0fnyvoy3gAVIRfobZPEPZFOWYUl6uex9Dnx
wAm5PLVg/RuCGxZihgPOyBHFYUDkpdxypdb/ceCiL+o45JgoqLGQCwTlPm6g+loFqzrw+wb+elEWz+xLWcyhn4dcOTDY5+7m3a1gDVPM+znGlQetFSxRvzKK/5WdF1ML
kkl/I5hzZnDNVXHcV/Dfbsss+RMJEY9Pea6aRJP528ScP2ax1G0rKaY6iPpcBdJQdi62IFiNIEQNdnp4u6CAuRAFHP4i/0xhS7vSRi63v7r8ZWFJ3S8CCOoSiJ7L9hRM
Linge38/avpDNDDaljq+xDkVHM/i+O93HoTh3LkSG5Tvv9RMcaFOOa4HHD40bTiFjTGIKo6J0o5PZtCIfbH4uMWtRa9yw7ow1jU+azqMaAae8SUisQgZQpSzy8URSvGD
wBKIciUalJQylB+1jUSIghEPNu7d1PQko9EyFz0/qIEQRShFqgKmQ5T30y7z/nHrmfkHz+WR45P5Jc1/XOPvwpV6dCNMTsWvWllgkX98bBCmSkfpuEFE38TEue3cWJrg
PwwSneTLiZSgPuM19BQC3mNJ3YAKMU1B3LkKcR9+tJZG567uapwOYSy8v9rPnUsn4Vx+m9gugqXLG9/8lcSdKz+j3p3LDekRZ0AQd2WwiSJ8VXKM91nVEuchGeTjRpFD
OULpJ4KaR0sCr3xBYdLb6QQhVu5c2QC8xJ1LnyJxd/vcuXTQ1H+8Vsmdy4+dE58w7x+WunPFGpGNF0gcy7TlUDev1PEuDyySDPbzL0jYGkFLNMI6WedmlzFEf7Gsisnh
XMEUc6a8f0tApIxknpwcovy3uTABRjLNn3NG8UFAFC0wyLR4Do1RCmmJimFNUjBTKzPsmChvMdB5rkFGZyWBReEhyo9ySdaXEOwS5cCi3sR9TQftZLNdyUMDz4QcE10l
j1gJHTgjZb/EKcp/T3Dq+SAqj77hRQgSkhMssMgXsyN9tAyi/CeF4DJVHVjkV++cqSeJpZIGFvGLXfjMXFkp4ocPfpx/uqxJK6Sg8BUiEhpab7ww5i0N9RLnwEhO3jUo
6RH+M0tWXp9cihDVUiMI0QjrZJ2bXTMhuupcnbjdWSgFOusO1fmh17mCKebsmz3KFh54dBfTSQXcVIqCt8Q1g2T84/toycASb/rwo3dCJK3YR/AWockQ5QMmfXNbg01x
UQFRYjaFXbFIiMOKT0mtLEgW1hsSTWpxyZuAM6HGRCE0Rny07/sDzBrlKRzKE0X85uSIkcbChAqYB1IurMGkmLJsikvYR8shysfK+nzd6qa4BHw8BZ3iEmiJklk0s6aM
mECmACUWbXvON+opTHERx+aDR435TXGhH1ID0rLfbLusWCPgongzjyywNWTWtmnCYDx8WwjTo2UzghQhSi7mJx2FrZFgEIV32eQfnOJissBWJ88YooOWVfmOVedq1UG0
9lCd7MZlkRZY9F216pVWjM4WxwehAuYrwFGcDyH2eW7Nf67wdjBb5UP76wZ7Gpr8gxA1WWCrk2cM0cHLqnzHytaD39y48m3Yo+PgnlrZjREH0ZtXretfQkYCYzZQASYK
+C/TGG6tKyYP9SViI0TN31IUIWo15Ux+HmOI/nJ5NZPD5FKbkHywNeiReahARCrgWxdJOr+ZMSyDKWMjRGFvYJN/EKImC2x18ghRRop/32BR/xKRPbJ2rxoWExWwXgHz
fbnQ3SBEGfW5TknGTIiuaMg8eG7JoXN/31bHmad1U/aS/y7e0ZAQzmB1ijzq8wEfsMoxusgPVAAViAQF4P01f0duhKj6PjVSrmQM0V8tr/Ydq2l07k9X6k9zJ0/v5Pbi
7vz83DDpZUq/R4p8snz+eAGNUVQAFYhUBcwfDaXdBVqiEdm9B880QpRphWKYrvUuOHwiKmBcAXhzrfpBiFqltEXPQYiyFho5arxHwxRQASsVsMoGRUuUdW/riPQYQ/S+
5dW+g3fndnf+eJOb6HLze27a6E+3bl2VzXv5/uDeOtmNy637KjSlEsCvi+OjVnaC+CxUQJ8CsLRC53VTOoHgiaIlarHgZj/OCoiGKwOsWFTvKohyXwrdEK+L8170dW14
FypgqgLwjQuBuDC9244fhKgdqpv4TISoieKSpOE7F5xFAFR4aeGzF48IVODsyWzxwBqMYAXgNfzhjF3sFDsahKjJfa7VyTOG6P3Lq5kcVsuAz0MF0P+GbcASBRCilshs
3UNYQ3RFzf0sDusEwCehAuEUwF4vnEL4dw0KYHPSIFYkXIoQjYRawjzaqgD2erbK77aHY3NyWY2aCdE1n6rdCs3T4Ge/ukxlLE5EK4C9XkRXn9Myj83JaTViMD+MIfrA
ihrfsebTenVbodV7GmQ3rqgxWCq8HRVgqAD2egzFxKSwObmsDZgJ0dVnD31zA6aEhju+P7SvHiHqsoblpuJgr+em2rS9LNicbK8CthlgDdGVNQ+wONgWElNDBYwogL2e
EfXwXj8FsDm5rEkwhuhDK2sUjlV1Ez6oe0T4U+KmluUVl3Y3XN5Wfva1fK/iLS5TGYsT0QpgrxfR1ee0zGNzclqNGMyPyRBd1Zhde/3KrZ86z3+aSCDqTdl/9eItspcL
/fnpx46PPmoI5KjBUuHtqABDBbDXYygmJoXNyWVtwFSI1k6r/b6TE4yHaMGn9Tf9Bfzp+2vZ6/ztV5epHM3FkXYZ+LtDFIjmBml72RGitlcB2wyYCdE1n5zkkNn5Q0f5
0VPDV9ZOrv2eGqE3rn35/uEvPrp8k/vvrZqyej9jlG0hMTUbFXAINjAb2Hfb+BZIH40V4ZCKYJUNxhB9ZKXXd2xv4xZ4/tGzs56cXHWm5Gu6jcsPu4tgiNT7yPvnW7hd
u682tMhuXOllVTxMx3YFkF4OVMD2VhHNGUCIuqz2LYDozYp9DcDI3+65dp0Tr+vqhec51g7bfPFzYooiRF3WqGTFcSBCMEtubnCOLxtC1PFVpC2DZkJ0zScVnDv3p1s3
Pv6i4yofT3S7pbz5kdWnVzR+1dJB12IAdy6hrPTQVgi82sEKYJfhkMrBisCKcIgCLssGY4gOXeWVHPV/bfiBBhaJPz999+Wcdd6haz8TFzOCwKK/wxnZjejOdU8zw77b
IXWJFYEV4RAFXJYNUyHqHbq66e/1337F26A/3fj2m8KiesJLHqKSMwhRl7UsoTjYdzukYrEisCIcooDLsmEyRCkaV9enbj89fWtDkkjK1U2zPefmFzX6ziBEXdayEKIO
q1CEqEMqBCvCIRXBKhuWQFQOSD/PreJ/WRUP07FdAewybK8CmgGsCKwIhyjgsmwwhuijq7wKx+r6FzbVDxf+9Nt/fLyy4tJHDZc/LP/kLwW1irewUrmx6ZRzju9/+CEK
D2nfHYXFd06RsSIcUhdYEXZVBCus+KVjMkRhTJRf9u+z3xKI1j63/0u/Zf/27GkI5Cir0jqHoFGbE2mXEbUiOKHgWBFOqAXIA1aEjRXRdOrM2U8+u/rlNQA5K8qYCtG6
133L/nEQff8zxWX/IDrXj6OsimdjbQU+et3B1ig8pF1GFBbfOUXGinBIXWBF2FIRhZ7WkvKP91W0nKg9TTvnpuYzl9uu3Lp1yyBuGEN0xCqv7xDmiXb+s+PEsdNJq2qn
1v4gLvu34cgXe4Vl/7wHG2Q3rmI2xcVREH179ydReEi7jCgsvnOKjBXhkLrAirC9InL2fPKPIx8frTlDAXHx4qXbt+miBXp+WEN0de0I8Si6Qpf9O7yrgTt5pvQbuuzf
P/cU15MzG774mC7719jiu4u7XU9RlO5BiNreXrHLsL0KaAawIrAiHKKAc7KxZN/ZQ1UEpeDm/e677/RxxwKI3qw40AhcHLPXt+xfKkfKx7Zc4pf9Q4i610jFvtshXQZW
BFaEQxRwWjbAvVxVT3y84N3VwVEzIbr2nOKyfx+fODVi7ZmVTV99LCz75z1IKCs9dJRE8Ra0RG1vr9h3214FaIk6pAqwIhxVEdLMgIOXmqTg2tVKH8YQfXx1reRoeKtR
Ydm/eetrH1/3WYPggv7ph2sL4IzsRnTnRvbo6YvzC+cVN4foMuCvry3d5dg3yjUZm7xom1gWxa+ZvxaWv7GmzDXljYiC4GelY6sJwo502KOmQhTQ2LSgoV267N/G4gbC
Sx6iZNk//gxC1EUeXQDk0OTx0EErDsVBz373L+6nf8XDVAXga+aJP7w8a4tXsSLgr1AR9K94WKYAQtQyqXU8iNqj169/q94eZQzRx2CkU+FoeGn7mde3NSaLf1rTPPfw
p28XNfnOyO9SX4DQV6I7V0czYnIL9M7QWYyd8jdplwG99n3Dfgtn4F8mT8FEQisAFj/VP1hFJKdmoIYWK4AQtVhwTY8Dvy7MgYHZL+qnvjCG6BNrarUf9X94v87vLoSo
pop34MV+vba044DfgaYOzLMrswSY9BNf+l+pv9eVxXdgoRCiDqwUaZZWHjgL1tdnn3+hEkO2QTSx8PTbRy6Wnfvu0o+3Go40IkQd3rC0Zg+8tSH6bnQhatVT9/WAyWAV
Ad4Ccehad/p4o1YFEKJaFbP+eliWATiqclUjiyFaP3HHuQ111xq+/PFHH+U7EaLWtxILnkg9t4EHjNJZ8HR8hKgAda0HHuAtQJWsVwAhar3mWp8ITt3ahlOwQKAaY9QK
iCYWnppz6MKe1vZLP9IFi2Q/nT9+v+ejBrREtVaz86+fMHOlYt+NLkSL6y6Yax0DpC2uCPo4hKgtsmt9KDVGb9yQmHtBiMoYoiPX1PqOtadya770Xr3xfbAFlf75TX5x
05PSW4Tf1fBfzTUYWKS16TC8Hny2ihBFFyJDkdUkBZNYAisCY7vUSGfGNQhRM1RlniYsZqRyuouZEF3vmwza3d3Vfr3j1Lkvd1WeX7b3k6K22wSB7VdmKBEUMKwGkGqu
QYgyb1uaEoSJLn7dN7oQNQnI6uJA13rK6zmsEsd0NCmAENUkl40Xw3SX5tMfhwWNZRDt7vzx5qWr31aeadty7PO9kQHRhuOl62akTxo1dqL8mDStsFwHnm1sDXY9OjCq
BV2IttQFINPvawbn6dpSEejOtUt2Hc+FRerVeHQZQ/Q3a2p9x9rmdyqvlH/x/de3FIZCCd5//G7vkbNvflAvu4tLISz8VV6gA3XiLfUHliX1fqBHbODx2NgVR3SkrKMW
I/0WcZ4i7cEhwiXSSxSh+fdzrYOHIEIL4oJsoyUaKZVIPbqw+Who3JgJUR9QG17b+9nWxq9Of3VTaZT2Vu2hRj+OqmRk2Mt0oE64pfFQXnqP2GembThaw22XY/yIlKbD
Np/SeYroQmSrrabUpK51nKerSTq2FyNE2eppamqwMH3YCaOsIbq27jchj6c2tbxz9NJBMj1UNE87G482+d0Vlo4qLzBAvqaThW/2jE3JKvUaSESGXlMr27GJg/9W7DXQ
hWhjNQE4xYrAebo2VgRC1EbxtT4ahkVPhRsWtRqiElg2pJZ8UuD9svbq9+UeB0K0uXrvmolDh90x5LkJ02ZNy5gtOeYtLKrUQVat9eea6+k8RQwHtbdCRdc6LvVnb0Ug
RO3VX9PT6UQXS925o9bWMTlUGpphL9OBOrk7V3FMdPioPI+OlDVVnpsupvMU0YVoe51S1zrO07W3IhCi9uqv6elqYosYW6K/XVun4djy+ZEvvm384uvijxr97gpLR5UX
6ECd7xZvpcdz9JDCcbzc26QjZU2V56aL6RKA6EK0vU7p/jk4T9feikCI2qu/pqfDft1h1/+zFaIlV74kMCRjok6EKItgIilrNVWeyy7G6aEOqVCM7bK9IhCitleB+gzY
ANHktXUaDglE/e5SaWiGvUyHvdjY4Fk7c870nNKDRSumy4ZCxWFRl4yJbiy/8GHVJfcdefs/Vf+S4JWogMUKIEQtFtzI42yHaOOU4pa/lgQ/PF99LViiDoJoffG0gQ/0
GLtsM5ni4p4x0TWHz5c1fdl4/ttr34VfDTLs10lEXAAlhfLuqm1zJlYhV/AFA5VSfe4bFx9QQCimM6vASPeq+16EqG7prL/Rbojmf94YbNVc+RL04M51EESbGiuOHfOc
qGtwxZgodF7Qi13//lZEYM+8TH5x7Qfoyq1/CQOfCFAHtH/dcdO8wjoz5Y4bnVBwh9SCjS0BIWqj+FofjRDt1uPO5YdCm44X/m20/4J/dP2/yFj2D/AJ9k1nV5DlopzZ
0ZqcqyvXb4ATW+uLxOR6Wh0AEpOLGAHJgwjwYcdE1UhMBCEaQbVmA0THrKvzHfmtJZ9D8G3Y4+uSPY2yG9fVseoJjEH0rSEDH1Tw6Pb63UuOXzsXzJ3O24hP5XYEMLPy
Nab4vNmpyi3DquU7Px2wxe36oLGy9gOfhRC1V39NT7cbolKgavydVRdgAKKnvKULft1rVErOziPihJb6ih05f+4Zmzwx/7iOlDVVnu6Locv+pK2DlYBuTQck0q2wphuB
E2h9hmhFUWiSIkQ1vUH2XuwciDa8VNSad/Szv2+t5yzOxqyyz/L2nHmpQGK2yinLqu/WgTr5YgsvLCxrkCXiWTkq9oE7M4rrtE+AsaA1AEG/ib7BNn2txQKOAiH05S2q
7oo2jiJELegJWT3CBoj+bl2d/KiftP9y07fc7qHdnU1Hm7i/fry/nfM03rpR5z2b7n8LSYFVJ2IAoqe8Rdn3xg4b8lLumq1795MlFzw7t29aNOWPP48dPjKnrMF5EAWC
YgCRppZjKkeRoOrrIqo4ihBlRTgL0rEfoil7rl6hAFWEKDnZdeXUJykBHFX/+oW+0ghEG5sqixdMHtjLb5bL0IHPLt1R06wjZbOrHAJQWekWPemY1H3DmHT0aMikpNET
tYsQNbsnZJi+7RBt2f0NDaboav+qvbqlbV1pA2eJNi+q/rL64g/t9I8//bC7qN7PhGXyWkIiOlAnv6WxomzH2rxFGWTVhblZC9asLTpard0GpWkyrNrApI63fMVKtKhK
B8KvmE9hhCm5GEaktRXByDHzijD1jdOdOEJUt3TW32g3RLdc/JR4bbuunjr7RyWf7R93Xb3KXfBp1WmnQrTuyO6dm7cWy4/SncfqdeDZvBYAvQ/G4mrttcXrmTt1L39z
Q3dmovlGi6OmzXsfQ6eMELVLeR3PtQGiv19X7ztKr3JhFbfPlJ+SnRev2fDFGWKM/vRlU6vfBay6Eh2o891Sd3jNlHF3KCxa5LhdXD6+/B0rxaIzHbAddbxgireAWzI6
NTReajDfo8EYRYiyetcsSMcOiK6v/7148JZod+dXVxdubvCd5y84tfDUD9zM865Pq8/4/dX4C0lTMADRphP5f/lvscN+NTF7Yd7KXNmxtmCvnp26TapyYobiigrGWgx8
hbCqHTRDjVRFNBijCFFW75oF6dgN0fVnNrcJYUVdnZfbrp88fXV/Exxfnvy84/KPwlIAt7/bvMUfsUbeQ+m9BiDaeIisnZue62k0kAgZChUPk6oco0CNtxZwhjOpHbBo
jWcmmlMAY5RJRTg5EYSok2vHL282QPSp9fXSY1zxxVYRlsp9w63WypZx8rsgBVb9iBH+cVNcRo3P21tRL2Oh7jRNajoXv/4nK7miOR2IpzVeQRjeZbwJMakI41VpXgoI
UfO0ZZ6y/RAFHI7d/MmHZzu+uRW4BN3tb6589eGeU2MDCOoQiDY2Hsp9+jGljVweG7viiA6UMq9gmqDxbgtTAAWYeHTRl2u8LcEi9Sa9KQ5JFiHqkIpQkw1HQFQwTJte
Kz279Oj59cfg+HzpnpbXNjb4ma3S/xp/FQ2PidJl/x7oMXDM4/7L0DtoAXoMY2HVVP5587aalyr0NawyE83pwJq6xivCySkgRJ1cO45z54bAZOg/sepEdNiL8mX/UrJK
9cQQKT7XjKaDA6KsmgqkYzA0FJbJZZiZaE7KjDfFOWkiRJ1TF2FzYoMlCr7ZMEf+6YVHz+cf+2zhtoYQV7LqQQxAtLlq01t9Yp0OUYhmZKWVcjodrQdzXoiPiSVvfr8X
cstadaxt3+nNGXxvjhdCsbvavDv2eNtgK80Ob87Iwdw55/wYXDTHfK/AhZLUQZIuOCEtp5gTU8uPrwq03GXttQYrImzPaO8FCFF79df0dEdC9P3zTWRuaGfTsWZnQ7Sp
YvvCxLsfvGPIcxOmzZpGViwSj3kLiyp14FlT5am82GSIXvfmPBmXOM9DeuqbbZ55STFP5nqv6+9RO725947M9eoAsf5nqr/T4BKA5i/1x0E0tZhfUbCjpSQzOS4xz9uh
ZZM1Z1cBrSyDFaHy3bHrMoSoXcrreC5C1Mg8UTrFxW/hXPpfBy228PmXZq6X29VSkDxoTH4L30mT//Y3ZD46uwc3OEnR5A8agIsconCioyo3UVJBar4XnF0FtAQGK0JH
X2nlLQhRK9U2+CwbIPr0+vowx/vnmzlLtPlYc4gr1fQGaq7RYS/6bvFWesjmLYHH8XJxh1Et6+garE7F280NB+WoGZ/paee1bm/17NjpbYMK7Gqr2gBmEHHzJmflZCTF
TClp6yRu25jkGZnPc+7f/kmZxa2ckcS7cy8Up1G3cEzs4BxPpejO7WqrXsx7jONT8w62ck/znfSlo6bGjVxjsO+2AaLdN1rzU+KS81u5KhFkFBW72Va1Iq2fxBXfJqmC
t3MW3JuQljk1iVQH+NXbW4tnwu/Ub59XBbUsSZzI6vdfI0qHuddgRZjxojFMEyHKUEyzk0KIGrFExbmhjRWefdvI8rmlxftO1mihph/CzahvcyHKu3ChU15H2cn/dJ0v
SU+IT93Q0tHV1VY2K7F/nA+i/ZNmlsGl3HneSPKNifrMIHFMtKvdMzO+X3pBC7CT8x4TJNy8VDx1cOqKanAjdzQXpD6clFNlgQvYYN9tB0Q724qncOL/oKBYuyerX0Ja
fnNHd1eHNy8pJqWg9QZ80fAedfJLrOCrp7VA2dnekp8ez13c1Zo/ht5FPmvkbgkTGYqWKJm6hocTFHAkRNc3TS9pmV3aMn1jg9Mt0aZTtZ5NGeOSJcvnPnjnE6+/U6pn
QNSkXVxMhijpOztaj5TkZ3I2SnJWIellu4lBI/StsEUP9L8+iIrnCSbpAF5IiHIY6DfTw+3pA1EvO4uPtLafLkgekeW5xnXUXPo0LsnknwiEKKctiH+xWUExYvo/zMtI
4ol2eMDKl0G0v+CrJ45in8tB9NuTX/iKkAHV2RXhhM43RB7QEnV4BUmz50yIhvP3cg5hVi+pIXdu+ZZXhw7rMfCZlIx3ueVzV8yfnTEqYWiPu19euLdWR8pmNB3zISpW
BXX3kW73Ju2423is8f04784Vz6uEKAzsga2ZQEJ/txeXeLjoX2JC8Y5fvsdBiJJ6CBgT7RYs0Zb9SopRmxKCeDeXwKcJjT+SQXRQWjE3LYecFH4n/xfrjrhwObha58uF
xxv8mjHjRWOYJkKUoZhmJ2UDRJ/Jb2ByOACiTcfWTP157NMZRTUyXh5dN673Q7+Yvateu1/XjPo2F6IdrZ5iOiOF/vA96ekqphDlzE1i7xavy0rsT7zEl8qy+gkmFKum
oCIdg323He5cgW3X4bMjiGKkErcXwAA29Zlrg2g3MUCJn+CqJ3OEL8RMhZhGLjFYEWa8aAzTRIgyFNPspOyGaCGNIfrpy+azHFnPlrWTxf9uXzj/PGXtDrpXGgQZnfJD
r5E3UHqvDntRvtjChPl75VuHVm1+qd8Dd2YU1zkDouZ23MQilBooQpd9MYQ7V6slerPNu0cccOV8hiNzq6olUcER4841f+GL4NG5sgFLXrHqC96dO4ShbNFDqwhRzsZV
cOeSzxvOo7v9g6x+oqOe1dsZNB2EqNlswPRVKmAHRAsanxGPDV/4IEpOihD94nl6zU5+w9Hm46d9d3F/YvWaGoDoqfq9ix/tBVuhvbNy6979JEb3yEelm3OmPx8TO/ql
wpM6UlZZbZouMxei3dc8mQ+LsScdrcVZNFYoVGCRVohyYO43teQS2Luc+5H83gFhMny0UeQEFlm02ILyPFESiuWnWDv5IkmYVHwewrw6Wjak9eN+V4aocmCRz/0AI+I0
BtiSH4Sopk4ALzZPAYSowejc+oPrM4fA8rmy2aIjR8/fWaHdDDUpsMj0Cf5+KxbBCjlcT9rVdiIPBjJJtBGdJiFOcdEKUencDAgWzdxAn+CbsAFDevv58TyTe3CD+4eY
vw9ayBWLFBSTTHERg8KUIQrKBk5x4eXm3ANiCJLJdcAljysWmUcFTFmTAjZA9A8Fjb5DsES/+eSLOTtb5+z8ouJ7zp17pS2b/Ld1zpGvuTXrboMlKrvRGZYoZ2s2VXt2
rs1blEGWK5qb9U7+xr0VOhy51GzVVHkqL8b1Whl26sb7btgOk2F+HJKUlXG5tMjGK0Ll62PLZTgmaovs+h7qEIiG7QqcCdHqjwqXZ6SnP/7ICGKJ9kp6eOyrU7LXbzsq
HyLVYpLqq8Wwd8GG0mElxgvUKBBW6rAXmBvnpaYM7K+xNC6XZj+szhF9AUI0gqoPIarXnVt3eM2Ucdz00AfvfGT8KNgK7amn+1O/7t0vzXXSPFFojl9cM3PlP/adskNT
/PaHW8bfbRduyq1jZUFjNYxboRlvh5gCKwVsgGhKQaPvKDy383x784Wwxzc7952S3WizO7fhYN7LP4+FkKL3Nh6o8jlvveXFq+fAkvQ9fj1nc3WzQwKLoK2YHxRqrFOM
kLuZ7AVt/rBohKhpIJvujiqCFxYtUVaEsyAduyEqBarG3w28g7JbdaCusXH//KRhPfq+tvJ4Y8Dt3uLZKT1iR71UWKEjZZOqHHbBZCVXNKcDo8tMKggMqWiW0XjZ4UOE
SUU4NhGEqGOrJjBjCFFd7tz64mkDH+gxduUhpfHOuq2z73TSLi601j9ps2BlWePdo3NT+OHH26xebHQMGKlmGFRmVRGOTQch6tiqcTZEN5yee+D81tqrZc1Xy5rath75
dO6WZj8XrvS/Rt5D6b067MXGCIQoehENNhi2G1h23DB/nV+DBXbq7e6Oy6V9NEIUIRrq/Rv/fqP/8cHH65rbv7wVGEF6+8sLV9eVNivc8r6tiy1QiA6Z+JJsI25+R+7X
Jj79c+dZomiMGoHC9e8ZhBRJ+wU0RvVVB2yOG0Hdq+6sIkR1S2f9jTa4c8e/3yA7PmgtuXIr1Bv143clu4Cj8rveb9D3Egbepd8SVd6O23GbcoutCoxRnOuir9mwGg2V
vuFunOuiT121d8EUWxjdt76XtP6JCFHrNdf9RFsgKrVEm+c1/MA7tm79+PEnX+6qulB4/IvC8ou7Tn/z8Xe36evV+c2VeYX+9qvaNy/cdXog2tRYceyY0l7c4u7cDtqU
Gw2gcE0gzN/ZOnLF6gAeuHLhBYNqh7g9Ghy56M7VDTO7brQbooXnjnQQL+5PHV+v2tYU4LY9s+rTHzkn740je/yduqzeVV0QFbfjZvyLBe3g48vfsZIuGtIBucyrFDBw
kaMqW5FJnzLmVa6RlNESNaKexffaANFn32/0HRu/OMXt4vL1mU+ek54Xfn/uo2tfk5fs9qnjp2U32jsmqmURIk2Qtqb6MVJXZcfNZGJo6DpFjoatC/jOiB4bFC1Ra/pA
hk9xCkSvNZ/1YyT/311XryFEuYA9tgdyNHTfDYPHlpk+wFEM1g1WHTBy7PpZoYGvNlqibLs7U1NzCETDfoyiJcoYotCqABIYZ6TY8q5ct7rjhvFRsHrDvgZRdQF8WFj2
HWNqJ6sjcYSoDtHsusUGiP6psNF3fEDduWF/bp8qPy27sdDWKS4yd6734LaCv89Zua2yqbHBs/ZvObmF+8rrdY6VWtwO4BsfTVJp4/uy/UcbPYdQHThiDdUB1mfU4hPd
uRb3gcYfZztEPzvx7Y/Xvgt7/HDi8CknQrTxWP6rdBn69FxPI78IQ+yDMePydtQ4aO3c0A0F+m4wg/55k4+FDvtF474LoOyggBnzWHS8omCVAkJgQmRU+Xhh4BOKDKvz
R6HzFt25Ol4T59xiN0SlVqnG31l15ZoCf+QXN1dteqtP7EMDJ763YXd5DTFPGyvKdqzMeiEmdvjInLIG7fFH9rYMoAj0YmAMwWeNu5kKpQOjE8AJuHIIO4NVPVjGlh1S
L6JlD4UHRcnsT/VvN7pz1Wtl+5UIUV1r5/J0bDyUl94jdsy0rTUyuJYtS4x94M6MYh1bc9veIGzJAHYZtsiOBpBDZMeKcGxFqMmYDRB9fkMjk8MBlugpb+mCX/d6qP/4
t1du3bvfAystHPmo9B8L08feEfvEuBVHdNi4aurMfdcgRB1Sp1gRWBEOUSCCsoEQNWKJgv+2snjB5IF0L27f8djQ6RsP1umJLYqgpsMwq9h3MxTTSFJYEUbUY3gvVgRD
Mc1OCiFqEKJAyqZqz861y/KyZsAC9Nlzcgs27q3Q4cilZqvZ9e3M9LHLcEi9YEVgRThEgQjKhg0QnbChkcnhBHeuDodt6FsiqOkwzCr23QzFNJIUVoQR9RjeixXBUEyz
k0KI6rJEYT7ozDnTc0oPFq2YrrQb2rSMeQuLKnUg1uz6dmb62GU4pF6wIrAiHKJABGXDFog2TdjA4LDTEuU35V62mUTn+g2IOncrNMe2S+y7HVI1WBFYEQ5RIIKygRDV
ZYlyW6F5TtQ1eCs9JCg38HDoVmjObJrYdzukXrAisCIcokAEZcMGiE7c2MTksNMS5dy505QduRBeBAe6czUs9ot9t0O6DKwIrAiHKBBB2UCI6rJEqTtX2ZGL7lwN+KSv
CvbdDukysCKwIhyiQARlAyGqC6KcO1fJiyv6ddGdqwGl2Hc7pMvAisCKcIgCEZQNhKg+iPotpNBY4dm3bWvx5q2lxXvLK/Ru4YLzRKETj6CXx31ZRYg6pE6xIhxSEWqy
YQNEUzc2MTnsHBP1rSzfVLFrzZQxv+E2cuGPOxLSpq3YU6F99XmEqLTvwN9RgdAKqOngIvQahGgEVRxC1JAlCgFGT9/9YI+Bz6RkvLswb2Vu3or5szNGJQztEfv7KZsq
cJ6oyjcBaYEK6FBAZeuKxMsQohFUazZA9IWNzUwOB1iijYdXTL4jduT4NcekvGzYu3gY7uLCRQypPHR0oHgLKqCydUXiZQjRCKo1GyCa9kEzk8MBEG06WfhmzwCI1pYu
uD/20UcX7KvX7tGNoKbDMKvIA1RAhwIMW6DTkkKIOq1GQuQHIarLnSvOE33jtcfBndvrN4+/mMlPG53258eHDO3R648Z26vQnRtBbwJm1fkK+IHW+RnWnUOEqG7prL8R
IaoLojhPVLWr1vo2jU90qwIIUbfWbESXCyGqC6I4TxQhigpYrgBCNKJh49bM2wDRFz9oZnI4YUz0eOHfRo+dOErhmDStsBzduW59bbBctiiAELVFdnxoaAUQovosUbrY
Ao3OVVr/b+AzUxCillsq+La7WwEdwUcuuMXddeqC0iFEjUDUb90i7r/1Vbvzpvbs9cy0LThPVO0UFxe8SFgECxRwARF1FMECYfERRhRAiLKGKHC0bFkizhNFMxQVYK2A
DgK54BYj/Tvea4ECNkD0pU3NTA4njIlWFK2Y7rch2htvjB06okfs8JE5ZQ04T5R1N2rBK4GPcKwCLiCijiI4tjowY1QBhKgRS7TxUF660oZojw2dsu6jmmYMLMLXDBVg
qED0BBYxFA2TMlsBhKgRiJ5q9FZ6POL2Z/wvnhN1OvBJbzG7vjF9VCByFUCIRm7duTjnCFFjENXusA3NVxc3NSwaKmBQAYSoQQHxdjMUsAGi6ZuamRx2j4nWH9r03ktj
f3dn7IN3PvLCS/O3HapTCtbVSFkz6hjTRAXcoQBC1B316LJSIET1WaKNxzfNGtLrgR69kh5+6vmHYbHc2GFDpm85rhGZgVapy5oXFgcVYKgAQpShmJgUKwUQorog2li2
8HfDe/ROX3iAG/6sO7Bw3GM9eqUtPFCvezQUx0RZtWlMx00KvLZ017ziZloiRYjO2uKFa9xUZCxLZClgA0QnbTrF5LDTnUsXoB+78hBvetIw3THTttYgRCPrBcDcOlyB
N9aU3f2L++FfRYi+OL8Q/vrXwnKHlwKz52IFEKK6LFGEKE4ARQWsUuC+Yb8FG/SJP7zsZ4nS8/CviztoLJrzFUCIGoDokIkv8SstzHpp7ChYYOHhicKuohnzFhZV6rBK
nd9iMIeogMUKpLyeE2KNggkzV1qcH3wcKiBVACFqAKKKS8/zJ4ePyvMgRPFlQwWMKwCjniEgCn81/ghMARXQrYANEH35H6eZHHaOieJ+ola58nS3bLzRTQoMTR6vyFE4
76ZiYlkiUQGEqC5L1PBUlmBGaiS2IcwzKmC2AhBApAjRyYu2mf1oTB8VCK0AQhQhihuWoQJOVwBmuShCVJz9gh09KmCXAghRhKjTO1C73g18rqMUSE7N8OMonHFUDjEz
0amADRB95R+nmRy2jokyWOFP0aMbna0QS40KhFUAPLd+EMU1FsKKhhdYoABClIkl2ljh2bdta/HmraXF+07WGBgxtaDK8RGoQIQqAOsqiByF3yO0FJhtlymAEDUK0VrP
poxxyXf4prs8eOcTr79TqmeSKG6F5rK3C4vDVoGxU/4mQhR+Z5s4poYK6FPAFoieeuUfDA5HuHPLt7w6dFiPgc+kZLy7MG9lbt6K+bMzRiUM7XH3ywv31uI8UX2NEu9C
BRQVgMX/RIjiUn/YSByigA0Qnbz5FJPDARBtOrZm6s9jn84oki+Ze3TduN4P/WL2rnrtfl2HNAvMBirgTAVwqT9n1ks05wohasSdS9ednzB/r3zzlqrNL/V74M6M4jqE
KK7JgAowVYAuAYhL/UUztJxWdoSoEYieqt+7+NFew3418Z2VW/fu9xw95DnyUenmnOnPx8SOfqnwJLpzndbcMT+RrgBdAhCX+ov0enRT/m2A6JTNp5gcDnDnwkSX+oPr
M8nu3LJ1dEeOnr+zQrsZioFFbnq1zCjLxvILH1Zdqj73TTQfB45WRnPxadnLmr6ElrDm8HkzmhmmqUkBhKgRS7SpomjF9BnLNuwqXZu3KIPs6DI36538jXsrdDhycVNu
TQ03ei4GcDae//byNzdYfTViOm5S4GZn1+df/gBMzdv/afS8FI4qqQ0QfXXzaSYHqzdBh9O1sYnDZwbdAW3UqCmzpvF7ogFH6YFboeFCSIYUgD7xeMtXHTc6WbVzTMf1
Cnx8+Tu0Ta3nqw0QnbLlNJOD1SuhC6I0pMjPiyv9L26FZggh1r8Jjnoi+OvAwmDVwjGdqFIAGo+jGrPrM2MDRP+85TSTg9WLoQuipxq9lR7P4W3ZEyA6d07R4UMkqkh6
HC/3NulI2fUNDgsYWgFw3n7dcZNV28Z0olMBaELo3bWsq0GIGhkT5VB6uNLIOn9+oLWs4vFBDlQARrbQAI1O7DEvNQwEwAeZAxu5+7KEEDUG0aaG46XrZqRPGjV2ovyY
NK2wHC1R970w5pUICMq8J8UEo1kB4Cjao+a9sGLKCFFDEK0/sCypt+LI6GNjVxxBiFrQgt3xiF21bdHc3WPZTVIAgrrd8YI4uRQ2QHTqltNMDlbNTgfqhFtoeNEz0zYc
ZeXRdXJbwbyZpABEVKIXl9XrjOn4KYBxRia9tnZaokwIComwelsMQLTpZOGbPWNTskq9BhKRbU1qdn1j+g5UQOMc0M624imwak98pqfd9w7caM1PgZODc7yq5sR0enPv
HZRWfKGb/DIy19uh7m3q8OaMVPuItuI0yGR68SUhyrjTmzM4ZkpJm6oMhs5PV9uJvNQEbjH6/kmZH3jbuFAsbWUJ9QSS1XuplO0t+enx8KDUt3NTB6ktuyivOlnDX2Ug
Qfg+w3kvpr71aIkacec2V+9dM3HosDuGPDdhmt9UUZwnilNcVCkA686E70NlV/AQjes309MuAKqrpSC5vx6Iany2hss5iMbFPJnrvU7vYgbRjqrcxEFJM8vaoPQdzQVA
08Q8b0cXQ4j6itnuyer3cJbnmoaC8zjnvlFY/RiAKGQB5o+aSpEoTxwhagSiIWaL4jxRVQiJ8tcPiq/RDCU9NLVE42IknTvp6+GMdkuUVS8fmA4PUZ8xygiinM1Nqcn9
dF0qnkQ5x84S9ZWGlEK9pS7cZ4x5CnViOEE0Rs3ramyA6GtbTzM5WL3+hjyxZLao3wxR+l+cJ4oQDa8AdG3amzGF6MNJiYMEj25Xu2dm/IiRSf0EiHa1VS9+gTghibez
uJXypqvNW5iZRE7GxpGLA9y5vgvgrrezEhMCbCmfO1fiUE1Iy9nPP0JaGA4/72zP5wnnZ4l2tJRkJtPNQeNTV1QTfyxJPC5xahbvp03OKm5R8jJfKEkVC06fR84QR6sE
ol1tVRv49JOzcjKSqBvZJws8NO9gK+cOVzrJu3MvUGOafp1s3Sa6c9XLK69dxVxx3xbJMzKfV1Vf2psLvQNHRhGiCtzV25z879MD0QbP2plzpueUHiSL/4lL/Ul/QXdu
eISY16wjJWXo2rQ3YwrR9PX5GfHJ+a2Ej9c8mQ8Pfjtnwb0UojcvFU8dTMlEvJ0PJ+VUdXAn4/ulF7QAOa57c56Mi/GDqOSCrkuemUC4QIekCFHyxPjUDS2AZ865Oia/
xX+BJd6Gu0CexRmOEkuU3i7mMCGOFISDaEzyLA+Mot5s88xLikkpaA1YMZiQsr/C44iJLozvdp0vSU+g2etqK5uVCI5ugOhN8qkhVYA8lPv+8D/JeZ7pmKjPEhVQrUle
ae0q5wrQDxDtT73TXG6pmEHqS3tzoXfAdJdIeSkiLp9oiepy59YXTxv4QI+xyzYHXfwP3bkI0fAKaPflElZwEJ1S0rI/qx+HGTIgOiJr/+5cClH6X34Yj4ME4QEwIMHH
HuL+9YNokAtkvbYIUak5eLPNu6fE0+pvNQr44dytCZOKz98UA4vIn3y+6K7W/DHEZdpGIMp/FlAiKg0rhnBsihAl6YsA5hQgEL1BdBMGksHq3ll8pLXjptJJjvfBIKpJ
Xn/TPDBXFKLiee5LIrW4jZjXSvWlF6JwH3p0TcIzQlQXRJsaK44d85yoa0B3LtMtl01q5Y5NVleXKEC0rc2TOQK42AkQAjZ8XcVDVBgfpX5IcgAPbsiZFBid6wcnZVaJ
EO3qaNmQ1g+cojlFxTs81C/q9+Oz4fhRzErPOzQ6139wlH/WaYEfXEJiBoSxVVIQoIsKS9Qvfd9/aRRSvxdytxf7qK90MhRENckr0SRYruTnBYiqqg5tzQf2M3DsixDR
GbMBotO2nmZyaGtBwa/W487VtVeomgdFdGPCzGtSAFZl09WGRYh2kBCb5NWe7VPI4CjpdjlLVDGgNFinLFpvqnptvyku7a2eHSX5MM6akJbfHMwSJWUkWer/eOIIziLU
CFF/jQLGRLnIZOmYaFCIkqS6OlqPlBSvy0rsz7ujlU6Gg2hAvK4K9WyHKMboano91V9sC0TPTNvK4NDVASncpIZtll2jvubwykhXQPvkFtp6RYh2co5QiDDi/H4iRAlU
xEFKc9y54AzdsYefndnNGZr8rErJ+yWLa+VG+IhZzAX4hHDnEk+m3BL1f2W5x0mn9wS6ppXduT+A23mnl8yLISzlfchfK53sCOfOVS2vNPPKufL7pDDRnYurF5nUYyBE
9blzZSskMESsSdWMyTpQAXCv6foQ9EGUGw2FqBluRE2EqDQmxaTAIu65/EIKnDtUuqgCXyi/ySEk/ogG+EC4TvDAovAQhSAZbp4ojTqmUb5+80SVQ3g4w73f1JJLEAnM
LaFAfm9XOnkzbGARH4sUVl5pBYcKLBLXoBAhyjiwiGbEgW+BC7JkB0S3nZnG4tDVAaElGj7axQXNOiKKoCs0V2aJdlMrkAbj+CAqnbYhmX8im5ghzGCRzq2UTfbImKF2
iotkzSB/w0s6w5IaowItgk1xUQNR4pLdnxtyxSLZDJzMqYFTXOISMzdQq1RSavFkSIhqkVfe3yjmSnlMVJaxYDOONHeBEfFeRFwmbYDo9G1nmByaW1CQGwzbkU01x/Zv
zl+Xm7d62fZdW9du2lZWVad30DTiGhBmWLcCeiHKquFjOlGngO62ijeGUAAhatCdW1m8YPLAXvxGLndOmz0Fpr70Gj1uwc4KXRzFxho9CiBEow5idhc4el4uK0uKEDUE
UW9R9r2xw4a89O6KwrXTnhh25xsbPyratDB97B2xyRPzj+uwca2se3yWvQogRO1mStQ9394G79anI0SNQJSunZue62lsbPLkjh1+Z0YxceR6Vo6KfYD/XaM96tZ2huUK
VAAhGnUQs7vA+BqaoYANEP3LtjNMDlYNUoe9KN7CWaIjHs9Yv21v0ZzkR//HlPw9u7YumvLHn8c+MQ435cZ1GEIqgBBl9QpjOioVMAMhmCZC1IglChNdZGOiPWLp4Ohj
Q6dvPFinZxoMtsjoUQAhqrLrx8tYKRA9L5eVJUWIGoQokLKxomzH2rxFGWQl+rlZ7+Rv3F1eo9GLK5q2VtY9PsteBbRClNFWYkKHbHh3LVY9e+h0fLNNfCs8aNkbXCl1
fyXJtNeHYXVf6Rr62tUmawiLizmYJI72XMkyYm+Dd+vTEaJGIVrr2TZ/2l+mF5Y3NtUfLHxn4vgXRk98a/6mI7W6OOrWdoblClRA64pFBjtQ/249QiDqyza77UL9lCSr
F0mXQOIeqV1to2hXw13tuUKImj4z3gaIvv7hGSaHmjan5hojY6KN5VteHToM/LdjVxyp2p59vzDXpUevP2Zsr9KRMsImehRAiKp5Pc2HKFmwQtiZVfo02FxFXEhITU4R
oqbjypmdA0LUiCXadGzN1J/HJo7L3V/ddGLtS0k97vnLyqN1VUV/vz/2wbuyduhYcsGZrQRzZZICavpm8RrOCiF7cXN7syjuti1d2uZmW9UK2GiFXAz7lpQFbFXGbYfC
LQpPd8YWNqmGvTzFGxNnlvA7tASeVLWHtuLe3Zr2plbaH9tTmTOS2zkVlhs6kccvXRRsbSZ+T3LJQ31L4RNtJVubBblGQZCA534OG4OLe+ZUVuQM7vd8VgbsyQprNrV3
tBbDevfcXxPSFp8g+4aSlXt9u6X6/qu03XfQnGtqPd3dX3fcNKkZR3myCFEjEG08vGLyHbG/mZhfXntg+ejeD/aZtq2q6VRt6QKEaJS/VyqLD/2a+p4w/O7N0s20ybLs
dHMV2O06T2GDa26ZwLjEeR7Yu5veyK1AS7b/vPeFvCro6rkFZoOebFexh7bS3t3a9qaW7I/tc+eG3htcaU9yyUO5pXfFVXw5nlFfbpBrlAS5qrQnuc8SldYUt4MNZSfd
P47bUVy2SYC4dqO2nKtvOfTKz7/8QWWzxMs0KYAQNQLRUw2etU/f/SAflNvr+Tm7ao4XvjVk4IM9yO9edOdqaotReHHj+W/Vd4Xadm+W7pRCQnICdv3025iTXy/+msy3
SQAAtpTiSTV7aCvt3R1qM5PAvalDQ1QpfcVNsy8obtMNpqzEl6ucMbJsvc/ZywtyGuxO4aS4J7kfRGlZuN0CfAOu4o43kueKQNWWc/UNh78S9xM1qYexAaJvfNjC5NDc
iILcoAN1kluaKnatmz4xbdT4198qhGAisE3/PDB5xt+3HsfAIpOarJuS1bSlqMbdmzk7EvyHOZtLio+QDU/8fpS3wPSCjeXbzZt4IAGinymd5CAaZr14hb27tW2rSQN8
6D5rCpao0t7gSptmE/+qZIDTlwcJt4JkDHY+DxSkXWlPcj+I0vFUcVcWXn3xKaIF7PPlasq59u5vzeHzbnp3nFMWhKghS9QYgBUmkjqnZWBOrFGg4wZ0tap+NEKUS7Oj
1VO8vQA2C+uXXtDSLntMcIgGRNlwXlnY91t2vxwPoWJ9ZXt3f0tGdn0BO2Khgm1mEhKiNEPyvcGV9iQPRm5pXG4IiAaGHSk8l+MlHamVJBUUosJY7NV2z8x4ug+Plpyr
ajGSi3BA1LzXGSFqBKJNxwv/NnrsxFEKx6RpZNKL5vUWzKtpTNmZCqifLRoEM+DS5Dbl5oECDthBacUXwIO7c4e4AzXZ/pP2774fuTtX2KSaeG75vdUInnzu3ICTKixR
xb27g3hW9UBUMf2bSnuSKz9U7qoN7s71L3tVq9Ke5IoQDebOBXGpR/eDoswRfPUp7qYe1BGtDaNlTV86s/27IFcIUYMQ5UZA+YWK+L1cyH97/e4lhCgu+6dCgbz9n97s
DPC1KvWQQTAj2b1ZEljEQTGBW0CA+jzp734QDRJYxEckyQOL/E9ygUWh3bmKe3d3ni9JT4hP3dACQUxtZbOEGB9dEFXcG1wiiLhptmLQ0MXmguQRWZ5rvCghAov8yt5+
WmlPckWI0g+RgMAi7pFcHYHDXBwJVp1z4ijW8AMNDJqZC3DlzCLYANGM7S1MDg2NKOSlOuxF39q5pQt+3WtUSs7OI94m/mR9xY6cP/fEXVxU8MOZr4T1uVJpjKrYvRlm
qoibaUsmZsQkZxWScNsAd25C2sJ5dBqM4hSXkCdVuXMlU0F8e3dr2ps6tDtXMX3JPtu+eS+SK5OzcjKSYtILit9Nkq+xEHANdTv7lBQFUXpuEIiSLcT9p7gI2CYfAT4z
l3C1rXrxC9ykoxA51zR7lTwKzVBTX2qEqBFLlO7i8sLCsgYZiXEXFySoRgXUj4yy+nbEdOxXQOa/NSs7l7+5YSpCMHGEqBGInhL2E81ds3Xvfs/RQx7Pzu2buF1cho/M
KWvAMVGNLInaF1JTmK5Z3S2ma60CfksumPFw+DhDR67ZvQpC1BBEg+ziMnTgs0t31DTrcBSbXd+YvmMVAJ+bGd0opulUBa57c56U+XJZZxSGQuHjzLEN3jUZswGiM7a3
MDlYNTkdqJPfIt/FZcGatUVHq7XboDRN1zQsLIgOBZCjrF5qTAfmtCBBdbyDOm5BiBq0RIF8TTXH9m/OX5ebt3rZ9l1b127aVlalY9VchKiO5uu+W4CjKoN1kROoQDAF
YIU/9OJa1jkgRA1CVLYp953TZk8ZCPNbRo9bsLNClzFqWcXjgxyrABgQEAyChEAFdCgAg6CwO5Bj27YrM4YQNQRRIbDo3RWFa6c9MezONzZ+VLRpYfrYO3CKC4YUGVMA
TFJNy9Pr6HDxFjcpAB9eOJXFFkjbANE3i1qYHKxeAANjonSKS3qup7GxyZM7dvidGcXEkYtTXIzxw5Y3wZkPBasUFqlHmrJ62d2XDrATVpbHdXFtfH8RosYt0RGPZ6zf
trdoTvKj/2NK/p5dW7kpLk+MW3FEB55tbAr4aCcrAENc4KYDUwNWZojmo7SkRDyiWYddtW0YN+SQFxYhagiiQaa4PDZ0+saDdZoXzsXoXIe8FZgNxyog3WHGsZnEjEWV
ArZA9OM3ixgcrDwzOuzFUFNc3snfuLu8RldUEUI0qt49LKwOBRCiOkTDW0xVwAaI/rXoYyaHnRCFzbhnzpmWMTv4MW9hUaUOPJta2Zg4KhDpCiBEI70G3Zd/WyDa8tci
BoedEK0vngZTWQI3b/GdGT4qz4MQdd8LgyWyVwGEqL3649MDFUCI6hsTbaw4duwQWSw32HG8XNzXRYtrF9soKoAKhFAAIYrNw2kKIET1QVQaNIQrFn3itGaN+XGrAghR
t9Zs5JbLBohmFrcwOex05/qMS1yxCAmKClinAEI0cmHj1pwjRA1ZorhikVtfDCyXMxVAiDqzXqI5VwhRIxDFFYusM0Gi+S3FsosKIESxMThNAYSoEYjSTblxxSJEKSpg
kQIIUachBPNjA0TfKv6YyeHAMVFh0guuWGRRl4ovcLQpgBCNthp3fnkRooYsUW4mqHxTbm7FourKvRt34GILiFJUgLECCFHnQyXacogQ1Q3R+kOb3nsx+Td3xA7tP3LK
9BV7hA1EG44XLRn/SCIuthBt7xKW1wIFEKIWiIyP0KQAQlQfRJurtmff3wsWLRrxq+Q/PTxkaI/YkWNy9tXWHdkw++WBcH7gcxlbK3DFIk1tES9GBcIqgBANKxFeYLEC
NkB0ZsnHTA5bx0SPr5yY2KPXszO2cz7byuIZIx/tMeRPY5MTe8QOHTh+QUGZVwdBcQF6i1s/Pi7iFECIRlyVuT7DCFFdlihdO3fMsv38qgt1O7OfJVFFA1PS83Ydr9ez
CRqFrusbHBYQFTCiAELUiHp4rxkKIEQNQHTsykM8RGHC6KSYMXNW7q3WZ4CKd5lRx5gmKuAaBRCirqlK1xTEBoi+VfIxk8NOdy61RIdMfInfDe2tiWPGj31tlmRnNNwK
jXFYpmteOSyIJgUmL9r2xpoy8ZZAiP61sPzF+YWa0sSLUQGGCiBEDViiuBXabiQlKmCuAvOKmwGcE2auhF+g45NCFM7AeTjz2tJdDPtETAoV0KSADRCdVdrK5LDTEoW5
obgVGhIUFbBEgeTUDCDl3b+4f+yUv0khCmfgv/cN+62mLg8vRgXYKoAQ1WWJatkiVNMoKdvaxdRQARcoAB5dKTv9fk95PccFZcQiRK4CCFGEqLnuuMh9NzDnzlGAGp2K
B4yJOiefmJMoVAAhihBFiKICTlfAz5Er0nRo8vgo7LWxyI5SwAaIzi5tZXLYOiaqfyZoaO+uoxoHZgYVcIgCEKCraIZiXK5DKiias4EQRUvU6VZINL+fWHZRAQggCuTo
rC1elAgVsFcBhKhhiNbXHPEcPeQ5UcEvVFRXfhj+e7zc26QppAhXLLL3TcCnO1wBCCDygyhE7To8z5i9aFAAIWoUovW7F/2aTBh9ds7uOgLCio0T+8J/kybmn0CIRsMr
hGW0RgEwOv0gClG71jwan4IKhFDABojOKW1lcjhkTLShbF3q2Imjxr65tKyeULO6OOsZ+O/krK24nyg6ilEBlgpAGJHIUYjXpcsv4IEK2KsAQtSoJarD3Axxi72tAZ+O
CjhZAQgjEiEK8bpOzirmLXoUsAOiO1rnsDhst0TrTuwryFuUkTF7+uzl+bsr6ugKDI1HCubOmZaRnVuqZzH66Gl5WFJUQKsCdAlAeuBSf1rVw+tNUgAhqtMSrfUUpg8d
RrY/o0ev0eMW7KwAiDbsmTMc9ujGMVH0s6EC7BWgSwDiUn8m8QCT1aEAQlQfRI+unPgbws67n534xlsvjk2+g6B05Oj5OysQojhMhQqYpgBdAhCX+tPR1+MtJilgA0Tn
7mhlctjpzuVDcJ8Yt+IIceHWHf/HnBdjKEf/viQDLVHT+lCTXgNMNoIUgJAiXOovgurL9Vm1A6I7z85lcdgJ0eptU37xYI/YR4dmfXicnx5aWTz/JcLRXo/eOQD+hO5c
9q4817+NEVrANYfPf1h1ybLj7+t2WPYsKFqEVgpm2zIFEKL63LknNkx/mnPhPtBj+KKdDXQVQIGj5DxCFCHqWgU2ll843vLV51/+0HGjk9W3rMPTufzNjcbz3+6qbbOs
a8YHRYoCCFF9ED3VWLnrnfQ/3CmDqJSjCFHXIiRS3m3m+QSzrPrcN9EDTkWu3+zs+vjyd2ihMm9dkZugDRD9286zTA5Wn64GJno2Vnj2bSvykKBc34HL/iE+3aZA3v5P
gRys3jh3pAOGKcgSuV0/5pyVAghRvZaoOftys6pXTAcVYKUAeG7B/HIH+diWAoxy8Gyz0hnTiVAFEKIIUbeZTRH6Kjow22BpwcAnW/C4L7Wypi8dWHeYJcsUQIgiRBGi
qICCAkDQrztuuo95ZpQIOWoZsRz4IIQoQhQRggr4K4AE1cRacHejX9eBeLMmSzZAdN7Os0wOTa08xMUGAouk8URsfrem1vEpqEBoBTCMSGv3AuOjGGcUna8VQlS3JdpU
sWvd9Il/7N/rgTuG/DFlxrodlXp24fZDeHS2Qiy1oxSA2ZDhENLV7pkZHxMbn+lpV7y005t776C04gvh0uH+Ti4emevtCHpxmAtutnn37PS2qYx96mrz7tzBXR32uapy
77sI5v84qh4xM9YogBDVB9Hm6l15o++GlYmEBehjH4wZl7ejptmgXWtNreNTUIEQCqiYCXqjNT+F7KbSb6anXQlemiCqkVUBl3d4c0YOzvGqXPeh05sz+F7VV2vMG84f
jcI3CyGqD6InC6aM7gHgHDtvxaaijavnjSJAHf1S4UmEaBS+RW4qMsTIhAdHV0tBckLautVZ/R7O8lxTuD5aIQpucDc1BiyLGgUQorog6r9Vy4m1LyX1iB366+w99cbm
j6qpM7wGFTBPARVmaHd3W3FaTEpBa2tJasKY/BbeFAU/aWFmEt3vc8TIpH7EnUvMvpjkGZnPg+83LiYhbfFuz/aZ/DWJM0taOWew6FYlv/RPyshI68clEnhB9822qhX8
X/u9kFvW2tF9oSR1EL/J6L2ZuW+PjE/NmJHYP47YmuDm/SALfidJZeRmJselbvUWTxF2JB2ZW+Hh3MjXiFXts02JXRuXnN/aJXmWmJNw3xcQYYQjo+Y1TmembANEs3ed
ZXKEa89q/67HduQh+tio2Rs2by3evHVD1tjHesQ+dM+UFf8g/4WjdOexeh0pO7OVYK6iRAEIMVXx2nADooQ6nFOX8AZuunmpeGp8v/SCFuDidW/Ok3ExIkT7J80sa+vq
6mjZQPiXOM/TdrO763xJegI/pCqDqHjBJc/MZD5x8YJ2T1a/hLT85o7urg5vXhIB+Y3ubtGdy/EvJnmW5xLkqOtS8ST+4pttnnmE3KnFMNjrc+cKyXa15o/hk4LbwMge
BF8GnXD7vS/kVcHgaXtLfnp8Yp63Q9WoK053iZKXRSwmQtSIJSoOiAb+gmvn4ryRyFMAFidSAdFrnsyHKf84Q5OSDCxCiVVKaCdCdEpJGzdeKfCJY1FnGxiF1P6TW6Ki
acslzt0rXkAsYMGBDIbvjh0eYsvKIcpDnUuf/x0eR/IcDKLSjAlAvQ7fB76wKVKckKFPEtVgeYpoo0iUlxchihCNvL4+yl9a84oPe5WEhygdEKWRt4QuHNX8BkGF//pA
SK4G0D4shOwGg6gvplcBotQoBLdwzuaS4iOtvGkohyhnblKyUmpyP77/Blqi3d2iSS3+wkGXuqb5Qy1EwaNrXgVhyg5UACGqC6LGBj5DuHkd2EQwS9GjgJo1cjlbTUoX
bqKLRRClQGz1FG8vgDFO3ntsHKLdXKGmlFxqpr7cLs5yDTqBJ9yHBi68ED2vDJTUBojO3/UJkyNcS1b7dx0jl+bdElWNDwvrNAVUvDPScVC4nPsv8cqqcOcatkR9Uzx5
53B/bmaLIkS1uHNFkzp/KRcwBea4vJha3LmQGA6LOq1hm5ofGyD6992fMDlUvPCqLtFFxIriNatz89ZtLKtrbGosL92Ym7fyvU2eWmKhSv+keRkjUysbE0cFQiigLqoI
TLQRvohcGOjko3LagwcWCWOixiFKnpUwqfh8FwQWkTAl+rsiRDUEFnHdhOC/FYZRJXFJ2gKLIC1cdSGqXjSEqC53rmyKS93O7Gdh1YX/9tLGEwBR/9kv2jgaVY0PC+so
BT6suhT+qzPQJhPDhbraqhe/wE1l6Z+U+XZWIhk3ZT0mKpl2EpOcVUhiZ/0Di3zjoNL5MM9nZcAUF+XoXK7UdA2m/pLvA9/t8al5B+lsHHU/OFvUUQ3b7MwgRBGiGFiE
ChAFVEFUHUWi/CqIzzK748b0naOATogea/lqW+UlfQcTXy4kou/pcNdX38k2eNLjzpXNE92aO+X3YIn+fOyC9TBDdMuKl379UI9YnOKCZIowBRCirNiPEHUO4SzIiU6I
QhTfe/s/ZYVDK9NpufSd36tiAKI4TzTCOGHBGxW5j0CIIkQjt/XamHOdEIXWBvbc4v2f2ph1HY+u+uSbwPcEIapDSbzFfQogRBGi7mvVFpRIP0QjjqMHgqysrQeiTTX7
i/Sv7YfzRC1o2fgIrQogRBGiWtsMXg8KGIJoBHE0GEGhCHogaiwEFyGK754DFUCIIkQd2CydnyWjEIVm99mX3zu8nCEIagyiIx6f9h7MEFU66BRSbfNb4HqHK4nZc7EC
sP0IK4rI0iEL3kpWOILdV4pV76AtJhR6A23W22sb1AGXz3XxaxJYNAYQhQb38SXn7qK34fiF0IuZ6UCdMBkUA4swsMhVChiEh/LtBKLiirhdHa3FWYmDknKqOkx5mCMS
xcUWEKJ+DfFnahqmMzkalqDGLNGh/Z94ftTYiUrH5KytlTrwHFWNDwvrNAW+7pDN/lLz4oe/RgZRuFy6i1n4uyPxCoSo0xq2qflhY4nSht54/tsFH33inAOWMVOzoLYO
1BlclgjHRE1t05i4bgVgqR320PKHqGxPtK62E3mpCdxOKclZxS2ceaq0G7bPYRu4L7dkMzW4u6OlBNam5xzI8akrqmHvUn7LNnFvcFhQqVjYAYZ9cSFFGF3WXQV4Y8Qp
wBKi0HrKmr90CETzDnyqhqA6LdHGIwVz50zLyM4trdbD4OBjpRHXgDDDblIAVk5nT5VAiJJFdAeRRfjI1twj0xafELbsfjLXe50uWksWxe3i9uWmu2GH3pfbh1hu9xXK
zo7mAsAztxYut/og3Ru8u6utbFYi3arFrB8YXXZTq8CyhFaAMUQdwlEgqHrHFFsKGkwN2ysqYKMCpsQWKUCU393zEiwo32+mp53ijPBvcE7FBclm2sLq9jfC7MutuGs3
vzg+2QdUsnk4sVXlW40yRin0PDbWID7aegXYQ9R2jmoiqE5LlJiSTdWe4vdmL1p7sJ6As+5IftarQ4cM7dHrN49PWbL5KHdS+2F9C8AnogJSBSCylDFVglqiH7aQNd9l
W5MOzvFUyjbTFvLiszWV9uUW/ipf7566eUlMk/y8uRA93vIVtqioUsAUiELDh/FIW/y6WgmqF6KNxzf9bejAB3vEPjtnN0xlObFh+tN3xPqCde94NHtbdTNCNKreJXcU
dldtm+kQ5Td+OX0dIOqzROljgxDObxKL377cToLomsPn3dESsBQqFTALojAeaQtHdURG6EBdY2PZwt8N7xE77FcT87adaGw4sGxkLyDoow9PW72hMG/i0GE9Yke/VHhS
R8oqqw0vQwXMU6DjRidLjgaPzvV5a4O4c7vFndcETCrvy63KnStua2qiJYqboJnXLB2bslkQJTF2lnNUB0F1WqIVGyf2faBH7ylLjzY2NtXvz0kjZug9b6wth//S7UWH
/jp7Tz26c3e7ahqlY19jthljHF4UYp4oCSxKiE/d0NLRyW2yzQUWcTtvp+U3d3RLdsMWIaq4L7eqwCIrIIpmKNumGBGp/ePIx2Av3bjxY4hPT1XzRBXvB46uOfy5NX5d
fQTVCdHqbVN+8WCPXs/O2F7ZUPHh9EfB9Hywz7RtVYSax9emJ/eIHT4yp6wBIYoQjUwFYDMvZsZoyBWLfFNcYCWjslZtU1zEfbmlzt6gU1xMhyhOD40I5jHPZEk5gWjo
90U/RCFdiFWDcUqzOQpTVHW/8zqcrgIpJSsW9fpjxvaqhrK1zz4yAvYW7dFrfFapV0fKzCsYE0QFdCgAFpXKGWK63zuX3YhL/eloZu645VDVmaZTZ0yEqAUchcmpRl5I
Hagjt1TunP/saD6YqNfocQt2VjSdqt+96NckvGjk6PnkvzpSdkerwlK4QAH2EUZG3lJn30tMBZwbGplOF+OvalX96U/OfWYuRE3lqEGC6nTn8oCsO75v9+atpcVlVXX0
zIndK1d8sHlvBf9f7Rw1XqOYAirASgHGg6POBqHu3IHrGwnKqslFXDpL9p2Fnv/ql9dMhyg8AJoac6eucYIag6geWzO0eRpxbQgz7G4FgKPo1w3RP8JAkrsbAJYutAJq
ooqg/RgaE5W2P4j9YchRmEKj++NReqMOp6t5t2CTRQWcpgC8aOrX/2LySkZEIqAJrpHrtLZqfX5O1J4+dfrjsC2WGUThSaw4qnJx+bBlQ0vU+maHT4xEBcAkZTx/VM3L
6chrAJ+gRiRWIuaZrQJ0hmhYXy5LS5S+EcY5ypCgCFG2rQpTc7cCEG0E7290OniBneC8hc7H3VWMpVOvwNGaMwDRW7duhf3YY2mJ0ocZ2ewFJp6yfYfN883qSFl9/eGV
qICNCgBLwBqDmZHAFQh3sOyge5zRw4KHQgHhALcthg7Z2Nic+Whqhl5uuxKWoOwtUSMc1bE0btgS6kCdebc4s7lgrlABhygghahDsoTZiEIFcvZ8AjNbYHro7duqttRj
b4nq46gZBEV3bhS+AFjkyFUAIRq5deemnFNH7nffqd3E3iyIAsDAT6IyXtckgiJE3dSysSyuVwAh6voqdn4B91W0qIwnEv2gJkJU/SL1n3/5fVjHrL4LzPPN6kjZ+Q0I
c4gK2KgAQtRG8fHR4MWFRf6gY7948ZIm3JgIUciHGo7qXlxeTTl1oM68W7CZogKoQAgFEKLYPOxSYOWBszArVH0wkZQ+5kI0LEdNJSi6c+1qkfhcVECHAghRHaLhLQYV
AAN09wniwm1qPqN+HNRSiMLDgm32YjZBEaIGmxfejgpYqQBC1Eq18VmwNC7sdFbbQFZ4/ezzL9RMCVV0f5puidKnBnKUydK4YT265vlmdaSMrRYVQAXQnYttwF4FgJ2w
KC4d/oTj7Cefff/DD2FREuICiyDqx1FrCOo0SxQm8OKBCqACwRSQWqKoEirAUAGgJhidAE6YAErZ2Xz6Y1hL4caNH43gk95rHUQpR2HSi2UEdRpEdRiveAsqED0KSCEa
PaXGklqmAKwmD25bWA6XCTutmOKiSHhYzcs4+dWnYFn1qHkQOA3wQAVQgWAKSCGKKqECDBVgS00/AFlqiaqHH16JCqAC0aaAFKLRVnYsb+QqgBCN3LrDnKMCrlIAIeqq
6oyawiBEo6aqsaCogLMVQIg6u34wd8oKIESxZaACqIAjFECIOqIaMBMaFUCIahQML0cFUAFzFECImqMrpmquAghRc/XF1FEBVCCYAv/85z+lf1KEqN81KCYq4DQFEKJO
qxHMDyoQLQqcOHGipLhYLG0gRA8cOLBxw4ZokQPLGZkKIEQjs94w16iAKxQY9sgjmX/9a2trK5RGCtH6+no4D2cuXrzoioJiIVyrAELUtVWLBUMFnK/AiuUrKDufGTdO
ClH6+8uTJjm/CJjDKFcAIRrlDQCLjwrYqQDYoIHsFM+AO9fOzOGzUQEVCiBEVYiEl6ACqIBpCijaoJSjX3/9tWmPxYRRATYKIETZ6IipoAKogD4FIHRI0RhduGCBvgTx
LlTASgUQolaqjc9CBVABfwXA3FSEKMTuoliogPMVQIg6v44wh6iAyxWAACI/jkLULs4QdXmtu6V4CFG31CSWAxWIWAUggMgPohC1G7GlwYxHlwII0eiqbywtKuBABcDo
9IMonTmKP6iA8xVAiDq/jjCHqID7FYAwIpGjEK/r/gJjCd2iAELULTWJ5UAFIlkBWKJIhCgu9RfJNRl1eUeIRl2VY4FRAWcqAMFEOD3UmVWDuQqhAEIUmwcqgAo4QgG6
BCAu9eeIysBMqFYAIapaKrwQFUAFzFQA1poHiOJSf2ZqjGmzVwAhyl5TTBEVQAX0KQAhRTg9VJ90eJddCiBE7VIen4sKqFPgp1vdP17o/q66+5s93VdWu/u4WLfQzQW8
+j6pRKhKqFD8cYsCCFG31CSWw30K3P6+u728G3pet7MzGgsI1fp9Qzd8IeFPhCuAEI3wCsTsu1IB6FvBXkF2ul6Ba1u6O6+7sglHT6EQotFT11jSCFEACPpVCRI0WhQA
kxQ5GiGvpmI2EaKRXHuYd/cpgAR1vfUZWEDkaCS/yAjRSK49zLv7FIiC6KFoMTE1fQ2A7wF/IlMBhGhk1hvm2pUK3DiHgIleBSDOCH8iUAGEaARWGmbZrQpAmIkm8wUv
dpMC4NTFnwhUACEagZWGWXalAjB30E1IwLLoUABcEfgTaQogRCOtxjC/blUA57TooI7Lbrl+yK2t28XlQoi6uHKxaBGlAE5rcRkRdRQHPboR9crSzCJEI7DSMMuuVCBE
n3t5XkFib3G7zbiY+Kyi3O6zr2fdFRsX81DByeXdV3I9U+PjYnonzc3sIOksb138EPx3zOJ5XVdWtReNiY+JjUtMbb1MVg3sanyrZO4wciYmNj4l5eDJPM6NzKfA3bK6
m38iTSHEWoP0LpIUdwzJWvx667lVXILcc+8a4zlL/+uM49ycgpQBgmhiluRl57LadTJ1DCkRlTds5jnBaWFJvXAVFP4upWRhmSr8iSgFEKIRVV2YWRcrwACisXw/HgKi
l98u+RNQRMRebNzwFC/BHhOIcmD+0+RLhNYOhKjwPeGPRuFTQPjO4DNvC0RvXnVxG3dl0RCirqxWLFQEKhAeonK7UMESBYbRa4JaooKBlZB7YHE3D1RqNhmAqGhunptX
MnUIbyjrs8PMvSsY10V7WrQ7A8+ENkYllqjBIiBEI+3dRYhGWo1hft2qABuIUstyaRB3rmCK3ZVYUi96KVf9cG5pFxOIQhHOZeYO7x0/9fV2qSXKwxXyNqaE8x5zLH9o
/bYXJxGP9IC07DfbOFczOKLbDryYNZz4rn2u5oDbwVLsODktlzhmeydNnSw4kGWc62rM3ECIDtb5sNxt2R2iW1vBvuSQOXxo2vC+vPuafKAMmJDyQLxos57LPkh94EIR
SG4vv1udTU7Gpzy9Hp4V6M4VLogb/mTR4iRVzm2EaKS94AjRSKsxzK9bFQgPUdEHG2xMNH7G3CfHkBHThUHHRHn7lY5fTvbwA6LimKjEzUtgozyqKhnt4/AjG/jkzhC/
qGj2UaILKXPeYw6i8UnD+wrnB0wqeBsGXwVDWbiYpKxwO0W1cK84EiyBqMIo8iJ+bDgYRBPHl+Q+xOGfZuOBd+YmChBd7J2b4FeE7ivyk4TWfmOiQS4IbaoiRCPtBUeI
RlqNYX7dqgALiGZtyyRDnhwPgiAQbLjJ1NTjDtGS8wsR4v+qGJoUHqIEJyuEwCKOgtxwY1f95Elc0A1HKQF+NNiHXEAtwt97GsFKXtVRnpZGLuY+CGS3czjkjWlFDy01
uIfMKnqHREVx6fsbxzK1efC3lKeOEbGdOKF6GyTCOXg5w5Ri3hc3RE72Tpo+ndjQtAh+EA12AULUXa8wQtRd9YmliVwFwkM07JgoIIfaW4PTUgaHtCPBa/paER+jS5Nl
MSYqRvnKLNFV4Pb0Lk8tWP+G6HellqgQwioMKH48F4KQqS3IOUtJTDL5r//tdMRXajT7xdD6jVCK/xW57hcwLFjPrTSwdq5n6qAxi+d+S5QkKfvbx5yB3qlYBEl0rnIZ
w8YqoyUaaa8wQjTSagzz61YF2EA0V5idouiMBTP0jZKCySVFMEYozoShs18YQVRhTHRxa9GrOw+823Ulr3Xb+KzpZAhTC0Rfqfa/Xe7gVXDP6oUoEWHQmFlPzyAopZ8j
CFG3vm/MyoUQZSYlJoQKGFKAFUSvLL9UAIN5yhDlxwWpL1SY7sIZfywgKovOlY2JxqektcBEGmEOpVZ3rvx2qTuXG3f0TU2hw6I63bn8OC4/urlShKjEnbuq40BKks/H
K3ikqZKK7lw6c1d6AbpzDb0njrsZIeq4KsEMRakCzCBKx+2ChAXJQnKoR5Sb7hIKov7LNfiPico8qwrzRLmhUFlUVICDlHftKgUWrQq8XR5YpLSygeLyFEGnrorBUEJk
k+iO5qNzZSFCgsNZerL348MH8cG3vsUWglyAEHXXG44QdVd9YmkiV4EQO4kqrh+kME9UxAntvhVja8Gj+3oBnftB5mb8oYQ4WkOvWKQeosFWLFreVvT7JLqk0dJMiMTh
YDkgbdbv0whch2QVzOPcy0GmuMC8F/ntkikuA9IWzxHuDT3FJcT6Dz6Ics5wOtGFlloYbRWmuPA2Mc2tMPcmPiW1siA5AKJBLggN0c7rkduEozPnCNHorHcstfMUgO0k
Dc7Tj5zb5WOiYRfVi5oLcO1c572XYXOEEA0rEV6ACliiAJggkUNBg1lFiCoLiLu4WPKqsX0IQpStnpgaKmBAgajZlBshqgxR3E/UwNtj160IUbuUx+eiAgEKQB8aNcYo
ltRfAfiEwp8IVAAhGoGVhll2sQK4q2jUfkbgMguR+V4jRCOz3jDXblUgmkZG0Rj1KfBdtVtbtOvLhRB1fRVjASNNAXTqRpsx2l4eaW0U8+tTACGKrQEVcJ4CwFGY7RBt
LInO8v5wxnntD3OkQQGEqAax8FJUwDoFbn/fHWL5hejkjctKDQYo1DL+RLgCCNEIr0DMvrsVgGAT6GrRKnUTPiF2DEZAEZ9ueXMRom6pSSyHuxWAPheA+uOFbljYCI9I
VADqDuNv3fiSIkTdWKtYJlQAFUAFUAFLFECIWiIzPgQVQAVQAVTAjQogRN1Yq1gmVAAVQAVQAUsUQIhaIjM+BBVABVABVMCNCiBE3VirWCZUABVABVABSxT4/wOrKR4d
D4eg/QAAAABJRU5ErkJggg==
              </image>
            </content>
            <controls>
              <block>
                <ID>0374</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal procedures</title>
                <content>
                  <para>
                    Agencies must document procedures for the disposal of media.
                  </para>
                </content>
              </block>
              <block>
                <ID>0329</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal procedures</title>
                <content>
                  <list>
                    <head>Agencies declassifying media must ensure that:</head>
                    <item>
                      the media has been reclassified to an unclassified level either through an administrative decision, sanitisation or destruction
                    </item>
                    <item>
                      a formal administrative decision is made to release the unclassified media, or its waste, into the public domain.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Declassifying media</title>
            <content>
              <para>
                The process of reclassifying, sanitising or destroying media is not sufficient for media to be declassified and released into the public domain. In order to declassify media a formal administrative decision will need to be made to release the media or waste into the public domain.
              </para>
            </content>
            <controls>
              <block>
                <ID>0375</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Declassifying media</title>
                <content>
                  <para>
                    Agencies must declassify all media prior to disposing of it into the public domain.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Disposal of media</title>
            <content>
              <para>
                Disposing of media in a manner that does not draw undue attention ensures that previously sensitive or classified media is not subjected to additional scrutiny over that of regular waste.
              </para>
            </content>
            <controls>
              <block>
                <ID>0378</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Disposal of media</title>
                <content>
                  <para>
                    Agencies must dispose of media in a manner that does not draw undue attention to its previous sensitivity or classification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                For further information on media security see the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Software Security</title>
      <section>
        <title>Standard Operating Environments</title>
        <objective>
          <block>
            <content>
              <para>
                Standard Operating Environments (SOEs) are secure.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the hardening of SOEs used on workstations and servers.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								The standards endorsed by the Whole of Government Common Operating Environment (COE) policy come into effect when an agency is ready to deploy a new version of their base SOE. Agencies are now required to build the SOE in accordance with the standards endorsed by the Australian Government Information Management Office (AGIMO).
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Developing hardened Standard Operating Environments</title>
            <content>
              <para>
                Removing or disabling unneeded software and operating system components and functionality from a system reduces its attack surface. This could include removing hardware such as optical media burners or drivers for undesired inbuilt hardware components such as Bluetooth, wireless and webcams.
              </para>
              <para>
                Antivirus and other Internet security software, while important, can be defeated by malicious code that has yet to be identified by vendors. This can include targeted attacks, where new malware is engineered or existing malware is modified to defeat the signature-based detection schemes used by most software.
              </para>
              <para>
                The use of antivirus and other Internet security software adds value to the defence of workstations and servers, but it cannot be relied upon by itself to protect them. Hardened SOEs still need to be deployed to help protect against a broader range of security risks.
              </para>
            </content>
            <controls>
              <block>
                <ID>0380</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Developing hardened Standard Operating Environments</title>
                <content>
                  <list>
                    <head>Agencies must develop a hardened SOE for workstations and servers, covering:</head>
                    <item>
                      removal of unneeded software, operating system components and hardware
                    </item>
                    <item>
                      disabling of unused or undesired functionality in software, operating systems and hardware
                    </item>
                    <item>
                      use of data execution prevention functionality, preferably hardware based, when available
                    </item>
                    <item>
                      implementation of access controls on relevant objects to limit system users and programs to the minimum access required
                    </item>
                    <item>
                      installation of antivirus or other Internet security software
                    </item>
                    <item>
                      installation of software-based firewalls limiting inbound and outbound network connections
                    </item>
                    <item>
                      configuration of either remote logging or the transfer of local event logs to a central server.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Maintaining hardened Standard Operating Environments</title>
            <content>
              <para>
                While a SOE can be sufficiently hardened when it is deployed, its security will progressively degrade over time.
              </para>
              <list>
                <head>Agencies can address the degradation of the security of a SOE by ensuring that:</head>
                <item>
                  system users do not have the ability to install or disable software
                </item>
                <item>
                  system users cannot disable or bypass security functionality
                </item>
                <item>
                  antivirus and other Internet security software is appropriately maintained with the latest signatures.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0382</ID>
                <revision>2</revision>
				<updated>Sept-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Developing hardened Standard Operating Environments</title>
                <content>
                  <para>
                    Agencies must ensure that for all servers and workstations, system users do not have the ability to install or disable software.
                  </para>
                </content>
              </block>
              <block>
                <ID>1033</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Developing hardened Standard Operating Environments</title>
                <content>
                  <list>
                    <head>Agencies must ensure that for antivirus and other Internet security software on servers and workstations:</head>
                    <item>
                      detection heuristics are set to a high level
                    </item>
                    <item>
                      pattern signatures are checked for updates on a daily basis
                    </item>
                    <item>
                      pattern signatures are updated as soon as possible after vendors make them available
                    </item>
                    <item>
                      all disks are regularly scanned for malicious code.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Vulnerabilities and patch availability awareness</title>
            <content>
              <para>
                It is important that agencies monitor relevant sources for information about new vulnerabilities and security patches. This way, they can take proactive steps to address vulnerabilities in their systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0297</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Vulnerabilities and patch availability awareness</title>
                <content>
                  <para>
                    Agencies should monitor relevant sources for information about new vulnerabilities and security patches for software and Information and Communications Technology (ICT) equipment they use.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Patching vulnerabilities</title>
            <content>
              <para>
                Applying patches needs to be considered as part of an agency’s security risk management program.
              </para>
              <para>
                Critical patches are patches that address high risk vulnerabilities, such as vulnerabilities enabling unauthorised code execution by an attacker using the Internet.
              </para>
              <para>
                If a patch is released for a high assurance product, the Defence Signals Directorate (DSD) will conduct an assessment of the patch and might revise the product’s usage guidance. Likewise, for patches released for High Grade Cryptographic Equipment (HGCE), DSD will subsequently conduct an assessment of the cryptographic vulnerability and might revise usage guidance in the Consumer Guide for the product.
              </para>
            </content>
            <controls>
              <block>
                <ID>1143</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Patching vulnerabilities</title>
                <content>
                  <para>
                    Agencies must have a patch management strategy.
                  </para>
                </content>
              </block>
              <block>
                <ID>0940</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Patching vulnerabilities</title>
                <content>
                  <para>
                    Agencies must apply all security patches as soon as possible.
                  </para>
                </content>
              </block>
              <block>
                <ID>1144</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Patching vulnerabilities</title>
                <content>
                  <para>
                    Agencies should apply all critical security patches within 2 days.
                  </para>
                </content>
              </block>
              <block>
                <ID>0298</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Patching vulnerabilities</title>
                <content>
                  <para>
                    Agencies should ensure that security patches are applied through centralised patch management wherever possible to better implement and control the patching of software.
                  </para>
                </content>
              </block>
              <block>
                <ID>0300</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>DSD</authority>
                <title>Patching vulnerabilities</title>
                <content>
                  <para>
                    Agencies must not patch high assurance products or HGCE without the patch being approved by DSD.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>When security patches are not available</title>
            <content>
              <para>
                When a security patch is not available for a known vulnerability there are a number of approaches to reducing the security risk to a system. This includes resolving the vulnerability through alternative means, preventing exploitation of the vulnerability, containing the exploit or implementing security measures to detect attacks attempting to exploit the vulnerability.
              </para>
            </content>
            <controls>
              <block>
                <ID>0941</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>When security patches are not available</title>
                <content>
                  <list>
                    <head>Where known vulnerabilities cannot be patched, or security patches are not available, agencies should implement one or more of:</head>
                    <item>
                      controls to resolve the vulnerability by either:
                    </item>
                    <item>
                      disabling the functionality associated with the vulnerability though product configuration
                    </item>
                    <item>
                      asking the vendor for an alternative method of managing the vulnerability
                    </item>
                    <item>
                      moving to a different product with a more responsive vendor
                    </item>
                    <item>
                      engaging a software developer to correct the software
                    </item>
                    <item>
                      controls to prevent exploitation of the vulnerability by either:
                    </item>
                    <item>
                      applying external input sanitisation (if an input triggers the exploit)
                    </item>
                    <item>
                      applying filtering or verification on the software output (if the exploit relates to an information disclosure)
                    </item>
                    <item>
                      applying additional access controls that prevent access to the vulnerability
                    </item>
                    <item>
                      configuring firewall rules to limit access to the vulnerable software
                    </item>
                    <item>
                      controls to contain the exploit by either:
                    </item>
                    <item>
                      applying firewall rules limiting outward traffic that is likely in the event of an exploitation
                    </item>
                    <item>
                      applying mandatory access control preventing the execution of exploitation code
                    </item>
                    <item>
                      setting file system permissions preventing exploitation code from being written to disk
                    </item>
                    <item>
                      controls to detect attacks by either:
                    </item>
                    <item>
                      deploying an Intrusion Detection System (IDS)
                    </item>
                    <item>
                      monitoring logging alerts
                    </item>
                    <item>
                      using other mechanisms as appropriate for the detection of exploits using the known vulnerability.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Firmware updates</title>
            <content>
              <para>
                As firmware provides the underlying functionality for hardware it is essential that the integrity of any firmware images or updates are maintained.
              </para>
            </content>
            <controls>
              <block>
                <ID>0303</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AA</authority>
                <title>Firmware updates</title>
                <content>
                  <para>
                    Agencies must ensure that any firmware updates are performed in a manner that verifies the integrity and authenticity of the updating process.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Unsupported software and products</title>
            <content>
              <para>
                Once a cessation date for support is announced for software or ICT equipment, agencies will find it increasingly difficult to protect against vulnerabilities found in the software or equipment as no security patches will be made available by the vendor. Once a cessation date for support is announced agencies should investigate new solutions that will be appropriately supported.
              </para>
            </content>
            <controls>
              <block>
                <ID>0304</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Unsupported software and products</title>
                <content>
                  <para>
                    Agencies must assess the risk of using software or ICT equipment when a cessation date for support is announced or when the software or equipment is no longer supported by the vendor.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Default passphrases and accounts</title>
            <content>
              <para>
                Default passphrases and accounts for operating systems are often exploited by attackers as they are well documented in product manuals and can be easily checked in an automated manner with little effort required. When default passphrases are changed they must meet the requirements in the Access Control chapter of this manual.
              </para>
            </content>
            <controls>
              <block>
                <ID>0383</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Default passphrases and accounts</title>
                <content>
                  <list>
                    <head>Agencies must reduce potential vulnerabilities in their SOEs by:</head>
                    <item>
                      removing unused accounts
                    </item>
                    <item>
                      renaming or deleting default accounts
                    </item>
                    <item>
                      replacing default passphrases.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Functional separation between servers</title>
            <content>
              <para>
                Servers with a high value include those in a gateway environment such as web, email, file and Internet Protocol (IP) telephony servers.
              </para>
              <para>
                Agencies may also implement separation through the use of techniques to restrict a process to a limited portion of the file system, but this is less effective.
              </para>
            </content>
            <controls>
              <block>
                <ID>0385</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Functional separation between servers</title>
                <content>
                  <list>
                    <head>Where high value servers have connectivity to public network infrastructure, agencies should:</head>
                    <item>
                      maintain effective functional separation between servers allowing them to operate independently
                    </item>
                    <item>
                      minimise communications between servers at both the network and file system level as appropriate
                    </item>
                    <item>
                      limit system users and programs to the minimum access needed to perform their duties.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0953</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Functional separation between servers</title>
                <content>
                  <list>
                    <head>Agencies should ensure that functional separation between servers is achieved either:</head>
                    <item>
                      physically, using single dedicated machines for each function
                    </item>
                    <item>
                      using virtualisation technology to create separate virtual machines for each function in the same security domain.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Using virtualisation for functional separation between servers</title>
            <content>
              <para>
                Virtualisation is approved as a method of achieving functional separation between servers if the servers reside in the same security domain. Virtualisation is not approved as a domain separation method.
              </para>
            </content>
            <controls>
              <block>
                <ID>0841</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Using virtualisation for functional separation between servers</title>
                <content>
                  <para>
                    Virtualisation technology should not be used for functional separation between servers in different security domains at the same classification.
                  </para>
                </content>
              </block>
              <block>
                <ID>0842</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Using virtualisation for functional separation between servers</title>
                <content>
                  <para>
                    Virtualisation technology must not be used for functional separation between servers of different classifications.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Characterisation</title>
            <content>
              <para>
                Characterisation is a technique used to analyse and record a system’s configuration. It is important since it can be used to verify the system’s integrity at a later date.
              </para>
              <list>
                <head>Methods of characterising files and directories include:</head>
                <item>
                  performing a cryptographic checksum on files/directories when they are known to be virus/malware free
                </item>
                <item>
                  documenting the name, type, size and attributes of legitimate files and directories, along with any changes to this information expected under normal operating conditions
                </item>
                <item>
                  for a Windows system, taking a system difference snapshot.
                </item>
              </list>
              <para>
                There are known techniques for defeating basic characterisations. Therefore other methods of intrusion detection are also needed, particularly in situations where it is impractical to use a trusted operating environment for the generation of the characterisation data. However, it is very useful in post-intrusion forensic investigations where an infected disk can be compared to stored characterisation data in order to determine what files have been changed or introduced.
