%PDF-1.4 % 44 0 obj <> endobj 49 0 obj <> endobj 54 0 obj <> endobj 67 0 obj <> endobj 68 0 obj <> endobj 69 0 obj <>stream /P <>BDC q 1 i 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS2 gs BT /F1 1 Tf 7 0 0 7 36.9471 23.0228 Tm 0 0 0 1 k 0 Tc 0 Tw [( 2019 ISA)5.4(CA. All rights r)9.3(eser)-8.8(v)6.4(ed. )]TJ ET EMC /P <>BDC BT /F2 1 Tf 7 0 0 7 144.4321 23.0228 Tm [(www)60.6(.isaca.or)9.3(g)]TJ ET EMC /P <>BDC BT /F1 1 Tf 7 0 0 7 488.5055 23.0228 Tm [(ISA)5.4(CA )]TJ ET EMC /P <>BDC BT 7 0 0 7 509.9464 23.0228 Tm [(JOURN)-8.8(AL)]TJ ET EMC /P <>BDC /GS3 gs BT 7 0 0 7 540.8551 23.0228 Tm .73 .19 0 0 k [( V)6.4(OL 3)]TJ ET EMC /P <>BDC BT 7 0 0 7 584.9167 23.0228 Tm (1)Tj ET EMC /Artifact <>BDC 0 0 0 1 K 0 J 0 j .75 w 10 M [] 0 d /GS2 gs q 1 0 0 1 570.156 31.289 cm 0 0 m 0 -39.376 l S Q EMC /P <>BDC BT 9 0 0 9 36.9471 587.25 Tm 0 0 0 1 k -.005 Tc [(It is only r)9.3(ecently that quantitativ)6.4(e risk for)]TJ ET EMC /P <>BDC BT 9 0 0 9 199.3432 587.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 575.25 Tm -.005 Tc [(information security has been intr)9.8(oduced as a)]TJ ET EMC /P <>BDC BT 9 0 0 9 217.5069 575.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 563.25 Tm -.005 Tc [(possible e)6.4(v)7.3(olution fr)9.8(om qualitativ)6.4(e risk)]TJ ET EMC /P <>BDC BT 9 0 0 9 189.1192 563.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 551.25 Tm -.005 Tc [(methodologies. E)12.7(v)7.3(olving fr)9.8(om a qualitativ)6.4(e-based)]TJ ET EMC /P <>BDC BT 9 0 0 9 231.373 551.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 539.25 Tm -.005 Tc [(risk assessment int)9.8(o quantitativ)6.4(e can giv)6.4(e r)9.3(eal)]TJ ET EMC /P <>BDC BT 9 0 0 9 219.333 539.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 527.25 Tm -.005 Tc [(tangible indicat)9.8(ors t)9.8(o)0( decision mak)9.8(ers, and this)]TJ ET EMC /P <>BDC BT 9 0 0 9 222.663 527.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 515.25 Tm -.005 Tc [(tr)19.5(ansition can be done simply)52.3(. )]TJ ET EMC /P <>BDC BT 9 0 0 9 36.9471 491.25 Tm -.02 Tc [(While the most pr)9.3(e)6.4(v)7.3(alent international standar)9.3(ds on)]TJ ET EMC /P <>BDC BT 9 0 0 9 233.5071 491.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 479.25 Tm -.02 Tc (information risk, the US National Institute of)Tj ET EMC /P <>BDC BT 9 0 0 9 203.1926 479.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 467.25 Tm -.02 Tc [(Standar)9.3(ds and )19.5(T)48.4(echnology \(NIST\) Special Publication)]TJ ET EMC /P <>BDC BT 9 0 0 9 240.3493 467.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 455.25 Tm -.02 Tc (\(SP\) 800-30 R1)Tj ET EMC /P <>BDC BT 5.4 0 0 5.4 94.4524 457.95 Tm 0 Tc (1)Tj ET EMC /P <>BDC BT 9 0 0 9 97.3046 455.25 Tm -.02 Tc [( and the International Or)9.3(ganization for)]TJ ET EMC /P <>BDC BT 9 0 0 9 241.4837 455.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 443.25 Tm -.02 Tc [(Standar)9.3(dization \(ISO\)/International Electr)9.8(otechnical)]TJ ET EMC /P <>BDC BT 9 0 0 9 233.3008 443.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 431.25 Tm -.02 Tc [(Commission \(IEC)12.7(\) ISO/IEC 27005, do not necessarily)]TJ ET EMC /P <>BDC BT 9 0 0 9 237.7915 431.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 419.25 Tm -.02 Tc [(pr)9.8(omote the use of a specic type of analysis, ther)9.3(e is)]TJ ET EMC /P <>BDC BT 9 0 0 9 241.3566 419.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 407.25 Tm -.02 Tc [(a tendency t)9.8(o)0( adv)7.3(ocate the use of qualitativ)6.4(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 207.152 407.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 395.25 Tm -.02 Tc (assessments as stated in the ISO/IEC 27005)Tj ET EMC /P <>BDC BT 9 0 0 9 207.1687 395.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 383.25 Tm -.02 Tc [(document: In pr)19.5(actice, qualitativ)6.4(e analysis is often)]TJ ET EMC /P <>BDC BT 9 0 0 9 229.6799 383.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 371.25 Tm -.02 Tc [(used rst t)9.8(o)0( obtain a gener)19.5(al indication of the le)6.4(v)6.4(el of)]TJ ET EMC /P <>BDC BT 9 0 0 9 238.3201 371.