              </para>
            </content>
            <controls>
              <block>
                <ID>0386</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Characterisation</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      characterise all servers whose functions are critical, and those identified as being at a high risk of compromise
                    </item>
                    <item>
                      store the characterisation information securely off the server in a manner that maintains its integrity
                    </item>
                    <item>
                      update the characterisation information after every legitimate change to a system
                    </item>
                    <item>
                      as part of the audit schedule, compare the stored characterisation information against current characterisation information to determine whether a compromise, or a legitimate but incorrectly completed system modification, has occurred
                    </item>
                    <item>
                      perform the characterisation from a trusted environment rather than the standard operating system wherever possible
                    </item>
                    <item>
                      resolve any detected changes in accordance with cyber security incident management procedures.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0954</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Characterisation</title>
                <content>
                  <para>
                    Agencies should meet the requirement for characterisation using a DSD Approved Cryptographic Algorithm to perform cryptographic checksums.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Automated outbound connections by software</title>
            <content>
              <para>
                Examples of applications that include beaconing functionality are applications that initiate a connection to the vendor website over the Internet (a continuous signalling of error or location information) and applications for inbound remote management.
              </para>
            </content>
            <controls>
              <block>
                <ID>0387</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Automated outbound connections by software</title>
                <content>
                  <para>
                    Agencies should review all software applications to determine whether they attempt to establish any external connections.
                  </para>
                </content>
              </block>
              <block>
                <ID>0388</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Automated outbound connections by software</title>
                <content>
                  <para>
                    If automated outbound connection functionality is included, agencies should make a business decision to determine whether to permit or deny these connections, including an assessment of the security risks involved in doing so.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Knowledge of software used on systems</title>
            <content>
              <list>
                <head>Information about installed software that could be disclosed includes:</head>
                <item>
                  user agent on web requests disclosing the web browser type
                </item>
                <item>
                  network and email client information in email headers
                </item>
                <item>
                  email server software headers.
                </item>
              </list>
              <para>
                This information could provide a malicious entity with knowledge of how to tailor attacks to exploit vulnerabilities in the systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0381</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Knowledge of software used on systems</title>
                <content>
                  <para>
                    Agencies should limit the disclosure of software installed on their systems.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Independent testing of different antivirus and other Internet security software and their effectiveness can be found at http://www.av-comparatives.org/.
              </para>
              <para>
                Further information on the Whole of Government COE can be found at http://www.finance.gov.au/e-government/strategy-and-governance/Whole-of-Government-ICT-Policies.html.
              </para>
            </content>
          </block>
        </references>
      </section>


      <section>
        <title>Application Whitelisting</title>

        <objective>
          <block>
            <content>
              <para>
                Only approved applications are used on operating systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the use of technical controls to restrict the specific applications that can be accessed by a system user or group of system users.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								Application whitelisting is an approach in which all executables and applications are prevented from executing by default. Those that are allowed to execute are explicitly specified.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Application whitelisting</title>
            <content>
							<para>
								Application whitelisting can be an effective mechanism to prevent the compromise of a system resulting from the exploitation of vulnerabilities in an application or from the execution of malicious code.
							</para>
							<para>
								Defining a list of trusted executables—a whitelist—is a more practical and secure method of securing a system than relying on a list of bad executables to be prevented from running—a blacklist.
							</para>
							<para>
								Application whitelisting is just one part of a defence-in-depth strategy for preventing attacks and reducing the consequences of attacks.
							</para>
						</content>
            <controls>
              <block>
                <ID>0843</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Application whitelisting</title>
                <content>
                  <para>
                    Agencies must implement application whitelisting as part of the SOE for both workstations and servers.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System user permissions</title>
						<content>
							<para>
								An average system user requires access to only a few applications, or groups of applications, in order to conduct their work. Restricting the system user’s permissions to this limited set of applications reduces the opportunities for attacking the system.
							</para>
						</content>
            <controls>
              <block>
                <ID>0844</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user permissions</title>
				<content>
					<para>
					  Agencies must prevent a system user from running arbitrary executables. 
					</para>
				</content>
              </block>
              <block>
                <ID>0845</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user permissions</title>
                <content>
                  <para>
                    Agencies must restrict a system user’s rights in order to permit them to only execute a specific set of predefined executables as required for them to complete their duties.
                  </para>
                </content>
              </block>
              <block>
                <ID>0846</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user permissions</title>
                <content>
                  <para>
                    Agencies must ensure that a system user cannot disable the application whitelisting mechanism.
                  </para>
                </content>
              </block>
              <block>
                <ID>0847</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user permissions</title>
                <content>
                  <para>
                    Agencies must ensure that application whitelisting does not replace antivirus and other Internet security software already in place for a system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System administrator permissions</title>
						<content>
							<para>
								Since the consequences of running malicious code as a privileged user are much more severe than as an unprivileged user, application whitelisting must also be enforced for system administrators.
							</para>
						</content>
            <controls>
              <block>
                <ID>0848</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System administrator permissions</title>
                <content>
                  <para>
                    Agencies must ensure that system administrators are not exempt from application whitelisting policy.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Application whitelisting configuration</title>
            <content>
							<para>
								A decision to execute should be made based on cryptographic hash as it is more secure than a decision based on the executable’s signature, path or parent folder.
							</para>
							<para>
								In order for application whitelisting to be effective, an agency must initially gather information on necessary executables and applications in order to ensure that the implementation is fully effective.
							</para>
							<para>
								Different application whitelisting controls, such as restricting execution based on cryptographic hash or folder, have various advantages and disadvantages. Agencies need to be aware of this when implementing application whitelisting.
							</para>
							<para>
								Application whitelisting based on parent folder or executable path is futile if access control list permissions allow a system user to write to the folders or overwrite permitted executables.
							</para>
							<para>
								Adequate logging information can allow system administrators to further refine the application whitelisting implementation and detect patterns of occurrences of system users being denied access.
							</para>
						</content>
            <controls>
              <block>
                <ID>0849</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Application whitelisting configuration</title>
                <content>
                  <para>
                    Agencies must ensure that the default policy is to deny the execution of software.
                  </para>
                </content>
              </block>
              <block>
                <ID>0851</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Application whitelisting configuration</title>
                <content>
                  <para>
                    Agencies should plan and test application whitelisting thoroughly prior to implementation.
                  </para>
                </content>
              </block>
              <block>
                <ID>0955</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Application whitelisting configuration</title>
                <content>
                  <list>
                    <head>Agencies should restrict the decision whether to run an executable based on the following, in the order of preference shown:</head>
                    <item>
                      cryptographic hash
                    </item>
                    <item>
                      executable absolute path
                    </item>
                    <item>
                      digital signature
                    </item>
                    <item>
                      parent folder.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0956</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Application whitelisting configuration</title>
                <content>
                  <para>
                    Agencies should restrict the write access to folders of any executables which are permitted to run by the application whitelisting controls.
                  </para>
                </content>
              </block>
              <block>
                <ID>0957</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Application whitelisting configuration</title>
                <content>
                  <para>
                    Agencies should ensure logs from the application whitelisting implementation include all relevant information such as the enforcement setting, file name, date and time, and user name.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on application whitelisting as implemented using AppLocker by Microsoft can be found at http://technet.microsoft.com/en-us/library/dd723678(WS.10).aspx.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Web Content and Connections</title>
        <objective>
          <block>
            <content>
              <para>
                Access to web content is implemented in a secure and accountable manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes web browsers, plug-ins and active content including developing and implementing appropriate usage policies. The requirements in this section apply equally to websites accessed via the Internet as well as websites accessed on an intranet.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								This section covers factors that need to be taken into consideration when creating policy for the use of web applications to ensure the confidentiality, integrity and availability of information and to protect against the execution and spread of malware.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Web usage policy</title>
						<content>
							<para>
								If agencies allow system users to access the Web they will need to define the extent of web access that is granted. This can be achieved through a web usage policy and education of system users.
							</para>
						</content>
            <controls>
              <block>
                <ID>0258</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Web usage policy</title>
                <content>
                  <para>
                    Agencies must have a policy governing appropriate web usage.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Web proxy</title>
						<content>
							<para>
								Web proxies provide valuable information in determining if malicious code is performing regular interactions over web traffic. Web proxies also provide usable information if system users are violating web usage policies.
							</para>
						</content>
            <controls>
              <block>
                <ID>0260</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Web proxy</title>
                <content>
                  <para>
                    Agencies should use a web proxy for all web browsing activities.
                  </para>
                </content>
              </block>
              <block>
                <ID>0261</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Web proxy</title>
				<content>
					<list>
					  <head>A web proxy should authenticate system users and provide logging that includes the following details about websites accessed:</head>
					  <item>address (uniform resource locator)</item>
					  <item>time/date</item>
					  <item>system user</item>
					  <item>amount of data uploaded and downloaded</item>
					  <item>internal IP address</item>
					  <item>external IP address.</item>
					</list>
				</content>
              </block>
              <block>
                <ID>1149</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Web proxy</title>
                <content>
                  <para>
                    Agencies should block system users without a demonstrated business requirement from downloading executable files from external websites.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Applications and plug-ins</title>
							<content>
								<para>
									Web browsers can be configured to allow the automatic launching of downloaded files. This can occur with or without the system user’s knowledge thus making the workstation vulnerable to attack.
								</para>
							</content>	
            <controls>
              <block>
                <ID>0262</ID>
                <revision>0</revision>
<updated>Sep-08</updated>
 <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Applications and plug-ins</title>
                <content>
                  <para>
                    Agencies should block the automatic launching of files downloaded from external websites.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Secure Sockets Layer and Transport Layer Security filtering</title>
						<content>
							<para>
								Since Secure Sockets Layer (SSL) and Transport Layer Security (TLS) web traffic travelling over Hypertext Transfer Protocol Secure (HTTPS) connections can deliver content without any filtering, agencies can reduce this security risk by using SSL and TLS inspection so that web traffic can be filtered.
							</para>
							<para>
								An alternative to SSL and TLS inspection for HTTPS websites is to allow websites that have a low risk of delivering malicious code and have a high privacy requirement, such as Internet banking, to continue to have end-to-end encryption.
							</para>
            </content>
            <controls>
              <block>
                <ID>0263</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Secure Sockets Layer and Transport Layer Security filtering</title>
                <content>
                  <list>
                    <head>Agencies permitting SSL and TLS through their gateways should implement either:</head>
                    <item>
                      a solution that decrypts and inspects the SSL and TLS traffic as per content filtering requirements
                    </item>
                    <item>
                      a whitelist specifying the addresses (uniform resource locators) to which encrypted connections are permitted, with all other addresses either blocked or decrypted and inspected as per content filtering requirements.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Inspection of Secure Sockets Layer and Transport Layer Security traffic</title>
							<content>
								<para>
									As encrypted SSL and TLS traffic may contain personally identifiable information agencies are recommended to seek legal advice on whether inspecting such traffic could be in breach of the Privacy Act 1988.
								</para>
							</content>
            <controls>
              <block>
                <ID>0996</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Inspection of Secure Sockets Layer and Transport Layer Security traffic</title>
                <content>
                  <para>
                    Agencies should seek legal advice regarding the inspection of encrypted SSL and TLS traffic by their gateways.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Whitelisting websites</title>
						<content>
							<para>
								Defining a whitelist of permitted websites and blocking all unlisted websites effectively removes one of the most common data delivery and exfiltration techniques used by malicious code. However, if system users have a legitimate requirement to access a numerous and rapidly changing list of websites, agencies will need to consider the costs of such an implementation.
							</para>
						</content>	
            <controls>
              <block>
                <ID>0958</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Whitelisting websites</title>
                <content>
                  <para>
                    Agencies should implement whitelisting for all Hypertext Transfer Protocol traffic being communicated through their gateways.
                  </para>
                </content>
              </block>
              <block>
                <ID>0995</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Whitelisting websites</title>
                <content>
                  <para>
                    Agencies using a whitelist on their gateways to specify the external addresses to which connections are permitted, should specify whitelist addresses by domain name or IP address.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Categorising websites</title>
						<content>
							<para>
								Websites can be grouped into categories and non work related categories can be blocked via a web content filter. There are specialised devices that categorise and allow access to websites.
							</para>
						</content>
            <controls>
              <block>
                <ID>1170</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Categorising websites</title>
                <content>
                  <para>
                    If agencies do not whitelist websites they should implement categories for all websites and block prohibited categories and uncategorised sites.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Blacklisting websites</title>
						<content>
							<para>
								Blacklists are collections of websites that have been deemed to be inappropriate due to their content or hosting of malicious content. Sites are listed individually and can be categorised.
							</para>
							<para>
								Agencies can extend blacklists to include dynamic and other domains where domain names can be registered anonymously for free. Intrusions commonly use such domains due to their lack of attribution.
							</para>
						</content>
            <controls>
              <block>
                <ID>0959</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Blacklisting websites</title>
                <content>
                  <para>
                    If agencies do not whitelist websites they should blacklist websites to prevent access to known malicious websites.
                  </para>
                </content>
              </block>
              <block>
                <ID>0960</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Blacklisting websites</title>
                <content>
                  <para>
                    Agencies blacklisting websites should update the blacklist on a daily basis to ensure that it remains effective.
                  </para>
                </content>
              </block>
              <block>
                <ID>1171</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Blacklisting websites</title>
                <content>
                  <para>
                    Agencies should block attempts to access a website through its IP address instead of through its domain name.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Client-side active content</title>
						<content>
							<para>
								Software that runs on systems should be controlled. Active content delivered though websites should be constrained so that it cannot arbitrarily access system users’ files or deliver malicious code. Unfortunately the implementations of web browsers regularly contain flaws that permit such activity.
							</para>
						</content>
            <controls>
              <block>
                <ID>0961</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Client-side active content</title>
                <content>
                  <para>
                    Agencies should block client-side active content, such as Java and ActiveX, which might not have a large business impact.
                  </para>
                </content>
              </block>
              <block>
                <ID>0962</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Client-side active content</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      use client-side controls that allow JavaScript on a per website basis
                    </item>
                    <item>
                      add JavaScript functions used only for malicious purposes to the web content filter or IDS.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Web content filter</title>
						<content>
							<para>
								Using a web proxy provides an opportunity to filter out potentially harmful information to system users and their workstations.
							</para>
						</content>
            <controls>
              <block>
                <ID>0963</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Web content filter</title>
                <content>
                  <para>
                    Agencies should use the web proxy to filter content that is potentially harmful to system users and their workstations.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                A web whitelisting software application that allows for the management of whitelists can be obtained from http://whitetrash.sourceforge.net/.
              </para>
              <para>
                The sites http://www.shallalist.de/ and http://www.urlblacklist.com/ contain lists and categories of sites that can be used to block access too.
              </para>
              <para>
                Examples of client-side JavaScript controls are available at http://noscript.net/.
              </para>
              <para>
                A list of JavaScript functions that are typically used for malicious purposes is listed on the OnSecure website at https://members.onsecure.gov.au/.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Email Applications</title>
        <objective>
          <block>
            <content>
              <para>
                Email messages have appropriate protective markings and active content is controlled.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes protective markings on email and active content in email.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
            <para>
              Information on email infrastructure is located in the Email Infrastructure section of the Network Security chapter.
            </para>
					</content>
          </block>
					<block>
            <title>Automatically generated emails</title>
						<content>
            <para>
              The requirements for emails in this section apply equally to automatically generated emails.
            </para>
					</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Email usage policy</title>
						<content>
							<para>
								There are many security risks associated with the non-secure nature of email that are often overlooked. Documenting them will inform information owners about these security risks and how they might affect business operations.
							</para>
						</content>
            <controls>
              <block>
                <ID>0264</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Email usage policy</title>
                <content>
                  <para>
                    Agencies must have a policy governing the use of email.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Email active content</title>
						<content>
							<para>
								Software that runs on systems should be controlled. Active content delivered though email, especially on Internet facing systems, should be constrained so that it cannot arbitrarily access system users’ files or deliver malicious code. Unfortunately the implementation of email permits such activity.
							</para>
							<para>
								If active content is displayed automatically in the preview pane it can run even though an email item has not been explicitly opened. If active content is allowed, restricting the preview pane to only render content as plaintext ensures emails from a suspicious source would need a system user to make a conscious decision to open an email before the active content is displayed.
							</para>
						</content>
            <controls>
              <block>
                <ID>1172</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Email active content</title>
                <content>
                  <para>
                    Agencies should block client-side active content, by viewing email in plain text mode instead of in Rich Text Format or Hypertext Markup Language mode.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Email distribution</title>
						<content>
							<para>
								Often the membership and nationality of members of email distribution lists is unknown. Therefore system users sending sensitive emails with Australian Eyes Only (AUSTEO), Australian Government Access Only (AGAO) or other nationality releasability marked information to distribution lists could accidentally cause a data spill.
							</para>
            </content>
            <controls>
              <block>
                <ID>0269</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Email distribution</title>
                <content>
                  <para>
                    Agencies should ensure that emails containing AUSTEO, AGAO or other nationality releasability marked information are only sent to named recipients and not to groups or distribution lists unless the nationality of all members of the distribution lists can be confirmed.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Marking emails</title>
						<content>
							<para>
								As for paper-based information, all electronic-based information needs to be marked with an appropriate protective marking. This ensures that appropriate security measures are applied to the information and prevents unauthorised information being released into the public domain.
							</para>
							<para>
								When a protective marking is applied to an email it is important that it reflects the sensitivity or classification of the information in the body of the email and in any attachments to the email.
							</para>
							<para>
								Emails that do not contain official government information are recommended to be marked with an UNOFFICIAL protective marking to clearly indicate the email is of a personal nature.
							</para>
            </content>
            <controls>
              <block>
                <ID>0273</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Marking emails</title>
                <content>
                  <para>
                    All official emails must have a protective marking.
                  </para>
                </content>
              </block>
              <block>
                <ID>0275</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Marking emails</title>
                <content>
                  <para>
                    Email protective markings must accurately reflect each element of an email, including attachments.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Emails from outside the government</title>
						<content>
							<para>
								If an email is received from outside government the system user has an obligation to determine the appropriate security measures for the email if it is to be responded to, forwarded on or printed out.
							</para>
						</content>
            <controls>
              <block>
                <ID>0278</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Emails from outside the government</title>
                <content>
                  <para>
                    Where an unmarked email has originated outside the government, system users must assess the information and determine how it is to be handled.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Marking personal emails</title>
						<content>
							<para>
								Applying incorrect protective markings to emails that do not contain government information places an extra burden on protecting emails that do not need protection.
							</para>
						</content>
            <controls>
              <block>
                <ID>0852</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Marking personal emails</title>
                <content>
                  <para>
                    Where an email is of a personal nature and does not contain government information, protective markings for official information should not be used.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Receiving unmarked emails</title>
						<content>
							<para>
								If an email is received without a protective marking the system user has an obligation to contact the originator to seek clarification on the appropriate security measures for the email. Alternatively, where the system user receives unmarked non-government emails as part of its business practice the application of protective markings can be automated by a system.
							</para>
						</content>
            <controls>
              <block>
                <ID>0967</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Receiving unmarked emails</title>
                <content>
                  <para>
                    Where an unmarked email has originated from an Australian or overseas government agency, system users should contact the originator to determine how it is to be handled.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Receiving emails with unknown protective markings</title>
						<content>
							<para>
								If an email is received with a protective marking that the system user is not familiar with, they have an obligation to contact the originator to clarify the protective marking and the appropriate security measures for the email.
							</para>
						</content>
            <controls>
              <block>
                <ID>0968</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Receiving emails with unknown protective markings</title>
                <content>
                  <para>
                    Where an email is received with an unknown protective marking from an Australian or overseas government agency, system users should contact the originator to determine appropriate security measures.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Protective marking standard</title>
						<content>
							<para>
								Applying markings that reflect the protective requirements of an email informs the recipient on how to appropriately handle the email.
							</para>
							<para>
								The application of protective markings as per the AGIMO standard facilitates interoperability across government must be followed.
							</para>
						</content>
            <controls>
              <block>
                <ID>0270</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Protective marking standard</title>
                <content>
                  <para>
                    Agencies must comply with the standard for the application of protective markings to emails as promulgated by AGIMO.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Marking tools</title>
						<content>
							<para>
								Requiring system user intervention in the marking of system user generated emails assures a conscious decision by the system user, lessening the chance of incorrectly marked emails.
							</para>
							<para>
								Allowing system users to choose only protective markings for which the system is accredited lessens the chance of a system user inadvertently over-classifying an email. It also reminds them of the maximum sensitivity or classification of information permitted on the system.
							</para>
							<para>
								Gateway filters can only check the most recent protective marking applied to an email. Therefore when system users are forwarding or responding to an email, forcing them to apply a protective marking that is at least as high as that of the email they received will help gateway filters prevent emails being sent to systems that are not accredited to handle the original sensitivity or classification of the email.
							</para>
						</content>
            <controls>
              <block>
                <ID>0271</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Marking tools</title>
                <content>
                  <para>
                    Agencies should not allow a protective marking to be inserted into system user generated emails without their intervention.
                  </para>
                </content>
              </block>
              <block>
                <ID>0272</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Marking tools</title>
                <content>
                  <para>
                    Agencies providing a marking tool should not allow system users to select protective markings that the system has not been accredited to process, store or communicate.
                  </para>
                </content>
              </block>
              <block>
                <ID>1089</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Marking tools</title>
                <content>
                  <para>
                    Agencies providing a marking tool should not allow system users replying to or forwarding an email to select a protective marking that is lower than previously used for the email.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Printing</title>
						<content>
							<para>
								The Australian Government Information Security Management Protocol requires that paper-based information have the protective marking of the information placed at the top and bottom of each piece of paper.
							</para>
						</content>
            <controls>
              <block>
                <ID>0969</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Printing</title>
                <content>
                  <para>
                    Agencies should configure systems so that the protective markings appear at the top and bottom of every page when the email is printed.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                The AGIMO email protective markings standard and its associated implementation guide are available from http://www.finance.gov.au/e-government/security-and-authentication/authentication-identity.html.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Software Application Development</title>
        <objective>
          <block>
            <content>
              <para>
                Secure programming methods and testing are used for software application development.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes developing, upgrading and maintaining application software used on systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								By following the guidelines in this section, the software flaws and vulnerabilities which are able to be exploited by an attacker will be considered and addressed.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Software development environments</title>
						<content>
							<para>
								Segregating development, testing and production environments limits the spread of malicious code and minimises the likelihood of faulty code being put into production.
							</para>
							<para>
								Limiting access to development and testing environments will reduce the information that can be gained by an internal attacker.
							</para>
						</content>
            <controls>
              <block>
                <ID>0400</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Software development environments</title>
                <content>
                  <list>
                    <head>Agencies should ensure that software development environments are configured such that:</head>
                    <item>
                      there are at least three environments covering:
                      <list>
                        <item>
                          development
                        </item>
                        <item>
                          testing
                        </item>
                        <item>
                          production
                        </item>
                      </list>
                    </item>
                    <item>
                      information flow between the environments is strictly limited according to a defined and documented policy, with access granted only to system users with a clear business requirement
                    </item>
                    <item>
                      new development and modifications only take place in the development environment
                    </item>
                    <item>
                      write access to the authoritative source for the software is disabled.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Secure programming</title>
						<content>
							<para>
								Designing software to use the lowest privilege level needed to achieve its task will limit the privileges an attacker could gain should they subvert the software security.
							</para>
							<para>
								Validating all inputs will ensure that the input is within expected ranges, reducing the chance that malicious or erroneous input causes unexpected results.
							</para>
						</content>
            <controls>
              <block>
                <ID>0401</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Secure programming</title>
                <content>
                  <list>
                    <head>Agencies should ensure that software developers use secure programming practices when writing code, including:</head>
                    <item>
                      designing software to use the lowest privilege level needed to achieve its task
                    </item>
                    <item>
                      denying access by default
                    </item>
                    <item>
                      checking return values of all system calls
                    </item>
                    <item>
                      validating all inputs.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Software testing</title>
						<content>
							<para>
								Software reviewing and testing will lessen the possibility of vulnerabilities being introduced into a production environment.
							</para>
							<para>
								Using an independent party for software testing will remove any bias that can occur when a developer tests their own software.
							</para>
						</content>
            <controls>
              <block>
                <ID>0402</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Software testing</title>
                <content>
                  <para>
                    Software should be reviewed or tested for vulnerabilities before it is used in a production environment.
                  </para>
                </content>
              </block>
              <block>
                <ID>0403</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Software testing</title>
                <content>
                  <para>
                    Software should be reviewed or tested by an independent party as well as the developer.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                An example of a 'Secure Development Lifecycle' model, used by Microsoft in the development of all versions of Windows since Windows 2003, can be found at http://msdn.microsoft.com/en-us/library/ms995349.aspx.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Web Application Development</title>
        <objective>
          <block>
            <content>
              <para>
                Security measures are incorporated into all web applications.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes developing, upgrading and maintaining web applications used on systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Protecting web servers</title>
            <content>
              <para>
                Even though web servers may only contain information authorised for release into the public domain there still remains a need to protect the integrity and availability of the information. Web servers are therefore to be treated in accordance with the requirements of the sensitivity or classification of the system they are connected to.
              </para>
            </content>
          </block>
          <block>
            <title>Web application components</title>
            <content>
              <para>
                Web application components at a high level consist of a web server for presentation, a web application for processing and a database for content storage. There can be more or less components, however in general there is a presentation layer, application layer and database layer.
              </para>
            </content>
          </block>
        </context>

        <controlsTitle>
          <block>
            <title>Website content</title>
						<content>
							<para>
								Reviewing web applications on web servers will assist in identifying and mitigating information security issues such as buffer overflows and Structured Query Language injection vulnerabilities.
							</para>
						</content>
            <controls>
              <block>
                <ID>0389</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Website content</title>
                <content>
                  <para>
                    Agencies should review all web applications on their web servers for information security issues.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Segregation of web application components</title>
						<content>
							<para>
								Web applications are typically very exposed services that provide complex interactions with system users. This greatly increases the security risk of being compromised. Segregating components limits the impact of potential application flaws.
							</para>
						</content>
            <controls>
              <block>
                <ID>0390</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Segregation of web application components</title>
                <content>
                  <para>
                    Agencies should minimise connectivity and access between each web application component.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Web applications</title>
						<content>
							<para>
								The Open Web Application Security Project guide provides a comprehensive resource to consult when developing web applications.
							</para>
						</content>
            <controls>
              <block>
                <ID>0971</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Web applications</title>
                <content>
                  <para>
                    Agencies should follow the documentation provided in the Open Web Application Security Project guides to building secure web applications and web services.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on web application security is available from the Open Web Application Security Project at https://www.owasp.org/index.php/Main_Page.
              </para>
            </content>
          </block>
        </references>
      </section>

      <section>
        <title>Databases</title>
        <objective>
          <block>
            <content>
              <para>
                Database content is limited to system users with a need-to-know.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes databases and their interfaces, such as search engines.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								The use of data labelling, control of access and logging system users’ access to databases and search engines will protect the confidentiality of information and ensure that information can only be accessed by those intended and authorised to do so.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Data labelling</title>
						<content>
            <para>
              Protective markings can be applied to records, tables or to the database as a whole, depending on its structure and use.
            </para>
					</content>
            <controls>
              <block>
                <ID>0391</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Data labelling</title>
                <content>
                  <list>
                    <head>Agencies should ensure that all information stored in a database is associated with an appropriate protective marking if either the information:</head>
                    <item>
                      could be exported to a different system
                    </item>
                    <item>
                      contains differing sensitivities or classifications.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0393</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Data labelling</title>
                <content>
                  <list>
                    <head>Agencies must ensure that all information stored in a database is associated with an appropriate protective marking if either the information:</head>
                    <item>
                      could be exported to a different system
                    </item>
                    <item>
                      contains differing sensitivities or classifications.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0392</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Data labelling</title>
                <content>
                  <para>
                    Agencies should ensure that protective markings are applied with a level of granularity sufficient to clearly define the handling requirements for any information retrieved or exported from a database.
                  </para>
                </content>
              </block>
              <block>
                <ID>0394</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Data labelling</title>
                <content>
                  <para>
                    Agencies must ensure that protective markings are applied with a level of granularity sufficient to clearly define the handling requirements for any information retrieved or exported from a database.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Database files</title>
			<content>
				<para>Even though a database may provide access controls to the information it provides, the database files will still need to be protected.</para>
			</content>
            <controls>
              <block>
                <ID>0395</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Database files</title>
                <content>
                  <para>
                    Agencies should protect database files from access that bypasses the database’s normal access controls.
                  </para>
                </content>
              </block>
              <block>
                <ID>0396</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Database files</title>
                <content>
                  <para>Agencies must protect database files from access that bypasses the database’s normal access controls.</para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Accountability</title>
			<content>
				<para>If system users’ interactions with databases are not logged and audited, agencies will not be able to appropriately investigate any misuse or compromise of database content.</para>
			</content>
            <controls>
              <block>
                <ID>0397</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Accountability</title>
                <content>
                  <para>Agencies should ensure that databases provide functionality to allow for auditing of system users’ actions.</para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Search engines</title>
			<content>
				<para>Even if a search engine prevents system users viewing information that they do not have sufficient security clearances to access, the associated metadata could contain information above the security clearances of the system user. In such cases, restricting access to, or sanitising, this metadata prevents system users seeing information they are not cleared to view.</para>
			</content>
            <controls>
              <block>
                <ID>0398</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Search engines</title>
                <content>
                  <para>
                    Agencies should ensure that system users who do not have sufficient security clearances to view database contents cannot see associated metadata in a list of results from a search engine query.
                  </para>
                </content>
              </block>
              <block>
                <ID>0399</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Search engines</title>
                <content>
                  <para>If results from database queries cannot be appropriately filtered, agencies must ensure that all query results are appropriately sanitised to meet the minimum security clearances of system users. </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Access Control</title>
      <section>
        <title>Identification and Authentication</title>
        <objective>
          <block>
            <content>
              <para>
                Passphrase selection policies and passphrase management practices are implemented on systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the identification and authentication for all system users.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Methods for user identification and authentication</title>
            <content>
              <para>
                User authentication can be achieved by various means, including biometrics, cryptographic tokens, passphrases, passwords and smartcards. Where this manual refers to passphrases it equally applies to passwords.
              </para>
              <list>
                <head>Multi-factor authentication uses independent means of evidence to assure an entity’s identity. The three authentication methods are: </head>
                <item>
                  something one knows, such as a passphrase or a response to a challenge
                </item>
                <item>
                  something one has, such as a passport, physical token or an identity card
                </item>
                <item>
                  something one is, such as biometric data, like a fingerprint or face geometry.
                </item>
              </list>
              <para>
                Any two of these authentication methods must be used to achieve multi-factor authentication. If something that one knows, such as the passphrase, is written down or typed into a file and stored in plain text, this evidence becomes something that one has and can defeat the purpose of multi-factor authentication.
              </para>
              <para>
                Strong identification and authentication mechanisms significantly reduce the security risk that unauthorised users will gain access to a system.
              </para>
            </content>
          </block>
        </context>

        <controlsTitle>
          <block>
            <title>Policies and procedures</title>
						<content>
            <para>
              Developing policies and procedures will ensure consistency in identification, authentication and authorisation.
            </para>
						</content>
            <controls>
              <block>
                <ID>0413</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Policies and procedures</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
										<list>
											<head>
												develop and maintain a set of policies and procedures covering system users’:
											</head>
											<item>
												identification
											</item>
											<item>
												authentication
											</item>
											<item>
												authorisation
											</item>
										</list>
                    <item>
                      make their system users aware of the policies and procedures.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System user identification</title>
						<content>
            <para>
              Having uniquely identifiable system users ensures accountability.
            </para>
					</content>
            <controls>
              <block>
                <ID>0414</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user identification</title>
                <content>
                  <list>
                    <head>Agencies must ensure that all system users are:</head>
                    <item>
                      uniquely identifiable
                    </item>
                    <item>
                      authenticated on each occasion that access is granted to a system.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Identification of foreign nationals</title>
						<content>
            <para>
              Where systems contain Australian Eyes Only (AUSTEO), Australian Government Access Only (AGAO) or other nationality releasability marked information, with foreign nationals having access to such systems, it is important that agencies implement appropriate security measures to ensure identification of system users who are foreign nationals. Such security measures can help prevent the release of particularly sensitive information to those not authorised to access it.
            </para>
						</content>
            <controls>
              <block>
                <ID>0420</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Identification of foreign nationals</title>
                <content>
                  <para>
                    Where systems contain AUSTEO, AGAO or other nationality releasability marked information, agencies must implement appropriate security measures to ensure identification of system users who are foreign nationals, including seconded foreign nationals.
                  </para>
                </content>
              </block>
              <block>
                <ID>0975</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Identification of foreign nationals</title>
                <content>
                  <para>
                    Agencies implementing security measures to ensure identification of system users who are foreign nationals, including seconded foreign nationals, should ensure that this identification includes their specific nationality.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Shared accounts</title>
						<content>
            <para>
              Using shared non user-specific accounts can hamper efforts to attribute actions on a system to specific personnel. Agencies allowing the use of non user-specific accounts need to determine an appropriate method of attributing actions undertaken by such accounts to specific personnel. For example, a logbook may be used to document the date and time that a person takes responsibility for using a shared account and the actions logged against the account by the system.
            </para>
						</content>
            <controls>
              <block>
                <ID>0973</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Shared accounts</title>
                <content>
                  <para>
                    Agencies should not use shared non user-specific accounts.
                  </para>
                </content>
              </block>
              <block>
                <ID>0415</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Shared accounts</title>
                <content>
                  <para>
                    Agencies must not use shared non user-specific accounts.
                  </para>
                </content>
              </block>
              <block>
                <ID>0416</ID>
                <revision>0</revision>
<updated>Sep-08</updated>
 <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Shared accounts</title>
                <content>
                  <para>
                    If agencies choose to allow shared, non user-specific accounts they must ensure that another method of determining the identification of the system user is implemented.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Methods for system user identification and authentication</title>
						<content>
							<para>
								A numerical passphrase (or personal identification number) employs a small character set (0-9), making it susceptible to brute force attacks that will be successful in a short period of time.
							</para>
							<para>
								A simple six character passphrase can be brute-forced in minutes by software available on the Web. Passphrases with at least nine characters utilising upper and lower case alphabetic characters, numeric characters and special characters have a much greater resistance to brute force attacks.
							</para>
							<para>
								Due to the computer processing technology available to an attacker, passphrases not meeting the requirements in this manual are able to be retrieved using brute force attacks in a short period of time. Passphrases will have to increase in length and complexity as better processing technology becomes available. To provide a secure authentication mechanism that is not as susceptible to brute force attacks, multi-factor authentication should be used for all accounts. Using multi-factor authentication will reduce the demands on system users to remember long passphrases.
							</para>
							<para>
								Privileged accounts are targeted by attackers as they can potentially allow access to the entire system. Stronger authentication must also be used for positions of trust, such as an account that is able to approve financial transactions or accounts that have access to sensitive information. Positions of trust, including access to sensitive information and databases, and privileged accounts must use multi-factor authentication to provide a secure authentication mechanism.
							</para>
							<para>
								As privileged access should not be used off-site, and if the access for positions of trust is not required remotely, the multi-factor evidence used for something one has should be kept in the office and physically secured according to the requirements in the Australian Government Physical Security Management Protocol as per the sensitivity or classification of the system that it is used to access.
							</para>
						</content>
            <controls>
              <block>
                <ID>0417</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Methods for system user identification and authentication</title>
                <content>
                  <para>
                    Agencies must not use a numerical passphrase (or personal identification number) as the sole method of authenticating a system user.
                  </para>
                </content>
              </block>
              <block>
                <ID>0421</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AH</authority>
                <title>Methods for system user identification and authentication</title>
                <content>
                  <list>
                    <head>Agencies using passphrases as the sole method of authenticating a system user should implement a passphrase policy enforcing either:</head>
                    <item>
                      a minimum length of 12 alphabetic characters with no complexity requirement; or
                    </item>
                    <list>
											<head>
												a minimum length of nine characters, consisting of at least three of the following character sets:
											</head>
											<item>
												lowercase alphabetic characters (a-z)
											</item>
											<item>
												uppercase alphabetic characters (A-Z)
											</item>
											<item>
												numeric characters (0-9)
											</item>
											<item>
												special characters.
											</item>
										</list>
                  </list>
                </content>
              </block>
              <block>
                <ID>0422</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Methods for system user identification and authentication</title>
                <content>
                  <list>
                    <head>Agencies using passphrases as the sole method of authenticating a system user must implement a passphrase policy enforcing either:</head>
                    <item>
                      a minimum length of 15 alphabetic characters with no complexity requirement; or
                    </item>
										<list>
											<head>
												a minimum length of 10 characters, consisting of at least three of the following character sets:
											</head>
											<item>
												lowercase alphabetic characters (a-z)
											</item>
											<item>
												uppercase alphabetic characters (A-Z)
											</item>
											<item>
												numeric characters (0-9)
											</item>
											<item>
												special characters.
											</item>
										</list>
                  </list>
                </content>
              </block>
              <block>
                <ID>1173</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Methods for system user identification and authentication</title>
                <content>
                  <para>
                    Agencies must use multi-factor authentication for privileged access, positions of trust and remote access.
                  </para>
                </content>
              </block>
              <block>
                <ID>0974</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Methods for system user identification and authentication</title>
                <content>
                  <para>
                    Agencies should use multi-factor authentication for all system users.
                  </para>
                </content>
              </block>
              <block>
                <ID>1174</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Methods for system user identification and authentication</title>
                <content>
                  <para>
                    For authenticating positions of trust and privileged access, agencies should secure the multi-factor evidence used for something one has, such as cards and tokens, on the premises where they are used according to the requirements in the Australian Government Physical Security Management Protocol as per the sensitivity or classification of the system that it is used to access.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Protecting stored authentication information</title>
            <content>
							<para>
								Limiting the storage of unprotected authentication information reduces the security risk of an attacker finding and using the information to access a system under the guise of a valid system user.
							</para>
						</content>
            <controls>
              <block>
                <ID>0418</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Protecting stored authentication information</title>
                <content>
                  <para>
                    Agencies must not allow storage of unprotected authentication information that grants system access or decrypts an encrypted device, to be located on, or with, the system or device to which the authentication information grants access.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Protecting authentication data in transit</title>
            <content>
							<para>
								Secure transmission of authentication information reduces the security risk of an attacker intercepting and using the authentication information to access a system under the guise of a valid system user.
							</para>
						</content>
            <controls>
              <block>
                <ID>0419</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Protecting authentication data in transit</title>
                <content>
                  <para>
                    Agencies must ensure that system authentication data is protected when in transit across networks.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Passphrase management</title>
            <content>
							<para>
								Requiring a passphrase to be changed at least every 90 days limits the time period in which a disclosed passphrase could be used by an unauthorised system user.
							</para>
							<para>
								Preventing a system user from changing their passphrase more than once a day stops the system user from immediately changing their passphrase back to their old passphrase.
							</para>
							<para>
								Checking passphrases for compliance with the passphrase selection policy allows system administrators to detect unsafe passphrase selection and ensure that the system user changes it.
							</para>
							<para>
								Forcing a system user to change a passphrase when resetting accounts ensures that the system user changes the passphrase and it is a passphrase that only they know and remember.
							</para>
							<para>
								Disallowing predictable reset passphrases reduces the security risk of brute force attacks and passphrase guessing attacks.
							</para>
							<para>
								Using different passphrases when resetting multiple accounts prevents a system user whose account has been recently reset from logging into another such account.
							</para>
							<para>
								Disallowing passphrases from being reused within eight changes prevents a system user from cycling between a small subset of passphrases.
							</para>
							<para>
								Disallowing sequential passphrases reduces the security risk of an attacker easily guessing a system user’s next passphrase based on their knowledge of the system user’s previous passphrase.
							</para>
						</content>
            <controls>
              <block>
                <ID>0423</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Passphrase management</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      ensure that passphrases are changed at least every 90 days
                    </item>
                    <item>
                      prevent system users from changing their passphrase more than once a day
                    </item>
                    <item>
                      check passphrases for compliance with their passphrase selection policy where the system cannot be configured to enforce complexity requirements
                    </item>
                    <item>
                      force the system user to change an expired passphrase on initial logon or if reset.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0425</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Passphrase management</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      ensure that passphrases are changed at least every 90 days
                    </item>
                    <item>
                      prevent system users from changing their passphrase more than once a day
                    </item>
                    <item>
                      check passphrases for compliance with their passphrase selection policy where the system cannot be configured to enforce complexity requirements
                    </item>
                    <item>
                      force the system user to change an expired passphrase on initial logon or if reset.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0424</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Passphrase management</title>
                <content>
                  <list>
                    <head>Agencies should not:</head>
                    <item>
                      allow predictable reset passphrases
                    </item>
                    <item>
                      reuse passphrases when resetting multiple accounts
                    </item>
                    <item>
                      store passphrases in the clear on the system
                    </item>
                    <item>
                      allow passphrases to be reused within eight passphrase changes
                    </item>
                    <item>
                      allow system users to use sequential passphrases.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0426</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Passphrase management</title>
                <content>
                  <list>
                    <head>Agencies must not:</head>
                    <item>
                      allow predictable reset passphrases
                    </item>
                    <item>
                      reuse passphrases when resetting multiple accounts
                    </item>
                    <item>
                      store passphrases in the clear on the system
                    </item>
                    <item>
                      allow passphrases to be reused within eight passphrase changes
                    </item>
                    <item>
                      allow system users to use sequential passphrases.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Resetting passphrases</title>
						<content>
							<list>
								<head>To reduce the likelihood of social engineering attacks aimed at service desks, agencies need to ensure that system users provide sufficient evidence to verify their identity when requesting a passphrase reset for their system account. This evidence could be in the form of the system user either:</head>
								<item>
									physically presenting themselves and their security pass to service desk personnel who then reset their passphrase
								</item>
								<item>
									physically presenting themselves to a known colleague who uses an approved online tool to reset their passphrase
								</item>
								<item>
									establishing their identity by responding correctly to a number of challenge response questions before resetting their own passphrase.
								</item>
							</list>
						</content>
            <controls>
              <block>
                <ID>0976</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Resetting passphrases</title>
                <content>
                  <para>
                    Agencies must ensure system users provide sufficient evidence to verify their identity when requesting a passphrase reset for their system account.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Passphrase authentication</title>
            <content>
							<para>
								Local Area Network (LAN) Manager’s authentication mechanism uses a very weak hashing algorithm known as the LAN Manager hash algorithm. Passphrases hashed using the LAN Manager hash algorithm can easily be compromised using rainbow tables or brute force attacks.
							</para>
						</content>
            <controls>
              <block>
                <ID>1055</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Passphrase authentication</title>
                <content>
                  <para>
                    Agencies should disable LAN Manager for passphrase authentication on workstations and servers.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Session termination</title>
            <content>
							<para>
								Developing a policy to automatically logout and shutdown workstations after an appropriate time of inactivity helps prevent the compromise of a workstation that has been authenticated to and contains sensitive or classified information in memory. Such a policy also reduces the power consumption of systems during non-operational hours.
							</para>
						</content>
            <controls>
              <block>
                <ID>0853</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Session termination</title>
                <content>
                  <para>
                    Agencies should develop and implement a policy to automatically logout and shutdown workstations after an appropriate time of inactivity.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Session and screen locking</title>
            <content>
							<para>
								Screen and session locking prevents unauthorised access to a system to which an authorised system user has already been authenticated to.
							</para>
							<para>
								Ensuring that the screen does not appear to be turned off while in the locked state prevents system users forgetting they are still logged in and will prevent other system users mistakenly thinking there is a problem with a workstation and resetting it.
							</para>
						</content>
            <controls>
              <block>
                <ID>0427</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Session and screen locking</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      configure systems with a session or screen lock
                    </item>
                    <item>
                      configure the lock to activate either:
                    </item>
                    <item>
                      after a maximum of 15 minutes of system user inactivity
                    </item>
                    <item>
                      if manually activated by the system user
                    </item>
                    <item>
                      configure the lock to completely conceal all information on the screen
                    </item>
                    <item>
                      ensure that the screen is not turned off or enters a power saving state before the screen or session lock is activated
                    </item>
                    <item>
                      have the system user reauthenticate to unlock the system
                    </item>
                    <item>
                      deny system users the ability to disable the locking mechanism.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0428</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Session and screen locking</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      configure systems with a session or screen lock
                    </item>
                    <item>
                      configure the lock to activate either:
                    </item>
                    <item>
                      after a maximum of 10 minutes of system user inactivity
                    </item>
                    <item>
                      if manually activated by the system user
                    </item>
                    <item>
                      configure the lock to completely conceal all information on the screen
                    </item>
                    <item>
                      ensure that the screen is not turned off or enters a power saving state before the screen or session lock is activated
                    </item>
                    <item>
                      have the system user reauthenticate to unlock the system
                    </item>
                    <item>
                      deny system users the ability to disable the locking mechanism.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Suspension of access</title>
            <content>
							<para>
								Locking a system user account after a specified number of failed logon attempts reduces the security risk of brute force attacks.
							</para>
							<para>
								Removing a system user account when it is no longer required prevents personnel accessing their old account and reduces the number of accounts that an attacker can target.
							</para>
							<para>
								Suspending inactive accounts after a specified number of days reduces the number of accounts that an attacker can target.
							</para>
							<para>
								Investigating repeated account lockouts reduces the security risk of any ongoing brute force logon attempts and allows security management to act accordingly.
							</para>
						</content>
            <controls>
              <block>
                <ID>0429</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Suspension of access</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      if an incremental delay is not used, lock system user accounts after five failed logon attempts
                    </item>
                    <item>
                      have a system administrator reset locked accounts
                    </item>
                    <item>
                      remove or suspend system user accounts as soon as possible when personnel no longer need access due to changing roles or leaving the agency
                    </item>
                    <item>
                      remove or suspend inactive accounts after a specified number of days.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0430</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Suspension of access</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      if an incremental delay is not used, lock system user accounts after five failed logon attempts
                    </item>
                    <item>
                      have a system administrator reset locked accounts
                    </item>
                    <item>
                      remove or suspend system user accounts as soon as possible when personnel no longer need access due to changing roles or leaving the agency
                    </item>
                    <item>
                      remove or suspend inactive accounts after a specified number of days.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Investigating repeated account lockouts</title>
            <content>
							<para>
								Repeated account lockouts may be an indication of malicious activity being directed towards compromising a particular account.
							</para>
						</content>
            <controls>
              <block>
                <ID>0431</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Investigating repeated account lockouts</title>
                <content>
                  <para>
                    Agencies should ensure that repeated account lockouts are investigated before reauthorising access.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Logon banner</title>
            <content>
							<para>
								A logon banner for a system reminds system users of their responsibilities when using the system.
							</para>
						</content>
            <controls>
              <block>
                <ID>0408</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Logon banner</title>
                <content>
                  <para>
                    Agencies should have a logon banner that requires a system user to acknowledge and accept their security responsibilities before access to the system is granted.
                  </para>
                </content>
              </block>
			  <block>
				<ID>0979</ID>
				<revision>3</revision>
				<updated>Sep-11</updated>
				<classification>G</classification>
				<classification>P</classification>
				<classification>C</classification>
				<classification>S</classification>
				<classification>TS</classification>
				<compliance>should</compliance>
				<authority>AA</authority>
				<title>Logon banner</title>
				<content>
				  <para>
					Agencies should seek legal advice on the exact wording of logon banners.
				  </para>
				</content>
			  </block>
			  <block>
				<ID>0980</ID>
				<revision>3</revision>
				<updated>Sep-11</updated>
				<classification>G</classification>
				<classification>P</classification>
				<classification>C</classification>
				<classification>S</classification>
				<classification>TS</classification>
				<compliance>should</compliance>
				<authority>AA</authority>
				<title>Logon banner</title>
				<content>
				  <list>
					<head>Logon banners should cover issues such as:</head>
					<item>
					  access only being permitted to authorised system users
					</item>
					<item>
					  the system user’s agreement to abide by relevant information security policies
					</item>
					<item>
					  the system user’s awareness of the possibility that system usage is being monitored
					</item>
					<item>
					  the definition of acceptable use for the system
					</item>
					<item>
					  legal ramifications of violating the relevant policies.
					</item>
				  </list>
				</content>
          </block>
            </controls>
          </block>
          <block>
            <title>Displaying when a system user last logged in</title>
            <content>
							<para>
								Displaying when a system user has last logged onto a system helps system users identify any unauthorised use of their account. Accordingly, when any case of unauthorised use of an account is identified, it should be reported to an Information Technology Security Manager immediately so that it can be investigated.
							</para>
						</content>
            <controls>
              <block>
                <ID>0977</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Displaying when a system user last logged in</title>
                <content>
                  <para>
                    Agencies should configure systems to display the date and time of the system user’s previous login during the login process.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>System Access</title>
        <objective>
          <block>
            <content>
              <para>
                Access to information on systems is controlled through appropriate access controls.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes how systems are accessed. Additional information on security clearance, briefing and authorisation requirements can be found in the Privileged Access section of this chapter and the Authorisations, Security Clearances and Briefings section of the Personnel Security for Systems chapter.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								Enforcing authorisations of system users through the use of access controls on a system helps enforce the need-to-know principle.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Access from foreign controlled systems and facilities</title>
            <content>
							<para>
								If an Australian system is to be accessed from overseas, it needs to be from at least a facility owned by a foreign government with which Australia has a security of information arrangement. Furthermore, due to the sensitivities involved with AUSTEO and AGAO systems, such systems can only be accessed from facilities under the sole control of the government of Australia.
							</para>
						</content>
            <controls>
              <block>
                <ID>0855</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Access from foreign controlled systems and facilities</title>
                <content>
                  <para>
                    Unless a security of information arrangement is in place with a foreign government, agencies should not allow access to sensitive or classified information from systems and facilities not under the sole control of the government of Australia.
                  </para>
                </content>
              </block>
              <block>
                <ID>0854</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Access from foreign controlled systems and facilities</title>
                <content>
                  <para>
                    Agencies must not allow access to AUSTEO or AGAO information from systems and facilities not under the sole control of the government of Australia.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Enforcing authorisations on systems</title>
            <content>
              <list>
                <head>Enforcing authorisations of system users through the use of access controls on a system helps enforce the need-to-know principle. Agencies should follow a process for developing an access control list, such as:</head>
                <item>
                  establish groups of all system resources based on similar security objectives
                </item>
                <item>
                  determine the information owner for each group of resources
                </item>
                <item>
                  establish groups encompassing all system users based on similar functions or security objectives
                </item>
                <item>
                  determine the group owner or manager for each group of system users
                </item>
                <item>
                  determine the degree of access to the resource for each system user group
                </item>
                <item>
                  decide on the degree of delegation for security administration, based on the internal security policy.
                </item>
              </list>
            </content>
            <controls>
              <block>
                <ID>0856</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Enforcing authorisations on systems</title>
                <content>
                  <para>
                    Agencies must have system users’ authorisations enforced by access controls.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Protecting compartmented information on systems</title>
            <content>
							<para>
								Compartmented information is particularly sensitive. Therefore, extra security measures need to be put in place on systems to restrict access to those with sufficient authorisations, briefings and a demonstrated need-to-know.
							</para>
						</content>
            <controls>
              <block>
                <ID>0857</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Protecting compartmented information on systems</title>
                <content>
                  <para>
                    Agencies must have access to compartmented information enforced by the system access controls.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Privileged Access</title>
        <objective>
          <block>
            <content>
              <para>
                Privileged access to systems is appropriately controlled and monitored.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes what must be in place to control and monitor privileged access to systems.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <list>
                <head>In this section, privileged access is considered to be access which can give a system user one or more of:</head>
                <item>
                  the ability to change key system configurations
                </item>
                <item>
                  the ability to change control parameters
                </item>
                <item>
                  access to audit and security monitoring information
                </item>
                <item>
                  the ability to circumvent security measures
                </item>
                <item>
                  access to data, files and accounts used by other system users, including backups and media
                </item>
                <item>
                  special access for troubleshooting the system.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Use of privileged accounts</title>
            <content>
							<para>
								Inappropriate use of any feature or facility of a system that enables a privileged user to override system or application controls can be a major contributory factor to failures on systems that lead to cyber security incidents.
							</para>
							<para>
								Privileged access allows system-wide changes to be made. An appropriate and effective mechanism to log privileged users will provide greater accountability and auditing capabilities.
							</para>
							<para>
								Privileged accounts are targeted by attackers as these can potentially give full access to the system. By ensuring that privileged accounts do not have a channel from inside the agency to the Internet minimises opportunities for these accounts to be compromised.
							</para>
            </content>
            <controls>
              <block>
                <ID>1175</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Use of privileged accounts</title>
                <content>
                  <para>
                    Agencies must not allow privileged accounts access to the Internet or to email.
                  </para>
                </content>
              </block>
              <block>
                <ID>0445</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Use of privileged accounts</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      ensure that the use of privileged accounts is controlled and accountable
                    </item>
                    <item>
                      ensure that system administrators are assigned an individual account for the performance of their administration tasks
                    </item>
                    <item>
                      keep privileged accounts to a minimum
                    </item>
                    <item>
                      allow the use of privileged accounts for administrative work only.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Privileged system access by foreign nationals</title>
            <content>
							<para>
								As privileged users often have the ability to bypass controls on a system it is strongly encouraged that foreign nationals are not given privileged access to systems processing particularly sensitive information.
							</para>
            </content>
            <controls>
              <block>
                <ID>0446</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Privileged system access by foreign nationals</title>
                <content>
                  <para>
                    Agencies must not allow foreign nationals, including seconded foreign nationals, to have privileged access to systems that process, store or communicate AUSTEO information.
                  </para>
                </content>
              </block>
              <block>
                <ID>0447</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Privileged system access by foreign nationals</title>
                <content>
                  <para>
                    Agencies must not allow foreign nationals, excluding seconded foreign nationals, to have privileged access to systems that process, store or communicate AGAO information.
                  </para>
                </content>
              </block>
              <block>
                <ID>0448</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Privileged system access by foreign nationals</title>
                <content>
                  <para>
                    Agencies should not allow foreign nationals, including seconded foreign nationals, to have privileged access to systems that process, store or communicate sensitive or classified information.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Remote Access</title>
        <objective>
          <block>
            <content>
              <para>
                Remote access to systems is authorised and authenticated. 
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the authentication required by personnel to access a system from a remote location.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information about working off-site can be found in the Working Off-Site chapter.
              </para>
						</content>
					</block>
						<block>
              <title>Remote access</title>
							<content>
								<para>
									Remote access is considered to be any access that originates from outside an agency network and enters the network through an Internet gateway.
								</para>
							</content>
						</block>
        </context>
        <controlsTitle>
          <block>
            <title>Authentication</title>
            <content>
              <para>
                Authenticating remote system users and devices ensures that only authorised system users and devices are allowed to connect to systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0858</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Authentication</title>
                <content>
                  <para>
                    Agencies must authenticate each remote connection before permitting access to a system. 
                  </para>
                </content>
              </block>
              <block>
                <ID>0706</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Authentication</title>
                <content>
                  <para>
                    Agencies should authenticate both the remote system user and device during the authentication process. 
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Remote privileged access</title>
            <content>
              <para>
                The extent of a compromise of remote access to a system can be limited by preventing the use of remote privileged access.
              </para>
            </content>
            <controls>
              <block>
                <ID>0985</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Remote privileged access</title>
                <content>
                  <para>
                    Agencies should not allow the use of privileged access remotely, including logging in as an unprivileged system user and then escalating privileges. 
                  </para>
                </content>
              </block>
              <block>
                <ID>0709</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Remote privileged access</title>
                <content>
                  <para>
                    Agencies must not allow the use of privileged access remotely, including logging in as an unprivileged system user and then escalating privileges.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Event Logging and Auditing</title>
        <objective>
          <block>
            <content>
              <para>
                Security related events are logged and audited. 
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes automatic logging of information relating to network activities.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
            <para>
              Information on manual logging of system management activities can be found in the Privileged Access section of this chapter.
            </para>
            <para>
              Event logging helps raise the security posture of a system by increasing the accountability of all system user actions, thereby improving the chances that malicious behaviour will be detected. Agencies should ensure sufficient detail is recorded in order for the logs to be useful when reviewed and determine an appropriate length of time for them to be retained. Conducting audits of event logs should be seen as an integral part of the maintenance of systems, since they will help detect and attribute any violations of information security policy, including cyber security incidents, breaches and intrusions.
            </para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Logging requirements</title>
            <content>
              <para>
                Event logging helps raise the security posture of a system by increasing the accountability for all system user actions. 
              </para>
              <para>
                Event logging increases the chances that malicious behaviour will be detected by logging the actions of a malicious party. 
              </para>
              <para>
                Well configured event logging allows for easier and more effective auditing if a cyber security incident occurs.
              </para>
            </content>
            <controls>
              <block>
                <ID>0580</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Logging requirements</title>
                <content>
                  <list>
                    <head>Agencies must develop and document logging requirements covering:</head>
                    <item>
                      the logging facility, including:
                    </item>
                    <item>
                      log server availability requirements
                    </item>
                    <item>
                      the reliable delivery of log information to the log server
                    </item>
                    <item>
                      the list of events associated with a system or software component to be logged
                    </item>
                    <item>
                      event log protection and retention requirements.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Events to be logged</title>
            <content>
              <para>
                The events to be logged are listed in their importance to monitoring the security posture of systems and contributing to reviews, audits and investigations.
              </para>
            </content>
            <controls>
              <block>
                <ID>0582</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Events to be logged</title>
                <content>
                  <list>
                    <head>Agencies should log, at minimum, the following events for all software components:</head>
                    <item>
                      all privileged operations
                    </item>
                    <item>
                      failed attempts to elevate privileges
                    </item>
                    <item>
                      security related system alerts and failures
                    </item>
                    <item>
                      system user and group additions, deletions and modification to permissions
                    </item>
                    <item>
                      unauthorised access attempts to critical systems and files.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0583</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Events to be logged</title>
                <content>
                  <list>
                    <head>Agencies must log, at minimum, the following events for all software components:</head>
                    <item>
                      all privileged operations
                    </item>
                    <item>
                      failed attempts to elevate privileges
                    </item>
                    <item>
                      security related system alerts and failures
                    </item>
                    <item>
                      system user and group additions, deletions and modification to permissions
                    </item>
                    <item>
                      unauthorised access attempts to critical systems and files.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1176</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Events to be logged</title>
                <content>
                  <list>
                    <head>Agencies should log the following events for all software components:</head>
                    <item>
                      logons
                    </item>
                    <item>
                      failed logon attempts
                    </item>
                    <item>
                      logoffs.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0584</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Events to be logged</title>
                <content>
                  <list>
                    <head>Agencies must log the following events for all software components:</head>
                    <item>logons</item>
                    <item>failed logon attempts</item>
                    <item>logoffs.</item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Additional events to be logged</title>
            <content>
              <para>
                The additional events to be logged below can be useful for reviewing, auditing or investigating software components of systems.
              </para>
            </content>
            <controls>
              <block>
                <ID>0987</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Additional events to be logged</title>
                <content>
                  <para>
                    Agencies should log the events listed below for specific software components.
                  </para>
                    <table>
                          <header>
                            <cell>Software component</cell>
                            <cell>Events to log</cell>
                          </header>
                          <row>
                            <cell rowspan="6">Database</cell>
                            <cell>System user access to the database</cell>
                          </row>
                          <row>
                            <cell>Attempted access that is denied</cell>
                          </row>
                          <row>
                            <cell>Changes to system user roles or database rights</cell>
                          </row>
                          <row>
                            <cell>Addition of new system users, especially privileged users</cell>
                          </row>
                          <row>
                            <cell>Modifications to the data</cell>
                          </row>
                          <row>
                            <cell>Modifications to the format of the database</cell>
                          </row>
                          <row>
                            <cell rowspan="12">Network/operating system</cell>
                            <cell>Successful and failed attempts to logon and logoff</cell>
                          </row>
                          <row>
                            <cell>Changes to system administrator and system user accounts</cell>
                          </row>
                          <row>
                            <cell>Failed attempts to access data and system resources</cell>
                          </row>
                          <row>
                            <cell>Attempts to use special privileges</cell>
                          </row>
                          <row>
                            <cell>Use of special privileges</cell>
                          </row>
                          <row>
                            <cell>System user or group management</cell>
                          </row>
                          <row>
                            <cell>Changes to the security policy</cell>
                          </row>
                          <row>
                            <cell>Service failures and restarts</cell>
                          </row>
                          <row>
                            <cell>System startup and shutdown</cell>
                          </row>
                          <row>
                            <cell>Changes to system configuration data</cell>
                          </row>
                          <row>
                            <cell>Access to sensitive data and processes</cell>
                          </row>
                          <row>
                            <cell>Data export operations</cell>
                          </row>
                          <row>
                            <cell rowspan="4">Web application</cell>
                            <cell>System user access to the web application</cell>
                          </row>
                          <row>
                            <cell>Attempted access that is denied</cell>
                          </row>
                          <row>
                            <cell>System user access to the web documents</cell>
                          </row>
                          <row>
                            <cell>Search engine queries initiated by system users</cell>
                          </row>
                    </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Event log facility</title>
            <content>
              <para>
                The act of logging events is not enough in itself. For each event logged, sufficient detail needs to be recorded in order for the logs to be useful when reviewed.
              </para>
            </content>
            <controls>
              <block>
                <ID>0585</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Event log facility</title>
                <content>
                  <list>
                    <head>For each event identified as needing to be logged, agencies must ensure that the log facility records at least the following details, where applicable:</head>
                    <item>
                      date and time of the event
                    </item>
                    <item>
                      relevant system users or process
                    </item>
                    <item>
                      event description
                    </item>
                    <item>
                      success or failure of the event
                    </item>
                    <item>
                      event source (for example, application name)
                    </item>
                    <item>
                      Information and Communications Technology equipment location/identification.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0988</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Event log facility</title>
                <content>
                  <para>
                    Agencies should establish an accurate time source, and use it consistently throughout their systems, to assist with the correlation of logged events across multiple systems. 
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Event log protection</title>
            <content>
              <para>
                Effective log protection and storage (possibly involving the use of a dedicated event log server) will help ensure the integrity and availability of the collected logs when they are audited.
              </para>
            </content>
            <controls>
              <block>
                <ID>0586</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Event log protection</title>
                <content>
                  <list>
                    <head>Event logs must be protected from:</head>
                    <item>
                      modification and unauthorised access
                    </item>
                    <item>
                      whole or partial loss within the defined retention period.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0989</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Event log protection</title>
                <content>
                  <list>
                    <head>Agencies should ensure that:</head>
                    <item>
                      systems are configured to save event logs to a separate secure log server
                    </item>
                    <item>
                      event log data is archived in a manner that maintains its integrity.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0587</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Event log protection</title>
                <content>
                  <para>
                    Agencies should configure systems to save event logs to separate secure servers as soon as possible after each event occurs. 
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Event log retention</title>
            <content>
              <para>
                It is important that agencies determine an appropriate length of time to retain event logs for systems. Since event logs can assist in reviews, audits and investigations, logs should ideally be retained for the life of the system and potentially longer. The retention requirement for these records under National Archives of Australia’s (NAA’s) Administrative Functions Disposal Authority is a minimum of 7 years after action is completed.
              </para>
            </content>
            <controls>
              <block>
                <ID>0859</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Event log retention</title>
                <content>
                  <para>
                    Agencies must retain event logs for a minimum of 7 years after action is completed in accordance with the NAA’s Administrative Functions Disposal Authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0991</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Event log retention</title>
                <content>
                  <para>
                    Agencies should retain Domain Name System and proxy logs for at least 18 months. 
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Event log auditing</title>
            <content>
              <para>
                Conducting audits of event logs should be seen as an integral part of the maintenance of systems, since they will help detect and attribute any violations of information security policy, including cyber security incidents, breaches and intrusions. Agencies can use a Security Information and Event Management solution to correlate logs from multiple sources to identify patterns of suspicious behaviour.
              </para>
            </content>
            <controls>
              <block>
                <ID>0109</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Event log auditing</title>
                <content>
                  <list>
                    <head>Agencies must develop and document event log auditing requirements covering:</head>
                    <item>
                      the scope of audits
                    </item>
                    <item>
                      the audit schedule
                    </item>
                    <item>
                      action to be taken when violations are detected
                    </item>
                    <item>
                      reporting requirements
                    </item>
                    <item>
                      specific responsibilities.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Cryptography</title>
      <section>
        <title>Cryptographic Fundamentals</title>
        <objective>
          <block>
            <content>
              <para>
                Cryptographic products, algorithms and protocols that have been evaluated by the Defence Signals Directorate (DSD) are used.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the fundamentals of cryptography including the use of encryption to protect data at rest and in transit.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
			<content>
            <para>
              Information on product security such as product selection, acquisition, installation and configuration can be found in the Product Security chapter.
            </para>
            <para>
              Detailed information on algorithms and protocols approved to protect sensitive or classified information can be found in the DSD Approved Cryptographic Algorithms and DSD Approved Cryptographic Protocols sections of this chapter.
            </para>
					</content>
					</block>
					<block>
            <title>Purpose of cryptography</title>
						<content>
							<para>
								The purpose of cryptography is to provide confidentiality, integrity, authentication and non-repudiation of information.
							</para>
							<para>
								Confidentiality is one of the most common cryptographic functions, with encryption providing protection to information by making it unreadable to all but authorised system users.
							</para>
							<para>
								Integrity is concerned with protecting information from accidental or deliberate manipulation. It provides assurance that the information has not been modified.
							</para>
							<para>
								Authentication is the process of ensuring that a person or entity is who they claim to be. A robust authentication system is essential for protecting access to systems.
							</para>
							<para>
								Non-repudiation provides proof that a system user performed an action, such as sending a message, and prevents them from denying that they did so.
							</para>
							<para>
								Using approved encryption generally reduces the likelihood of an unauthorised party gaining access to the encrypted information. However, it does not reduce the consequences of a successful attack.
							</para>
							<para>
								Care needs to be taken, with encryption systems that do not encrypt the entire media content, to ensure that either all of the data is encrypted or that the media is handled in accordance with the sensitivity or classification of the unencrypted data.
							</para>
						</content>
					</block>
					<block>
            <title>Using encryption</title>
						<content>
							<para>
								Encryption of data at rest can be used to reduce the physical storage and handling requirements of media or systems containing sensitive or classified information to an unclassified level.
							</para>
							<para>
								Encryption of data in transit can be used to provide protection for sensitive or classified information being communicated over public network infrastructure.
							</para>
							<para>
								When agencies use encryption for data at rest, or in transit, they are not reducing the sensitivity or classification of the information. However, because the information is encrypted, the consequences of it being accessed by unauthorised parties are considered to be less. Therefore the security requirements applied to such information can be reduced. However, as the sensitivity or classification of the information does not change, the lowered security requirements cannot be used as a baseline to further lower requirements with an additional cryptographic product.
							</para>
						</content>
					</block>
					<block>
						<title>Product specific cryptographic requirements</title>
						<content>
							<para>
								This section describes the use of cryptography to protect sensitive or classified information. Additional requirements can exist in consumer guides for products once they have completed a DSD Cryptographic Evaluation (DCE). Such requirements supplement this manual and where conflict occurs the product specific requirements take precedence.
							</para>
						</content>
					</block>
					<block>
            <title>Using products with DSD Approved Cryptographic Algorithms and Protocols</title>
						<content>
							<para>
								Where this manual states a requirement for a product that implements a DSD Approved Cryptographic Algorithm (DACA) or DSD Approved Cryptographic Protocol (DACP) to be used to provide protection for information at rest or in transit, the product does not need to have undergone a DCE.
							</para>
							<para>Federal Information Processing Standard 140</para>
							<para>
								The Federal Information Processing Standard (FIPS) 140 is a United States standard for the validation of both hardware and software cryptographic modules.
							</para>
							<para>
								FIPS 140 is in its second iteration and is formally referred to as FIPS 140-2. This section refers to the standard as FIPS 140 but applies to both FIPS 140-1 and FIPS 140-2. The third iteration, FIPS 140-3, has been released in draft and this section also applies to that iteration.
							</para>
							<para>
								FIPS 140 is not a substitute for a DCE of a product with cryptographic functionality. FIPS 140 is concerned solely with the cryptographic functionality of a module and does not consider any other security functionality.
							</para>
							<para>
								Cryptographic evaluations of products will normally be conducted by DSD. Where a product’s cryptographic functionality has been validated under FIPS 140, DSD can, at its discretion, and in consultation with the vendor, reduce the scope of a DCE.
							</para>
							<para>
								DSD will review the FIPS 140 validation report to confirm compliance with Australia’s national cryptographic policy.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Reducing storage and physical transfer requirements</title>
						<content>
							<para>
								When encryption is applied to media, whether the media resides in Information and Communications Technology (ICT) equipment or not, it provides an additional layer of defence. Encryption does not change the sensitivity or classification of the information, but when encryption is used the storage and physical transfer requirements of the ICT equipment or media can be treated at an unclassified level.
							</para>
						</content>
            <controls>
              <block>
                <ID>1161</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reducing storage and physical transfer requirements</title>
                <content>
                  <para>
                    Agencies must use an encryption product that implements a DACA if they wish to reduce the storage or physical transfer requirements for ICT equipment or media that contains sensitive information to an unclassified level.
                  </para>
                </content>
              </block>
              <block>
                <ID>0457</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reducing storage and physical transfer requirements</title>
                <content>
                  <para>
                    Agencies must use an Evaluation Assurance Level (EAL) 2 encryption product from DSD’s Evaluated Products List (EPL) that has completed a DCE if they wish to reduce the storage or physical transfer requirements for ICT equipment or media that contains classified information to an unclassified level.
                  </para>
                </content>
              </block>
              <block>
                <ID>0460</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Reducing storage and physical transfer requirements</title>
                <content>
                  <para>
                    Agencies must use High Grade Cryptographic Equipment (HGCE) if they wish to reduce the storage or physical transfer requirements for ICT equipment or media that contains classified information to an unclassified level.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Encrypting information at rest</title>
						<content>
							<para>
								Full disk encryption provides a greater level of protection than file based encryption. While file based encryption may encrypt individual files there is the possibility that unencrypted copies of the file may be left in temporary locations used by the operating system.
							</para>
						</content>
            <controls>
              <block>
                <ID>0459</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Encrypting information at rest</title>
                <content>
                  <list>
                    <head>Agencies using encryption to secure data at rest should use either:</head>
                    <item>
                      full disk encryption
                    </item>
                    <item>
                      partial encryption where the access control will only allow writing to the encrypted partition.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0461</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Encrypting information at rest</title>
                <content>
                  <list>
                    <head>Agencies using encryption to secure data at rest must use either:</head>
                    <item>
                      full disk encryption
                    </item>
                    <item>
                      partial encryption where the access control will only allow writing to the encrypted partition.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Encrypting particularly sensitive information at rest</title>
            <content>
              <para>
                As Australian Eyes Only (AUSTEO) and Australian Government Access Only (AGAO) information is particularly sensitive, it needs to be encrypted when at rest.
              </para>
            </content>
            <controls>
              <block>
                <ID>1080</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Encrypting particularly sensitive information at rest</title>
                <content>
                  <para>
                    In addition to any encryption already in place, agencies must, at minimum, use a DACA to protect AUSTEO and AGAO information when at rest on a system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Data recovery</title>
            <content>
              <para>
                The requirement for an encryption product to provide a key escrow function, where practical, was issued under a Cabinet directive in July 1998.
              </para>
            </content>
            <controls>
              <block>
                <ID>0455</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Data recovery</title>
                <content>
                  <para>
                    Where practical, cryptographic products must provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.
                  </para>
                </content>
              </block>
              <block>
                <ID>0456</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Data recovery</title>
                <content>
                  <para>
                    Where practical, cryptographic products must provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Handling encrypted Information and Communications Technology equipment</title>
            <content>
              <para>
                When a system user authenticates to ICT equipment employing encryption functionality, all information becomes accessible. At such a time, the ICT equipment will need to be handled as per the sensitivity or classification of the information it processes, stores or communicates.
              </para>
            </content>
            <controls>
              <block>
                <ID>0462</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Handling encrypted Information and Communications Technology equipment</title>
                <content>
                  <para>
                    When a system user authenticates to ICT equipment storing encrypted information, it must be treated in accordance with the original sensitivity or classification of the equipment.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Reducing network infrastructure requirements</title>
            <content>
              <para>
                When encryption is applied to sensitive or classified information being communicated over networks, less assurance needs to be placed in the protection of the network infrastructure. In some cases, where no security can be applied to the network infrastructure—for example where information is in the public domain—encryption of sensitive or classified information is the only mechanism to prevent the information being compromised.
              </para>
            </content>
            <controls>
              <block>
                <ID>1162</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reducing network infrastructure requirements</title>
                <content>
                  <para>
                    Agencies must use an encryption product that implements a DACP if they wish to communicate sensitive information over public network infrastructure.
                  </para>
                </content>
              </block>
              <block>
                <ID>0465</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Reducing network infrastructure requirements</title>
                <content>
                  <para>
                    Agencies must use an EAL 2 encryption product from DSD’s EPL that has completed a DCE if they wish to communicate classified information over public network infrastructure.
                  </para>
                </content>
              </block>
              <block>
                <ID>0467</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Reducing network infrastructure requirements</title>
                <content>
                  <para>
                    Agencies must use HGCE if they wish to communicate classified information over public network infrastructure.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Encrypting particularly sensitive information in transit</title>
            <content>
              <para>
                As AUSTEO and AGAO information is particularly sensitive it needs to be encrypted when being communicated across network infrastructure.
              </para>
            </content>
            <controls>
              <block>
                <ID>0469</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Encrypting particularly sensitive information in transit</title>
                <content>
                  <para>
                    In addition to any encryption already in place for communication mediums, agencies must, at minimum, use a DACP to protect AUSTEO and AGAO information when in transit.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <list>
                <head>Further information on the FIPS 140 standards can be found at:</head>
                <item>http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf</item>
                <item>http://csrc.nist.gov/publications/PubsFIPS.html</item>
              </list>
              <para>
                The storage and physical transfer requirements for sensitive or classified information can be found in the Australian Government Physical Security Management Protocol and Australian Government Information Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>DSD Approved Cryptographic Algorithms</title>
        <objective>
          <block>
            <content>
              <para>
                Information at rest is protected by a DACA.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes cryptographic algorithms that DSD has approved for use in government.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								Implementations of the algorithms in this section need to undergo a DCE before they can be approved to protect classified information.
							</para>
							<para>
								High grade cryptographic algorithms, which are not covered in this section, can be used for the protection of classified information if they are found suitably implemented in a product that has undergone a high grade cryptographic evaluation by DSD. Further information on high grade cryptographic algorithms can be obtained by contacting DSD.
							</para>
						</content>
					</block>
					<block>
            <title>DSD Approved Cryptographic Algorithms</title>
						<content>
							<para>
								There is no guarantee or proof of security of an algorithm against presently unknown attacks. However, the algorithms listed in this section have been extensively scrutinised by industry and academic communities in a practical and theoretical setting and have not been found to be susceptible to any feasible attacks. There have been some cases where theoretically impressive vulnerabilities have been found, however these results are not of practical application.
							</para>
							<para>
								DACAs fall into three categories: asymmetric/public key algorithms, hashing algorithms and symmetric encryption algorithms.
							</para>
							<list>
								<head>The approved asymmetric/public key algorithms are:</head>
								<item>
									Diffie-Hellman (DH) for agreeing on encryption session keys
								</item>
								<item>
									Digital Signature Algorithm (DSA) for digital signatures
								</item>
								<item>
									Elliptic Curve Diffie-Hellman (ECDH) for agreeing on encryption session keys
								</item>
								<item>
									Elliptic Curve Digital Signature Algorithm (ECDSA) for digital signatures
								</item>
								<item>
									Rivest-Shamir-Adleman (RSA) for digital signatures and passing encryption session keys or similar keys.
								</item>
							</list>
							<list>
								<head>The approved hashing algorithm is:</head>
								<item>
									Secure Hashing Algorithm 2 (SHA-224, SHA-256, SHA-384 and SHA-512).
								</item>
							</list>
							<list>
								<head>The approved symmetric encryption algorithms are:</head>
								<item>
									Advanced Encryption Standard (AES) using key lengths of 128, 192 and 256 bits
								</item>
								<item>
									Triple Data Encryption Standard (3DES).
								</item>
							</list>
							<para>
								Where there is a range of possible key sizes for an algorithm, some of the smaller key sizes do not provide an adequate safety margin against attacks that might be found in the future. For example, future advances in number factorisation could render the use of smaller RSA moduli a vulnerability.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using DSD Approved Cryptographic Algorithms</title>
						<content>
							<para>
								If a product implementing a DACA has been inappropriately configured, it is possible that relatively weak cryptographic algorithms could be selected without the system user’s knowledge. In combination with an assumed level of security confidence, this can represent a significant level of security risk.
							</para>
							<para>
								When configuring unevaluated products that implement a DACA, agencies can ensure that only the DACA can be used by disabling the unapproved algorithms in the products (which is preferred) or advising system users not to use them via a policy.
							</para>
						</content>
            <controls>
              <block>
                <ID>0471</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Using DSD Approved Cryptographic Algorithms</title>
                <content>
                  <para>
                    Agencies using an unevaluated product that implements a DACA must ensure that only DACAs can be used.
                  </para>
                </content>
              </block>
            </controls>
					</block>
            <block>
              <title>Approved asymmetric/public key algorithms</title>
							<content>
								<para>
									Over the last decade, DSA and DH cryptosystems have been subject to increasingly successful sub-exponential index-calculus based attacks. ECDH and ECDSA offer more security per bit increase in key size than either DH or DSA and are considered more secure alternatives.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0994</ID>
                  <revision>3</revision>
                  <updated>Sep-11</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>should</compliance>
                  <authority>AA</authority>
                  <title>Approved asymmetric/public key algorithms</title>
                  <content>
                    <para>
                      Agencies should use ECDH and ECDSA in preference to DH and DSA.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Using Diffie-Hellman</title>
							<content>
								<para>
									A modulus of at least 1024 bits for DH is considered best practice by the cryptographic community.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0472</ID>
                  <revision>2</revision>
                  <updated>Nov-10</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>must</compliance>
                  <authority>AH</authority>
                  <title>Using Diffie-Hellman</title>
                  <content>
                    <para>
                      Agencies using DH for the approved use of agreeing on encryption session keys must use a modulus of at least 1024 bits.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Using the Digital Signature Algorithm</title>
							<content>
								<para>
									A modulus of at least 1024 bits for DSA is considered best practice by the cryptographic community.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0473</ID>
                  <revision>2</revision>
                  <updated>Nov-10</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>must</compliance>
                  <authority>AH</authority>
                  <title>Using the Digital Signature Algorithm</title>
                  <content>
                    <para>
                      Agencies using DSA for the approved use of digital signatures must use a modulus of at least 1024 bits.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Using Elliptic Curve Diffie-Hellman</title>
							<content>
								<para>
									A field/key size of at least 160 bits for ECDH is considered best practice by the cryptographic community.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0474</ID>
                  <revision>2</revision>
                  <updated>Nov-10</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>must</compliance>
                  <authority>AH</authority>
                  <title>Using Elliptic Curve Diffie-Hellman</title>
                  <content>
                    <para>
                      Agencies using ECDH for the approved use of agreeing on encryption session keys must use a field/key size of at least 160 bits.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Using the Elliptic Curve Digital Signature Algorithm</title>
							<content>
								<para>
									A field/key size of at least 160 bits for ECDSA is considered best practice by the cryptographic community.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0475</ID>
                  <revision>2</revision>
                  <updated>Nov-10</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>must</compliance>
                  <authority>AH</authority>
                  <title>Using the Elliptic Curve Digital Signature Algorithm</title>
                  <content>
                    <para>
                      Agencies using ECDSA for the approved use of digital signatures must use a field/key size of at least 160 bits.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Using Rivest-Shamir-Adleman</title>
							<content>
								<para>
									A modulus of at least 1024 bits for RSA is considered best practice by the cryptographic community.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0476</ID>
                  <revision>2</revision>
                  <updated>Nov-10</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>must</compliance>
                  <authority>AH</authority>
                  <title>Using Rivest-Shamir-Adleman</title>
                  <content>
                    <para>
                      Agencies using RSA, for the approved use of digital signatures and passing encryption session keys or similar keys, must use a modulus of at least 1024 bits.
                    </para>
                  </content>
                </block>
                <block>
                  <ID>0477</ID>
                  <revision>3</revision>
                  <updated>Sep-11</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>must</compliance>
                  <authority>AH</authority>
                  <title>Using Rivest-Shamir-Adleman</title>
                  <content>
                    <para>
                      Agencies using RSA, both for the approved use of digital signatures and for passing encryption session keys or similar keys, must ensure that the public keys used for passing encrypted session keys are different from the keys used for digital signatures.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Approved hashing algorithms</title>
							<content>
								<para>
									Recent research conducted by the cryptographic community suggests that SHA-1 may be susceptible to collision attacks. While no practical collision attacks have been published for SHA-1, they may become feasible in the near future.
								</para>
							</content>
              <controls>
                <block>
                  <ID>1054</ID>
                  <revision>1</revision>
                  <updated>Sep-11</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>should</compliance>
                  <authority>AA</authority>
                  <title>Approved hashing algorithms</title>
                  <content>
                    <para>
                      Agencies should use a hashing algorithm from the SHA-2 family.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Approved symmetric encryption algorithms</title>
							<content>
								<para>
									The use of Electronic Code Book mode in block ciphers allows repeated patterns in plaintext to appear as repeated patterns in the ciphertext. Most cleartext, including written language and formatted files, contains significant repeated patterns. An attacker can use this to deduce possible meanings of ciphertext by comparison with previously intercepted data. The use of other modes such as Cipher Block Chaining, Cipher Feedback, Output Feedback or Counter prevents such attacks.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0479</ID>
                  <revision>2</revision>
                  <updated>Nov-10</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>should not</compliance>
                  <authority>AA</authority>
                  <title>Approved symmetric encryption algorithms</title>
                  <content>
                    <para>
                      Agencies using AES or 3DES should not use electronic codebook mode.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
            <block>
              <title>Using the Triple Data Encryption Standard</title>
							<content>
								<para>
									Using three distinct keys is the most secure option, while using two distinct keys in the order key 1, key 2, key 1 is also deemed secure for practical purposes. All other keying options are equivalent to single DES, which is not deemed secure for practical purposes.
								</para>
							</content>
              <controls>
                <block>
                  <ID>0480</ID>
                  <revision>3</revision>
                  <updated>Sep-11</updated>
                  <classification>G</classification>
                  <classification>P</classification>
                  <classification>C</classification>
                  <classification>S</classification>
                  <classification>TS</classification>
                  <compliance>must</compliance>
                  <authority>AH</authority>
                  <title>Using the Triple Data Encryption Standard</title>
                  <content>
                    <para>
                      Agencies using 3DES must use either two distinct keys in the order key 1, key 2, key 1 or three distinct keys.
                    </para>
                  </content>
                </block>
              </controls>
            </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <list>
                <head>The following references are provided for the approved asymmetric/public key algorithms, hashing algorithms and encryption algorithms:</head>
                <item>
                  Further information on DH can be found in Diffie, W and Hellman, ME ‘New Directions in Cryptography’, IEEE Transactions on Information Theory, vol. 22, is. 6, pp. 644-654, November 1976
                </item>
                <item>
                  Further information on DSA can be found in FIPS 186
                </item>
                <item>
                  Further information on ECDH can be found in ANSI X9.63 and ANSI X9.42
                </item>
                <item>
                  Further information on ECDSA can be found in FIPS 186-2 + Change Notice, ANSI X9.63 and ANSI X9.62
                </item>
                <item>
                  Further information on RSA can be found in Public Key Cryptography Standards #1, RSA Laboratories
                </item>
                <item>
                  Further information on SHA can be found in AS 2805.13.3 and FIPS 180-2.
                </item>
              </list>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>DSD Approved Cryptographic Protocols</title>
        <objective>
          <block>
            <content>
              <para>
                Information in transit is protected by a DACP implementing a DACA.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes cryptographic protocols that DSD has approved for use in government.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								Implementations of the protocols in this section need to undergo a DCE before they can be approved to protect classified information.
							</para>
							<para>
								High grade cryptographic protocols, which are not covered in this section, can be used for the protection of classified information if they are found suitably implemented in a product that has undergone a high grade cryptographic evaluation by DSD. Further information on high grade cryptographic protocols can be obtained by contacting DSD.
							</para>
						</content>
					</block>
					<block>
            <title>DSD Approved Cryptographic Protocols</title>
						<content>
							<para>
								In general, DSD only approves the use of cryptographic products that have passed a formal evaluation. However, DSD approves the use of some commonly available cryptographic protocols even though their implementations in specific products have not been formally evaluated by DSD. This approval is limited to cases where they are used in accordance with the requirements in this manual.
							</para>
							<list>
								<head>The DACPs are:</head>
								<item>
									Secure Sockets Layer (SSL) and Transport Layer Security (TLS)
								</item>
								<item>
									Secure Shell (SSH)
								</item>
								<item>
									Secure Multipurpose Internet Mail Extension (S/MIME)
								</item>
								<item>
									OpenPGP Message Format
								</item>
								<item>
									Internet Protocol Security (IPSec).
								</item>
							</list>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using DSD Approved Cryptographic Protocols</title>
						<content>
							<para>
								If a product implementing a DACP has been inappropriately configured, it is possible that relatively weak cryptographic algorithms could be selected without the system user’s knowledge. In combination with an assumed level of security confidence, this can represent a significant level of security risk.
							</para>
							<para>
								When configuring unevaluated products that implement a DACP, agencies can ensure that only the DACA can be used by disabling the unapproved algorithms in the products (which is preferred) or advising system users not to use them via a policy.
							</para>
							<list>
								<head>While many DACPs support authentication, agencies should be aware that these authentication mechanisms are not foolproof. To be effective, these mechanisms must also be securely implemented and protected. This can be achieved by:</head>
								<item>
									providing an assurance of private key protection
								</item>
								<item>
									ensuring the correct management of certificate authentication processes including certificate revocation checking
								</item>
								<item>
									using a legitimate identity registration scheme.
								</item>
							</list>
						</content>
            <controls>
              <block>
                <ID>0481</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Using DSD Approved Cryptographic Protocols</title>
                <content>
                  <para>
                    Agencies using a product that implements a DACP must ensure that only DACAs can be used.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on the OpenPGP Message Format can be found in the OpenPGP Message Format specification at http://tools.ietf.org/html/rfc4880.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Secure Sockets Layer and Transport Layer Security</title>
        <objective>
          <block>
            <content>
              <para>
                SSL and TLS are implemented correctly as a DACP.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the conditions under which SSL and TLS can be used as DACPs. Additionally, as File Transfer Protocol over SSL is built on SSL and TLS, it is also considered in scope.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								When using a product that implements SSL and TLS, requirements for using DACPs also need to be consulted in the DSD Approved Cryptographic Protocols section of this chapter.
							</para>
							<para>
								Further information on handling SSL and TLS traffic through gateways can be found in the Web Content and Connections section of the Software Security chapter.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using Secure Sockets Layer and Transport Layer Security</title>
						<content>
							<para>
								Version 1.0 of SSL was never released and version 2.0 had significant security flaws leading to the development of SSL 3.0. SSL has since been superseded by TLS, with the latest version being TLS 1.2 which was released in August 2008.
							</para>
						</content>
            <controls>
              <block>
                <ID>0482</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Using Secure Sockets Layer and Transport Layer Security</title>
                <content>
                  <para>
                    Agencies should not use versions of SSL prior to version 3.0.
                  </para>
                </content>
              </block>
              <block>
                <ID>1139</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Using Secure Sockets Layer and Transport Layer Security</title>
                <content>
                  <para>
                    Agencies should use the current version of TLS instead of SSL.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <list>
                <head>Further information on SSL and TLS can be found in:</head>
                <item>
                  the SSL 3.0 specification at http://tools.ietf.org/id/draft-ietf-tls-ssl-version3-00.txt
                </item>
                <item>
                  the TLS 1.2 definition at http://tools.ietf.org/html/rfc5246.
                </item>
              </list>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Secure Shell</title>
        <objective>
          <block>
            <content>
              <para>
                SSH is implemented correctly as a DACP.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the conditions under which implementations of SSH can be used as a DACP. Additionally, secure copy and Secure File Transfer Protocol use SSH and are therefore also covered by this section.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								When using a product that implements SSH, requirements for using DACPs also need to be consulted in the DSD Approved Cryptographic Protocols section of this chapter.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using Secure Shell</title>
						<content>
							<para>
								The configuration directives provided are based on the OpenSSH implementation of SSH. Agencies implementing SSH will need to adapt these settings to suit other SSH implementations.
							</para>
							<para>
								SSH version 1 is known to have vulnerabilities. In particular, it is susceptible to a man-in-the-middle attack, where an attacker who can intercept the protocol in each direction can make each node believe they are talking to the other. SSH version 2 does not have this vulnerability.
							</para>
							<para>
								SSH has the ability to forward connections and access privileges in a variety of ways. This means that an attacker who can exploit any of these features can gain unauthorised access to a potentially large amount of information.
							</para>
							<para>
								Host-based authentication requires no credentials (for example, passphrase or public key) to authenticate (though in some cases it might make use of a host key). This renders SSH vulnerable to an Internet Protocol (IP) spoofing attack.
							</para>
							<para>
								An attacker who gains access to a system with system administrator privileges will have the ability to not only access information but to control that system completely. Given the clearly more serious consequences of this, system administrator login should not be permitted.
							</para>
						</content>
            <controls>
              <block>
                <ID>0484</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Using Secure Shell</title>
                <content>
                  <para>
                    The settings below should be implemented when using SSH.
                  </para>
                    <table>
                          <header>
                            <cell>Configuration description</cell>
                            <cell>Configuration directive</cell>
                          </header>
                          <row>
                            <cell>Disallow the use of SSH version 1</cell>
                            <cell>Protocol 2</cell>
                          </row>
                          <row>
                            <cell>On machines with multiple interfaces, configure the SSH daemon to listen only on the required interfaces</cell>
                            <cell>ListenAddress xxx.xxx.xxx.xxx</cell>
                          </row>
                          <row>
                            <cell>Disable connection forwarding</cell>
                            <cell>AllowTCPForwarding no</cell>
                          </row>
                          <row>
                            <cell>Disable gateway ports</cell>
                            <cell>Gatewayports no</cell>
                          </row>
                          <row>
                            <cell>Disable the ability to login directly as root</cell>
                            <cell>PermitRootLogin no</cell>
                          </row>
                          <row>
                            <cell>Disable host-based authentication</cell>
                            <cell>HostbasedAuthentication no</cell>
                          </row>
                          <row>
                            <cell rowspan="2">Disable rhosts-based authentication</cell>
                            <cell>RhostsAuthentication no</cell>
                          </row>
                          <row>
                            <cell>IgnoreRhosts yes</cell>
                          </row>
                          <row>
                            <cell>Do not allow empty passphrases</cell>
                            <cell>PermitEmptyPassphrases no</cell>
                          </row>
                          <row>
                            <cell>Configure a suitable login banner</cell>
                            <cell>Banner/directory/filename</cell>
                          </row>
                          <row>
                            <cell>Configure a login authentication timeout of no more than 60 seconds</cell>
                            <cell>LoginGraceTime xx</cell>
                          </row>
                          <row>
                            <cell>Disable X forwarding</cell>
                            <cell>X11Forwarding no</cell>
                          </row>
                    </table>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Authentication mechanisms</title>
						<content>
							<para>
								Public key-based systems have greater potential for strong authentication—put simply, people cannot remember particularly strong passphrases. Passphrase-based authentication schemes are also more susceptible to interception than public key-based authentication schemes.
							</para>
							<para>
								Passphrases are more susceptible to guessing attacks, therefore if passphrases are used in a system, counter-measures should be put into place to reduce the chance of a successful brute force attack.
							</para>
						</content>
            <controls>
              <block>
                <ID>0485</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Authentication mechanisms</title>
                <content>
                  <para>
                    Agencies should use public key-based authentication in preference to using passphrase-based authentication.
                  </para>
                </content>
              </block>
              <block>
                <ID>0486</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Authentication mechanisms</title>
                <content>
                  <para>
                    Agencies that allow passphrase authentication should use techniques to block brute force attempts against the passphrase.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Automated remote access</title>
						<content>
							<para>
								If passphrase-less authentication is enabled, allowing access from unknown IP addresses would allow untrusted parties to automatically authenticate to systems without needing to know the passphrase.
							</para>
							<para>
								If port forwarding is not disabled, or it is not configured securely, an attacker may be able to gain access to forwarded ports and thereby create a communication channel between the attacker and the host.
							</para>
							<para>
								If agent credential forwarding is enabled, an intruder could connect to the stored authentication credentials and then use them to connect to other trusted hosts or even intranet hosts, if port forwarding has been allowed as well.
							</para>
							<para>
								X11 is a computer software system and network protocol that provides a graphical user interface for networked computers. Failing to disable X11 display remoting could result in an attacker being able to gain control of the computer displays as well as keyboard and mouse control functions.
							</para>
							<para>
								Allowing console access allows every system user who logs into the console to run programs that are normally restricted to the root user.
							</para>
						</content>
            <controls>
              <block>
                <ID>0487</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Automated remote access</title>
                <content>
                  <list>
                    <head>Agencies that use logins without a passphrase for automated purposes should disable:</head>
                    <item>
                      access from IP addresses that do not need access
                    </item>
                    <item>
                      port forwarding
                    </item>
                    <item>
                      agent credential forwarding
                    </item>
                    <item>
                      X11 display remoting
                    </item>
                    <item>
                      console access.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0488</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Automated remote access</title>
                <content>
                  <para>
                    Agencies that use remote access without the use of a passphrase should use the ‘forced command’ option to specify what command is executed.
                  </para>
                </content>
              </block>
              <block>
                <ID>0997</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Automated remote access</title>
                <content>
                  <para>
                    Agencies should use parameter checking when using the ‘forced command’ option.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>SSH-agent</title>
						<content>
							<para>
								SSH-agent or other similar key caching programs hold and manage private keys stored on workstations and respond to requests from remote systems to verify these keys. When an SSH-agent launches, it will request the system user’s passphrase. This passphrase is used to unlock the user’s private key. Subsequent access to remote systems is performed by the agent and does not require the user to re-enter their passphrase. Screen locks and expiring key caches ensure that the user’s private key is not left unlocked for long periods of time.
							</para>
							<para>
								Agent credential forwarding is required when multiple SSH connections are chained to allow each system in the chain to authenticate the system user.
							</para>
						</content>
            <controls>
              <block>
                <ID>0489</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>SSH-agent</title>
                <content>
                  <list>
                    <head>Agencies that use SSH-agent or other similar key caching programs should:</head>
                    <item>
                      only use the software on workstation and servers with screen locks
                    </item>
                    <item>
                      ensure that the key cache expires within four hours of inactivity
                    </item>
                    <item>
                      ensure that agent credential forwarding is used when multiple SSH transversal is needed.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on SSH can be found in the SSH specification at http://tools.ietf.org/html/rfc4252.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Secure Multipurpose Internet Mail Extension</title>
        <objective>
          <block>
            <content>
              <para>
                S/MIME is implemented correctly as a DACP.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the conditions under which S/MIME can be used as a DACP.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								When using a product that implements S/MIME, requirements for using DACPs also need to be consulted in the DSD Approved Cryptographic Protocols section of this chapter.
							</para>
							<para>
								Information relating to the development of passphrase selection policies and passphrase requirements can be found in the Identification and Authentication section of the Access Control chapter.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using Secure Multipurpose Internet Mail Extension</title>
						<content>
							<para>
								S/MIME 2.0 required the use of weaker cryptography (40-bit keys) than is approved for use in this manual. Version 3.0 was the first version to become an Internet Engineering Task Force standard.
							</para>
							<para>
								Agencies choosing to implement S/MIME should be aware of the inability of many content filters to inspect encrypted messages and any attachments for inappropriate content, and for server-based antivirus and other Internet security software to scan for viruses and other malicious code.
							</para>
						</content>
            <controls>
              <block>
                <ID>0490</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Using Secure Multipurpose Internet Mail Extension</title>
                <content>
                  <para>
                    Agencies should not allow versions of S/MIME earlier than 3.0 to be used.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on S/MIME can be found in the S/MIME charter at http://www.ietf.org/html.charters/smime-charter.html.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Internet Protocol Security</title>
        <objective>
          <block>
            <content>
              <para>
                IPSec is implemented correctly as a DACP.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes conditions under which IPSec can be used as a DACP.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								When using a product that implements IPSec, requirements for using DACPs also need to be consulted in the DSD Approved Cryptographic Protocols section of this chapter.
							</para>
						</content>
					</block>
					<block>
            <title>Modes of operation</title>
						<content>
							<para>
								IPSec can be operated in two modes: transport mode or tunnel mode.
							</para>
						</content>
					</block>
					<block>
            <title>Cryptographic protocols</title>
						<content>
							<para>
								IPSec contains two major protocols: Authentication Header (AH) and Encapsulating Security Payload (ESP).
							</para>
						</content>
					</block>
					<block>
            <title>Cryptographic algorithms</title>
						<content>
							<para>
								Most IPSec implementations can handle a number of cryptographic algorithms for encrypting data when the ESP protocol is used. These include 3DES and AES.
							</para>
						</content>
					</block>
					<block>
            <title>Key exchange</title>
						<content>
							<para>
								Most IPSec implementations handle a number of methods for sharing keying material used in hashing and encryption processes. Available methods are manual keying and Internet Key Exchange (IKE), versions 1 and 2, using the Internet Security Association Key Management Protocol (ISAKMP). Both methods are considered suitable for use.
							</para>
						</content>
					</block>
					<block>
            <title>Internet Security Association Key Management Protocol authentication</title>
            <content>
							<para>
								Most IPSec implementations handle a number of methods for authentication as part of ISAKMP. These can include digital certificates, encrypted nonces or pre-shared keys. These methods are considered suitable for use.
							</para>
						</content>
					</block>
					<block>
            <title>IKE Extended Authentication</title>
						<content>
							<para>
								Agencies should disable the use of IKE Extended Authentication (XAUTH) for IPSec connections using IKEv1.
							</para>
						</content>
					</block>
					<block>
            <title>Internet Security Association Key Management Protocol modes</title>
						<content>
							<para>
								Agencies using ISKMP in IKEv1 should disable aggressive mode.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Mode of operation</title>
						<content>
							<para>
								The tunnel mode of operation provides full encapsulation of IP packets while the transport mode of operation only encapsulates the payload of the IP packet.
							</para>
						</content>
            <controls>
              <block>
                <ID>0494</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Mode of operation</title>
                <content>
                  <para>
                    Agencies should use tunnel mode for IPSec connections.
                  </para>
                </content>
              </block>
              <block>
                <ID>0495</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Mode of operation</title>
                <content>
                  <para>
                    Agencies choosing to use transport mode should additionally use an IP tunnel for IPSec connections.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Protocols</title>
						<content>
							<para>
								In order to provide a secure Virtual Private Network style connection, both authentication and encryption are needed. AH and ESP can provide authentication for the entire IP packet and the payload respectively. However, ESP is generally preferred for authentication since AH by its nature has network address translation limitations. ESP is the only way of providing encryption.
							</para>
							<para>
								If, however, maximum security is desired at the expense of network address translation functionality, then ESP can be wrapped inside of AH which will then authenticate the entire IP packet and not just the encrypted payload.
							</para>
						</content>
            <controls>
              <block>
                <ID>0496</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Protocols</title>
                <content>
                  <para>
                    Agencies should use the ESP protocol for IPSec connections. 
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Internet Security Association Key Management Protocol modes</title>
						<content>
							<para>
								Using ISAKMP main mode instead of aggressive mode provides greater security since all exchanges are protected.
							</para>
						</content>
            <controls>
              <block>
                <ID>0497</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Protocols</title>
                <content>
                  <para>
                    Agencies using ISAKMP in IKEv1 should disable aggressive mode for IKE.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Security association lifetimes</title>
						<content>
							<para>
								Using a secure association lifetime of four hours, or 14400 seconds, provides a balance between security and usability.
							</para>
						</content>
            <controls>
              <block>
                <ID>0498</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Protocols</title>
                <content>
                  <para>
                    Agencies should use a security association lifetime of less than four hours, or 14400 seconds.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Hashed Message Authentication Code algorithms</title>
						<content>
							<para>
								MD5 and SHA-1 are no longer DACAs that can be used with Hashed Message Authentication Code (HMAC). The approved HMAC algorithms are HMAC-SHA256, HMAC-SHA384 or HMAC-SHA512.
							</para>
						</content>
            <controls>
              <block>
                <ID>0998</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Hashed Message Authentication Code algorithms</title>
                <content>
                  <para>
                    Agencies must use HMAC-SHA256, HMAC-SHA384 or HMAC-SHA512 as a HMAC algorithm.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Diffie-Hellman groups</title>
						<content>
							<para>
								Using a larger DH group provides more entropy for the key exchange.
							</para>
						</content>
            <controls>
              <block>
                <ID>0999</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Diffie-Hellman groups</title>
                <content>
                  <para>
                    Agencies should use the largest modulus size available for the DH exchange.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Perfect Forward Secrecy</title>
						<content>
							<para>
								Using Perfect Forward Secrecy reduces the impact of the compromise of a security association.
							</para>
						</content>
            <controls>
              <block>
                <ID>1000</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Perfect Forward Secrecy</title>
                <content>
                  <para>
                    Agencies should use Perfect Forward Secrecy for IPSec connections.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>IKE Extended Authentication</title>
						<content>
							<para>
								XAUTH using IKEv1 has documented vulnerabilities associated with its use.
							</para>
						</content>
            <controls>
              <block>
                <ID>1001</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>IKE Extended Authentication</title>
                <content>
                  <para>
                    Agencies should disable the use of XAUTH for IPSec connections using IKEv1.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on IPSec can be found in the Security Architecture for the Internet Protocol at http://tools.ietf.org/html/rfc4301.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Key Management</title>
        <objective>
          <block>
            <content>
              <para>
                Cryptographic keying material is protected by key management procedures.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the general management of cryptographic system material.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								Due to the wide variety of cryptographic systems and technologies available, and the varied security risks for each, only general key management guidance can be provided in this manual.
							</para>
							<para>
								If HGCE is being used, agencies are advised to consult the respective Australian Communications Security Instruction (ACSI) for the equipment.
							</para>
						</content>
					</block>
					<block>
            <title>Cryptographic systems</title>
						<content>
							<para>
								In general, the requirements specified for systems apply equally to cryptographic systems. Where the requirements for cryptographic systems are different, the variations are contained in this section, and overrule all requirements specified elsewhere in this manual.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Compromise of key material</title>
						<content>
							<para>
								If the private certificate and associated key used for encrypting messages is suspected of being compromised (that is, stolen, lost or transmitted over the Internet), then no assurance can be placed in the integrity of subsequent messages that are signed by that private key. Likewise no assurance can be placed in the confidentiality of a message encrypted using the public key, since third parties could intercept the message and decrypt it using the private key.
							</para>
						</content>
            <controls>
              <block>
                <ID>1091</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Compromise of key material</title>
                <content>
                  <para>
                    Agencies must immediately revoke key pairs or certificates when they are suspected of being compromised.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>High Grade Cryptographic Equipment</title>
						<content>
							<para>
								ACSI 53 and ACSI 105 provide product specific policy for HGCE.
							</para>
						</content>
            <controls>
              <block>
                <ID>0499</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>High Grade Cryptographic Equipment</title>
                <content>
                  <para>
                    Agencies must comply with ACSI 53 and ACSI 105 when using HGCE.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Transporting commercial grade cryptographic equipment</title>
						<content>
							<para>
								Transporting commercial grade cryptographic equipment in a keyed state exposes the equipment to the potential for interception and compromise of the key stored in the equipment. Therefore, when commercial grade cryptographic equipment is transported in a keyed state, it needs to be done according to the requirements for the sensitivity or classification of the key stored in the equipment.
							</para>
						</content>
            <controls>
              <block>
                <ID>1002</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Transporting commercial grade cryptographic equipment</title>
                <content>
                  <para>
                    Agencies should not transport commercial grade cryptographic equipment in a keyed state.
                  </para>
                </content>
              </block>
              <block>
                <ID>0500</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Transporting commercial grade cryptographic equipment</title>
                <content>
                  <para>
                    Unkeyed commercial grade cryptographic equipment must be distributed and managed by a means approved for the transportation and management of government property.
                  </para>
                </content>
              </block>
              <block>
                <ID>0501</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Transporting commercial grade cryptographic equipment</title>
                <content>
                  <para>
                    Keyed commercial grade cryptographic equipment must be distributed managed and stored by a means approved for the transportation and management of government property based on the sensitivity or classification of the key in the equipment.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Communications security custodian access</title>
						<content>
							<para>
								Since communications security custodian access involves granting privileged access to a cryptographic system, extra precautions need to be put in place surrounding the personnel chosen to be cryptographic system administrators.
							</para>
						</content>
            <controls>
              <block>
                <ID>0502</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Communications security custodian access</title>
                <content>
                  <list>
                    <head>Before personnel are granted communications security custodian access, agencies must ensure that they have:</head>
                    <item>
                      a demonstrated need for access
                    </item>
                    <item>
                      read and agreed to comply with the relevant Key Management Plan (KMP) for the cryptographic system they are using
                    </item>
                    <item>
                      a security clearance at least equal to the sensitivity or classification of information processed by the cryptographic system
                    </item>
                    <item>
                      agreed to protect the authentication information for the cryptographic system at the sensitivity or classification of information it secures
                    </item>
                    <item>
                      agreed not to share authentication information for the cryptographic system without approval
                    </item>
                    <item>
                      agreed to be responsible for all actions under their accounts
                    </item>
                    <item>
                      agreed to report all potentially security related problems to an Information Technology Security Manager.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Accounting</title>
						<content>
            <para>
              As cryptographic equipment, and the keys they store, provides a significant security function for systems, it is important that agencies are able to account for all cryptographic equipment.
            </para>
						</content>
            <controls>
              <block>
                <ID>0503</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Accounting</title>
                <content>
                  <para>
                    Agencies should be able to readily account for all transactions relating to cryptographic system material, including identifying hardware and software that was issued with the cryptographic equipment and materials, when they were issued and where they were issued.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Audits</title>
						<content>
            <para>
              Cryptographic system audits are used as a process to account for cryptographic equipment.
            </para>
						</content>
            <controls>
              <block>
                <ID>0504</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Audits</title>
                <content>
                  <list>
                    <head>Agencies should conduct audits of cryptographic system material:</head>
                    <item>
                      on handover/takeover of administrative responsibility for the cryptographic system
                    </item>
                    <item>
                      on change of personnel with access to the cryptographic system
                    </item>
                    <item>
                      at least annually.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1003</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Audits</title>
                <content>
                  <list>
                    <head>Agencies should perform audits to:</head>
                    <item>
                      check all cryptographic system material as per the accounting documentation
                    </item>
                    <item>
                      confirm that agreed security measures documented in the KMP are being followed.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1004</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Audits</title>
                <content>
                  <para>
                    Agencies should conduct audits using two personnel with communications security custodian access.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Area security and access control</title>
						<content>
            <para>
              As cryptographic equipment contains particularly sensitive information, additional physical security measures need to be applied to the equipment. Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
            </para>
						</content>
            <controls>
              <block>
                <ID>0505</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Area security and access control</title>
                <content>
                  <para>
                    Cryptographic equipment should be stored in a room that meets the requirements for a server room of an appropriate level based on the sensitivity or classification of information the cryptographic system processes.
                  </para>
                </content>
              </block>
              <block>
                <ID>0506</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Area security and access control</title>
                <content>
                  <para>
                    Areas in which cryptographic system material is used should be separated from other areas and designated as a cryptographic controlled area.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Developing Key Management Plans for cryptographic systems</title>
						<content>
							<para>
								Most modern cryptographic systems are designed to be highly resistant to cryptographic analysis but it must be assumed that a determined attacker could obtain details of the cryptographic logic either by stealing or copying relevant material directly or by suborning an Australian national or allied national. The safeguarding of cryptographic system material by using adequate personnel, physical, documentation and procedural security measures is therefore crucial.
							</para>
						</content>
            <controls>
              <block>
                <ID>0507</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Developing Key Management Plans for cryptographic systems</title>
                <content>
                  <para>
                    Agencies should develop a KMP when they have implemented a cryptographic system using commercial grade cryptographic equipment.
                  </para>
                </content>
              </block>
              <block>
                <ID>0509</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>DSD</authority>
                <title>Developing Key Management Plans for cryptographic systems</title>
                <content>
                  <para>
                    Agencies must develop a KMP when they have implemented a cryptographic system using HGCE.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Contents of Key Management Plans</title>
						<content>
							<para>
								When agencies implement the recommended contents for KMPs they will have a good starting point for the protection of cryptographic systems and their material.
							</para>
						</content>
            <controls>
              <block>
                <ID>0510</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Contents of Key Management Plans</title>
                <content>
                  <para>
                    The minimum contents which should be documented in the KMP are described below.
                  </para>
                    <table>
                          <header>
                            <cell>Topic</cell>
                            <cell>Content</cell>
                          </header>
                          <row>
                            <cell rowspan="3">Accounting</cell>
                            <cell>How accounting will be undertaken for the cryptographic system</cell>
                          </row>
                          <row>
                            <cell>What records will be maintained</cell>
                          </row>
                          <row>
                            <cell>How records will be audited</cell>
                          </row>
                          <row>
                            <cell rowspan="2">Cyber security incidents</cell>
                            <cell>A description of the conditions under which compromise of key material should be declared</cell>
                          </row>
                          <row>
                            <cell>References to procedures to be followed when reporting and dealing with cyber security incidents</cell>
                          </row>
                          <row>
                            <cell rowspan="10">Key management</cell>
                            <cell>Who generates keys</cell>
                          </row>
                          <row>
                            <cell>How keys are delivered</cell>
                          </row>
                          <row>
                            <cell>How keys are received</cell>
                          </row>
                          <row>
                            <cell>Key distribution, including local, remote and central</cell>
                          </row>
                          <row>
                            <cell>How keys are installed</cell>
                          </row>
                          <row>
                            <cell>How keys are transferred</cell>
                          </row>
                          <row>
                            <cell>How keys are stored</cell>
                          </row>
                          <row>
                            <cell>How keys are recovered</cell>
                          </row>
                          <row>
                            <cell>How keys are revoked</cell>
                          </row>
                          <row>
                            <cell>How keys are destroyed</cell>
                          </row>
                          <row>
                            <cell rowspan="2">Maintenance</cell>
                            <cell>Maintaining the cryptographic system software and hardware</cell>
                          </row>
                          <row>
                            <cell>Destroying cryptographic equipment and media</cell>
                          </row>
                          <row>
                            <cell>Objectives</cell>
                            <cell>Objectives of the cryptographic system and KMP, including agency aims</cell>
                          </row>
                          <row>
                            <cell rowspan="3">References</cell>
                            <cell>Relevant ACSIs</cell>
                          </row>
                          <row>
                            <cell>Vendor documentation</cell>
                          </row>
                          <row>
                            <cell>Related policies</cell>
                          </row>
                          <row>
                            <cell rowspan="3">Sensitivity or classification</cell>
                            <cell>Sensitivity or classification of the cryptographic system hardware</cell>
                          </row>
                          <row>
                            <cell>Sensitivity or classification of the cryptographic system software</cell>
                          </row>
                          <row>
                            <cell>Sensitivity or classification of the cryptographic system documentation</cell>
                          </row>
                          <row>
                            <cell rowspan="7">System description</cell>
                            <cell>Sensitivity or classification of information protected</cell>
                          </row>
                          <row>
                            <cell>The use of keys</cell>
                          </row>
                          <row>
                            <cell>The environment</cell>
                          </row>
                          <row>
                            <cell>Administrative responsibilities</cell>
                          </row>
                          <row>
                            <cell>Key algorithm</cell>
                          </row>
                          <row>
                            <cell>Key length</cell>
                          </row>
                          <row>
                            <cell>Key lifetime</cell>
                          </row>
                          <row>
                            <cell>Topology</cell>
                            <cell>Diagrams and description of the cryptographic system topology including data flows</cell>
                          </row>
                    </table>
                </content>
              </block>
              <block>
                <ID>0511</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Contents of Key Management Plans</title>
                <content>
                  <para>
                    The level of detail included in a KMP must be consistent with the criticality and sensitivity or classification of the information to be protected.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Access register</title>
						<content>
							<para>
								Access registers can assist in documenting personnel who have privileged access to cryptographic systems along with previous accounting and audit activities for the system.
							</para>
						</content>
            <controls>
              <block>
                <ID>1005</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Access register</title>
                <content>
                  <list>
                    <head>Agencies should hold and maintain an access register that records cryptographic system information such as:</head>
                    <item>
                      details of personnel with system administrator access
                    </item>
                    <item>
                      details of those whose system administrator access was withdrawn
                    </item>
                    <item>
                      details of system documents
                    </item>
                    <item>
                      accounting activities
                    </item>
                    <item>
                      audit activities.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information key management practices can be found in AS 11770.1:2003, Information Technology – Security Techniques – Key Management.
              </para>
              <para>
                ACSI 53 and ACSI 105 can also be consulted for additional information on high grade cryptography.
              </para>
              <para>
                Further information relating to physical security is contained in the Australian Government Physical Security Management Protocol.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Network Security</title>
      <section>
        <title>Network Management</title>
        <objective>
          <block>
            <content>
              <para>
                The configuration of networks is controlled through appropriate change management processes.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the management of network infrastructure.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
						<content>
							<para>
								Agencies can structure and configure their networks to reduce the number of potential entry points that could be used to gain unauthorised access to information or disrupt agency services. Appropriate network management practices and procedures can assist in identifying and addressing network vulnerabilities.
							</para>
						</content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Configuration management</title>
						<content>
							<para>
								If the network is not centrally managed there could be sections of the network that do not comply with information security policies.
							</para>
							<para>
								Changes should be approved by a change management process involving representatives from all parties involved in the management of the network. This process ensures that changes are understood by all parties and reduces the likelihood of an unexpected impact on the network.
							</para>
						</content>
            <controls>
              <block>
                <ID>0513</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration management</title>
                <content>
                  <para>
                    Agencies should keep the network configuration under the control of a central network management authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0514</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration management</title>
                <content>
                  <para>
                    All changes to the configuration should be documented and approved through a formal change control process.
                  </para>
                </content>
              </block>
              <block>
                <ID>0515</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration management</title>
                <content>
                  <para>
                    Agencies should regularly review their network configuration to ensure that it conforms to the documented network configuration.
                  </para>
                </content>
              </block>
              <block>
                <ID>1007</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration management</title>
                <content>
                  <para>
                    Agencies should deploy an automated tool that compares the running configuration of network devices against the documented configuration.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Network documentation</title>
						<content>
							<para>
								Detailed network documentation and configuration details can contain information about Internet Protocol (IP) addresses, software version numbers and patch status, security enforcing devices and information about enclaves contain highly valuable information. This information could be used by an attacker to compromise an agency’s network.
							</para>
						</content>
            <controls>
              <block>
                <ID>1177</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Network documentation</title>
                <content>
                  <para>
                    Detailed network configuration documentation must be classified to at least the same level as the network or enclave it documents (e.g. for a SECRET network, the network configuration documents should at least be classified SECRET).
                  </para>
                </content>
              </block>
              <block>
                <ID>1178</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Network documentation</title>
                <content>
                  <para>
                    Agencies providing network documentation to a third party, such as to a commercial provider, must only provide information necessary for them to undertake their contractual services and functions, in line with the need-to-know principle.
                  </para>
                </content>
              </block>
              <block>
                <ID>1179</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Network documentation</title>
                <content>
                  <para>
                    Agencies must perform a security risk assessment before providing network documentation to a third party, such as a commercial provider.
                  </para>
                </content>
              </block>
              <block>
                <ID>1180</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Network documentation</title>
                <content>
                  <para>
                    Agencies must not publish sensitive or classified network configuration information in tender documentation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Network diagrams</title>
						<content>
							<para>
								A network diagram illustrates all network devices such as firewalls, Intrusion Detection Systems (IDSs), routers and switches. It does not need to illustrate all Information and Communications Technology (ICT) equipment on the network, such as workstations or printers, although the inclusion of significant devices such as servers could aid in its interpretation.
							</para>
							<list>
								<head>As most decisions are made on the documentation that illustrates the network, it is important that:</head>
								<item>
									a network diagram exists
								</item>
								<item>
									the network diagram is an accurate depiction of the network
								</item>
								<item>
									the network diagram indicates when it was last updated.
								</item>
							</list>
						</content>
            <controls>
              <block>
                <ID>0516</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Network diagrams</title>
                <content>
                  <list>
                    <head>For each network an agency must have:</head>
                    <item>
                      a high-level diagram showing all connections into the network
                    </item>
                    <item>
                      a logical network diagram showing all network devices.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Updating network diagrams</title>
						<content>
							<para>
								Due to the importance of the network diagram and decisions made based upon its contents, the network diagram should be updated as changes are made to the network. This will assist system administrators to completely understand and adequately protect the network.
							</para>
						</content>
            <controls>
              <block>
                <ID>0517</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Updating network diagrams</title>
                <content>
                  <list>
                    <head>Network diagrams should:</head>
                    <item>
                      be updated as network changes are made
                    </item>
                    <item>
                      include a ‘Current as at [date]’ statement on each page.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0518</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Updating network diagrams</title>
                <content>
                  <list>
                    <head>Network diagrams must:</head>
                    <item>
                      be updated as network changes are made
                    </item>
                    <item>
                      include a ‘Current as at [date]’ statement on each page.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Limiting network access</title>
						<content>
							<para>
								If an attacker has limited opportunities to connect to a given network, they have limited opportunities to attack that network. Network access controls not only prevent attackers gaining access to a network but also prevent system users carelessly connecting a network to another network. It is also useful in segregating sensitive or compartmented information for specific system users with a need-to-know.
							</para>
							<para>
								Circumventing some network access controls can be trivial. However, their use is primarily aimed at the protection they provide against accidental connection to another network.
							</para>
						</content>
            <controls>
              <block>
                <ID>0520</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Limiting network access</title>
                <content>
                  <para>
                    Agencies should implement network access controls (e.g. through use of the IEEE 802.1x standard) on all networks.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Network segmentation</title>
						<content>
							<para>
								Separating an agency’s network into multiple functional segments makes it difficult for an intruder to propagate inside the agency’s network. Proper network segmentation assists in the creation and maintenance of proper network access control lists.
							</para>
						</content>
            <controls>
              <block>
                <ID>1181</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Limiting network access</title>
                <content>
                  <para>
                    Agencies should divide their network into logical segments according to the function and security requirements of the devices connected to the network. For example, user workstations should be on one network segment and authentication servers on a separate network segment.
                  </para>
                </content>
              </block>
              <block>
                <ID>1182</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Limiting network access</title>
                <content>
                  <para>
                    Agencies should implement network access controls to limit traffic within and between network segments to only those that are required for business operations. For example, computer management traffic should be permitted between systems used for administration and workstations, but not permitted from workstation to workstation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Management traffic</title>
						<content>
							<para>
								Implementing security measures specifically for management traffic provides another layer of defence on a network should an attacker find an opportunity to connect to the network. This also makes it more difficult for an attacker to enumerate their target network.
							</para>
						</content>
            <controls>
              <block>
                <ID>1006</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Management traffic</title>
                <content>
                  <para>
                    Agencies should implement security measures to minimise the security risk of unauthorised access to network management traffic travelling across a network.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Virtual Local Area Networks</title>
        <objective>
          <block>
            <content>
              <para>
                Virtual Local Area Networks (VLANs) are deployed in a secure manner that does not compromise the security of information and systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the use of VLANs in networks.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Multi Protocol Label Switching</title>
            <content>
              <para>
                For the purposes of this section, Multi Protocol Label Switching is considered to be equivalent to VLANs and is subject to the same controls.
              </para>
            </content>
          </block>
          <block>
            <title>Separation of networks in the same security domain</title>
            <content>
              <para>
                A single network, managed in accordance with a single System Security Plan (SSP), for which some separation is needed for administrative or similar reasons, can use VLANs to achieve that separation.
              </para>
              <para>
                VLANs can also be used to separate IP telephony traffic from data traffic at the same sensitivity or classification.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Using Virtual Local Area Networks</title>
						<content>
            <para>
              Limiting the sharing of a common switch between VLANs of differing security domains reduces the chance of data leaks that could occur due to VLAN vulnerabilities. Furthermore, disabling trunking on switches that carry VLANs of differing security domains will also reduce the security risk of data leakage across the VLANs.
            </para>
						</content>
            <controls>
              <block>
                <ID>0529</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Using Virtual Local Area Networks</title>
                <content>
                  <para>
                    Agencies must not use VLANs between classified networks and any other network of a lower classification.
                  </para>
                </content>
              </block>
              <block>
                <ID>1138</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Using Virtual Local Area Networks</title>
                <content>
                  <para>
                    Agencies must not use VLANs between a sensitive or classified network and public network infrastructure.
                  </para>
                </content>
              </block>
              <block>
                <ID>0535</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Using Virtual Local Area Networks</title>
                <content>
                  <para>
                    VLAN trunking must not be used on switches managing VLANs of differing security domains.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Configuration and administration</title>
						<content>
							<para>
								When administrative access is limited to originating from the most trusted network on a switch, the security risk of a data spill is reduced.
							</para>
						</content>
            <controls>
              <block>
                <ID>0530</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Configuration and administration</title>
                <content>
                  <para>
                    Administrative access must only be permitted from the most trusted network.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Disabling unused ports</title>
						<content>
							<para>
								Disabling unused ports on a switch will reduce the attack surface from which attacks could be launched.
							</para>
						</content>
            <controls>
              <block>
                <ID>0533</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration and administration</title>
                <content>
                  <para>
                    Unused ports on the switches should be disabled.
                  </para>
                </content>
              </block>
              <block>
                <ID>0534</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Configuration and administration</title>
                <content>
                  <para>
                    Unused ports on the switches must be disabled.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Wireless Local Area Networks</title>
        <objective>
          <block>
            <content>
              <para>
                Wireless Local Area Networks (WLANs) are deployed in a secure manner that does not compromise the security of information and systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes 802.11 WLANs.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information covering wireless communications other than 802.11 WLANs can be found in the Communications Systems and Devices chapter
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Providing wireless communications for public access</title>
						<content>
							<para>
								To ensure that a wireless network provided for the general public to access cannot be used as a launching platform for further attacks, it must be physically segregated from all other systems.
							</para>
						</content>
            <controls>
              <block>
                <ID>0536</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Providing wireless communications for public access</title>
                <content>
                  <para>
                    Agencies deploying a wireless network for the general public to access must physically segregate it from all other agency networks.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Using wireless communications</title>
						<content>
							<para>
								As the accreditation authority for TOP SECRET systems, the Defence Signals Directorate (DSD) has mandated that all agencies considering deploying a wireless TOP SECRET network must seek approval from DSD before initiating any projects.
							</para>
						</content>
            <controls>
              <block>
                <ID>0538</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Using wireless communications</title>
                <content>
                  <para>
                    Agencies must not use wireless networks unless the security of the wireless deployment has been approved by DSD.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Wired Equivalent Privacy</title>
						<content>
							<para>
								Wired Equivalent Privacy (WEP) has serious flaws which allow it to be easily compromised. A WEP network should be considered equivalent to an unprotected network.
							</para>
						</content>
            <controls>
              <block>
                <ID>0539</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Wired Equivalent Privacy</title>
                <content>
                  <para>
                    Agencies must not use WEP for wireless deployments.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Wi-Fi Protected Access</title>
						<content>
							<para>
								Wi-Fi Protected Access (WPA) has been superseded by WPA2. Agencies are strongly encouraged to deploy WPA2 wireless networks instead of WPA based wireless networks.
							</para>
						</content>
            <controls>
              <block>
                <ID>0540</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Wi-Fi Protected Access</title>
                <content>
                  <para>
                    Agencies should not use Wi-Fi Protected Access for wireless deployments.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Authentication</title>
						<content>
							<para>
								Authenticating each end of a wireless link will prevent a range of man-in-the-middle and rogue Wireless Access Point (WAP) attacks. 
							</para>
							<para>
								The use of WPA2 with Extensible Authentication Protocol-Transport Layer Security (EAP-TLS), or an evaluated Virtual Private Network solution, will satisfy the requirement for mutual authentication and reduce the security risk of off-line brute-forcing of passphrases when using pre-shared keys.
							</para>
						</content>
            <controls>
              <block>
                <ID>0541</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Authentication</title>
                <content>
                  <para>
                    Agencies should use WPA2 with EAP-TLS for wireless deployments.
                  </para>
                </content>
              </block>
              <block>
                <ID>0542</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Authentication</title>
                <content>
                  <para>
                    Agencies not using WPA2 with EAP-TLS should use an authentication protocol that authenticates each end of the link.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Encryption</title>
						<content>
							<para>
								As wireless transmissions are capable of radiating outside of secured areas into unsecured areas, they need to be encrypted to the same level as information communicated over cabled infrastructure in unsecured areas.
							</para>
						</content>
            <controls>
              <block>
                <ID>0543</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Encryption</title>
                <content>
                  <para>
                    Agencies using wireless networks to communicate sensitive or classified information must use encryption approved for communicating such information over public network infrastructure.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Pre-shared keys</title>
						<content>
							<para>
								While the use of pre-shared keys is not recommended for wireless authentication, the longer the pre-shared keys are the greater the security they provide.
							</para>
						</content>
            <controls>
              <block>
                <ID>1010</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Pre-shared keys</title>
                <content>
                  <para>
                    Agencies should not use pre-shared keys for wireless authentication.
                  </para>
                </content>
              </block>
              <block>
                <ID>1011</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Pre-shared keys</title>
                <content>
                  <para>
                    If pre-shared keys are used, agencies should ensure random keys of the maximum allowable length are implemented.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Management frames</title>
						<content>
							<para>
								Effective denial-of-service attacks can be performed on the 802.11 protocol by exploiting unprotected management frames using inexpensive commercial hardware. WPA2 provides no protection for management frames and therefore does not prevent spoofing or denial-of-service attacks.
							</para>
						</content>
            <controls>
              <block>
                <ID>1012</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Management frames</title>
                <content>
                  <para>
                    Agencies should take steps to ensure the confidentiality, integrity and authenticity of 802.11 management frames.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Documentation</title>
						<content>
							<para>
								Wireless device driver and WAP vulnerabilities are very exposed to the threat environment and require specific attention as exploits can provide immediate unauthorised access to the network.
							</para>
						</content>
            <controls>
              <block>
                <ID>0544</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Documentation</title>
                <content>
                  <para>
                    Key generation, distribution and rekeying procedures should be documented in a SSP for the wireless network.
                  </para>
                </content>
              </block>
              <block>
                <ID>0860</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Documentation</title>
                <content>
                  <para>
                    Wireless device drivers and their versions should be documented in the SSP for the wireless network.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Devices connecting to non-agency controlled wireless networks</title>
						<content>
							<para>
								When devices connect to non-agency controlled wireless networks, particularly public wireless hotspots, the devices may be exposed to viruses, malware or other malicious code circulating on the network. If a device becomes infected and is later connected to an agency controlled wireless network then a crossover of viruses, malware or malicious code could occur.
							</para>
						</content>
            <controls>
              <block>
                <ID>1081</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Devices connecting to non-agency controlled wireless networks</title>
                <content>
                  <para>
                    Agencies should advise system users of the security risks connecting devices to non-agency controlled wireless networks.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Radio Frequency controls</title>
						<content>
							<para>
								Minimising the output power of wireless devices and using Radio Frequency (RF) shielding on facilities will assist in limiting the wireless communications to areas under the control of the agency.
							</para>
						</content>
            <controls>
              <block>
                <ID>1013</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Radio Frequency controls</title>
                <content>
                  <list>
                    <head>Agencies should limit the effective range of communications outside their area of control by:</head>
                    <item>
                      minimising the output power level of wireless devices
                    </item>
                    <item>
                      RF shielding.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Video Conferencing and Internet Protocol Telephony</title>
        <objective>
          <block>
            <content>
              <para>
                Video conferencing and IP telephony, including Voice over Internet Protocol (VoIP), is deployed in a secure manner that does not compromise the security of information and systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes security requirements for video conferencing and IP telephony, including VoIP. Although IP telephony refers to the transport of telephone calls over IP networks, the scope of this section includes connectivity to the Public Switched Telephone Network (PSTN) as well as remote sites.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Additional information on topics covered in this section can be found in the Product Security chapter, the Telephones and Telephone Systems section of the Communications Systems and Devices chapter, the Mobile Devices section of the Working Off-Site chapter, the Gateway Security chapter and any section relating to the protection of data networks in this manual.
              </para>
						</content>
					</block>
					<block>
            <title>Video and voice-aware firewall requirement</title>
            <content>
              <para>
                Where an analogue telephone network, such as the PSTN, is connected to a data network the Gateways section of the Gateway Security chapter does not apply.
              </para>
              <para>
                Where a video conferencing or IP telephony network is connected to another video conferencing or IP telephony network in a different security domain the Gateways section of the Gateway Security chapter applies.
              </para>
						</content>
					</block>
					<block>
             <title>Hardening video conferencing and Internet Protocol telephony infrastructure</title>
            <content>
              <list>
                <head>Video conferencing and IP telephony traffic in a data network consists of IP packets and should be treated the same as other data. As such, hardening can be applied to video conferencing units, handsets, software, servers, firewalls and gateways. For example, a Session Initiation Protocol server must:</head>
                <item>
                  have a fully patched operating system
                </item>
                <item>
                  have fully patched software
                </item>
                <item>
                  run only required services
                </item>
                <item>
                  use encrypted non-replayable authentication.
                </item>
              </list>
              <para>
                Apply network restrictions that only allow secure Session Initiation Protocol and secure Real-time Transport Protocol (RTP) traffic from video conferencing units and IP phones on a VLAN to reach the server.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Video and voice-aware firewalls</title>
						<content>
            <para>
              The use of video and voice-aware firewalls ensures that only video and voice traffic (e.g. signalling and data) is allowed for a given call and that the session state is maintained throughout the transaction.
            </para>
            <para>
              The requirement to use a video or voice-aware firewall does not necessarily require separate firewalls be deployed for video conferencing, IP telephony and data traffic. If possible, agencies are encouraged to implement one firewall that is either video and data-aware, voice and data-aware; or video, voice and data-aware depending on their needs.
            </para>
            </content>
            <controls>
              <block>
                <ID>0546</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Video and voice-aware firewalls</title>
                <content>
                  <para>
                    Agencies using video conferencing or IP telephony that have a requirement to implement an evaluated firewall in a gateway environment should use an evaluated video or voice-aware firewall of at least the same level of assurance.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Protecting video conferencing and Internet Protocol telephony traffic</title>
            <content>
							<para>
								Video conferencing and IP telephony traffic is vulnerable to eavesdropping but can be easily protected with encryption. This helps protect against denial-of-service, man-in-the-middle and call spoofing attacks made possible by inherent weaknesses in the video conferencing and IP telephony protocols.
							</para>
							<para>
								When protecting video conferencing and IP telephony traffic, voice control signalling can be protected using Transport Layer Security (TLS) and the ‘sips://’ identifier to force the encryption of all legs of the connection. Similar protections are available for RTP and the Real-time Control Protocol.
							</para>
            </content>
            <controls>
              <block>
                <ID>0547</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Protecting video conferencing and Internet Protocol telephony traffic</title>
                <content>
                  <para>
                    Agencies should protect video conferencing and IP telephony signalling and data to ensure confidentiality, integrity, availability, authenticity and non-replayability.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Establishment of secure signalling and data protocols</title>
            <content>
							<para>
								Use of secure signalling and data protects against eavesdropping, some types of denial-of-service, man-in-the-middle and call spoofing attacks.
							</para>
            </content>
            <controls>
              <block>
                <ID>0548</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Establishment of secure signalling and data protocols</title>
                <content>
                  <para>
                    Agencies should ensure that video conferencing and IP telephony functions can only be established using the secure signalling and data protocols.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Local area network traffic separation</title>
            <content>
							<para>
								Availability and quality of service are the main drivers for logical and physical separation.
							</para>
            </content>
            <controls>
              <block>
                <ID>0549</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Local area network traffic separation</title>
                <content>
                  <para>
                    Agencies should either physically or logically separate the video conferencing and IP telephony traffic from other data traffic.
                  </para>
                </content>
              </block>
              <block>
                <ID>0550</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Local area network traffic separation</title>
                <content>
                  <para>
                    Agencies must either physically or logically separate the video conferencing and IP telephony traffic from other data traffic.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Video conferencing unit and Internet Protocol phone setup</title>
						<content>
							<para>
								Video conferencing units and IP phones need to be hardened and logically or physically separated from the data network to ensure they do not provide an easy entry point to the network for an attacker. Universal Serial Bus (USB) ports on video conferencing units and IP phones may be used to circumvent USB workstation policy while unprotected management interfaces may be used to upload malicious firmware for call recording/spoofing and entry into the data network. Unauthorised devices and unauthenticated devices should be blocked by default to reduce the security risk of a denial of service.
							</para>
						</content>
            <controls>
              <block>
                <ID>0554</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Video conferencing unit and Internet Protocol phone setup</title>
                <content>
                  <para>
                    An encrypted and non-replayable two-way authentication scheme should be used for call authentication and authorisation.
                  </para>
                </content>
              </block>
              <block>
                <ID>0553</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Video conferencing unit and Internet Protocol phone setup</title>
                <content>
                  <list>
                    <head>Authentication and authorisation should be used for all actions on the video conferencing network, including:</head>
                    <item>
                      call setup
                    </item>
                    <item>
                      changing settings.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0555</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Video conferencing unit and Internet Protocol phone setup</title>
                <content>
                  <list>
                    <head>Authentication and authorisation should be used for all actions on the IP telephony network, including:</head>
                    <item>
                      registering a new IP phone
                    </item>
                    <item>
                      changing phone users
                    </item>
                    <item>
                      changing settings
                    </item>
                    <item>
                      accessing voice mail.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0551</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Video conferencing unit and Internet Protocol phone setup</title>
                <content>
                  <list>
                    <head>Agencies should:</head>
                    <item>
                      configure IP phones to authenticate themselves to the call controller upon registration
                    </item>
                    <item>
                      disable phone auto-registration and only allow a whitelist of authorised devices to access the network
                    </item>
                    <item>
                      block unauthorised devices by default
                    </item>
                    <item>
                      disable all unused and prohibited functionality.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0552</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Video conferencing unit and Internet Protocol phone setup</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      configure IP phones to authenticate themselves to the call controller upon registration
                    </item>
                    <item>
                      disable phone auto-registration and only allow a whitelist of authorised devices to access the network
                    </item>
                    <item>
                      block unauthorised devices by default
                    </item>
                    <item>
                      disable all unused and prohibited functionality.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1014</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Video conferencing unit and Internet Protocol phone setup</title>
                <content>
                  <para>
                    Agencies should use individual logins for IP phones.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Video conferencing unit and Internet Protocol phone connections to workstations</title>
						<content>
							<para>
								Availability and quality of service are the main drivers for logical and physical separation.
							</para>
						</content>
            <controls>
              <block>
                <ID>0556</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Video conferencing unit and Internet Protocol phone connections to workstations</title>
                <content>
                  <para>
                    Agencies should not connect workstations to video conferencing units or IP phones unless the workstation or the device uses VLANs or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.
                  </para>
                </content>
              </block>
              <block>
                <ID>0557</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Video conferencing unit and Internet Protocol phone connections to workstations</title>
                <content>
                  <para>
                    Agencies must not connect workstations to video conferencing units or IP phones unless the workstation or the device uses VLANs or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Lobby and shared area phones</title>
            <content>
							<para>
								Lobby IP phones are in public areas and may give an attacker an opportunity to access the internal data network (depending on separation arrangements) by replacing the IP phone with another device, or installing a device in-line. There are also the security risks of social engineering (since the call may appear to be internal) and data leakage from poorly protected voicemail boxes.
							</para>
						</content>
            <controls>
              <block>
                <ID>0558</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Lobby and shared area phones</title>
                <content>
                  <list>
                    <head>Where an agency uses an IP phone in a lobby or shared area they should limit the IP phones:</head>
                    <item>
                      ability to access data networks
                    </item>
                    <item>
                      functionality for voice mail and directory services.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1015</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Lobby and shared area phones</title>
                <content>
                  <para>
                    Agencies should use traditional analog phones in lobby and shared areas.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Software used for softphones and webcams</title>
            <content>
							<para>
								Software used for softphones and webcams can introduce additional vulnerabilities into the network as they are exposed to threats from the data network via the workstation and can subsequently be used to gain access to the video conferencing or IP telephony network.
							</para>
							<para>
								Softphones and webcams typically require workstation to workstation communication on (potentially) a number of randomly assigned ports to facilitate RTP data exchange. This presents a security risk as workstations generally should be separated, using host-based firewalls that deny all connections between workstations, to make malicious code propagation inside the network difficult.
							</para>
							<para>
								On workstations using softphones and webcams, separate network cards can facilitate a simple VLAN separation. Host-based firewalls ensure a minimal set of ports are exposed to a minimal set of workstations.
							</para>
						</content>
            <controls>
              <block>
                <ID>0559</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Software used for softphones and webcams</title>
                <content>
                  <para>
                    Agencies should not use softphones or webcams.
                  </para>
                </content>
              </block>
              <block>
                <ID>1016</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Software used for softphones and webcams</title>
                <content>
                  <para>
                    Agencies using softphones or webcams should have separate dedicated network interface cards on the host for video conferencing and IP telephony network access.
                  </para>
                </content>
              </block>
              <block>
                <ID>1017</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Software used for softphones and webcams</title>
                <content>
                  <para>
                    Agencies using softphones and webcams should install a host-based firewall on workstations that only allows traffic to and from the minimum number of ports required.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Workstations using Universal Serial Bus phones and webcams</title>
            <content>
							<para>
								Adding USB phones and webcams to a whitelist of allowed USB devices on a workstation will assist with restricting access to only authorised devices, and allowing the Standard Operating Environment to maintain defences against removable media storage and other unauthorised USB devices.
							</para>
            </content>
            <controls>
              <block>
                <ID>1018</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Workstations using Universal Serial Bus phones and webcams</title>
                <content>
                  <para>
                    Agencies should use access control software to control USB ports on workstations using USB phones and webcams by using the specific vendor and product identifier of authorised USB phones and webcams.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Developing a denial of service response plan</title>
            <content>
							<para>
								Telephony is considered critical for any business and is therefore especially vulnerable to a denial of service. The guidance provided will assist in protecting against video conferencing and IP telephony denial-of-service attacks, signalling floods, established call teardown and RTP data floods.
							</para>
            </content>
            <controls>
              <block>
                <ID>1019</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Workstations using Universal Serial Bus phones and webcams</title>
                <content>
                  <list>
                    <head>Agencies should develop a denial of service response plan including:</head>
                    <item>
                      how to diagnose the source of the denial of service
                    </item>
                    <item>
                      what actions can be taken to clear the denial of service
                    </item>
                    <item>
                      how capabilities could be maintained during a denial of service.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Content of a denial of service response plan</title>
            <content>
							<list>
								<head>A denial of service response plan will need to address the following:</head>
								<item>
									how to identify the source of the denial of service, either internal or external (location and content of logs)
								</item>
								<item>
									how to minimise the effect on video conferencing and IP telephony of a denial of service of the data network (for example, Internet or internal denial of service), including separate links to other office locations and quality of service prioritisation
								</item>
								<item>
									strategies that can mitigate the denial of service (banning certain devices/IPs at the call controller and firewalls, implementing quality of service, changing authentication, changing dial-in authentication
								</item>
								<item>
									alternative communication options (such as personal mobile phones) that have been identified for use in case of an emergency.
								</item>
							</list>
						</content>
            <controls>
              <block>
                <ID>1020</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Content of a denial of service response plan</title>
                <content>
                  <list>
                    <head>Agencies should develop a denial of service response plan include monitoring and use of:</head>
                    <item>
                      router and switch logging and flow data
                    </item>
                    <item>
                      packet captures
                    </item>
                    <item>
                      proxy and call manager logs and access control lists
                    </item>
                    <item>
                      video and voice-aware firewalls and gateways
                    </item>
                    <item>
                      network redundancy
                    </item>
                    <item>
                      load balancing
                    </item>
                    <item>
                      PSTN failover.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Email Infrastructure</title>
        <objective>
          <block>
            <content>
              <para>
                Email servers are hardened and protective marking of email messages is enforced.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes email infrastructure security.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Information on using email applications can be found in the Email Applications section of the Software Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Blocking emails</title>
            <content>
            <para>
              The intent of blocking specific types of emails is to reduce the likelihood of phishing emails and emails containing malicious code.
            </para>
            </content>
            <controls>
              <block>
                <ID>0561</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Blocking emails</title>
                <content>
                  <list>
                    <head>Agencies should block:</head>
                    <item>
                      inbound and outbound email, including any attachments, that contain either:
                    </item>
                    <item>
                      malicious code
                    </item>
                    <item>
                      content in conflict with the email policy
                    </item>
                    <item>
                      content that cannot be identified
                    </item>
                    <item>
                      encrypted content, when that content cannot be inspected for malicious code or authenticated as originating from a trusted source
                    </item>
                    <item>
                      emails addressed to internal email aliases with source addresses located from outside the domain
                    </item>
                    <item>
                      all emails arriving via an external connection where the source address uses an internal domain name.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Preventing unmarked or inappropriately marked emails</title>
            <content>
							<para>
								Unmarked or inappropriately marked emails can be blocked at two points, the workstation or the email server. The email server is the preferred location to block emails as it is a single location, under the control of system administrators, where the requirements for the entire network can be enforced. In addition email servers can apply controls for emails generated by applications.
							</para>
							<para>
								While blocking at the email server is considered the most appropriate control there is still an advantage to blocking at the workstation as this adds an extra layer of security and will also reduce the likelihood of a data spill occurring on the email server.
							</para>
							<para>
								For all systems it is important to note that all emails must have an appropriate protective marking. This requirement is described in the Email Applications section of the Software Security chapter and mirrors the requirements in the Australian Government Information Security Management Protocol for paper-based material.
							</para>
            </content>
            <controls>
              <block>
                <ID>1022</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Preventing unmarked or inappropriately marked emails</title>
                <content>
                  <para>
                    Agencies should prevent unmarked and inappropriately marked emails being sent to intended recipients by blocking the email at the workstation.
                  </para>
                </content>
              </block>
              <block>
                <ID>0562</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Preventing unmarked or inappropriately marked emails</title>
                <content>
                  <para>
                    Agencies should prevent unmarked and inappropriately marked emails being sent to intended recipients by blocking the email at the email server.
                  </para>
                </content>
              </block>
              <block>
                <ID>0875</ID>
                <revision>0</revision>
                <updated>Sep-09</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Preventing unmarked or inappropriately marked emails</title>
                <content>
                  <para>
                    Agencies must prevent unmarked and inappropriately marked emails being sent to intended recipients by blocking the email at the email server.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Blocking of outbound emails</title>
            <content>
							<para>
								Blocking an outbound email with a protective marking higher than the sensitivity or classification of the path over which it would be communicated stops data spills that could occur due to interception or storage of the email at any point along the path.
							</para>
							<para>
								Agencies may remove protective markings from emails destined for private citizens and businesses once they have been approved for release from their gateways.
							</para>
						</content>
            <controls>
              <block>
                <ID>0563</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Blocking of outbound emails</title>
                <content>
                  <para>
                    Agencies must configure systems to block any outbound emails with a protective marking indicating that the content of the email exceeds the sensitivity or classification of the path over which the email would be communicated.
                  </para>
                </content>
              </block>
              <block>
                <ID>0564</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Blocking of outbound emails</title>
                <content>
                  <para>
                    Agencies should configure systems to log every occurrence of a blocked email.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Blocking of inbound emails</title>
            <content>
							<para>
								Blocking an inbound email with a protective marking higher than the sensitivity or classification that the receiving system is accredited to prevents a data spill from occurring on the receiving system.
							</para>
            </content>
            <controls>
              <block>
                <ID>0565</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Blocking of inbound emails</title>
                <content>
                  <para>
                    Agencies must configure email systems to reject, log and report inbound emails with protective markings indicating that the content of the email exceeds the sensitivity or classification of the receiving system.
                  </para>
                </content>
              </block>
              <block>
                <ID>1023</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Blocking of inbound emails</title>
                <content>
                  <para>
                    Agencies should notify the intended recipient of any blocked emails.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Undeliverable messages</title>
            <content>
							<para>
								Undeliverable or bounce emails are commonly sent by email servers to the original sender when the email cannot be delivered, usually because the destination address is invalid. Due to the common spamming practice of spoofing sender addresses, this often results in a large amount of bounce emails being sent to an innocent third party. Sending bounces only to senders that can be verified via Sender Policy Framework (SPF), or other trusted means, avoids contributing to this problem and allows trusted parties to receive legitimate bounce messages.
							</para>
            </content>
            <controls>
              <block>
                <ID>1024</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Undeliverable messages</title>
                <content>
                  <para>
                    Agencies should only send notification of undeliverable, bounced or blocked emails to senders that can be verified via SPF or other trusted means.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Automatic forwarding of emails</title>
            <content>
							<para>
								Automatic forwarding of emails, if left unsecured, can pose a security risk to the unauthorised disclosure of sensitive or classified information. For example, a system user could setup a server-side rule to automatically forward all emails received on an Internet connected system to their personal email account outside work.
							</para>
						</content>
            <controls>
              <block>
                <ID>0566</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Automatic forwarding of emails</title>
                <content>
                  <para>Agencies must ensure that the requirements for blocking unmarked and outbound emails are also applied to automatically forwarded emails. </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Open relay email servers</title>
            <content>
				<para>An open relay email server (or open mail relay) is a server that is configured to allow anyone on the Internet to send emails through the server. Such configurations are highly undesirable as they allow spammers and worms to exploit this functionality. </para>
			</content>
            <controls>
              <block>
                <ID>0567</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Open relay email servers</title>
                <content>
                  <para>
                    Agencies must disable open email relaying so that email servers will only relay messages destined for their domains and those originating from inside the domain.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Email server maintenance activities</title>
            <content>
							<para>
								Email servers perform a critical business function. It is important that agencies perform regular email server auditing, security reviews and vulnerability analysis activities.
							</para>
            </content>
            <controls>
              <block>
                <ID>0568</ID>
                <revision>0</revision>
				<updated>Sep-08</updated>
				<classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Email server maintenance activities</title>
                <content>
                  <para>Agencies should perform regular email server auditing, security reviews and vulnerability analysis activities. </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Centralised email gateways</title>
            <content>
				<para>Without a centralised email gateway it is exceptionally difficult to deploy SPF, DomainKeys Identified Mail (DKIM) and outbound email protective marking verification. </para>
				<para>Attackers will almost invariably avoid using the primary email server when sending malicious emails. This is because the backup or alternative email gateways are often poorly maintained in terms of out-of-date blacklists and content filtering. </para>
            </content>
            <controls>
              <block>
                <ID>0569</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Centralised email gateways</title>
                <content>
                  <para>Agencies should route email through a centralised email gateway.  </para>
                </content>
              </block>
              <block>
                <ID>0570</ID>
                <revision>3</revision>
                <updated>Sept-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Centralised email gateways</title>
                <content>
                  <para>
                    Where backup or alternative email gateways are in place, additional email gateways must be maintained at the same standard as the primary email gateway.
                  </para>
                </content>
              </block>
              <block>
                <ID>0571</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Centralised email gateways</title>
                <content>
                  <para>
                    Where system users send email from outside their network, an authenticated and encrypted channel must be configured to allow email to be sent via the centralised email gateway.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Email server transport encryption</title>
            <content>
							<para>
								Email can be intercepted anywhere between the originating email server and the destination email server. Enabling TLS on the originating and accepting email server will defeat passive attacks on the network, with the exception of cryptanalysis against email traffic. TLS encryption between email servers will not interfere with email content filtering schemes. Email servers will remain compatible with other email servers as Internet Engineering Task Force (IETF) Request for Comments (RFC) 3207 specifies the encryption as opportunistic.
							</para>
            </content>
            <controls>
              <block>
                <ID>0572</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Email server transport encryption</title>
                <content>
                  <para>
                    Agencies must enable opportunistic TLS encryption as defined in IETF RFC 3207 on email servers that make incoming or outgoing email connections over public network infrastructure.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Sender Policy Framework</title>
            <content>
							<para>
								SPF, and alternative implementations such as Sender ID, aid in the detection of spoofed emails. The SPF record specifies a list of IP addresses or domains that are allowed to send email from a specific domain. If the email server that sent the email is not in the list, the verification fails. There are a number of different fail types available.
							</para>
            </content>
            <controls>
              <block>
                <ID>0574</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sender Policy Framework</title>
                <content>
                  <para>
                    Agencies must specify their mail servers using SPF or Sender ID.
                  </para>
                </content>
              </block>
              <block>
                <ID>1183</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Sender Policy Framework</title>
                <content>
                  <para>
                    Agencies should use a hard fail SPF record when specifying their mail servers.
                  </para>
                </content>
              </block>
              <block>
                <ID>1151</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Sender Policy Framework</title>
                <content>
                  <para>
                    Agencies should use SPF or Sender ID to verify the authenticity of incoming emails.
                  </para>
                </content>
              </block>
              <block>
                <ID>1152</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Sender Policy Framework</title>
                <content>
                  <para>
                    Agencies must block, mark or identify incoming emails that fail SPF checks in a manner that is visible to the email recipient.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>DomainKeys Identified Mail</title>
            <content>
							<para>
								DKIM enables a method of determining spoofed email content. The DKIM record specifies a public key that will sign the content of the message. If the signed digest in the email header does not match the signed content of the email, the verification fails.
							</para>
            </content>
            <controls>
              <block>
                <ID>0861</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>DomainKeys Identified Mail</title>
                <content>
                  <para>
                    Agencies should enable DKIM signing on all email originating from their domain.
                  </para>
                </content>
              </block>
              <block>
                <ID>1025</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>DomainKeys Identified Mail</title>
                <content>
                  <para>
                    Agencies should use DKIM in conjunction with SPF.
                  </para>
                </content>
              </block>
              <block>
                <ID>1026</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>DomainKeys Identified Mail</title>
                <content>
                  <para>
                    Agencies should verify DKIM signatures on emails received, taking into account that email distribution list software typically invalidates DKIM signatures.
                  </para>
                </content>
              </block>
              <block>
                <ID>1027</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>DomainKeys Identified Mail</title>
                <content>
                  <para>
                    Agencies operating email distribution list software used by external senders should configure the software so that it does not break the validity of the sender’s DKIM signature.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Active web addresses in emails</title>
            <content>
							<para>
								Spoofed emails often contain an active web address directing system users to a malicious website to either illicit information or infect their workstation with malicious code. To reduce the success rate of such attacks agencies can strip active web addresses from emails and replace them with non-active versions that a system user can type or copy and paste into their web browser.
							</para>
            </content>
            <controls>
              <block>
                <ID>1057</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Active web addresses in emails</title>
                <content>
                  <para>
                    Email servers should strip active web addresses from emails and replace them with non-active versions.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <list>
                <head>Further information on email security is available from the following IETF documents:</head>
                <item>
                  RFC 3207, SMTP Service Extension for Secure SMTP over Transport Layer Security
                </item>
                <item>
                  RFC 4408, Sender Policy Framework
                </item>
                <item>
                  RFC 4686, Analysis of Threats Motivating DomainKeys Identified Mail
                </item>
                <item>
                  RFC 4871, DomainKeys Identified Mail Signatures
                </item>
                <item>
                  RFC 5617, DomainKeys Identified Mail (DKIM) Author Domain Signing Practices (ADSP).
                </item>
              </list>
              <para>
                Further information on email server security can be obtained from National Institute of Standards and Technology publication SP 800-45 v2, Guidelines on Electronic Mail Security.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Intrusion Detection and Prevention</title>
        <objective>
          <block>
            <content>
              <para>
                An intrusion detection strategy is implemented for Internet connected systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes detecting and preventing malicious code propagating through networks as well as detecting and preventing unusual or malicious activities.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Methods of infections or delivery</title>
            <content>
              <list>
                <head>Malicious code can spread through a system from a number of sources including:</head>
                <item>
                  files containing macro viruses or worms
                </item>
                <item>
                  email attachments and web downloads with malicious active content
                </item>
                <item>
                  executable code in the form of applications
                </item>
                <item>
                  security weaknesses in a system or network
                </item>
                <item>
                  security weaknesses in an application
                </item>
                <item>
                  contact with an infected system or media.
                </item>
              </list>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Intrusion detection strategy</title>
            <content>
							<para>
								An IDS when configured correctly, kept current and supported by appropriate processes can be an effective way of identifying and responding to known attack profiles. Appropriate resources need to be allocated to an IDS to allow maintenance and monitoring including training and time assigned to the validation of IDS alerts and the tuning of rules.
							</para>
            </content>
            <controls>
              <block>
                <ID>0576</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Intrusion detection strategy</title>
                <content>
                  <list>
                    <head>Agencies must develop, implement and maintain an intrusion detection strategy that includes:</head>
                    <item>
                      appropriate intrusion detection mechanisms, including network-based IDSs and host-based IDSs as necessary
                    </item>
                    <item>
                      the audit analysis of event logs, including IDS logs
                    </item>
                    <item>
                      a periodic audit of intrusion detection procedures
                    </item>
                    <item>
                      information security awareness and training programs
                    </item>
                    <item>
                      a documented Incident Response Plan
                    </item>
                    <item>
                      the capability to detect cyber security incidents and attempted network intrusions on gateways and provide real-time alerts.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1184</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Intrusion detection strategy</title>
                <content>
                  <para>
                    Agencies must ensure that if an IDS is deployed, appropriate resources are allocated to maintenance and monitoring.
                  </para>
                </content>
              </block>
              <block>
                <ID>1185</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Intrusion detection strategy</title>
                <content>
                  <para>
                    When deploying an IDS on a network that is not connected to the Internet, either directly or indirectly via a cascaded connection, agencies must use an IDS that monitors unusual patterns of behaviours or traffic flows, rather than incorporating signatures that detect specific Internet-based communications protocols.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Intrusion Detection Systems on gateways</title>
            <content>
							<para>
								If the firewall is configured to block all traffic on a particular range of port numbers, then the IDS should inspect traffic for these port numbers and generate an alert if they are detected.
							</para>
            </content>
            <controls>
              <block>
                <ID>0577</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Intrusion Detection Systems on gateways</title>
                <content>
                  <para>
                    Agencies should deploy IDSs in all gateways between their networks and public network infrastructure.
                  </para>
                </content>
              </block>
              <block>
                <ID>1029</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Intrusion Detection Systems on gateways</title>
                <content>
                  <para>
                    Agencies should deploy IDSs at all gateways between their networks and any network they do not manage.
                  </para>
                </content>
              </block>
              <block>
                <ID>1028</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Intrusion Detection Systems on gateways</title>
                <content>
                  <para>
                    Agencies should locate IDSs in the gateway environment, immediately inside the outermost firewall.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Signature-based intrusion detection</title>
            <content>
							<para>
								When signature-based intrusion detection is used the effectiveness of the IDS will degrade over time as new intrusion methods are developed. It is for this reason that signatures for the IDS need to be kept current to identify the latest intrusion methods.
							</para>
            </content>
            <controls>
              <block>
                <ID>0578</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Signature-based intrusion detection</title>
                <content>
                  <para>
                    When signature-based intrusion detection is used, agencies must keep the signatures current.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Malicious code counter-measures</title>
            <content>
							<para>
								Implementing policies and procedures for preventing and dealing with malicious code outbreaks enables agencies to provide consistent incident response, as well as giving clear directions to system users about what to do in the case of a cyber security incident.
							</para>
						</content>	
            <controls>
              <block>
                <ID>0579</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Malicious code counter-measures</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      develop and maintain a set of policies and procedures covering how to:
                    </item>
                    <item>
                      minimise the likelihood of malicious code being introduced into a system
                    </item>
                    <item>
                      prevent all unauthorised code from executing on their networks
                    </item>
                    <item>
                      detect any malicious code installed on a system
                    </item>
                    <item>
                      make their system users aware of the policies and procedures
                    </item>
                    <item>
                      ensure that all instances of detected malicious code outbreaks are handled according to the procedures.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Configuring the Intrusion Detection System</title>
            <content>
            <para>
              Generating alerts for information flows that contravene any rule in the firewall rule set helps security personnel respond to suspicious or malicious traffic entering an agency’s system due to a failure or configuration change to the firewall.
            </para>
            </content>
            <controls>
              <block>
                <ID>1030</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuring the Intrusion Detection System</title>
                <content>
                  <para>
                    In addition to defined configuration requirements, IDSs located behind a firewall should be configured to generate a log entry, and an alert, for any information flows that contravene any rule in the firewall rule set.
                  </para>
                </content>
              </block>
              <block>
                <ID>1031</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuring the Intrusion Detection System</title>
                <content>
                  <para>
                    Agencies should test IDSs rule sets prior to implementation to ensure that they perform as expected.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Event management and correlation</title>
            <content>
							<para>
								Deploying tools to manage the archival and correlation of events of interest across all networks helps identify suspicious patterns in information flows.
							</para>
            </content>
            <controls>
              <block>
                <ID>1032</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Event management and correlation</title>
                <content>
                  <list>
                    <head>Agencies should deploy tools for:</head>
                    <item>
                      the management and retention of security event information, with the appropriate metadata for the maintenance of the information’s integrity
                    </item>
                    <item>
                      the correlation of events of interest across all networks.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Host-based Intrusion Detection Systems</title>
            <content>
							<para>
								Host-based IDSs use behaviour-based detection schemes and can therefore detect malicious code that has yet to be identified by vendors.
							</para>
            </content>
            <controls>
              <block>
                <ID>1034</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Host-based Intrusion Detection Systems</title>
                <content>
                  <para>
                    Agencies should install host-based IDSs on high value servers, such as authentication servers (e.g. Active Directory Domain Controllers and RADIUS servers), Domain Name System (DNS) servers, web servers, file servers and email servers. 
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Active content blocking</title>
            <content>
							<para>
								Filtering unnecessary content and disabling unwanted functionality reduces the number of possible entry points that an attacker can exploit.
							</para>
            </content>
            <controls>
              <block>
                <ID>1035</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Active content blocking</title>
                <content>
                  <list>
                    <head>Agencies should use:</head>
                    <item>
                      filters to block unwanted content and exploits against applications that cannot be patched
                    </item>
                    <item>
                      settings in the applications to disable unwanted functionality
                    </item>
                    <item>
                      digital signatures to restrict active content to trusted sources only.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Additional information relating to intrusion detection and audit analysis is contained in HB 171:2003, Guidelines for the Management of Information Technology Evidence.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Internet Protocol version 6</title>
        <objective>
          <block>
            <content>
              <para>
                Internet Protocol version 6 (IPv6) is disabled until it is ready to be deployed.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes IPv6 and its deployment in networks.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Where this manual specifies requirements for network devices, the requirements apply equally whether deploying IPv6 or Internet Protocol version 4.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Purchasing of compatible hardware</title>
            <content>
							<para>
								Agencies should ensure that all hardware and software that is purchased is IPv6 capable.
							</para>
            </content>
            <controls>
              <block>
                <ID>1186</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Purchasing of compatible hardware</title>
                <content>
                  <para>
                    Agencies should ensure that new security hardware and software (e.g. firewalls and IDSs) is IPv6 capable.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Use of dual-stack functionality</title>
            <content>
							<para>
								In order to reduce the risk of attack to their systems, agencies need to disable unused services and functions in network devices, ICT equipment and operating systems. This includes dual-stack functionality if it is not being used.
							</para>
            </content>
            <controls>
              <block>
                <ID>0521</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Purchasing of compatible hardware</title>
                <content>
                  <para>
                    Agencies not using IPv6, but which have deployed dual-stack network devices, ICT equipment or operating systems that support IPv6, must disable the functionality.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Using Internet Protocol version 6</title>
            <content>
							<para>
								The security implications around the use of IPv6 are still largely unknown and untested. As many of the current network protection technologies such as firewalls and IDSs do not currently support IPv6, agencies choosing to implement IPv6 face a significant security risk of being compromised.
							</para>
            </content>
            <controls>
              <block>
                <ID>0523</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Using Internet Protocol version 6</title>
                <content>
                  <para>
                    Agencies using IPv6 must conduct a security risk assessment on any security risks that could be introduced as a result of running a dual stack environment or transitioning completely to IPv6.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Introducing Internet Protocol version 6 into gateways</title>
            <content>
							<para>
								Introducing IPv6 into gateways introduces a significant number of new security risks. Undergoing reaccreditation when IPv6 is introduced will ensure that any IPv6 functionality that is not intended to be used cannot be exploited by an attacker before appropriate security measures have been put in place.
							</para>
            </content>
            <controls>
              <block>
                <ID>0524</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Introducing Internet Protocol version 6 into gateways</title>
                <content>
                  <para>
                    Agencies deploying IPv6 in their gateways should undergo reaccreditation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Enabling Internet Protocol version 6 in gateways</title>
            <content>
							<para>
								Once agencies have completed the transition to a dual-stack environment or completely to an IPv6 environment, reaccreditation will assist in ensuring that the associated security measures for IPv6 are working effectively
							</para>
						</content>
            <controls>
              <block>
                <ID>0525</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Enabling Internet Protocol version 6 in gateways</title>
                <content>
                  <para>
                    Agencies enabling IPv6 in their gateways must undergo reaccreditation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                A Strategy for the Transition to IPv6 for Australian Government agencies can be found on the Australian Government Information Management Office website at http://www.finance.gov.au/e-government/infrastructure/internet-protocol-version-6.html.
              </para>
              <list>
                <head>Additional IPv6 information can be found at:</head>
                <item>
                  http://www.nsa.gov/ia/guidance/security_configuration_guides/IPv6.shtml
                </item>
                <item>
                  http://www.cpni.gov.uk/Documents/Publications/2006/2006005-TN0206_Security_IPv6.pdf
                </item>
                <item>
                  http://www.cpni.gov.uk/documents/publications/2011/2011mar22-infosec-cpni_viewpoint_security_implications_of_ipv6.pdf.
                </item>
              </list>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Data Transfers</title>
        <objective>
          <block>
            <content>
              <para>
                Data is transferred between systems in a controlled and accountable manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes data transfers between systems. It applies equally to data transfers using removable media and to data transfers via gateways.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Additional requirements for data transfers using removable media can be found in the Media Usage section of the Media Security chapter while additional requirements for data transfers via gateways can be found in the Data Import and Export section of the Gateway Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>System user responsibilities</title>
            <content>
							<para>
								When system users transfer data to or from a system they need to be aware of the potential consequences of their actions. This could include data spills of sensitive or classified data onto systems not accredited to handle the data, or the unintended introduction of malicious code to a system. Accordingly system users need to be held accountable for all data transfers that they make.
							</para>
						</content>
            <controls>
              <block>
                <ID>0661</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user responsibilities</title>
                <content>
                  <para>
                    Agencies must ensure that system users transferring data to and from a system are held accountable for the data they transfer.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Data transfer processes and procedures</title>
            <content>
							<para>
								Ensuring that correct processes and procedures are adhered to facilitates the appropriate and consistent application of security controls as well as the generation of necessary audit records.
							</para>
						</content>
            <controls>
              <block>
                <ID>0662</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Data transfer processes and procedures</title>
                <content>
                  <para>
                    Agencies should ensure that data transfers are performed in accordance with processes and procedures approved by the accreditation authority.
                  </para>
                </content>
              </block>
              <block>
                <ID>0663</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Data transfer processes and procedures</title>
                <content>
                  <para>
                    Agencies must ensure that data transfers are performed in accordance with processes and procedures approved by the accreditation authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Data transfer authorisation</title>
						<content>
							<list>
								<head>System users can help prevent cyber security incidents by:</head>
								<item>
									checking protective markings to ensure that the destination system is appropriate for the data being transferred
								</item>
								<item>
									performing antivirus checks on data to be transferred to and from a system
								</item>
								<item>
									following all processes and procedures for the transfer of data.
								</item>
							</list>
						</content>
            <controls>
              <block>
                <ID>0664</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Data transfer authorisation</title>
                <content>
                  <para>
                    Agencies must ensure that all data transferred to a system of a lesser sensitivity or classification is approved by a trusted source.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Trusted sources</title>
						<content>
							<para>
								Trusted sources include security personnel such as the Chief Information Security Officer, the Information Technology Security Advisor, Information Technology Security Managers and Information Technology Security Officers.
							</para>
						</content>
            <controls>
              <block>
                <ID>0665</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Trusted sources</title>
                <content>
                  <list>
                    <head>Trusted sources must be:</head>
                    <item>
                      a strictly limited list derived from business requirements and the result of a security risk assessment
                    </item>
                    <item>
                      approved by the accreditation authority.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Import of data</title>
						<content>
							<para>
								Scanning imported data for malicious content reduces the security risk of a system being infected, thus allowing the continued confidentiality, integrity and availability of the system.
							</para>
							<para>
								Format checks provide a method to prevent known malicious formats from entering the system. Keeping and regularly auditing these logs allow for the system to be checked for any unusual usage.
							</para>
						</content>
            <controls>
              <block>
                <ID>0657</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Import of data</title>
                <content>
                  <para>
                    Agencies importing data to a system must ensure that the data is scanned for malicious and active content.
                  </para>
                </content>
              </block>
              <block>
                <ID>0658</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Import of data</title>
                <content>
                  <list>
                    <head>Agencies importing data to a system must implement the following controls:</head>
                    <item>
                      scanning for malicious and active content
                    </item>
                    <item>
                      data format checks
                    </item>
                    <item>
                      log of each event
                    </item>
                    <item>
                      monitoring to detect overuse/unusual usage patterns.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Export of data</title>
						<content>
							<para>
								When data is exported between systems, protective marking checks can reduce the security risk of data being transferred to a system that is not accredited to handle it or into the public domain.
							</para>
							<para>
								When highly formatted textual data with no free-text fields is transferred between systems the checking requirements are lessened due to the strongly defined format of the data.
							</para>
							<para>
								As data that it is not highly formatted textual data cannot be thoroughly checked in an automated manner, a number of checking measures are needed to ensure that classified data is not accidentally transferred to a system not accredited to handle it or into the public domain.
							</para>
						</content>
            <controls>
              <block>
                <ID>1187</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of data</title>
                <content>
                  <para>
                    When exporting data, agencies must implement protective marking checks.
                  </para>
                </content>
              </block>
              <block>
                <ID>0669</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of data</title>
                <content>
                  <list>
                    <head>When exporting formatted textual data with no free-text fields and all fields have a predefined set of permitted values, agencies must implement the following controls:</head>
                    <item>
                      protective marking checks
                    </item>
                    <item>
                      log of each event
                    </item>
                    <item>
                      monitoring to detect overuse/unusual usage patterns.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0670</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of data</title>
                <content>
                  <list>
                    <head>When exporting data, other than highly formatted textual data, agencies must implement the following controls:</head>
                    <item>
                      protective marking checks
                    </item>
                    <item>
                      log of each event
                    </item>
                    <item>
                      monitoring to detect overuse/unusual usage patterns
                    </item>
                    <item>
                      data format checks
                    </item>
                    <item>
                      limitations on data types
                    </item>
                    <item>
                      keyword searches
                    </item>
                    <item>
                      size limits.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Preventing export of particularly sensitive data to foreign systems</title>
						<content>
							<para>
								In order to reduce the security risk of spilling data with a caveat onto foreign systems, it is important that procedures are developed to detect Australian Eyes Only (AUSTEO) and Australian Government Access Only (AGAO) data and to prevent it from crossing into foreign systems.
							</para>
						</content>
            <controls>
              <block>
                <ID>0678</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Preventing export of particularly sensitive data to foreign systems</title>
                <content>
                  <list>
                    <head>Agencies must:</head>
                    <item>
                      ensure that keyword searches are performed on all textual data
                    </item>
                    <item>
                      ensure that any identified data is quarantined until reviewed and approved for release by a trusted source other than the originator
                    </item>
                    <item>
                      develop procedures to prevent AUSTEO and AGAO information in both textual and non-textual formats from being exported.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Peripheral Switches</title>
        <objective>
          <block>
            <content>
              <para>
                An evaluated peripheral switch is used when sharing keyboards, monitors and mice between different systems.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the use of keyboard/video/mouse switches.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                For more information on DSD’s Evaluated Products List (EPL) see the Product Security section.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Peripheral switches</title>
            <content>
							<para>
								The level of assurance needed in a peripheral switch is determined by the highest and lowest sensitivity or classification of systems connected to the switch.
							</para>
							<para>
								When accessing systems through a peripheral switch it is important that sufficient assurance is available in the operation of the switch to ensure that information does not accidently pass between the connected systems
							</para>
            </content>
            <controls>
              <block>
                <ID>0591</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Peripheral switches</title>
                <content>
                  <para>
                    Agencies accessing a classified system and a sensitive system via a peripheral switch must use an Evaluation Assurance Level (EAL) 2 product from DSD’s EPL.
                  </para>
                </content>
              </block>
              <block>
                <ID>0593</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Peripheral switches</title>
                <content>
                  <para>
                    Agencies accessing a highly classified system and a less classified system or sensitive system via a peripheral switch must use a high assurance product from DSD’s EPL.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Peripheral switches for particularly sensitive systems</title>
            <content>
							<para>
								As AUSTEO and AGAO systems are particularly sensitive additional security measures need to be put in place when connecting them to other systems.
							</para>
            </content>
            <controls>
              <block>
                <ID>0594</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Peripheral switches for particularly sensitive systems</title>
                <content>
                  <para>
                    Agencies accessing a system containing AUSTEO or AGAO information and a system of the same classification that is not accredited to process the same caveat should use an EAL 2 product from DSD’s EPL.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Ensuring Service Continuity</title>
        <objective>
          <block>
            <content>
              <para>
                Agencies take steps to ensure that their services are available if an adversary attempts to flood their network with unwanted traffic.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section outlines steps for minimising the effect of attacks aimed at disrupting or degrading services provided by an agency.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Additional information on business continuity and disaster recovery can be found in the Information Security Monitoring chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Contacting Internet service providers</title>
            <content>
							<para>
								Agencies’ Internet service providers are in a unique position to assist in the mitigation of Distributed Denial-of-Service (DDoS) attacks. Proper coordination between agencies and their Internet service providers is essential to ensure resilience against such attacks.
							</para>
            </content>
            <controls>
              <block>
                <ID>1188</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Contacting Internet service providers</title>
                <content>
                  <para>
                    Agencies should ensure their Internet service provider can respond in the event of a DDoS attack against the agency’s network.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Planning</title>
            <content>
							<para>
								Effective planning with an Internet service provider is a key part of defending against DDoS attacks.
							</para>
            </content>
            <controls>
              <block>
                <ID>1189</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Planning</title>
                <content>
                  <para>
                    Agencies should have a denial of service mitigation plan with their Internet service provider, outlining pre-approved actions that can be taken in the event of a DDoS attack.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Maintaining multiple Internet links</title>
						<content>
							<para>
								The use of multiple Internet links increases an agency’s options for responding to DDoS attacks, and increases the complexity required for a successful DDoS attack.
							</para>
						</content>
            <controls>
              <block>
                <ID>1190</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Maintaining multiple Internet links</title>
                <content>
                  <para>
                    Agencies should use multiple Internet links provided by different Internet service providers.
                  </para>
                </content>
              </block>
              <block>
                <ID>1191</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Maintaining multiple Internet links</title>
                <content>
                  <para>
                    If an agency has multiple Internet links, it should use separate links for public facing services (e.g. web servers and public DNS) and routine agency business (e.g. Internet access for system users and remote connectivity).
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Gateway Security</title>
      <section>
        <title>Gateways</title>
        <objective>
          <block>
            <content>
              <para>
                Gateways facilitate secure information transfers between systems of different security domains.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the use of gateways including cross domain solutions.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Gateways act as information flow control mechanisms at the network layer and may also control information at the transport, session, presentation and application layers of the Open System Interconnect (OSI) model. Cross domain solutions provide information flow control mechanisms at each layer of the OSI model with a higher level of assurance than typical gateways. This section is equally applicable to both typical gateways and cross domain solutions.
              </para>
              <list>
                <head>Additional information relating to topics covered in this section can be found in the following chapters:</head>
                <item>
                  System Accreditation
                </item>
                <item>
                  Information Security Monitoring
                </item>
                <item>
                  Physical Security for Systems
                </item>
                <item>
                  Product Security
                </item>
                <item>
                  Access Control
                </item>
                <item>
                  Network Security
                </item>
                <item>
                  Gateway Security.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>Deploying gateways</title>
            <content>
              <para>
                This section describes a baseline for deploying gateways. Agencies need to consult additional sections of this manual depending on the specific type of gateways deployed.
              </para>
              <para>
                For devices used to control data flow in bi-directional gateways the Traffic Flow Filters section of this chapter needs to be consulted.
              </para>
              <para>
                For devices used to control data flow in uni-directional gateways the Diodes section of this chapter needs to be consulted.
              </para>
              <para>
                For both bi-directional and uni-directional gateways the Data Transfers section of the Network Security chapter and the Data Import and Export section of this chapter need to be consulted for requirements on appropriately controlling data flows.
              </para>
              <para>
                The requirements in this manual for content filtering, data import and data export apply to all types of gateways.
              </para>
            </content>
          </block>
          <block>
            <title>Types of gateways</title>
            <content>
              <para>
                This manual defines three types of gateways: access gateways, multilevel gateways and transfer gateways.
              </para>
              <para>
                An access gateway provides the system user with access to multiple security domains from a single device.