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 359.25 Tm -.02 Tc [(risk.)83()]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 55.133 361.95 Tm 0 Tc (2)Tj ET EMC /P <>BDC BT 9 0 0 9 57.9852 359.25 Tm -.02 Tc [( Howe)6.4(v)6.4(e)0(r)60.1(,)0( ther)9.3(e is little e)6.4(vidence that qualitativ)6.4(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 237.8327 359.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 347.25 Tm -.02 Tc [(methods ar)9.3(e suitable for managing information risk.)]TJ ET EMC /P <>BDC BT 9 0 0 9 235.2429 347.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 335.25 Tm -.02 Tc [(As stated b)5.4(y)0( some of its most ar)9.3(dent detr)19.5(act)9.8(ors, the)]TJ ET EMC /P <>BDC BT 9 0 0 9 234.6939 335.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 323.25 Tm -.02 Tc [(pr)19.5(actice of information risk assessment is seriously)]TJ ET EMC /P <>BDC BT 9 0 0 9 233.6611 323.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 311.25 Tm -.02 Tc [(awed and r)9.3(epr)9.3(esents the one patch most needed )]TJ ET EMC /P <>BDC BT 9 0 0 9 36.9471 299.25 Tm [(in cybersecurity)52.3(.)83()]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 100.7901 301.95 Tm 0 Tc (3)Tj ET EMC /P <>BDC BT 5.4 0 0 5.4 103.6423 301.95 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 275.25 Tm -.005 Tc [(Risk can be dened as the pr)9.8(obability and)]TJ ET EMC /P <>BDC BT 9 0 0 9 203.8123 275.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 263.25 Tm -.005 Tc [(magnitude of a loss, disaster)60.1(, or other undesir)19.5(able)]TJ ET EMC /P <>BDC BT 9 0 0 9 233.2946 263.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 251.25 Tm -.005 Tc [(e)6.4(v)6.4(ents.)83()]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 67.749 253.95 Tm 0 Tc (4)Tj ET EMC /P <>BDC BT 9 0 0 9 70.7362 251.25 Tm -.005 Tc [( )19.5(This denition highlights the concept of)]TJ ET EMC /P <>BDC BT 9 0 0 9 228.7386 251.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 239.25 Tm -.005 Tc [(pr)9.8(obability and loss, both of which ar)9.3(e at the cor)9.3(e of)]TJ ET EMC /P <>BDC BT 9 0 0 9 240.8501 239.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 227.25 Tm -.005 Tc [(a quantitativ)6.4(e risk assessment. )]TJ ET EMC /P <>BDC /GS3 gs BT /F3 1 Tf 11 0 0 11 36.9471 201.25 Tm .72 .13 .67 .01 k [(Intr)17.6(oducing the Compar)14.7(ativ)6.4(e A)23.5(nalysis )]TJ ET EMC /P <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 36.9471 183.25 Tm 0 0 0 1 k [(A compar)19.5(ativ)6.4(e analysis is pr)9.8(o)7.3(vided based on)]TJ ET EMC /P <>BDC BT 9 0 0 9 212.4421 183.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 171.25 Tm -.005 Tc (experience working as an information risk manager)Tj ET EMC /P <>BDC BT 9 0 0 9 239.0975 171.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36.9471 159.25 Tm -.02 Tc [(in a lar)9.3(ge multinational corpor)19.5(ation. )19.5(The or)9.3(ganization,)]TJ ET EMC /P <>BDC BT 9 0 0 9 239.524 159.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 587.25 Tm -.02 Tc [(I)14.2(T)13.7(Corp \(a ctitious name based on a r)9.3(eal case\), is a)]TJ ET EMC /P <>BDC BT 9 0 0 9 450.0517 587.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 575.25 Tm -.02 Tc [(lar)9.3(ge multinational or)9.3(ganization designing and selling)]TJ ET EMC /P <>BDC BT 9 0 0 9 458.6127 575.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 563.25 Tm -.02 Tc [(mass-mark)9.8(et I)14.2(T)19.5( equipment. )19.5(The risk management)]TJ ET EMC /P <>BDC BT 9 0 0 9 445.9459 563.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 551.25 Tm -.02 Tc [(fr)19.5(amework for information security was pr)9.8(omoted)]TJ ET EMC /P <>BDC BT 9 0 0 9 445.6914 551.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 539.25 Tm -.02 Tc [(thr)9.8(oughout the or)9.3(ganization, based upon ISO/IEC)]TJ ET EMC /P <>BDC BT 9 0 0 9 441.9605 539.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 527.25 Tm -.02 Tc [(27005, and r)9.3(e)0(f)11.7(ers t)9.8(o)0( qualitativ)6.4(e indicat)9.8(ors.)]TJ ET EMC /P <>BDC BT 9 0 0 9 415.2543 527.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 503.25 Tm -.005 Tc [(The risk assessment was per)-7.3(formed for a critical)]TJ ET EMC /P <>BDC BT 9 0 0 9 448.515 503.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 491.25 Tm -.005 Tc [(system containing a lar)9.3(ge amount of cust)9.8(omer)]TJ ET EMC /P <>BDC BT 9 0 0 9 439.7609 491.