              </para>
                <image>
iVBORw0KGgoAAAANSUhEUgAAARQAAAFSCAIAAAC8E7dfAAAABGdBTUEAALGPC/xhBQAAXK9JREFUeF7tvQdUVFnb79mz5s6aWfPdu+Zbd9bMe7877/vZLdrd2tra3drm
hJgVMeeIJDGAIEiQICCCCErOGclBBZSgYAAjiIoJwQyohKKKrGLN/9SGY1FAURyKSpxaD6xzTu10nr1/tfd+zj7P/l/4fP4P7IfVAKsBBhoAPOyH1QCrAQYa+IFBHDYK
qwFWA9SQjdUCqwFWA8w0wMLDTG9sLFYDbM/DtgFWA0w1wPY8TDXHxhv2GmDhGfZNgFUAUw2w8DDVHBtv2GuAhWfYNwFWAUw1wMLDVHNsvGGvgSGBp66urrCwMDoqev++
/YZ7DdVG/EjLzGnTcdHYyPhsbGxWVlZZWdmwr4JhpIBvLS1fysraLl5siQxvtLHh6evy9PV4BhB93l593j7DRju7lpio1qRkBOuoq1Nw1UgTHjCTnp6+dcuWBfMXGBgY
nnBx8/MPSkpOS8/IyryYfSkrNyv7cu7l/HPn06NjYv38Amxt7XX26IArsJQQH8+CpOBthXHxPpeUNPt6NyxewlGfx92s1Wiq3exo1OJp3eJt0xrs1J7m9/lCYGugc2uI
S1voyZYz9s3HDvP0dnA3rKv/52jegf2tcbFIAeAxLsAQRZQOPO/fvz/udBzM7N9/MDgkPD4hJSExNTnlfErqhbRzGecvZIrwcyXval7+9avXCm4U3CwovHX+Qoa3j6/O
Hl2AZG9nf+P69RbF09QQVYAKJ4uuo9nfn/PX39xNK5usdFu9rdoiHNuinNtiXNtiT7bHu7cneLQnebaneBN+PqcHf74Y9uVSxJec6C+5Z7/mxX/NT2yP9W0949h4QJcz
ZTrv4MG2zEzF6ZGkAM+1a9c05mvY2NhHRsVGRcedjU2MjUsaKD83b925feceWIqLi7e2Ojpj2vQ92nsuXbyI3kyFm5eq3hp6iaYTJzgT/2rUX99yyrg10Lo12LYtxK4t
zIEBP1+vp3QUnOu4eaE9KaT5mEXDkiXcXbvaLmbKvS8aLDxpqamaKzTdTp0OC48Oj4gZPD937xUXFd0vvv8gISHJ5qjtjKnT9mhrsxQpEWZtV69y5s7l7Vnd4nawxdus
1ce81c9CWvx03M7suHupPTWiycoEg7qm06e/vn8vL+UMCh73U+6LFy729gkICg4PDomQOj8lJQ8fPnqcmXnR1fXkyhWa6IvCw8PZvkhebaXffNEVNDoea1ii3nRMt9nd
qMXDuOWMyRDx01GU8/XWxdZA94alS3mHDsHA0G/xpB6AOTwBAQGLFiw6fcbHPyAkIDB0SPkpLX3y+Mmz/Pxrbm6nZk6f4eXpiVmW1HXBJjgYDYCchk2buRuXNJ3Y2+y6
r/nkfhnw03H/csfD/NZof8yIms6cljFCDOGB1WyhxsJT7p7odnx8A2XGz9Onzx8+LPX3C0BHtGbVKidHx5Tk5JKSEljq8GGJGkzrH0xcipz1G3i6q5ocdZuO68uen6/3
clpCPLlbNnOmzWp0ONaSmNheUAiWIEM3rmMCz+PHj+fMmu3i6n7G08fTy0/2/Dx//uLFiwpMjTIzLgYFBnue8Tp44OAhY2OTQyamJqazZ86C1e6IubmF+ZGUlBSgxdru
BgOGJHG5erpcbc1Gu91Nx/bIi5+OR9e+Pin4fDu77UJss79Hc8AZ3j593gFDntFBnrFRg9ZqzJG4Ono8M/OWiMj2goLBW+0GDA8a4oL5Gkdt7E+5n3H38JIvP+XlL1++
fP369du3b9HrVFVVVX/48OnTp9ra2rr6ek5x8X30kKEhIfq6egb6+tnZ2SxFkpAw0DAYLzWsUm+03t5os1MR+Pn67NbXF3e/VhR/fVXy9c2jr+8ef6163lFd3vHpdUfd
+8+P77cX5DcHBXB19bh6Bm3ZOYwpGjA8To5OuroGrifdT7qdVnx+uFxeY2NTc3MzwLqYeXHDuvV+vr6syWGgeIgJ/7m0lDN7RuORzY2WW5WFnw5O9TduzbfGuq+Vb1oz
0oFQk48vA4QGBg/mFTBMH3d2xeoBpeOntbW1vf3z9evXgRAs7FJsQMM5qQZNTZ7+ykazjUrKz7cW3re2pi9PSrl6e1uiogf07Ghg8ODxv/Ghw07HTyg1P1++fMFcaK+B
ATuKGyT2rTnZDctm8ozXNpquV3Z++J/b2i5lcfUNJe+CBgAPmhps08ccnBwcnVWAHzyItbK0ZPkZDD+c2XN4Bpo8o9Uqw8/XN68b1m2U0EA3AHhyc3N37Nhla+egMvzA
zoD+ZzCtZ5jH5cyayjPU5O3XUjF+eBZWkozfBgAPzFb79h2wsbVXJX6ys7LY+Q/jnwDOlIk8g+Wqx8/noqImX/9+1TIAePYZ7rOytrE+aqti/FhaWLD2t34bSq8BOAsX
8PSWqiQ/jc4n+l2vMAB48DgfzyFVj5+nT59GRUUxaz3DPFZzYECD1iyV5KfjQzXs1+LrdwDwxMbGamvrWFhYqR4/eIQ6zDFgdvvUqpwlS3i7F6okP43HncXPfAYAD8Y2
G9ZvMD+CYY6q8ZOUmMSui2PGDx6SNiycxdNZrHr8tOVf+Xy/RIxaBgAPUjE6aKSnq696/JQ+eoTFO8xaDxuLa7iXu3W+6vGD9QdYBSc1ePBUZNaMmYcOmaoePz4+PiwG
zDSAp4oNC2ZSgzeV638wcpMaPEgIKzEXL1x08ICRivHjfPw4s6bDxoIGuDu28HYtUD1+mkOCpQkP0tq9a7eR8SGjLfNGf/cppTZRfe3ug9ZD9vw00XXLn79ucU8V+N8R
8R9C/B/Q72+T909LH2Y6a/yqpuGS/ZR6f0H8+musH01MTGQxYKaBr1VVnPkzuNvnC/hRz5yqJuRs7BezpfPu71szNOt33GuPLR83akVOrG9f/kNo/wfU+9v5J61+/u4F
bdy6Q9lZl8Wsv8b6UZ7pYWnCk5OTs2rV6kOHTA5sFoZHUKaRc7aY2g0NP3EnNgMet5Qu/1X983Mr3OAXlGrliUuPyPs/4vmJj49n1nTYWDxTU+6aWdyt6gJ+5mX+LQwP
1TDGTZ713Ggo1r+dqrVbNm7U8pwYLzH+d77zc8VFGB6qxf6iffleoRh+eKYmUoMHc56VmisPHoSjtUP7Ns4ZPWLM3C0HBeO3w4YbNSaM+PFndW0LhVi/c78g2GDsLzPn
zZhpEHEL75/2yw8cx7EYMNAAjLkc9dnc9bO5m+YK+JlDwfPT+MydAvubzvzY6T+rjRhltn6F/Ne/5ToDnnHaJzlFOR33Lzx1XDVuxF+WEZli3v9ptLeTGjzBQcGbN23Z
f8Do4EEjww2A59c5mw+amR0R8GOqs+QPtZEau47YYf2OvTlo+lPQHc1cpWfhSL3/42a5dbqa2jI9051z1X5U+2Olgb2Hq9XO+TgeMU5jj7N/p/+dKG8H3UWjcHH6xsP7
1476Y6NDTErqWaeNf/y6ySUxIz3YdKHaLGM31z0zqUHjnF1nUvO6/L8Jjd/ygnT+HqvrG+ukOVYv4s6TZ/3yg0fADJoOG6U5KpKjMalh7cwufmZnTAY84zK3ddkPdOae
GPPTuBlzK6n1o6vLd8wy++0nqjuaMiPdcDP1/pztuoCJI8dpLMnf8Ne4ESMXL9J86Kh9fe2kcahftSlBNkad/ncCjG9snUZd/GtRvJ76uFGLsoNP1NgsGTdqWU6Ee6v3
ds0RMwKd9llPGQVWl2wzf5fZzf8b1f9kH6fg2e3CuXupo+jc02Na40YsDsvIxfunffHTclZK1jY851m2dJnB3n2Ghvv3Hzi4d/1sCp6N+0wPmwv4sTDZpv7ziMmr91nZ
2BxcO1G47/5tsf4x15OuRzYDngl//Y7bEwzzJvw1iSKHyBwd5+Cw8KiAY7v+FnLPqzZi4nr7yOSUGMcNf/y60SX+wrkgk4Vqk6fPGN0VcfSu05lXaf+JnfzcST02b4Zu
8NXi844LftkbfrsU/kPE8IN3URMS2DkPk5+Chk2bGlZObVg1vYufmRmTAM9vmVtp+8GCzGmj1H6bcn+fVsOuaSuEK3fk5EyzbY1H11Dw/D5mfudXIzUmjKEgIfLX8kde
8F9ldHPDRGG/zWqjFmYHOtUcBTxLcsJPtXpu1Rwxbsnfv3SF+d3C1UvEf+LXLIfuw7bZVh4RvIf55P3tXvlp8nCXTs+Dx/A7d+7W198r4Gef/joKntkbDGG5FvBjbrxV
HQM59R2mZjs1fh4xccFuM3u8v2BjvGH6mJ8XGti7nDDfPE1txN9rTFzcPU476C78ZcTYeTvtPHwD/VwPLFD7XcvMOzjEx0JrgtqkTVbeUVHRYe57l/4KeOwiEhIjHQDP
BufYc2kBhxaojZi1zTU2M+tSrP36MSP+2nH6vLD/UfBzM9l+/s96QdeKim+E6P2s6ZRxn/jf6YufgoLCoqIiJm1neMeBkZozZxpn+d9C/MzI+Gsk4MnYROwH6H80KBPC
TxMydZdkzhilNvavTL3VjabrPujM2jVytNn29Y1WqwMmjFQbP/uGtXaTw5a4WaPVRk4KNNNrPmlYvmfqOLXZWS6HWty2HFFTW6y59XWAdauPYbD6rxQ8AcdqrBYBnuxQ
19YzgGfUko0H3iR7t4bu1Rv947hNZrUi/kcz7S2FDAZU77fa4mlhDvzv9MpP+908vGcqBXhKS0tXaa3es0dX4A4A/BjqrpkJeGatNzCC4w2KHzOB/W2SloGp4arJ9Pjt
mIO98fqpaiMX69k5mW2ahmHbXicPvL99ymrH3yNm7LD1ovyHuB/WVBs1Vds5MMhF5+/Rv2hZ+wv8J0aeMpw+YuI627D4hAj7dYDneExqip/RArXRW08k4q3q7Mww8zkj
/trufr67/eBaos0yYYOPhsP5Etjf+ubHx9uXfbGHwe9Ac1AQZ94fnKWThfiZlvEn4BmbsZHYD7rsb2Mn39eb7/8bPX5b22iyLGD8T+PmLKqy0AI849SXVVH+Q3Y9WD9B
7Y+FD5zhv8rww96Z40b8EWR1oOno8hUjfj1ifFDgP9GidA+GhhrZfvY1lgsF4zeXltOb0fNY2DlR/nuTbYOnjxq36XCtiP/eDDtLQLXTgUP5H02tDD+w5+efV9qHfRH4
r+rJT0tMcEdNjRTg0d6tvX37zt2793TxY7BnNeD5ZdY6fYH9APzs37lwotrIeVsPmRmsnAR4dprbCNZf2xqvm6I2cpGurYPpBlC0dK/jKfg/cLPcPnnEjO02Zyj/O6dM
V6iNmrL7uH+A8x7As9LSTzD/iXADPBPW2oTGxoXZrZv46zrH6JRk34MagMc5Ph3+r9NDzADPNrfU7vbrSz67JnXr4tUdzxcL7Nd98BMTE8Og6bBRuLq6HI0/OYv+EuJn
SvofI9V+HJuxjtgP5vO2TT/x60/jpk6v1J1HwTN9diV5/8doiQCeBVXmmgG/jxw3b2kV5T9kx4O1v6tN1HjgBP9VBh8MAM/EQMv9TVbLKHiMDgjmP2al2hgaamT72NQc
ATwYvx1vcd+kOeI3CztHyv914lEKng0mtSL+r8/bUPBst68n/nsL/MPm/txlP+iFnyaXfh79SbQ8B6tX4LoAb8Lt2qXdxY++9qoZgGfmGh2B/cBw96o5v4/4cfTsrUad
47cJ83ccssL7C5b710779WcNXWtHBxMKniX6x07C/4GrxbbJI6Zvs/Kg/O+cNKHg2enoF3DmsObvan9tt/UNDwsPP220/JcRE9ZYB52NDbVdC3gcIhITfADPqC1OcRfg
P/5C0OHZI/7cejKF7L/Q2f9c8t7986TdPlmC+c+d/AC9sSNWOJy72/n8pwc/yUkpT58+Y0lgoAHO4sWcuX9052dy+kTAMyZjtcD+tnHG2cmj1UaomS1X7xy/jZmYuXs5
b//K6p3Td/40ymyTVuPhFQG//zRu7uIqyv/OtpI1gGf+Awf4f9Or1p9BwXNkb7Pz+iMYvazdVgP/vd57E9R/UVObn+V9tMZcg4InwKHFbSMFj4095T8+3lIAj3GtiP/4
c9YCeOzq8xO/Xk/mxZrs+W4/gP2tGz/tOSlteZfF60QieMwOm23YsGnr1u1C/Ojs0gI83x85Ub/0P01brWdMzX8O6638XdhgMFZjt6XQ+M0F/kNcjmwFPFstT1H+q1yN
l6uN+nung7dvwBlrQNWV7B+T/x41YY1VUFR0kM2aib+uPRaeEO+5fz7gcTx7HvsvnAs0BTxbXJPo/UvAz+UYq3kjlh6Nv4r9Fyh+8gJ0fp6sE5gH/9e98gOUGbQbNgre
VeZM+I0zc2J3fv5KxwSme8MYN2HS853U/Kdh46RuBoOf/sg0XPN9/Eb539lasno8nrg/sIf/N51q3ekUPOYGzSf1CgBVZ7JqGn/8Nk5tXpan5SczjXHU+O1Yi+t6Cp6j
dtT+C3EWwdNGjVt/sFZk/4UUS8DTvWyz3cPjiP9r+O8V5qfJyb7fKpYIHq2VWhs3bt68easQP9o7NKcJwTNy/Iyl63cads1/zA/v26U1Z4LAVD112fYDFt3Gb87wH+Js
tmXSiGlbLNwo/1UnjCh4ttt7Uf5HPR0wZ6LMlAt1rA+uGjVhtWVAZFSQ9eoJv66xD42L9dwHeDY5xJzD/iWp/iazAM+JRKH9f7KjLBarzbY6m9+5f8nNWzn+2pPH7IH5
gPIfL8JPREQk/L71qyY2QE8NtF64wPnjN870Cd35+Sv9d2F4Rh2eNbn4+/xnwYs1k83GCEzVf066sGN5t/Eb5b9qc8mq8WoT5pXYYv6jXa0D2/SEgMN6lP9ep+3xS8ZT
EWcvv6Y/h4LHw/zT4fkUPD62LS7rNEeMtbA6Su1fctacgmfd/lqR/UuSLbrBM319REjoF8H+CyL8tCWFfS592G+l9w8PzFCLFy1Bz9ODH3r+Q+xvsF9j/EbmP8T+Rp7/
KO77C3l5V8+dO9evjtgAvWqgyeUk589xnL/H9+BH2H5AP/+h7QeKvn4U/uNbwsUtaaO10T882ApBS2v12rXrVYwfrIWLj2NXFTD/ZeDu3VePYdtfqsZPk4ONhErpHx64
gQY8q4GPavGDDRck1BEbrFcNNFpZ148bq2L8tAa4f2vkSVjj/cNjZ2enqamlevycO3cBVkQJ1cQG66mBRkvr+l/HqBg/7QmBXx6XSljdEsBja7d8uaZK8uPuLm7xhYQa
HLbBGi2t6kf/qnr8tEYGSVin/cNjbm6+dOlyleQnLe3cI7bzkbCl9AjWaGFV/9MvqsdPq7e4t0eF1dA/PHDTtnjxUlXlJzQklGnjGe7xeMam9f8arXr8YP/tLw/uS1K7
/cNz4cKFObPnqio/3t6s6wJJ2kkvYZo8zmC7KJXkpzUtRRKl9A8PUlm7es3ChYtVkp+QkDDWXagkDaVnmPa7dyl4VJGflqB+3B0SbUgET1JS0swZs1SSn8TEZGw6xKz1
sLE4C5eqJD8tQRKNRySCB61k86bN8+aqqx4/8QlJLDyMfwUa7R064VGh/udzRlhLZJgkOpEUHk59/fKly+ara6gYPwEBQSw8kjSUXsN01NVzZqurGD9toSfbC29IohNJ
4UFaFRUVq7S0VIwfh2Os6wJJ2kmfYVriE77DoxL9T6PFAQk3hxsAPISfhQsWzJ0zV2X6H7PD5oNqO2xkPp93+Igq8cMz3i9hrQ4MHiSK15Xxes+8OfM0NGCAU+7nP5GR
MSnJEhklJdTmsA3WHBBYP/4vFRi/tZw+2nYpQ8J6HDA8JN179+7p6+mpz5sPhJT3+enOHbtY1wUSNpR+g32trOQaGH5HSDmfn3J3bJZkQ8UBmKr7UlxVVRX8o8P77ry5
8+bNU1+6ZJkSrR8NDglnn5D2i8RAA2C2gF4IFHGWalK2hBE/14/sWsLz21jO72M5kxX3/Z+mo/vacrIkv2WGPY9IBvj9vn79ureXl66ODl6LW7VSa5XWqnVr16nPU4eB
QWP+goULFi3GKG/RkiWLly7DSrllK1ZgsekKzTVr1snl/bmk5DS4NGG7HckbCrOQeFUbmxO2X7/RkpDY7OdPBO55GzZupmTpMs4CjfrJ4zhzJsKFSHf/b13+Q2TlP77F
9yjP1HhAtykdePrKEq0ThmAxH5ujR/GOnez5gQ8g7KY4IE2xgYdIA6Cr2d+fA5DmzOIsmCTkP1F2/LSGOHC3bpR8wCaFYZtUtLl54yYZ9z/Y0zsnN1cqhWcTkaIGMOTj
HbGoHz+RM+8vIf+9Q/7+dmugLXfj6q+vXg30Xoa255GwNOh/VixfIZv+Z+/efTk5LDkS1owcggGhRhsbzuQpcIFNbb7Q6T+e9j8q5f0bm91MuBtWMSAHqlEIeFCOiIiI
ObNmYzQ1dP5D/ANCtm7Zhi1S5NAi2CwHqAGMoJoDAjgzZnNm/CG0f4mU989qstbBtlyYmA2wdJ3BFQUeFAcefTXU5y9ftnz//oNS979jbm6pu0f31cC7ZmZqZWNJSwOt
WVkNmlqcWTMalk7jbpknrf3nmp33cdcvbz7jMdB5jvB9KRA8pFjwBaU+d+7iRYvhy0oq/qssLY9qrVwVKXZnVmnVNJvOEGkAnUOThwdn5uyGBXMpigaxf3DTMV2e9mru
zm2fJfZV0NdNKRw8pKAYXOElormz56xds85w7z4G/t8srWy0d+usXbMWA0LWJD1EbVr2yVIUefs0aK3iTJnGmTupQXMmd4sGz1CTR/xfG/e5/1yj1U6ewdqGdSu4u3e2
FxZIpeQKCg+5N7ymho7I1MRk0p9/rl61esWyFXC8uH37DnhXPHDQ2NjYxPjQYRPTw6am5rq6BnCivW3rjo3rN8K/qc4enTNnPLFNqVR0xCaigBrAcAs27pbwMJ6xEXfb
1vrxfzSsWNqguZQzbwp39TzuGnXuOg3OIvWGVSsEArQOtCYnSbjiU8L7VWh4hO8BIOF50dX8/NCQEIGEdn3CQsPCoqKiyNMkCW+bDaaSGgAbIIoW6aLSU2NKA49KVjZ7
U0qtARYepa4+tvDy1IA84WEfuciz5pU/7/aCQvnehDzh2bh+fUlJiXzvn81deTXQsG4jpjdyLL/c4Hn//j32WvHz9ZPjzbNZK68GPpeU4N27Jl9/Od6C3OABNmSPLvYh
jByrX3mzBjaAhzNLXY63IDd45s2ZQ+ApLJTzyFWO2mezZqYBPOQBNuStbznOfOQDD6Y69NaQVpaWzDTIxhq2GgAwtL+ExhOu8tKDfOBxdXER3leVdXgrr+pX0nwBjLC/
nsEs7hyMBuQADyY5IrslszbrwVThcIuLdQPdPF39c3RbtnxeM5EDPJjkiMADm/VwawHs/TLWAFARgYerb8g4tcFElAM8ew0MRODBKSzXg7kNNu7w0QBQEYEHp0O9jK1X
9coaHkxvepKDK9FRUUpY/a1lYVvURmwJL2uVX+E7GsuyPbSnUlpdbJNWxhWUpIObZzNeYMwUyNilVmF5nV8Jvm8su+y+RxBA0zryTnWH/Io/wJzxSkJPcnClJSp6gClJ
Ibis4UlLTe0VHliupXA3sk6iJs9qNpqmVtgzeTW/jspUgzE0JODHMa+6vQc8ggBjjNIq8RW+fJOmL4CtU6YapL6RV/kHWmOApFd4sNpgoEkNPrys4cH0pld4cFH5lupw
86zH/LF08ezxVnnkB1/mH9L1adrmVXbwOxqfRemMISSTnme2dV6NoEjcslSbpSN+JOXsKAvTQl9kk0t1OB2VeTaaamNs8rjKgQ/9eKcnQrJfqiNTeMiSnL5E2ZbqCBro
GJvLd0K0hBsfPSISGkR1jawwfEotayTNlB5uCV1sfJZmpdl9ANbZ7qnxVeqzRhE6O56Fa44VQlfAkmZYWYcIPIjGKXJf3QkJxTzNFQkp35GnpL85ZElOXyL7pToyhYde
ktMXP0q1VIdqqVTDpVqwRtdvvKCN0j8QVDvGBOOOx+Kx9PSjc4zX/eJS9zuNfNKNdP24LPYsauwQ9BL0z81qjyJOt4ZGYSA8aKRJaO7e81CsCkHSXp3nqKXtd5ca4CnT
hyzJ6Utkv1RHpvDQS3L6gkeZlup8ZwYzH41OJAStWUACGUThB/6joNWSds99FqaPziqP+0XQa5FJSGcPlsdt7uo3MJjCTIbqHATwCLoFwURFZHwo+JbuQ4Qx6Nnz9LjS
WJaXGudh5RieerWrM1RokPAkVAw5clmqIzt48I60mDEb+QorDxS6AoUK171P+FEwWCLTia7WTNH1h1bY/WfoT7rGdV0wcLp1MtS9E0Kqi2LCwpOFW3N7dVFyeFhyN1sZ
XQxGPQ8yuZB6saiz26F6oaWCXk7BNS+8JKcvimS8VEd28IjUjTBICl5tvRVPxBbc2fp7wIMJScZdUXhA17ve4PlYlnf+QhGm8dyyXG9rG8yOvjSWXU07j0uCCZLViS5L
dFeJep3z0D1bt07p+5xHpL/qu/tS6GoR5kdeBWXhYaZ5ykj9fRBF9wBk2CYwZHUNvciwjRjE2itTjXoM2wTNmuq4BJMo7ahn6AS65vRUyx6jH/4MRrLuOXaWWtjahn4r
13YxsR+Is7bxCXIkIzKS7H3sx0wzMorFwtM5FZaRvqWYTeeQjH68Q7fs7gYDMhzqxTYgYkXoHOl1f2gjuNj9mUxPm7jocx7heZSIYZN+zkMYFv5WeUzVdB2y8CgrPN/n
8Z2VSU/6gUrXw3tJTdVTdcJKu2zQghlI9wf/pD8RrBKI6ZqodLMNMFlh0PXkB4Pn8dqel4UXH0jxJ2Yok2LhUVZ4hrJVsGlLpAEWHhYeiRoKG6inBlh4WHhYLhhqgIWH
hYdh02GjsfCw8LAUMNQACw8LD8Omw0Zj4WHhYSlgqAEWHhYehk2HjcbCo9zw1NbWvX79Vtnlw4ePX758UToaWXiUGJ4nT5/n5OYV33+g7IK7uH3nntLxw8KjrPA0NjZe
vJSD32yl+8HuWWDcBe7l7dt3ynUvLDzKCk99fX1e/rUnT5/l5V/Pzrmi1PLwYWlB4a0X5RUsPAPVAPtKwkA1RoWHz8q0cxlZ2Zf7kgvpF5OS04S/PXs2XvJTxEUKdPie
qYnJmsFXF9IvPX/+goki5BeH7XmUteeBqSAp+VzmxexeJe1c+oZ166dPmRoVHUsCWByxxPrlM2e8yKmpyWGc+vr6k1NcxykuklPEQlykgHRwiv9bNm8RTq2vfBlfRxZP
nz2XHwhMcmbhUVZ4ampq4+KT0zOyepWTJ0+R92T19fQRIDIyhpzOmDb9/PnMuLhE+i3alNTzuILr5EpwcDjCb9nU6QYE6eD0hHOnU3yTQ6Z95UhfD485a3nCjohnoF+/
4UkA/BA8fvKUSROWXxwWHmWF59OnmuiY+PMXMnuVy1fy42LjfLx98q9eRwCc5mTnHLU+WlB4E6eZF7NuFt40OmiE/zjGFVzHtwiDkDhFLMRFCuT05q074WHhdGp9ZZqU
krbNRPuHNSN/MP37B9uZP1hO+2HzLwt1VuB6X1Ho6/EJyY9KH8sPBCY5s/AoKzwfP34Kj4jBtKcvgf238OZt+lucljx4RJ/ix7609An+01fwLcLQp4grciqcWq+ZLtiz
4gezSSlPslq/tJHGmF1xfcqxFbiekJQqpqj46mxsIswGTJqw/OKw8CgrPB8+fgwJjcSgC4LegxyISFx8kvCVyKizYk5FAvc8Fbkiktfx0yf/t62jve97f2x8JCwJz6L/
D8NxZk5WvZYQPQ+5jllWSclD+YHAJGcWHqWF58OHgMBQTBUePHj07t37S1m5OBYWs8PmmzZsxC86uXjwoPG0v6cEBoWRU1dXalKE/+QU1/Ht6dNe5BSxEBdR6NN1a9ZB
6NRE8sLpyr0bJvnOuPDM43FVrLBkv/CeEjRr8pY5PaOgwyl7UV5UdB9fhYVHF99Xsm3JWXiUFZ7q6g8+voH45cYBpKLiZUJiKi30FF9PVw8XPTw8iT1g2pSpmCkFh4TT
BgMc4wqukyshIeEIj1jk1M72GE4Pm5qRU8O9+4RzET6evGX2rviZ7rc2XnthJSyhRdrGeRo/LPtXz4jAhhQ+Kys3JDSiqKiYye+//OKw8CgrPFVV1Z5eviEhEe6n3F+/
foP2DeMbLTk5V1xdXHft3HX9egEuZmRmhYaEzpo+4/LlK/iZP3c+A3+rVmrhP45xBdfxLcIgJMIjFuIiBaSDU/yHOQEGBjyWFc5F+Fh999KjqVM8b872vz0vomgBkcA7
83Dl1LWZgKdnxCNHrO7fL0lPz3A96R4YFHr3XpH8QGCSMwuPssJTWVXl7uGJcZSPb8DuXdowHuBYWK5evYERHX0lPf3Ss+dliUmp5ApOgRz+k1Ncx7f0Ka4gLlKgo4uk
JpIXTnea6pkH/Zb64O+e4pzw+7xdS3pGwRVj40PHHI7jwNcv6Padu0yasPzisPAoLTyVlfjBjoqOUxA56Xl63Kb/vFI85t6LsdVV/2qs/b/x/375mILHY+bqjjh6wkF8
Ob28/W7dui0/EJjkzMKjrPC8f1/pfOJkZFRsX2K4d/8qrVWYS5AADg7H165ZS5+e8fRdoLEA/8m3uI5vEYY+RdyTrqfoxJEaREx2+Er3yL4lBv8suP0/Wur+W3v9/4n/
t+/9Y8vhf24/tEd8RHx7xtPn5s1bTJqw/OKw8CgvPO8dHI/DSNWrHDpkSqb4q1etRgBgRk5hQ4NhzdsnALY1yn7w9xQc4wqukwAIifCIRU5PuFCndGo46CtHct3EzuKn
1b9rGf5/Zk7/gf843md1SHwU8u0p9zMFBYXyA4FJziw8ygrPu3fv7OwdQsOiepXc3CuY8cMGkJt7GQFgFcCMHzDExsbGxydDvDypxWz4T05xHacIg5AIj1iIixSQDk4z
Mi7iGAYGHPSVo/B1Z3c3IpIEJmEwBL1+4waTJiy/OCw8ygoP3n6xsrYNCg7vS4qKS0oflUZExpAAsJg9elQKwwA5xUHJ/RLhU3yLMORbxEJcpEAnjuUFEDHZDfIr9HjX
rl2XHwhMcmbhUV543lpYWGPEpRri5HTi6tVrTJqw/OKw8CgrPG/evDlwwBjPSf0DQlRA8MwnLy9ffiAwyZmFR1nhaWho2L17z/4DRl7e/nhIotQCcnAvSrcVOQuPssKD
n8r79+/v339g+/adKiAXLqQz+fGXaxwWHiWGh7ScSX9OUnaRKwLMM2fhUW54mpqatm/foezS0IA9G5Xvw8KjxPA8ffo893L+nbtFyu63jbqLO0Ws3zYGvx+s9xwGSuMT
v21PnjxjElnB4rB+2xhXCAsPE9XBbxs8PLF+25joTkpx2GGbsg7b4LcNS2kG5LdNxI2beK9uPf22CbtxY+CZTXyU9IxLz8tYv20DxprteQasMkSQxG8b3g+l/bbBJ9v0
qdPg95C4VoPHNmE3brgu4rcNcYX9tuF486bNxI3bUAjrt41JI+DzWXiY6E2837YjAheHkOVLl8FFjrcPhQpEc4UmvLTB4Qb9GnZiIhy3ZeI6uYKQCI9Y5PTYMUec0qnZ
HLXt1w8bnCY4eJwgftvgw63f8KzfNibV3xWHhYeJ9uC3LeZsn37biKc1rJKGJY74bcMb13iP+sqVPOK3DQdYJY3/xG8bDvAtwhBHbYiFU6SAdIjfNjhtQ2rEC5wYv21G
9maU37YDf1J+2+C9bc3I1fs2Sea3LQWusJgoQn5x2DmPss55+vXbhkXQwo7aBuq3DXGFHbWRVdXifa+t2rfxh91j4betroWDJg3vbTj+4fAk1m/b0AHO9jxMdCvst432
ftarbzTZXITftv+ydbTLLbeapifCElEa+r+zftuY1LBEcYYpPNFRUTk5OS0tLRIpqUegD11+227cuNmr3zZ4XRP2tAafbMJ+20LDIpctWYr/tN+2qX9Pod24wSMH4tJ+
2xAGXuDE+23bbLzrD98Z6c89n1YnCEtOud8ksX7b4GlkMH7bPpeUNPn6f33/npkaBxOLHbbJbdhmZdk5p3d1cSksHPAbyMRv28WLOb36bTM3tyAzfngmgMM0X98Ackr8
tsFnwIxp03CK/zgW9tvmcdoL4RFL2G+brY2dJH7bdsTBb9um6+U2whJapGOYpd6r3zZgQwoP/uH9FG7cJG/KoKUlKpozS5204C9lZZLHlVZIFh75w0Pa5bw5c/x8/cok
bgTEb5ufXxD8nvXqtw3ze7w7nZNLOV67cuUqZvx4szo9g/LShgdEcOKOTPGf+G3DdXyLMAhJOWrLvQJzAuX6XeC3DbMd2A+Q2qVL2WL8tlmlTjl9c3bAHfWIooXxJUuj
iheF3NPAlZN9+G3DFgwoOVy3wfuHhH7bOurq2rJzGtZtFG64LDzS+jkYQDq0uRYHA4gmpaB0zyNcDBxvXL8eI7q6ujrx+dB+2+D3TF/PoF+/bXC8Vl7+UozfNnwr7KhN
xG8bToW9wPV0wrbhwHbzwHEpJVN6yvH4CX35bbOyOgrvBf36bfvW0tJeUMizsBJhhj5lex4ptUqJkxFptYp2utfAQMykqLKy8qSbB0ZcCiJuXmd+2/Sf1x+PvfPit3eV
I6qq/gUpLh+DK1rGP9q4OIovJ54v3brdi982MqXpixnFuS5xo5NyQIUwGCgaOcLl6XVS1K/fNnhdMzpoTDtM8/UL3Lplmxi/bfgWYejwiEu7ccNFSfy2wT8bvLTduPUf
Ar9t/9Za919flP2/uLJMd/VA/baJTGkUB5K+SiJlJiROjoWnc94lBmCM5dALCav0/fv3jo7OGK31Ki4ubiS1vXv3IQB+12dMpSwEcMgWFBwGSwPttw3HuEIctSEMQiL8
oUMmXSsMnHCKDeHIKQ76ypFc329tAl9te478z8NO/4H/sBPomBuKj0K+dRfy24YxmJgRmmKCJHFrl3JAFp4+4RFjRRDvt414WoMNIC3tHPHbhhk/Wn9IcAjc3sbFJcGJ
O07xH8e4gus4pRYZCPy2JSYkEb9taecuEL9tsB/gSnJySr+u2PyDQmi/bTjuN3xfftv6sg2w8AjzJzd4pPwjMMDk+jIYkN/4fu3X8NtmfdQuOCSiL7l58/a9e0WRkWdJ
ABjQ7t69h7XS9OnTp89wkZziOr6lTxELcZECnTiO4cmNTk1Mvsy+OuHi1pffNkmGcHIxGAywwockOAvP955HvJFAWP1v3/bvty08IlrYq5vIaczZBDHfigRGyJ5XpOgy
ThK/bWKMByw8Q4KmwiYq3PNIaJ4Wvhf4bYPnaBXw2EZuwcb2mIR+23o1W7PwKGw7H5KCAZ6BPhgVLgf8tmlr6xyxsFZqj22k8E7HXXAvA/XbJjwpYuEZkjaqsInCXDbI
ssFvmwp4bCO3EB+fwFgbmBShO2IcXakjDtM5j1TqrLW1VdmdtqH8HE6DVLQxDBNh4WFe6W1tbcrutA3lh/c55ioY3jFZeBjW/4vyCpXx2wbXcwy1MLyjsfAwqf/GxqZL
WblwPcUksoLFgd823Mvbt4OdBCrYbcmiOCw8TLRcX8/Jz7/+4kVFQcEtvGKtvJJ/9QZcn969V1xeXsFEEcM7DgsPk/rv128b/KSJeFoT77dN5FuRuDhl/bYxqachjsPC
w0TB8NuWnHIOHnf7EgsLS3haw1o1EsDU9LDgNdJYcnrG0xuLgPCfnOI6vkUYcopYiIsU6NMN6zdA6NTE5MvsK7gWefrsORNFDO84LDxM6h9+2+ITUvryioaXNMkaOX09
fWG/bdOnTE1JvQBfbfQKbhzjCq6TK8RvG2KRU6Qj7LftwP6D/fphg982V5/TcNoG72047jc8CZCccl41/G4zqctBxGHhYaI8gd+2BDKa6il4JxTvVGOVdGHhLXxLvVwd
G4eV0TcLb128lA3JFCyUxn9yius4RRiERHjEwpJqpHDr1l2cIjWsv0Zqd+8W9ZUjuW4Mv23L/vWD/gTKdRv+rxm5zXRPcuo58bHwbUKi8vltY1Jt0o7DwsNEowz8tmFe
jt944nsNB3AyKHyKb2F1oD2z9fTbJuwFrlcHbroW++C37fhVv7LaV7il99xqym/bwT/ht028wzd8izexHz4sZaKI4R2HhYdJ/QMeOI6SjU82SXI55ev5v24dffSGY13z
c2GJLA3/L3vGmDlZiU8E7xSVPHjIRBHDOw4LD5P6x7MRvBEAxzdi/LatWb0Wv+jEMxt8sq1ft54+RdxFCxaSFCC4jm+F/bYhrrDfNhzDVTwJ3KvAb9s4j2kZz72ff0gW
lsvlAX8GzZqvvbxnLHQ4MLUTv214mRRudJgoYnjHYeFhUv8iftvwbhz8rdEi4rcN3tiIAWDzxk1wxBEWFgXbGk7xH8e4guskgIjfNqSDNOnU4MBNOBfhY/Xdy7bFzfK6
s/NG+TFhibpvaJA1X+p+25ioTBXjsPAwqVVhv20Ayf2Uu7BHtbz8a5jfwwZw+TLleA3+1jDjx3vU6IaI37bQkFCggv/Ebxuu41uEIZ7ZEAunlL3h5m2cIjXYD5CaGL9t
k7bMPpIy9VThnIA7C2KKl8WXrIi9vzz47kJcOXF1FuDp6fDN3u4Y8dt2/PgJCf22MdGUSsdh4WFSvVVVVeglMNyC3zYDfX0f3wARX2oYDj0ufUI7aoPFTPg0Pf3Sg5IH
+E9iIRi+pf22kVNhR204vnPnXk93bfQV+G07GjE+qWRKT3FLm9ir3zYM1eBxztj4EBLx8w+6c+cuE0UM7zgsPEzqXwH9ts3RHXG19LdbZePevP+xsuo/8f/ei7E4XWn8
o7njUWZ+25ioZjjFYeFhUtv9+m2D1zVTEzPaYdoZT989e3Rov204gB8p4VN8izB0eMQV9tsGL3DCqfXqhw1+2zab/vPRk//ZWvff+Nwf2ur/6+vX/zB3/eecnYsH6reN
iUaGZRwWHibVTvltc+rTb9uxY07CfttOn/YmjtqI3zbIpg0bcYr/5JT4bUMYhMRoCt7ehP220V7gJPHbhumNqeN/EMHxVmPtwBA4D+ndvxx93d3Ds6BgwN7umShOteKw
8DCpT/F+2+ITkointdDQcDhGS007jxk/ePDy9CJ+2+DEHaf4T/y24TpOEQYhKUdqoeE4RQq03zYkBYmOPtuvHzb4arNzOW5oZWzpZOvl599veBLg5En3GzduMFHE8I7D
wsOk/gfqt624uETEb1th4U0Rv20IQ7yuifhtwymctgl7gWPmnE1MLDF+25hoZ9jEYeFhUtUM/LaJOGoTf9rT55vc/bYxUZOqx2HhYVLDAr9th1XGb5ut7bH8/Hwmihje
cVh4mNQ/lucMc79tTLSmcnFYeAZcpZ8/f4HTqfT0THg827t3/4EDRkotuAu8OIQXy3m8RtzXly9fBqyR4RqBhUeimv/27VtbWzu8NMHLWU1NXXX1x/fvq/BaQUHBzevX
C65du3H16vX8/GtX8q7mXs7LybmcnXP5UhZeC83OzLyUnnHx/IWM8+fTYT3D6ubklLSkZCyES4lPSI6PT4qNS4g5Gw+Jjo6Nij4bGXVWYEGODg+PgoR1CTmlrkfEIAxC
IjyJiBSQDlJDmkgZ6SMX5IUckS9yRxlQEpQHpULZLl/OQzlRWpQZJcfahVevMA59hzvCfeHuGhq4uFPcL+5aIu0M10AsPJLWfHv75+bmZjQsvIP94cOnysoqeJxBs3v5
8jU2RXxR/rKsrPzpszK8kln6+OmjR48fPCy9X/KwqLjkXtH9O3eLbt+5d/PWnYLCWzcKbl67XgDPG3n51wWw5eNNHvg8gMCLTebF7IzMbPKC54X0S8JCLuJbhEFIEgVx
kQLSQWpXrxUgZaSPXJAXckS+yB1lQElQHpQKZUMJnz1/gdKizCg5yo+7wL3gjnBfuDsul4c7/fLlq6SqGa7hWHgGXPP4Pf769Ss8HqKFYbTz8WMN1obiZxs/3oSliopX
FE4vKp4/fwGc8KLbYxBV+oQQhdfa0JThKo1wBc81BC3Irdt3IWj3EKwK7SnkKxKMREFcpEAIQZpIGel3clL6BPkid6CCkqA8KBXKRmjp6mo+oKvh8QgtX3BfA1bHMI7A
wiPlyu/o6EAj/Pz5M4Y9mELgVxwjvbo6Dn7R4fng06faysrq16/fovnSpBHYaEGH8F1eVKDRUyJ0UTgw4tI8IEEwjBf1kAvyQo7IF7m3tLS0tgL2dpQKeLCDMWlVOQuP
tDQ54HSwMUG/2273myh2K8DOOf0GYwMMhQZYeIZCqxKliW1ORLY6lSha90Bt2TnYQpRBRDbK4DXAwjN4HTJJAX0OFrBhXy0mkYXiNKzbiH1C0f8MMh02OgMNsPAwUJoU
oqDPIUunB7NTEPbGITvsov+RQpnYJAaoARaeASpMSsHR5xB4oqOiGCfZEhVN4EH/wzgRNiJjDbDwMFYd84jobWinodjdkXFCnFnq9N7u6IUYp8NGZKYBFh5mehtULPQ2
NDw4GOh+oCRvGNlocnCAXmhQZWIjD1wDLDwD19mgY6C3EYbHz9ePQZJNvv7C8KAXYpAIG2UwGmDhGYz2mMRFPyNMDjnGc8wBpYU9dIXJIcfsA58B6XDwgVl4Bq/DgaWA
fqYnPIWFA3Mh0F5Q2BMe9EUDKwobenAaYOEZnP4GGBs9TE9ycAUPTAeUEh6M9oQHV4btru4D0p60ArPwSEuTEqWDHqZXeHBR8qU6eCTaKzm4iB5JonKwgaShARYeaWhR
4jTQw/QFj+RLdfBItC942KU6EleFFAKy8EhBiRImQZbk9CWSL9UhS3L6EnapjoTVMfhgLDyD16GkKdBLcvriR5KlOvSSnL7gYZfqSFofgw7HwjNoFUqcAL0kpy94JFmq
Qy/J6QsedqmOxBUy2IAsPIPVoITxMWbDhIcWYX7oi64uLv2m1njCFRMbIsL80BdxwI7c+lWjVAKw8EhFjQNORBieAUfuiiAMD+NE2IiMNcDCw1h1g4rIwjMo9SlGZBYe
+dQDC4989C7VXFl4pKpOiRNj4ZFYVYobkIVHPnXDwiMfvUs1VxYeqapT4sRYeCRWleIGZOGRT92w8MhH71LNlYVHquqUODEWHolVpbgBWXjkUzcsPPLRu1RzZeGRqjol
ToyFR2JVKW5AFh751A0Lj3z0LtVcWXikqk6JE2PhkVhVihuQhUc+dcPCIx+9SzVXFh6pqlPixFh4JFaV4gZk4ZFP3bDwyEfvUs2VhUeq6pQ4MRYeiVWluAFZeORTNyw8
8tG7VHNl4ZGqOiVOjIVHYlUpbkAWHvnUDQuPfPQu1VxZeKSqTokTY+GRWFWKG5CFRz51w8IjH71LNVcWHqmqs+/ExHs8JCxJ4vdQvMdD4hKE9Z4jm0pl4ZGNnqlcxPja
JfBI4nFXjK9dQg58U8nuloZ3Tiw8sqt/MV7eCTyS+HoX4+WdwMP6epdZjbLwyEzV/L72FyHkSL7LSF/7i4Ac7A/H7jIisxpl4ZGZqqmMet3ZisAj+f5Wve5sRboddn8r
WVYnC48stc3vdU9FAo/kOyv2uqciu7OiTCtSkBkLj6x1LrKbLyFnoHv6iuzmS8hhXbzLuC5ZeGSscL7IPvIEnoHuJi+yjzyBh91NXsZ1ycIjY4XzsQmP8BNSHKMvYlAI
2AZEdhnB1j0M0mGjMNYACw9j1TGPKLJRjyTb8vTMTGSjHq6+IfMCsTEZaYCFh5HaBhdJZIs4STaE65mhyBZx7IZwg6sTJrFZeJhobZBxhJfq7DUwYJya8FIddkkOYzUy
jsjCw1h1g4pIL9WRZElOXznRS3XYJTmDqgymkVl4mGpucPHopTqSLMnpKyt6qQ67JGdwtcEwNgsPQ8UNMhpZqiPJJqTiM8JSHXZJziDrgnF0Fh7GqhtsRDwYlXxJTl+Z
oc9hl+QMtiaYxmfhYaq5QceDkU3yJTl95YalOuzjnUFXBcMEWHgYKo6NxmqAhYfP/9rMb//Eb33bTXAF15Xt097eXllZ+e7du3KZfF6/foPsamtrlU1P0invMIbnC5ff
VMbnFPDrr/I5N/i8+3xeCb+5nN9cxuc9oI6p6wVUmM910lH2EKcCcsLCI9xOeVRXf5CZILvjzq5Pnz4d4ptTxOSHJTxfGig86vP5DbcoVKhOhkf1Mx2t/G+fKelo53e0
8L828tur+I2P+ZzrVEiFRyg0NDw4JCIuPllm5CAjZHc2NtHO3qFm+PU/wwyeb1/4jaX8+iv8hpvfWl7w2z/wP9fwP9fzv3IpVAAM+KEE5DRRRAEzMNP+kd/8jEII3VFH
myL+BgrKZGvnEBoWFR4RI0t4PL18Y+OSkPX7ykqF1cwQFWw4wQMeqEHalW+Npd9aX39re0d1LADjcy3/C4fiB//bcAUdUWMXOfUUXe0fvrVVfmt5zefeo/orEKWQH1u7
Y6FhkRCP015Z2ZdlIMjL9eQpATzHWHgUslFIpVDgAe2ec5Xf/PRbSwUFT+tbIMFvfsFvfEBBVZfTTerz+A23+U3P+G3vwRhIo6K0vOQ3PuTXX+a3VUulUNJNxMbWPiQ0
AuLucebipRwZSEhouIurG4ZtyPr9e7bnkW59KkhqIKfuCh88ND3mt5TxW8qBwTfKJJDHr83qXzg3vjU9E8BTwcdgr/ERhVl7jYLcHF2MozZ2BJ5T7qczMrNlIEHBYSdc
KHiQNQuPorUHaZQH85y6XEqaHqLb4Tc/5zeh9efyay8OTGCRw8wH7CGRxhIqBTCpSB/ro7bBIbAZhMMClp6RJQMJDAp1PnEy5mwCsmb2YoUi6W/AZRkGcx5uMb/mIp9b
RI240PNghFaTwVBqL/F5xfymJ/ymUiod4KRIHxqek24eF9IvykACg0JYeBSpCUi3LJj916Tz66/xgRAxT+N0kMK9TXGIUR8Gby1vpFvewaRmZW2DcRTE9aT7ufOZMhD/
gGA85ImOiUfWbM8zmLpTyLh1l/noLhruUj0Pjj+dl45wCikaYVFAn4ZhoWJ8LK2OYhwFQVPeuGGTDMTMzNLpuEtUdByyZuFRjFYgrVLADP0pTfAw9DZlMMCx1OQ89di0
4Q6/Npvf8kpa5R1kOhYWVgGBoZQEBIWHhctAYs/GOTk5Ax5kzcIzyOpTsOhgBrQ0FFLPNz8mS1k+XaCY5FyjsFSMDw2Ph8eZy1euykAiImJYeBSj8qVbCqyy+ZhIGQYw
rQdCOJa61GVRZoNPKfyvLdItO7PUjlhY+QeEQDAPSUxKk4F4efs5OjlHRsUi63fDz/GV6lrb2mv5HxKoOT2e5OBgSCSJ6nnQBTVXMGvu0o1lZm5B4HE6fiIhMVUGgrU5
xxyOAx5k/e7dsPMap7rwND7lV8dRY6qPKdTBEElNJmUzaLgnXQyYpYYW7OcfDHF0OoH1mlKU+IQUZkWSfaz7JQ+bmppkk6/qwgML24d4akJfHTuE8iGJsubV5cumtsTn
cviwua9fEMTB4TjWm0lRYPVWhBuUpAw5uXlFxSWShBx8GNWFB30OhmqwTVfHDK2g81EMm4HpYXMf30AIhlJYMiMtgTEtITFFBstMpZXFvaL7gwdDkhRUF57ay9RQDfxU
RQ2tgE/kpQAfGh77Y054cCkViYg8a2Fp7esXIINlptLK4u7dItnUhgrDk9s5WquK5A+pUIPDXNnUlvhcDpkc9vENgODVNHQXUhE//6ADB4y8ffzplXKeT94rptAlvH1b
RlNQFYYnh18Zwa8MH3qJ4NfmKAQ8h0zRyiEmJodXr1ojFVmxXHPWjJkOjsfplXKEnJRXnyDJrz4lCSSRyMuPCQKJF0gcpOJjrEDOUvIhprxToss/EIkq/xBJ5MWHiBfV
kHCBhEHKKAkVSEinVAWXVQU/rwrqksDnVQHPq/yeVaJIdAlv3b4rm+pQXXh4j/iVoTISxTAYGHfBg1XVPt6+UhF399PW1rb+/sFp5zKIeD99D+F9/sr9/LW+/Utd25fa
ti+fWj9/bP38oaW9qrntfXPbu6a2N02trxtbX/Jay7ktL7gtZdyW5w3NTznNTzjNjzlND+ubHtY1PqhrLK5tLKrl3avl3anh3f7EvfmJW/CRe+NDw/UPDVerG/KrOXlV
nMtVnNzK+pzK+qz3dZfe1118V5fxrjb9be35t7Vpb2pSXtfEvvyIItElLLx5m4VncBpofsl/Hywj4T0cXFmlE9vI2ARPLSHHj7tIa0l1UnIqFvtER8empJ4norDw0CW8
UXBTOgrtLxXV7Xnw0vW7QBlJ28f+9CyL7w8aHcJTSwjeTQgJjZSKeHr5Yc5z+rR3UvI5IhgjQRSq54l7+QlFokt4/QYLz+DbW1Uc/23AkMv78MGXVCopHDxofMbTFyJ4
NyFcKnLG0wfweHh40usV/J9VQhQNHhSJLuG1awVS0We/iahuz4Nbb3zCf+s75FJ3rV8tyyYAWjnaOsTK6qhUyEEiBJ5T7mfoR66BzyshigYPikSXMD//umwUrtLwwP3a
u2D+G++hlS8yWgzSb4PY3wWPheXRzncTyBsKgxCP096Ax+3UafqRK7F0yQWe829qzr2pSXj5CXY8GO4iXnyAXY42vtElzMuX0c+ZSsOD5tZwn//Gawil7mq/bVpmAfbt
P3j6jDfkiIU1WSE6eHH38AI8J0+600+NKGNx2ZDDc7Wac+l9fSpQefUxpuJDKCAR5CtG6BJeviKj1VKqDg86n/cR/Nenh0Te+vO/KJAPkH37DnTCc8SKLHIbvGDABnhc
XU9hqQER8vhF6j3PrU9cWKVhgMZTIzz/IbkMSOgS5ubmyeYHS9XhgRZbq/mv3IdEGstkU0kS5mJouB/uDiHm5pZkkdvgBQM2wAP/UmHh0UTIQ0ypwFNcy0MPg4c2eKJK
kh2M0CXMzpHR64nDAB40Pc49/qtTUpYaGdWQhOQg2N69+9w9PCEHDxgb6BtKRbS1dbRWauE5KW34JusAROC5/ehJUFRMQHhkQEQUJDAyOjAqRiCxgTGxQTFxwbHxQbHx
l4oe4iHpvRrelar6lNefSFK0JN17WuIV8Pi095MzPk88fZ94+T3xDnjiE/jEL+iJf8iTgLAnQRFPgqOuJqSLRCSndAmzsmW0Wmp4wIOWVXOZ//Kk1ASpKd7HoAsee3sH
fT19qcge7T2bNm62sbGnzXdYUAOh4ank8Cxt7NTnqh86ZIpgx4454hGtq6sbliZ4eXr7+foHBlIOFaKjokNDQubMmm184hRJQUQK4tLq/zmat2tt4+E9TRZ7m2yMmh3M
mp2tWtzsW844N/ueag7yagkPajkbxTUz/7BT90JBiUgKdAkvXZLRaqlhAw/V/9zlv3SVgtTI6IdtoHgaGBi6u3tCnJ1d8vOvSUWycy6npJyLjo6jTXZkTRoNj1dA0OJF
S+CmFJZiPOPH6kyMmq5eK7h56w7eqyktfVJWVv7q1Rv4nq+rq8fuxXp6+tZBkfTaNnKQlXuzftzEZifD1mDbtsjjbXGn2lN9PmeGfrkc+/VGasfdSx0Pr34tu/P1zaOO
j6++cWuavLyqd+iIJEKXMPNi9kBVxyz8cIIHGmp+RVkOXjozFMTlPmCmaBnE0tffe+rUGYiJiRlMzFIR5xNumPM4Op4g76hCYipg/vpIw4Ntid1OncGvPl7GloSfhw8f
Tp85iyRCy5u9B7g6q5vdjVq9zSTkh7NmfdblW8KJ0CXMyLwkA20ji2EGD+4Y9reaHP7L4wOW6gSFsq31bB96egZubqchhw4dholZKuLsfBLw4O06b58AIoL10Z3w3Hv8
dOnS5afP+MCsJ8zPhaDDc0b8PM8qrqC3/ge8kURoqV6/kXdwQ9OJvV38mGWv+g3BOmX0wlNnfHnd+58md7ci/wjhROgSXkiX0Xuvww8e0ujg4aDCYQBSq0DPc/r6WdXV
MzjpdhqC5dUwMUtFjju7UPAcc/Ly9idCvWjw8js8a9asg3ff7vwkxjhu+RVNf9aRs/m9jN+ABEmElup1G3gGqxrttbv4OZC1cux3eCiKJlh6RQqP3zD/KQ6IEE6ELuGF
Cyw8Q9H1tlbyP2XxX7nxK44xEcTFYm1F/ejq6p886QExMjIhFA1eHJ0oeOztHcnCH0j8y08QMmxDz7Nq9Ro46+nOT5Dt2om/Tpk6ZfT2U+dye85/QAVJhBYKHu1ljZZb
u/jRz1r2q5qaRnaAU1ucW73Pbu3RP47bZlMvNP+B/aA4IFI4EbqE586ny6aKhk3Pg67mfSi/wl4K8saH6rgU76Ojo+fq6g4xMjqE1iwVgSMewGNr60APAsl7bzQ8mitX
YWerbvx4W6wZNWHdUYeD0ydvOZHY034AeDpfnut6i656zXrutoWNh9Z18aN9aQngmZvlbdMW6VTnsU171ChNE+d2IfsB7G/3AyKF06FLmJp2QTaVMwzgaX3PfxfCL7eV
srz24jcphLs2uqHs2aPr4uoOOXLEysX1lFQEjngAD/auogeBNDx4+y22sGjBshXwVCrMj88x7alqq60CI04bqv+64XhiD/tbL/CsXs/dMI+3T7OLn60XF/4iNGxTW7JW
+3Gst7D9DfZrEXjoEqamnmPhGbQGYBuoTuGX2wyhVMbwv/AGXVDpJIAHmgQevL52o6AQeyVgZcAg5ZiDE+DB3lV0P5b8ugbysK4J/33yb2ssWW5iaibEz0nrbTN+WWHm
FRwWaLX+12kHfFNE7deggiRCS/WqdQ1aM3l7Fnfxsz5z/s/d5jyjZgV7HBe2X+P5T0lglHAi30uYkiYdhfaXiur2PNi5DZblF1ZDLhXHFaQL2r17zwmXUxAbGzv4/vvw
4QN+g+F6dzBiZ+8IePB2Hd2PYbEmLX5Xb89fvBSrub/z42S65c9RQu1+nuFp6i1U4ec/+FY4ERwDHs6SKdyt6l38rMycO1pt5NSL9gawvzUf3+6u/qvalA2lsd+f/+D5
6YOgKOF06BLi7df+mr10vldReHiP+S8sZSp1MnoBS0y179qljccyEHQU8PJ+Je9qecVLDoeTkpLqfMIV0xIGYmd3DPDg7TpsYkVEBJ55C5fg+dJ3fiy0F47sMjFTVrLR
0/Xdz3Z/ftoLPCvXctT/bFgzs4ufJZmzRqmNnJxpuVtgf9tfuuOvLvtBJz9YfyACD13CxKRk6cDRXyqqCE/dDX6ZuRzkg4yMPH3VKQ0Peh6QQ+T6jcI3b942Nzc/elQa
FhYOv+wDEkxmyLCNBu/cm1pa/K/embNgEfLt4uewyTb1n0cu0LV1FtjfXA+t+F3tb123yG7PTwGPcCI4rtZcy5n2O2fZ3138aGROH6X205+Zplso+9uxzYGzfu6yH3Su
P8D6HcAjnA5dwoSEpP6avXS+Vzl4Ppznl5nKTZC7/D47d+4+7nwScvSorYCca0Ty8q/fuHGzouJVa2tre3v7y5evMi9e8vH1x0bWePrZq6Ahenn5pJ07n3/1WmhYFDbM
cnB0JoK3BmgJunpn9vyFmzdv7eJn/57lf6n9vuqALbG/ubsc0PxFTcvMO0x4/QHgEU4Exx8Az4TfOHP/6OJnduYUte7PeUYuXrOlVmj9Ada/PQqKEk6HLmFcfKJsKkG1
4OE+4j8/JGf5ICNTT8/2sWPHLjK9wRSFxgbkEMm/egOC9WaVVdU83vfXkIBTpdCHx/tu/2hpaX395s3FS9kwZNkfcyQiAs+UGbPwnLSTH72tS8aNmrhcBzuOdNrfnPYv
UxuvaXJaeP1BL/CsWFP/86+cSeO7+JmWMUkYnjFm61ZVONPrD6j1b7z920XgoUsYGxfPwjNADTS94D83UggBw/L4bN++EwsCINbWNqTDEcaGwINHlkTg3OzRo8dv372H
cHm8hgYuh9MAcj7V1GCnnWfPy+4VldwouIWnNIFBYYAHMBDJfFcnLCBhyZKl3/kRnv+IPP8RrH/DZt2TJv8tksi7PYb1/xpdP2aMED/0/Ie2X9PrD6j1b/WzZhZcuyuc
Dl3Cs7FxslG/qvQ8n7mUeeD5AUUReTij2rZtB3YIhWB+Lwaba9cLaMGMiBa4O+uSW8CGCDYdQKcBeDDtIQKfg8Ky28xy4u8TVqxYKQk/WAK3ZMkyM3dvkUTuZF2r/3GM
5Pw0Hthco7FYJBG6hDExsSw8A9HA2yD+s30KJBVO/I62gdyAFMJu3bodCwIgVlYUPKSrEe5t0OFIjk1B4S0I4AkOicD7pACSCHx2Csv58koNzVW/j/997px5AGPlylXr
1q3fsnkrxpB4aGtgsPfAQRiyD2Mgt2/fwRnTZ27U0UcUkURwWu7gWqf2G17pocZvmP/AfqD+J+zXeP6D56dYf4D1O1j/xtXR4mjMrJs4+fq9UpFE6BJGR8dIQZsSJKES
PU/9bf4zA4WTTxcl0L80g2zZsq0LnqODx4bAA2caMBgAHjwGJZJdWd9TTiVd2LLPeM0unTW7dddCtHXXUaK3HrJHfwNEx2DvUfsz57N6jU4u3rpxr8LRtXKHDiU7u2SX
biVkN0SvSpuS0uiEKxVVPdOhSxgZGS1NtfadlvLDgx94mNee6imifG6QTS2SXDBrJxYnS0sKHnp60+s4jR6k4aXl6OizcXEJ+MHGbCE17TzBBpMiCODBa6CAx/yIJRH4
jFZMoUsYERklG7UrPzwfM/hPdRRU3vjJphZJLps2bcFSNIilpTUhRzw24Cc0NKK4+D7itre01L17hwOsSwBFV6/dADl4GxQm7/CIGDc3D2w7RwQ+1xVT6BKGh0fIRu1K
Dg+6nSfaCi1tH2RTkchl48bNePEGgu2o+sUGxoCoqBhs3/nly5dmHu96aKj3pEmcjx9xik9a2jmkQOCBSyc88cTmP0SuVHEUU+gShobJyAGyksMDRxxPdiq0VCXIDJ4N
GzZhTzgIRv8EHjHGNKw3Ky9/iQc+Jdk5QX9NSjcyDv23fw/5t3+/HhCIizU1teERkdjoBoYHOBPEsA0v2BGBdzXFFLqEoaFhstG5ksNTZsV/vF3RpaNVNnVJwWPvCAE8
/dqgY2Pjq6s/Vjx5Fvxv/1fOvgN3PX0u/ff/KAkNT/33f9wMCcNXFy9m0fDgBTt4kSeCPXMUU+gShoSEykbhygwP7yn/8RYlkIZi2dTl+vUb7ewcITQ8Qo9u8Ayn89EN
sQfExye+fPk61839wh+Ty588e+wf+OAf/8KV+8ccLy9ehoMbNwrPX8iA4SHmbAKGbfDlS+TahwbFFLqEQUEhslG4MsODhTClm5RA3gbLpi7Xrdtga+cIwUMVMdgQeCIj
o548eZa5R7dQRw8HL7188YwFB8+9fG7/P//EAQTwwHIAB+roeeCOlAj2bIPI5o4kzwVFoksIT3GSRxxMSGWGp+wwv3S9cshgqkjiuGvXrre1c4AcOWLZc60AYYa2QYeF
RWCdW76DU5HGovs3b+OYyFvLo08WLMZB5sUsAg8cSsHRO5zCEcGehxCJCyWjgCgSXcKAgEDZ5Kq08Hzm8B+tVRqBv7ih/2CBjI3tMYgAnu9LbESwIQ9wzpzxwvXr5y48
/Me/3hoeuHsp+1be1TKXk+h/Hp44ia9gMLh95x7s3XHxyXgpFa55iBR+5Cqm0CX09w8YemVTOSgtPPBi82iV0kitLLZbWr16LYEHjt4JPL1iAwM05Ny5C3HxSbmX8294
+nz8Ywq1LkYg5UamuHjxUg4MvnfuFl27Xogd1zBsg3cRIt3fFBB+703Ox3QJ/fz8WXjEauDjJf7DFUojVSkyqM5Vq9YctbGHmJlb0NjQ4zTy0JMWWNK8vX1hDLiQfikz
5fz1wFBITlwSTiHwFo+BH+CB1S4xKQ09D97xlq7gHbvCwpsODk7STRap+fj4ykDbytzzVCXzHy5VGnnpIoPq1NJabX3UDmJmfkR4etMTG5ADwagsIiIKGwDDJEBv6AmP
z25u7oScu/eKcYCNcgEP3rSTrvj4+MGBNZ7JSDdZpObt7SMDbSszPBUn+A8WKY2gtEP/wYrmTnjMjpCJDRHh3oZgQ8ghApP02dj44JCwkNBwGHmx1I1gQwTw4HEqDAZ4
WUjqYmZ2ROppIkEvL++hV7ZSz3kqnPkPNJRGSjfKoDo1NbXwDikEjVISbGh+cABgiNDY4OBe0X30YCmpF/wDgr29MQ8PVnxBOc+dk9HL8EprMCg/zi9RVyYZenrwRhp5
pwVLJEWmNyK9jQg26G2wnQ66ndi4BAIPsCFSUHg77VwGJCAwBJsrioiD43E4i4PA0Hf2bGxOTm5fsmKFpuQiJp1+v7pxQ3ZujJQXHkd+yWxlEpnAY2llAzlsdoTA03OQ
1mtvc+SIxdu377hcHramysm9QpNTVHQfPdi585l9ydmz8Zj3Q8Dty5fivHgvWLBIchl6VUknB+WFx4F/f6YyiXTqS1wqy5drWlodhaDnEY+NyDgNvprevauE3Lp1B5vb
AB5gQ+TmzdsX0i/2JbGxCQQeZC0eHgSQXIZeVdLJQXnhOca/P1WZRDr1JS6VZXAbbWkNoeER7mfo457TG0yTkpJS8vKvGu47cO3aDZocrDNA90WM171KbGwigQdZi4cH
z6Akl6FXlXRyUFp4Xtjxiycpk0invsSlgn2myKvIpofNJMSGTG8wNsOryyEh4bm5VzrJ6Vqtc/PW3YzM7L4EHtIIPMhaPDx410hyGXpVSScH5YXHhl88QZlEOvUlLhX4
38DCHIipqSg8dG8jbE+j5zbC4zR6kRsOiu8/wPAPW3z2JVijQOBB1hUV4uY88AciuQy9qqSTg/LCc5RfPE6ZRDr1JS6VRYuWkPf4TUwO9xykDRQbkANBOpeycvuS+IRO
eJB1RYW4DVfotTOSHAy9qqSTg/LCY80vHqNMIp366g8ec0ssbCPw9NrbCJuhv89tYBvoGqcRZohgqwUkkpV9uS9JSEwmPU+/8GCbe8ll6FUlnRyUFh68Q1o0WplEOvUl
LpWFCxebmVlAAE9fDz3JUE0SbEAO5O7dIjgN7UsSElMIPMhafM9DXvM0N7ewsLAWIwiAYEOvKunkoLTwPLfk3xupTCKd+hKXisb8BYfNLCCHDpn2XCsgBhsyvaF7G4IN
pISCpxiLrPuSxKROeJA1gQc7MhQjteISbAwKyb18JSEhmUhePjwASyR0FEQn6cBi/uJF+dCrcGA5KC88Fvy7/6lMMrB6YRJaAM8RyM6du+hVNpJYBXrFBuRQ8Ny7j61+
+hJsI0V6HmSdj+2Ayl+6nfKAY/jbt++ic8N/mO+IpKSmYYIkLNExsdipASJyHacITEekk8LOKPBJz0QvQxZHaeF5as6/8z+USL52dHz79m3I6pFKGI4vsLAaoq6uYWxs
Ynzouxw6ZNIlpuiXRKXLrRS8N2HIJywwfLu4nHRxFRY37E0CwSYiW7ftIPDADICXFzDRwrvQyJp+I1q6B6Wlj+HZp6Wlpb3981ArU5KaUnR4Ojo6Pn/5go1lmhobOfX1
NZ8+Vb5///rVy5ZiHf6d/65E8vzp05cVFXiM/+njR9wIbgc39flzO25QknrqNQwaEJoRNq7Cypq6uvqPH2vOnPGcO3eejGX7jl1p59LxLAgWbSxqhh+SIZKHD0vfvn3/
/n0VnPt8+lRbX88BS1AjHM0x1uFgIiooPGgW0EhbG8VMA4fz6dNHNLtXFeXPnjwuKS66VVhw/2p8cW7w7Yu+N86fzkt2zY51yIi0SQsxT/Q3jvXaG+WuHeayLdBpo5/9
aq+jyz0sFrqZzTthMtPJaIpU5MShGSfN5iJZz6PLfO1WBTptCHXZFum+O9bTINHPKC3ELDPyaFasw5Ukl+vnPG5l+tzLCcq/nHuz4HrxvXtPHz+uKC9/9/btp48fCEW4
TdwsA4oQC00HDQjNCI0Jr8egYb158+7Vqzdwf4NB1Ivyl2Vl5c+ev3j69PnjJ89KS588fPS45MEjjNMwrMKIDlMjdBdYRoDV03j7AK7e4C4Hvtrg6xDzHHh5J3Y2vFgK
MLCvqGCdwcXzF6jVbmTBaGpaOoQc4yK+EqzluURYgo0b0WFvQFKCnR6pjU/waje6KfKiK7ImhkHKjFFcQk20HjxCIVFUFBjFfv78xYsXUBh+eV7hpl6/fgt+KiurPnzA
Zih12BYFfhtbW9sYaG8w2JC4CgoPKRyGOvhtbm1p5nG5dbW1H6qr3r55Xf6i7PGjR8X37qItokVmX8xMT0vDhPRsVFR4cHCgr4+nh4fbiRNO9na2lpYWpqYmBw7s0zfQ
1dbeuW37lo0b169Zo7Vy5bJlSxctWjRfQ2POPHj370fU589HYETRWqm5bvXqzRs27ti6VWf3bkM9/UP79x8xNbGxtITHp5POxz3d3f19vMOCgmIiIxPj4s6npl7KzEAh
C69fu3fnTunDBy+eP3vz+nV1VRVuh9fARafR1t7+9evXQY7n0HTQBQEkbLNTW1uHLkgEJLQ8iqUXFWiLwixhi54HD0sxt0GrpazVQkQRqLD4QMAVkZto9LQvUtoXtohT
bOIyTuCBpNPfCFmiSh49EVs5MiKmcIIKilH6+Cn89YAWFA/AA3sCDH4IaGBIhwNgKL21tVF6G+KRsHjAFBoekaJDU9Qo7jP8KreQHqm2pgZE4VccnVLZs6donfhpv3Oz
sPDaVTTZ3KxLWRnp6efAVnJyQnz82bNnIyMjw8LCgoNDsNs6XnX38fbF7oHwhXHaA8ih6X8XDw8vDw98hQD+3t6Bvr6IgoiRYaEAIy4mJikuLi05CdxeTE9HRsjuxtV8
ZA2qHz14AMdNFRXlQB2cYKhJ9TA8Xmtry5cvn3ELMqtyZIQWhg6KoIW9qxoaeOimMMb79KkGK0HRTaFpkp6KAEYEbRekoRET2CjenpVR8hTDz+fEMVVfQsKQ8IiIFCAU
Dy8qCBKECtKT0GyACnzq0JdwGlBIlLatrf3z589yJ0QMP8oEj+T9LIWZgDQ0VnxgpcEPVWtLC36xqE9TUyPaET5cLhc1hfrq/NRzOLRQl/AVAiAYwiIKIjY3UQkgKSSI
ZJE2GicyooCQ66+g5MqRMKTghjo/uD3qHgf8EU5jkJ2rhKWWaTDVhEemKmQzG64aYOEZrjXP3vegNcDCM2gVsgkMVw2w8AzXmmfve9AaUHJ4uHnWY4QdVY7VCnsm2UPH
1rKwLWpjbPK43YJ3lIVpjZhtnVfTqVgqfcnTHHRtsAkolQZYeFh4lKrBKlJhVQAeZj0D2/MoUjNUzrKoJDwCMDT98nIdl47AoE7TNq+ys3/pqL57Zs/4ET+O1z4ZaqU5
kGFbR2NZqvXisWojxi61Si1rJOlxy3I9dahxo6Z16rNGXOh4Fq75h5Z7TKj2bIkHkMrZcNhSK/jynP4rqPc5jwAejSVL6elQ59yGU+S+upuTf8nnPBQVIIfMr8Yudb/T
yO9oLPIUwElktUcRh8CzcLHG+BHM+sP+75gNoTgaUIGep6fBQABPZ4fTXplqNJ7YAASz/6U2udXoNhpLw7WnDqDnIV0KZY0QJEhR9zHPavZ4/VRBp1ZDHVvB+iBgbLFj
XrVivXmiOA1OlUqiAvD0/I3vNp+hDWjdLWkDnvN0VN+JCYtKySujhmedIzS6LxIArBlW9oWCh6JIldoIey99aICFRzJrW2NZXurFIvQnjWWX3W1sMcPpNpBj4RmOhA0j
eDqHbdR0BTP7N2n6vQzbBGFgTogCHLAHPAvT7xzyUajM1gkrxVSHm2cjOmxrvOOxWDCoExDF9jzDhCQVgKePOU+XMUBotCZsMBhLTet7GAzI7KU3owKZO3XlRUX80s1g
QJJi4Rkm3Ahuc1jBAzvBszRYqClTddjtVKve4EEYDMwoc7YgmOflsq75S0dlng0VV22xVVQRZXT4bqoeox/+TBCMhYeFZzhpgL1XVgMMNaDkPQ/Du2ajsRqQggZYeKSg
RDaJ4akBFp7hWe/sXUtBAyw8UlAim8Tw1AALz/Csd/aupaABFh4pKJFNYnhqgIVneNY7e9dS0AALjxSUyCYxPDXw/wO8u22XXN3bCAAAAABJRU5ErkJggg==
                </image>
              <para>
                A transfer gateway facilitates the transfer of information, in one (uni-directional) or multiple (bi-directional) directions between different security domains. A typical gateway to the Internet is considered a form of transfer gateway.
              </para>
                <image>
iVBORw0KGgoAAAANSUhEUgAAAmcAAAGMCAIAAAAQu5KaAAAABGdBTUEAALGPC/xhBQAA0OJJREFUeF7s/QdUHFmXJor+77657643b6bv6+npnu7+u0dVRVVJVaUy8r7k
vffeCzmEEELCSoAQCARIeO+9NzIgjARIQt4hLyHvPV4YmeJ+kQFBkGQmmRGRkZHJYZ3FysiM4/be3/6OP/+v5ubmv5E/IgEiASIBIgEiASIBdSQA1iR/RAJEAkQCRAJE
AkQC6kjgb+q8RN4hEiASIBIgEiASIBKgRmeJFIgEiASIBIgEiASIBNSUAGFNNQVFXiMSIBIgEiASIBIgfU1ONvC1PGpGtz93FL9riV1dvOOnn2dE3fmqNLV3xXZ//mpX
XN3xBSruN0bdWsMEu+ji8tqW15TH0rjYAiaFvL9WF9v/+pN9cbXyGmtcQhKBSEC3EpBZNYPEbgON9xeU18osnAIpC+9txZSL8vMku6ji8laUK42leTUFTIrKXFhvoHl1
9DwG6WtyUaAWWZMC7cANWU9kYOVp3Gxu45mUnJQIa3IxGxJH2hKQo0CqIdvS0lWXNWVt35+2ZL9oUsm1aoqBhTLCmmrKTJTXCGtyEbPmrKk8F1lfs7Ub+rW2PGvHhJ+N
hOnGaY/btJcyF3WQOEQCQkiAZs3WPmXtjejVAztDYvsozdXlWfaTGK7lWybtoUzYNjTfeupdfMKaXFSmnDUbyqMWG00LKj7qDPAYdZvmUPyik15jO9ZEYb7WXvKd1AJd
xrjpZD0yI9b/Oi2q/CvItcALkO6GEaGslkEkIPaorzE12DttR9adWnoQlR5uojj4DWuIuOnVpQSKmwHv1b7H6AGlr3eip/WaEVFwzH4aFWWCc/ErWXsZv7w67UvnZR8X
bUWPM2sPz1zUQeIQCQghAUWsScGt0xFa9uBt5aX9s1q4lukg0uDanxC5+k/ZPI4cVOmyq8Tvs6OsIWL++CWsycteCGtyEV8nrDlm4iRmqrKl19jJvGa7Kc+2WdL2rEkn
CxhXn/eScZ4s/Dxp/3lwpIxrmfnRxdHlH5WxpqzwrJlUuoQyYI+bMIaZ12kpUi07L2bMirAmF7MhcaQtgQ4jtBPss+k2ZScjtGzWpBMBABvaYrWBC6sfblW3g+osr0uV
rW1l5fhlsaYQ+CWsycsSCWtyEV8nrNnSxWx6kbWldcBHU9akx2zbs2ZLsjRj0XMnDHtRXUmjCb6XsHhBNrLUoUfIJEV9aO1Kfq29E2dML3OggP1zy/dfn2Svp8emPstc
AN1jpl+mC0ZYk4vZkDjSlkDHec2BxlE3qKV5GrOmDFPt+pqt4KJBvT5LNgYlh0rl+G0rgCD4JazJyxIJa3IRXyes2ToryXqtPTzaBk4xWsOe16SHapgVue1ZsyVZ2Wgt
u7OIhu2dK+C81g4rPZxLDeSyVrq2JiVjx7auLfPY7ntZClR2H1s/yIaZ294hrMnFbEgcaUug/Qjt11cXfNbI9xplPNeCvrZmpTp9zVbQ0c1TNn4B1c9sVCrCb3sC5o1f
wpq8LJGwJhfxaZM1lc9rasSaDKTlhogJa3JROInTFSQgt7SnuQ3mcl29tlYvPRijzrymhqwph1/CmlIyQMKanLRBdxBXx92htnNV34la34ocppdGdc4U9TU7ZKdqDa3C
viZ7hFa29IDqVrLGbWTjq9xGaNv1Vtua0vTUS/PXF1kbyAgtJ3shkfRBAvILYttwre4Ibfs1tIqpjjVCSy0a6CVbH9QZftUboVUbv6SvycseCWtyEx9roIY93NrMkTXb
j7h23K/ZLtnmdit06Hau3GqgliUGCkZoW7hc4Wqg9mO8dCe1fV6TJvQi85rcLIbEkrwEFOzXbFkrwHO/ZrsBnvZQbRkK6gy/rAIoXw2kPn4Ja/IyRsKaXMVXW35sP6Y9
ZMtKmf0b/FlT8dlA7VkTHNmy86R1tYJsOrT9zhOqc6iQNZubla1cV4Q6Ki/ZFlIclRJ1NLvlhCMyr8nVbEg86Uqg40E/CZfo/VfqsqaSs4HkpkUYqP60PvoOc1yYSvy2
KwB//BLW5GWFhDV5iY9EJhIgEiASIBLoUhIgrNml1E0qSyRAJEAkQCTASwKENXmJj0QmEiASIBIgEuhSEiCs2aXUTSpLJEAkQCRAJMBLAoQ1eYmPRCYSIBIgEiAS6FIS
IKwpjLrll4O3nJku4PWTLQfayXZnalpmZnke+7R3lVcDti3TxUnudnGXXmmcp6ZlJO8TCUhCAh3P3mKuJBKqfPQOb9U38irJq23pPn1JA/0ntxFu2g7c8knfDEr9seHf
uipYqKp0yXQIawqjdu2zZiswNGZN+jhcZoMmri45KuNARbvTWq8GpA80aNtFylwZKIy0SCpEApKVgPZZs+Uies1Zkz4gug3L7a5Uar/n+5vWo27l4M98L1n560HBCGsK
qiT6kEmNiU2dMnDdYsU+lr3lGCPZhQwtrMkcBsY+1oR2HC2Y/PrqqMME1tG16hSWvEMkoOcSkLWDNSc2dWrN9YppukgtrV76+s8WVyNrUjOX8tbeybbDfX8dbmXARu1i
3GDIPv9PneKSd+QlQFhTUJtox5pyl2I2vTofRN9/6ZARYd1204jCWy1bOKz1skzWCIzi+zXl8mqrlPyRufRVf9QhXvKnbjY3M1cDyk7XbLsZW5a7VpoCggqfJEYkIJwE
2rGm3AWZLQe7Y/LCKTNqG40U2fuLI4sPookpu4y2ZUSn9ZCQ1smRlo4mdcef4rs25S/jZKokd9QJfWAn3QJuz5qIITvSq/29SfRgLXMzhHCS6nopEdYUVOcdWbPlUszw
S+fZ918CM0xLUMGtlu3He3E83r22mxYU368pQxRzAWfbJCTrtr+WijIU2JE1WS9/fVFsv9jY5zSZzxTUPkhieiOBjqwpu30WVHf6Ag5/7nBDLd08xZGTrT+xunrsq3Db
saaiuzbbXcaJ1i3z16Hx2v5ypLa+JhWj7WVqrGjaet/zBMqC2R5hTcFESSXUkTVbxjnZt+KxTntXfKtlS7uVakW2HcXOjNAqvF9TdqVX65gqq0ry7VPWT8pYkxnAwVl6
x7MzfHfYR2RjbYGgciKJEQlIXAIdWLP1gkwZV7UbJm3ra7Z833bPQdvQjmx+kR6/aX8Uu/xdm+2mVNh4bX/HXzvxdehryvc+q8uLD2but3eIyiqm79kmfzwkQFiTh/A6
Ru3ImjRO2h9E2TZqqvhWS7QvcdRkRnRUBsvE299/Ine/Znllu4sw2wrGra9Z/erSkeyDrQtnqX7nrEn7zxPiFNRWSGKSlkBH1qRvFGk/5dHWKm33PQvXX1+dT4iKy2S3
O+Vuq1Z11yZbRJz6mp9fXTqYdYiBMrVGYQF9hRH54ywBwpqcRacoojCs+Znq5FGkJTul3c4tm2oecmNNOZB3uFla8dWA7S+jbn8kvaDyIokRCUhUAsKwZm15cdYR6gh4
aseIvQO9V4Qjayqc16RHhpTPayq7T1eiUtePYhHWFFRPyliz5f4830vUJip6LXjbtEeHW/FkI7Qt9yEwZKlwhJa5X1P5SGy7AR/2Ijr52wTLs+wn4f6WtgZ164Uq9Gq9
tsVBgkqMJEYkIEkJKGNNekFNy9ALvRWkbYS2dXaD4Srqw5/GUTdq2RcQKRyhZe7alL8ghTVwxF5DS40ATWtFpfI1tC1NXvpylZY9360OR5Jy14dCEdYUVEtKWbP9/XnU
sh1VrElPZzIrDuTXwim4X1PF/KWyDVuq9mvKFYC6DU3GpuSPSKCLSEApa9JLzVsX+FBLhFSwZksTuXXrs/y8pqK7NpWzZgdUtruIV8l+zZbL5Fm/kp0nfE2YsCZfCbaL
r5Q1qXEZujNnhE7k2YwdqlkTzULZLklqCbsdfZwHe79mx/s1VbCmLOujvrJNL+qfDYTF6/SuL8QaaLy/gHXUiKASI4kRCUhSAspZsw0av66OOpdlp5I1gWRZpxA4Ys7Y
ardfsxWbzF2bKlgTguJyNhBzRS6czxqvo2RlH1+DI6zJV4IkPpEAkQCRAJFA15EAYc2uo2tSUyIBIgEiASIBvhIgrMlXgiQ+kQCRAJEAkUDXkQBhza6ja1JTIgEiASIB
IgG+EiCsyVeCJD6RAJEAkQCRQNeRAGHNrqNrUlMiASIBIgEiAb4SIKzJV4IkPpEAkQCRAJFA15EAYc2uo2tSUyIBIgEiASIBvhIgrMlXggrjV1VVP3781AACKqIVAZFE
iQT0RAKvX78xACCjCo2NjXoicqkXk7Cm8Bq6d+9B4dHi69dvPn78RK/DufMXUZFXr98ILyOSIpGAPkiAhsC9+w/0GsgoPCpSUnKytq5OH6Qu9TIS1hRYQw0NDblHCm7d
uiNwurpI7suXL6fPnIPX0EXmJE8iAR1L4O3bd8Dyq9evdVwOIbKnsXzlylUhEuvqaRDWFNgCKioqDh7KvXbtRnHJyYLCIr0OqAIqguoILCOSHJGAPkgAXczikhOAgF6j
mC586akzZVevnzl7Xh8EL/UyEtYUWEMfPlRkZB7MLzimIkRFx7J/9fHxYz8GB4cdOnyE+SYxMQWBecRP7Ed8L5ea6qw5/IrqCCwjkhyRgD5I4O7de9kHclRAplMw8oQ2
B7SqiIJ+c2npGX0QvNTLSFhTYA29f/8hOSUDBqos2Fjb4gIEwIl+YZvFdjziP/2I7/E4f+687AOH8RgXnzR4wEAEfMAjvsRPQwYNBnHS78ulpiJfzj+hOgLLiCRHJKAP
Erh9+256RrYy4HQKRp7Q5gxYZRHB8SXHS/VB8FIvI2FNgTX07t37+ISUwzn5CkNKajp90R2Y7+DB3OTktKGDh9DfgBcRZdpU+nKub0JDw/FosXUb/Wi/0wGPHh776MdN
JpvwKJeaskzp75PS0m3dHJdtM0bY7eWGR9XvM7+iOgLLiCRHJKAPErh56zaajMpgohqMbGjjs6bQVo3N6IREYHm26aL1dpvdA7wzsw+pg2X0m4uKjuuD4KVeRsKaAmsI
KwiiouMxF6gw5B7JLyoq3rlj56XLV+gXTp0+g8czp8/gJzzie/e97oUFhceKSvCIeYgA/4DIiEj6Ef8PHDiIb0qOn8Rjx9SU5Wvjav+3yf/5t239/+YwlAqbe/8wp9de
v/3K3md/j+oILCOSHJGAPkjg+o2baDIqw0inYOQDbWWZpmdmr7M1/dvs7/5mO6gFyyt/AZaj4uM6xTKmWjDBqQ+Cl3oZCWsKrKE3b96GhUejWacsoFV46XIZ+1c84kvm
G0zaY9kq80ivYmUe8RnfMI8dU+uYr9WenX9b/OOe4sAP9ZV0bfHB+MAOYM8ryF9FUemfUB2BZUSSIxLQBwlgHVB0TIIKgHQKRj7QVpjvEovVf1v1c+at/IbPLZsvy98/
GhAw7/s5vSJiY1VjOS09Oy+vUB8EL/UyEtYUWEOv37wJCg7PzDqIgL4g/UEuxMYlsr9R/Zicko6g4n25X+XySk5N/372H1PSl7+uucoOjysu/N+BI/CTwhKyC4/qCCwj
khyRgD5IoKzsWkRkrGosq8YmT2jLYdM/LOS/zPnW7uQuOSyfeZb3310GzjCZrxDLdB8UP6WkZuTk5umD4KVeRsKaAmvo9evXvn5BaNadLD3z6tVr/MdndjDbbI7VPRGR
MfSXe/dSU5X4Tz+GhEYO6j8A79CPCYmpc2bPRcAH+pvt263wAl6jH728/NipyeWFR+f9e7/Z/Itl6dobLxPkAr78l2U/+IZQpZUL6O8+e/b8SN5RfI/qCCwjkhyRgD5I
4PKVMhpobDiwkQIwLpy/gMGmsNDuiMrVVht6OvcNK7PviOXRB8dhCiYhqcVLMHGzsg+Xl9+/e7ccH1DOg4dy9EHwUi8jYU2BNQSm3O/le+jQEXygAz6npmXRwcvLt3U1
0CAsNIiNS6IfEQIDQ/HC5ImT6Ee8iUeTjZvox+3bLPHo5rqXfsRreIyIiGanxuTC/mDhZDPNq6/18Qk5t8yP37NhAh63Fo/pZ/4zXpCLeAQ7u2Ulf/DgIX5CdQSWEUmO
SEAfJHDp0uWAwFA5ODBgYcC4bu061dAOj4jWFNoKsTxtw7ylcYOdT804dteSjeXYK8bAMljTJzhQLiKW/9BYPnPmXFx8clY22UUmgOUR1hRAiOwkXr58tdd9X0xsYkBA
IMWg+/YDM0nJ6XQ4nJOXnJQ8c/qMY0eL0tOzEQ4fzsEj1vjgJ7xQWHhs5YqVWP5DP54+fW6L2RYsF8LyIDweP1GKpUB44eSJUia1YYOH0KkxubA/mDtaLd33m9/ZPwPO
DY+8ODr20hgEfMA3CGO2d3f02CMXMTAoFMXGKVygavyE6ggsI5IckYA+SODChYs+vgFycGDAAkhi4Z4cGIHlU6dOy0Ebe1Q0hbZCLE9dP8ckvDdgG3RuRHQrlsMvjKKx
DNYMCA2Vi+juvg8e5sqVMmsrW8zRpmdk6YPgpV5GwpoCa+jFy5cue/YmJqXBRs02bwkIDMFndjh8OO/mzdtp6Vn0l/iAR3zJvHPp0hW5x+PHS5lf8RkvMI9yqcnlhUdX
L8+Ba77Nvtq/Y0i90O/HBd38Q+RLiFgo9qqVq1EFfEZ1BJYRSY5IQB8kcO78BQy0yMGBDTHVYOQJ7Y5YtnaxX+veQyGWI4p6fzf7945R8I3T7j3m5lvxITIqLjU1XR8E
L/UyEtYUWEMvXrzY5eSMwRDphD6Lhgak/nDp/s9Pnn9T+/6fqt79S/mT7/HoFGI0ed3sTsuJ6ggsI5IckYA+SODs2XPuHvs7BYhoLwSFhX8367es490B3lev/hNY/vDm
X28/pqC9fOe3ZvbbVZcEi+GTksneawEsj7CmAEJkJ/H8+fMdOx0wYaks7N69Z87sOVgNRL/g4xs4fuw4jALRj/h+5oyZeIeJvsXM3GSjKfPo4b4PLzDR8eaAvv2QiIoc
vQMDAbbI5H97++J/NFX818aK/9/r5//kGvDv+DIwNFxFRPonVEdgGZHkiAT0QQKnz5zZ4+quAiAAphwYBYS2wnx3ujr1Xvyfh/L/te79P9BYfvzgf25y/PvwFRPCo1pc
irICY2VTfEKiPghe6mUkrCmwhsCaNjZ2OBlAYXB186DX72DpXWhYlH9ACBbEUkcFDRzk5x+EKLNmzqJfwJt4tLPdQT9u3boNj257W6LjNTwyqSERJKUsU3y/389vovFM
zHxYuvzbGut/x4fZJov8g1VFYVJDdQSWEUmOSEAfJIAZyt3Oe5TBCpCksSkHxo7QDgmN0BTaKrDs6rWv18IhNJZnmPwdH9ZYmoSER6qIQv8UGBQWG0tOLBHA8ghrCiBE
dhLPnj3btt0KUwgKw4GDOVhBAKQlJSWlpGQgRIRH4NHP1y8z8yCipKWmY3UPVgDhTTzm5BzB+gKsOMAHPB49WoTPeOHQIepXudSUZcp87xcU7LrfEyE4LKLTl5kXUB2B
ZUSSIxLQBwmcLC113LVbGVIYMB49eqwjGNnQxmdNod0pPPf5+mqKZSxWiIqO0QfBS72MhDUF1tDTp8/MtmzFFIKyUFhYdO/efawUoF/Ah7IrZcxjTGzCxYuX8A4THScB
ITCPOG3kxvUbeI3+Ri41Ffly/gnVEVhGJDkiAX2QwIkTJ+12OKgAjmow8oQ2Z8Aqi4h5nIiISH0QvNTLSFhTYA09ffp006bNGH01mIDqCCwjkhyRgD5I4PjxEzY2OwwG
yN4+/mFh5JwvASyPsKYAQmQn8eTJk3XrNmBzdHBIhAEEb58AVEdgGZHkiAT0QQJYQ7t5s7nBYNnZxS04OEQfBC/1MhLWFF5DW7ZsNd28xc8/GNPveh327/ddu3Y9jmsQ
XkYkRSIByUugqqpq1ao1hoFlF5e9qEtaWprkpa4HBSSsKbyScBStqenmZctWGECws9uB6ggvI5IikYA+SODKlSsGg2U/P/+GhpabUvRB9tItI2FNbekGx+n17d1Xr0Nl
ZZW2pEPSJRLQHwnoNYrpwjc0NOiPvKVeUsKaWtFQY2NjVVX1smXL9TqgCqiIVgREEiUS0BMJ1NXV6TWK6cIDy58/f9YTkUu9mIQ1hdfQ69dvjh4rOXX63OUrV/U6oAol
x0vfv/8gvIxIikQC+iCB27fvAsvnL1zSayCj8Lj4AVhuII1gIayOsKYQUmSlgQbdkbzCM2fPf/nyReCkRU8OVUBFgDfRcyYZEgnoXgK1tbXA8q1bd3RfFN4lQI8Z9H/j
5i3eKZEEmglrCmwEFRWVhw4fQRP11KmzhUeL9TqcO3/x3r0HqI7AMiLJEQnogwTu339QQJ1J8sAAsHzt+s2r166fPXdBHwQv9TIS1hRYQx8+VGRmHcwvOKYiJCamsH9N
z8hW8QjSQlDxglxqqrPm8CuqI7CMSHJEAvoggbvl93BopQrIAJhy4BUW2hzQqiJK7pGC0lNn9EHwUi8jYU2BNYRZwJTUTBiosrDNYjsOnvXx8aNfwAc8BgYG049x8UmD
BgzEO/Qj7rNdtHDR/Lnz8IH+xsbaFi/gNfpRLjUV+XL+CdURWEYkOSIBfZDA7Tt30zMOKAMOIAlgyoFx8MBBIE5BoM0ZsMoiguPJbIsgdkdYUxAxtiXy7t37+ISUwzn5
CoN/QDB9TwJCWloWAvOYmpaFKFMmTaa/wZt4tN/pQD9aW9vi0cNjH/2I1/Aol5qyTOnvM7MP+YYG2bo5IuCD6pfZv6I6AsuIJEckoA8SuHnrdnJKhjKkAJIKwThk0OCD
B3PZ0MZojabQ7hTL7gHeNJajExLVxHL2gZyiouP6IHipl5GwpsAaevv2XXRMwsFDuQrDsaKSAwcO4t6SM6fP5B7JRygqKsatJrk5ufiMKKdOn8GvkRGReBOPJcdP7tyx
E9ek4AMesTYnwD8AN6LgNTzKpaYsU3zvHRLww5xef1v5y99sB/1tW/+/Leo+YOmI4MhwFVGYn1AdgWVEkiMS0AcJ3LhxKyExRRlGGDBifW1HMHaENpCuDrTp1FQEG1d7
3A72t/W//81hKI3lWZsWRsXHdYplkHfh0SJ9ELzUy0hYU2ANvXnzFncOoFmnLGB9ENYKoXlIv4APACfziG/Krl7HO0x0+s4T9iNeYB7lUlOYqavvvr/N/s44067sFbWC
ruFzIz7MCFkH7AVGhKkoKv0TqiOwjEhyRAL6IIFr126gyagCIACmCjDyhLbCfM0ct/9t1c97igKfV7+isXzq6aUBHrO+n9MrNT1LNZbT0rPz8gr1QfBSLyNhTYE19PrN
m6DgcDTrJBKSU9O/n/1H35hZz6uuvq+7zYT778//X+5D+i8Z3mk5UR2BZUSSIxLQBwmUlV2LiIztFCCivRAWHfV/zPl2c6ENG8j4nHs/8//c+rux9UbVJUlJzcjJzdMH
wUu9jIQ1BdYQjjjAue1YRJCXf/TZs+elpWfwmR3c3fcN7D8A1w/RX+IDHvEl/ZiYlIa74L29/ZgoltutzMzMmUd8njt7Ll6jv5FLTS4vPDp7uf/r2h7bTq6/8zpdLuDL
f1r2g28IVVq5gGKj8KgCvkd1BJYRSY5IQB8kcOVKGY1TNhzYSFENRsSdOH5CUHAYN2h3ROWmnRbdnfqGlTl1xPKgtDEYOuoYBd9cvXq9/N59dEPhNA4dytUHwUu9jIQ1
BdYQjp/d7+WXmXUI11PjM8KhQ0ew0ocOXt7UilkELL2LiopDwAf6m8DAULywaMHC1scQPDrYO9KPVlY2eMR/+nHO7DkdU2NyYX+wcLIZ69bb9sS04vKdJ+87MqHgrq1p
0dg+5j/bue2Si1hYWEyX/MGDh/gJ1RFYRiQ5IgF9kMClS1dwTRgDByCajRTVYGRDOzwiWlNoK8TytA3z5oQPcj09nw1kfD5wcxuwDNb0CQ6Uiwi+p7EM7oyLT87KPqQP
gpd6GQlrCqyhly9fuXvsj41L2r9vP8Wg+/ZHRMRgJR4d8vIKsLRn2OAh6CqiGYjdYMlJyWBBLP/Jyc2XLdjLwa9YAYQ36fexggChuOQEHgsLi7AUCC8cO1aER6yIw+Ig
JjUmF/aHrbusF3v+5nV6uP/ZkXGXJqWUTUWIuTTB58wIfDlqWw/bPY5yEX18Ag4fznn8+Mn2bZb4CdURWEYkOSIBfZDAhYuXfP0CaTgAy4EBgWyk0GDEUj4ajCqgTcFc
Q2grxPLUDXNNY/ruOz086NyYWBmWk65Mibw43uvMCHwJ1vQK9JeLuGePG3rMwPIuR6eY2MSMjCx9ELzUy0hYU2ANvXz5co+rOwZDAgJDwHb4j8/scPx46c0bt9LSs+gv
Dx/Ou3PnLv7Tj/geLVy8w0Q5f/4i2onMo1x0uUe5vPDo6uU5ZrNRRtkAheGHBd38Q+RLiFhOu/esX7cBSyHwGdURWEYkOSIBsSTw4cOH+vp6brmdP38Bg0M0HNCCpOGg
AsvCQrsjljfYmhm791AI5JjSvmDNjlHwjbn5VhrLUdFxqWkZ3ESBWJAk/jhHN6SIhDUF1uaLFy+cdrtgj6NEQmRM3Hezfo/P63GuvOedxz+8ePm/EW487I5H3+QfR6yc
2Gk5UR2BZUSSIxIQSwLZWdSWaPe9e0+fPq1pnmfPnfPw9OoUIKK9EBweAWo8dPpngPfRs+9oLF+6Rz1u3PPdcgtj1SUJx6BXcqqmQkCbA6LbuGEDxAhhahrdIN8nrCmw
Wp8/f7HT3hEjtMqCj2/gmjXGEZEx9Av4sGH9RnzJvG9jbbd79x7mcZuFpYf7PuYRP+Eb5lEuNYWZ7vbc22vxf2bn/XvV23/8UvV/far8/35480+J2f/+3azfvAPb8lVW
YFRHYBmR5IgExJIAzZp0GDl8eFBgUHl5uZqZnzlz1tXNQwWWVYNRIbQDg0LVhLbCfDfv3AYsnzz7bx8//MPXqv8TWH729J9dAv7ee+HQ8KgWl6KswKFhkQkJSWrWHa+V
lZWhtcFIj7AmIzrCmupbkVpvPn/+3MZ2B8ZDFAZvb/9B/QfA/mbNnBUWHoWAFbPU4qD+A/ATomzdakGbqZubJx4ttm6jH/fupR6dnFzox40bN+FRLjVlmVIRPVyBq+km
f9/m/G8I+IDH/f5Ujp0GVEetmpOXiASkJwE2azIEsGDevPi4uE7HG0+dOu3s4qoMIKrByIY2lhQx0B4ycBCO9OoU2ipQuW2X7bezfltt/e80lvsv+Y9Ja2eGRkR1CmRs
IYuNi+9URfBgaFughcHmS/oz6WvS0iOs2akVafbCs2fPtm+3ioyKUxiSklIx2Qn78/P1w5K25OR0LA7CI5YVZGRkI0pEeAQe8Q7m7fEYH5+IxT4IGRmZeMw+cAirD6jV
Q5HReGSnFhkZqyxT5nvX/Z4mduYWjtb7fH07fZl5AdXRTATkbSIByUhAIWsyfICBx8LCQmUTn6WlpY67ditDigow0tDGmj4a2visKbRVwzM4LMJx7x5NsYw1FtHRMco0
gzYEZIX2REeyZL4hrElYUyvIxvL0LeYWmEJQFnCo1YULF3FVAv0CHq9cvoL/9CO+x69nzpyjH2NjEy9evHTj+g18oL/BT/iGeZRLTUW+nH9CdbQiKZKoAUlAhavVi58U
TnyeOHFyx05HFcBRDUae0OYMWGURff2CIiKj5IyOPW2pF5pSVkgxwUT6mgJL++nTp5s2bcYGZxUhOiae/WtCYqqKR7ws977qR9VZc/gV1RFYRiQ5g5OAXjtcuYlPRjnH
j5+wsdmhEZaFhTYHtKqI4u3jHxbWds4XOpdy05Z6rUQxIUVYU2BpP3nyZP36jTiyIDgkwgACKoLqCCwjkpzBSUCvHW7LWoENG7BYlD1ae/bsua1btxsAiukqeHh4hYSE
sk0PxIkBatWjsvqiWTEhRVhTeGljg9TmzeY4iC4wKEyvA6qAitiTNbTC24ihpagvvrVjOcEZmK5TuDIIp2OuXm1sbbNDr1FMF36/l++6dRuwH1yh5WEFEJZHKVwBpC+a
FRNRhDWFl/aVK1eWLVuxdu36zZu36HVAFUxNN79+/Vp4GZEUDUsCbN8qqZopWw1E70IBW6gu7aFDh4HljRtN9RrIKPyqVWtcXfc2NDSqri92m0AsyphSaquBdGV1hDW1
gvGqqqpHjx7169NXrwOq0NDQoBUBkUQNSwK68l+dSrEja2IyD9zQaUTmBWBZr1FMFx5YVr/K9BIhO9uWa7clu4ZWV1ZHWFN9W9Lszaqq6mXLlut1QBU0qzN5u6tKQFf+
q1N5M6yJTSZy05adxqVf+Pz5s16jmC58XV2dmvVlvyY38Un6mrRwCGtysKVOomA65PiJU8eKjhtAwL273PAmvFhJihKWgGRZE0ypbNpSHXECywaAYroK5y9cRgtAnVp3
fIee+ORwKiG37NSMpSurI6yppoI0eO1YUcnZsxe+fPmiQRxJvgq+BNjOnDkvydKRQklIArryX1oVQW1tHa6YvXX7jlZzESdx0D/qcvPmbXGyEycXXVkdYU2B9VtRUXno
8JFnz19cu37z8uWreh1u37776NETVEdgGZHkDE4CuvJfWhXk4ydPS0pOAst6jWK68PfuPbh56/bZcxe0KjGRE9eV1RHWVKDoTg+oVGEcHz5U4Erq/IJjKgJ4iP2rRo+I
qPp91Vlz+BXVERkMJDu9k4Cu/FengvrK43Kru+X3DxzMFRDLOPlLBfA7QpsDWlVEyT1SWHrqbKcSU/ECH2HyyVdZXF1ZHWFNBRrBRIiaC9M7Rn7//gOuUz+SV6gs+Pj6
DxowMD4hiX4BZ8kOHjAQX9KPuMB20cJF27ZtZx7nz5tvY2PLpIaf8A1eo7+RS01Fvpx/QnW0YfEkTUOSgK78V6cybMjKrpq7oD4u/ktnm0w6JnXnTnlG5kEVwFENRjlo
A/IAvvrQ5gxYZREP5+SdOHGqU4l1fOFzeXldYHDlsFEQJofo2ouiK6sjrKmYNRl9qNgErdAa3r17jxPyDufkKwxBQaF0ymBK9OHS0rKGDBpMfxMZGYMoixcuph/37fPG
42ZTM/rRyckZj87OrvTjvLnz8CiXmrJMme+jExJDoqMQktLSO32ZeQHV0Z7dk5QNQwK68l+dSg+OvuI/fqBD9XqTxoJC9TtMt27dSUnNVIYU1WBkQzshIRmJAPLqQ7tT
eNJA1gjL2QdyiopPdCox5gUICq0NtDkYARLWpIVDWLMT1mTcgZor19++fRcTm4hBVIWhqOg4bjvBHSa5OUeO5BUUFBYdOHAQj5ERkfgJUYqKSvCIi1CwpAiPpSdP4f4T
XJuAD3jEZfG4SAHXnhTLfpVLTVmm+D4qIX6c8bS/zf7ub+t/p8Lk/5xluhBfqojC/ITqqI808mbXlIBesCbj/Wvd3JtOnf6rvl61sm7cuJWYlKoMI6rByIY2PneE9tGj
RTS0L1y41BHaKoDpExo4cOnIvy3qzmB5nZ1pRtaBTrGclX3o6NHiTu0TYkHbAi0MRlyENeWERlhTXdZk/ILqXdJv3r7FnQNo1ikLhUeLy+/dR1uSfgGPT548xX/6Ed8/
fPgI+z2Y6IAuAvOIn9iPcqkpzDQiNvb7Ob0GeM0puH+y/P0jhMyb+QM8ZuFL/KSiqPRPqE6nSCMvdHEJ6BdrMjSAgcdPyk88uHbtBpqMKgCiGow8oa0wX1fffWj7GqfY
nnpyicZyzKXMv5n1Hrtmamp6lmosp6VnYxmtCkNFSwLtiY5kSVhTP1iTDUJpflY28fnmzVsclIzRV+mE/kuG9/Gd+rDiamX9QybcfHv+/+08aIbJ/E7LieqwjUaa6lBR
qi7OZ+JUnzNrqvDRov2EGTuFE59lV6/hnstOASLaC7EJSRglmpK++lXNHTaWM++m/R/mf2x22Ka6JBhtzs3NVzFtKZrAVWSkkblytjqNcun4skT7mnrkmumJT+aqBOyL
8g8ISc84gGYdtm3gPz6zQ2RU7PJlKxIxtSj7Hh8wUIP7fZjH2bPmuLvvY6KYmZkjMI/4aZvFduYREZcuWcakJpcXHj39ff5x6Q9bT5iUvzkoF9YWr/lvc78NiYzsGKu0
9AyWqqPpip9QHcKaPGFm8NE5+y8peGqmDJjDw+Ako6wrV67SwGTDgQ0WOTDKQRtxx48dxxnaHVG5fbddN7teYWV7OmK5d+rY72f/0TEKvsFI8tWr12lXc+hwLlM7jMTK
TVtKQRcaIYWz1WmUC2FNaimNgKFjj/PVq9de3v6HDh3B9dT4jP/4jGWodAiPiB4yaBAKMGf2nPiEFIRFCxbiEYvrQkIi8AK+p4vn5e2HRysrG/oRH/DotteTfty+zRKP
iIKITGpMLuwPFk42I117Wx6fceahKzucuO9sVjzpjy0/797nJhexuPgESo5QXn4fP6E6hDV5wszgo3P2X1Lw1HQZOi61vXTpCm4LkYMDAxY5MHaE9uSJk2hoR0XFaQpt
hVietmHejLBBHmeXyWH50C2bdcfGohvqExwoFxGjxDSWL168DG+TfaDdLjJmcax0tKARUjhbnUa5ENYUjDKVzW6+fPXKw9MrIiLm8OEcGCv+43NySgYd8vIKMP8PZWP5
D1p/aelZbq5ueMQaH0zmU+8kJeMRvc+8vEI8ZmZmY3EQQvaBg3jMyTmCn/CIjioeEYVODSuMkBqTC/vD1l3WS/167T01IuDc+OSymalXZyPgg+/ZsfhyxLYetnsc5SJ6
enpduVKGwvv6+OInVIewJk+YGXx0zv5LCv5a2ezmxYuX/PyDgoPD2HBgwAIwYl0eA0YV0MYyHE2hrRDLUzfM3RjTD7ANvTCJBjJCwpUZnqdH4Uuwplegv1zEwMDgx4+f
IOzZ44o52oxMxVtHOp3RFE1NGiGFs9VplItesibPGnKIrux2ISip05W0L1++3OPqjsEQp9173N3d8R+f2QEDJkDj4cN59Jf4gEd8yTzeuHETIyr0I2gVDd7z5y8yKeAz
vsH39DdyqcnlhUdHd5dRpkbJlwcqDP1Wf7vP369jLFwR6uS0OyAwBD+hOhxkqNsouoKTbmutw9w5C5ztjrVRfvbOEznXX2Njp3ol7fnzFzDkAwi4e+xn4MAGi2ow8oR2
R1RusDXb6POLQiCHn+gH1oyOS+gYy8XFFUNT0TEJUdHo8maoELKK1bO06LS084SzDXC2Op6WpgfzmjxryCF6R9ZUf9fmixcvwZT06GtIaAT9QS6kpGawv5F7zMw8qOJX
/KQ6ulxekTFx3836PenYz6V3frt475cbD7sj4AMeg7J69Fk0TGEJ2YVHdTjIULdRdAUn3dZah7lzFjhnj6lmZTuyJj15qc6uzbPnzmOghQYIRlk5YJkntOVy9PTz+Xnh
/y669ivAW/bgJxrLZ8t74nFH0A/zTJcqwzJdeCyGT05Wa+91x52ahDXZ9kZYUwH6GNakpy3Ly8vVhChee/78hb3Drrj4ZGUhMjJ2xw575lc8bthggv/MN+bmFr5+Qcwj
NlMjMI/4CS+wo7NTU5jpTrfdfyz6z7OX/17z7h+bq/+G8P71Pxef+Q986bzPXUVR6Z9QHfWrL5E3OTtxiZRf74rBWeCisaayhbIqRH3mzFlMXqoASFBQmJtbG4KAzW3b
LDlDG6mxoa0w32UWxgu3/WfZzb83Vvw3APlr1f/n7at/icv6j+9m/RYUFq4ay2HhUeiKamRa2JZDnwpEWJOwZieWA9bEtCW3a3FwpY6N7Q6MhygMMNyF8xfAxWzdaoEX
8Dhr5iw84j8+45uNGzdRKwj6D/D29sejk5ML7Y/wAY/4Ej9RA8UbN9HR2akpyxTf2+3Z9e2s35z2/2tyxj8jrLL6d+rRw1VFFOYnVEcjpEnhZc5OXAqF18cycBa4CKyp
elOmCmmfOnXa2UUpRvwDgocMpFb27d3rycYmN2gzqdHQVhGMrUwwGOsd8r8A5PC4f5m28e+9Fw7d70+5C9UhKDgcbXMO1oWRW3rik4zQ0tIjfU0OVqQqyrNnzywtraOi
4xWGlJR0rCAA0rCKh24YYnUPvfwnJoaKYmNN3Z+OJQaxsZiHiA8Pi6D9UUxMHB7DQsPxEx69vXzwKJeaskzp70PCIy0cbTbZbUWwdXHEo+r3mV9RHYFlpP3kODtx7RfN
MHPgLHBtsyYfcZeWntrl5KwMJoCkCjCyoR0bl9gptOVSU41N/+AQGsgIu9xd1QRyYFBoTEwsH4FoKS5nG+BsdTwrQliTpwDloz999sx86zZMISgLZ86cS01JLTxaRL+A
D4cPHcaX9CNuRSjILygpOcE8njxxEuiNjU3EN/iPz3gBr9EvyKWmIl/OP6E6AstI+8npCk7ar5lEc+AscM4eUwRBnDh5cqe9ozLgdApGhdBmI101tDkDVllEDCBHRkaJ
IDdNs+BsA5ytTtMSyr1PWJOnADuw5tOnm0zNwsKjVQSsgGX/KveIoy/Zv+IxJhaDsS0J4rPcC3LRVWfN4VdUR2AZaT85XcFJ+zWTaA6cBc7ZY4ogiOPHT9jY7lQBmU7B
yBPaHNCqIoqPb0BYWLtzvkSQoTpZcLYBzlanTqlUvENYk6cA5aPjUFms7sEpdIYRMKqD6ggsI+0npys4ab9mEs2Bs8A5e0wRBFFSctzSysYwgIxaYD1wSEioCHLTNAvO
NsDZ6jQtIelr8pRYJ9EbGxvXrFmLJirm3vU94Cw9M7OtDg6O2hWZFlLXFZy0UBX9SJKzwDl7TBHk8uTJE2AZ+5X1HcgoPzaerl+/kcxrCmI2pK8piBjbEvn8+XNeXv7y
5StNTEw3m5nrdVi3bgMqgpWEHz9+bGxs+vr1q8DC0lpynJ241kpk4AlzFriUWfPTp88JCYmAgF6jmC786tXG8EgPHjzE6bNNTZ/++usv6VgkZxvgbHU8605Yk6cAqehg
yoaGhpqa2g8fKt68effy5Suc+4wNxUlJKYmJyQkJSQjYZhwbGx8TGx8dHRsVFRMZGR0RERUeHomZhtDQ8JDQsODgUNwyHRgUHBAQ7B8Q5OcX6OsX4Osb4O3j7+3th+Dl
5bvfy2ffflnY543gKQv0Z3yJX/GOl7cv/b6Prz+i+/kF4FQwJBgQGBwUFBIUHBocEoYcQ8MiwsIjwyOiIiKjsZo2KjoWBUMJY+MS4uMT6DKj8Lgs6cmTZ8+f46DAN+/e
faisrKqrq5M+g+oKTgIYk34mwVngnD2mluQEpkQbsbq65v37D69fv8WhJViaByAj0KCIj0+ksRwdE6cOloE+GsvAI41lILQNy634bQNyRyz7+FNYBpBlWIZ/gJdQhmX4
FpQKZWvFciJdbJzNeffuvadPn6NGqBdqV1VVjZpKgUE52wBnq+NpPIQ1eQqwGa02WB64BFYIXgG7wC7BNLjw5OHDx/fvP7x3/yHs9fadclwNj6sxr12/WXb1+pWya5cu
l124ePnc+Ytnz13ARX2lp86eLD19/MSp4pKTuHL9WNFxnLycX3AM4UheYe6RAly9eehwHs6ePXgo98BBKtDX6dGf8SV+wjs5uQV4GXetICKuwz16rKSo+DgSLDleeuLk
qdJTZ06dPnvm7Hnke/7CpYuXrly+crWs7NrVazeuX7954+bt27fv3rl7D+e2o+QPHjxCFR4/xrrgF2gKoEGAZgEaB2gifPnyha/gtBlfV3DSZp0knTZngXP2mNoQB0ZT
0CKsra1D6/Dt2/c4ihntRRrLwAKF5XsPKCzfvnuTwXLZNSAIh1wqx/JxYJDGMlAJLAOhclhm7sWkgSzDch6NZbwvh2X4B3gJ+Aoay/AewDJyRxkYLMPPoIQ0llFmGsuo
BY1l1Au1q6ioRE0bGhp1PobE2QY4Wx1P4yGsyVOA7aKDSzCvCVsEu8ihjmbQNuDRJHrzNrgKjMXwKEwfTAY+AxIQQG8gVGADnCoLZ4AWOoAC6cB8g19l4SzeRyzEpRFF
gwrJgqdpXCE7kDcDLTA6fIEcuuhmKd3FRI3q6xs+f/4iqYEdFZrTFZyENCa9SouzwDl7TK2KB3YOaweW2QNI4Jt2DHr/IRqXoKUWEmWwXHaNbhPTVEpjGUgUBMtITQ7L
8B5sLNNNXrTU5ZgSrV50MeGX6uo+0q1e6WCZsw1wtjqexkNYk6cA1Yr+5ctXjOKiSyobyK2prKxGQw+DJOi9gZzQAEQzkO6b0k1auocKGgMAEEBpAAOFzzvlLeH2XWC1
LbR+T7+G9xEo8Nx7QOOHDnTfkW5yAv/gdfwBSGhZV1dTPcgmFPHTJ5RWOohSS74dXtIVnLiV1gBicRY4Z4+pE6EBF+AbGssfP9bTWP7wgcIy2pcMlmkgaw/LdOIMltEh
bsVyJbBM9yCBZZQT/UjpY5mzDXC2Op7GQ1iTpwC1Hh1Gz/4DCmSh4x/1vdyf1gsn1Qx0BSepykPr5eIscM4eU+tV0kIG6gGZYrouhWXONsDZ6njqlrAmTwGS6FKUgK7g
JEVZiFImzgLn7DFFqRbJRAwJcLYBzlbHs1aENXkKkESXogR0BScpykKUMnEWOGePKUq1SCZiSICzDXC2Op61IqzJU4AkuhQloCs4SVEWopSJs8A5e0xRqkUyEUMCnG2A
s9XxrBVhTZ4CJNGlKAFdwUmKshClTJwFztljilItkokYEuBsA5ytjmetCGvyFCCJLkUJ6ApOUpSFKGXiLHDOHlOUapFMxJAAZxvgbHU8a0VYk6cASXQpSkBXcJKiLEQp
E2eBc/aYolSLZCKGBDjbAGer41krwpo8BUiiS1ECuoKTFGUhSpk4C5yzxxSlWiQTMSTA2QY4Wx3PWhHW5ClAEl2KEtAVnKQoC1HKxFngnD2mKNUimYghAc42wNnqeNaK
sCZPAZLoUpSAruAkRVmIUibOAufsMUWpFslEDAlwtgHOVsezVoQ1eQqQRJeiBHQFJynKQpQycRY4Z48pSrVIJmJIgLMNcLY6nrUirMlTgCS6FCWgKzhJURailImzwDl7
TFGqRTIRQwKcbYCz1fGsFWFNngIk0aUoAV3BSYqyEKVMnAXO2WOKUi2SiRgS4GwDnK2OZ60Ia/IUIIkuRQnoCk5SlIUoZeIscM4eU5RqkUzEkABnG+BsdTxrRViTpwBJ
dClKQFdwkqIsRCkTZ4Fz9piiVItkIoYEONsAZ6vjWSvCmjwFSKJLUQK6gpMUZSFKmTgLnLPHFKVaJBMxJMDZBjhbHc9aEdbkKUASXYoS0BWcpCgLUcrEWeCcPaYo1SKZ
iCEBzjbA2ep41oqwJk8BkuhSlICu4CRFWYhSJs4C5+wxRakWyUQMCXC2Ac5Wx7NWhDV5CpBEl6IEdAUnKcpClDJxFjhnjylKtUgmYkiAsw1wtjqetSKsyVOAJLoUJaAr
OElRFqKUibPAOXtMUapFMhFDApxtgLPV8awVYU2eAiTRpSgBXcFJirIQpUycBc7ZY4pSLZKJGBLgbAOcrY5nrQhr8hQgiS5FCegKTlKUhShl4ixwzh5TlGqRTMSQAGcb
4Gx1PGtFWJOnAEl0KUpAV3CSoixEKRNngXP2mKJUi2QihgQ42wBnq+NZK8KaPAVIoktRArqCkxRlIUqZOAucs8cUpVokEzEkwNkGOFsdz1oR1uQpQBJdihLQFZykKAtR
ysRZ4Jw9pijVIpmIIQHONsDZ6njWirAmTwGS6FKUgK7gJEVZiFImzgLn7DFFqRbJRAwJcLYBzlbHs1aENXkKkESXogR0BScpykKUMnEWOGePKUq1SCZiSICzDXC2Op61
IqzJU4AkuhQloCs4SVEWopSJs8A5e0xRqkUyEUMCnG2As9XxrBVhTZ4CJNGlKAFdwUmKshClTJwFztljilItkokYEuBsA5ytjmetCGvyFCCJLkUJ6ApOUpSFKGXiLHDO
HlOUapFMxJAAZxvgbHU8a0VYk6cASXQpSkBXcJKiLEQpE2eBc/aYolSLZCKGBDjbAGer41krwpo8BUiiS1ECuoKTFGUhSpk4C5yzxxSlWiQTMSTA2QY4Wx3PWhHW5ClA
El2KEtAVnKQoC1HKxFngnD2mKNUimYghAc42wNnqeNaKsCZPAZLoUpSAruAkRVmIUibOAufsMUWpFslEDAlwtgHOVsezVoQ1eQqQRJeiBHQFJynKQpQycRY4Z48pSrVI
JmJIgLMNcLY6nrUirMlTgCS6FCWgKzhJURailImzwDl7TFGqRTIRQwKcbYCz1fGsFWFNngIk0aUiATtbWyaw4cT+XiplNYhycBP45/LyGhs7JrA9JvNlfVy8QUiIVEKp
BGrd3FXbAH79+uGDXPznz593anVBgUHaljthTW1LmKQvkgTc9+5lk2XHz3hBpKJ0jWw6FTgcXEdJ/FVfz2ZKhZ+bTp3uGiLsurWsCwxWbQZVcxcolM7I4cNVwzw+Lk7b
YiWsqW0Jk/RFksDp06dVwwkviFSUrpENZ4Gjn6HaY4JZu4YIu24tvzx/rtoGGrKyFUoHpKga5uiPalushDW1LWGSvkgSqK+vV9EOxU94QaSidI1sVAscrk2ZwD+Vlanw
mODUriG/rl5L9CZVmEHH4VlaXiBFFay5ccMGEcRKWFMEIZMsRJIApjSUIUqE2Q6RKimlbDgLvHLYKGUeE5wqpSqSsmhLAuhNKrOB6vUmKnJdMG+eMpgXFhZqq7isdAlr
iiBkkoVIEigrK1MGJ/wkUiG6UjacBa5sWgts2pXk16Xrit6kMtZUPbENalQG8w8dFhBpQ8SENbUhVZKmziSgsB2KL3VWIEPPWKHAMR6uut7KprXApoYuMFK/NgmgT6mQ
OFVPbIMaFbKmaMv9CGsSIzYoCShcLCDCsjqDEqImleEscIXTWmBTTTIn7+q3BNCn7Mia6kxsY3l2R+IUbbkfYU39NjtSejkJKFwsIMKyui6rCM4C7zitpWyzQZeVrcFX
XOE2JHUmtjuu3xZzuR9hTYO3zC5XQayjY7dDxVlW1+WkzKqwnMDVHA/vOK2lbLNBV5atwdddbhuSmhPbWJ4t19cUc7kfYU2DN8suV0G5xQLiLKvrclJmVZizwOWmtZRt
NujKsjX4usttQ1J/Yltu/baYy/0Iaxq8WXa5CsotFhBnWV2XkzKrwpwFzp7WUr3ZoCuL1+Drzt6GpP7ENnv9tprDG0JJkrCmUJIk6UhIAsxhb6Itq5NQ5XVRFEbgCk/R
U1Yi9rQWOUVPF3qTRJ7MNiRNJ7aZU01EXu5HWFMSdkMKIawEmMUCoi2rE7b8epcaZ4Ez01rkFD29U7pQBWa2IWk6sc2s3xZ5uZ9EWVMofZB0uqYE6MPexFxW1zXlzNSa
OV1P02ML6WktdTYbdHEJG3b16W1Imk5s0+u3xV/uR1jTsK2x69YOiwXEXFbXdQXdWnPOAse0ljqbDYiEDVgC6GVym9jGjKb4y/0IaxqwKXbpqmGxgJjL6rq0rGWV5yxw
cpsmMR70MrlNbIMyxV/uR1iTWCyRAJEAkQCRAJGAuhLQGWtiSBqN0+SkpISEhG0WFmabN5tuMsWfxdatXl5eSUlJ+fn55eXlmk6TqFtv8p5UJfC5vBzjdfWJCfVxMTXm
W2s2mdSYbKDCVouPIcH1yUn4VdP5D6nW1XDKBZwCrVgTlJiQEBYats1i22ZT082mm7eYbdm+bTvgnJ6WRuBsOPpWrybAMnqQCrFcnxDXkJqqp1gWjzWBK9BkcHDwksVL
BvYfsHTJsu3breztd0VERkdFx8bExMfGJcbFJyYkJiclp/r4+Lm7e6xZvWbq5Ckzp8/w9vYmo23qGar+vYXFk4DWx8CA6oULKvv0r144u9Z8dZ3Nxnpfh4aQPQ3hbo2R
Ho1R+xpjvBrjfD66WNdabKyaML5qytS6/fsBS/2rsKGUGA3fnMM59jvtp0yeMmH8BCDa0XG3u7tnbGwCgByfAK5MSU5JS0lNDwuP8PTcZ75l65CBg1avWnXkyBHxR9UM
ReqSrgc10HriRJ3HXgrLvfu1YNnWpCHEuSHUtR2Wwz2A5ZoNK6smTKyaOr0+Ilz9nZo6F4HWWRNkeeLECVsb2wH9+i9butxlz97omITMrENZ2YcPHMw9dDgvJ7fgSF5h
fsGxwqPFx4qOFxWfKDleerL0dOmps6fPnDt77sLRY8VRUTFbzS2GDh7s4+0j8iJjnWvIUAsAkKDvWL1gfuWokTUr59Q5mjaEOzUm72tK9WpK92nK9G/KCvx0MOTTobBP
uZGf82I+F8R9Ppr4uSj5S0nalxMZn47EN/i6VM+fUzVtetPJk4YqJQnWC+3XvXvdJ0+cNGP6DHPzbV7efqlpWYcOHzmck597pCAv/2hBYdHRYyVFxceLS06eOHmq9NSZ
U6fPnjl7/tz5ixcuXs47kr/HxXXIoMG7HHeh9ynBCpIiaSoBNF6BZfBf5YjhNRsXf9yzVR7L2UEUlg+Hs7H8pTiFwvLJTBrLVePHV69YoRdY1iJrgt7cXN3GjR23atWa
Pa7uCYmpScnpySkZwFh6xgGNiPP8hUsXL10BiYaEhKFhixFdgjdNLVsi71NkGRxUNW5c1YQxtRYr6vdta4xyaoxxbozd0xi/tzHJQ33i/HIq++uZQ03p4TWrl1VNm0H6
nVpVMdq+Nta2A/r2W75shdPuPTGxiSmpmWnp2RmZB4Hl7AM56hPnpUtXLl+5Ghsbj5EkZ2dn0u/UquK0lzjGV+tcnCt7969eMA1YbvC1bozaTWE5zlUBllUSJxvL1StW
SrzfqRXWvHXr1ob1GyZPmmxnZx8SGonOJTAWF5/MnzgvXS67UnYtLi4BeMN8CcGb9iAhbMoYuqmPi60cM7Zq3Mha04X17mYNQTYNoTsawuwbIxx5EufXczlNmZFVEybU
R0aQzfLCKg7NU1dX1/Hjxq9YsWq3syuwHBuXFJ+QkpiUhkYwT+Isu3rd19cPY0hgUWGLTVLTngSAZTR8geXqOZNrLZbVe1u0xzIv4gSWGyK9K/sPakhL014VeKYsMGuC
xtauMZ4xfSZao+DL0LCo8IiYyKg4wYnz6rUbwBvGedLT03mKgETXqgRAYzXWVpVDBtesm1O3e329l3m9j0W93/YGf0thifNL6cFas3XVq1YT4hREoY8ePpo0YeLCBYus
re38A0LCwqMjImOjouMFJ05MwaARHB0VJUixSSLakwD4snr9usrRw+WxHGAlLHECyzVrVtRYWEgTy0KyJoZkR40YaWOzw88/OCAwNCg4XNvEWVp6esP6jViwR5baag8q
fFKG0VdNm1q9ekad28aPe00+eph+3GemPeL8eiGvfp9T5cAhEh/h4SNSceJevHChzx+9dju7gS8Dg8KCQyKAZe0RJ+Y7lyxa7OfrJ07tSC4cJABMVY4cVbN+tmIsC02c
wHKdjbk0G8GCsSZ4a+zoMY6Ozt4+Ab5+QaIR5/XrN/38AoYNHkJWCXFAgrajVK9bW712Zt1u4zqXdaIRZ0OUrwrixPQnHaTZjNW2RtRJHyNGI0eM3LXLxcc3EFgWjTix
PkgZcdI7W+g/dapA3hFWAlTzd+aMapO5dc5rlWJZdOLUFZYFY809Li7r15t47vPe7+UnPnFmZmYPHTRY7p5Sucd1xmutLC2traxiY2IzMzMBPzItKiy05FJrOHCgasro
WoeVtU5rxCdOHGspF6qXLa3ZvKnGzLRmy+aaLWY15ltqtppXzZyN16rXrquxsm7IzMACB8Km69aus7Cw2u/l6+XtLyZxXrt+Ez1OOdiiQWxutsV8i/lWc3Ns5rbYaoGx
pe0W2/DaiGF/WltZBwQEFBQUEDbVKpY/RoRVLxxf67iKwrLoxNkRyzWmJh2xXDnkT7xZY2lVu2dPQ2aW9pYHCsOaMNnp06bvdd/n4emtK+K8cfP2rVt37ty9V15+/979
hw8ePHr06MmTJ8+ePXvx4sXLV6/evHnz7t69+xcwGHTpMraShYdHrF+7bt7cuXGxcQRygkMO3FM5ZEit1aJa+xU6Ic6vlwq+Xjn29Wrx1+snvtw69eX2mS/l57/cv/Tl
UdmXx9e+PLv55cWdr6/uf337+Ov7Z18rXzVdOtt4NK/O26tq9rwaa9umU6e6Jn0eP3589qw5Hp5ewLJOiPPGjVs3b925faf87t179+49uH//IYD8+PHTp08xnAQgv379
+u3bt+/fv/9QWVn1+PGTsrKrKSkpLi4u8+bOCwwIIBu7BccypjMrBw6stVtKYVkXxPn1UiGF5WslbVi+d6EFy0+uU1h+eZfB8pdXjz5dPtdwMLPOxxtYrnV1A5aFlYkw
rImdyxbbLN32ekqfON+9Qw+zoqqquqamtra2rqKi4vz58/7+/vPnziO3SgloWx/Dw6rnjK61XdICNl30ODUlzq9Vb/6q/fDXx6ovr541pKdVr9uIQ6W7GndOGD/e3sEJ
WNYX4qyuBpLrPn782NDQiA2hAcDyPIJlAaHcXLtzR/WyiW1YljxxohH8V/U7Csv1NZ8flNdHR1fNWSAglgVgTbQAp06Z6rLHDScY6CNxYsoEeHvz+k1MTAzwRvqd/AFH
dTQHDa41n1trtVBPifOvxrrmT43Yc407jLrO2iIsAlowfwGw7OrmoafE2dT06e2bN+h04gIpskiQP5apjuaAAbWWC9phWa+IE1j+q7qqISNDKCwLwJqODo5btmzFVhN9
J85Pnz4/fvwYYCOdTp5ga8jOrpoxvNZiXu32+fpOnH/V1tTY2HUR4ly9cpWt7Q5nF1d9J87Pnz+XlpYS4uQJZESnxjkXjqWwrOfEiUbwlyePBSFOvqyJ4c7Jk6Y4ODrt
cnI2DOIE3oICA3FLOH+D67IpVE2aVGMyo8Z8NiFOPbKBmzdvzp0zz3HXbqfdLoQ49Uhx2isqNWg0elSN2awa8zmEOBk582VNfz//des22DvsMjziJD1ObmhsLC2tmjC4
xnS6DGyEOLlJUQexdtjZrV+/EVgmxKkD6Usyy4a0lKopQ1uxTIizRUl8WXPRwoW2djt37HQwMOKsqanB8A7ZA8oBy3XurlWzhteYTCPEyUF6OoyCvRx2O3CFiSMhTh1q
QVJZVy9ZUr1oNAvLhDgp/QjAmtY2dgZJnJjjtLWxkZQR60Vh6va6Vi/AGSKTDZI4q9ebGOqq2j+HDrOx3WGoxBkUGKQX8JFUISnWXDGuPZYNhzixXoGbtPmyJvqY69Zv
NFTizMjIIEtqNTWspkuXqkb3r1k70SCJE6tqGwsKNZWJXrxva2sLLBsqcaIFTE410dQOGzLTq6YMqVk3ySCJs84/gNv99nxZE4Y4cfxEK2tbgyRObAUj3U1NkYb3qyZO
rFk5zlCJE2cgcJCJ9KO8evVq5oxZwLJBEuelS5dwhJD0tSC1ElaOHFmzZoJBEuenixe4tYD5siZ0vH/fftygaajE6ebqSnZ9aYrkhoL8qkkjKLAZYo+zzs+fWxNVUzGK
//76dfjbYKjEaWNNJlw0tqmPoSFVkwYZJHF+rXxfHxursUT4z2siS5AKLnbfunWbQRJnTk4uGaTlYFjVSxZXL5C1Ug2OOJvOn/10pYyDTKQfBUNHM2fMtLSyMUjidN3j
Kn0VSLCEVQvmVy8ZbZDEWcOpISVAXxNqPnXq1OzZc6ij0Q1uqPb6tevYLi1BU5Z4kagjRYYPpcZpDY44P1293JCZKXH5cy4eLqxdunSZQRJnamoaWRXPwTA+Xb9ROWZo
zSoZlg1rjrPO35+DQIRhTWS8cP4CHEVreMSJs6FxQQoHyZIotXa21YtGGiRx4nYUA9bvsqXLtm23MjzixCHvZNyIm91WrzWuXjrK8IjzI6e70AVjTV9fX8yIGCRxZmYY
sovkhiJ1YlGzmzOHVq8YY3jEiTMt1ZGAnr5jsnHjVovthkecyUnJhDW52eTHkJCqWcMoLBtWjxPXinEQiDCsSU1tTpq8hbr/DpffGVqPk7AmB8NClGpj4+q5f6KJamDE
2XTxdH26wbImpjanTZ1GYdngiDMxMYms7OOG5crxE6oXjKheNtrAiLM+NYWDQIRhTSxOwzJaMzPzLSYLh3/7Tdu9sj1Hzly2yUpbJwcluszv1WPB3tTDeTm5BUfyCvML
jhUeLT5WdLyo+ETJ8dKTpadLT509febc2XMXzl+4dPHSlUuXzx/cPc2o27Q9OVfUuY8T14rhPk7s2uQg2S4epenixco/e1cvGF69eFhOXyPWVcM/Wo4demXdVG2dHBS5
0eb7njaOLk3pPk2Z/k1ZgZ8Ohnw6FPYpN/JzXszngrjPRxM/FyV/KUn7ciLjS4GL3Y9t5tpz9ubCQzmd3sfZeLzg8507hqpfYHn1amOzLVspLH/XHsvLTa21dXLQwaQ9
S3r8sNQt7UjukYK8/KMFhUVHj5UUFR8vLjl54uSp0lNnTp0+e+bs+XPncRvY5UuXrly+cuGgswzLuWVq3se5e/duQ9WaVutVn55eNba/DMsjq5cNz+nXHs7j/7yyfpq2
zqqNMqHg7LSHwnJ2EIXlw+FsLH8pTqGwfDLzy6nsr0dd28F5jllhTl7L3bqK7uNsOlvScCSXg+gEYM0bN27MmDHTxMR0k6mZ2Yb5f7JZsxtQ133IfDM7rRBnvDNYc75b
8sHcQ+oSZ3GYcX8UaYzz4avXb6pDnOfOXbhjuC6Sg8WoGaVq5syqGUOq5g6rXjA0p893LNakHHHPPoPubtTOkXthG2y+/8XGYXdTqlfnxJm325bFmlQhf1xRdPqYauL8
GOhrqMcDYcsmBo02bdpsunmL2cYFCrC8YMsOrRDngQTnxT1+WOKWmnM4J1894mzB8liXnGvqXWTt4+2jpvWS19gSqBw/rmr20Op5f7Y0gtuxpgzOfYfc3USfOy30yUFy
jWDVxNm+ESyD88qisyXKiLMhJfbLs6ccdC0Aa25Yv8HYeN2GjZso4lw/b9i33/wwdOEmaqh2u/naeSN7Ghl9N2rZ9h2SOKu2JNT4x57Dh/X/eW3k6Ws3rqtBnDExsWTd
naaG1XjyZOXw3lUzBwNsVXMH5/T+zujbX3IWyoZql/6ZNOAHo25GljPH6f7IvdxdYM2eK10qzxz6ei7ttuO0nt1624Vnfb1arII4ax0dNBWIvryPYdnVq9YAyxRxbmjF
MjVUa2m+jsby6OWWOyVxVu3xsFYsR50BkDsjzrIrV9GN1RdFSKec6GgyWJYRp6wRDDgvls1xrhiRNPBHCs6zJ+r+kPd8qhHcc5Vr5bmcrxcyb++a0bNbH7vIg21Ybt/j
rPPYw03OfFkTHc1ZM2etXbsetyVQxLl2zlCKNeebtMxxbjdfOfG3bj+NXLqVOqt2x7Z1c8b8QXVAewyZusbCEdf47XW1XNy3W8+JqzctHvazUbe+k9c6eOyxWjD8F7QU
uo9Yu9svIjQsKjwiJsLbcfnonkbdfhgwx3TjzD96zHGKSoneNbdXj3l7ErIyg7aMNRqy2W3PqsFU4n8u90zNVzBUe+ZY0NqfflwXHLdrzI/rw0+VXVWDOPd57ucm2a4c
q2rBgsrJ/aumDZQR56DDvb4z+ubnnPkjW+Y4lw5x6/Ftz4FDXsjOqq1aMypsaHeqYfjdr24Lp7ymLrJeVDajp9F3/ZONR63EIOFvg5ItVjwwHUN97vbjysXL3nmZ1/tY
1PualM7v3xMRe49JXj28p9GYgqBdjSHGVF9zh0NjolX4oB+nmWzMW9CXSnzArKMxgfJDtYcdbH/4pufy3RUY3jmTctthas9u46KyD3+9ckwZcTZdKG7IOWSQysWM5ozp
M9au27BhgwlFnOvmylrACygs08S5chKwPGqZBXVW7c7tDJaHTjMGlnGRNbDcT4blpRSW+01Z6wgsL6SxPJLCclh4dERkbKQPg+XNJjIsR6dmxDot6vH9YufEg1nBFsO6
jTV3272Ucsc/Dlm2L62w41Dt2aJgBssbIk5fvdYZcQYGBJIT9TjYbeXYsZVTGCyjxzmktRHcOse5YpjbT9/2HDT0BXVhw9R7i4dY/vwt1QHtN+jwurnUpfS2M0N+/67n
6PHFc3r37PbdhLGTr+5acXJWHwq5Rv3CbE0oLPttb/A3LV04gPqyz9iUNSN6fj+uIGR3Y+g6Cs72uxqTbCg4b9qUt6CfDM6zj8YFyw/VKmgEj486cOTrtRKFxPkxNJiD
QBCFL2ti/c/y5SvXrFnbQpzGMtYcMm8j5jhp4ty8eMR3Rn9M32BlY71xhqzCreHHMWvt97g5b1vYt9uPvX8HI9I/9ezTS+ZDqfD9gJUuwaGRof4Oi/ugg9IWt/vsXZHJ
UY5z/ugx1zkuIz3QbIxR34GDfmh94YflntmFHeY4T6TaT/5pVUjxucxdI4cYh5VcKbvWKXGGh4Vzk2yXjfX5wf3KkYMrJ/ZtJc4Bh/8Aa/6UM0c2L0ItDhqR29/I6Oe+
V4wn1qwbFfwLhbHW8IPlopm1VvNlrNl9/C+tQ7s9f5rQNsf2R6jtpnovk9Nzfm838AvWDHBoDFpt8/3PNnY7GuO2hw/8cUy/3ygcykLP+Vvfy81xHrQHa7ISGWrnEVpz
Ie/rpQJlxFnn62mow7O4Vn7JkmUYN2ohTgbLmOOkidNsCY1lHLpnMrM9lseuA5b3bF9EYfkPJVhetQdYDgtwlMNyDwrLadGOC3t8v2h3woGMwK3DuvUaPBC8S6umz9J9
2R3mOE+kAcurQ0rOZzmNHLI2/HjZVeysVtXj9Nrv1WUhybnijSdOVg76jcJyG3EOoliTbgS3LA4alTsAcO53Zd3kqqUDprK8tNF3fXPNF9TazAj57buev/YY3fLTd6N/
68Gg0qj3pOv70Qg2PT23A5yDnOQawWP6/94G5wXb3svNceY4ysPZM6LmUiGF5Q7E2Zib1nTxPDfJ8GJNtN3GjR23cuVqLAVqIc7Vs4aANQfPWYc5Tpo4N1FrCn4YvsR8
67KR3xn9Pmq5+Q4c+W5rOnvoj9+NW7PDxXnbgj7djHrNMN/tvs/d3nik0Tc/Dlth5+Hv67tn/chfuk/Z7hUc5rN9VvduA2ZZ+URExYbsNRn7/TfdZzmEJ0Y4gDXn7I5J
S/XfPMao29BFLrHZBw/G7JzTo1vvJR4Z8ouDTiTvHDFoVWDB2XNHg1cPHr0r+8LlMtXEmZdXcPHiRW6S7bKxarZaVA7vVTmuTytx9qNZ8/BMzHHSxPkntaDg219zl49/
MR2s9qPN7AlVuI9z4/jgvkY9h415uX1u2TR0UH52W7Og1n5Z+SI0S39YOXfeG5d1NXZT137X3Wqj8cc986yNvpswecEj3+0N+9eEjehuZDQ6329nY8AqijVtbRtjLMIH
oi07pSDYvSnFIX3Sz0bfTy1MDGi3OCjbrj3Mvuk5Y9vtkkNflRDn5xun6/Z7Gqpm58yeQ2O5hTjXzJZhee56zHHSxGm6SIblpcDyKBmWt+7EtWK2m+cAy+ON7fcAy31l
WHbx9GrB8p8rd3gGAMsbRv3Sfaqld0h4C5atfSOj41qwPNsxIik10mFBj+8XOsVlpQeYD+3246BFrnEHjxyK2zX9h296LN6fLbc46GQKsLw6sPDc+WMhawaP2ZV98cpV
FcSZmZlNVidwsNvqtWsrR/duwXILcdKN4J9bGsEUccoawYDzqrG5g4yMfuqVu2ZqjdnMVyuHrPzuB8vFs2otp4I1jXoOKbVZXuuwIHnID0bf9QnZuqrObf39lQN6Gg3N
27O53m0+BecpCx/7WzV4rw0bCTjTjeA1skbwTlkjGHCeWhjq2ZS2SwbnaUdTgtstDpJvBH/Tc+b22ydyvyoizo8+3IHMizUjIyPnzJ67bNmKNuJcOZNmzbX04qCWVbXf
/THFeNva6X8wQ7U7HXZuntO7289jV9vuMp/fp9sv49Y6uO313LvXZnHvH/stttvn5eft475l8q9GfVftCgh0WjnMyGjWdr9IDNVGRnqsG/BD95n2YfFhO2fTQ7XJvqaj
jb5fRA3vZB/ODtk2rFvvxXvT5VbVFiXuGMluB43clXUBq2pVESfu3OZgal08SuWECZXD/2gD2+Q+h4GZb3ocno45Tpo4Zatqf+p9ZcWYK6O7G337W+7qSbI5zqlXJv5s
9G3vXNPZZVN/oRqq2xbX2i2tNh05tduvIVtW1u02rrOfYfXdd1MXLqm2nji1W3dr0w2y4Z2tN5b3MTIame9r1+C30sboZywEbYw2Dx9g1HPWhndJHo3Je29uGmz0/ZTC
BL92q2ozbakR2qX2H6hVtUnPwzas+fGH6fbBn6l5EQU9zo8hPl/fvTVI/eIArCmTp2DcqI04V7VgeR29OKhlVa3RH1PXbltHYbllqNbesQXLa+x2W6AF/Mv49buAZQ8P
WwrLS3bu9/b38fVowXJg4O5VfwLLlv5RGKqNivKksDzLPiwhOcJ+fo/vFzjGZKT6bxnardcC58TsAzmHDoZbDP2xx2LPzParakuSdrbHslP2BayqVUqcnh7cXaRBqlud
SmFMpXL48HZYpoizpRGcM4teHNS6qvanPldWjQj+mRmqnV6zeUJwz29ljWCw5rc9R0x4abe01n5p2ezfjP4YfXX32jqXta/WD+nZ7Y9Q6421tpOmduthvdmEGqoN2HZj
JRxE+0Zw7DawZs/ZG98l72tK9bhpCjhPLUySrZBnepyyRnDPZY4V1Kra1OcRJmt+/HG6Q+hnCsvtepyfzubXJ8arIwSF7/BizbXGxosWLcGoThtxLp8+GKw5aNYaenGQ
6eaNi8f+2q3H8AWbtq6ZRrHmEnP6dhS7TbPBmmNW2ThumSdjTXvMcbq5WS8C0hbZeezz3u/ltnkSWHOlg5//rhVgzZnbfWVznOF711KsuTMkNnTHrN9lQ7VJPptGGaGh
Gp+dmXUoMwgjPL0XYTVeu+0oxYe9V/3EZs1ukx0zz8i2oygmTvyUnJTEWbJdM2LThYuVv/9SOeR3Fth6H/4VrNn98FR6cdCw6rn9Xbt/27Nv/+crRl1BoxKt1JX0tWJT
rkz4yejbXrkmM8qmgDX7UMM7tkuqNw6nWHPzslqnNXU7plOsuWBJteV4sKaVybp6ao5zy/VlYM0R+V7WDb7LrY1+srGyaow0o1hz5tp38Xsbk1xvmAwy+n5yYZx3u+0o
6dYUzJbYfaC3oxT5Rg7/oXVxkDxxfjqTV58YZ6hqxSbr+fMXLl26vI04V8yQYXk2sCxbVWu2cck4GZZNLYxbsEzfjrLDlGoBj6FawC1YxhwnsEyx5iK0gH29vPeaybDs
6B+wi2oBU1im5jgj3GUt4J2hcYlhO8Ga8x2i0pJ9zSjW3J0ALGdnh24d8mOPRZ7p7bajFOf4yGF5yq6ss7LtKAqIMyQ4FHflGqritFevhgMHK3v9Ujn0j/bE2dYIbllV
O38ABed+A16s/JNizYFD6fUKNZvGUqw5dPTLrZNDfv225/BxLzHHabe4bNavRn+MKtu1ps7Z+JXxYIo1LdfXyjWCV8g1gm2VNoLZq2pbG8EV9HaU4/6RI35oXRzUjjg/
BnnxmWfhxZo4tH3BgkXtiHPptEFA2sCZq6nFQSbrlk4b+jMWXP0532SrbKjW6LcRi02tcK3Y9g0zBv/43ZiV1o72ZnOpTifGave4ubhsX9j7x74Lbdw9vT33uZhO7GnU
Z4W9b6DHlunduw1cYOcXEhoZ4mk2Dj54hl1wTIjtzN9lQ7UJ3iZgzQW7YjPTM1rmRRbuSW6/HeWA17I+Py3zzaX3cRYErfqx+yiHjLMt+zgVEKe3lzfZE60pJuvcPSr7
/Fo58DcWcfY6/Ou3FGtOki0OmtE/sdf3Rt2+2z5+GOY4n0/uidFXm2mjqnDI+5qRwb0xkDP8hdmMK5N/pljTbF6t1UIZa/YMMV1a67Cy1m4axZrzFtbsmoUPE2YufLvP
rH6/ceqIHynW9Nze4LUUrGm9fXtj+GYZaxq/i93TGO9yYyNYc1JhzP5221FSLG3AmottP1D7OBOqYk3XtC0OwqradsRZ52zPB2maSlLk9xcuWLhw4WJguY04W7G8hloc
ZLJ+2fRhDJapoVpgeQmwbGNruXFmC5YdzOb26fbzOOOdwLKrqxWw3G+RLbC838vVdFJPo74Ulj3NKSwv3OEPLIfu2zIOsy0zdgTHxIfazev+/Xz7yNRE781Duv0x3yku
I/NgZmawOVhzoXtau+0oB70pLPvl0fs4C4NW/9h9tEPGuZZ9nO2IE3u14+MMtq2jVSOpsdhW2V+G5XbE2Vs2dNTSCK6ePSCxtwzOE4e3DNX2+C13GRrBk14tGbji2+8t
502t2TJRxppjXzIL/X4fWeawqtZp9SvjQT27/R6yfd1Hp9lWGKGdtYha6Oe9LpUaoR3ZvhG8RTZ0tE5BI5ghTlYj+EtxcnWc2Zq2FfI0lqke5+eThxqy0vmIjjtrYj/G
2DHj5s1b0I44l0wdKL9f88f+01ZvpuY4t6ye3LvdaqCRKyxZQ7VOu/e4uGyb3wusae3mvs/D08VkAlhz+Q7vAN99NvMoV0uvDvitX58e3afbBkYFUaxJDdXG7d9IsaZj
dHpqWlYaNS/Sa4FL4gH2Ps68GKthP4+wjj/acgDCEf+VfX9aFXSs7QCEdsRZUnz82LFjfCTbNeNWr1lb0btnZV82cf5xuN16H9nCnF//uDtfNryzZEjwT+zVQPQSdmao
dm7t9vnV64ZRrLlxca39ilrrKZZgzbnza1xWlk7/tdUkvhvzx889jYbne2xr8FwsY02LhtBN4f2Nes5Y/S7GuTHW6caGgUbfTyyI8my3jzNlG1iz/V7SofvCYqgDEKhV
tW3E2ZgS9vn6VUPVKVqHI4aPQF+zHXEqxPL0NZupOc4tq6f0aY/llVasoVpnF1dgeYEMy+6eXsCyrAW8fKdPILA8Xw7LM+yCouOCbed2/37ezvDkBG9TsOY8x5i09OyM
jGCzwT/KTjI50raPMz/W+s+fR9jEH2s5ACEvgMJycFHbAQhtxOlF2r5crbZy6nQKy/LEKWsEtxu0+6bnb73uLqIWB1XO6d1uNdC3f+TiAARmqNZyQctCv9+Gl+1cUeu4
8uXqgRRrWqypc1tzagYLzr0A5xH5+ywVNILjXBU0gmniTKUawfJwjohvj+XCj3t38Wz+cmfNoqKiiRMmzZkzrx1xLpzcjjV/Gjx+1rJ1zBznlg3Lpvz5m+zog4Hjl6zf
Zsseqt3l5OzkZAHW7DN/uyvmON13bwRr9l5qtx9znP6eDhunUGD7ZdTK7Zum/dZ9mo1/RID1DLAmhmpjPDeMNKKHd1IyUvxkIzzOiZjjZIgzJ9JqeLfxVjH5rScHncj3
W/PTj8YBR8+wTg5qI87Q0DCuxtal41FI++2X9sT522HZSvTWYLR9YK/LM5g5zpGVcweG9pMtkP72J7dpI1+1G6qdVWsxr9p46NRuv4RsXIQ5zlrryRRrzplfgzlOh4XJ
46jlmj2HTjy+emhPoz/z926t91hkbdTD2mJLQ8jGMLDm9FXvopwaYxxvrBtg9P2Egkj3RmpepPUAhMSt7WA2aFZMcFATc3JQK3F+KT1YH2XI9oAbm4HluXPntyPORVM6
Ynk9M8cJLE8dzmB5w3Y79lCt024XZ2dZC3iBFbAM1qSw3GfZDi/McQYAy1NpLK+SYXm6TUBkTJDNnO7fz7ULTYzbv2lwtz/mOkSlpGampQWaDf6hx3zXJMxxthJnbhSw
PME6tqD15KCTBf4UlgOPnWWdHEQRZ3pG5o3rN7o0IHlUvqLvgBYstyNOuUaw0fZBvS/PZuY4R5VP72PZQ7bzpFfvQ4smtBuqtZhXazmPWugH1rTFHOfyl6vAmr+FbF1d
57KuzmlJyngZnIdNOmE8rKURvG9J+0bwGqoRHLdbQSMYxCnXCB40OyY05BNzcpCsEdyUGdl0mu8dVtxZMy4ubsrkqbNmzZEnTvbiIGYfJ0Oc+nBWbUJi0pvXb3jYW9eN
WvFd94pffu5AnOzFQW17v1oXB7Xu45TqtWIf3Q38JDZgedKkKcCyPHGyFwcx+zgZ4pT2WbUlx0+SszA5e6LP5eUVRj3asKxgqJa9HYU5OYjZjiLRa8XqQ/w4y4SJyJ01
Q0NCpk6dPmPGLMMjzgzDPZubv8WoSOHL8+cV3/xY0f0nQyLOxhifxvwcrcpN54kDy9OmzZg5c7YhEefevXtra2t1Lls9LcCna9epFjAby/pPnA0h7p+vXuGvEe6smZuT
M27seIMkzqAgjmdG8NeHXqdAtU+7/Vhh1B5s7eY4W/d+tZ0c1DZUK9nbUUCcDelc7kbQF23SLWDDI05vb5/7Dx7oixYkVc6mk6UUlr/vYWjEGb6/MfcgT1FzZ03MhYwa
OXrKlGmGR5xHjuSfO8fx2Aie+tD36BX/8QPV3TQ44mzKjjTgHmdIcMiECZMMlTjfvjXMLbZa9RVUC/g/ZVg2POIMcf909jQf6XFnTay7GzN6DKZDDJI4U1NS+Yi1y8at
HDLcUImzztnWUNWK5eIjR44Clg2SOKOjog1VcdqrF1aZUkA2UOL86LaLj+i4syZyXbxoMZqoBkmcUQRpnMyqauFSCmyG2ONsyghr4tdE5SRRMSLhaMxBAwdNnDjZIInT
11eABSBiqEFieVTNmGOoxNkY5fXlwX3O8ubFmgEBARikNUjiDPAP5CzTrhyxzsevhTUNkTjrYyIMVbk44GDcuAkGSZwJCUnkthMOdltjbduCZYPrcX46FN106gQHmdBR
eLEmBmknjp8wdux4wyNOf/8AzjLtyhG/vHhR8Xs/QyXO+jCDbUulp6cPGzrMIIkzLS2jvLy8K6OSW90/3bjRBmSDI876BO4nRvFiTSjD09Pzz2HDDY849+714GZqJFat
jV0b2Ayox/kpN6Y+1pBnyLDvZMzosYZHnBihJX1Nbn6pepWxQRJnY4xXU+lxbjLh29ekc120cNHIEaMMjDgDAgy2V8HZVtSMSF2VMHSk4RFnY9S+pjN8TxVRU4Y6ee3U
qVOjR40yPOJ0dnbRiTwNINOvHyoqR44zPOKs93H8fPsWZwXx7Wsi45cvX44YPtzAiNPHx5ezTEnEz/fvV46bZGDEWWdr9vXDB8NWbmRExID+AwyMOJ2cDPxoJ63aZNPF
ixW/9DIw4qy1MOEjNAFYE9k/ePDAkIgzNi6xsKCQj1hJXIo4J00zJOKs2bq5K6gVE5zjx43DKj/DGKpNTcvIzMzsCorTXh0xwWlgPc5aRzs+4hKGNVECrAxavmzZoAGD
DGCodpvFdjIRwseq6LgYqqWW4f3axwAWBzWEODdk8rpdiL88RUsBo0cUlgcOMgDiJFgWxGwoLJtva1vop8+Lg+o9bBqLi/iIRTDWpAuBhuqcWbMHDxqiv6tqDxzMcSET
IXxsqn1crKqtXr6qDW/6eXJQjfEynrcLCSdRkVI6dOjQ+LHjhgweqr/bUQ4eyiVYFtBcmi5cqJo9X9+3o1SvWMxTJgKzJl0a4G3VylW4sU8fj9yzt9914/p1nmIl0eUk
AO6sMTPX05OD6v131oeHdE2d5ufnL1q4cMTwkWPGjNO7k4NsbXfcvn27aypOe7UGd6LfWTlgqD6eHPRxj0VjHt/LGLTCmrTCMMgZFxtnvMZ43tx5UyZPwW4w3OFHHSQ0
eeq0qdNxa/ySJcuWSexaMVyEu32bpfYMrounjO5aw4GD6HpWjp3YcsTlTz9J/1qx6sXzulpHU85QgeXw8IgVy5dPnzYdO80mjJ+Iy44kfq1YUnKqtZV1F0ec9qrfguUN
JpWTp1d80506rpbBslRvR2mIdatesYS/TLTImuzCYdYTG41x4HtcXHyo7M9rv9f6deuWLlm6bOmyqZOnYNnenDlz1+r6Ps41q40fP37MX6wkhU4lgGvFwKB13j5V8xZW
rzGuHD+pcuSYqukzKn77ueKPXyr69Kzo27Oi/68VA3+rHPR75Z+9q2YM0cl9nHV2GxqyyXKSNn0CyLiP08HefsnixWuN106eOAlh+bLlY8eMxSVIE8ZNAKdOmjh5Mk61
nTIVl+9u0sV9nLidfuMGE7I6oVMYCvICsFyfkla310OG5bUAMoXlKVOoBrFCLM/WzX2cNeuWfLpaxr/KIrFmpwUFFD09PKZMAtgmGxuv27Bxk4m4F1nHJ6QsWbyk8OjR
TotKXtCqBNCGxX0LcqEhK6ty8ODKiQNEJs4a0xW1zk5ara/BJA6KAorl/px2OY0bO3bDBhPTzVvMtmzdIspF1lHR8cuWLifXFunctBRi+WNUFLBcNXlg9bw/qxcMr14s
xkXWDeGONcaLhGr+SoU1GQVnZ2ePHD4co7irVxuLRpze3v6YiH30iPQydQ40pQXAXsnqRYsrB/1RNWtoC9iWjqpeMaZmpezW+LUTa9ZPrjGZVmM6vcZsVo357FqLebXb
59daLay1XVJrt7TWfkWtw8papzV1u43rXNbVuW38uNfko4fpx31m9V7m9T4W9X7bG/wtG4JsGkJ3NITZN/haVy+Y1ViQJ12J6EnJLpw//+fQYfPnLRCHON3d92HEiGBZ
ytbx+cGDqklTKof1rp49TATirN+3DVgW8OoFybEmrezCggKc74VW6qKFizeZmpmZmVOt1K3bLLZZWlpitsLW2sbO1m7njp0O9g67HBzRonV22r3HZY+by569bns997rv
8/D09tznvd/Lz9snwNcvyM8/OCAwNCg4PCQ0MjQsKjwiJjIqLjomITwiGolbWVljDFnKdkbKRkuA6nT2G1A5sq9WibN267LqVcu/PHpExC6IBAAuqtM5Zuzy5Su11+OM
iIxZvmyFv78/wbIgWtN2IlSn88/hVWP7a484632315osrDZeLez5JBJlTVphz58/B9iGDxs2adLkNWvWCkucYFAzs61YqXTrFvejlbRtWCT9jhLAsM/HkJDKfgOrRver
XjCiWtAeZ63FsqopExtSk4nkBZcA4Lxu7dpxY8etXLla2KHa4JCILVssVq9cRbAsuNa0miDIrNbBofK3P6rG9xd8qJbGcuMx4SfdJM2ajMKOl5Sgpzl82J8Txk9YvnwF
mqt8epz79vsYG6+fO2du0TFee121ak8kcdUSAN4o7hz6Z+XgXlVzhvEfqq3ZvLBq8oT6qIguvlxW24aHiU+LrRaDBw7CEtzNZubbtltZWtlg9MjGdofdDvud9o4YPXLc
tdtpN3ZaumL0yNXNA6NHHp5eGD3a7+Xr5e3v4xuI0SP/gJDAoDB8s2mTGYXlIoJlbatOW+lT3OnsjHZw5Z99qHYwpl1WyaZd1k1qP+0yh5p2sVzQbtrFcRU17eK8tm3a
Zc/Gmg1ztYpl/WBNWl0YeMEcyW4npzGjRiPMmD4Tc59otKo5VLtjp+O6dRunTJri6OB48eJFbZkASVdECVDL3/Pzq2bNqezTjxq2nTNcszlOh1U1m+dXL5hSNX1aQ0Y6
4UvRVIelQ7ExMUAx1twuWLAIKxg0Ik5XN08LC6sli5duNd9adOyYaMUmGWlPAhSWs7IoLA8dUolh27kyLKtPnI6ra9bPprA8a2bj0UKtYlmfWJOtMKAOHVA/X9+VK1b0
7d174oQJWHw7d868xYuxDXTp0qXL0SXFJMrixUtnz5o9dfLUNavX+Pj4XLxwQXtaJynrUAJorjYU5NdsMav8rU/luNFVYwdUTRpcvXRc9bJx1euntSwOMp9bs256zYaZ
1UsmVs0eUzVzWtXMGXX792HdvA5L3sWzxrAt6BPw7PNHr4kTJs6fv2DVqjVYyoClQ1i1QPc48WH7dmtLSxu0koHoGdNnYIFDVmYW2VhikMZDYTk7qwXLI4dVjR1YNW0Y
C8tUj7Nm8+wWLM8fVzV1ROX4sdUrln+MCBcHy/rKmh3NpeOqd/obsjTAIKGlolJA3aeysvroqI9hodXGxtVLl1Yvawm1uxw/hoc1HDiAnS1dTSzSry/Qevr0ady74ufr
h9NRsKwdU5WrV1EBa3yioqLQ6gXLSr8ipIRCSQAsCCwDyAqw7LQLWG4sLBQfy5JmTUJ4QhmfQaZj1O0bJnCooFbHcDiUR9+jcEYrUYS+q16Q8nM2A86Gx7nY0mXNsrIy
NDw5V4xENHgJ8GFNtE8bsrINXkSiVRBdwPi4OG7Z1bq5c/aY3HIksaQmAeqkMK54dN+7V2TilC5rQhYbN2yQmnZJeaQjAT6sWRcYXDV3gXTqou8lAWXicBIOtQBf4g6N
plOkfcxBeIYThTMeMbcNPyBy/0qirIm2A+0TyYS/4SBD6JrwYc3KYaPgrMVZOyB0vaWY3oJ586AOjA9pWjjwJRRRvd5E04jkfUOSAI1HDjOUhYWFMDx0scSUhkRZE20H
2idmZ2WJKQ6Slx5JgDNr0p4aAS1cPaqvZIsKsqR1ERQYpGkhwZe0LoQ9vUXTYpD3dSgBrPfhjEe6uSZy/0qirImxWVoWEIoO1UmylrIEOLMmJtJolKKFK+UK6kvZQJaM
LjSaYQJTtlxx/B8/cJ7W0hcpkXIqkwBnPGI2nTE8dDpFk7AUWZMeqmYCWWsumjXoV0bcWJOeSGMC2rn6VWuplRY0iRlNRhcazTCBKRlFkGlmqWlWnPLI4VGjGW7MpjOG
J+YiGCmyJkZl2Q6Rw7CPOPomuehWAtxYs7GgkM2aaOfqthb6njszmUKrw87WVv0agSnZuiDTzOqLzmDeZKZLaEvQCI/s5hpsT7T+lRRZkxmqpnHIbW2ewVgVqYgyCXBj
TWYijfHXZNsDHxvDQgy2ItSfYQJHsimTTDPz0YL+xuWMR2Y2nTE/znufNJWe5FiTPVTNiIPD2jxNBUHe1zsJcGBN9kQa47I1GhTSOylptcBykym0RtScYcJSLDnWJNPM
WlWWBBNXiEeMBqlTVPZsusiLYCTHmh1lAYmIvLBYHZ2Rd3QuAQ6sWR8XL+epybYHPnqk1/3LBTVX8NGbDeQCmWbmow69i8ue2GYsQZ1tSMzWRDnbE6d/JTnWlBuq5rY2
T++shxSYgwQ4sKbcRBoDVLLtgYP8EYVZ6y7nvDqdYWI2G8ixpkbTWtzKTGJJRwKc8Sg3m86YnziLYKTFmh2HqrmtzZOOWZCSaE8CmrIm9lB37NzQ35BtDxzUpHAyhVZK
pzNMzGaDjhoh08wcdKGPUTpObDPGgDEh1TXCorOOgxz0IhiN9j5xk5u0WLPjygKdLCzmJkoSS2QJaMqaHSfSyLYHPipjr/uXc2GqV/DJbTaQI04yzcxHKXoUlzMeFc6m
i9m/khBrKhuqZsRBTtfTI0iIUFRNWVPhRBrjssm2B01VJrfWXf0ZJrnNBnKsqc60lqZFJe9LUAKq8ajidD2Fs+mM+YmwCEZCrKlsqFr8hcUStDBSpI4S0Ig1VXtqsu1B
UwNTMZlC60XFDFPHzQZyxEmmmTVVh969r2xim7EEFaddqm6uwfa03b+SEGsqW1nAOEc11+bpnQGRAnOTgEasqWIijQYq2fagkRYUrnWX624qnGFSuNlAjjXJNLNGutDH
lznjUcVsOmN+au594iw3CbEmjgRiAht+7O9FmOnlLEoSUWQJaMSacMRMYPto9veki6O+BuGYOkWrwiY/fZOial2QqU31FaGnb3ZqA3hBIR7Ly8s7ZQqNjnXkIEAJsSa7
9Bo5RA7VJlEMQAKcjYTNmgYgB51XgbMiUHKiC52rT+cF4GMDfGyPc8UJa3IWHYmoYwlwBgwflOq4zpLMnrMiCGtKUp9iF4oPHvnYHud6EtbkLDoSUccS4AwYPijVcZ0l
mT1nRRDWlKQ+xS4UHzzysT3O9SSsyVl0JKKOJcAZMHxQquM6SzJ7zoogrClJfYpdKD545GN7nOtJWJOz6EhEHUuAM2D4oFTHdZZk9pwVQVhTkvoUu1B88MjH9jjXk7Am
Z9GRiDqWAGfA8EGpjussyew5K4KwpiT1KXah+OCRj+1xridhTc6iIxF1LAHOgOGDUh3XWZLZc1YEYU1J6lPsQvHBIx/b41xPwpqcRUci6lgCnAHDB6U6rrMks+esCMKa
ktSn2IXig0c+tse5noQ1OYuORNSxBDgDhg9KdVxnSWbPWRGENSWpT7ELxQePfGyPcz0Ja3IWHYmoYwlwBgwflOq4zpLMnrMiCGtKUp9iF4oPHvnYHud6EtbkLDoSUccS
4AwYPijVcZ0lmT1nRRDWlKQ+xS4UHzzysT3O9SSsyVl0JKKOJcAZMHxQquM6SzJ7zoogrClJfYpdKD545GN7nOtJWJOz6EhEHUuAM2D4oFTHdZZk9pwVQVhTkvoUu1B8
8MjH9jjXk7AmZ9GRiDqWAGfA8EGpjussyew5K4KwpiT1KXah+OCRj+1xridhTc6iIxF1LAHOgOGDUh3XWZLZc1YEYU1J6lPsQvHBIx/b41xPwpqcRUci6lgCnAHDB6U6
rrMks+esCMKaktSn2IXig0c+tse5noQ1OYuORNSxBDgDhg9KdVxnSWbPWRGENSWpT7ELxQePfGyPcz0Ja3IWHYmoYwlwBgwflOq4zpLMnrMiCGtKUp9iF4oPHvnYHud6
EtbkLDoSUccS4AwYPijVcZ0lmT1nRRDWlKQ+xS4UHzzysT3O9SSsyVl0JKKOJcAZMHxQquM6SzJ7zoogrClJfYpdKD545GN7nOtJWJOz6EhEHUuAM2D4oFTHdZZk9pwV
QVhTkvoUu1B88MjH9jjXk7AmZ9GRiDqWAGfA8EGpjussyew5K4KwpiT1KXah+OCRj+1xridhTc6iIxF1LAHOgOGDUh3XWZLZc1YEYU1J6lPsQvHBIx/b41xPwpqcRUci
6lgCnAHDB6U6rrMks+esCMKaktSn2IXig0c+tse5noQ1OYuORNSxBDgDhg9KdVxnSWbPWRGENSWpT7ELxQePfGyPcz0Ja3IWHYmoYwlwBgwflOq4zpLMnrMiCGtKUp9i
F4oPHvnYHud6EtbkLDoSUccS4AwYPijVcZ0lmT1nRRDWlKQ+xS4UHzzysT3O9ZQQa44cPpwtAoWf6+vrOVeVRNR3CZw+fbpTCwkKDFJYzaq5C9jgVPj564cP+i4i0cq/
YN68TnXx/PnzjuVpOnW6U0XUurmLVhGSkU4kwBmPfJyAUDWVEGvC36nGofvevUJVm6SjjxJAm6lTT11WVqawavVx8aqddfV6E32Uia7KXFhYqFoXoFVlZascNkq1LsCs
uqoXyVccCXDGIx8nIFTVJMSa5eXlqnGIVoZQ1Sbp6KkEVDetMFyhrF5fnj9X7akbCwr1VCY6KfaHDx9UozU7K0tZweoCg1XoApyqkxqRTMWUAMZ1OOORsxMQqoISYk1U
ScWwjwqHKJQsSDrSlwC6kiqcdXxcnIoqoDepAqh/kcF/DdVvZ2urQhegVWXpfS4vV6EIcKqGBSGv66UEOOORjxMQRFLSYk14PWU4VDZfJYgUSCJ6JAEV898KJ9KYqqE3
qcxZk4k0DgagYoYJhKo6QRXTWuBUDoUhUfROAnzwyNkJCCIlabGmimEfjN8KUmGSiL5LQFnTSsVEGl1l9CaVsSaZSONgFSpmmDqdTFE2rQU25VASEkUfJcAHj5ydgCCC
khZrokobN2zo2N3s1CEKIguSiF5IAB1KhQMSWJ/SafnRp+xInGQirVO5KXtB2QxTp2vdlU1rgU05F4ZE1DsJcMYjHyfAX0qSY02Fa/NUz1fxlwJJQb8koHD+W8VEGlM7
hdseyEQaZ+0rnGFSczJF4bQW2fzDWRf6GJEPHjk7Af6CkhxrKhz2Ucch8pcFSUFfJNCxadXpRBpTtY7bHshEGh+9d5xhUrb5Ry6XjtNaZPMPH0XoaVzOeOTjBHjKSnKs
ifpgXyZ7CA5jtjwrSaIbmAQ6zn93OpHGSEBu2wOZSONpG3IzTOqvde84rUU2//DUhT5G54xHPk6Ap6CkyJpya/PUma/iKQUSXe8kILftodOJNKaCctseyEQaT9XLzTBp
NJkiN61FNv/w1IU+RueDR85OgKegpMiaqBJ72Ed9h8hTFiS6HkmA3bRScyKNqR172wOZSOOvdPYMk+rNP3J5sae1yOYf/orQ0xQ445GPE+AjK4myJrM2j5yix0e7BhyX
Pf+t5kQaIw1m2wOZSBPEQpgZJg5r3ZlpLbL5RxBd6GMinPHIxwnwEZREWZM5XU/9+So+UiBx9VECdNNK/Yk0po7MtgcykSaI3pkZJg6TKfS0Ftn8I4gi9DQRPnjk7AT4
yEqirIkqod3KwSHykQWJq18SoLc9aDSRxlSQ3vZAJtKE0jg9w8RhrTs9rUU2/wilCD1NhzMe+TgBzrKSLmvCG2o6X8VZCiSinkoA7SqNJtKYaqKXSSbSBFQ6xoTU3/wj
ly+mtcjmHwF1oY9J8cEjZyfAWVDSZU20W8kpepz12kUich7ARy/zk5I7xbqI6IStJmaYNJ1dZgpAZjSF1YU+psYHj5ydAGdBSZc1OVeJRCQSIBIgEiASIBLQkgQIa2pJ
sCRZIgEiASIBIgEDlIC6rNnU1PTixYtnz57dF+sP2eHPAEXOuUpfG5s/fWhueEqFunvNtbdbPuNL/CSBP1plYhnIfVgjsoNlSqDq+lSEmpoaMbH88OEjZPf+/Xt9kpG2
ywrANr1twS+ADDjTuP5c3fzXF21n3mn6tLcXE8v65e3VYk0IMTIq2nOf16tXr0ULyG6vu2defkGnOjbwFwCwxhfN1ZebK45ToeZKc01Z88f7zQ1PmuvuUp+rzlLf4wW8
pjv6hKagL/GNBJZJiFN9CIC99u33Fl9NsI3bt2+rX07DfBPwrH/YXHWOAmxlaQuW6x9TWK69SWG58lQLlpveNP/1WSdCYLy9mEaCvBD0xdurxZpZ2Qf8/IOSUzJEo0xk
hOwQ9nv5XLlSphPr0X2mgA14saKkufJkc+315oZnzV+qm7/UNn+tb/7a1PzXJyp8bWj+8rH503sKjdUXqZcRRXS8QUduez1plYlsJMEh4bBP3StLT0rg7rEvPCJGfDUh
R1jIuy7b4/xS11xzVYblU80f7zY3vWz+UtOML4Hfv2gsN8mwXEdhGW1iMCtoFWwqOpYZby+mkdCuAyyjF95eLdZMTEr2DwiJjkkQ0yG6e+xPSk5HvmfOntMTjyRoMRuf
N1eeaK4s+avuFoUxjOdgJPZzVSvYQJwNslBP8SjY9FNF86d3zY3PmmsuURERXcQ/6IjWF/6LaSSwycioONiniHXV76wcHHdDYiGhkWKqydcvkLaN511zzqXhcXNFEdq+
f1F8+ar5ExvLH2WNYBrIHyl0A+NAOt6pf9Bcfba56gz1jYh/jLcXE8v65e3VZ83gyKhYL2+//IJj4gQHRycZawafOXtWRJuRQFZUF/N284ejzdUX/qp/+FfD078w9Nr0
miJFUCNNnCDRRsDvg4xEq5s/V1JNVIzqNL38q/HZXx/vUOM8SESship0hE4M9AWtiWMeyAXWCJtEIKypvtVCQZAYYCUaltMzsmnbwP8ux5oAYNV5YPmvmit/NTymsNmI
FvAbCq2fK2RDRzXN+AZYbmkQA8to/lJYxpvU+7XooRY11z9SX8U835SxJuXtxcSyfnl7tVgzITEJfeeIyBiMlx7JKxQn2DvsSkxKQ75nznQl1qRghmmPY821V5rr7/9V
/+ivhid/oePYiFnMW7IpzOLmD4XtQtVpaoKk/j6YFfxKsSzw+fFec9UpKilRiBM6wsQV9AWtiWMeyAXWCJtEgH3y9BRdJzoUBIkBVqJhOTUtk7YN/H/+vCut78MgEEZZ
geW6m+g4/tXQiuWGR821NygsywEZj9XnmmuvUcuCml4B9RT28TKav5VoBN8Sx0oZby8mlvXL26vHmgktrIl1BDm5BeKEnfaOXZE1MSAD8AA5GMypv/cXwEZhprT5fX7n
gW7SonuKOU6QaH05NYmCBLX/B9bErBX0Ba2JYx7IBdbYwpoJhDXV1TEURLOmaFhOSaVmNGEb+N+FWBOt1YqTzR9AmTcoJFIt4Id/AdcYBFIHyxXFf9XdoJq/NJap0aNi
asWQ9v8SWr29mFjWL2+vFmvGJyRiZiI8glpGezgnX5ywY6dDQmIq8j19Rgy/r31rVCMHtEDfH8HALNU4/XibggrWAeEbjcKHAop06+9RvItEKkuohq2W/6AjVzcP6Ata
E8c8kAusETaJAPvUcv0MJ3koCBIDrETDcnJKOm0b+M/t+EO9lD5GgMCONZepPiKADESjv6gRkPEypmko0gWWkcINioMxnKvlP8bbi4ll/fL2mrGmh6fXocNHxAn6JUcB
LBlTle9ymiuwHv0qhRDMZwA2+IZbQPcUQEWg0smn5kG1+cdmTXHMA7nAGglraqpVhjVFw3JSclqXY00sggVsMaNJYxntYD5YxpogNH+RDhb6vS+klg5p84/NmqJhWb+8
vXqsGZ/g4xsQFh6FlU4HDuaKE+x22McnpCDf06e7QF+TGs8pan5f0Fx9SbYF80zzu8N8AzXSe5XCLTUbWqTVCU7oaI+rO/QFrYljHsgF1gibRIiPT9CmGzGotKEgSAyw
Eg3L6GXStoH/XaKvCVYDeD8UUVuogT60X/ljGeO62HtG7V05SS1W0OYf0ER7ezGxrF/eXi3WjItP8PbxDw2LRN0WzF8oTrC12xkXn4x8T3UF1sTinbcHKYBhz2Xlaeqz
IOF9HtU+BRO/P9qMLLT2Bx257NkLfUFr4pgHcoE1wiYRYJ9aq5mhJQwFQWKAlWhYNjHZTNsG/ncJ1gS3vT1EcRtwB5ITBMhIhKLhK1Sa6MViLb3W/hhvLyaW9cvbq8Wa
sbHxWKeOPV4hIWHRUdHiBBsbOyAN+Z46dVprFiKZhIEEjOFQW5tpyswWLKDHWXWBShZZaO0POnJxcYW+oDVxzAO5wBopmwyNhH1qrWaGljAUBIlRcBYLy8nJKbRt4L/h
s+aXegq5mI+kVsKDMoUDMpJCjxNYpo5K0KJLZLy9mFjWL2+vGWt6efkcKzouTtAvOfJyro2vm99kUm1JDMyilYrPwoaKE9QgLYaJkJF2/tisKY55IBdYI2FNTfXJsKZo
WM4+cLgLsSZW3gG8GDTCaqA32QIDuSXlM1TKoGft/LFZUzQs65e3V5c193v5BodEYGYiLT1bnGBtYxcbl4R8Db+vifmPN+nUclk0Ud+kaSFkNFeVUhtakJF2/qAjZxdX
6AtaE8c8kAusETaJQPqa6msVCoLEACvRsBwdE0/bBv4/ey7qkVXqi0WwN6lVP7Kplve5WgByWvM7jP3Kxo1wcpB2/oAm2tuLiWX98vZqsWZMTOy+/ZQcXfa4paZliRMs
rWyANORbWnpKO+YhmVTRcsSoLIZfXqc3v07VSsAEZ0Ux1UTVzh905LR7D/QFrYljHsgF1kizJuxTO9UywFShIEgMsBINyzjAj7YN/H/2zKBZE/0/4PcddowUaQXFtHNA
4lhJW6mtNZKMtxcTy/rl7dVnTZ+g4HBnF7eU1ExhQ05uvr44p9ev3whfVBw++Sq5+S1WzB6hPmgpvE6jpkPwH9lp4U/Gmi4xsYmwfmHNA6kdOKjFGVlhhXH//kNhExQ8
NSgIQN6334dgWXDZNje9p/CLjV5vD2gLyEgfbV+0gF9nCl9+WYoy1qS8PcGyMgmry5qe+7yDgsKcnV1xnqSAIT3jQOHRYi2pX/BkUdTaujqBk2161/wqiVoKhEkLfNBe
eJdHjQMjOy38Uazp5Iyz1C0trQU0Dzop/bKQZ9I+NA4KApABZ8GxnH0gR780JTwOam9R+MU8y6sULQKZyuIYlb52/sCatLcXHMuYVdEvC6msUnxuvlqsGRUdgz3RAYGh
GGPByVgChti4RNEO+xYko8pKoe8foFgzgepr4r9Ww9ss7bHmydJSx127o6Ljt223EtA8kBSOfxNEcaIl8vDRY+14M2FShYIAZMBZWCxjiSzOmxVNyIJkJIxA2alQrJlA
TTpqFchUFoebX6doadyI8faCY9lgvL1mrLnLyQW7lYUKWB2w23mPaId9C5JRZWWlwGADa76Ma36TQf3XaqDGdjK11Ndks6ZQ5oF0fH0DN2/eIojiREvkwcNHAluIoMkx
rCkgljEyb2O7IzAoRDQhC5KRoHKVJYZzYiksZ2oXyLS7AJy1M27EZk0BsWxI3l4t1oyMisZJIgGBIehPoFEpVIBDxGQYc2ypUbdvfG89l2BAwZhCVlQIzppvm1/GUuMt
+K/t8BpI08rReidPlto7OKGvudViu1DmgXR27nSEkeiXhUh8ahMKApABZwGxHBQcBjXheilGUxJEMV0kNpa1wJo3KAijF6htIFOrH5K0hGXG2wuLZUPy9uqxZmSUu/s+
oMLK2mbr1u1ChRnTZ2wxM2eOOpQyazKF1AprvohufhHTTP3XdojREtJOnjxpb78LqyW3bt0mlHkgnYULF8FI9MtC7t/X1pYAQbw8FAQgA84CYnnjRlOoae9eT0ZTUmZN
ppCCyLNdIjU3ZBAWAcvIIkb48stSjGz19sJi2ZC8vWas6ea6d8P6DUKFhQsWbdtmiUUEdABr+t9+/rCmvvrTl8qmLxVNn983fn7X8Oltw6fX9U2v6puef2x8Vtf4tK7h
cW3Dw5qGBzX196rry6vr71Z9vFP18Vblx5uVdTcq6q59qL36ofbKh9pL72suvq+58K7m3Nvqs2+rT7+pLn1ddfJ11YnXVcdfVRW/rCx6WXnsZWXhi4qCFxX5zz8cefYh
99mHnGfvDz59f+DJ+6wn7zIevwu9+xIFYwr54YPQZ1l9qmx+ESleQHZa+GOzplDmgXSWLlkKI5GzkLNvqmpaLeRDewt52WohT+oaHtVSFnKfZSG3GQupqKMt5PL7WtpC
zr+roS3k1JtqxkJKXrVYyNFWC8l73mIhh2UWkv3kXebjd9H3XrMtpPzefS0IWLAkGdYUEMvGq42hJvRfGU0ByAhQE41lqInG8hs1sAw10Vi+1oplqInGMtREYxlqYrAM
NdFYhppoLENNNJahJjaWUSS2pgSTKZPQx0fiARlOQzt/bNYUEMuaens2lmlvz8aybr29WqwZERmFu/Hom2xPnz4rVMjMPECFrIN0kDJrMoUUnjVh+s/DxQvaQdqJEydl
FzfGbjG3EMo8kM7BgzkdLUSarMlYyN1yLZ73y197UBCADDgLiOWi4hK2miAKKbMmoyn+wpRPofGNeEDGknjt/DHeXlgsa+rtdcianXp79VgzIhJ3/eBOPtznAs8oVMBI
t6Pjbmw+oQNYM+jOC6n1NcPLX6FgTCHff/ggvK2+PdL8LFSMgIy08wfWlF1BFWO2ZatQ5oF07OzsYSRyFoLehqT6mrH3qb4mU8i7dyXNmlAQgAw4C4hlX78gqMnb258R
AoCMILW+JorE1pRWoCAOkJELDqTVzl9Eq7cXFsuaenudsKaa3l5D1txhD88oVIAcHRycmKNkYNDBd148ktgIbYSMNZlCvn+vBdasvd38NESMgIy083fixIkdMtswMzMX
yjyQDs2achYiTdZkCnnnTrl2ZCxMqlBQC2sKh2V6qbOXly8jBAAZQWqsiSKxsSyMQOVSeXdMDCDDXdQ/00r5m5vbWFNQLGvq7XXCmmp6e7VYMzycOoEWl67Z2e0MC48W
KsjkuCs5JYMOMOgQ6bFmpIw1mUJqhTW/1DU/DRQjICPt/IE1aduAToUyD6SD+4OQoJyFnJdYXzNO1tdkCnn79l3tyFiYVCFPABlwFhDLSBDJ7t/vwwgBQEaQGmuiSGxN
CSNQuVTq7osB5JeJWim8LFHG2wuLZU29vU5YU01vrxZrhrWypo3tTvqWCUEC5IiFl8ymeBh02N2Xj2oadLIa6OCTd1jckfLwbfLDN/H3X8fcex1971VU+SsUCQVjCvnu
3Xut2Ou7guYn/toNyEJrf8dPnADDgedMN28RxDboRGxtKdaUsxBdsaZsBdC7tEeUhSQ+eENbCIKchdy6dUdrYhYgYSiIZk0Bsezl7Q814UAZRlOQCYJOWDPveQXUxGAZ
4+e0ptCNkNOUANJUmMSLeO0CGY6i6oq2Ct/czHh7YbGsqbfXKmvS3p7GMgdvrx5rhuHc9r24ydbaZgd9XrYgAXLEhjxmex/IKbxcDNbEcjtAC6sfUx69SXjwOvLeK+Sr
IqBgTCG1xZq4w+uJn3aD1q4JA4CPHz+Bfe6hYVGbTM0EsQ06EaQJI5GzkAva72tiWSbtfNMfvYWFwOeqbyE3b2prGFwQRwkFAciAs4BY3u/lBzV5eOxnNEWLSwTWxKJZ
LHoHlpPg/h68Vq0m/MrGsiDyVJBI3T3tAvlZWPPXJm0VHqzZ6u2FxbKm3l4o1tSGt1eTNcNdXNwo1rS2CwwKEyrQcsRlCHSAQUdohzWxSB2r0g89fQ9oyVqdLzUKKBhT
yLfvtHKOK4WB9yXNj320FSq0dUMCjV6KNW1krLlps1DmgXSQJoxEzkK0wZrYzFD0krKQ1EdvYu/zspAbN29pz6PxTxkKoljTxU1ALOOwb6gJO08YTdH40gZrAsvYJIZd
YcCyRiimX2Zjmb8wlabwMlVbQIaLwK5Qbf6FhbV4e2GxrKm358yaZ95o3durxZqhodS57bj/3crKFodYChUgxx07HHCgDB1g0KA07MUUZIQWW7uOvaw4+PRdoqyvwCeg
YEwh377VGmui/fg8pvmxt/AByWqzcSpjzePwwhhTNTExFco8kA7uqoWRyFnIxXc1gqyhxf6/468qDz97nyJrS/EJbAu5fuOmNn0a37ShIAAZcBYQyxibhZqwm4XRFC1M
oVgT+2gLXnzIevwWU8h81IS4bE3xFaWK+E0fmp8GCw9kOIfXB7RYbFnSjLcXFsuaenuNWFNkb68ua+7evQdXlZptNt+w3kSogNMi1q/bwGxUgEHHcGLNlIKina5715pu
Wbt5y6pNZstMNi/auHkhFcwWmZgt3rRliam5fXisx9HTSJ9DoDrBrftt3r7Vyol0LUgA2J4ENj/aJ2RAgkhWy38lJcfhhTGmunHjJqHMA+nMm7cARiJnIZfas+a9l28i
EpI2mZlv2oKwlQrmW023Wmzaus0UwWI7gq2Tc8yBw2WvPmDvPM40wLBe2kNMTLYZQ9L1R6XJ2fftHJ6u2fDUeOPTtSZP15k8Xb/p6XrTpxs2P91o9tRky9NNW2+ExR0p
VGBFbAu5dl27XQGemoSCAGTAWUAsr15tDDWhBcxoipatHGuWnL+4PyBIpqkWNW0yh5pkmrKQaWrbdt/wyKT8Iuxhv1ZRizZNztP3ydQUcpum0i/eLvMLebRl21NjRlMy
NVGaMpNpyvyRjcOl+HS82RHsbE3xlGQn0WvLhUQx7ROeRWq7+UuzJu3thcWyOt4eFuLVwUJasMyykOQCykKA5VOvq/KevZfDcjsLWUtjmbaQzZpaiDJvrxZrhoSG4YYE
yHHXrt3r160XKuC0CNNNZsySS2rK4f7rJ5r0NW+8qZi7aAl8665dzuHh0TEx8UlJKenpmdkHDubmHiksPFpScuL06TMXL15KSUkZPuxPM1dPZKFpoJYpta4cfvNGm6wJ
m/34uPmhh5ChVowlnWBNSxlrbti4SSjzQDpLZGcDyVnIZRZr5hwthnbWr9+ISbWIyOi4+MTklPTMrAMHD+Xk5RUcO1p08kTpubPnjx495ufrN3TYnyGnr3bU/qFTZW9H
j6ucMbHOZl29386GEOfGKM+meL+m1NCm7Nim3OSmYweaSvObLpR+DA+tGDLy3p59comwLeTaNUmzJhQEIAPOAmJ5zeo1UBNW9jGaouXDZk0be8dRI0bJhvFx0GlsQiLu
SEnPxmFCOUcKCo4WFx/HZXPnz184dPDQvLlzF60yjrzxuKOmTiVnV/zHDzUrZ9c5ba73d2gIdW2M3teUGNCUHtF0KL4pL62p+FDT6WMN+YfrfHw+DB5xOj1Hhaa0y5pI
HdATEMuP/UVo/qLUjLcXFsuqvf3LqhqTzVtgIbbU8gjFFnLq1GnKQg5RFrJwlXH0zScqLcSsxUJi9rdZSH56i4UU5NAWknf0jAoLUebt1WPNEOqOsP37fV1d95aUnBQq
4LSIlJR0ZsklXA+WM2nEmkvXbVyxfBVmU7DkPTPrUE5uAe5vO3Hy1NlzFy5dLrtx41Z5+f3Hj5++evUa58d++PABjtg6JAa5aBSoLTGty4a1zpow24aXzY/9mh+68w1I
BEmJ8idjTRuKNTeYCGUeSOfAwcMwEjkLYVjz4s3bfXv38fLyS0ikPDBaSrgKowj+99TZCxcvl129jk0gOEv92bMXb9++r6mpPV5yfMjQYVE3Hstp/+Xs+dULJjUE2zZG
OTXG721K8/50MORzfuyXktSvZw59vXz0y83SLw8uf3lx5+uH51/fv6qcPR/umJ0I20KuXr0uisg5ZgIFAciAs4BYLig8BjXFxyczmqKFw7BmRFzihPETw8KjcFtqRubB
Q4fzcNVXyfHS02fOXbp05fr1mzga4tGjJy9evMTOrtraOjdXVwu3fXJqyrp0B5T50XljQ+jOxhjnxiSPpgy/T4fDPxfGfzmR8fVc7terxV9un/ny6OrXV/e/Vr5qLD4G
t4hYyjTFUYIaRaOIkzeQkcLTcHEok2LNVm8vLJZVe3u/kDBYSHhENCwER/Mos5CXL1/BQurqKAtBF6gzC/FssZCjCW0Wcudsi4VUvaYtJKW9Q1DH26vLmrhXaN8+HwsL
S2+fAKECRrqxSBKXhtMBxU148EYd1iyv+ljysjL49NU/fv/DxzcQ2+HVJM6zZ89OmjELuWgUUDCmkK/fvNEINRxfxqXwz2ObH7pyD4iORMT6Kykp2Y7rjoPD0e0TyjyQ
DkZ9YSRyFnLlfS09r+my12P9ehN4akynqUmc1lZWdrFpbO3nnCr7MHDgRw/Teh8LNYmz6Uzpm5Vr2YmwLaSs7JpYUueSDxQEIAPOAmIZM5pQk7OzG6MpWjgMa/bv28/d
wws9Udxbrg5xYqU6tcrh5hO2kG+6elUvmPhxn1m933Y1iRP9icsJmco0xUV8HOJQjWBv7kCGE3hzSISBWaZmYE3a2wuLZdXevl+fvh6e3rAQ3DqnDnG+f6/AQm47u3ew
kE6IExZyIS5dmYUo8/ZqsWZwcMiuXS6e+3xwDQVWmQsVKDna7GAWj1DbIjtjzcvva3AuM15D8Dp2ZuL4idh8hsWWLOLMDLcYZ9Rtgl1SscIeJ52LRgFRmEK+fi0Ka9Im
XHm++bFX88M9mgVEQURx/4qLS7Zvt4LTXLdug1DmgXSsrGxgJHIWwrDmqjXG2NDp5x/cjjgPhG0f+qPRn7bJJxX0OJOSkpzR8WEZQMGxs5UjBtY5r20lTvOCGT9D4y3h
hzH7vHxrOvQ40elhJ8K2kCtlV8WVvWa5QUEAMuAsIJZdXT2gJkyGMZqihcOwJuSDPZ3+ASFs4jwYtn14tx9H2CaVKupxbt66DQBnC/npCuMa07l1e9a3EKfvCpvvW9XU
7ZueU1YUJMbL9TgbslIf2zoq05RmguPzNtbivSvUDMU06oHlWrG3/zLeXlgsq/b2tIXAftoR58EIy2E/Gg3fkXqq3ZgE3eNcsXpNJxYSuq1gJhvLY/d5B9TQYxKtPc76
hJg77R2COt5eXdZ03OWMtoD51m1YZS5UgByx8BJejw4oLvacPlU0r/niYyMuPcC+VLzABJ+iM+PGjsOt9O2JM9p5fi+jbj8Ot4orUTRUS+eiUUAUppCisiaA+rmm+WVy
84Pd6ga8LGIXk/EkYE1cd4zmy9p1G4QyD6SDUV8YiZyFlLX2NZetWGlpaYPX2hFnnMvCH+BMx9vEF3Ycqo2NiXMOj2Nr/2jR2cph/Wt3Lm8lTpP8qT+1sSZFn7/b+kTI
DdWCNdmJsC3kypUyPg5W23GhIAAZcBYQy3tc90JNTk4ujKZo4bBZE/tS2hNnWvzuxT0g3mHWCcUKhmqxtgsAZwv5GVhz/fRah5UtxOmxyNqojTUplf0w51heOps4Mcf5
bJO5Mk1pW9Ty6Te8oNb6qY9lLJfV8tJ3hRIAa9LeXlgsq/b2UB9tIe2IM3HPIhmWbROL5AbzQZxKLGRGm4X4meZP64Bl3+gWC5ERZ31UyJ3wGGUWoszbq8uaDo67PTy8
tmyxgDSFCjI52oLz6ADB4Wiep7WN7J0nuCMMOw1wYxd+kgu+RWfHjBrjssetHXGG2s/9/qdBA3r1WOR5QNEcJ52LRgFRmEK+ev1aDLABLTgz9nV28wMnLgEREV1EyIE1
LbZZwuLXrl0vlHkgHZAijETOQhjWXLp8hbm5BYYHWcQZF24/v8f3/Qb17b/EI6PjHGdEeKRTWCxb+0eLzlUO7lNrubCVOI3zJ/UwMhpVELSrMd6twnf56h++6bnYrqL9
HCdYk50I20IuX74ihoVwzYNSkIcX4Cwglp1dKNbEijxGU7Rw2Kzp7OLanjhDHOb80aP/wAE/LPXMLuw4x7nB1AwAZwsZrFm9anKt9aIWt7hnHliz57QV76g5Tufrm0f2
7Pab7b5g9hwnln48NzFXpimuItQwHmBYXdb8PIoLkB95Nr/Nb/74UMMseb0O1qS9vbBYVu3tgSDGQlqJMyHSYQGwPLhf/6WeWR0tZOPmLYotxGZxK3Guy58MLI8uCNmN
WfAKvxUUlpfurGBmwe+c/Rjiczc0WpmFKPP2arFmUFCwvYOTu/v+LVu2gqKECpAjJq7QvqADBJf66O3TuhbWfNv46dL7WmxnxpcKg2/x2ZEjRjo4OrGIM9Tfanb37+fZ
u5oO/X7x3vS8jouD6Fw0CvToAR2wsIiXSXYaGRirONv8yKP5wS6+AYkgKVG4s7i4GDe/YwjO2HidUOaBdCwtrWEkchaCqzHpec0ly5ZjI7bTbhcWcfrazPi9+2zbvaaj
eyzYm9FhcRA8glNoDFv7x4rPVQ7oVWM2q5U4l+eN725kNDzf26YxatcHz0Wrv/9+mvnupvaLg8Ca7ETYFoLlLZ0qWYcvQEEAMuAsIJadXdygJrhaRlO0cNisae+wqx1x
+tvM+v73uTt3mw3ut8gttePioHUmpgA4W8gUay4ZW2M+p4U4HWZagTUnL3pLLQ7aeX3j8J7dhkSEBbEXB2FV7XMTM2Wa0roWMFD0No8vimk/8CRAtHYw4+2FxbJqbw8E
sS1ERpz+tjN/7zFnh4fZmB4LPbI6LB9TZSEtxLkybwKwPCLfd0djzO4P+5dQWN7q0sRaHPQxwONuSKQyC1Hm7dVizcBAijX3uu/HgOpe931CBcgRQ3DMgB4Eh4MBadbE
LdP0OYEqgl/x2eF/Dsd6IhZx+uxaOaz7dNvQ2P2bBvVd4JzYcVUtnYtGAVGYQr569UpbYKP48kzzw73N9x2EDEgQyWqZO4uKimXXHYesWbNWKPNAOtu3U6wpZyE0az6u
bZy2YDGmXnDjVRtx+jmt7tdrpk1wvNemod8v2pNyWG5VbYB/oGNIFFv7RWDNvr/VrJ/cSpwLj4z5kTVCazRx1sqbcV5yq2rBmuxE2BZy8dJlbVmIEOnKFESxpoBYxowm
1ASvx2iKFg7UhPuoMQ8N+Vjb2LHdop/jqoFGs2xDorxNRvWYvye1w6pa4w2bAHC2kJ8tN66eO7xm49QW4rSeYvUde4S2l802q4r2q2qxHeX5RjNlmhJCnErSANxwK5+w
QEZqWBVfo/WTpxhvLyyWVXv7jhYSEOC8pn/vWXahid6b0QVyS82Va1p1YiEUcS46MrZ7OyzPXn0zwZdad91KnPXeLneDI5RZiDJvryZrBmEzFsDm4+Nbeuo0RlrQuucf
KDlaWjNdE1QPI7HXPtRhEzo+dBoCSs4NGzIU02ltxOlhu6zvH9MsvMMjAuxm9RmyyS+jw3YUOheNAqIwhXypJdZseN782Lf5vr22AhJHFlr7A2uam1OsiQ3vd+7cxZlt
/M0DKWCFEYxEzkLOva3BObHQ4CTs2lq1Bg0vhjg9bZf1N5q+3TciKnjHnO9HbfZPk9uO4u3tC9Zka7+45Fxlr1+rV4xpJc7ZuSPZrPmN0fdDwz2d5LajgDXZibAtBJuD
tSZmARKGgijWtN8VHh6JjZKCqAmtFuq8NHtHRlO0cMqr6w8+fY8PkA+GIljE6b5j6ZDuU7b5hUcF287tMWhzQIb8ZoPV6zYC4GwhgzWrpg+pWTWuhTi3jrdsx5rf9Bw9
/3q0O3s7CvZxPt+wWZmmBJCmwiRwtPpDN20BGS7iRUJzk9ZOKGtuDgxs8fYwlctXysTx9h0sZP/+HcsHGM2w9I+KCcGk2yizwAy57SidW4jN3NxRHbC834W9HaXew6E8
KFyZhSjz9mqxZkBAIA6Mddu7z97e8UrZtdevX2dmZePaBJ4BSMN2BaZrAsHhFGb1Q2DJuSGDBiMRhjidty3ox6x+xIcBJj7J8vs4Nc0F5UEUppCYhRYebO+Kmu/ZiRGQ
kXb+ioqKME+GxSCgsdNnzkNKJ0+egkfmaSHQLPSrzEImzl2wdMky3DjfSpy7LBcOYjUtfxi80Se1/T7Offu8HIMj2TZWUnKu4tefqxcMbyXOqbnDfzD6rv+RncZYVVvn
vHj/iO5GA+beiGu3jxOsyU6EbSEXLlzUjoyFSRUKApABZ2D5+o1bT58+C4+I4qkmLB6hzkvb6cBoSg7FkA+OAm8jTudti3p/z9LUCBPvJLl9nKvWrgfA2ek8W2ZcOaF/
9eKRLcRpMhqs2XPUlFfUqlrTR5aTVhkZTVtnXs/ax4nt7c/XmyrTlDACZafytbH5VYYYQH6wp7lKW0MajLeHqVy4cBnePivrAE8LQXTV3l7eQlx2Wy1qh+UhJugCtWta
dW4h5tNzRwDLA444rMO667o9S/ePBJbn3Uhs247ycY9NeWCYMgtR5u3VZc0dFGt6ojl5rOg4Flk8efK0srISjITLEzgHSo7brXCtPB0gOMxiqh+Cjp8b2H8AtuK2Eqed
zaqxP7JZs9vw9Z6xcgcgaJoLyoMoTCFfvhT03ADADBfM3rMVLyA7ZCr0H1gTN7+DNVeuXE1bCA4xr66uPnGyFKLjbCHbtlGsqcxCJs5ZsGDBIpz71UqclmvGsBaaU82m
DfsT2h2A4Obm4RAcwbYxijV//qlq+sBW4hyXO/R7o+/65lotk62q3Xh9ae/WxUFtxAnWZCfCtpDz5yXNmlAQgAw401g+WXoKZwu8ePkyLDySs5ocHXdDTXY77BlNyaEY
8sFYehtxWq8e166b+MOgdfsS2x+AsGLNWgCcnc7zZWsqR/SqmjWkhTiN/7T89puew8e/pFfVeq4I62vUujio5QAEnBz0fP0mZZoSGATo/2GjiJhYfpMjcBVkyYE1aW/P
YPn+g4fw9pmZ2ZwtBBFVe3t5C3GwNh77C6tdBSxv9E5qdwBC5xaycYIMy/1yrVfI1l1vur6sT+vioBbi/Oi0rTwwRJmFKPP2arPmDgdXN0+0T+EQ6XCy9DS4s+7jx7Nn
z/n6BWCqX9NAsd02K0YTkNGBJ7jCUN0QfPx8vz790CBqJU6zZSN++nH0ant6Va27+TSj7weu2RvT/uQgTXNBeRCFKST8i2CW2vi2+UlQc7mV2AGZImtB/yjWNNvq6xcE
pDEWUlR84s7de/UNDdev34iKitbUPPD+tm2WMBJlFjJh9vzZs+dizUILcZovHf3dz2PX2MkWB3l7bJnevduf69yj2AcgODvvcQiMYNvYiZLzFT/2qBzXp5U4R+QOMjL6
tlfulgXUqlr7+aHY/dmyOKjt5CCwJjsRtoWcO39BUNEKnBgUBCDjzFg2ls+cPf/6zVscn5R75IiH5z5NNYWFBRRr2tkzmpJDMeSDfFuJc9vWpaN+/G6ssf0e2araveZT
fjXqv9Y9ut0BCEtXrQHA2ek8R19zwK+VE/u2EOfSQRRrDh39klpVu+KNxfiVbYuDWk4OwpF7L9ZvUqYpISULQN13EhvIcB3AstCNYIo1Zd6ejWXa23/UmrdvbyHbrS2W
jfnu53HGO2UW4rdv64zu6AJ5xLAPQFBsIQNZFrJqVO7g742+7Z1rIVt37bggFLs/WxYHwUIo4qzbufleQIgyC1Hm7dViTexPBiT2uHrs3Okg84knmFBaeubJk2cNDQ2A
3LVr1xOTUrxkp1yqDn5+ATgADU4We1p3O7vSAYLDLIj6IeT4+T69ei9evLSFOE1XTv31+14zNtq3rKp1MZv0a/eplv7tTw7SNBeUB1GYQqJhLgzYKJjtai631E1A1oIS
57FjRZs3m+OcphUrVslZSHHJSZyXVltb29TU9PDhI+gd2u/UQmBFsKWo6LjIqDhlFjJ+9rypU6YtX76SJk6zVVP+6NZ31ia7lsVBrpunGP2KSU72yUGOjk72geFsGztx
/HzFd90rh/zeSpxDc/oZtWvkdvtuwsyF79qfHATWZCfCtpBz58Q+YkIjg4SCAGTAWQ7LUBNOBYF5f/r8GQevnDlzFuf6wmep1hSWrwcEBmO+xj8gGLt1GU3JoRjyWbRo
SStxblo9pY/RbzNN7elVtfvcTKd2N5qOGSz2yUGLV6wCwNnpUKz528+Vf/7RQpzz+4E122uq516LDeyTg3AS6Yt1Jso0pZHcVL2sWywLTZyMt++IZXj7Bw8etXr7GwJ6
+/YWYma+Zmqvbn1nb97Zsu7azXyq0a+Y5GSfHKTUQoa3WsjiYbn9O2B51qJ3bWdLedZZr7/nH6TMQpR5e3VZ09ZuJ8amMXXB8CVgRgfspEG4eesOzmiFQGnzqqmpeaHo
D66TfgFvHj9eGp+QtMvJmQ4Q3OGn79UPYcfP//Hb73PmzKOJc/3i8b936zXVeFvr4iBXZ5PJ3Y2mbfUKZR+5p2kuKA+iMIVEnQQAG5qHOFvyroUuAwogXCsVrImb37Fd
DxzW0UJoI8HJwC9evsIpo7QAYQkKLQSWQ7/w+fNn7OI4klegzEKwGghnV86fv1BGnGuWjvvDqOeUdZbM4iCnTRN7dp9s4cM6co/qYwWEsW2sFKz5v3+s+P2XVuLsl9P7
O5Yv7mE5e9qD3czJQS1n1YI12YmwLQRDLwJYiNaSgKwAZMBZBZbvlt//8KEC8qdLARJVqCmmjLg+7+ix4oDAEEZTciiGfGbNmtNCnGsXT+z5/e9TjK2YVbXOmyYb9Zxq
vp99ctDCZSsBcHY6z5euqfi+R2Wfni3EOa3XdjZr9uwbvn5hDXNykOysWhzy/tjBSZmmhJExKPOegy6BDDfyOECYushSAWvS3l4hlmlvf/XaDWG9PSwE40atTau1yyb0
Mvp16nprZt21s+mknt2nbPdjHbmnykJaiHNgTh82ln+ynDP9gUvr2VIyC6ndtuaeX6AyC1Hm7dViTT8/fxxdhhNAduywh09k+JKhTMjx+IlTdLh85eq9e/efPnteXV0D
7DGhorISR6g/e/78zt3yi5fKcG4LLjFGExXbvOgAweU++6B+iLtw46fuP02dOp0hTtYcJ3s7StuRez4+AaMmTFI/C/pNFIwp5HP+rAmuwgryu+a6DyiGQMR57NgxU1Mz
sOayZSs6tZDz5y/hXHVYyIcK/OFU/TYjAWXCQu7ff4Cz12EhGFyFkSizEGNbh0EDB82cObuVOFuHalmrauVODoIjcE3KZBvAiQs3Pvzwa4VRdxZxMnOczHYU5uQg6qza
j06b3s6Zx06EbSFnpM2aUBCADDjLYZn2hnRgY/nho8dYE1FVVc1WU2VVFY3lGzdvnz13saCwCGqCqBlNyUHs119/nzBhUhtxsuc45fZxys6qRZcCIk29fp+dzn0ndzRW
Krr/1EaczBwnsx2FOTlI1p/A7Sh3giKUaUoApvlU3Xxvp+6BDGci3L2bjLdXE8vKvD2NZTW9PdQNC2ERJ2sWnGUhzMlBtIVk33uh1ELaepyty8ew07ftAISW04xhIdfj
05RZiDJvry5r4sBYTFpgwl+ui8nGGMCG+0bogHFwJpSeOsMKZ+ENEU6dPoumJVgTqxLoACngjFmNwvQlK3r36q0mceKU1IkTJzuExmiUBV5GwZhCPn/Ou6+Jg3vumkkl
oDBC/OEqrk2bzHDe+tKlyztaCNtIGAthG4kyC0lMSoORKLOQiBMXfureY8yYcWoSJxaO9unb/8C9F3IG8HryTModq0mcnmaVY4aXZRxmJ8K2EIxtCiFRbaUBBQHIgDNv
LLcAGVjGWSJQE1iT0ZSchM33ev3a87dJk6aoSZyrVq5ZuM5ELpHi6w8oNalNnHX2az/80Q+xlGlKABFjQ5d0sCzQ6dNgTdrbK8Qy06Jie3t1sKza21MW8kvPKVOmqUmc
6JVucnCWsxCqBfz9r20W0hlx1los+9CrvwoLUebt1WJNX18/7InGCSCYDmH3Lzl7Q1AmAgZOscMP6KUDXE/e8w8ahbQb9wePHN2rV58Rw0cCkzNmzJw3d/6SxUtXyOa6
Nmw02Wy2xWIbtVEMPaGhQ//c5OiiUfr0yygYU8jnz/nteqwrb75rKq2AIvH+A2uamGzG0TBLlizjbyF0owohKTkNRqLCQjzSD/78088D+g3AUC3mOAE5rKrFdhSM2FNr
TzZtxpF7OJYPpyUsXrS0d59+QQUnOhrAyYs33g0aQYHt2x8rfvm5st+v1Bjg2L5VUwdVzR5WvWh09YqJNWun12yaU710csUvvz1y2C2XCNtCcJ8rb3FqMQEoCEAGnOWw
rNAbqtP2hZrAmlCT5z5vRlNy8jl4/8X0pSt+7vHzsKHDJk6YNH36zLlz5y1atHjZchzBbbx+w0YM72NfipW1LXb9Tp02Y+q8hYjSUVNlaQdbiBNDtZjjxOKgEb2wHQX7
OHEAAk4OwpF7OKu2esOsqllj8GZZ5mEVmuIrZZz7Iyks37NpbhTgbgnG2wuCZRrInXp7qHvczDnAMmUhEyersBD4mbFjxquwEGroCFimLQSLgxRYyAzaQj781ke1hSjz
9uqyplULa+7sOIyjUe+BESJO48XN75gLwTQkHeB6Cl5UaBoOP3jpEpeyeJP57JXGs1etnbNq7dzVVJi3et28NQjr5yMYb9i4c1dI4QlNE6ffR8GYQvJiTQyHYvnPnQ3S
CigS73Hao0ePbtxoCtbEHHNHC1FjEKKt48K2EFwxDSNRbSHRpRfNXDxk2jeG9lsNYJ3MANZTBmC8YYHxBvvgiIybD5QZQNGDlzdiU55t3PJiuTEVVrSGlWtfrJKF1ete
rl73xM7+bOnFjomwLQR35/J1x9qMDwWBNQFnOzvBsHz0WAnUBNZkNKVQzj4H89dY2bVpSobTuVCTTFM0TleaW3pn5qjA6fGbDx84u7eoidEU1NSiqXW0pu4GhuFN1Zri
JWbwk9SAjPJgXxnvP7Am7e0VYll9b8+0fYFoNb09y0IoIM/RtYXwYk0cCWRpZYsFcpgO0WhIFveLBgaG0CEnN492iJAgHbC4MTAoFA1MOsD14FQgCQYUjCnks2c8+prY
AX17nRQDCsbvD6y5YcMm3O2FkRONLORwTh522dMWkpKaLmchKamZMBL9spDSU6f4yVK7saEgABlwlsNyp94QLRhaTRGRUbiGmq2pY0UlUBNYk9GUBFFMF4mNZV6CfrRP
ikCGe6nme1Ed4+01xXLX8fZq9TVlcrTBaZO2tjuYkRzVU5jwhpmZWThXAqZZ++ED/j9+/Dg+PqHwKHXnCwK2iAFpmN3FQQd0gEEffVEhwYCCMYV89uwZR7B9qmq+bSzd
gOLx+CssPLp+g8l+L9+FCxd3tBCF0x7FJSdgD7dv32YspKqqCjaTfeAQYyGpaRRr6peFlJaW8hCk1qNCQQAy4MxgWSFfYmyWmWyGNywqKoZ2GE3hXpeY2PjjJ6gbvhCw
1whqwiZpRlMSRDFdJDaWucsad5hIFsv3HXkOHTHeXiGWFQ7aw9sfPHio63h7tVjT29sHk0PYuYURGDVG284AZpcuXfoq+3v35Il/v370Z/ylpqZhkTooEwHroIKCw3DD
FB1g0EUvKyUYUDCmkNxZ82Va863V0g0oHo8/ijXXbwRrYlpRnWUCmPuEJTBWAQuBndCPsJy0tAzaQtLSs2Ak+mUhJ09KmjWhIAAZcFYPy2cxAIATUmjVXMvLY7BcX1+P
kyvAuFATWBNqws1ujKYkiGK6SGwsc7f3e/bSBTKcDG5r4PHHeHs5LCub5AZlohXFeHvP//JfGCwfOnQ490i+4Xl7dVkT6yl2ObnY2Nh17GLKLYCEQzxyJA/b8irevkvb
suXAFvPQ//oPh7aYnwgJxZcIWFoOOWJLdWxcElgTt+PSQcqsyRTyKbe+Jnpyt1ZIPfDobhYWFmL1DVZRYhNIpxaCCY+oqBjaGIpCQrO3mIf81/8OC4GpwGbwJewHicBC
0jOyYST6ZSEnTp7k4bK0HhUKApABZwbLKpb80A4RGnl2527i8hU0lvMdHC9nH8CX799/SExMApYxbAA1oa/JaErKrMkUkqOsa+9IHcj3dnCsmiwaWJP29upgGd7+wIGD
tLc/6ODAePuTIaE0lpOTUw3P26vLmjhHG7fO0khTvaUE0x7Pnr148+Zd8pKlyX36XYqKOfSP/3o9NT3j//8vJ/0C8D29dR0+MS4+GbtBzMzM6QDWxF0WEgwoGFPIp0+f
crHId8eaby6TekAhuf6BNXHzO2a2aKQpccQtS37gi2EDsISjfv7R/+1/lKWkHfzHfy2DnfQdcGjJMnwP+4lPSISFZGQegJHol4WcOHGCqxTFiEex5i5n6sIDNbCMxg3U
8ehOeVSvPlmTppx2cz/8j/96wT8w7f/+l4spafgpTwZkuE6oCfcYM5qSIIrpIrGxzFHczyKlDmS4mhpq4oPbH1iT9vZyWFa4PSw2LpH29klLlib16XfOPxDe/qJ/ILx9
ge0OfH/z5i3D8/ZqsaaXF8ZerBwdKdZURJntFkBGREQ9evTkfM6R5H/451tFJXeLSi7+y3/gm2shYXn/49/u376Lz8EhYefOX8Qe9pDQCCw6pwMM+sTrKgkGFIwpJEfW
LLduvrlY6gGF5PpXUFBovHY9xujmzVvQuYVEUhZy7/bduP/+TxeCQ/H5wr/8xz2ZqRz9p38vyzmCb0JCw2EhmVmHYCT6ZSHHpc2aUBCADDgzWFa2WRbrfTIysqCL4uCQ
rF797l25ej0k7JIMyxcsbQonTMaHixcvHzh4GOu/oCb0NRlNSRDFdJHYWOZi7F8bpI5i2s+8SOZSO1kcxturg+XY2HiYweWikqR/+J/Xc47Q3r68qORGXAK8/d0rV/Er
jmY0MG+vNmtaWDo4OmPjI3uZAH1eAXNqAb2sLjAo5Pad8iK/gPx/+nd8uJtf+PrvRvhwJ78QzrEsrwCfU9MyIEfsYQdrmpiY0oFmTc7K1l5EFIwpJBfWbHjVfGOhfgQU
ldMfxZrGFGvOnTu/vYXggAvFFnI+rwAdl+t5hbCHl383up9PfSj7X/953j8QH3A5ESwkK/swjES/LOT48eOcRChSJCgIQLawsFQHy7FxCdBFjvG6UuP1+HDfP+gNjeXs
g2f++T/wAeHgoRwsC4Ka0NdkNEVTlEhVUjsbmjWZQqodj/Ui7ufSCyzfXs+ldgxryrx9Byyr8vbgSMbb3wOWr14HfRqqt1eLNffv98IeZByXZW1tq/CUH/YeO3//QNzB
eTwo5NQ//73s3AV8psPd1PT7//bNpYKj+IxRXPhEHGAfEhq5YeMmOsCgS6WHNBgSCsYUEgf/a2yObwuab8zTj4CicvorKChYs2Ydehs43bBTCwkKDoUNnM0vLPmff7+W
ms5YyNVzF57++7cXZb+Gyvqa2QcOw0j0y0JKSiTNmlAQgExdddmGZcWbZWV77KKhiyKbHRfGTmDUhA9P9rjd+tf/jQ/QNc2aUBO0z2gKQJYgllEkNpa5WPrTMP0AMhzO
x0dcKtjczHh7dbBMe/uTMbGl//z3q8dPynn7iwcP45uY2DgD8/bqsiam0O0dnFqRJt97aLcLM4pa7HOq4OjFP/o+nT3//PGTeLxyKOft2ElPx07EZ6yhTc/Ighxx82Vo
WCRWkdABBn36TbUEAwrGFPLJkyca2+Kj/c3X5+hHQFE5/YE1V69eiysycDqPjDWVOmL4YuwtoddRn54553HvAbANfIadvFix5sN//HC24Cge6RHaAwdzYCT6ZSHFxSWc
RChSJCgIQAacZVhWoCY2lsPCIqCLk2kZV//Xfz62sqUXQ15Ny3zfZ9BtSxt8TkhMxgJarJqGmqB9RlMSRDFdJDaWuUj81hr9ADIcDtcWMFiT9vZyWGa6RmwLwQYkCsjH
T174o++TVm9/seDoqzkLnrV6e1yNYmDeXi3W3LdvPy1HK6sWpCmUIL0LEw4xMiqGuoDTPxBjszjc6OWMOfj/rvfA02kZ+N7LywdCPH/hUmpaVlh4FI6+owMMWrKBKSQX
1ry1qvn6TP0IKCqnv/z8glWrjeE3cdBoxyFZ5lwL2kIQ9nv5wBJK0jIe9erHWAh1BJp/EL6n7QcWcvDQERiJfllIcXExJxGKFAkKollTNZZbdv6kZRzOOQJdnLPdgQYN
IExjGf9L8grwfYhsgcKJk6ehJozQ6pemNJb4p0r9QDHtbXAOA6c/xtszWFbt7WNi4mhv/7xXf9jGsyUr2N6ebv4amLdXlzW3mFvstN+FzdFy5yQxDpGGGb3IOJq6CTo9
J7egICXjur0TQtke9/zsw/gmOCQce3ggREaOq1cbCx6w9g9B8GSR4OPHGvY1KaRN06eAAmv+B9ZcuWrNXvd9OEi9UwuBkWAJCSwB9nAk+zBsgzaSYykZ+AaWEx4eSVsI
zZra0COupz5yJF8bKRcVSZo1oSAAGXAGllV4QwbLfv6BBw7mQi9FcUm0mi7u98UjgrePP/acQE00a6LNpA15Qk1QljZS1tjMPz7UJyDfWq5xBWURwJq0t1cHy/D26Eoy
3p7GMuPtsR8pIzPb8Ly9Wqzp6bnPbMvWHTsdLa2s5c48Y3oPNF8yITQsHPdGpWccYALGcDDzwQjxwsXL+Ck8Ihp31QoeMPuIIHiySBAnHGlmi3UPm69N1qeAAmv+l5+f
v2Llare9njNmzGJPcjOn/LAbVbSRYJQe9gCrYBsJbAajgjTMYCGHc/Lxqzb0iDPWX716vXu3s+CJFxUVaS4/8WJAQQAy4Kw+ln19/TEmJIdl3L+YX3CUVhPG5PErWFNw
YUJBUBOUJXjKSFBjob/J0ycgw+1w+mO8PYPljmNFTKOKxnJiUqqct4c9eHv7JyWlMFg2JG+vNmuayVjTkmLNjv1LNmWiP04HdNtxz7uHx34//yA3Nw+MgANdNMzokJF5
EFcl4BY3wcOuXU4IgieLBDVmzZobzdcm6lNAgTX/o1hzxSqwJi4rUN9CSktPY3gHtgELgZ0EBgbTfRfGQnJy82Ek2tCjickmLGTQRsq4alRz+YkXAwqiWNNsK7Cs0Buy
274MlrHkx8fHb/9+Hx8ff/xne0OaNaEmsKY25Ak1QVnaSFljob85ok9AhttpeKlxHZubKdaUeXuNsNylvL1arOnh4bnZzByXvzNIY7oOCvmSARv9gW5usL0hkHbx0hXs
xsNBXLi0yNXVXS8Cdv7Sp3Fq8Pcmt/nqOH0KKLDmf3l5+ctlrDlt2gyFg/aML5azDdUWknukAEaydet2vTAPFNLJyYU+WVeyf1AQgAw4c8AyA2Q2lgFktJOgJgy5o/r6
oilsvNFYR8+i9QnIcDt1DzSuY3Mz4+0ZLAvl7RMTU+12OOiNhVjb0SfrdvxTlzWxfxmX5+F0ZmVDssq8IeY4U1LScCg304EAzOiA3XgI2Hzi4xvYMSBHECoCuiC5R/KU
BVxQpVFQkVSnPz3jcCU1xZqj9SlwZc1ly1e6unnghnBNLQSD9rAQLE/vaCFH8gphITh/RKGF7HJypi1k924XiVjItWvXOPgpMaNAQQAywAUsq+8NQZPoUGI7EDSF9UFy
mgJr0lgODYvqqClfv0BaTQjopEpEUxj41VjsD/boE5DhdriyJu3tOWCZ9vZJyanKvL0yLEvQ29+4cVOZhajNmqZbbO3st1tay41oow+hovfg5xeQmJj45csX/AdxMnyJ
DzhTDasMVATobPPmLQjox6iw7zGjx2oUNIYKzwivc5rLRuhTQIE1/4OOli1bibkuaK3jFKYKCwFlOju7fPz48eLFi1h4ImcheflHVVgIura0haB1rMcWorm0+cSAggBk
U9MtmmJ5xw576Aiagr5Kjp9kNAUgo52kQk1Y0kWrCeHhQ1Wz5hoBGS/zkQOXuPdd9AnIcDucWVPm7RksKxy0Z4OaHoRAo4rx9iBOA/b2arGmu7vHJlMzW7udaJ+qKUFa
jrg68dWrN3RITEym5QiY0eHgoVwVYcqUaa2smafCxCdPnqpR4IIWPnFeH24uG6ZPAQXW/C8vL2/pshVgTWit00F79kAfGqdPnjyjLQRXnchZCNabqLAQt70etIXAPvXY
QjSXNp8YUBCADDhrhGVq7V56Jq2m8vL7ySlpbE2dOXNOhZoOHVaXNTUCMl7mIwcuce876xOQ4Xbq7nOoJuPtNcUy29uHhkUYsLdXlzVNNm3G1UIM0lTPTjHTHp6e+zOz
Dty4eRtLCYA0hi8vXS5DOHQ4T0UAKtRhTSz00ihwMCNeUV4far4yUJ8CCqz5H1hzydLlLnv2Qmt0u0qhhXSc5EabFLYBC4GdeO7zarMQtKsulxUUFqmwkL2tfU3VrKmR
eeBlzWuvTzGgIAAZcNYUy9u2WeJc/stXrlpZ2+CWXDaW0U5SoSYc1q9mX1PqmrrvpE9Ahtvhypq0t1eN5Y6T3Gxvj/Np5bBsSN5eLdbcu9fdZJMpjnvett1STb6kx7Ux
dANXCLeI7QRylAmfSO/6UhYmTZpCgw33RqlwSziYX6Mgtod7daj5cl99Ciiw5n/Q0ZIly1z2uEFrqgftOy4Kg23AQvbt80KXpcVIZI0qhMKjJSoshGFN2KceW4jm0uYT
AwoCkAFnjbCMfgOY0t0d6yu9cESwnJrOnL2gGstqsqZGQMbLfOTAJe49R30CMtxO7T0O1WS8PUxFzbZvV/P2arOmiSlWnaG92VGOypbIyvXQKaS1ekO0WBGwQlJFmDhx
sjqsuXTpco0CBzPiFeXVwebLv+tTQIE1/wNrLl68FKwJrWlqIexBe8ZC8AEWcvRYiQoLUZM1NTIPvKx57fUpBhQEIOME845YVrhEll7urhrLaCepxjLDmg8eqJrXlLqm
cBm1fmGZM2vKvD0HLMv1L2k4G563V4s13dz2bty4ycraVg5pqvlShTek5Yi1HirChAmTWlnziAq3pOmhIWJ7uFcHmi/31KeAAmv+d+TIkUWLlji7uEJrHZcJyO07klsm
INdxYWAGCykqPqHCQva6t6wGgn3qsYVoLm0+MaAgABlw1gjLKrwh1ASNq8RyoZqsKXUs39upT0CG2+HEmoy3V4ZlZn0su0XVpby9uqy5YcMmHFxpYbFdboOd3M4tBc3S
1v4l2xvSR+PnFxxTEcaPn6gOa27YYKJR4ONxuMSlWPMnfQpcWXPhwiW7nV2hNY0tpMMgBN2ogoXg0AMVFqIma2pkHniZi5b1Jw4UBCADzh2xzM0bQk1wAiqxfJTFmqp2
EEpdU/d26BOQ4Xa4sibt7blguWt4ezVZ0239BhNLGWsq2+msJl/S3pAOWOuhIowbN4EGW26uqr4mA0g1P4jt315lN1/6QZ8CCqz5H3S0YOFisCa0puJci04H7Rm+pC2k
pOSkCgvBNButdDc3NxVFVtMwmNc0r70+xYCCAGTAmT+WGSDDJ6hQEwhVTdaUuqbK7fQJyHA7teUcTBNoor09TIV4e4UCVIs1XV3d1q3fuN3SBtfyKTzlR1NvWFZ2DaHw
aLGKMHbseDZrNjV9ev36DcIV8K4s4BR4BM99PtEx8alpmenpWapDSmoG3qRjFRQeoxO5ees20kTiHMxLrSggoYvf6VPgzJoLFjnt3gOtCWIh8MiwkJLjpSosxN19H20h
sE9aF7SFQKe0cqFl2kJCQyOh/U4tBFaEEzVpC0FgLA1p1tXVqaVuyb8EBQHIgHNHLKs/cs5u+0JNFy5cUqEmEKoca9JYfvr0WUcsQ/6dqgkvJCenQae0mnC7J53O/fsP
kKwWNXDXVp+ADLfDiTUZby8Uljl4ewbLjIUwWJaCt1ePNfe44uY8bItesWKlwmEc1dMechijhYhwrOi4ioBdzDTYsIj56dPnx46V4Gb5Y7iXEbdNnTmH6Hfv3kPAB/ob
JuAdHJtJB+Z95teOEYHAsrKr2gLby6zmC/9bnwIKrPlfbm4u1jQ67XaB1jgP9DF9F8ZCcJmGCgth+pq2tjtgIdev3wwMCs3LK6B1jWLQFnLz5m05CzlxopSxEOZ95p2O
EfHOgQNclhZrLkitx4CCAGTA2dTUTCgsIx0VasLVgQxrnio9DU3hVs6MjGxogZY5FERrCunIaQqSZzTFvM+80zEitgy+f/9eW0K8a6NPQIbb4caard5eGZbV9/Z021dS
3h6Gx9/bq8Wafn7+8+YtwAHKY8eMCwgIokJgWwgMDGoNwTj9riUEhQTKQhArBAeFtITg0ODg0LT0TFnIogO7jZmQkDx61BgabBGRUZgT9fDcj93ZOEQNV9gg4NIG/oFO
ymKbZWxsXEND4+fPn4XHG8Wa/6ZPgRNrlpSUTJ0ybe3a9dAa9pAIZSFJSalsC2EbCbb/Llu6nLaQHTt2wkLi4hOhSmcXN0at/C0EJie7IM8WHxoaGj590oKFCG9zqlK0
trYBkAHnCeMnymGZBWQgWh7IbCy3ARmIDg6NiIhSgWVvbz+GNQsKjkJTuKSMATIEy19N0DvjFo4ePdbY2ITzyISX611rfQIy3A4n1kxLS6O9PbCsK2/v4+uvPW8fEhLK
09srZc2vX7/C+HCAVnV1zYsXL7dsMR85crT4AZtt6YUGDg67sLdBSwHIf/bsxcuXr16/fvv+/YeqqmqMyEGymmLvy9evnz41NdR/rKupqayoePvmTc3t8Obz/1OPQtWN
4BfPn6PkKD9qgbqgRqiXQh/05cvX+vr6mpraiopKnJ4ovnkgR9xQhtNnYCHoaGrJPJDs1q3b0EkCEHA4zrt3Hyorq2prYSENWmlpCe3vYcbAMkwahv38+QszM91gOSAw
hMYyVvBqT1MYFaCx/ObNOxrLcGKoPhya+nL966+/KKE1UQ6wprq64sMHDP03lm3UIyCjqK/Li16+eP7u7VsKy7W1smafYjmgvrBk2tt/+FChKywz3t7FxU17FuLl5cN4
exrLmnp7xayJNjVETHvDt2/f46TjBw8enTx56sSJk8ePnywuPo57YTD4efRYUWHhsbz8QhxDmnskPyfnCDXTcOgw7hzOyj6I014yMtGJpDqUKanp6Bzg/tKExJT4hGR0
CzDcirvDoqLjoqLiIiJjIiKjcYcfTn/GdEVIaARuAMcVCgi4gSgzC+FQWnp2eHg07uOMiIyNjIqNjo6LiYnHWcBx8UnxCUmJiSmYEUlKTkNGOJgNnRIccIrt2NnZB1GY
Q4dyDh/ORfFQSIz55OcXos2LXduoQnFRCapz69adR4+ePH78lMEbTAcGBDPCHAxMSgXegEbYoow8aioqKl6/fvX0yeP798pvXr9+6cKFW6cSn5Tueliy494xqzv5W2/m
br5+aENZ1ppLGcsvpC46mzT3dPyMkzGTj0eNL44YfSz0z8LgwflBA/ICeuf6/57j9xufgBSQDlJDmkgZ6SMX5IUckS9yRxlQEpQHpULZUEKU82pJzJmTJ1BylB+1QF1e
v3oFr4HaoY4dUQcjgeWBS8AouPmLsRBIlbEQHIwHsR/Jy8/JzcPZ31DHwUOHsw8coowkMzs9o81CcFQQjESZhWD8raOF4IZO2kJwenirhcTAQmBasJCY2AQYCSwEoxey
63MZC8nEBZ8wUVgISoJhQJguLAQlPKLIQjC/QlsIuFOudaWpR1bfd/N/E6YLA4biaG8IIgGW799/SGO5pOREK5aLAAeAolMsp6ZlpKSwsByfRGMZs00QOMQOLENNLCyH
01gGbBk1AarQlAz1rViWqQlYptQkw3JySnqq2ljGIHCRDMgIDx8+hqZwTOPz52jivIb7ghODlcqst5OhArrVSzPlh/fvX718CZXfu3vn+tWrF86de3Aq4MlJhwfFdveO
WsqwbHrt0PorWasvpS87n7LobOKcU3HTga+SyPFF4aOOhg4rDB6UH9j/CLDMD8hwArn+f+QF9KWwHDLkWNjw4ogxx6MmlMZOPR0/82zSvAupiy9nrCjLNr5+aOOtI2Z3
C7fdP2b96PjO8yXZZ0+VXr508daNGw/u3Xv29OnbN6/bGPTzZ3ZLAqbCeHuITpm3l2FZqbdnY1kb3p7Gsg69PQ1JVSO0kCkgBx4GG6PVhn4Y/AV4Bb4DdgkeBfzu3X+I
cynv3L13+/bdm7fu4Gg0TC9dvXYDY9mYzsRoDJYYYLoC6yqxFRonb+G0oNJTZ3F/wkl42JOnjp84hRUfxSUnsTMPTEyRsWyyE9vbmcBMmchewGsn8D5iIS5SQFJIELcu
0Mef0gs46c1DKAA1pH71+rXrN2/cuIXioZAoKgqMYqPwqALjCpluBEynrg5kiUEetRqnkBKaaY2NDWjNVVWikfEGfbVHD+7fuXXr6pXL58+cPllSdDQ/L+fgway0tOT4
hJiIiNDAQD8vL083N+ddjvY2NlZbt5pv2rRh7drVy1csWbhw3uzZM6ZPmzhx4ugxY4aPHMEtIC5SQDpIDWkiZaSPXJAXckS+yB1lQElQHpQKZUMJUU6UFmW+evkyyo9a
UP3Ot29QL9QOdURN5ZD26RPllNGiZ5wyIAefBcHCf0HIlJHce4BZq9t3ytE6abOQq9cx7UHtg261EOiOthBok4eFUEbCthBYGm0hSJmxENgkbSHU1EurhaBsKCHKidKi
zLSF0F4YZMl4YdQUHc3GRo2HIvizIOcU0HOCSaPYwDLTykGlVGH5xi0Apw3LsrMOAC4GyzI1tWiqPZApLDOw7YhlGumMmoBlAFmmJgrL9J057bAs2ykPLKMwcC+qsSzX
jaivb4ATU7OjSbWAP1MdBli7bKzoNZgGdnD75s0rly6CgU4UHys8cuRwdnZGampiXFxUeHhwQIDP/v0ernt2OzjstLbebm5uZmKyfo3xymXLFi9YMHfWrGlTp06YMH7U
6NHcgIxYY8aOmTRp0szp0+fPnbt00aI1K1aarFu31dTUets2Bzu7PU5O+/bu9ff2DgsOio2KTElMzM5IR9/lWEF+6fGSC2fPYl6x/M6dx48eot/5/t3b6qoqqvNN+bcv
7P4A7e3xE7Csjrdvh2XZine2t2ewLGVvT7eoNPL2nbOmQojKSOILfCXVIsM4ZCVEXAE2hU9hQAhHQ3Mq7THBUnBDFLPeKQdvQdw0v8L6gQEEgJPGJwXRq9cVBvpXBLxJ
x0J0KpGbt5Ea5exu36X9HUWK9x4wvEh7Pbr5CUS9efP2AzrlldUoPOABQ5FjAs6OiY5Idz1p4MFA3797hxYremwP7pUDe+DRC+fOnj55oqToGCgKxn0wKxMIBG/FRUcD
hGFBQYF+fuAzL1zkgf3GLs57du3a7WDvuGOHg63tThubHVZWdlaWttu30wGf8Q2+x694B2/ifcRCXKSAdJAa0kTKSB+5IC/kiHyRO8qAkqA8KBXKhhKinCgtyoyS00M6
nz+r63EYuUECAKTMQqjB26oqdMEr0epXaiGyhpcyC6GNRFMLoY2EshCZkbAtpKXZ1GohTOOJsRAUFbwIdpENNtSDbGAhaEKpHnLgaTY6iY5KyRp8GLxtwTL8CN0yBlho
QmWwDEC1w3IrkDtimYGqaizTOmVjWU5NDJZpT8K0YOgeP8zp3TvK69FYRiMGJgdFff2qamRIfTkjFbrriUYhTaIY6gTxwJvcLy+/deN62eVL58+eOXX8eMmxo6DS3EMH
szMy0pKTk+LjY6OiIkND0SQN9PP13Q9SdQetujo7o7XqZE9h2R5YtrbeYWXZhmVL6vMOa2s0asGFMiw7gBH3urgAy96enuDFYH9/UCMG3OJjYsCOmWnActaRw4ePFuSf
KC46c+rkxfPnr5eV0e1d8P3rVy/RY6Zosg6NvAbKiDUZpqa9GcvbU1gW39u3YVlzb4811Qq9PU8sq7UaSH1Tk3sThcMf40ZBUYAo7BtThmgDwhzhlegA3DIBLWK5wP6V
iYLoSAR/SBDJMvyH7Oh8eYqGc61VRKRLBVIBG6HElChaMQn7xmwiDB3dO1g8eB5+AuMqgCiailS7AL1l3PlGu5n2Ad/jV7yDN/H+/9PeGbu0EcVx/E+J4GQgQ7dOTlLS
DEFcO1ohY/eEuHQTLHXp1EaQrsati3JzLZkqGK8qdZBQHCQeQaQE+3vvzpjES7zT3Evy+pFM8eX3u/f5vZ/f+/3euyifks+KBbEj1sSmWBb73tWVUBaPPi9fEccL6m6F
qEUif/UkiAGWa1kkcqX3iyT6CpGR/iLprBC9RsTwjbgQR/pnQldIEqtuJDYH53JPmJ6XyzqVdS5LjnTHaSRTGK2RTi7rdatzudXy9VXuO6VOlRtQlctnZ1LniYzJXemx
e+Tnstykiu6GJfJP+ZUMODo8VLn8yz05Of59eiqNYsllMSfbJdL7CXK51fJzWfx3cnm0c4xl7WEuJ/nXXt3L9mTy0H20WBN5dHCyqvmoewZAAAIQgAAEpogAqjlFweJS
IQABCEBgzARQzTEHAPcQgAAEIDBFBFDNKQoWlwoBCEAAAmMmgGoaC8CFU5yfTc3cv/IVN9KzLddu5c3sXNlp9oxuu5XF1HzJuQgm0HRKc+nFSj2SSWOTxhEE7COgcq0r
kVPR845ctmE1oJrGoohqGkONIwgkSQDVTJLu5NtGNY3FSKtm1Pqy+6q4PzUWIxxBIAKBp/d1yOUIeCd+CKppLEShqqmzKP/J2X2fU83b/KpzHrRY240fH99mUjOZ5bUv
xXycDm3bc6ulbHo2lc4Vq67n22u6uxsrqq2UL1XrnnrHd722/bmQeYqWG+OGIwhMGIFw1SSXJyxMiV0OqpkY2n7DoR1anWkLr3OdbZJg//Kytr7UswkafV+zXd/Mi2T6
+y7p3Pq+d9v2ahtalf3X0ofaZaCavmtU09gqwJEFBMI7tOSyBaGNNAVUMxKmUQwarJpBiXlzXn2X8Q/46JvZXHm3IYWid7C5/DJGralU84U+FqQNKrn9I83hTKGqy1h1
GZmi0/Rrze7qdhSTxAYE7CcwRDXJZfvDP/Tb2/+D6Zuc4uAO7V0d2TkW23s+NvZeSLux/7Wyte24uhMr3ybZXX3qclMVl+FmTRLBFwSmksCQDi25PJURjXfR1JrxeD1j
tCnV9Fyn+q3WuJH/Sbu3Xl6VXUxU8xlh46MQ6CdgTDXJ5YlcfKimsbDEUM2gQ6u2JKVSPNsphHRo9Rg5K7QlqiiHfeqVQtDdVRo5v1I5kO3MplPu79B6+x+yfv+WWtNY
6HFkF4E4qkku2xV7NRtU01hMB+9rPujq3N52nwZKv8ouaPHr+wKDBwaDMf7+6N3ZH/Xm357TQMEwVNNY6HFkF4Eh+5rksl2hDp0NqmksyLFUUw4B1XfkgRP15Enle7UY
ppoyRnqw6ukUPWxjz20Gk2mfO2X12dlscaumThTdP3kyV9is+8NQTWOhx5FdBOKpJrlsV/SpNW2LJ/OBAAQgAIEkCVBrJkkX2xCAAAQgYBcBVNOueDIbCEAAAhBIkgCq
mSRdbEMAAhCAgF0EUE274slsIAABCEAgSQKoZpJ0sQ0BCEAAAnYRQDXtiiezgQAEIACBJAn8A2D9A7YuCaOdAAAAAElFTkSuQmCC
                </image>
              <para>
                A multilevel gateway enables access, based on authorisations, to data at multiple classifications and sensitivity levels.
              </para>
              <image>
iVBORw0KGgoAAAANSUhEUgAAARIAAAHYCAIAAAAOJvCmAAAABGdBTUEAALGPC/xhBQAAf9FJREFUeF7tvQdYVMnWNjr3v/c+98//DV/+zvmcM+jM6OikM+bsmAPmhFkM
KGYUJSsSBCSK5BwkSVCSBMlBURQVETErigEkSlCx77u7YLvppnPTdEPxrIdn1+6qVVVr17tXVe2qt/43Ho/3Df2jFqAWkMkCgA39oxagFpDJAt/IFJtGphagFmA6aNQK
1ALUArJagMJGVovR+NQC1NvQNkAtILsFqLeR3WY0xaC3AIWN+CbQ2ZhtPmrIt1pdMm67U3pVcyc/zbtskymjTLIbhRU0ZpsOZ5N8qzXXJCi7qrkrmuhUMrdFJapC3vya
DjfPbiS1o3/iLEBhIxNsGDB0Q0Vq2DCQG7cr/hm/PSrY1rmNW0FVAhWnsJHhTUFhIw1spphmv2PiNZcH6Y7TkvhK5nubbnR1NlfFm84dITmVVE+t7xp332mWqmKaFYnC
RnbYaAdWMY5Dgrfh9N86m0vd5g8h2GNTtVUFrtPSdojz1xvFKAS60p2BySEj5pvEd/cDG6sy3bYz/T1t0/jKZtKPIt1FBrpvOL3EjprScAaccIa6bper+D3Hzsog7d+W
+KdfNtdmksy1yq7pILXtrClyI3mZhwYdJV1NChsZkEthIw1suAMV8wTSKGWADY/H+J8RSwIrOwVgM3PefKACsGksceY3er6MmO9UApDwwcZmvS6o6oMo2HRWBS75GpOA
qpPAZvbcmezYrAvJzdy82G4nhQ2FjQwWkBE2Q8ZtDyznj++l9zYENqTb1tPbDNG2yH6JBs4fjh9IeAlvwDZfxplozXUrxQwEv3Mo5BNYVcxFtzPpbK4M3T6c79kY2Izo
ut/5LEGPdC8/8bHXlS8/MikYhY0MjYZ6G2lg0z226ay55rpt1BC8+Ns4sOG32q99p04OSLqVi/I2XcMkfoeN6y6QReVNNPrunh7p0TF9Oc58Vzds+PD42idkgz3u8zUw
2X3ovuDPUHyNQ2FDYSODBWSBDZoZ0x0SGKVIhI3osY1MsGF9RVcqChulPWZZFVFvIxNsGisD9UYJwkZIg7iZtJ6dtC4AcDtp9aVOy/iOhdP14nex5Ouk9fBXXztpy5xL
6xln8zJ+F+2kyQoaupRTksUEPnfyB+hkvCFpbNOz0yX83YbtNfE7Sz2G6cSbCUwJkIbe+3cb0VMCPbt5BKU985o/9zc6tpHUDAR/p95GGm/DTmdhdji8tGsaV+rPnb2v
EugJG4CkawKanXJAwQQmoBn30MvYhqmBqAno3mDD5MX/lMRMb2QmdK11oGMbGbBDYSODsWhUagFiAQob2hKoBWS2AIWNzCajCagFKGxoG6AWkNkCFDYym4wmoBagsKFt
gFpAZgtQ2EhjMuHFL+y+AGmSSxOHrCXjL+uUeZ8YO0/NXT3NWbvALNvRNg3EXjlWNTcJO6UuTTlpHDqTJm0bUAFsulu5zLDpeBl/gLP/FHsBMmu69zX0/OT67Si9eKwb
xUeenknY+9Kag8aj3kaGNsD/GE/W/yv9T96tmtxlzjyy9ufrStOve+OaKxNMsOtGaGU0vpNmW3XvBVJ6pQasQgobGR5tD9iQTWBO4QG6U/hA6qgp8SRbyixi/Y99Xbrf
20axrkaMdTpk9w6nQ8V4G+HFAQJ72r6WmbO0lH+TlKp7Y0+PLaX8NTU9Ny/wk3xdnS2DKQZ5VAobGRqAMGz4m8Dgfyoae2wpA3jY97rwRrGeXT5mhRt/aw3ZOKDtV1rC
3Z1GlqLxk7B72r46O7JkjrgX8sdHILsStMf+bfYn7O7MtNDWcyvh9+bon+wWoLCRwWZCsOneBEYaa9euY84q6d43ivF3vPDHMPwFyL1sQ+gehPS6p41bYIGFbdyf+EUS
hs3XO41V2RfjnMwtAuOzu/arymCKQR6VwkaGBiAMm65l+T03in3tOPW+UQxwwc7/wKDYXM7UVo/NMz2G8gzARMFDLm/zqab0YnxiaZerYTzP3DVkHwH9k9ICFDZSGoqJ
piTY1OM1z2+1GMO4m5oTwg35YMPdNsevyFegCnkbdmwjajeoDJYY7FEpbGRoASJh09VJI/twyPTu1zkroY1iTCdtlG5oJSIzw3HRnTSmoZPxvejOWI+ZNO60WE/YcGfS
urTpBVViNqLre1HvPIky2GZwRaWwkeF5i4ZNzy1lzNhdDGw6yZ7K7p6YAGx6quLumu6dn03URxiBz518hpqu7zZdmzo5XcFusgQZjDGoo1LYyPD4RcMGShqr4s0Zfqbh
ekFXYrt8iKixTdfXEv7H+xAyn8X9btM9AQ1VjEPAn5ihPz/rLjo16VcJsDvVUOBtzpks164M1hjMUSlsBvPTp3WX0wIUNnIajiYbzBagsBnMT5/WXU4LUNjIaTiabDBb
gMJmMD99Wnc5LUBhI6fhaLLBbAEKm8H89Gnd5bQAhY2chmtvb29oaBwAImf9B3cyCht5nv+Dh48yL+eUXCu9cfOWRktuXkFJSemnT5/kscIgTkNhI/PDb25uuZSWWXGv
UuaU6pegpaXlclbu3bv31K9oal0iChuZH8/Dh49ycvJfVL+8ceOWpsu9e/erqh5euXpNZisM7gQUNjI///tVDy5cTE5LvyxGEpNSub8KBM/HJnB/FQgKREZM4Tvic5fp
15TU9ILCYpmtMLgTUNjI/PwrK6ti4y6mXsoQJYcPH9FZqwNokQient7jx44LC48gQVc3dyw9xn8SxH38iiQkiFSrV602MjJmlQtoE5OvfD8lJV/KyyuU2QqDOwGFjczP
v6KiMio6Lik5rVexsrIlC/L1duohQmhYBAlOGDsuLj4xPDySXa6Pa0TAfXLH0dEFQd2tuiTo4OCIoIA2UZmS+3EJid5BgcanjtufdYmIOS8+MvtrwoXkrOw8ma0wuBNQ
2Mj8/MvLK8LPRaPj1Kvk5haYmZpt2bwlOysHEbKycgP8AyZPmJiVlZN6KR0Sez5u6eIlFy5cTM/IQoTioisInnU/i54SgkVFV5AWGqAHQfy3t7NntYnKFPctnWyHrfjt
my0/faP3CyML/rrh8LbY+AtikpCfAOaMzCyZrTC4E1DYyPz8b98uDw45h5e0KCkqvgposb9mZGZXPXiItzu5gwsEcZMNPn78BEnY+EjLDQpo6zXTozZm3yz/zjDpVFlN
RVXtE0jc3bRvjoyetW1R9Pl4MUXFTzHnEzAxKLMVBncCChuZn3/ZrdsBgaF4SauJhIRH/KcVf9t/yfj9h4dcia2M/j8O/br9mL74cqLDmZKSJrMVBncCChuZn//Nm2U+
voHnYy8UFBQ/ePAIL2xcc8XF5cxhgyPsHXt7x1UrV53DaIMfDWnnzJpNNEBwf/myFYjDxt+//yCEDQpoE8gLwT1mBt+Z/uZbZn3/TYKA/HHuz6HLfxVOgju3bt2BkAIk
JqbIbIXBnYDCRubnX1p608PTNyMju6bmNQTfPaJj4llxdnYjY/ojhw1x09nlDAnqrFkbFh4VGBiKeTME8R/XiLBi+QoSATER3L/vAAkePWrEJO+pjZsRe629a9Wq4Imn
izcUPbLmSuLdY7svz8Igx9PfXyDhlSvXSOGvX7+BUiVcSJTZCoM7AYWNzM//+vXSM+6erq5nk5KS0fLcXN0io2JZuXQpHSN4zAEkJSfjJoIY3wMGkRGRmFyGnHFjgISB
fnxCIiKEhIQi8oH9BxATwfT0TAShgQQFtHEzYq8X7Vp5MHKMQ9FU75I5kWWLY24thQSXLnAqno6bgI2zh7tAQgsLS/jMp0+f2djYYpwWG5cgsxUGd4LBCJtPVVUfy8rk
fu4lJdfgGdC3sTxpY3jE8KyHN665UlJyHR4p5nw8uYnZsPLyu0lJl0gQFwjiJgkiGiJzg3fLK6CBVSigTSAvBHcZ79/j+lP0zXHCEpA/GrARToI7Bw8egj8MCgbNIZxe
rNzW+Fxd3VFYJHdyDU04GGHTFp/w/i/D6ifPaA0Nw1OX9clduXrV4bQz+jak00Uu+lFOn3H9ae1/ZN8ZWXR/1N0n31e/HPLouVbJg58Q1LPW2mSwXVTZSOH9/IMjI6Nl
NUJnXV17ekbDyjWwZJORiazJNT3+4IUNnjcRPHu0ALQDKZ9lcfGVU3YOIaERouTkSZuDBwzYX13dPA4bGLJB/4Bg/d178Z+9g8iIwwZtbe2ggQ0KaOs10x3H9qw9/Jfb
Ff/W/v6/8xq/+Vz/n1+/+mefiL98t+xnv8CvGfWa1sc3IPxchJR1/9LaCt8CnLDWo7CR0nQaH414G2FBa0CbQMsQX8PCwiIra1t0b3oVS0trMqbfvXsPIri4uI8fMxbB
Q4cMEPT1C1y2dBmCa1evwTXuIBozQzBmLGIiaGd3miSHHgQFtInKFPe3H9VHf8zA6l+jYv/BxeeftXf/+9RNc5zcGZ3ixdPLLyQ0TOJDRbe2xcNLlN0kJh9gEai36QU/
aB9iBj8FBQXHT5zEp5teJSoqGmN6tHsfvMYDQyOjYrAIAEFMDISGRkAw+kcQg/7IyPOIYG1lgyDiICajMCAIQWgIDg5BUECbqEzJ/TOeXgbHj+mbHIQ4urmJj8z+irFZ
UFCwqGaNTiy6sujQ9goYcpN20pT5UhBjaI34SdTgJy8/38z8OIYEvUpIyDlMteXn5WNdM4lQXHy1qKgYC1hIEBdJiUlsENHS09IRh/yK5AUFhRBckKCANlH5yn3f7Yxn
QECgwIPnDl004mGJKaQy23S3rj70Nppubrb8jXr63J5bbm6ekbEpvleKkqDgMCxa4/4aExPPDQr8KhBEcggbX1ibmKzl+MnF1d3X15/btkR1xjT0gVLY9NKh6tNn2XzK
Xri3lpOTc+jQES9v/4EhDg7O3t4+Am1Lmr5Zn1peicopbFQEG7gXMXMDr1+/2bZth5GRKdYKaLo4Obvp6e3GxyNRbUvMTIASW3afqtJg2PRF0eXWKWomDTPR+EmamWiM
1Ddt2qKvv3ff/oMaLbq62/fu3d/Q0CDemGTeGW8TTZlJ45ZT7nYiJqGKxjZ9UXS5dQrABkN/9OZl/e6JZTV/zvhT0+XevXttbexxuZItincKrEe+crKihjNpFDaSn6Ws
MVjY9Dp0kV4bu09Tcy+kr6zw4AfvGjIxTWEjtxl7SdjXiJe7rOhvSPNZU4x+DG9y8wpBlTQA5E55hSI8aRj84DUk97Poo4R93fYGYydNwUfV1tYOahiQJH3+/FlBVf2e
HPhHXR4/edrvJVFuAShslGtPJWh7+ux5WnoWeNJu37mr6TxpqMXdinsDjyeNwkYJDV25Ku5XPbxwMUUmLjJ1jpySmlFQeEW5Jup3bRQ2/f4IBAsgDU8adkGzPGmgRFuz
eg0bBDHa/LnzIiKiWWI0RGZp03Dz2FEjljYNQVxztclHhiYm1YDkSaOwUTvYgCcNe4yTU9J7FVNTczKxtnrlKkTw9PIlwXU66+ITkqKiYgkx2sTxE0AZgwiIRiIgJoJG
x4xJEHoQFNAmKlP2fuT5WJ/gQIjEmGwEeM7snIHGk0Zho3zYFBUVZWRktEraICAqYxAynYsQyZNWkF9INkWDGA0sZJezcrD/GUFCjAYBbRpQga3RhCcNtGn4FeujERNB
sKthNTQ0ZGYyvwpoE0N65hXoP27DdOwdYEjSdH4AZ5rxKQtpeNKwNzszM1sRK5eVlcGeimhQeloKG6WblJcQH0/e6PZ2doCQrBkQnjS8pEUJcFVRcS85JY1EKC4uAds6
DvYgQVzcunWbDSLazZs3EYfVhj3SEDYooK3XTE+5OYEnbYnfrvSHBSBJK3tVYZPjCapB8KSJKSf5CeQ18vGkVVdXh4WGTp86FZY0MTaW1Yx9Gp/CRvnmZWFDwIMH7+nh
WVVVJWVOasiTBlanhee3vW152NT+nJXwu+e+0R1uaG2qXJ60uro6+JY1q7r6lsSGFDZSNh7J0foa8ZJLICKGAGzYb/xoCnh9olmI13zz5i3CcoaXNE6GEeZJA+nZsWPG
LDsZIuvt3MXypPHpLwzYIKKZmVkEBIaw8ZGWS5smoE2Y9OzISZO/mIAnze7h2xSu3K25MCJwmiieNJC8wad18aQlSeZJQ58Wnhnw6HVJBIWN3K1RMKF8sFGHhSq7d+0S
M/ghPGmpqRnPn78Q5kk71b2rGYxnmDnw9vYnxGjgQyNUGIQYjdCmIQLoY/gzBOP9/IO4PGnQg6CANlE8aQt9JjiXbL/yxIErafdPbM2c3StPWn5+kfQ8aRi6wBurw3NB
GaRsnfK1PSmVI5rarRJQk8cjZvDD50nz8vLyBdWYME9abGw82RQdHhYOdrK4uASM7xE8ZXuK0DsR2jRsjSY8aYQ2DXEuXEhCkOyChoDDE0EBbaJ40g7FjrcpmBZUujju
9uqUu+sTy9dFlq1wLJqJm73ypLm6ngFJGocn7YJwi+EOXdTnoUjZsilsmK5z/wp6INxpNxCXObu4E6oxS8uTvfKkAVosMRri5+cXsEFQol3GUrZunjTcx68sMRpwBYoP
Ls0afuJqEyY923x4p57LT+Gl44UlqHhcrzxpIOWAl+vmSQsDRAWaIzqr/WtzUblT2PRuAfV5WmSog5euQEGvXC1hedK8ffx7ZSGLi7vIvS9TMCo6FiImuUCO4EmbvP3b
jFs/5977paRq5O3HP0JwDbEK+GHV3g29lhAkaeJ50shgBv1V9XkitJMm8q3BfUhSvlpkjSZqSoA7sYYOvSi1xVeu2NmfDg2LFCUgtcBxTuyvAQEhhoZG3MhGRia4yd4R
CCKtp6cv+6uAtl4zXbl3/erDf614+NdP9f8FPGmQ6pf/FpPyV/CkuXp6iCkqfgLv1LmISDE2xBwJLCYwdSaApT6dEpCjSQzqTpqseJAyvijYkM84Ej+DFhYVW1mfEkU+
xhKjEaIzlhiN0KZBQJiGdgC2NC5PGkubRojRJo4b737Wi0uzRrSJEh//wOV71o1e/xffkH9KSvn/Is7/46GT//q3ZT9LyZMGck5pTAfHi7kB8qGGwkYai8kTRz7Ey/Fq
kbVwArAh82YS553ZXMDGdMLSKjAorFfx9fEjVThx/AQi+Pj6kxmCzZs2oVMUEnqO0KbhP64RYd/efQgiTkBgMIJIRZL7+fojyGrDOERUjux9W2fHPSaH5m1fuv6grrH1
cW+/AIlJEMHD0wecbDLZEK4Yrxjuk6LeRiYDious5rARNXSRWP/8/HxzsTxpwBWoz1ietJycvOioaJYYDZRoCLLEaLiPIEuMRmjTWJo1QpvG1SY3H5qohGd640mTaARE
gFvG64YMfihspLGYVHHUFjZYECBm6CKxbrl5ecYmZr5+QaIkOCQcE2LcXzG5zA1mZGRxgzjMDEnYO0jLTS6sTUzWcvzk6nbW168HT5pECwhEgKOWY42S9LnI0QGRr+1J
XyS1/m4jfTVUGTMnJ9fwqNHAIElDLZyc3IR50lRpT4l5UdhINBFPDhtJVqrUGJWV98GTZmNrD9JxTRf3s9779x+SdWyjVHNKViZHk6DeRrJZVR/Dzs5+8+atRsb44n9c
o0V/z759+w68fv1a9TaUPkcKG8m2ksNGkpX2QYwbN278OWOmpktmZqZEbsE+MJ5sKuVoEtTbyGZiVcZWq8/n8hVGleaSOy8KG8mmk8NGkpUqO0ZDQ2NR8dUBQJIGtreH
Dx8r2zxK1idHk6DeRsnPQHF14EnLys4dGDxp9+7dV3+eNAobyY1WDhtJVqrUGM+ePc/JKcCQ4MnTZ5outbV15XfvXb16XakWUrIyOZoE9TZKfgaKq6uqengxceDwpIEL
qrDoquJm6TsNFDaSbSuHjSQrVWoMiTxpID3jEp2BEm3rlq0sTxoudHW3gS2N5UnDr1yeNKT19PRmmc0EtA1CnjQ5mgT1Nkpt8spQJp4nzcWF2a0JMTA4Ai6y8HNRoERD
EHxo4EmDgDANQbClgTNNmCcNqUjysx5e+FVAm/TsZ9LHVH+eNAobyc1WDhtJVqrUGOV3wZMWI4qy7FJaBlY3M7uao88jTmpqGtkUjc3PqZfSL11KB20agvhQimtEILRp
iJOScglBpCKbotPSMhAU0CaGJy0wPGzD4W0MTxpfwJlm7+4kJj77E8OTdjlHqRZSsjI5mgT1Nkp+Boqru32nPCQ0Qgz/GLY044/Lk4ZdzSwxGijRbt74SoyG+/iVJUYj
tGlcmjUBbb3mGxAaCj7BsfbL3YtC4yrSIdvDjUAyuMN4rzQ8aWnpmYqbpe80UNhItq0cNpKsVKkxbt26ExAYKp587GJiKjeCQDAlNZ37q0AQkcUnF8g6MjoWrE6jPZZV
Nz740PGGFacSz2/Wf29ubyWZJy01XakWUrIyOZoE9TZKfgaKqwNPGtbnx8ZdxBePm2W3cSEg2Lbp5OTC3oyIPG9ufoIb3Ld3P26ydwwNjyEJG3RwcMKGNjYooE04OzP7
k/+wd6TfLccntZlcKXt1Qct76pj1U4WT4A5OGYDgAiVJlIInTXG7ya2Bwkay6eSwkWSlSo1ReuMmFj6zPGllZbe59GWgOyPk6M7ObrgP+gtQoiFIaNNYnjRCm8YSo4FL
DYxqLDEaS5vG0qwRbaJ40v48M/bs9b3XnrpxJeehw/oMhicNtAUCCVmeNFygGNgOpFQLKVmZHE2CehslPwPF1WEogo3+4eER4BkDT1p6ekZUdBwrYaHhZBe0jbUNboIn
jQT379uH9zo418kMAf5HMww1caYmpggiTnTMeQRPn3YkrQR6EAzwD+Jq42bEXmvvWrnv/ATrgpnnytak3dMlknBng2Px3BP5DJm6i+dZgYSRkdGEXjA8/BzGaXHxvfCk
KW4oZWmgsJFsSTlsJFmpUmOUXLvu4srwpFlb28ZEx1ietOFylxGis4z0DC5PGrY9s8Ro6emXkxKTWGI03EeQJUZDKqSFBughdIQC2oR50lbv27jPc1Tw9QnC4lc0HrAJ
Cg0XSAUqj7NnPZwcnUDyBjqB8+fjlGohJSuTo0lQb6PkZ6C4uqtXS047uoSfi4Y4ObuRC65Ex8Rhepd7B98oxQRxTgaSsBGQlhsU1iaQnYW99aTt32ZV/Erk2oOf2Gv7
c8MX7lwhXELcCQoKY3zmuWj/gJDIqBjFzdJ3GihsJNtWDhtJVqrUGBJ50sCBBnIzLk8atoJyycqOHz/JDeJXLm0a0opPLsx7Nm3zXHO3/7j/9NtP9f+V8KS9qP73vOtD
ftH5q4Obi4I8aUo1njzK5GgS1NvIY+g+TVNUVGxtY4cjbnoVTAmA9AxEZ+j/IAKCy5cuw4PHwQEkvv7uPQjiPwmij4cg4iAmgq6uZ8ePGQvBBUkObfxFA4w2UeIbEDR1
89yFu/895dI/PKz4n7du/D+OXv8CnjRTW0sxqchPoBMIk44nrU+tKkY5hY1ky8thI8lKlRqDz5NmLYqC7PRpJ1IF/d36iOPp5U2CS7QX460PrzJpArPWBv+9vPwQYcP6
DSQCYiJ48MAhEjx5kqFiE9AmnvcM3GjL9XXAkwbZZqjvzlcoUeTgSVOqOSUrk6NJUG8j2awqjsHnSTuBIUGvEht34ULChbPuZzFiQQTMUwFmWFADYjQSH7RpCDLEaKER
CILtiR85kwSRKigwCBqgB0H8B0kaq01Uporcx+kJAQGBKrahTNlR2Eg2lxw2kqxUqTHy8vJMxPKkYfoLYGApy0B0hjNluQxmCHKJ0QR40hDk8qQJaJODCU18EvCk+SnG
k6ZU6/aiTI4mQb1NXz8UmfWDJ+3oUWNvn4CBIU7OZ7x9fGW2ggoTUNhINrYcNpKsVKkx7t+/v2uXvrPLGU0nSUP5wZN24MAhT08vpVpIycrkaBLU2yj5GSiurr29HTxp
27fvNDM/oemyZ+/+LVt0cfb158+fFbdMH2mgsJFsWDlsJFmpwjE6OzvBvNHS0lJf3/DuXd3Tp89DQsJsbE5hoQDEysqGL9YnT1pbWlrhPIITJ04ehxy3tDh+wsLihLnF
cTPz42ZmFqYQU3MIRkcQY2NTIyJGJscgxyDGRI72FPY+E8fIBPGNjJiE0EBUEbXQj1yQF3JEvsgdZUBJUB6UCmVDCSGkwCg5tpEWF1+prn6FhTZv39a+f1/f3NyCmqoV
iuRoEtTbKNzkFVaANtTW1tbU1IxW9ebNO7SwFy9eAjlPnjx79OgJCJPALlB5/wFYYEBncefO3Vu3y7G+s/RG2fXSmyXXSq+WXC++UlJYhBXHxXn5hTm5BVnZeSCLysjM
xhpqHDeNNQTYjJmYxGxTw/YYHD2NTaD81f4XuyURd3Afv/K3l11CfKRCWmiAHmiDTmiG/vyCIuSFHJEvckcZUBKs1EapUDaUELtTUVqUGSVH+R8/foq6oEavXtWgdnV1
71FT1PfTp08KW045CihsJNtRDhtJVqqMGF++fPn48eOHDx9AkgbCl9ev3758+er582q0ObQ8gp8HDx7dB34qq9A0uRC6cfMWVp2xKAJZFGjW+EC6glaOtg6+MjT67Jx8
CADAFyBBQPJIBMREfIIQaIAeaIPOrzgpxUa4W4AuFyooFcqGErJoAexRftSipuYNXCjqxUfLZ9RUGQZTmg45mgT1Nkqzfl8oQucN7Qxwamn50NTUVF/fWFdXj4aIl/ez
Zy/QLlmPxICqG1eMa6qsgncCuu7yAcZIeQUEDgFyuzchPzEeAzH5SZAWGqAH2qATqIAPQS7Ii4sNlATlefsWnqQeJUQ5MTxDmdUQIb0+IwobyU1XDhtJVqoeMfAWx19n
JwRg+4SG29HR0d4OacdwAm/61lYI8/fhQy9CfkIc/h+TBGnxBz1QSP5IFupRXaWVQo4mQb2N0qxPFWmoBShsJD84OWwkWSmNockWkKNJUG+jyQ+cll0ZFqCwkWxFOWwk
WSmNockWkKNJUG+jyQ+cll0ZFqCwkWxFOWwkWSmNockWkKNJUG+jyQ+cll0ZFqCwkWxFOWwkWSmNockWkKNJDHxvU11dbWJszArXRuzNsNBQTX7utOyyWaCurk5ik7C3
sxOjVMNg056e0RafQIRbdPYmLjrr6gQqPH3qVC5ahK8T4uNlMzyNreEWWLNqlfgm4enhKVBF+dqefHb6Rr5kolK1eHhx0SJ8XT95hnBamEC8jfD6UW45qTY1t0BGRob4
JoFOikAV5Gt78tlBybD5XF0tHjaom3BBYQIxNtq9a5d8daOpNNcCeFGKaRLwRcJV+1RVJb7ttYaGKcsgSoYNitWwco2Y0qNuvRZdjFMuKipSVm2pHg2yAIY3opAjqtMu
vu3hna6s6isfNgKjGi6EUCtR5RbjlLHoV1m1pXo0yAJ4XYqCjahOO/yJqFe2mLYnh02UDxuM+EUVXYyXFOWUxU+YyFFhmkRTLIDXZa+wEdNpF9P2MGGgxIorHzYoXKOe
fq/IEZ5D49akV6dcVlamxNpSVZplgV7nisR32uVre7KapU9g01FYJAwb1Ed84YSdMiamZa0PjT+QLICXprDDEd9ph1cRbntNRibKNUufwOZLa6tw0SV6SWGnLDw3r9zK
U23qbwGBb3oSO+29tj28x5Vb0z6BDYrYfMpeADmoj8SiCzhl4bl5iRpohAFmASwQ4TocaTrt8rU9mezWV7D5WFbGhQ1qIk2xuE6517l5aZTQOAPJAtxvelJ22gXGCL1+
KlTQRH0FGxQLCwJY5EjvJVmnTBfUKPhoB0xy9pue9J12btvDG1zppuhD2LCLHXpdUCOqJqxTpgtqlP6wNVQh+01P+k67fG1Pevv0IWzYhTYyeUnilOmCGukf4YCPSb7p
ydRpZxfaKHFBDdfOfQgbZEMWO4haUCPqecNAdEHNgAeDTBXENz1ZO+2k7SlxQY3qYIOFNnIsagBm6IIamVrVgI+MuSJZO+3wM3K0PSkt2bfeBssC+shLSlk9Gm3QWgBt
T+KnQrmN07ewkbtYNCG1gDpbgMJGnZ8OLZuaWoDCRk0fDC2WOlugT2CDAX0V/w8z7pgAgeCC3JF1YKfOtqNlk9sCmFwVEGnWXsmdndITKg02gEpeXr65mfmC+Qvmzp6z
Tme94ZFjOAfv+HHmBDwcfGdqarZ58xadNWsxB79v3z4/X7+C/HyKIqU/UTVUCIS0hoc2GR1tXMtMCjduXNu4SadxpXbjqsWNq5c0rlnauHVD09aN9X+MrR87oWnP7hYn
x7boaKRSWywpATbwIcZGxmNHj9m5Y9fp0y4RkedxgB5OzLuYmJKUnJaSmk7Oysu8nIPjwXAYGE4CS0i46OPjBzitW6uzRHuxs5MznXRWw+auYJGwqqXF1qr+72Ma1y1r
PrCp1dGwLdCmPeJ0R5RzR4xLR+yZjvizHRe8Pib6fEz2/5ga+Ckt5FNGWEeUR7v/6Q/WRk2b19WPHt+4ceMHX5++WCCjSO0Ugg2+6KPdr1yxysbW/lxEDAATFR0XHRMf
G4dDJyUgBwdZkiMmMzKzAgKDDuw/OHH8BINDBmlpadQFKfJE+z0tXETbxQsNs2Y3rtZuObatzc+iPeBEe5BVe7B1e9ip9nB7icj5dDnic07059zznwviPyYEtp2xad6n
BzfVbGHekZ+vDi5IfthUVFTMnjnLzOx4UHB4SGhEaFik3MjBoZPXrt/A6ZZRUTFmpmYTx43ftlX3UmoqxU+/Y0DWAnRcu1Y/a1bjmgWt9vvbPI61eRm3+ZgpiJzOwgud
V5I+5yW0Bbg2H9hdP25ii4tzH33+l7K+csImLy/vj99+dzjt4ucfHBgUpkTkkLNak5JT7ezstRcu2qare/58rPRr+KSsNo2mdAvACTQdO9owf8YHi+2tLoda3Q63uRsq
FzmdV1M6r6d9Lkpu83ZsmD+v6dChjoICpVdEGoXywCY3N2/hgoV2do7ePgG+fkF9hBwc+4qzXbOychzsTy9epL1sydL0tDRpqkTjqN4CePfXz5zVtEn7g8PeD6f3tTod
6FPkdJZmdJZltYV6NO3UbVi8VNZFj4rbR2bY5ObmLpi/0NnF/ayHj5e3vwqQgyORcRhybl7BHv09y5YuDQoKwiSE4jWnGpRlAQYz02c0G+i02O76cGq3KpHTeTunPTao
Yf6Cxq267WlpKuu5yQYbdJamTp5qedLG7Yyn+1lvFSMHZ4hfv37Dy8t73959mMVesWz5EYPDx44eBZDOM3+x8fHx5OsQXQmqLEhI1MNgZtr0psM6LSe3t1jv7BfkdJbn
t8eHtjhYNm5Yz0xwb9VtMjBoMjzaGhPdGhPTej4Gi9PIZyKJ1ZEyggywQVuc9edMi+OWTs5nXN3O9hdyHjx49ODh48ePn8IF5eXm5+cVFBYWXb6cFRIcGhISGhYWbnnC
8qih4bTJU07Z2qanp9N5BSmbghzRMJ5pWLSw6cDqZvMtzSd0+xc5nyuKPlde+fzg+scbOR3ZiR05yR35aa2RQa2B3q3Bfq2hAU0Ghxq37WhYvqrF/WxHYaEiM3IywMbI
yEhPbzemARydXNUEOU+ePHv+vPrFi5evXtXU1Lx5+7b23bu69+/rGxoam5tb4HaSk5P1durt1ttFN/DIgQqJSZoMDRt15jQbb2g226RWyPn86MbnJ7c+P7vzufre51f3
O18/6nz3rLOuurPh9ZfGdx9vlX7w92tYvrrZ9pR8Lkha2Ny9e3f+vAWn7E7bOzhpEHJaWlra2tpqal7HxsauXkl3v0kEggwROkpKGuZOazZc22y0TuOQ86Wl/ktr08e7
d1rOuDcZGcsKHmlhM3fOHFMzC3zW1FDktLd3NDU1hQSHYJ8g7bbJAA7RURsWLGjavaT5yGqNRs6XjtbO1zVNx4xl2hgmFWzgalavWn3Sytba5pRGI+fTp0+VlZXYdE0/
BCmInLaM9AbtKU0HlzcfWjkAkMP72I6JOBDHSjngkQo2xy2O79t/0PKk9cBAztu3b+FzKHIUQU7jpvVNuxY17Vs6kJCDj6dSIkcq2GC1pbnFCYvjJwcSckCOQ+ep5UZO
k75u0+5FTXsXDzzkSEO0JBVsli9bhoHNAEPOjRs36Em6csOmfvasJj2MbQYgclrOekicIZAKNsuWLjMxNR94yDE6ZkSnB+RDTrOJceOaGQMSOV8aGxr1dos3i7SwMTIy
GXjIwaKdUHp0u1y4AS9M/awZTTvmDUjktAYFiXc4UsFmw/oNBocNByRy4HDkajY0Ee+Dj3fDggkDEjmfa162hoSIecZSwQZMANiLdvSY8cBDTlBgEO2nyf0OaFi4qGnz
rAGJnKaj4t6nUsEGZt2wfr3+7j0DDzklJSVlN2/K3W4GecKP5eUN86c16c4ZeMhpcXVV1NsgPdZOLlq48NChwwMMOVi3FhcXN8hbvyLVb1y/rmnL7IGHnNbIcDHDG2m9
DUHO9KnTDA2PHT1mZLBhxvdDvu0+5krr15mrth863ldrCOKdNgz7+0aniyyDB8tDwO6mJntCyc42Zn/O3Ut2M3/UmuWQWcWslRa/4hNbDhRpN4M8bcPq1Y2bZnKQMztl
wlDO+Wc/Gi6aVXZwTV+tW4s0MBo2yuiUK8vgweUhILupyZ5QZmdbobPJ92yj/XbkasP0y/miVnx+vHH10/37oh6uDLBJiE8AjdPhI1iVf/Tg+hnDvsKGX5Tvpm04atUn
yIk9vX7Y3zecjudy30hATknI7h9QqiX2mRVkl4EY5OA1MMibvtzV//zqVf2MiY0bZnCQMytlvJbAObUjx06rOtI3Kz7PHWRgY+vM5b4RiZw8Ry5smEL+sOPyreu9Iqej
tPjTvQpFYYMP6nNmzT5w0AD9tMNHDA+smz5syPAZGw7xZ6WN9urM+nXIt9/P3GGqFuvW7lwN1B/xw6TpkybtDi1h9+eIQo6NtbXc7WaQJ2wyMmpcPqlRZxoHOX+mjNPS
+tvPKdsXMmsIds2JmPSD1pChhjpL+3/FZ+5pwGbkDuf62zmd5WkVtstHDvnDOOxyr7sMOq4VfLx3V1HY4Py3TZu27N9/kI8cg306DGymrz/YPbd2bOeC37W+m73N1Arr
1qyM966d/TuDZq0py3aZ2jL7c5zNNk7U0lq0y3DrdK1vtX5fusfazdFs60xcDxk5a6e9bxf3TYSXjd7cobg5ce2xAyuH/rbWJuJilN26Yb+vsz9/KTXIcPKIaYaOTpun
Mson6rkn5hHWqJ69tbyAnWNH7PSOslk8Ylfo9fsPxCMnOjp6kLd++aqPVY/106c0rJzcuGYqBzkzUsbyYaM7v2sNwa4/T43428jJf75i1kqvfqg7zXDkd3h8I8dNTtq/
kdnZZrXW+7fvRs5emKszeuSQ7+bOW3Ln1M6CVbhG+xnna3m4i/vG/0jhxgnMzT/mR+2aOXLo/Iwgp46QfUZDRxpZ2XckWPpP/EH74OG0DWOZtjF+TWZMKMsa1dVby7Jj
YLPNsb4sq/N2yj3rZSOHzA9Iy8PONmHkdFzNxbJfhWCDLWDgD9DX37t33wE+cg7tWTMVsJm2bn/3DIGZ4eaZ3w8Zs2K/haXloVW/ct30yHn61o5OjibrAZtf//5Ld8f3
1z9GM5ghMm2nfVBI6Dk/661je/T9fltjdS4h0k4HsDkVk5IccGTyiHHjxw7vjjN8k3t6N9/aV+SUXrSaMVEvoPB2iu2sH/RDrt3DbmpRyKmqeojd1PK1m0Gequ3ixfo/
/96wbGJP5ExLGQPYjErZwn4JnZ8ycajWyAllB1c2bp+0iPt8vxubYry1xXI1A5tfRszs+um7mb+OYOBB5I/F5Z5gjTIs1uG/iFkZOi89wKEjaC8Dm5OnOuIs/Cb+MGvs
b2zCketN6zh8awxyLp/q2UmbauJ2rrF7T6gActqiQ8UwE0g1ttmlt2vrFt1du/d0I+eA/mrA5sepOvv5MwT4nmN8ZBNgM2LmlqNGW2d/P+S3OduNrbDL4MThtROHfz9n
j9Xp08brJ2gNGbPy6Gm3M+7wKD8M+WnG1pNuPgE+jgdma/281MgrKNjbZNkvWn/omHtFRESGuuxZ8OOQ39acDI87Z7t22G86tpFJif6HJ32vNX7b6ai0zIxoq6W/ag3b
6nYpX2Cccy3h5Mzvd/kXlt2+ErTrh8U2KbewfVoUcrCbGlsJBjkA5Kt+486dDYvGNiwZ3xM5U5JH82GzkZ2VnsvA5m+/pegvSpk8VOun0Sl7Vjcb6bzeNW3Ld98bbtZp
Pr7K+9fvtH6eVnBC74Ptpqgp32tpjfY12t3qcuDRjgkjtaalOR1tc9l4TEtr7pLNz/xPtHvv9/vzR62hc9P97NoD9BnYnLDuOG/uh6mIscszQzw+Jjqc1/5Ja9jyzAuh
PcY56TYCY5uRK0zvleSyu6m5yGk566LQBDRo/+bNnb9j5y7siO5Gzv7dq6YwsFmzhz9DwM6tjV6259je5WPY3pq1jdXh1eO0vpu/28rumM4ELa2Fe0+5gYfA1WLLmCGT
t5zwYLhv3I4t0Ro2bptdQODpnWOH/bDM3JfPVHjOZd/EIb+uOhESG26zhvTWLvoaTPr+x3Wn4xh23NSQY3O1hm1xSQH/VCEHOUVxJxZyXks/zLJOuc3nvukVOR5nz9J1
0HLAhumh/TmtfsEYIeRMSv4DsBmZsp6dlebPrY0cd3PPHK+RbG9tbfOxxd4/fzdy+vxXZisAm5EzF9cwDB47bq/5Vev3ebcdwBq1/83eKSOH/O5rYfDhxGLtIcOPHTnM
Zyo0K98xVmvonHRf23a/XUZDfzI6bt0RbQLYjFx9sJZhx/WoMJiiNWxZZnww2HG/IifNiumkbT1Vz8ytJb8MPbjt++8XW4V+Ks8XRs4Hr7MKwWbVipUY1WzbtoODnD16
KxnYTFmtz58hAHIObp3zq9Z3MzYZGu1ZNlrru1lbjSz5uwxOGjCwmadnaXtUBzMsC/bYuoCHwMV885ghkzYfP8tw37geXaw1FLDx9bNjYLPUzIc/zgl32cvA5nhwdIgV
YMP01hJ8Dk38/ked0+cZXumUQMM5DGySswmvdDdyMrx0R/fw5n/apNzmz0r3hhxvb285Gg1NwvTQJv1SP/cPIeRMSv77d1p/+ylZp3tWeuvkU8P/NnLClJd7ZjGwmTTj
FdnZdmQRA5tp816ZLvP+5buRfy6qYbhvtt1a/YvWb3Nu24Nvbe+bPXzYmB/8YKHNwMbgIH+cY1K+fYzW0Nnp3lbtvnoMbMwtOyKN/cYPHbnqQC3DK+1ecWiy1rClmbEB
hFe6CzmplsaAzRabejIrXeIfOP377hmCHsj5eDO/Lemi/LDJSE9ftFB7yxbdrVu3cZCjv2P5JMBm8qpd/BmCfduXT/95yLfDpm406Oqt/TpryxFz7M8xO7BqwvDvZ+lZ
2NoYrmVgs9vaGQwejiabxgyZuMniDMMa5XREG7DRtfXxcz+6+GetPzZb+oSFhIaeObToxyG/rrQIjAo+uQqwQW8tzusgYLPWLoZhZE8KOALYbHZKzOrxPSfDU/f70du8
LvPZcUvz/XaNGKJtnXyz63tOT+RkZ+fm5uRQDMhhgaZDBvUzfquf/Xch5ExI/h2wGZG8lj8rvWFKxNhhWkO0DJfObtrN762N+D1l59LmQyteb5+85bthhhtWNhstZWAz
Y+Erhvtm661VgM3s27bgW9vzWn/yyCG/+Zrub7Vfy3TSVm+pBTuu9/5ofJQbOivd62S79w4GNmbH288dY2Czcl8tw8juevfAJK1hSzJj/Hp8z0k5YTzs25GbreqZ7zkX
m2IMt32dIcDc2lfkfPB2Fb/NU8LYBos416/fCG/TEzm7ti0DbDjjM+a7zcSV+keYcc6x3Ut/4U4JjJi93YzTW3MEg8dp442jh0zcaO7KsEY5Hl6kNXTsVhsvH393c9zv
Vvv7mLFDf1lhHhARaLlqKL+3Fuu1f8L3P66xi2LOMkjyOzxba9im0wkZ3O85eVHmM4YsMI8p6JohyPPb8f2YnX55X7+EcpCDBWlytBiaBBZoWL2mfuqvvSFnXNJvzEQZ
V0b+Nub+dmaGoGH9mJ5TAn9PObDma2+NYY3afGvlz1q/zbplA6bCXa93T2JgY7y31WVP0cpf2M/rM38fOVJrZrrH8Xav7UZDRxiZmreHGfqNGzpyxd5a5iwD57v7J2oN
W5wZ5d3je06iOWDTs2xTncLiCMcnmAoJcj7dyhXfQ0P1xcHm0aNHM6bP0NFZL4QcPd2lEzmw+W7UpIVrdfd1j3OMj+3TXT79V/430PELtxw069FbcwD3jb3RhtFDJmww
cWb41hwMGNhstvJkOD49bPYuY5AzdM7O44eWD/1luanvuYATKwEb9Naiz+6fMOzH1bYRzCkgF3wNAJuNDvHpnFNALp8zma81zTyqgJ2VzvLdNmbEdmaCQAA5mZmXs6mr
kesdwAxsJoyvn/hLb8gZk4Tx/VfYDD0ybezNDew4Z/6D1eMMR/yNmYD+Y0yS7tIevTWGNWpj2YqfserklhXGOXqv9SaOHPKrj5E+w45rvzV6/s9MwmmL83ZPH6n1Z5q7
ebuHLgMbY5P20MN+47RGLtevZU4BOX1330StodoZkZ49TgG5YNoDNhPXgFvvE7uGoBs5rYFnO9+9FW8YcbCxtrJatmzFmjU6vSGHO0NAZqXJl1AyQ6ABa6Xdz7jL1WZo
It7H23fqf/6pftzPIpAjMLfGXUOg7vtzPmaeb0uQvNhKHGzAubxixarVq9cOPOR4eni9e/eOIkA+C7RGx7wfOaL+j1EDDDk4y+CDs700NhEHG8yhwdsMPOTExV949Oix
NNahcXq1QIuL6/uff3r/68gBhpw2/zNfmpukeegiYYOvGZMmTFqyZNnAQ46b6xlpTEPjiLJAs7Hp++HDBxhyPqVHduRLO60qEjbYiDJ1yjRt7SUDDzkXLiTeunWLokJu
CzQbm7z/YfjAQ05bgLhPnFxziYQN2PcmTpi0cKH2gEQOTvuQu9HQhM1GJu+1fhh4yGkPdvv8+JE0z1fc2Gbc2HHz5y8ckMiJjIx68viJNAaicYQt0Hzi5Ptvvx+QyGkN
9JXmiYuDzTodnblz5w9U5IBGXRoD0TjCFvgQFIzTlwYkclo9xVEIsKYQB5ujRwxnzpw9UJHj4eFJISGfBXAcNAObgYicNh9xC5+lgs2rV6+mT50+G8AZiD7HxcVNvkZD
U8EC9VNmDEjktLrYSvN8JaxJMzxiOH3ajAGJHHv709IYiMbp1QJNBw93wWZg+ZwPzjbSPHEJsMHXm9mzZv05Y+bAQ46dnYM0BqJxerXA137awOqttViZSvPEJe/uxJlQ
kydNGnjIwQkK0hiIxhFlgcat2786nIHic1pOStUqJMMGVissLBx4yHE87UQhoYgFOuve14+dPJCQ0x7i2BYTKY1NpIINFMHnLJy/YNrUaQOjt3bhYpKHh4c0BqJxxFjg
08OHAwk5zft0cZKCNE9cWthAF8Y5ZqammFsbALPSNjannj59Ko2BaBzxFvj88mXj2g0DwOe0R7k0nzCT8nHLABuiEbPShw0M5s2dN2XKVA39EnoxMYWezyFl+5AyGmYI
GtZtfD/q75o7K918eOcn0XyCAnaQGTYkPTxPYmLiYYPDK1esJFNtc2bP1ZS10gcPHgIfh5QNgkaT3gLo4bRduIjDyht36TcsXVE/9c+G1WuZNTjf/0gWsNX/9lP9aOzS
GVU/5dfeeAgEmApVx8je6mra4iTVThtiDTlhwzUlIASyCxxL5uTotGP7jvXr1llaWuJi+dJlC+YvWLhg4SIiCxdpQxZpQxYv0sbut37ZE+p25iwYRqVvCjSm4hYATx/Y
+4m0xsR88PRqPmHZsEanfv6C+glj6if/2gDiKEG+NdXtCW0LtGncvE7Ko9WVBhv5zLpzxw7VI8fPPwh4lq/ANFVfWAAOqjUyqn7+wvppk+tnjxbi+OSeZdAnJ+y2+Z1o
XLv885MnMtVOCd5GpvzYyPBROmvWLl++UmU+x9vbf8e2HZRMUL7n1dep4Iga9+2rnzi+fu4YIV7pvuqttXmbNSyc96lCJEW6qFr3G2zIAMnczAydtz36e/uawcPFxX2b
7naKmb5u/Qrqh/PBKQb1o0fXzxzdk5Fd+chpdT7SuHqprH6mnztprH1jYmImjB23ZfPWvkPOoUNHdu3cRTGjYJtWWXKAp8XJuX7cxPpJvzeumNzz/BzlcN+0mGxrWLZE
PswoZ0pAcWtiJ+nmTZvmzpkLjmnlskbZ2TvqrF2XkJCgeCGpBhVbAGP0trS0hsVL6seOaZg/vnH9DKWcdvjBRr9x5YIPrs4yzQEI1L0/O2kCRQGv7JxZs0BouGnTZsX5
1swtLFetWAWqN3oQtIqbu9Kzw0Rci/vZ+qnT68eNbZg9tnHtDPlO2G0x023U0W7U3fLxbrmChVQj2JCagPrD3Mx82uQp8+fN11mro79nn/SnuluetDEyMl23bsOyJUtx
PBUFjIKNQ92SAz9tCfGNmzfjo2r99MkN8yc0rJjWuBHs0oubDi5vJozshj1OO2w6rNO0Z2Xj6rkNq1c0HzdXHDDqMrYR9WyAn5Dg4G2628b8/Y95c+Yu1l6srb1YR2cd
ULFhw8YNGzbBKYGcGvdXr1yN/4hpecIyKCgICdXtedPyKN0CgFBHYdEHX5+mgwcaN2xoWLqMwdLMPxsWL2hYvLB+8pTGTRsbN29sMjj0wd9XzJnP8hVM7byNqGpg/AM8
CP9RlyLfg6epFLFAP8CGzmgp8sBoWkWG8sqyXj/AJiMjo6ysTFkVoHoGmwVaQ8OU3umS1Yb9AJs1q1bRVWGyPican7VAw8o1LR5e/WsQVcMGQxRy+AntqvXvg9fQ3OFn
mKH/5Bn9W35VwyYsNJTApqioqH9rTnPXRAvAz5AtPZhG68fyqxo206dOJbAxMTbux2rTrDXUAvAzBDbNp2TYHqP0yqoUNpgJ4J6cSOeOlf44B7ZCeBju7ut+nFJTKWww
E8CFDabUBvZjprVTrgXgYbiwaU/vt/ajOthgDkDgAGFMqSnXrFTbALYAfEsPoo+/DGvU0++v+qoONpgDEIANgphY66+a03w1ywLwLQKwQVBKfial11R1sMEcgDBsMLGm
9CpRhQPSAvAtwrDBp89+qayKYIPRvzBmcAcTa/1SbYUy7awM0h6hpR1Y1amQGoUSN1dddto2ipmT1DaNr2zu0vUu22QKx87apoHZVc1sKRurMt22D0eSEfNNwktrOhQq
gGoTw6sIYwZ38OlTtQXpyk1FsMHov1fY4KbmLbRpzDZlGt+6oKq2fnlmvM5nCXrjuPCwyH7JB4cAbJiJ/lF68fzfOl7GH+DDrEu67/dPDWTNFV6lV9jgZr8stFERbDD6
FwUbTVto09mYbT5q+Mz5M2eaZr+T9fErJX5nVeASeAzzzBrgobk8SHdct+vjw2a4eXYjH0TNlQkm2lpDpjDlJB5yrlU242Q6arKt5pP7GvIHryIKNv2y0EYVsGEX1IhC
jkYttGGa5iiT5GuB60aZZDd2NTu2/8PtMkl5s7O5Kt507gh+3yme36cSvsNt3W1Vgeu+YgOxGRQR19cTNgxySpznjuCXkxS7u8CMwxyxJLCyH7uZ0gOWLKgRJf2y0EYV
sGEX1IiCjSYttGFe24yfYRpr13u9s7nUbf7X/g9pwdLcXOZcWt/lB7qSj5jvVNJMPAP3To8mxscGd2T1FQNCsCFA4kfurMm00NZzK2FclGb9sQtqRCFH9QttVAEbdkGN
KNho0EKbr2hhGivnHT/XrRSOgt9lYt/uWr3d7B5UdL/+GZD8xn/x84cfgGJ9heAd0ukif3xQcRwdFwIiYMN223iNVdkX45zMLQLjs6u6PaXaY4hdUCMKNqpfaNPnsMEc
WkJ8PCtc5HDvq/2zIwXkd5C+OhZ+P6dHO+ZHwNv9E7dx97jZ493R5QdKwgND4zDpxUKjRvAOxz5yeZtPNaUX4xNLu1wN43nmrmF8ndr/MbzS8QmscJHDva/ievQ5bATq
w200Kq6qMrITmqrqFSFdHoP1Cd2jEcaNsL0v/owWksMBxKcy08HMnLK5BWaTm4Xu9Ch6r2MbMr4XPbYR8FHiXJYy7NRnOriw6bNMJCumsJFso68xmI4ZOwHFn1JjxuIv
mPEDmaTiTw1zOmm93OzqpDGDdX7fjGnBU7YHljfzyBwd6aT1vMPtpHXNAXTPpHW+zDbX7p4hED2TRvzkcL2gSvTNOpsrQ/EBR0RPTxaDqDwuhc23Kre5ohly5qz4qrpQ
9KbnlAB/oC84JdDbza4hR88vKszNth7fWL6OTNg+nMB3m3G74p9J+m7D63wZv4v53MSKJk1As0+OwkbjYNM9RPk6PmdndaWca2ag1vWpvuvFz28PxGOgQc81CSXDD+E7
ApCXZ5UAO6/9rdbwbc6ZX4dSir5OVJiewkbjYKPC1kGzEmEBChsKGwoOmS1AYUNhI3OjoQkobChsKApktgCFDYWNzI2GJqCwobChKJDZAhQ2FDYyNxqagMKGwoaiQGYL
UNhQ2MjcaGgCChtNhc2nT5+qq18+ffp8AEh7e7tmQZHCRiNhA8xcLbmek1vw9OkzTRfUIicnv7mlRYOQQ2GjkbB59vxFRmZ2C/+voaFRc4VUAXUpL6+gsJHVAnTjgGwW
e/DgUWHRlYLC4vSMLE0X1AJ1KS4ukc0E/RqbehuN9Db37z9ITEq9lJYpSsLPRULYXy8mpnh6+XAju7ic4QbxK+KwdwSCAtrE5CvfT6hLQUFxvwJBtswpbDQSNvfu3Y9P
SEpJTe9VQsMiJowdB8EFIiRcSFq9kmG6cnU9Q+IfNjiCIP6ToIeHF4KIg5gIIhqC63TWkSDRNnH8hHPnokTlqOB91AUjHNlabr/GprDRSNjcvXsv5nxCYtKlXuWUrR3Z
B2ZuZo4IwcFhJLhxw0YEQ0PPTZowEUH8j427mJSctkR7MYmAmIiAaCTo6+OHIKvN6JiRqBzZ+/buzjtN9i3bq7Ph8DZLp1Ox8RclJkEE1OVyVk6/AkG2zClsNBI2d8rv
RkXHolvVq6AJXrhwMToquvhKCSKkpKZlZWWfdT+bk5tPgsVFxfZ29qU3bpLkuEAQN/ETgkiFyBnpGdCDINEWFBhEtImS83EJs7cv+kbnh28sJhnG2i5x3/6N3i/DVvwW
GBYqJhX5CXXBCE22ltuvsSlsNBI2t2+Xh5+LRt9GlGRkZOflF7K/4o0uEMT8NTctgojD3kFkaGCDAtp6zXTmtkXfGP6R9jD3y5fPRO6/ezj27MqhK34NORcppqj4CXW5
dKnfTomRA4AUNhoJm7Ky2yGhEXHxFyFwEeSCK5FR5yHcOyGh58QE/fwDBX7lJhfWJpCdjYvD/7V+mPtNl5rGUq5cfhL3P4x+335st3AJcYe4GlygLknJl+Rovv2VhMJG
I2Fz40ZZQGAohgSlpTdfvKhOvZSJa1bw8l6xfOXa1WtwQW7u33dw/Jix3j4BJOjszAz67ewcSRAXCCIOCSIaIkMDSS6sjZsXuV68e9U4j4m+N03vvAzhSlqVy5+xM79Z
8FfhJHAy9+9XVVU9xAXqcuFiUn9hQI58KWw0EjalpTf8A4JTU9Nral5D0GeLjoln5chhQzKmNzUxw01nZzcSXDBvPoJhYREscQxe85CJ48eTO4iJCIhGghbmxxFktRkc
MuDmwr3W3rVKN2qSdaF2xn2D7KojrLiXrD2c8ydgI5wwP7+IFB4XqEt8wkU5mm9/JaGw0UjYXLt23dvH38PTx8nR6ebNsoMHDSIiz7OCwTyG+GamZrjATfR/IiMit2ze
kp9XgOD58wlJSckIXs7MwjWksLDowP4DGPcjJiKUlFxHEHMAufz4UIIZAlYbNyP2epHeCqPo0WevTPa6OiXg2vTg0hlB12f4lEzFHQhgI5zq5EkbFAOCC9TlfGx8f2FA
jnwpbDQSNldLSoCZcxExZz289+7djwsByc0tgLA3k5IuoTvHBmPOx9+6dQf/yR1cYEYbcdgIiMxNLqBNOLtdxvt3Ovxw8fZoYbGLHvV3ncnCSXDH8qQNBBeoS3T0eTma
b38lobDRSNhcuXL1jLtnaFikmoinrx9cyqUr3994+OP7N//cUvv/Nr77x7tPhhVX/DB9xxCzUyfFlxN1iYiM6i8MyJEvhY1GwqaouNjF1Z2MTHoV/d17ly9djjED+dXB
3nH1qtVsEP2isaPHuLp5kF9xgSBukiCiIS00sJoFtPWao5mt5e/r/pqU/i/N7/7Xx/r/0lr3P66V/tP6I/++8dA2MeUkP6EuYeHn5Gi+/ZWEwkYjYYPRiKOTa2BQWK9y
6NBhMqbX27kLEZxduqYEMLeGIBKSXzFd5n7WG4ILcsf2lAMiLFu6jAShB0FW28b1G0XlSO7bOjtO2TQHbofIb2snGhw3Ep+E/IoihYT0z6mx8gGPwkYjYZNfUGDv4IR5
214lMzMLI35IcnIqf243GTMEkydMzMy8jGBc3EV/P3+gIiIiIioqFt2nmOjz+BXj/tRLGYhQUFC0dPESzArgixCCrLZLaemicuTeP+PpZet02tHNTZrIJA7qEhgULF8L
7pdUFDYaCZu8vHx4Bl+/IFFSeqMMwv6akZH14MHD4JBwcgdzAE+ePMV/EsR9/Io4vQZxU0CbmHzl+wl18fcP6BcAyJcphY1GwiY3N9fK+pSPb+DAEKYuPr7yteB+SUVh
o5Gwyc7OOXrM5KyHj5e3/wAQ1MXLy7tfACBfphQ2Ggmb169fb926be++A2fcvTw8fTVajh0zQV2Ki+k2NZkhTDdFy2yymzdv7tmzd8OGTQNAEhMTZa5/vyag3kYjvQ3b
ZtjVZZp70a/tX87MKWw0GDa1tXVWVjaaLq9fvwF/lZztt5+SUdhoKmywsQw8STdu3tJ0ITxpbW2axDBIYaORsHn1qgafJvGe7qe3rTKzBU9a5uUccPEoU2kf66Kw0UjY
PHjI8KRhm42mk6Sh/FeuXiu5Vgqigj5u6spUT2GjkbDh86RhsctlUQLmsfOxCdxfBYJgb+L+KhBEZGhgIwhrE5O1HD+hLpQnTQ5Y0wlo2Yx2r/I+ITHrVfCTzlodlicN
cYyOGXOJzghPGkubRojRWNo0QozG0qYRmjWuNgVZ0YSTIwtsiZPNBP0am3objfQ2dyvunY+9AIqzXsXczILMRxscOowIPj5+JKi9SBtBoIKdrY6JiYcAUeSOn18QIqxb
u44ELS2tEDx2zLh7PbWeqBzZ+0Hh54xPHSfi5uMpMT6JgLpkZeX2KxBky5zCRiNhI54njRCdscRohOgMu5oJMRqhTcMCZ5YYrbCoGL+yxGgl165jxXSAfwDhSRPQJoYn
bYOB7jfLv/vm8BhQpX1jPB6caWBOozxpsiFSltiDq5NWV1cni3F6iYvJAOwlTriQLEqKiq9C2F8xVV126w4bxAseDP/4z97Br4gjKiigrddMl+5Z883WEXEVaXWt9Shx
26f2wuelY08sGrrit+jz8WKKip9QF/l40r60tkIUNKYcyam36QdvkxAfP33qVE8Pz+rqajmeGZKAJw19LTE8afhJPE+awK/ig8LahHnS/s/1w+yuOLxtLudK8sPz//nQ
LxJ50lCX5BTZeNI+lpU1n7JH8/1UVSWfDRVJRWHTP7BhRxdrVq0CimT1PzdulmFTJIYEYNIATxp4/nHNFcMjR1cuX4m3OLm5fz/Dk4ZdBiRob+84fuy4gMAQEsT9cWPG
4iYJIhXSIgmrUECbQF4I6hzc8qvLeN+y4xU1UVzJeOgxMWLG0OW/CieBk6l68BCCC9TlYmKyNO34c3V1i4dX/eQZbMOlsJHGbsqJw13BpRyNsmgBToSXkO3etauoqKhV
ui4HmGX8A0Kyc/IJ1dijR4+5RGTgNyP69Xfvwf1TtvZdu6DHjkPQw8OHBEGPhn38YeFRgBC5g58QYfOmLSR43MISQVYb7ovhSdscNcnpytq8h2ZcCSnbeSCboRcUTogq
kMKTusQniFvN2VlX1xaf0LByDfc1T64pbGRpeorFVUPYsEWyt7MrKysTX79r10t9fAOwlxg8YziEEAyAkVGxrGAoghE/NkVn5+Th5qVL6RjiY5/z5ctZCCanpIE2Dbug
MU+A/dL8GblkBDEHwPwUFZvB31PNTBJkMPHxn2jLzy/k5sK9XrRrpWn8WNfiKd4lM4JLZxPxvzYTdyCAjXBC7BcAwxsEF6hLbG88aRi3dBQWNerpC6OFehu0kP6cElDP
tcPiBz9XS65hjw2hGgPPRlBwuAARGTpvEPYmiM4ePnzMEqOBEg1gY4nRcL/yfhWXJw1pBXjSuNqESc82H965/8zw+FtjhMXpwi+ieNIOHjwE4fOk+QrwpGHogs6YGLSo
z0+KvcAVSk1hw3SKehUy+BGwLuFJQ/9KTeT0GdeRa//j8o0R1x789OLlkFev/gq5+XA4gksOfrvf/Ij4crI8aXAvraFh3KGL+sBDVEkUaviKJaawEYcZ4QmD4uIrrm5n
xfOkcYnOwIG2dMlSlicNxGizZs5iedJwf/26DaDGZBUe2H+QpU3DTajiaus13x3H9szT+0vBlX8BQ1rH+//aVvffHlT9o/7xf5+6ea5EnjTUJTw8gjQh4UG/miNHsZav
UGoKmx6wkTg9DZ40JydX9M16FSwOYFcJIMKpU6dJEARoCLq4uBNiNPwHG4GvXyAhRps4brz7WS9EOHTIoHuVgDWCrLbdu/eIypHcP3zC+G/Lfl6i/+9HrP9127F/w5Bm
+1F9H39wOfVeTvY+6iLMk8ZOMVPYiMKWqmGjEMYVTtzrTBppqdLMByB/8TxpoEfDBABG+YQnLSkpBQN6KAcxGoKxsQmYIUDwjNsZwpNGaNMY9vSLycz5H3zaNCRJuJCI
IKstIeGCNNRnIEkj4uXrL0188TxpEmcF+mUmTeEmoBwFgx02Ms0+w+QSedIwmVZ+p5wlRgPR2Z075SwxGibHuEHcxxEGXJ6069dLoYElPRPQJh8ZmphUDE9aQKD4piRq
DprCRjkQVH8trLeR71snKpibm2ctiSctKDiMy6KG0524QYFfxQeRUCCCcvnZUBdfXz8pH5zA4IfCRkq7aXy0jIwMRVbWoP7gScPnjgHAkEaqYG5hKQdPGhn8UNhoPB5U
VgF8ddHV3X7MyFSjGdJI4a1t7FCXrKxslVlvwGQ0uMY2SnlsiYlJGzdu3r177759BzRaUIszZ9w1i4JDKU9QcSUUNvLYsL6+4Y/f/9B0wbI0eSpP06h+cc3AsDk4XzZu
3KTp0tDQODAeh+prQb2NzDa/d+8+eJLA+aLpPGlMLUpKNY5hUOYH1gcJKGxkM+q7d7XYY1Nxr1K2ZGoZG2xvqMvjx0/UsnRqXSgKG9kez0M+T9qDB49u3Lil6QK3ee36
DbClyWYCGpuObWRtA/erHiQlS+BJ4xKdgbtMPG2aQGThoMAdOcjQxCRBXQoKNemgDlmfVx/Fp95GNsNWVlZh/Rj4bHsV/IRzoSFsnMOHj2ALZ1h4BInv6uaORWj4T4K4
j189Pb1JEKlAs2ZkZMwGBbSJylfu+8gxL69QNhPQ2NTbyNoGKioqY+MuimIhY5nN9u3djziOji5knSgoAhEMCAhmN/aAJC0uPhH3yR1QYSCC3k49EnRwcOTypOlu1ZXI
exaXkAh6NJCk2Z91AZGBxPgkAuqSlZ0nqxFofOptZGsDoGuKjolDx6lXwcZMbGnGiuZr10oRAf0fcKZhTXRx0RUEQeSH7dAIpiSnpl5Kh2Rl5WDJM3ZK4ydEKCq6guXP
WCUNPQiy2m7cKBOVI7lvfMpi2Irfvtny0zd6vzCy4K87TfbGxl8Qnwq/oi7YiS2bCWhs6m1kbQPS8KQBWiw7GbOEmUOMBko0UMawPGm4QJDLk4bIXJo1klw819kOoz3g
SbPJ8qiqfUIk7m7aN/t/n7VtUd/xpMlqtwEWn3ob2R5o2S3wpEWif6Um4u7r859W/M2swOb9hwdcCSkP/t/1Rxlam4ovJ+qSkpImmwlobOptZG0DIHzB1kiQzoCoH9PQ
8AMCRGRgOeMSnYEDbfmyFSxtGpb9z5k1m6VNw/1VK1dxedIQ2cXlDKsTqkCsLsx1xt7RPbp7mOUfvmVW99/EcyXzke8vvlNGr5vaa1rCE4KfUJfExBRZjUDjU28jWxvo
4knLziNUYxUV97hEZEePGpExPS5w39mFOVAAsmL5CgS9vf0JMRr+BwaGghxDZ81aEgExEQHRuoLObgiy2kArJYYnbV3EZLeSLYWPrLgSefvA7suzeuVJu379Bin8lSvX
JPKkyWadQRObwka2R43dl/AVXl6+cDvYRGBiYsolIgMxGsb0GPSnplwiPGmYHsCgHxSdCGIIjhkCAAPEaJj5hWAyAEHMIiAmIhDaNC7NGq5xh9Cs9SrgSTsaN86haKrv
tTkRZdrRtxZDAq7Pcyqehpu98qThdBCUHOW3sLBEXWLjEmQzAY1NO2mytoGSkmueXgxPGnjG4ASEedJKSq7fLa9gidEwGwYHxQ2Wl99lidFwgSBLjIZoiMwlRhPQJsyT
tnrfRtPgn6NvjhMWr8t/fLf8F+EkuGNibEJ40lCX6JhYWY1A41NvI1sbuHL1Klhm1IQkDcUAT9pPa/8j+87IovujHj3Xqn455Gn130oe/ISgnrWWRJ401CUyMlo2E9DY
1NvI2gYk8qSB5czW1o4lKAMl2sEDBmwQxGjgPWNp03CxdYsuS5uGaIjM5UkT0NYr79nGQ9vWHv7L7Yp/a3//33mN33yu/89Pn/7LSfe/gCfNLzBYPFUaw5N2rosnTVZT
DOb41NvI9vQZnjRnN1H8Y5aW1mRMb2d3mkuMRojOQIy2dvUaQpuGa5YnDbRpoFBDBETj8qQJaBNDegZWNAxjDKz+NSr2Hyyd/2X0+r/M37FUKp40Z7eQ0DDZTEBjU28j
axsoKChwcHASxUIWHByCETyafljYOcSJjIrB9ACCLs6uCEZERBPaNMwThIZGQAhtGm4iJiL4+PgiSLjVEYyKiibaAgKCJPKenfH0Mjh+TN/kIMTRzU1ifBIBdQkKCpbV
CDQ+9TaytYG8/PxTdqf9/IN7lZCQcwUFhRBckAjFxVfT09KxCJoEsZIF02L4zwaLiooRhwQRLT8vHzRrJDn+Y+KOq01UvnLfR10CJPGkyWagwRGbwka258zwpNnYiSEr
A62ZeJ40Ado0rOkUIFXjJhfWpmSeNBs7X19/2UxAY9NOmqxtICcnB587BgxPmqWljbe3j6xGoPGpt5GtDeDcKHCLweEMAJ40zG3s3LkrOVmqQwhlM9NAj01hI8MT/vz5
M1jFwsLCNm3asm//QU0X4N/S0urNm7cg4mlv70DtZLDF4I5KYSPh+X/58gVNCg0L3Gjv3tXV1Lx5+fIVNsYUFhYXFBTl5RXk5hXk5ORlZedevpyNsX56xuVLadiqmZ6S
egmHMCcmpeBM2QsXk+ITLsbFX8CJf1gKEBUdGxV9HrNn5yKiw8/hhKnIsLCI0LBzIaHngkPO8SeamQESR8JxH78iDmIiPlIhLTRAD7RBJzRDP3JBXsgR+SJ3lAElQXlQ
Kv5sRDbKidKizCg5yv/kybNnz16gRqgXagcKKAIh1Hpw40JC7SlsJBios7NTADbV1a/Q1NDgHj16ggMGsQ76/v0H9yqr7lZUYm/M7Tt3y27duVl2G8tkQHBxteQ6OC6w
baag8Ep+QVFuXmFObgE2VF7OysU2m/SMLGz0B31MSmp6cko6tt8kJgFpqRcTAbavwt9tdgm/Ig5iIj5SIS00QA+0QSc0Qz9yQV7IEfkid5x3gJKgPCgVyoatqSgnSosy
o+QoP4ENakRgg1cDYNPR8ZHCRnyzoLCR4a0KCHV0dHz40Pr+ff3bt7XE8zx/Xo3G9/jxUwEUgReGBdKt2+VlZbcZLN0oI3ACzRpaNgFV8ZUStHUQ4kDQ7rulGJtD+dJ1
h0RATMQnwIBAz/XSm9DZhZCy28iLgAS5owyV9x9wcYJyorQoM+thmpqaW1vbwJaG2slgi8EdlcJGCc8f72YMDNDy8J5ub29vamqqr28EtGpr68CrhiX6eKM/ffqcRRcB
GJEHfH8Fqap6CEETFyUkAomMVKwGaIMQPCCXly9rAGnkW1f3HmVASYAKlAplQwlRVOpJFH/kFDaK21AeDThhttdkpFn3+iccHweeyZM3TaOwBShsFDah7Aowiy18BrWs
aoCZRj19WVPR+EqxAIWNUswomxKcE4rj3GRLIxS7o7AIR9LihEAF9dDkcliAwkYOoymUBN0zssy5urpaEUVwNYBNWzzdm6mIFeVMS2Ejp+HkTlZUVERgg+MQ5VYCJ0NO
P29YuUZuJTSh3BagsJHbdHImxNnUBDbTp06VUwWPBydDYAPBSbRy66EJ5bMAhY18dpMzVV1dHctniwvMDcinCE6GhU2Lh5d8SmgquS1AYSO36eRJyJ7wTsCDuQE5tMC9
sJjBRf3kGXIooUkUsQCFjSLWkzktJtC43gbXoj7giFEN98KFDa5x4rnMRaEJFLAAhY0CxpMxKabOBDCDIGYIZFTDg3sRgE3zKXtZldD4iliAwkYR68mWFlNnwrDBDIFM
WuBYBDBDgnTFgExmVDAyhY2CBpQhOabOhGGDO5gnkF4LHEuvsMHXT+mV0JgKWoDCRkEDSpsck2a9YgY3pV9oA5fSK2Zwky60kfZJKCMehY0yrCiFDkyaiYKN9AttyIIa
UUIX2kjxHJQThcJGOXYUr4VdUCMKOVIutCELakQJXWijimfJz4PCRhWmZhfUiIKNNAtt2AU1omBDF9qo4llS2KjMyuyCGlGwkWahDXdBjSjk0IU2qnmm1Nuows5VnD8u
crj3JX73BCQ+VVUR4cKGvYkLOrxRxeOknTTVWJmbCxc2cufOhY3cSmhCuS1AvY3cppMzIYWNnIZTp2QUNqp+GhQ2qrZ4H+RHYdMHRhWrksJG1Rbvg/wobPrAqBQ2qjaq
qvOjsFG1xam3UbXF+yA/Cps+MCr1Nqo2qqrzo7BRtcWpt1G1xfsgPwqbPjAq9TaqNqqq86OwUbXFqbdRtcX7ID8Kmz4wKvU2qjaqqvOjsFG1xam3UbXF+yA/Cps+MCr1
Nqo2qqrzo7BRtcWpt1G1xfsgPwqbPjAq9TaqNqqq86OwUbXFqbdRtcX7ID8Kmz4wKvU2qjaqqvOjsFG1xam3UbXF+yA/Cps+MCr1Nqo2qqrzo7BRtcWpt1G1xfsgPwqb
PjCqkErwbrLChQ33vkQKDnALgryGCJdLgL2JC7BwqKI+gz4PChtVNAExlJwERdIQc7anZ4jhFiQ/UeYaVTxOylyjGitLpBcMCw2VWBKJ9IKUBlqiDZUVgXobZVlSnB50
wEQdN0C8jZSHDog6boC4GrgjVVSG5kG9jcraQK+H2xDMSH/EjXjqdHrEjcqeJvU2KjK1mIM6MjKk9RIAhvBRasTV0APVVPQg+dlQ2KjO2sIHdxJvI3EOjVtE4YM7CWzo
sVCqe5AUNqq0Ncb9wtTpsh4W3eshhPSwaFU+R+ptVGptZR15iwM5BGai4YJUWpNBnxntpKm0CQic2CHN+RzC5WsNDROADf3KqdKnSDtpKjY3Rv/cfpo0p0EJlxAndnBh
Q0+DUvFDpJ00VRtc4DRCnG8jXwm4pxHC+cinhKaS2wK0kya36eRMyC60kWZBjag8uAtt6IIaOZ+EAskobBQwnlxJ2YU20iyoEZUDu9CGLqiR6yEomojCRlELypGeLLSR
ckGNKP1koQ1dUCOH/RVPQmGjuA1l1oCZAOkX1IjSThba0AU1MltfGQkobJRhRRl1YCZA+gU1onQDMPRzjYyGV1p0ChulmZIqGjwWGPSw6WznfWrsIV8+D57HT2sqnwUG
JWwAjI63vOYKXn0R731eL9JQwmup4n2sk8+m/ZLqUlr6CUsrtzNnL2flqkASLiQiO4fTTrW1tf1S3/7NdJDBBr6l5T6vvoD3PofXdJPX+oTX8YbX2crD/S+f+NLB+9TA
a6/mtdzjNRQxMdueMffV++/SpTQXV/fAoNCamtcqE2QHcXJ2fTf4kDOYYAMA1OcDCV9a7vLaa3gfa3mf6nmfm3ifW7qQA/B0tjFB3AR44G1aH/EarzKpEFmN/yyOnwwI
DA0Ni1AZZpCRt09AROR5ewen4itX1dg2fVK0wQEbuIvGa7z3WV+abn5pffIFzqQDsHnLAAPwYJDTzPv8gS98zHxu5H18z/v4jtfx+kv7yy/wPEBOS6Xauh2L45YBgSEQ
Z5czaemXVSDnYxPsHRz5sHEsvnKlT9qmGisdBLABEtAle5/Fa6n40vr4S9vTL+0vvrS/YhwOnElLBa+xhC/XuqS5nNf6kPkV/beOV8DYl7ZnXz48ZPpsGPOoZYfN3OKE
f0AwxMnZ7VJapgok5ny8nf3pcxEx+F9cTGGjxhCXp2hwI3VZvPfZDDxaHwAnX9qefIHfAE5q0yTI+zx05760PWeQBoAhOaYQGorVEDlm5scJbBydXFJS01UgUdGxp+wY
2OA/hY08LVN908AzvM/l1WXyWu7wPtzjtVbxPlTy6nN5takySN3lL813GP/DJOf31uCX1OzP1MzCzz8YctrROSk5TQUSGXX+lJ0DHzYORcXFamaPPi/OgO6kNd7gvUvl
NV7nod0znbHrvNpLvHfJ8gim1DDCAWxayhkcos+mTn982ARBHE47JyalqkAiImNsTzmEn4vGfwobdWoLCpYFX2beJTHfZJrKeE23GLeDoCJSl8HAD9JYynuXwsy5qc2f
iam5r18gBPNaFxNTVCDnIqJtbO3DwqPwv6iIehu1aQqKFqTuMuNbGjDQv8EMb95eVIJgOISvPVAINNarUVsxNjHz8Q2EHD9hZWJirgI5ccLKxtaODxu7QgobRRurmqRv
q+a9TeDV5zFzX/AzuFaW1KYw3gZofJfI+9SkJtU1MjbFVxQIpgR279qtArGysra2ORUaFon/hYVFamIHlRVjgI5t6rJ5bxO7PvO/ieMpV+DHGq4yI5zGmyp7TuIzMjIy
IbDx9PS6fv2mCiQrK9fa2paBjbUthY2aNAPFivG5lffmPDO5XF/Ie3uBuVa6YD4N/TR0/NTj75iRiZe3PwQjjZjzCSqQoOAwK2vbkNAI/KewUY9WoGApPjzivY5mxjO1
6cxFXwjQiLm1N/G8DrVYdHP0mDGBjbWNXXRMvAoEq9FOWtkANvhfUFio4BPTuOQDsZOGiWa4F3zixP/XUX0lgCWGN4CoGvwZHjXy9PKDWFmfioqOU67EJyQlJl0SkLj4
iyGh4QkJSfifm5v/9OlzdZCWlhbVPI2BCJu6HN5rfietJqIPBT00TENjalsN/gwNj3l6+kKsrGyxTkyJAnhkXs5RgypKVYSc3AKp4ikcaSDCpuYc032C4KLvBH4Mqw0w
96AGf0eOHPXw9IWcPGmDL/dKlIQLyekZWWpQRamKoLKiDkTYvApjps5qInm46FOBw6lViyZ1+MjRsx4+EMuT1vhyryxxO+Ph6emjgoWhSsxCKngpHGlAwiaUGdW8Cu1z
YbqClxV+BEpQYHDYkMAGnzsxKaws2bfvwFkP7+SUdCLCxyWozx22kEqwphQqBiJsXgYzrgb/+1pehfNqM6Uwcp9HOWRwBO0bYmJqcfq0i7Jk86Ytzs5u7GQAQOJWUa2G
goKxhexzW/MzGIiwwbzzy0AViXossTl06LD7WS+IqYm5cj2AqanFhYspRKD5zL3qx02tj5paHzS2VjV8uN/wobL+QwUjLXfrW26/b75d13yrrulmbdON2qbS2qZr75pK
IG8br75tLH7TWPSmoeh1Q8Hr+vzX9Xmv63Nq6rNr6rNe1V9++T7z5fv0l+/TqusuVdelVtelvKhNfl6b9Lw28Xntxee1F57Xxj97F//0XdzTd+efvI158jb6ydvIJ28i
Hr9BkVAwtpAUNvJaADNp1f4qkqbb8pZSmekOHjp8xt0L4uHpfe/efWUJloQmXEiKi08kgtbpfq+66ePnxo+f6zs+17V/qm3/9K7t45u2j69bO2paO6o/tL9oaX/e0va0
ue1xU1sXuhpbGXQ1MOgCtMrft/Ch1Xyzrhm4us6HFkB15S1A1VjwuiH/dUPe6wYGUa8YRAFOGXxEMXB6ATjVAUsMkJ4xQIp9+g5FQsHYQirTrKJ1DURv01zJe+GrIml/
o5rnJD6XAwcN3M54QrBfDaQCyhKMbcDsERt3kQhap2flS3WDDYqEgrGFVM3jGIiw+VjPe+6tCqkOUs1DkpjL/gOHMOsFYferkV1rCgpgg7ENu+YArdNL/WCDIqFgbCEl
2kopEQYibGCYV+d4zz36XOrylPIMFFeyf/9BVzcPCH/jTZCyBLBxcnKNjIolgtbprX6wQZFQMLaQihtTGg0DFDYtD3nP3Ptc2l9LY2IVxEH7dnU7C2E33pDtNwoK1J52
dGE/nqJ1+t5/1b+dNMwQYFYAQ5pzj96EP3oT9ugNioSCsYVUgbUH6EwaqtXZwYxtnp3pQ3mTqJonJE0ue7thY2RsRtZ0KkUAG+yyxl40ImidflWqgw1m1TD6j336NvIx
4PE64MEr5N6roGBsIaUxl+JxBqi3gWFaHvCeuvahdLxX3PrK0rBn736M3SHHjEzJmk6lCGCDXdZY5kwErdO/L2GDaegLz95F80GCjKQXFIwtpLJMKl7PwIUN6v36Au+p
S5/IezXaEY2K7tmzD8SCEOwgIMsFlCKAjZ29Y1BwOBG0zqAHNUrspGHS+fKr93Ap8CfQLLcwBesuJIWNwhZAV+2ZB++Jo5LlZYTCJVOyAn39vQQ2WC5w/LiVsgSrBCwt
rdnpbLTO4N5gc//Vm+Lbd4tu382/XZ5/qzzv1p2csjtZN+9cvnkn88adjBt38ioecL/b4HNn6ovaiEdvoI0rqRlF4iXizhOBJCSIgrGFVLJlRagb0N4Gde6o4z07y3ty
Wmny8hwzcFKzv92794CPE4JBjnJXCcDhsPNyTF/owWuut7nz+Kme/p4xf4zevEV3q+72bdt37Ni5S2/X7l36e/T37ENh9h84eNDg8PLlK6ZMnuIecyHxWS00CEjknacV
NqdxMlzdooW169bUbtCp27Shbuumum1b63Zsr9ulV6evX7dvf92BQ4jzyNYJ8QU0MHMV3fOHqnkyAx02BDlPz/Ae2ytBqsPVEDOo4q5d+k5ObhAsWFYiezpmdYNDzrHT
cczI++FX2JQ/fgrAGBmZYlccPtKDChQ7c/ILiq6WXL9Zdrv87r0HDx49e/aipuZNfX3Dndt3pk6Zesw7GBoE5PnWHQ3TJ7a6Hm0Pte2IcuqI9/iYGvgpK/JzYULn9bTO
O3mfH1z7/Ly88+3TzrfVLWfOvN68I6r8KVcJCsYWksJGeRYAcqrDeI/tFJKa8+qJGQIbRydXyOHDR11czypL4GqwXZSdlBOAjaGxqf7uvf4BIVhwLQ1yHj58OHHS5MCe
LT4rKev9mDGt9vvazh5t87OQiJwvTbWNhkevhZ4XgA1bSOU1GnGaBoG3IdVHz6oun/fYVh7BvEKjWuziFPUk9fR2Ozq6QgwMDJ1d3JUlgM1JK1uyAQ7CfB559IbtpCF4
2tEVU3Y9kJMccGzK91pTzWKv9OJzjhw54ny5GEpYKXd0b1w3/8Op3a3OB/nIMX9nMmfkkG+7u5ojt+23vJ+fyvU57RmXXuw14CpBZLaQFDZ9YAEwm71L5z22llaeOjHx
1W8wI2AajCgcTrtAsKaTDHKUIoCN5Ukb97PeRNA6MY7nwgY5YmlCD+Scs103DI1+rmlkjnBv7bCBgcvlYihhpcLOuXHV7GbLbd3IMXxrOJMDGwY/I7dY13N6ax1Xcl7s
OcRVwqwx7S5kHzSaXlQOGm+Dun94zHubxsytPTopgyB+ba6aMNSIahN82DhDDhw8jO/6yhLABuybZNkOhFnD8vgtFzYgyumJnIig42t/HDp6wugxG50uCo9zMEXgmnUF
Sli5Z+fUuGx6s/GGbuQceHtw+sghI4xMzJhxToS5/4KftIatupwez45zOnJTXuw5yFWCgrGFpLBRkgXgK95fYebTHp1QSKCh+Z6SyqRkNdu377R3cIYcOHCI4EcpAthg
uyg7UmJWTD7pAZvjJ072RI6H6bJfflxp5rB/5o/rTl8UmiHYu2evW/YVKGEFsGnQntx8eFU3cna92Ttl5JDhxwwNmXFO8FG/uSO0Ju24l/l1hqAjI65a/wBXCQrGFlLJ
lh2ME9AEMJhDe3hcafLUnddUoZpnI30u27btsLN3guzbfxAfKJUlgI2FhSXb30PrxP4w4m2qWzoQxBK4HsjxtN4+5vflpr6RbvsnDV1nH3tJYG5Nf7f+mewrUMLKvVOO
DXPHN+1d3I0c3dd6E3t00kYvOO/hxJ1b60iOqN69n6sEJWELKb3RFIk5cDtpLY94j0/xHpr3ibzw44FmWm3+WNh4eHh6ePrgqCalCGBjZn6CjJogaJ3nn7x73/7pypsm
XCAIxhwuclzMN4/VWnrMIzjU12LV0D/3e8QJzErr7dRzz76KtKxU2jrWzxzTtH1uN3LWv9Id13NsM1x3z9H3nFnpjvjA6l37uEpQEraQqnkmAxE2OLm2Jpb3wLTP5Z1a
0NagoWzduu2UnSPEzs6h+uWr/IJCe3tHnDyjoDCwMTuOZWlE0Dqx+pgVBLFhgYMc62M6EzgfW4dN3OMe2/N7zo7tOzxyrnKVMLCZ8nvjxj+7kbPy1cYxI4d8f1RPl5lb
c99bsH78yCHj/Fzt2e85HVFe1bv2CpSELSSFjVwW6HjHe+rMe2CsIsF+OKC0v/9Y2JibH7+clYuvjXV1dXn5BYANxh5yC2ADLgHWcQESzIb+bkFw1+49HOQY75j1U481
CuP03aJ6fAnFUgLP3KtcJfdtHd+P+7lh5eRu5Gi/Wvv3kUOGGepuIHNrH45ra7MzBHyf0x7qWq23R6AkbCFV8ygGlrfBNpuHlryqoyoV5Nj+VjVPS1QuW7bo2p46DcGm
6KzsXCKV9x80NjbeuVPuduYsCM7lEMAGfTAWdYBEwrNaVhAEXL8i58jmmd+NmL3Dgj+3dtbZYOkPQ6bucgzlfgndvHmLZ24JV8l9G8f3v/9Uv3AMi5yXK35lYLNxNX9u
bfut9XA+3TME/DUEbf52gI1ASdhCquZBDCDYNJXzqgz7Rx6e6F/kbN681cbWAWJmZtENm7ysbEbu33/Q1tbW1NSMg2kDAoNsbOzwBVMacXZxAy06Oj8s3oATcF+wguD6
9RtZ5Bzerv3bkNEr9lt0za3ZH9LW+hkDHe4agg3rN3rnlnCVMLD5aUT9jN9Y5LzUHiXw3Ubr11nFTobsGoJWD8uXevoCJWELSWEjiwUa7/DuG/SnPLDoR+T0hE0XYLJz
8lm5dbv8zZu3nz59gk2bmppevnyZkZGZknoJctbD88yZs+ciIknw9u07+LWjg1mumpqaERwSBqZPIsAJFvmzguDKlau7kbNry7zftEZp7zZm59as988f9cMiw7Oc1Tfr
dNb55pZwlVRZO74f+mP92J9Z5FTP+4kDm+/mzJxVaKrXvYaAWX3T6mrycqe+QEnYQsrSaOSPOyC8DfpID8x49w/2s6AM/TTO2bhxMw4DhJiamhMnwwIGbOKs5OYV3r5z
9/nz6oaGxtbW3s8efV9f//bdu4cPH18vLcM5U1g+Y3H8JBEGNuBb6hYE589bwEEOd5wj8D2na93aokWLffOucZVUnj7z/q/DGIfDQQ5nhoD9nsOuvrFosdB/bmAoUBK2
kPJDQZaUmg8btNQHJrz7+9VCnrrJYnylxd2wYRPp3OPUTlGAAWYgeflfBV/xi6+U3Cm/W363ouzW7YLCYr5cYQWr8bE81NziBBHgBExlrGw1NB47Zpy29hIpkQM+qr//
MfrCg5dcJUV51+qGjXo/5HvpkVM/a1pZbDJXCQrGFlJpNhWrSPNhA86A+3vVSOpyVfPkuLl8hY0pAxsBD0MAw8UMAMNKN1p6AKaw6AoEsME6HZBIERGATcydhyNHjgJy
Fi7UlogcrG37/dffnXo2d9L0Hx+zqNP6SRrktFhsa1w8882K1VzM4BoFYwupGuNrOGzeX+VV7lY7UTnn4Lp1G7DCH4KJL26XTG7AADNFxVextBmwwXm6RNA606rBN/tV
zl2/u2jtBtwfN3Hy1Jmzp8+eO2POvJnzFs6ev2jOQu15i5YsWLxs4ZLliDBt1lyP1GyB5Gyw0s2n7sdf60b98W7itHeTp7+bOuPd9Bnv/pxZO2tm7ZzZtfPm1C6YWzdu
ArapPTE/efnhKwE90M8WksJGkgXQPas6wqvUUzvBumnV/unorCeTY8bGDGxYtEjhYYpx8BMkLf0y8TBEgBkIdhoDNjgYlAhaJ3hle5XggutiJO7uI1EJuffz7j6+WnBd
lBSW3hWlBAVjC6kaw2uyt3mTwru3Q02lsUw1z4/ksnbtOhwIBcFLV9jDYDwj3CXLzsnz9fPHabVP+X/37t3Dh8mo6PMEMBAMewKDwk6fdsZRbUTQOsHIrIaCgrGFVI3Z
NRY2Hxt497aprzy0UM3zI7msWaODwQOEwEZg3E8wwxnDFCclX4qJOU/SPr1589y2beT69evXYeHnCGYgoIPBSmqcOUUErRNEM2ooKBhbSNWYXWNh8yaJV7FFraXhpmoe
IXJZvXrtCUtriJGRCYsZUeN+zBlER8e08v+KIyKSj58483/9l6sRES8fPMAdICf8XAQwc+XqNZCPwdvgFBAiaJ04AkANBQVjC6kam2smbDCqwexZxSa1Fqy/VtUfA5sT
VhACG/ETZTjb+dWrmtrauvN79wb8t/8729Qs5n/9U46pedj/+IeqqyW4f/FiIjADwQd+eBvwshNB68T5GWoozKLS7kKqxuSaCRu8yO9u0ABBT1Ilf6tWrcF+Mghg09vM
8tfJZQz3g4JD8MXzSlxC+P/8h9txCbd8/Qv/8d+fVj0sWLchde4C/HT37r0LF5OwpRkMsYANVqYRQevMralXQ0HB2EKqxN4aepraC3/eXR0NkLpC1TxFfDaxOG4FwYSS
wDCG/XbJzpJFRERVVT3MOeuROWc+Lio9vJ7+69+Yi4tJ+f/w75W3y3Ht7eML2ICPHLAB5ScRtE4c2KSGgoKxhVSNwTXT25Sv4WmEPLRSzVNcsWIVWV1y7Jix8OdLgZnl
sPAILFHLcXYtmjUXF3fzC+8npeDifkxc+T//texaKa5Z2GApJ9Y4E0HrxGlnqqmR9LmgSCgYW0jpEyoSUwNh8+EJr3ylxsjn3pd+KfLMhNMuX76yJ2y+LpAR+BSDWTLM
O8OT5Iedu/FPf6nwD8Q15Fp+4esVax7NnIvrtLSMi4nJuAC9oIODM9ikiKB1Fr5RO9igSCgYW0jlGlaUNg2Ezdt03p3lGiOgy+n7v2XLVphbWEKOHoW36cKMMGDIzHJ4
eAT2KuOraMmhI7V/GfpMb0+ltd2bP+fiG/zV8Ejc9/ENAGZKrpViq4yDg9OOHXpE0DpxvKYaCgrGFrLvjc3koIGweebJu6OtMfL2kgoe5NKly7HpH2J41AiwEf7ez36K
IR9kTp92upSWCblx/ORznY2Qx9v08sOjcCc6JjY2LgGYgeBkP3TSdHW3K12MjU2wLVTpaqFQBdbWTNiAieb2Ao2RV7EqeJBLliwzNTsOMTx6TNjJEKgQITPLmDY47egM
VLAHLJMLnPUZERlNMHPt+o2Y8wn29k7YOqpcwQDs2bPnpaU3lKuWaFOBtTUTNrfn8TRIQDzd93+LFy/tgo0hAxt2gQzXyRDAEEEfrKCgyMfXz87u9Bl3T9BqwqvgmM7E
pBQCGCI4fhn3N23aonRJSUk9ceKk0tVCYd8bW0M7abdm8zRIHqnioyc2vZCV81iaxV1UxvUwLGDIHABXiHvhAgaYuV56E0s8cVI0eKU1RTAxQGEjwgK3/uRpkDyyUcGD
xK5JnBENAf2SGA/TK2DS0jPhZDBtzToZAIZIfEISBDvVbGzsNULAl6ACa2tmJ61sGk+D5KG1Ch7kV9gYHhMYxpAumSgP4+PjFxERiXVoBw8eysnNZwGDi9LSmwkXkkXJ
hYsp7If5S5fSxNRx+vQ/ZRIVmEvxLDRwJq1sMk+DRCVfPLG/EhvUIPA27LhfFGDI5DIRb2/f9+/rIffvV4WEhBHYADBELiamiJLEpFQObMTNFs6dO18mUbxNq0CDBsLm
5gSeBglY1Pr+b8GCRWR7I2DDHfdLHMbY2NiWl1dgNU1iYnJkVAwLGObiRlli0iVRgq0HUsIG4y6ZpO+tpYQcNBE2Y3k3NUdAodb3f/PnL8RhgJDDRwzF98oExv3x8Rfg
owKDQszMLIqLr3bB5kYZMANJSk4TJcnJaSxsUlPFeRusl5NJ+t5aSshBA2Fz43eeBgn40/r+b968BWRX8OHDhmI8DBczAsMYAcAAMzdu3sJiAjEiJWzAcyCT9L21lJCD
JsLmZ94NzZEH5kp4SpJUYPBw9JgxRAA27BhGVsAAM5DUSxlihAObVDEFlPWbpqS6qsXvmgibn3g3NEfAOdj3f3PmzMNqNIiBwRHibXoFDPkaIzDuJ8MYIgQtRMC/Dl4O
0ZIpJWx27twlk/S9tZSQgwbCpvQHngZJlakSnpIkFbNnzzU8agwhsBH1+VJ6wAAz0sMGn/zFFHDP3v0yiaS6qsXvmgibobxSzZEqExU851mz5hwxNIIcMjjS6/f+XpxM
t4fhOhmCFiJlZbczMrNFSXpGFuttBGDT0tLy+vUbyPPnL27evGVldYoIeHHFCE7aINGQBEI0QFRgPTmy0EDYXB/C0yC5byzHU5E1ycw/Zx0xPAbZu3e/fMMYAcAAMxAc
IShKACcWNiDBwZef3Nx8/4AgLKDOzMwicvt2OStgL5AoWN/JxsdCT6IEbO44H662rk5Wm/RpfA2EzbW/8DRI7hv16fMjylevWrNbfy9k6ZJlZI2MNBNl3GEM62EIYBi5
dQcnTIkSjHlY2OA7KT7+uLm5n3H3CAwM8fTygeCcD9tT9kRYEjOJFxYWJ9hU0EZUgf+toEBF28ulfFgaAJvOzk6cMNHe3vbhw4emxkZeyb9okHy8vQ8f4XE2Bgrf3tHx
+fNnVEfKZyMx2pcvXzo6PoKlCd/4scFTpjUsyoqM49YIWTtOpJJ10kz6+NgDVFPz5u1beJ33jY1NqDIqjupLNFEfRVBH2KBhffz0CYcZtTQ1o829ffP6xfPnjx48uHf3
7s3S601X1zcWr20oXPW+YHld3pLa3EVvs+e/yZrz+vLMmozpr9Inv0ybWH1p3IvU0c9Tfn+W/OvTpFFPE396cvHHxxe/f3xh2KMLWo8ufCejaCHh44s/PEkcDlVPk36G
2ucpf3+ROgYZIbtX6VNqMqe/vjzrbdbcdzkLanO16/KX1heuaCha/arIqKS46NaNG5UVFU8ePXz54sXbt29QqZbmZrwI8DqQD0UfP35C08FhT+gdoTHV1Ly+caMsODg0
KCgkKCg4ICAI4u8f4OcX4OvrD2IAL+a17e3h4YXTbM6e9TjjftbtjLur2xmcewa34Ozs6ujkgh04DqedHE472tvjxFyHU8zRn1jByRxkwBBMM2S5DPEnTpJhONn4/FI4
5BC7dLDcE0vXPL18bW2Je3HAQMXO/rS9gyMUgmnN0dHFydkVgrxcXc/AL+GANzgT97OeKI+Hp7enp7eXty9W+vj4+qPAfv4BTBUCg5nqBIeiXlevXnvy5NmzZy+qq1+h
sqgyKo7qwwgwRR9hQ4xatYMN61vQsL5i5uFDYOZG6fUrhQU5WZfTU1MSExJiIiPDgkMCfHw8zpxxdnCwtbI6bmpqdOTwoX379Hfu1N28ef3atSuXL9detGjOnDnTpk+f
On2agjJ9xoy5c+cuWay9asWKDTo627Zs3aOnZ7B/v8lRwxNmZnbW1q6Ojl7u7oG+vudCQ2Ojo5MuJGRcSs3LzgJyyljkVFcDOY0NDR9aGOTA/8j31kRCvFmam1u6kfPm
5ctXoGtC83r8+OmjR09wRs2DB49wmtq9yqqKisryu/fu3LkLeg10wNA9w7wzOnIYCGHmDcvYsG4a20KxfQ00a9gXDe+BQ3LQQ8PYBsMYTACQmWiyJ1T4Yw65T+IgMpIg
IZKTk3agkLC3IQuyQJtM96EziWKgMCgSCobioZAoKgqMYqPwqAIqguqgUqgaKkh8DsEMzq6CEVSPGeSodrBhrQD8wCjo2JC+WV1t7euaVy+ePXv0oAoQQissuVJckJuT
lZGelpJ8MT4ezTQiLCwkIMDf2xtAcnNyOn3q1KmTJy3Nzc2NjIyOHDmCVb579+7bvXv3zp07t21Do9fdtHnLxo2b1m/YhDPB1jGCi80bNm7ZuAmo2751q9727fo79fbr
6xvs22d48KCxoaGFsfFJCwu8e3EoM97SAIm/j09IYGBkeHhcTExSQgIKk3M5sygv99rVK7fLbhInA2+JWaH3/N5aW+uHjx+Z563cHkaXudrbGXM1Nb17V4cWhnb24sVL
vKR7YKkbTjjc8969+wRRGJyg1eLQKAZXt+6gHWO0w6ALE278ZZ3AGLuzgPtRSGDi7utKUP5XIDIjB4VQC+UMMMorurBx7z4KQODx4OFjLkJQYBQbhX/9+m19fSO/iwuv
8lHuV4zSoaW+sBFTVdJEYMeO9nY4Jby50SLxCsdkDRro0yePAa2qynsVeH+VlcFHXbt6Fe/74vw8wCw/JwvNOjsDr8T0zLRL8AYZqalwX6wgiJuZ6WmIgGhwbkiChMWF
+VByveQqNN65dQvQraqsxPsQb0J0vQDpd2/fwj02M8BAz7vj06ePKKd8nkTpj5koRGEwtkLPEKZrb+9oa2vHmWpokfX1MGA9hg2g5KytrX33rhZv9Ddv3uHcQjILDARC
gD1W4AFYYW+irZOYJBWSQwlUQSH/D8dX40HVt7QA2uhewVm2oxgED3xTKfdN0kdWZNRqJGz60B5UNbWAFBagsJHCSDQKtUBPC1DY0BZBLSCzBShsZDYZTUAtQGFD2wC1
gMwW0FDYvMs2mQIK06+iHVgl1cf3tqrAdVrDzbMbe8TurApcMmSKafa7Lvs1ZpsOH7EksFIqlTLbnCbQeAtQ2DCPkMJG4xuyaiugybCR1sNwLUq9jWrb1wDNbSDBhg8J
bc/sTKv5TP9N2yL7ZVcvq7Pmmuu2UUO+HaXrEGCiLUsnrbO5Kt507gitISPmm8RXNRN9jVWZbtuHM1mYxlc2M3dI1g5x/nqj5AHzAG1cA7damgwbwbENv+3OnDefadB8
6RrD1Jc6LesxEJJ+bNNZGaQNzBCFI+Y7lTTzOptL3fiwJLLMubS+CzYkawqbgYsWtmYDDjZdTqbjZfyBUWSUzx/fzzfPrIGraC4P0h0ng7dhYPMbf26Ar5DB2xvMRozS
i+c7MmZmYpRJdiPxNlz/NgiazmCuoibDRvC93mPcwo7yew73ZR7bdNaUhAeGxmVX8TtjmD3g+h++w2GK0bvawdywBnbdKWzEzqQ1V2XHp5bWdPCaqy47mVtgJENhM7AB
IV3tBj5sujppzLAEvuJZgl4vnTR+HEwYhAIWGPFXBup1dfAYkEzZHliOIU1jtrlgJ625xHku6cJRbyNdcxsosTQZNr1OCXQP9zl9M+6UwIjZc2fyW7/Al0yh76ddccgY
iTvH8KnHlEBXNAqbgQII6eoxGGCDmYDKBMw7MxPQgVfjTXqDDeKgG8ZMUvOjuV2uauwyYOfLbHMmrdZck9BSZlrh6wT0cL2gShKNwka65jZQYmkobAaK+Wk9NNMCFDaa
+dxoqfvVAhQ2/Wp+mrlmWoDCRjOfGy11v1qAwqZfzU8z10wL/P8dploe05yWbQAAAABJRU5ErkJggg==
              </image>
              <para>
              </para>
            </content>
          </block>
          <block>
            <title>Applying the controls</title>
            <content>
              <para>
                For the purposes of this section, the gateway assumes the highest sensitivity or classification of the connected security domains.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Allowable gateways</title>
            <content>
							<para>
								There are significant security risks associated with connecting highly classified systems to the Internet or to a sensitive or lesser classified system. An attacker having control or access to a gateway can invoke a serious security risk.
							</para>
            </content>
            <controls>
              <block>
                <ID>0626</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Allowable gateways</title>
                <content>
                  <para>
                    Agencies connecting a TOP SECRET, SECRET or CONFIDENTIAL network to any other network from a different security domain must implement a cross domain solution.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Implementing gateways</title>
						<content>
							<para>
								Cross domain solutions should implement products that have completed a high assurance evaluation. The Defence Signals Directorate’s (DSD’s) Evaluated Products List (EPL) includes products that have been evaluated in the high assurance scheme. However, the EPL is not an exhaustive list of products which are suitable for use in cross domain solutions. While cross domain solutions are not listed on the EPL, DSD can provide guidance on the agency implementation in response to a formal request for advice and assistance.
							</para>
							<para>
								Connecting multiple sets of gateways and cross domain solutions increases the threat surface and, consequently, the likelihood and consequence of a network compromise. When a gateway and a cross domain solution share a common network, it opens the higher security domain to exploitation from the lower security domain, which may include the Internet. DSD will be able to provide the necessary adjustments to the security controls of one or more of these connections to maintain adequate protection of networks connected through the cross domain solution.
							</para>
						</content>
            <controls>
              <block>
                <ID>0597</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Implementing gateways</title>
                <content>
                  <para>
                    When designing and deploying a cross domain solution, agencies must consult with DSD and comply with all directions provided.
                  </para>
                </content>
              </block>
              <block>
                <ID>0627</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Implementing gateways</title>
                <content>
                  <para>
                    Agencies connecting a typical gateway and a cross domain solution to a common network must consult with DSD on the impact to the security of the cross domain solution and comply with all directions provided.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Using gateways</title>
						<content>
							<para>
								The system owner of the higher security domain of connected security domains would be most familiar with the controls required to protect the more sensitive information and as such is best placed to manage any shared components of gateways. However, in some cases where multiple security domains from different agencies are connected to a gateway it may be more appropriate to have a qualified third party manage the gateway on behalf of all connected agencies.
							</para>
						</content>
            <controls>
              <block>
                <ID>0628</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Using gateways</title>
                <content>
                  <list>
                    <head>Agencies must ensure that:</head>
                    <item>
                      all systems are protected from systems in other security domains by one or more gateways
                    </item>
                    <item>
                      all gateways contain mechanisms to filter data flows at the network layer.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>1192</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Using gateways</title>
                <content>
                  <para>
                    Agencies should ensure that all gateways contain mechanisms to inspect and filter data flows for the transport and higher layers as defined in the OSI model.
                  </para>
                </content>
              </block>
              <block>
                <ID>0629</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Using gateways</title>
                <content>
                  <para>
                    For gateways between networks in different security domains, any shared components must be managed by the system owners of the highest security domain or by a mutually agreed party.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Configuration of gateways</title>
						<content>
							<para>
								Given the criticality of gateways in controlling the flow of information between security domains, any failure – particularly at the higher classifications – may have serious consequences. Hence mechanisms for alerting personnel to situations that may cause cyber security incidents are especially important for gateways.
							</para>
						</content>
            <controls>
              <block>
                <ID>0631</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Configuration of gateways</title>
                <content>
                  <list>
                    <head>Agencies must ensure that gateways:</head>
                    <item>
                      are the only communications paths into and out of internal networks
                    </item>
                    <item>
                      by default, deny all connections into and out of the network
                    </item>
                    <item>
                      allow only explicitly authorised connections
                    </item>
                    <item>
                      are managed via a secure path isolated from all connected networks (physically at the gateway or on a dedicated administration network)
                    </item>
                    <item>
                      provide sufficient logging and audit capabilities to detect cyber security incidents and attempted intrusions
                    </item>
                    <item>
                      provide real-time alerts.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Operation of gateways</title>
						<content>
							<para>
								Providing a sufficient logging and auditing capability helps detect cyber security incidents and attempted network intrusions, allowing the agency to implement counter-measures to reduce the security risk of future attempts.
							</para>
							<para>
								Storing event logs on a separate secure log server increases the difficulty for attackers to delete logging information in an attempt to destroy evidence of their attack.
							</para>
            </content>
            <controls>
              <block>
                <ID>0634</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Operation of gateways</title>
                <content>
                  <list>
                    <head>Agencies must ensure that all gateways connecting networks in different security domains:</head>
                    <item>
                      include a traffic flow filter on all gateways to filter and log network traffic attempting to enter the gateway
                    </item>
                    <item>
                      are configured to save event logs to a separate secure log server
                    </item>
                    <item>
                      are protected by authentication, logging and auditing of all physical access to gateway components
                    </item>
                    <item>
                      have all controls tested to verify their effectiveness after any changes to their configuration.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Separation of data flows</title>
						<content>
							<para>
								Gateways connecting highly classified systems to other potentially Internet connected systems need to implement diodes, content filtering and physically separate paths to provide stronger control of information flows. Such gateways are generally restricted to highly formatted formal messaging traffic.
							</para>
            </content>
            <controls>
              <block>
                <ID>0635</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Separation of data flows</title>
                <content>
                  <para>
                    Agencies must ensure that all bi-directional gateways between TOP SECRET, SECRET or CONFIDENTIAL networks and any other network have separate upward and downward network paths using a diode, content filtering and physically separate infrastructure for each path.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Demilitarised zones</title>
						<content>
							<para>
								Demilitarised zones are used to prevent direct access to information and services on internal networks. Agencies that require certain information and services to be accessed from the Internet can place them in the less trusted demilitarised zone instead of on internal networks.
							</para>
            </content>
            <controls>
              <block>
                <ID>0637</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Demilitarised zones</title>
                <content>
                  <para>
                    Agencies must use demilitarised zones to house services accessed externally and mediate external access to information held on internal networks.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Security risk assessment</title>
						<content>
							<para>
								Performing a security risk assessment on the gateway and its configuration before its implementation assists in the early identification and mitigation of security risks.
							</para>
            </content>
            <controls>
              <block>
                <ID>0598</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Security risk assessment</title>
                <content>
                  <para>
                    Agencies must perform a security risk assessment on gateways and their configuration before their implementation.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Security risk transfer</title>
						<content>
							<para>
								Gateways can connect networks in different security domains including across agency boundaries. As a result, all system owners must understand and accept the security risks from all other networks before gateways are implemented.
							</para>
            </content>
            <controls>
              <block>
                <ID>0605</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Security risk transfer</title>
                <content>
                  <para>
                    All owners of systems connected via a gateway must understand and accept the residual security risk of the gateway and from any connected security domains including those connected via a cascaded connection.
                  </para>
                </content>
              </block>
              <block>
                <ID>1041</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Security risk transfer</title>
                <content>
                  <para>
                    Agencies should annually review the security architecture of the gateway and security risks of all connected security domains including those connected via a cascaded connection.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Information stakeholders</title>
						<content>
							<para>
								As changes to a security domain connected to a gateway potentially affects the security posture of other connected security domains, system owners need to become information stakeholders in other security domains to which they are connected via a gateway.
							</para>
            </content>
            <controls>
              <block>
                <ID>0607</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Information stakeholders</title>
                <content>
                  <para>
                    Once connectivity is established, system owners should become information stakeholders for all connected security domains.
                  </para>
                </content>
              </block>
              <block>
                <ID>0608</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Information stakeholders</title>
                <content>
                  <para>
                    Once connectivity is established, system owners must become information stakeholders for all connected security domains.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System user training</title>
						<content>
							<para>
								It is important that system users know how to use gateways securely. This can be achieved through appropriate training before being granted access.
							</para>
            </content>
            <controls>
              <block>
                <ID>0609</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>System user training</title>
                <content>
                  <para>
                    All system users should be trained on the secure use and security risks of gateways before access to systems connected to a gateway is granted.
                  </para>
                </content>
              </block>
              <block>
                <ID>0610</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user training</title>
                <content>
                  <para>
                    All system users must be trained on the secure use and security risks of gateways before access to the systems connected to a gateway is granted.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Administration of gateways</title>
						<content>
							<para>
								Administrator privileges need to be minimised and roles need to be separated to minimise the security risk posed by a malicious user with extensive access to the gateway.
							</para>
							<para>
								Agencies must provide system administrators with formal training to ensure they are fully aware of and accept their roles and responsibilities regarding the management of gateways. Formal training could be through commercial providers, or simply through Standard Operating Procedures or reference documents bound by a formal agreement.
							</para>
						</content>
            <controls>
              <block>
                <ID>0611</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Administration of gateways</title>
                <content>
                  <para>
                    Agencies must limit access to gateway administration functions.
                  </para>
                </content>
              </block>
              <block>
                <ID>0612</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Administration of gateways</title>
                <content>
                  <para>
                    Agencies must ensure that system administrators are formally trained to manage gateways.
                  </para>
                </content>
              </block>
              <block>
                <ID>0613</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Administration of gateways</title>
                <content>
                  <para>
                    Agencies must ensure that all system administrators of gateways that process Australian Eyes Only (AUSTEO) or Australian Government Access Only (AGAO) information are Australian nationals.
                  </para>
                </content>
              </block>
              <block>
                <ID>0616</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Administration of gateways</title>
                <content>
                  <para>
                    Agencies should separate roles for the administration of gateways (e.g. separate network and security policy configuration roles).
                  </para>
                </content>
              </block>
              <block>
                <ID>0617</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Administration of gateways</title>
                <content>
                  <para>
                    Agencies must separate roles for the administration of gateways (e.g. separate network and security policy configuration roles).
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>System user authentication</title>
						<content>
							<para>
								Authentication to networks as well as gateways can reduce the security risk of unauthorised access and provide an auditing capability to support the investigation of cyber security incidents. Additional information on multi-factor authentication is in the Access Control chapter.
							</para>
            </content>
            <controls>
              <block>
                <ID>0619</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user authentication</title>
                <content>
                  <para>
                    Agencies must authenticate system users to all sensitive or classified networks accessed through gateways.
                  </para>
                </content>
              </block>
              <block>
                <ID>0620</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>System user authentication</title>
                <content>
                  <para>
                    Agencies must ensure that only system users authenticated and authorised to a gateway can use the gateway.
                  </para>
                </content>
              </block>
              <block>
                <ID>1039</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>System user authentication</title>
                <content>
                  <para>
                    Agencies should use multi-factor authentication for access to gateways.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Information and Communications Technology equipment authentication</title>
						<content>
							<para>
								Authenticating Information and Communications Technology (ICT) equipment to networks accessed through gateways assists in preventing unauthorised ICT equipment connecting to a network.
							</para>
            </content>
            <controls>
              <block>
                <ID>0622</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Information and Communications Technology equipment authentication</title>
                <content>
                  <para>
                    Agencies should authenticate ICT equipment (e.g. 802.1x or by media access control address) to networks accessed through gateways.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Configuration control</title>
						<content>
							<para>
								Changes that could introduce vulnerabilities, new security risks or increase security risks in a gateway need to be appropriately considered and documented before being implemented.
							</para>
            </content>
            <controls>
              <block>
                <ID>0624</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Configuration control</title>
                <content>
                  <para>
                    Agencies must update the Security Risk Management Plan before changes are made to the gateway to ensure all security risks have been accepted.
                  </para>
                </content>
              </block>
              <block>
                <ID>0625</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Configuration control</title>
                <content>
                  <para>
                    Agencies must document and assess all changes to gateway architecture in accordance with the agency’s change management process.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Testing of gateways</title>
						<content>
							<para>
								Testing security measures on gateways assists in ensuring that the integrity of the gateway is being maintained. Testing at irregular intervals should be performed as an attacker aware of regular testing activities may cease any malicious activities during the known testing period to avoid detection.
							</para>
            </content>
            <controls>
              <block>
                <ID>1037</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Testing of gateways</title>
                <content>
                  <para>
                    Agencies should ensure that testing of security measures is performed at random intervals no more than six months apart.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Additional information on implementing a cross domain solution can be accessed from the OnSecure website at https://members.onsecure.gov.au/ in the Guide to Secure Configuration of Cross Domain Solutions publication.
              </para>
              <para>
                Additional information on the OSI model can be found in the ISO/IEC 7498-1:1994 Information technology – Open Systems Interconnection: The Basic Model from http://standards.iso.org/ittf/PubliclyAvailableStandards/index.html.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Data Import and Export</title>
        <objective>
          <block>
            <content>
              <para>
                Data is transferred through gateways in a controlled and accountable manner.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the requirements for the movement of data between systems via gateways.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Fundamental requirements of data transfers between systems can be found in the Data Transfers section of the Network Security chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Import of data through gateways</title>
            <content>
							<para>
								To ensure the continued functioning of systems, it is important to constantly analyse data being imported over a network.
							</para>
							<para>
								Translating data from one format into another effectively destroys most malicious active content.
							</para>
            </content>
            <controls>
              <block>
                <ID>1156</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Import of data through gateways</title>
                <content>
                  <para>
                    Agencies importing data to a system must ensure that the data is scanned for malicious and active content.
                  </para>
                </content>
              </block>
              <block>
                <ID>1042</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Import of data through gateways</title>
                <content>
                  <para>
                    Agencies should convert data being imported at gateways into another format before entering the network.
                  </para>
                </content>
              </block>
              <block>
                <ID>0659</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Import of data through gateways</title>
                <content>
                  <para>
                    When importing data to a system through gateways, the data must be filtered by a product specifically designed for that purpose.
                  </para>
                </content>
              </block>
              <block>
                <ID>0660</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Import of data through gateways</title>
                <content>
                  <para>
                    When importing data through gateways agencies must perform full or partial audits of the complete data transfer logs at least monthly.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Export of data through gateways</title>
            <content>
							<para>
								To ensure the continued integrity and confidentiality of data on a system, data must pass through a series of checks before it is exported through a gateway.
							</para>
            </content>
            <controls>
              <block>
                <ID>0667</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Export of data through gateways</title>
                <content>
                  <para>
                    Agencies should restrict the export of data through a gateway by filtering data using at least protective marking checks.
                  </para>
                </content>
              </block>
              <block>
                <ID>0673</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of data through gateways</title>
                <content>
                  <para>
                    When exporting data through gateways agencies must perform full or partial audits of the complete data transfer logs at least monthly.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Export of highly formatted textual data through gateways</title>
            <content>
							<para>
								The security risks of releasing highly classified data are partially reduced when the data is restricted to highly formatted textual data. In such cases the data is less likely to contain hidden content. Such data can be automatically scanned through a series of checks to detect classified content. In addition, the security risk is further reduced when there is a gateway filter that refuses to export data above the sensitivity or classification of the network outside the gateway.
							</para>
            </content>
            <controls>
              <block>
                <ID>0671</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of highly formatted textual data through gateways</title>
                <content>
                  <list>
                    <head>When the export of highly formatted textual data occurs through gateways, agencies must implement:</head>
                    <item>
                      data filtering performed by a product specifically designed for that purpose
                    </item>
                    <item>
                      data range checks.
                    </item>
                  </list>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Export of other data through gateways</title>
            <content>
							<para>
								Textual data which is not highly formatted can contain hidden data. The security risk is somewhat reduced by running additional automated checks on non-formatted data being exported in addition to those for highly formatted textual data. A trusted source should also assess the classification of the content of the data, which cannot be interpreted by automated means. Further information on trusted sources can be found in the Data Transfers section of the Network Security chapter.
							</para>
            </content>
            <controls>
              <block>
                <ID>0672</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of other data through gateways</title>
                <content>
                  <para>
                    When exporting data other than highly formatted textual data through gateways, agencies must implement data filtering performed by a product specifically designed for that purpose.
                  </para>
                </content>
              </block>
              <block>
                <ID>0674</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of other data through gateways</title>
                <content>
                  <para>
                    Agencies must perform randomly timed audits of random subsets of the data transfer logs on a weekly basis.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Preventing export of particularly sensitive data to foreign systems</title>
            <content>
							<para>
								As AUSTEO and AGAO networks are particularly sensitive, additional security measures need to be put in place when connecting them to other networks
							</para>
            </content>
            <controls>
              <block>
                <ID>1077</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of other data through gateways</title>
                <content>
                  <para>
                    To prevent the export of AUSTEO and AGAO data to foreign systems, agencies must implement data filtering performed by a product specifically evaluated for that purpose.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Requirement to sign exported data</title>
						<content>
							<para>
								Digitally signing data being exported to systems where there is access by non-trusted sources reduces the security risk of compromising data integrity.
							</para>
            </content>
            <controls>
              <block>
                <ID>0675</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of other data through gateways</title>
                <content>
                  <para>
                    If, to reach the transfer point, the data is communicated over a network to which personnel or systems that are not trusted sources have access, then a trusted source must sign the data to be exported.
                  </para>
                </content>
              </block>
              <block>
                <ID>0677</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Export of other data through gateways</title>
                <content>
                  <para>
                    Agencies must ensure that the gateway confirms the signature before the release of the data to be exported.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Content Filtering</title>
        <objective>
          <block>
            <content>
              <para>
                The flow of data in gateways is controlled by a content filter.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the use of content filters in uni-directional or bi-directional gateways.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Content filters will reduce the security risk of malicious content entering the security domain and gaining unauthorised access to information.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Limiting transfers by file type</title>
						<content>
							<list>
								<head>The level of security risk will be determined by the degree of assurance agencies can place in the ability of their data transfer filters to:</head>
								<item>
									confirm the file type by examination of the contents of the file
								</item>
								<item>
									confirm the absence of malicious content
								</item>
								<item>
									confirm the absence of inappropriate content
								</item>
								<item>
									confirm the classification and releasability of the content
								</item>
								<item>
									handle compressed and encoded files appropriately.
								</item>
							</list>
							<para>
								Reducing permitted file types reduces the number of potential vulnerabilities available for an attacker to exploit.
							</para>
						</content>
            <controls>
              <block>
                <ID>0649</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Limiting transfers by file type</title>
                <content>
                  <para>
                    Agencies should strictly define and limit the types of files that can be transferred based on business requirements and the results of a security risk assessment.
                  </para>
                </content>
              </block>
              <block>
                <ID>0650</ID>
                <revision>1</revision>
                <updated>Sep-09</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Limiting transfers by file type</title>
                <content>
                  <para>
                    Agencies must strictly define and limit the types of files that can be transferred based on business requirements and the results of a security risk assessment.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Blocking active content</title>
						<content>
							<para>
								Many files are executable and are potentially harmful if executed by a system user. Many file type specifications allow active content to be embedded in the file, which increases the attack surface.
							</para>
            </content>
            <controls>
              <block>
                <ID>0651</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Blocking active content</title>
                <content>
                  <para>
                    Agencies should block all executables and active content from being communicated though gateways.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Blocking suspicious data</title>
						<content>
							<para>
								The definition of suspicious content will depend on the system’s security risk profile and what is considered normal traffic. Some filtering techniques are described below that can be used to identify suspicious data.
							</para>

              <table>
                    <header>
                      <cell>Technique</cell>
                      <cell>Purpose</cell>
                    </header>
                    <row>
                      <cell>Antivirus scan</cell>
                      <cell>Scans the data for viruses and other malicious code.</cell>
                    </row>
                    <row>
                      <cell>Data format check</cell>
                      <cell>Inspects data to ensure that it conforms to expected and permitted formats.</cell>
                    </row>
                    <row>
                      <cell>Data range check</cell>
                      <cell>Checks the data in each field to ensure that it falls within the expected and permitted ranges.</cell>
                    </row>
                    <row>
                      <cell>Data type check</cell>
                      <cell>Inspects each file header to determine the actual file type.</cell>
                    </row>
                    <row>
                      <cell>File extension check</cell>
                      <cell>Inspects the file name extension to determine the purported file type.</cell>
                    </row>
                    <row>
                      <cell>Keyword search</cell>
                      <cell>Searches data for keywords or ‘dirty words’ that could indicate the presence of sensitivity, classified or inappropriate material.</cell>
                    </row>
                    <row>
                      <cell>Metadata check</cell>
                      <cell>Inspects files for metadata that should be removed prior to release.</cell>
                    </row>
                    <row>
                      <cell>Protective marking check</cell>
                      <cell>Validates the protective marking of the data to ensure that it is correct.</cell>
                    </row>
                    <row>
                      <cell>Manual inspection</cell>
                      <cell>The manual inspection of data for suspicious content that an automated system could miss, which is particularly important for the transfer of multimedia or content rich files.</cell>
                    </row>
              </table>
						</content>
            <controls>
              <block>
                <ID>0652</ID>
                <revision>0</revision>
                <updated>Sep-08</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Blocking suspicious data</title>
                <content>
                  <para>
                    Agencies must block or drop any data identified by a data filter as suspicious until reviewed and approved for transfer by a trusted source other than the originator.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Traffic Flow Filters</title>
        <objective>
          <block>
            <content>
              <para>
                Networks connected to bi-directional gateways implement firewalls and traffic flow filters.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes filtering requirements for bi-directional gateways between networks of different security domains.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                When a control specifies a requirement for a diode or filter, the appropriate information can be found in the Diodes and Content Filtering sections of this chapter. Additional information that also applies to topics covered in this section can be found in the Data Transfers section of the Network Security chapter and the Data Import and Export section of this chapter. The Product Security chapter provides advice on selecting evaluated products.
              </para>
              <title>Government systems</title>
              <para>
                All references to ‘Government’ in the tables relate to systems containing unclassified but sensitive information not intended for public release, such as Dissemination Limiting Marker information. ‘Government’ is not a classification under the Australian Government Security Classification System as mandated by the Attorney-General’s Department.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Traffic flow filters</title>
						<content>
							<para>
								Where an agency connects to another agency over public network infrastructure both agencies need to implement traffic flow filtering in their gateway environment to protect themselves from attacks that originate outside of their environment.
							</para>
							<list>
								<head>These gateway infrastructure requirements may not be necessary in the specific cases where:</head>
								<item>
									the public network infrastructure is used only as a transport medium
								</item>
								<item>
									the public network infrastructure is not a logical source or destination of data
								</item>
								<item>
									link encryption is used in accordance with the Cryptography chapter.
								</item>
							</list>
							<para>
								A proxy is a proxy server that acts as an intermediary for requests from within the agency seeking resources external to the agency. A client connects to the proxy server, requesting some service, such as a file, connection, website, or other resource, available from a source external to the agency. The proxy server evaluates the request according to its filtering rules.
							</para>
							<para>
								The Network Device Protection Profile (NDPP), defined by the United States’ National Information Assurance Partnership, outlines the security requirements for a network device (as opposed to an end-user device) that can be connected to a network.
							</para>
            </content>
            <controls>
              <block>
                <ID>1193</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Traffic flow filters</title>
                <content>
                  <para>
                    All gateways must contain a traffic flow filter.
                  </para>
                </content>
              </block>
              <block>
                <ID>0638</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Traffic flow filters</title>
                <content>
                  <list>
                    <head>When selecting a traffic flow filter, agencies must use at least one of the following in the order of preference as shown:</head>
                    <item>
                      a firewall
                    </item>
                    <item>
                      a proxy
                    </item>
                    <item>
                      a router with access control lists configured.
                    </item>
                  </list>
                </content>
              </block>
              <block>
                <ID>0639</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Traffic flow filters</title>
                <content>
                  <para>
                    Agencies must use a firewall as part of their traffic flow filter which satisfies the following table.
                  </para>
                    <table>
                          <header>
                            <cell> </cell>
                            <cell colspan="6">Other Network</cell>
                          </header>
                          <header>
							<cell>Your network</cell>
                            <cell>Public</cell>
                            <cell>Government</cell>
                            <cell>PROTECTED</cell>
                            <cell>CONFIDENTIAL</cell>
                            <cell>SECRET</cell>
                            <cell>TOP SECRET</cell>
                          </header>
                          <row>
                            <cell>TOP SECRET</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                          </row>
                          <row>
                            <cell>SECRET</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                          </row>
                          <row>
                            <cell>CONFIDENTIAL</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                          </row>
                          <row>
                            <cell>PROTECTED</cell>
                            <cell>NDPP-compliant firewall</cell>
                            <cell>NDPP-compliant firewall</cell>
                            <cell>NDPP-compliant firewall</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                          </row>
                          <row>
                            <cell>Government</cell>
                            <cell>None*</cell>
                            <cell>None*</cell>
                            <cell>None*</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                            <cell>Consult with DSD</cell>
                          </row>
                    </table>

                  <para>
                    * No specific firewall requirement, although a traffic flow filter is still required in line with control 0638.
                  </para>
                </content>
              </block>
              <block>
                <ID>1194</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Traffic flow filters</title>
                <content>
                  <para>
                    The requirement to use a firewall as part of a traffic flow filter must be met by both parties independently; shared equipment does not satisfy the requirements of both parties.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Firewalls for particularly sensitive networks</title>
						<content>
							<para>
								As AUSTEO and AGAO networks are particularly sensitive, additional security measures need to be put in place when connecting them to other networks.
							</para>
            </content>
            <controls>
              <block>
                <ID>0641</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Firewalls for particularly sensitive networks</title>
                <content>
                  <para>
                    Agencies must use a DSD approved NDPP-compliant firewall from the EPL between an AUSTEO or AGAO network and a foreign network in addition to the firewall between networks of different classifications or security domains. If no suitable NDPP-compliant firewall exists on the EPL, an Evaluation Assurance Level (EAL) 4 firewall may be used.
                  </para>
                </content>
              </block>
              <block>
                <ID>0642</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Firewalls for particularly sensitive networks</title>
                <content>
                  <para>
                    Agencies should use a DSD approved NDPP-compliant firewall from the EPL between an AUSTEO or AGAO network and another Australian controlled network in addition to the firewall between networks of different classifications or security domains. If no suitable NDPP-compliant firewall exists on the EPL, an EAL 4 firewall may be used.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Further information on the NDPP is available at http://www.niap-ccevs.org/pp/pp_nd_v1.0/.
              </para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Diodes</title>
        <objective>
          <block>
            <content>
              <para>
                Networks connected to uni-directional gateways implement diodes.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes filtering requirements for uni-directional gateways used to facilitate data transfers.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                Additional information can be found in the Data Transfers section of the Network Security chapter and the Data Import and Export section of this chapter. The Product Security chapter provides advice on selecting evaluated products.
              </para>
              <para>
                While no DSD Protection Profile exists for data diodes, the EALs specified in the following controls may be used.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Diodes</title>
						<content>
							<para>
								A diode enforces one-way flow of network traffic thus requiring separate paths for incoming and outgoing data. This makes it much more difficult for an attacker to use the same path to both launch an attack and release the information.
							</para>
						</content>
            <controls>
              <block>
                <ID>0643</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Diodes</title>
                <content>
                  <para>
                    Agencies must use an EAL 2 diode from DSD’s EPL for controlling the data flow of uni-directional gateways between sensitive or classified networks and public network infrastructure.
                  </para>
                </content>
              </block>
              <block>
                <ID>0645</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Diodes</title>
                <content>
                  <para>
                    Agencies must use a high assurance diode from DSD’s EPL for controlling the data flow of uni-directional gateways between classified networks and public network infrastructure.
                  </para>
                </content>
              </block>
              <block>
                <ID>1157</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Diodes</title>
                <content>
                  <para>
                    Agencies must use an EAL 2 diode from DSD’s EPL for controlling the data flow of uni-directional gateways between sensitive and classified networks.
                  </para>
                </content>
              </block>
              <block>
                <ID>1158</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Diodes</title>
                <content>
                  <para>
                    Agencies must use a high assurance diode from DSD’s EPL for controlling the data flow of uni-directional gateways between sensitive or classified networks where the highest system is CONFIDENTIAL or above.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Diodes for particularly sensitive networks</title>
						<content>
							<para>
								While diodes between networks at the same classification generally are not needed, AUSTEO and AGAO networks are particularly sensitive and additional security measures need to be put in place when connecting them to other networks
							</para>
            </content>
            <controls>
              <block>
                <ID>0646</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Diodes for particularly sensitive networks</title>
                <content>
                  <para>
                    Agencies must use an EAL 4 diode from DSD’s EPL between an AUSTEO or AGAO network and a foreign network at the same classification.
                  </para>
                </content>
              </block>
              <block>
                <ID>0647</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Diodes for particularly sensitive networks</title>
                <content>
                  <para>
                    Agencies should use an EAL 2 diode from DSD’s EPL between an AUSTEO or AGAO network and another agency controlled network at the same classification.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Volume checking</title>
						<content>
							<para>
								Monitoring the volume of data being transferred across a diode ensures that it conforms to expectations. It can also alert the agency to potential malicious activity if the volume of data suddenly changes from the norm.
							</para>
            </content>
            <controls>
              <block>
                <ID>0648</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Volume checking</title>
                <content>
                  <para>
                    Agencies deploying a diode to control data flow in uni-directional gateways should monitor the volume of the data being transferred.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                Additional information on the EPL can be found on DSD’s website at http://www.dsd.gov.au/infosec/epl/index.php.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
    <chapter>
      <title>Working Off-Site</title>
      <section>
        <title>Mobile Devices</title>
        <objective>
          <block>
            <content>
              <para>
                Information on mobile devices is protected from unauthorised disclosure.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes the use of mobiles devices including: mobile phones, smartphones, portable electronic devices, personal digital assistants, laptops, netbooks, tablet computers and other portable Internet connected devices.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <title>Trusted Operating Environments</title>
            <content>
              <list>
                <head>A Trusted Operating Environment (TOE) provides assurance that a reasonable effort has been made to secure the operating system of a mobile device such that it presents a reduced security risk to an agency’s information and systems. Security measures that can be implemented to assist in the development of a TOE include:</head>
                <item>
                  unneeded software and operating system components are removed
                </item>
                <item>
                  unused or undesired functionality in software and operating systems is disabled
                </item>
                <item>
                  antivirus or other Internet security software is installed and regularly updated
                </item>
                <item>
                  software-based firewalls limiting inbound and outbound network connection are installed
                </item>
                <item>
                  installed software and operating system patching is current
                </item>
                <item>
                  split tunnelling is disabled when using a Virtual Private Network (VPN) connection between a mobile device and an agency system
                </item>
                <item>
                  each connection is authenticated before permitting access to an agency network
                </item>
                <item>
                  both the system user and mobile device are authenticated during the authentication process
                </item>
                <item>
                  Bluetooth functionality is not enabled
                </item>
                <item>
                  privileged access from the mobile device to the agency network is not allowed.
                </item>
              </list>
            </content>
          </block>
          <block>
            <title>Treating workstations as mobile devices</title>
            <content>
              <para>
                When a workstation is issued for home-based work instead of a mobile device, the requirements in this section equally apply to the workstation.
              </para>
            </content>
          </block>
          <block>
            <title>Mobile devices with multiple operating states</title>
            <content>
              <para>
                Some mobile devices have functionality to allow them to operate in either an unprotected state or a protected state. In such cases the mobile devices need to be handled according to the state that it is being operated in at the time.
              </para>
            </content>
          </block>
          <block>
            <title>Bluetooth Devices</title>
            <content>
              <para>
                For devices such as keyboards that utilise Bluetooth and for security risks to consider, refer to the Radio Frequency, Infrared and Bluetooth Devices section of the Communications Systems and Devices chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Mobile devices usage policy</title>
						<content>
							<para>
								Since mobile devices routinely leave the office environment, and the protection it affords, it is important that policies are developed to ensure that mobile devices are protected in an appropriate manner when used outside of controlled facilities.
							</para>
            </content>
            <controls>
              <block>
                <ID>1082</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Mobile devices usage policy</title>
                <content>
                  <para>
                    Agencies must develop a policy governing the use of mobile devices.
                  </para>
                </content>
              </block>
              <block>
                <ID>1195</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Mobile devices usage policy</title>
                <content>
                  <para>
                    Agencies should use a Mobile Device Management solution to ensure their mobile device policy is applied to all mobile devices that are used with their systems.
                  </para>
                </content>
              </block>
              <block>
                <ID>0687</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Mobile devices usage policy</title>
                <content>
                  <para>
                    Agencies must not allow mobile devices to process or store TOP SECRET information unless explicitly approved by the Defence Signals Directorate (DSD) to do so.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Personnel awareness</title>
						<content>
							<para>
								Mobile devices can have both a data and voice component capable of processing or communicating sensitive or classified information. In such cases, personnel need to know the sensitivity or classification of information which the mobile device has been approved to process, store and communicate.
							</para>
            </content>
            <controls>
              <block>
                <ID>1083</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Personnel awareness</title>
                <content>
                  <para>
                    Agencies must advise personnel of the sensitivities and classifications permitted for data and voice communications when using mobile devices.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Non-agency owned mobile devices</title>
						<content>
							<para>
								If agencies choose to allow personnel to use their personal mobile devices to access the agency’s systems, they will need to ensure that the device does not present a threat to the systems and does not retain any sensitive or classified information once a session has been completed. DSD recommends that agencies achieve this outcome through the use of bootable optical media or flash drive running an endorsed Standard Operating Environment (SOE). Failing this, DSD recommends the use of remote desktop software to present an endorsed SOE to personnel on their mobile devices.
							</para>
            </content>
            <controls>
              <block>
                <ID>1047</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Non-agency owned mobile devices</title>
                <content>
                  <para>
                    Non-agency owned mobile devices accessing sensitive systems should use a TOE that also prevents sensitive information being stored on the device.
                  </para>
                </content>
              </block>
              <block>
                <ID>0693</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Non-agency owned mobile devices</title>
                <content>
                  <para>
                    Non-agency owned mobile devices accessing classified systems must use a TOE that also prevents classified information being stored on the device.
                  </para>
                </content>
              </block>
              <block>
                <ID>0694</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Non-agency owned mobile devices</title>
                <content>
                  <para>
                    Agencies must not allow non-agency owned mobile devices to access classified systems.
                  </para>
                </content>
              </block>
              <block>
                <ID>0172</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Non-agency owned mobile devices</title>
                <content>
                  <para>
                    Agencies must not permit non-agency owned mobile devices to be brought into TOP SECRET areas without prior approval from the accreditation authority.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Mobile device storage encryption</title>
						<content>
							<para>
								Agencies should use encryption on mobile devices to lessen the security risk associated with a lost or stolen device. While the use of encryption may not be suitable to treat the mobile device as an unclassified asset it will still prevent a significant challenge to an attacker looking to gain easy access to information stored on the device. To ensure that the benefits of encryption on mobile devices are not negated, system users are reminded that they must not store passphrases for the encryption software on, or with, the device.
							</para>
            </content>
            <controls>
              <block>
                <ID>0869</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Mobile device storage encryption</title>
                <content>
                  <para>
                    Agencies should encrypt information on all mobile devices using at least a DSD Approved Cryptographic Algorithm.
                  </para>
                </content>
              </block>
              <block>
                <ID>1084</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Mobile device storage encryption</title>
                <content>
                  <para>
                    Agencies unable to lower the storage and physical transfer requirements of a mobile device to an unclassified level through the use of encryption must physically transfer the device as a sensitive or classified asset in a Security Construction and Equipment Committee endorsed secure briefcase.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Mobile device communications encryption</title>
						<content>
							<para>
								If appropriate encryption is not available the mobile device must not be used for communicating sensitive or classified information. All sensitive or classified communications must be encrypted regardless of the protocol used whether it is communicated using Bluetooth, infrared, Wi-Fi, 3G, 4G or other wireless protocols.
							</para>
            </content>
            <controls>
              <block>
                <ID>1085</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Mobile device communications encryption</title>
                <content>
                  <para>
                    Agencies using mobile devices to communicate sensitive or classified information over public network infrastructure must use encryption approved for communicating such information over public network infrastructure.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Mobile device privacy filters</title>
						<content>
							<para>
								Privacy filters can be applied to the screens of mobile devices to prevent onlookers from reading the contents off the screen of the device. This assists in mitigating security risks from shoulder surfing.
							</para>
            </content>
            <controls>
              <block>
                <ID>1145</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Mobile device privacy filters</title>
                <content>
                  <para>
                    Agencies should apply privacy filters to the screens of mobile devices.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Bluetooth functionality</title>
						<content>
							<para>
								Bluetooth provides little security for information that is passed between the mobile device and other devices connected to it using Bluetooth, such as car kits. Bluetooth has a number of known weaknesses that potentially enable attackers to exploit it, therefore it must not be used on mobile devices for highly classified information. To use Bluetooth to communicate sensitive or lesser classified information it must be secured appropriately.
							</para>
							<para>
								The number of devices that are paired to a mobile device using Bluetooth should be kept to a minimum and only when required for a business need. Unintended and unneeded Bluetooth device pairing should be removed from the mobile device.
							</para>
							<para>
								The device class can be used to restrict the range that the Bluetooth communications will operate over. Typically Bluetooth class 1 devices can communicate up to 100 metres, class 2 devices can communicate up to 10 metres and class 3 devices can communicate up to 5 metres.
							</para>
							<para>
								Agencies must use Bluetooth version 2.1 or later as secure simple pairing and extended inquiry response was introduced in this version. Secure simple pairing improves the pairing process for Bluetooth devices, while increasing the strength, as it uses a form of public key cryptography. Extended inquiry response provides more information during the inquiry procedure to allow better filtering of devices before connecting.
							</para>
            </content>
            <controls>
              <block>
                <ID>0682</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies must not enable Bluetooth functionality on mobile devices.
                  </para>
                </content>
              </block>
              <block>
                <ID>1196</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies must ensure mobile devices are configured to remain undiscoverable to all other Bluetooth devices except during pairing.
                  </para>
                </content>
              </block>
              <block>
                <ID>1197</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies should ensure mobile devices are configured to allow only Bluetooth classes that are required.
                  </para>
                </content>
              </block>
              <block>
                <ID>1198</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies must ensure Bluetooth pairing is performed so that a connection is only made to the device intended.
                  </para>
                </content>
              </block>
              <block>
                <ID>1199</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies should ensure Bluetooth pairing is only performed for a device required for business needs and pairing that is no longer required is removed from the mobile device.
                  </para>
                </content>
              </block>
              <block>
                <ID>1200</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies must ensure mobile devices use Bluetooth version 2.1 or later.
                  </para>
                </content>
              </block>
              <block>
                <ID>1201</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies must ensure mobile devices are configured to support a single Bluetooth headset connection.
                  </para>
                </content>
              </block>
              <block>
                <ID>1202</ID>
                <revision>0</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Bluetooth functionality</title>
                <content>
                  <para>
                    Agencies should restrict the range of Bluetooth headsets to less than 10 metres by only using class 2 or class 3 devices.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Configuration control</title>
						<content>
							<para>
								Poorly controlled mobile devices are more vulnerable to compromise and provide an attacker with a potential access point into systems. Although agencies may initially provide a secure mobile device, the state of security may degrade over time. The security of mobile devices needs to be audited regularly to ensure their integrity.
							</para>
            </content>
            <controls>
              <block>
                <ID>0862</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration control</title>
                <content>
                  <para>
                    Agencies should control the configuration of mobile devices in the same manner as devices in the office environment.
                  </para>
                </content>
              </block>
              <block>
                <ID>0863</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration control</title>
                <content>
                  <para>
                    Agencies should prevent personnel from installing or uninstalling applications on a mobile device once provisioned.
                  </para>
                </content>
              </block>
              <block>
                <ID>0864</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Configuration control</title>
                <content>
                  <para>
                    Agencies must prevent personnel from disabling security functions on a mobile device once provisioned.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Maintaining mobile device security</title>
						<content>
							<para>
								It is important that mobile devices are routinely returned so that patches can be applied and the devices can be tested to ensure that they are still secure.
							</para>
            </content>
            <controls>
              <block>
                <ID>1049</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Configuration control</title>
                <content>
                  <para>
                    Agencies should ensure that mobile devices have security updates applied on a regular basis and are regularly tested to ensure that they are still secure.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Connecting mobile devices to the Internet</title>
						<content>
							<para>
								During the time a mobile device is connected to the Internet for web browsing, instead of establishing a VPN connection to a system, it is directly exposed to attacks originating from the Internet. Should web browsing be needed, personnel should establish a VPN connection and browse the Web though their agency’s Internet gateway.
							</para>
							<para>
								A split tunnel VPN can allow access to systems from another network, including unsecured networks such as the Internet. If split tunnelling is not disabled there is an increased security risk that the VPN connection is susceptible to attack from such networks.
							</para>
            </content>
            <controls>
              <block>
                <ID>0874</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Connecting mobile devices to the Internet</title>
                <content>
                  <para>
                    Agencies should ensure that web browsing from a mobile device is through the agency’s Internet gateway rather than via a direct connection to the Internet.
                  </para>
                </content>
              </block>
              <block>
                <ID>0705</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Connecting mobile devices to the Internet</title>
                <content>
                  <para>
                    Agencies must disable split tunnelling when using a VPN connection from a mobile device to connect to a system.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Paging and message services</title>
						<content>
							<para>
								As paging and message services do not appropriately encrypt information they cannot be relied upon for the communication of sensitive or classified information.
							</para>
            </content>
            <controls>
              <block>
                <ID>0240</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must not</compliance>
                <authority>AH</authority>
                <title>Paging and message services</title>
                <content>
                  <para>
                    Agencies must not use paging, Multimedia Message Service, Short Message Service or Instant Messaging to communicate sensitive or classified information.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Emergency destruction</title>
						<content>
							<para>
								Agencies need to develop emergency destruction procedures for mobile devices. Such procedures should focus on destroying information on the mobile device and not necessarily the device itself if it can be avoided. Many mobile devices used for highly classified information achieve this through the use of a cryptographic key zeroise or sanitisation function. The use of a remote wipe can be used to achieve the destruction of information.
							</para>
            </content>
            <controls>
              <block>
                <ID>0700</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Emergency destruction</title>
                <content>
                  <para>
                    Agencies should develop an emergency destruction plan for all mobile devices.
                  </para>
                </content>
              </block>
              <block>
                <ID>0701</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Emergency destruction</title>
                <content>
                  <para>
                    Agencies must develop an emergency destruction plan for mobile devices.
                  </para>
                </content>
              </block>
              <block>
                <ID>0702</ID>
                <revision>2</revision>
                <updated>Nov-10</updated>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Emergency destruction</title>
                <content>
                  <para>
                    If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a mobile device, the function must be used as part of the emergency destruction procedures.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Unauthorised use of mobile devices</title>
						<content>
							<para>
								If mobile devices are issued for business purposes they should not be used for private purposes.
							</para>
            </content>
            <controls>
              <block>
                <ID>1086</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>should not</compliance>
                <authority>AA</authority>
                <title>Unauthorised use of mobile devices</title>
                <content>
                  <para>
                    Mobile devices should not be used for personal non-business use or by people other than those specifically authorised.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Working Outside the Office</title>
        <objective>
          <block>
            <content>
              <para>
                Information on mobile devices is accessed with due care in public locations.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes restrictions on accessing sensitive or classified information using mobile devices from unsecured locations outside of the office and home environments.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                This section does not apply to working from home. Requirements relating to home-based work are outlined in the Working From Home section in this chapter. Further information on the use of mobile devices can be found in the Mobile Devices section of this chapter.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Working outside the office</title>
						<content>
							<para>
								Personnel need to be aware of the environment they use mobile devices in to access and communicate sensitive or classified information, especially in public areas including, but not limited to, public transport, transit lounges and coffee shops. In such locations personnel should take extra care to ensure conversations are not overheard and data is not observed.
							</para>
            </content>
            <controls>
              <block>
                <ID>0866</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>Applicability G, P, C, S, TS;
                <compliance>should</compliance>
                <authority>AA</authority>
                <title>Working outside the office</title>
                <content>
                  <para>
                    Agencies should ensure personnel are aware not to access or communicate sensitive or classified information in public locations (e.g. public transport, transit lounges and coffee shops) unless extra care is taken to reduce the chance of being overheard or having the screen of the device observed.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Carrying mobile devices</title>
						<content>
							<para>
								As mobile devices used outside the office will be carried through areas not certified and accredited to process the information on the device, mechanisms need to be put in place to protect the information stored on them.
							</para>
							<para>
								When agencies apply encryption to mobile devices to reduce their physical transfer requirements, the encryption will only be effective when the decryption function of the device has been deactivated. In most cases this will mean the mobile device will be in an unpowered state (i.e. not turned on), however, some devices are capable of deauthenticating the cryptography when it enters a locked state after a predefined timeout period. Such mobile devices can be carried in a locked state in accordance with reduced physical transfer requirements based on the assurance given in the cryptographic functions.
							</para>
            </content>
            <controls>
              <block>
                <ID>0870</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Carrying mobile devices</title>
                <content>
                  <para>
                    Agencies must ensure mobile devices are carried in a secured state when not being actively used.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Using mobile devices</title>
						<content>
							<para>
								As mobile devices are often portable in nature and can be easily stolen it is strongly advised that personnel do not leave mobile device unattended at any time.
							</para>
            </content>
            <controls>
              <block>
                <ID>0871</ID>
                <revision>1</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Using mobile devices</title>
                <content>
                  <para>
                    When in use mobile devices must be kept under continual direct supervision.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Travelling with mobile devices</title>
						<content>
							<para>
								If personnel place mobile devices or media in checked-in luggage when travelling they lose control over the devices. Such situations provide an opportunity for mobile devices to be stolen or tampered with by an attacker.
							</para>
            </content>
            <controls>
              <block>
                <ID>1087</ID>
                <revision>0</revision>
                <updated>Nov-10</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Travelling with mobile devices</title>
                <content>
                  <para>
                    When travelling with mobile devices and media, personnel must retain control over them at all times, this includes not placing them in checked-in luggage or leaving them unattended for any period of time.
                  </para>
                </content>
              </block>
              <block>
                <ID>1088</ID>
                <revision>1</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Travelling with mobile devices</title>
                <content>
                  <para>
                    If personnel are requested to decrypt mobile devices for inspection by customs personnel, or their mobile device is taken out of sight by customs personnel, then the member must report the potential compromise of information on the device to an Information Technology Security Manager as soon as possible.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>Nil.</para>
            </content>
          </block>
        </references>
      </section>
      <section>
        <title>Working From Home</title>
        <objective>
          <block>
            <content>
              <para>
                Personnel working from home protect information in the same manner as in the office environment.
              </para>
            </content>
          </block>
        </objective>
        <scope>
          <block>
            <content>
              <para>
                This section describes information on accessing sensitive or classified information from a home environment in order to conduct home-based work.
              </para>
            </content>
          </block>
        </scope>
        <context>
          <block>
            <content>
              <para>
                When a workstation is issued for home-based work, instead of a mobile device, the requirements from the Mobile Devices section in this chapter equally apply to the workstation.
              </para>
            </content>
          </block>
        </context>
        <controlsTitle>
          <block>
            <title>Physical security for the home environment</title>
						<content>
							<para>
								When agencies consider allowing personnel to work from a home environment they need to be aware that implementing physical security measures may require modifications to the person’s home at the expense of the agency.
							</para>
            </content>
            <controls>
              <block>
                <ID>0865</ID>
                <revision>2</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Physical security for the home environment</title>
                <content>
                  <para>
                    Agencies must ensure that the area in which devices are used meets the requirements in the Australian Government Physical Security Management Protocol.
                  </para>
                </content>
              </block>
            </controls>
          </block>
          <block>
            <title>Securing devices in the home environment</title>
						<content>
							<para>
								All devices have the potential to store sensitive or classified information and therefore need protection against loss and compromise.
							</para>
            </content>
            <controls>
              <block>
                <ID>0685</ID>
                <revision>3</revision>
                <updated>Sep-11</updated>
                <classification>G</classification>
                <classification>P</classification>
                <classification>C</classification>
                <classification>S</classification>
                <classification>TS</classification>
                <compliance>must</compliance>
                <authority>AH</authority>
                <title>Securing devices in the home environment</title>
                <content>
                  <para>
                    Agencies must ensure that when devices are not being actively used they are secured in accordance with the requirements in the Australian Government Physical Security Management Protocol.
                  </para>
                </content>
              </block>
            </controls>
          </block>
        </controlsTitle>
        <references>
          <block>
            <content>
              <para>
                For further information on working from home see the Australian Government Physical Security Management Guidelines – Working Away From the Office.
              </para>
            </content>
          </block>
        </references>
      </section>
    </chapter>
  </part>
  <part>
    <title>Supporting Information</title>
    <chapter>
      <title>Glossaries and Index</title>
      <section>
				<title>Glossary of Abbreviations</title>
				<block>
				<block>
					<content>
          <table>
                <header>
                  <cell>Abbreviation</cell>
                  <cell>Meaning</cell>
                </header>
                <row>
                  <cell>3DES</cell>
                  <cell>Triple Data Encryption Standard</cell>
                </row>
                <row>
                  <cell>ACSI</cell>
                  <cell>Australian Communications Security Instruction</cell>
                </row>
                <row>
                  <cell>AES</cell>
                  <cell>Advanced Encryption Standard</cell>
                </row>
                <row>
                  <cell>AGAO</cell>
                  <cell>Australian Government Access Only</cell>
                </row>
                <row>
                  <cell>AGD</cell>
                  <cell>Attorney-General’s Department</cell>
                </row>
                <row>
                  <cell>AGIMO</cell>
                  <cell>Australian Government Information Management Office</cell>
                </row>
                <row>
                  <cell>AH</cell>
                  <cell>Authentication Header</cell>
                </row>
                <row>
                  <cell>AISEP</cell>
                  <cell>Australasian Information Security Evaluation Program</cell>
                </row>
                <row>
                  <cell>ANAO</cell>
                  <cell>Australian National Audit Office</cell>
                </row>
                <row>
                  <cell>AS</cell>
                  <cell>Australian Standard</cell>
                </row>
                <row>
                  <cell>ASA</cell>
                  <cell>Agency Security Advisor</cell>
                </row>
                <row>
                  <cell>ASIO</cell>
                  <cell>Australian Security Intelligence Organisation</cell>
                </row>
                <row>
                  <cell>ATA</cell>
                  <cell>Advanced Technology Attachment</cell>
                </row>
                <row>
                  <cell>AUSTEO</cell>
                  <cell>Australian Eyes Only</cell>
                </row>
                <row>
                  <cell>CISO</cell>
                  <cell>Chief Information Security Officer</cell>
                </row>
                <row>
                  <cell>COE</cell>
                  <cell>Common Operating Environment</cell>
                </row>
                <row>
                  <cell>CSIR</cell>
                  <cell>Cyber Security Incident Reporting</cell>
                </row>
                <row>
                  <cell>DACA</cell>
                  <cell>DSD Approved Cryptographic Algorithm</cell>
                </row>
                <row>
                  <cell>DACP</cell>
                  <cell>DSD Approved Cryptographic Protocol</cell>
                </row>
                <row>
                  <cell>DCE</cell>
                  <cell>DSD Cryptographic Evaluation</cell>
                </row>
                <row>
                  <cell>DDoS</cell>
                  <cell>Distributed Denial-of-Service</cell>
                </row>
                <row>
                  <cell>DH</cell>
                  <cell>Diffie-Hellman</cell>
                </row>
                <row>
                  <cell>DKIM</cell>
                  <cell>DomainKeys Identified Mail</cell>
                </row>
                <row>
                  <cell>DMA</cell>
                  <cell>Direct Memory Access</cell>
                </row>
                <row>
                  <cell>DNS</cell>
                  <cell>Domain Name System</cell>
                </row>
                <row>
                  <cell>DSA</cell>
                  <cell>Digital Signature Algorithm</cell>
                </row>
                <row>
                  <cell>DSD</cell>
                  <cell>Defence Signals Directorate</cell>
                </row>
                <row>
                  <cell>EAL</cell>
                  <cell>Evaluation Assurance Level</cell>
                </row>
                <row>
                  <cell>EAP-TLS</cell>
                  <cell>Extensible Authentication Protocol-Transport Layer Security</cell>
                </row>
                <row>
                  <cell>ECDH</cell>
                  <cell>Elliptic Curve Diffie-Hellman</cell>
                </row>
                <row>
                  <cell>ECDSA</cell>
                  <cell>Elliptic Curve Digital Signature Algorithm</cell>
                </row>
                <row>
                  <cell>EEPROM</cell>
                  <cell>Electrically Erasable Programmable Read-only Memory</cell>
                </row>
                <row>
                  <cell>EPL</cell>
                  <cell>Evaluated Products List</cell>
                </row>
                <row>
                  <cell>EPLD</cell>
                  <cell>Evaluated Products List – Degausser</cell>
                </row>
                <row>
                  <cell>EPROM</cell>
                  <cell>Erasable Programmable Read-only Memory</cell>
                </row>
                <row>
                  <cell>ESP</cell>
                  <cell>Encapsulating Security Payload</cell>
                </row>
                <row>
                  <cell>FIPS</cell>
                  <cell>Federal Information Processing Standard</cell>
                </row>
                <row>
                  <cell>HB</cell>
                  <cell>Handbook</cell>
                </row>
                <row>
                  <cell>HGCE</cell>
                  <cell>High Grade Cryptographic Equipment</cell>
                </row>
                <row>
                  <cell>HMAC</cell>
                  <cell>Hashed Message Authentication Code</cell>
                </row>
                <row>
                  <cell>HTTP</cell>
                  <cell>Hypertext Transfer Protocol</cell>
                </row>
                <row>
                  <cell>HTTPS</cell>
                  <cell>Hypertext Transfer Protocol Secure</cell>
                </row>
                <row>
                  <cell>ICT</cell>
                  <cell>Information and Communications Technology</cell>
                </row>
                <row>
                  <cell>IDS</cell>
                  <cell>Intrusion Detection System</cell>
                </row>
                <row>
                  <cell>IEC</cell>
                  <cell>International Electrotechnical Commission</cell>
                </row>
                <row>
                  <cell>IEEE</cell>
                  <cell>Institute of Electrical and Electronics Engineers</cell>
                </row>
                <row>
                  <cell>IETF</cell>
                  <cell>Internet Engineering Task Force</cell>
                </row>
                <row>
                  <cell>IKE</cell>
                  <cell>Internet Key Exchange</cell>
                </row>
                <row>
                  <cell>IM</cell>
                  <cell>Instant Messaging</cell>
                </row>
                <row>
                  <cell>IP</cell>
                  <cell>Internet Protocol</cell>
                </row>
                <row>
                  <cell>IPSec</cell>
                  <cell>Internet Protocol Security</cell>
                </row>
                <row>
                  <cell>IPv6</cell>
                  <cell>Internet Protocol version 6</cell>
                </row>
                <row>
                  <cell>IRC</cell>
                  <cell>Internet Relay Chat</cell>
                </row>
                <row>
                  <cell>IRP</cell>
                  <cell>Incident Response Plan</cell>
                </row>
                <row>
                  <cell>ISAKMP</cell>
                  <cell>Internet Security Association Key Management Protocol</cell>
                </row>
                <row>
                  <cell>ISM</cell>
                  <cell>Australian Government Information Security Manual</cell>
                </row>
                <row>
                  <cell>ISO</cell>
                  <cell>International Organization for Standardization</cell>
                </row>
                <row>
                  <cell>ISP</cell>
                  <cell>Information Security Policy</cell>
                </row>
                <row>
                  <cell>ITSA</cell>
                  <cell>Information Technology Security Advisor</cell>
                </row>
                <row>
                  <cell>ITSM</cell>
                  <cell>Information Technology Security Manager </cell>
                </row>
                <row>
                  <cell>ITSO</cell>
                  <cell>Information Technology Security Officer</cell>
                </row>
                <row>
                  <cell>KMP</cell>
                  <cell>Key Management Plan</cell>
                </row>
                <row>
                  <cell>LAN</cell>
                  <cell>Local Area Network</cell>
                </row>
                <row>
                  <cell>MFD</cell>
                  <cell>Multifunction Device</cell>
                </row>
                <row>
                  <cell>NAA</cell>
                  <cell>National Archives of Australia</cell>
                </row>
                <row>
                  <cell>NDPP</cell>
                  <cell>Network Device Protection Profile</cell>
                </row>
                <row>
                  <cell>NIST</cell>
                  <cell>National Institute of Standards and Technology</cell>
                </row>
                <row>
                  <cell>NZS</cell>
                  <cell>New Zealand Standard</cell>
                </row>
                <row>
                  <cell>OSI</cell>
                  <cell>Open System Interconnect</cell>
                </row>
                <row>
                  <cell>PSTN</cell>
                  <cell>Public Switched Telephone Network</cell>
                </row>
                <row>
                  <cell>RAM</cell>
                  <cell>Random Access Memory</cell>
                </row>
                <row>
                  <cell>RF</cell>
                  <cell>Radio Frequency</cell>
                </row>
                <row>
                  <cell>RFC</cell>
                  <cell>Request for Comments</cell>
                </row>
                <row>
                  <cell>RSA</cell>
                  <cell>Rivest-Shamir-Adleman</cell>
                </row>
                <row>
                  <cell>RTP</cell>
                  <cell>Real-time Transport Protocol</cell>
                </row>
                <row>
                  <cell>SCEC</cell>
                  <cell>Security Construction and Equipment Committee</cell>
                </row>
                <row>
                  <cell>SHA</cell>
                  <cell>Secure Hashing Algorithm</cell>
                </row>
                <row>
                  <cell>S/MIME</cell>
                  <cell>Secure Multipurpose Internet Mail Extension</cell>
                </row>
                <row>
                  <cell>SOE</cell>
                  <cell>Standard Operating Environment</cell>
                </row>
                <row>
                  <cell>SOP</cell>
                  <cell>Standard Operating Procedure</cell>
                </row>
                <row>
                  <cell>SP</cell>
                  <cell>Special Publication</cell>
                </row>
                <row>
                  <cell>SPF</cell>
                  <cell>Sender Policy Framework</cell>
                </row>
                <row>
                  <cell>SRMP</cell>
                  <cell>Security Risk Management Plan</cell>
                </row>
                <row>
                  <cell>SSH</cell>
                  <cell>Secure Shell</cell>
                </row>
                <row>
                  <cell>SSL</cell>
                  <cell>Secure Sockets Layer</cell>
                </row>
                <row>
                  <cell>SSP</cell>
                  <cell>System Security Plan</cell>
                </row>
                <row>
                  <cell>TLS</cell>
                  <cell>Transport Layer Security</cell>
                </row>
                <row>
                  <cell>TOE</cell>
                  <cell>Trusted Operating Environment</cell>
                </row>
                <row>
                  <cell>UPS</cell>
                  <cell>Uninterruptible Power Supply</cell>
                </row>
                <row>
                  <cell>USB</cell>
                  <cell>Universal Serial Bus</cell>
                </row>
                <row>
                  <cell>VLAN</cell>
                  <cell>Virtual Local Area Network</cell>
                </row>
                <row>
                  <cell>VoIP</cell>
                  <cell>Voice over Internet Protocol</cell>
                </row>
                <row>
                  <cell>VPN</cell>
                  <cell>Virtual Private Network</cell>
                </row>
                <row>
                  <cell>WAP</cell>
                  <cell>Wireless Access Point</cell>
                </row>
                <row>
                  <cell>WEP</cell>
                  <cell>Wired Equivalent Privacy</cell>
                </row>
                <row>
                  <cell>WLAN</cell>
                  <cell>Wireless Local Area Network</cell>
                </row>
                <row>
                  <cell>WPA2</cell>
                  <cell>Wi-Fi Protected Access 2</cell>
                </row>
                <row>
                  <cell>XAUTH</cell>
                  <cell>IKE Extended Authentication</cell>
                </row>
          </table>
				</content>
			</block>
			</block>

      </section>
      <section>
        <title>Glossary of Terms</title>
				<block>
				<block>
				<content>
          <table>
                <header>
                  <cell>Term</cell>
                  <cell>Meaning</cell>
                </header>
                <row>
                  <cell>802.11</cell>
                  <cell>The Institute of Electrical and Electronics Engineers standard defining Wireless Local Area Network communications.</cell>
                </row>
                <row>
                  <cell>access gateway</cell>
                  <cell>A gateway that provides the system user access to multiple security domains from a single device, typically a workstation.</cell>
                </row>
                <row>
                  <cell>accountable materiel</cell>
                  <cell>If strict control over access to, and movement of, particularly sensitive information is required, originators can make this information 'accountable materiel'. What constitutes accountable materiel will vary from agency to agency, but could include budget papers, tender documents, sensitive ministerial briefing documents, etc.</cell>
                </row>
                <row>
                  <cell>accreditation</cell>
                  <cell>A procedure by which an authoritative body gives formal recognition, approval and acceptance of the associated residual security risk with the operation of a system.</cell>
                </row>
                <row>
                  <cell>accreditation authority</cell>
                  <cell>The authoritative body associated with accreditation activities. Advice on who should be recognised as an agency’s accreditation authority can be found in this manual’s Conducting Accreditation section of the System Accreditation chapter.</cell>
                </row>
                <row>
                  <cell>agency</cell>
                  <cell>Australian Government departments, authorities, agencies or other bodies established in relation to public purposes, including departments and authorities staffed under the Public Service Act 1999.</cell>
                </row>
                <row>
                  <cell>agency head</cell>
                  <cell>The government employee with ultimate responsibly for the secure operation of agency functions, whether performed in-house or outsourced.</cell>
                </row>
                <row>
                  <cell>application whitelisting</cell>
                  <cell>An approach in which all executables and applications are prevented from executing by default, with an explicitly defined set of executables allowed to execute.</cell>
                </row>
                <row>
                  <cell>asset</cell>
                  <cell>Anything of value, such as Information and Communications Technology equipment, software and information.</cell>
                </row>
                <row>
                  <cell>attack surface</cell>
                  <cell>The amount of Information and Communications Technology equipment and software used in a system. The greater the attack surface the greater the chances are of an attacker finding an exploitable vulnerability.</cell>
                </row>
                <row>
                  <cell>audit</cell>
                  <cell>An independent review of event logs and related activities performed to determine the adequacy of current security measures, to identify the degree of conformance with established policy or to develop recommendations for improvements to the security measures currently applied.</cell>
                </row>
                <row>
                  <cell>Australasian Information Security Evaluation Program</cell>
                  <cell>A program under which evaluations are performed by impartial companies against the Common Criteria. The results of these evaluations are then certified by the Defence Signals Directorate, which is responsible for the overall operation of the program.</cell>
                </row>
                <row>
                  <cell>Australian Eyes Only</cell>
                  <cell>A caveat indicating that the information is not to be passed to or accessed by foreign nationals.</cell>
                </row>
                <row>
                  <cell>Australian Government Access Only</cell>
                  <cell>A caveat used by the Department of Defence and the Australian Security Intelligence Organisation indicating the information is not to be passed to or accessed by foreign nationals, with the exception of seconded foreign nationals. Such material received in other agencies must be handled as if it were marked as Australian Eyes Only.</cell>
                </row>
                <row>
                  <cell>Australian Government Information Security Manual</cell>
                  <cell>National information security policy produced by the Defence Signals Directorate that aims to provide a common approach to the implementation of security measures for information and systems across government.</cell>
                </row>
                <row>
                  <cell>Authentication Header</cell>
                  <cell>A protocol used for authentication in Internet Protocol Security.</cell>
                </row>
                <row>
                  <cell>baseline</cell>
                  <cell>A release of this manual including errata and interim policy releases.</cell>
                </row>
                <row>
                  <cell>blacklist</cell>
                  <cell>A set of inclusive non-accepted items that confirm the item being analysed is not acceptable. It is the opposite of a whitelist which confirms that items are acceptable.</cell>
                </row>
                <row>
                  <cell>cascaded connections</cell>
                  <cell>Cascaded connections occur when one network is connected to another, which has a connection to a third network, and so on.</cell>
                </row>
                <row>
                  <cell>caveat</cell>
                  <cell>A marking that indicates that the information has special requirements in addition to those indicated by the classification. The term covers codewords, source codewords, releasability indicators and special-handling caveats.</cell>
                </row>
                <row>
                  <cell>certification</cell>
                  <cell>A procedure by which a formal assurance statement is given that a deliverable conforms to a specified standard.</cell>
                </row>
                <row>
                  <cell>certification authority</cell>
                  <cell>An official with the authority to assert that a system complies with prescribed controls in a standard.</cell>
                </row>
                <row>
                  <cell>Certification Report</cell>
                  <cell>A report generated by a certification body of a Common Criteria scheme that provides a summary of the findings of an evaluation.</cell>
                </row>
                <row>
                  <cell>Chief Information Security Officer</cell>
                  <cell>A senior executive who is responsible for coordinating communication between security and business functions as well as overseeing the application of controls and security risk management processes.</cell>
                </row>
                <row>
                  <cell>classification</cell>
                  <cell>The business impact level associated with information or a system.</cell>
                </row>
                <row>
                  <cell>classified information</cell>
                  <cell>Information that requires protection from unauthorised disclosure.</cell>
                </row>
                <row>
                  <cell>classified system</cell>
                  <cell>A system that processes, stores or communicates classified information.</cell>
                </row>
                <row>
                  <cell>coercivity</cell>
                  <cell>A property of magnetic material, used as a measure of the amount of coercive force required to reduce the magnetic induction to zero from its remnant state.</cell>
                </row>
                <row>
                  <cell>Common Criteria</cell>
                  <cell>An International Organization for Standardization standard (15408) for information security evaluations.</cell>
                </row>
                <row>
                  <cell>Common Criteria Recognition Arrangement</cell>
                  <cell>An international agreement which facilitates the mutual recognition of Common Criteria evaluations by certificate producing schemes, including the Australian and New Zealand certification scheme.</cell>
                </row>
                <row>
                  <cell>communications security</cell>
                  <cell>The security measures taken to deny unauthorised personnel information derived from telecommunications and to ensure the authenticity of such telecommunications.</cell>
                </row>
                <row>
                  <cell>conduit</cell>
                  <cell>A tube, duct or pipe used to protect cables.</cell>
                </row>
                <row>
                  <cell>connection forwarding</cell>
                  <cell>The use of network address translation to allow a port on a network node inside a Local Area Network to be accessed from outside the network. Alternatively, using a Secure Shell server to forward a Transmission Control Protocol connection to an arbitrary port on the local host.</cell>
                </row>
                <row>
                  <cell>Consumer Guide</cell>
                  <cell>Product specific advice concerning evaluated products can consist of findings from mutually recognised information security evaluations (such as the Common Criteria), findings from Defence Signals Directorate internal evaluations, any recommendations for use and references to relevant policy and standards.</cell>
                </row>
                <row>
                  <cell>content filtering</cell>
                  <cell>The most commonly used method to filter spam. Most antivirus methods are classified as content filters too, since they scan files, binary attachments of email and Hypertext Markup Language payload.</cell>
                </row>
                <row>
                  <cell>cross domain solution</cell>
                  <cell>A highly trusted implementation of a gateway for high assurance applications.</cell>
                </row>
                <row>
                  <cell>cryptographic hash</cell>
                  <cell>An algorithm (the hash function) which takes as input a string of any length (the message), and generates a fixed length string (the message digest or fingerprint) as output. The algorithm is designed to make it computationally infeasible to find any input which maps to a given digest, or to find two different messages that map to the same digest.</cell>
                </row>
                <row>
                  <cell>cryptographic protocol</cell>
                  <cell>An agreed standard for secure communication between two or more entities.</cell>
                </row>
                <row>
                  <cell>cryptographic system</cell>
                  <cell>A related set of hardware or software used for cryptographic communication, processing or storage, and the administrative framework in which it operates.</cell>
                </row>
                <row>
                  <cell>cryptographic system material</cell>
                  <cell>Material that includes, but is not limited to, cryptographic key, equipment, devices, documents and firmware or software that embodies or describes cryptographic logic.</cell>
                </row>
                <row>
                  <cell>cyber security</cell>
                  <cell>Security measures relating to the confidentiality, availability and integrity of information that is processed, stored and communicated by electronic or similar means.</cell>
                </row>
                <row>
                  <cell>cyber security incident</cell>
                  <cell>An occurrence or activity that may threaten the confidentiality, integrity or availability of a system or the information stored, processed or communicated by it.</cell>
                </row>
                <row>
                  <cell>Cyber Security Incident Reporting scheme</cell>
                  <cell>A scheme established by the Defence Signals Directorate to collect information on cyber security incidents that affect government systems.</cell>
                </row>
                <row>
                  <cell>data at rest</cell>
                  <cell>Information residing on media or a system that is not powered or is unauthenticated to.</cell>
                </row>
                <row>
                  <cell>data in transit</cell>
                  <cell>Information that is being communicated across a communication medium.</cell>
                </row>
                <row>
                  <cell>data in use</cell>
                  <cell>Information that has been decrypted for processing by a system.</cell>
                </row>
                <row>
                  <cell>data spill</cell>
                  <cell>A cyber security incident that occurs when information is transferred between two security domains by an unauthorised means. This can include from a classified network to a less classified network or between two areas with different need-to-know requirements.</cell>
                </row>
                <row>
                  <cell>declassification</cell>
                  <cell>A process whereby information is reduced to an unclassified state and an administrative decision is made to formally authorise its release into the public domain.</cell>
                </row>
                <row>
                  <cell>degausser</cell>
                  <cell>An electrical device or permanent magnet assembly which generates a coercive magnetic force for the purpose of degaussing magnetic storage devices.</cell>
                </row>
                <row>
                  <cell>degaussing</cell>
                  <cell>A process for reducing the magnetisation of a magnetic storage device to zero by applying a reverse (coercive) magnetic force, rendering any previously stored information unreadable.</cell>
                </row>
                <row>
                  <cell>delegate</cell>
                  <cell>A person or group of personnel to whom the authority to authorise non-compliance with requirements in this manual has been delegated by the agency head.</cell>
                </row>
                <row>
                  <cell>demilitarised zone</cell>
                  <cell>A small network with one or more servers that is kept separate from the core network, either on the outside of the firewall, or as a separate network protected by the firewall. Demilitarised zones usually provide public domain information to less trusted networks, such as the Internet.</cell>
                </row>
                <row>
                  <cell>device access control software</cell>
                  <cell>Software that can be installed on a system to restrict access to communications ports on workstations. Device access control software can either block all access to a communications port or allow access using a whitelisting approach based on device types, manufacturer’s identification, or even unique device identifiers.</cell>
                </row>
                <row>
                  <cell>Diffie-Hellman groups</cell>
                  <cell>A method used for specifying the modulus size used in the Hashed Message Authentication Code algorithms. Each Diffie-Hellman group represents a specific modulus size. For example, group 2 represents a modulus size of 1024 bits.</cell>
                </row>
                <row>
                  <cell>diode</cell>
                  <cell>A device that allows data to flow in only one direction.</cell>
                </row>
                <row>
                  <cell>dissemination limiting marker</cell>
                  <cell>Markings used to indicate that official information has a special handling requirement or a distribution that is restricted to a particular audience. Example dissemination limiting markers include For Official Use Only and Sensitive.</cell>
                </row>
                <row>
                  <cell>dual-stack device</cell>
                  <cell>A product that implements both Internet Protocol version 4 and 6 protocol stacks.</cell>
                </row>
                <row>
                  <cell>emanation security</cell>
                  <cell>The counter-measure employed to reduce classified emanations from a facility and its systems to an acceptable level. Emanations can be in the form of Radio Frequency energy, sound waves or optical signals.</cell>
                </row>
                <row>
                  <cell>emergency access</cell>
                  <cell>The process of a system user accessing a system that they do not hold appropriate security clearances for due to an immediate and critical emergency requirement.</cell>
                </row>
                <row>
                  <cell>emergency situation</cell>
                  <cell>A situation requiring the evacuation of a site. Examples include fires and bomb threats.</cell>
                </row>
                <row>
                  <cell>Encapsulating Security Payload</cell>
                  <cell>A protocol used for encryption and authentication in Internet Protocol Security.</cell>
                </row>
                <row>
                  <cell>escort</cell>
                  <cell>A person who ensures that when maintenance or repairs are undertaken to Information and Communications Technology equipment that uncleared personnel are not exposed to sensitive or classified information.</cell>
                </row>
                <row>
                  <cell>facility</cell>
                  <cell>An area that facilitates government business. For example, a facility can be a building, a floor of a building or a designated space on the floor of a building.</cell>
                </row>
                <row>
                  <cell>fax machine</cell>
                  <cell>A device that allows copies of documents to be sent over a telephone network.</cell>
                </row>
                <row>
                  <cell>filter</cell>
                  <cell>A hardware or software device that controls the flow of data in accordance with a security policy.</cell>
                </row>
                <row>
                  <cell>firewall</cell>
                  <cell>A network protection device that filters incoming and outgoing network data, based on a series of rules.</cell>
                </row>
                <row>
                  <cell>firmware</cell>
                  <cell>Software embedded in a hardware device.</cell>
                </row>
                <row>
                  <cell>flash memory media</cell>
                  <cell>A specific type of Electrically Erasable Programmable Read-only Memory.</cell>
                </row>
                <row>
                  <cell>fly lead</cell>
                  <cell>A lead that connects Information and Communications Technology equipment to the fixed infrastructure of the facility. For example, the lead that connects a workstation to a network wall socket.</cell>
                </row>
                <row>
                  <cell>foreign national</cell>
                  <cell>A person who is not an Australian citizen.</cell>
                </row>
                <row>
                  <cell>foreign system</cell>
                  <cell>A system that is not solely owned and managed by the Australian Government.</cell>
                </row>
                <row>
                  <cell>gateway</cell>
                  <cell>Gateways connect two or more networks from different security domains to allow access to, or transfer of, information according to defined security polices. Some gateways can be automated through a combination of physical or software mechanisms. Gateways are grouped into three categories: access gateways, multilevel gateways and transfer gateways. Typical gateways process information at the network layer while gateways that process information at all layers of the Open System Interconnect model are often known as cross domain solutions.</cell>
                </row>
                <row>
                  <cell>general user</cell>
                  <cell>A system user who can, with their normal privileges, make only limited changes to a system and generally cannot bypass system security.</cell>
                </row>
                <row>
                  <cell>government system</cell>
                  <cell>Systems containing unclassified but sensitive information not intended for public release, such as Dissemination Limiting Marker information; note 'Government' is not a security classification under the Australian Government Security Classification System.</cell>
                </row>
                <row>
                  <cell>hardware</cell>
                  <cell>A generic term for any physical component of Information and Communication Technology.</cell>
                </row>
                <row>
                  <cell>Hashed Message Authentication Code algorithms</cell>
                  <cell>The SHA-1 hashing algorithm, combined with additional cryptographic functions, forms the Hashed Message Authentication Code algorithms of HMAC-SHA-1-96.</cell>
                </row>
                <row>
                  <cell>High Grade Cryptographic Equipment</cell>
                  <cell>The equivalent to United States Type 1 cryptographic equipment.</cell>
                </row>
                <row>
                  <cell>host-based intrusion prevention system</cell>
                  <cell>A security device, resident on a specific host, which monitors system activities for malicious or unwanted behaviour and can react in real-time to block or prevent those activities.</cell>
                </row>
                <row>
                  <cell>hybrid hard drives</cell>
                  <cell>Non-volatile magnetic media that use a cache to increase read and write speeds and reduce boot time. The cache is normally flash memory media or battery backed Random Access Memory.</cell>
                </row>
                <row>
                  <cell>Incident Response Plan</cell>
                  <cell>A plan for responding to cyber security incidents.</cell>
                </row>
                <row>
                  <cell>information security</cell>
                  <cell>Security measures relating to the confidentiality, availability and integrity of information.</cell>
                </row>
                <row>
                  <cell>Information Security Policy</cell>
                  <cell>A high-level document that describes how an agency protects its systems. The Information Security Policy is normally developed to cover all systems and can exist as a single document or as a set of related documents.</cell>
                </row>
                <row>
                  <cell>Information Security-Registered Assessor Program</cell>
                  <cell>A Defence Signals Directorate initiative designed to register suitably qualified information security assessors to carry out specific types of security assessments.</cell>
                </row>
                <row>
                  <cell>Information Technology Security Advisor</cell>
                  <cell>The Information Technology Security Manager who has responsibility for information technology security management across the agency is designated as the Information Technology Security Advisor. This title reflects the responsibility this person has as the first point of contact for the Chief Information Security Officer and external agencies on any information technology security management issues.</cell>
                </row>
                <row>
                  <cell>Information Technology Security Manager</cell>
                  <cell>Information Technology Security Managers (ITSMs) are executives that coordinate the strategic directions provided by the Chief Information Security Officer and the technical efforts of Information Technology Security Officers. The main area of responsibility of ITSMs is that of the day-to-day management of information security within an agency.</cell>
                </row>
                <row>
                  <cell>Information Technology Security Officer</cell>
                  <cell>Information Technology Security Officers implement technical solutions under the guidance of an Information Technology Security Manager to ensure that the strategic direction for information security within the agency set by the Chief Information Security Officer is achieved.</cell>
                </row>
                <row>
                  <cell>infrared device</cell>
                  <cell>Devices such as mice, keyboards, pointing devices and mobile devices that have an infrared communications capability.</cell>
                </row>
                <row>
                  <cell>Internet Key Exchange Extended Authentication</cell>
                  <cell>Internet Key Exchange Extended Authentication is used for providing an additional level of authentication by allowing Internet Protocol Security gateways to request additional authentication information from remote users. As a result, users are forced to respond with credentials before being allowed access to the connection.</cell>
                </row>
                <row>
                  <cell>Internet Protocol Security</cell>
                  <cell>A suite of protocols for secure communications through authentication or encryption of Internet Protocol packets as well as including protocols for cryptographic key establishment.</cell>
                </row>
                <row>
                  <cell>Internet Protocol telephony</cell>
                  <cell>The transport of telephone calls over Internet Protocol networks.</cell>
                </row>
                <row>
                  <cell>Internet Protocol version 6</cell>
                  <cell>A protocol used for communicating over a packet switched network. Version 6 is the successor to version 4 which is widely used on the Internet. The main change introduced in version 6 is a greater address space available for identifying network devices, workstations and servers.</cell>
                </row>
                <row>
                  <cell>Intrusion Detection System </cell>
                  <cell>An automated system used to identify an infringement of security policy.</cell>
                </row>
                <row>
                  <cell>ISAKMP aggressive mode</cell>
                  <cell>An Internet Protocol Security protocol that uses half the exchanges of main mode to establish an Internet Protocol Security connection.</cell>
                </row>
                <row>
                  <cell>ISAKMP main mode</cell>
                  <cell>An Internet Protocol Security protocol that offers optimal security using 6 packets to establish an Internet Protocol Security connection.</cell>
                </row>
                <row>
                  <cell>ISAKMP quick mode</cell>
                  <cell>An Internet Protocol Security protocol that is used for refreshing security association information.</cell>
                </row>
                <row>
                  <cell>Information and Communications Technology equipment</cell>
                  <cell>Information and Communications Technology equipment includes, but is not limited to, workstations, printers, photocopiers, scanners and Multifunction Devices.</cell>
                </row>
                <row>
                  <cell>key management</cell>
                  <cell>The use and management of cryptographic keys and associated hardware and software. It includes their generation, registration, distribution, installation, usage, protection, storage, access, recovery and destruction.</cell>
                </row>
                <row>
                  <cell>Key Management Plan</cell>
                  <cell>A plan that describes how cryptographic services are securely deployed. It documents critical key management controls to protect keys and associated material during their life cycle, along with other controls to provide confidentiality, integrity and availability of keys.</cell>
                </row>
                <row>
                  <cell>limited higher access</cell>
                  <cell>The process of a system user accessing a system that they do not hold appropriate security clearances for, for a limited non-ongoing period of time.</cell>
                </row>
                <row>
                  <cell>lockable commercial cabinet</cell>
                  <cell>A cabinet that is commercially available, of robust construction and is fitted with a commercial lock.</cell>
                </row>
                <row>
                  <cell>logging facility</cell>
                  <cell>A facility that includes the software component which generates the event and associated details, the transmission (if necessary) of these logs and how they are stored.</cell>
                </row>
                <row>
                  <cell>malicious code</cell>
                  <cell>Any software that attempts to subvert the confidentiality, integrity or availability of a system. Types of malicious code include logic bombs, trapdoors, Trojans, viruses and worms.</cell>
                </row>
                <row>
                  <cell>malicious code infection</cell>
                  <cell>A cyber security incident that occurs when malicious code is used to infect a system. Example methods of malicious code infection include viruses, worms and Trojans.</cell>
                </row>
                <row>
                  <cell>management traffic </cell>
                  <cell>Traffic generated by system administrators over a network in order to control a device. This traffic includes standard management protocols, but also includes traffic that contains information relating to the management of the network.</cell>
                </row>
                <row>
                  <cell>media</cell>
                  <cell>A generic term for hardware that is used to store information.</cell>
                </row>
                <row>
                  <cell>media destruction</cell>
                  <cell>The process of physically damaging the media with the objective of making the data stored on it inaccessible. To destroy media effectively, only the actual material in which the data is stored needs to be destroyed.</cell>
                </row>
                <row>
                  <cell>media disposal</cell>
                  <cell>The process of relinquishing control of media when no longer required, in a manner that ensures that no data can be recovered from the media.</cell>
                </row>
                <row>
                  <cell>media sanitisation</cell>
                  <cell>The process of erasing or overwriting data stored on media.</cell>
                </row>
                <row>
                  <cell>metadata</cell>
                  <cell>Structured information that describes and/or allows personnel to find, manage, control, understand or preserve other information over time. Metadata fixes the record in its business context and documents the record’s management and use over time. Records metadata therefore serves to identify, authenticate and contextualise the record.</cell>
                </row>
                <row>
                  <cell>Multifunction Devices</cell>
                  <cell>The class of devices that combines printing, scanning, copying, faxing or voice messaging functionality in the one device. These devices are often designed to connect to computer and telephone networks simultaneously.</cell>
                </row>
                <row>
                  <cell>multilevel gateway</cell>
                  <cell>A gateway that enables access, based on authorisation, to data at many classification and releasability levels where each data unit is individually marked according to its security domain.</cell>
                </row>
                <row>
                  <cell>need-to-know</cell>
                  <cell>The principle of telling a person only the information that they require to fulfil their role.</cell>
                </row>
                <row>
                  <cell>network access control</cell>
                  <cell>Policies used to control access to a network and actions on a network, including authentication checks and authorisation controls.</cell>
                </row>
                <row>
                  <cell>network device</cell>
                  <cell>Any device designed to facilitate the communication of information destined for multiple system users. For example: cryptographic devices, firewalls, routers, switches and hubs.</cell>
                </row>
                <row>
                  <cell>network infrastructure</cell>
                  <cell>The infrastructure used to carry information between workstations and servers or other network devices. </cell>
                </row>
                <row>
                  <cell>network protection device</cell>
                  <cell>A sub-class of network device used specifically to protect a network. For example, a firewall.</cell>
                </row>
                <row>
                  <cell>no-lone zone</cell>
                  <cell>An area in which personnel are not permitted to be left alone such that all actions are witnessed by at least one other person.</cell>
                </row>
                <row>
                  <cell>non-volatile media</cell>
                  <cell>A type of media which retains its information when power is removed.</cell>
                </row>
                <row>
                  <cell>off-hook audio protection</cell>
                  <cell>A method of mitigating the possibility of an active, but temporarily unattended handset inadvertently allowing discussions being undertaken in the vicinity of the handset to be heard by the remote party. This could be achieved through the use of a hold feature, mute feature, push-to-talk handset or equivalent.</cell>
                </row>
                <row>
                  <cell>official information</cell>
                  <cell>Any information developed, received or collected by, or on behalf of, the Government, through its agencies and contracted providers. This includes unclassified, sensitive and classified information.</cell>
                </row>
                <row>
                  <cell>OpenPGP Message Format</cell>
                  <cell>An open-source implementation of Pretty Good Privacy, a widely available cryptographic toolkit.</cell>
                </row>
                <row>
                  <cell>patch cable</cell>
                  <cell>A metallic (copper) or fibre optic cable used for routing signals between two components in an enclosed container or rack.</cell>
                </row>
                <row>
                  <cell>patch panel</cell>
                  <cell>A group of sockets or connectors that allow manual configuration changes, generally by means of connecting cables to the appropriate connector. Cables could be metallic (copper) or fibre optic.</cell>
                </row>
                <row>
                  <cell>Perfect Forward Security</cell>
                  <cell>Additional security for security associations in that if one security association is compromised subsequent security associations will not be compromised.</cell>
                </row>
                <row>
                  <cell>peripheral switch</cell>
                  <cell>A device used to share a set of peripherals between a number of computers.</cell>
                </row>
                <row>
                  <cell>privileged user</cell>
                  <cell>A system user who can alter or circumvent system security protections. This can also apply to system users who could have only limited privileges, such as software developers, who can still bypass security precautions. A privileged user can have the capability to modify system configurations, account privileges, audit logs, data files or applications.</cell>
                </row>
                <row>
                  <cell>protective marking</cell>
                  <cell>A marking that is applied to sensitive or classified information to indicate the security measures that need to be applied to the information to ensure that it is appropriately protected.</cell>
                </row>
                <row>
                  <cell>Protective Security Policy Framework</cell>
                  <cell>Australian Government protective security policy produced by the Attorney-General’s Department which provides a common and comprehensive approach to protective security across government.</cell>
                </row>
                <row>
                  <cell>public domain information</cell>
                  <cell>Unclassified information authorised for unlimited public access or circulation, such as publications and websites.</cell>
                </row>
                <row>
                  <cell>public network infrastructure</cell>
                  <cell>Network infrastructure within the public domain that an agency has no control over, for example the Internet.</cell>
                </row>
                <row>
                  <cell>Public Switched Telephone Network</cell>
                  <cell>A public network where voice is communicated using analog communications.</cell>
                </row>
                <row>
                  <cell>public system</cell>
                  <cell>A system that processes, stores or communicates only unclassified information that has been authorised for release into the public domain.</cell>
                </row>
                <row>
                  <cell>push-to-talk</cell>
                  <cell>Handsets that have a button which must be pressed by the user before audio can be communicated, thus providing fail-safe off-hook audio protection.</cell>
                </row>
                <row>
                  <cell>quality of service</cell>
                  <cell>A process to prioritise network traffic based on availability requirements.</cell>
                </row>
                <row>
                  <cell>reaccreditation</cell>
                  <cell>A procedure by which an authoritative body gives formal recognition, approval and acceptance of the associated residual security risk with the continued operation of a system.</cell>
                </row>
                <row>
                  <cell>reclassification</cell>
                  <cell>An administrative decision to change the security measures afforded to information based on a reassessment of the potential impact of its unauthorised disclosure. The lowering of the security measures for media containing classified information often requires sanitisation or destruction processes to be undertaken prior to a formal decision to lower the security measures protecting the information.</cell>
                </row>
                <row>
                  <cell>remote access</cell>
                  <cell>Access to a system that originates from outside an agency network and enters the network through an Internet gateway. </cell>
                </row>
                <row>
                  <cell>removable media</cell>
                  <cell>Storage media that can be easily removed from a system and is designed for removal.</cell>
                </row>
                <row>
                  <cell>rogue Wireless Access Point</cell>
                  <cell>A Wireless Access Point operating outside of the control of an agency.</cell>
                </row>
                <row>
                  <cell>seconded foreign national</cell>
                  <cell>A representative of a foreign government on exchange or long-term posting.</cell>
                </row>
                <row>
                  <cell>secured space</cell>
                  <cell>An area that has been certified to the physical security requirements for a Zone 2 to Zone 5 area as defined in the Australian Government Physical Security Management Protocol.</cell>
                </row>
                <row>
                  <cell>Secure Multipurpose Internet Mail Extension</cell>
                  <cell>A protocol which allows the encryption and signing of Multipurpose Internet Mail Extension-encoded email messages including attachments.</cell>
                </row>
                <row>
                  <cell>Secure Shell</cell>
                  <cell>A network protocol that can be used to securely log into a remote workstation, executing commands on a remote workstation and securely transfer files between workstations.</cell>
                </row>
                <row>
                  <cell>security association</cell>
                  <cell>A collection of connection-specific parameters containing information about a one-way connection in Internet Protocol Security that is required for each protocol used.</cell>
                </row>
                <row>
                  <cell>security association lifetimes</cell>
                  <cell>The duration security association information is valid for.</cell>
                </row>
                <row>
                  <cell>Security Construction and Equipment Committee</cell>
                  <cell>A standing interdepartmental committee responsible for the evaluation and endorsement of security equipment for use by Australian Government agencies. The committee is chaired by the Australian Security Intelligence Organisation and reports to the Protective Security Policy Committee.</cell>
                </row>
                <row>
                  <cell>security domains</cell>
                  <cell>A system or collection of systems operating under a security policy that defines the classification and releasability of the information processed in the domain. It can be exhibited as a classification, a community of interest or releasability within a certain classification.</cell>
                </row>
                <row>
                  <cell>Security Equipment Catalogue</cell>
                  <cell>A catalogue produced by the Security Construction and Equipment Committee (SCEC) that lists security equipment that has been tested and endorsed as meeting relevant SCEC standards.</cell>
                </row>
                <row>
                  <cell>Security Executive</cell>
                  <cell>A member of the Senior Executive Service who is responsible for protective security.</cell>
                </row>
                <row>
                  <cell>security of information arrangement</cell>
                  <cell>A formal arrangement between the Australian Government and a foreign government on the protection of classified information exchanged between the two parties. Details of security of information arrangements can be obtained from the Attorney-General’s Department.</cell>
                </row>
                <row>
                  <cell>security posture</cell>
                  <cell>The level of security risk to which a system is exposed. A system with a strong security posture is exposed to a low level of security risk while a system with a weak security posture is exposed to a high level of security risk.</cell>
                </row>
                <row>
                  <cell>Security Risk Management Plan</cell>
                  <cell>A plan that identifies security risks and appropriate risk treatments.</cell>
                </row>
                <row>
                  <cell>Security Target</cell>
                  <cell>An artefact of Common Criteria evaluations. It contains the information security requirements of an identified target of evaluation and specifies the functional and assurance security measures offered by that target of evaluation to meet the stated requirements.</cell>
                </row>
                <row>
                  <cell>sensitive information</cell>
                  <cell>Either unclassified or classified information with a dissemination limiting marker.</cell>
                </row>
                <row>
                  <cell>server</cell>
                  <cell>A computer (including mainframes) used to run programs that provide services to multiple users. For example, a file server, email server or database server.</cell>
                </row>
                <row>
                  <cell>softphone</cell>
                  <cell>A software application that allows a workstation to act as an Internet Protocol phone, using either a built-in or an externally connected microphone and speaker.</cell>
                </row>
                <row>
                  <cell>software component</cell>
                  <cell>An element of a system, including but not limited to, a database, operating system, network or web application.</cell>
                </row>
                <row>
                  <cell>solid state drives</cell>
                  <cell>Non-volatile media that uses flash memory media to retain its information when power is removed and, unlike non-volatile magnetic media, contains no moving parts.</cell>
                </row>
                <row>
                  <cell>split tunnelling</cell>
                  <cell>Functionality that allows personnel to access both a public network and a Virtual Private Network connection at the same time, such as an agency system and the Internet.</cell>
                </row>
                <row>
                  <cell>SSH-agent</cell>
                  <cell>An automated or script-based Secure Shell session.</cell>
                </row>
                <row>
                  <cell>Standard Operating Environment</cell>
                  <cell>A standardised build of an operating system and associated software that is deployed on multiple devices. A Standard Operating Environment can be used for servers, workstations, laptops and mobile devices.</cell>
                </row>
                <row>
                  <cell>Standard Operating Procedures</cell>
                  <cell>Instructions for complying with a System Security Plan. For example, how to update virus signature files.</cell>
                </row>
                <row>
                  <cell>system</cell>
                  <cell>A related set of hardware and software used for the processing, storage or communication of information and the governance framework in which it operates.</cell>
                </row>
                <row>
                  <cell>system owner</cell>
                  <cell>The person responsible for the information resource.</cell>
                </row>
                <row>
                  <cell>system classification</cell>
                  <cell>The classification of a system is the highest classification of information which the system is approved to store or process.</cell>
                </row>
                <row>
                  <cell>System Security Plan</cell>
                  <cell>A plan documenting the controls for a system.</cell>
                </row>
                <row>
                  <cell>system user</cell>
                  <cell>A general user or a privileged user of a system.</cell>
                </row>
                <row>
                  <cell>target of evaluation</cell>
                  <cell>The functions of a product subject to evaluation under the Common Criteria.</cell>
                </row>
                <row>
                  <cell>technical surveillance counter-measures </cell>
                  <cell>The process of surveying facilitates to detect the presence of technical surveillance devices and to identify technical security weaknesses that could aid in the conduct of a technical penetration of the surveyed facility.</cell>
                </row>
                <row>
                  <cell>telephone</cell>
                  <cell>A device that converts between sound waves and electronic signals that can be communicated over a distance.</cell>
                </row>
                <row>
                  <cell>telephone system</cell>
                  <cell>A system designed primarily for the transmission of voice traffic.</cell>
                </row>
                <row>
                  <cell>TEMPEST</cell>
                  <cell>A short name referring to investigations and studies of compromising emanations.</cell>
                </row>
                <row>
                  <cell>TEMPEST rated Information and Communications Technology equipment</cell>
                  <cell>Information and Communications Technology equipment that has been specifically designed to minimise TEMPEST emanations.</cell>
                </row>
                <row>
                  <cell>traffic flow filter</cell>
                  <cell>A device that has been configured to automatically filter and control the form of network data.</cell>
                </row>
                <row>
                  <cell>transfer gateway</cell>
                  <cell>A gateway that facilitates the transfer of information, in one or multiple directions (low to high or high to low), between different security domains.</cell>
                </row>
                <row>
                  <cell>transport mode</cell>
                  <cell>An Internet Protocol Security mode that provides a secure connection between two endpoints by encapsulating an Internet Protocol payload.</cell>
                </row>
                <row>
                  <cell>Trusted Operating Environment</cell>
                  <cell>An operating environment provides assurance that a reasonable effort has been made to secure the operating system of a mobile device such that it presents a reduced security risk to an agency’s information and systems.</cell>
                </row>
                <row>
                  <cell>trusted source</cell>
                  <cell>A person or system formally identified as being capable of reliably producing information meeting certain defined parameters, such as a maximum data classification and reliably reviewing information produced by others to confirm compliance with certain defined parameters.</cell>
                </row>
                <row>
                  <cell>tunnel mode</cell>
                  <cell>An Internet Protocol Security mode that provides a secure connection between two endpoints by encapsulating an entire Internet Protocol packet.</cell>
                </row>
                <row>
                  <cell>unclassified information</cell>
                  <cell>Information that is assessed as not requiring a classification. Unclassified information with a dissemination limiting marker is known as sensitive information while unclassified information without a dissemination limiting marker is authorised for release into the public domain.</cell>
                </row>
                <row>
                  <cell>unsecured space</cell>
                  <cell>An area that has not been certified to physical security requirements to allow for the processing of classified information.</cell>
                </row>
                <row>
                  <cell>Virtual Local Area Network</cell>
                  <cell>Network devices and ICT equipment grouped logically based on resources, security or business requirements instead of the physical location of the devices and equipment.</cell>
                </row>
                <row>
                  <cell>Virtual Private Network</cell>
                  <cell>The tunnelling of a network’s traffic through another network, separating the Virtual Private Network (VPN) traffic from the underlying network. A VPN can encrypt traffic if necessary.</cell>
                </row>
                <row>
                  <cell>volatile media</cell>
                  <cell>A type of media, such as Random Access Memory, which gradually loses its information when power is removed.</cell>
                </row>
                <row>
                  <cell>wear levelling</cell>
                  <cell>A technique used in flash memory that is used to prolong the life of the media. Data can be written to and erased from an address on flash memory a finite number of times. The wear levelling algorithm helps to distribute writes evenly across each memory block, thereby decreasing the wear on the media and increasing its lifetime. The algorithm ensures that updated or new data is written to the first available free block with the least number of writes. This creates free blocks that previously contained data.</cell>
                </row>
                <row>
                  <cell>whitelist</cell>
                  <cell>A set of inclusive accepted items that confirm the item being analysed is acceptable. It is the opposite of a blacklist which confirms that items are not acceptable.</cell>
                </row>
                <row>
                  <cell>Wi-Fi Protected Access</cell>
                  <cell>Certifications of the implementations of protocols designed to replace Wired Equivalent Privacy. They refer to components of the 802.11i security standard.</cell>
                </row>
                <row>
                  <cell>Wired Equivalent Privacy </cell>
                  <cell>A deprecated 802.11 security standard.</cell>
                </row>
                <row>
                  <cell>Wireless Access Point</cell>
                  <cell>A device which enables communications between wireless clients. It is typically also the device which connects the wireless local area network to the wired local area network.</cell>
                </row>
                <row>
                  <cell>wireless communications</cell>
                  <cell>The transmission of data over a communications path using electromagnetic waves rather than a wired medium.</cell>
                </row>
                <row>
                  <cell>Wireless Local Area Network</cell>
                  <cell>A network based on the 802.11 set of standards. Such networks are often referred to as wireless networks.</cell>
                </row>
                <row>
                  <cell>workstation</cell>
                  <cell>A stand-alone or networked single-user computer.</cell>
                </row>
                <row>
                  <cell>X11 Forwarding</cell>
                  <cell>X11, also known as the X Window System, is a basic method of video display used in a variety of operating systems. X11 forwarding allows the video display from one network node to be shown on another node.</cell>
                </row>
          </table>
				</content>
				</block>
				</block>
      </section>
    </chapter>
  </part>
</manual>