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 479.25 Tm -.005 Tc [(details. )19.5(The cust)9.8(omer r)9.3(elationship management)]TJ ET EMC /P <>BDC BT 9 0 0 9 444.1984 479.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 467.25 Tm -.005 Tc [(\(CRM\) system in scope contains up t)9.8(o)0( 60 million)]TJ ET EMC /P <>BDC BT 9 0 0 9 446.4682 467.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 455.25 Tm -.005 Tc [(r)9.3(ecor)9.3(ds deemed personally identiable information)]TJ ET EMC /P <>BDC BT 9 0 0 9 456.3319 455.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 443.25 Tm -.005 Tc (\(PII\), including information such as name, )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 431.25 Tm [(addr)9.3(ess, age, date of bir)-24.4(th, gender and pr)9.8(oduct)]TJ ET EMC /P <>BDC BT 9 0 0 9 438.769 431.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 419.25 Tm -.005 Tc [(r)9.3(egistr)19.5(ation number)60.1(. )]TJ ET EMC /P <>BDC /GS3 gs BT /F3 1 Tf 11 0 0 11 255.4471 393.25 Tm .72 .13 .67 .01 k [(Method A: Qualitativ)6.4(e Risk Assessment )]TJ ET EMC /P <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 255.4471 375.25 Tm 0 0 0 1 k (Once the asset has been identied for the risk)Tj ET EMC /P <>BDC BT 9 0 0 9 435.773 375.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 363.25 Tm -.005 Tc (assessment, method A follows a typical four-step)Tj ET EMC /P <>BDC BT 9 0 0 9 450.2684 363.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.4471 351.25 Tm -.005 Tc [(appr)9.8(oach \()]TJ ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 297.9495 351.25 Tm [(gur)9.3(e 1)]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 328.7523 351.25 Tm (\). )Tj ET EMC /LBody <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 266.4471 333.25 Tm .04 1 .83 0 k (Step 1: Business impact analysis)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 398.1751 333.25 Tm 0 0 0 1 k (The risk)Tj ET EMC /LBody <>BDC BT 9 0 0 9 436.5522 333.25 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 255.4471 333.25 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 266.4471 321.2499 Tm 0 0 0 1 k -.005 Tc (assessment begins with analyzing the business)Tj ET EMC /LBody <>BDC BT 9 0 0 9 454.2272 321.2499 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 309.2499 Tm -.005 Tc [(impact, which, in this case, was r)19.5(ated 4 \(high)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 441.7543 309.2499 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 297.2499 Tm -.005 Tc [(impact\) on a scale of 1 \(low\) t)9.8(o)0( 5 \(v)6.4(er)-8.8(y high\). )]TJ ET EMC /LBody <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 266.4471 279.2499 Tm .04 1 .83 0 k [(Step 2: Contr)17.6(ol assessment)]TJ ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 376.8063 279.2499 Tm 0 0 0 1 k [(The contr)9.8(ol)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 428.6406 279.2499 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 255.4471 279.2499 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 266.4471 267.2499 Tm 0 0 0 1 k -.005 Tc (assessment then followed, and it was based)Tj ET EMC /LBody <>BDC BT 9 0 0 9 441.2664 267.2499 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 255.25 Tm -.005 Tc [(upon a pr)9.3(edened questionnair)9.3(e and co)7.4(v)6.4(e)0(r)9.3(ed a)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 451.2268 255.25 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 243.25 Tm -.005 Tc [(wide r)19.5(ange of mainstr)9.3(eam I)14.2(T)19.5( and security)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 429.6011 243.25 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 231.25 Tm -.005 Tc [(contr)9.8(ols. )19.5(The assessment typically contains a list)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 460.2512 231.25 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 219.25 Tm -.005 Tc [(of 71 contr)9.8(ols, and its primar)-8.8(y purpose is t)9.8(o)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 437.6465 219.25 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 207.25 Tm -.005 Tc (identify the potential weaknesses of the system)Tj ET EMC /LBody <>BDC BT 9 0 0 9 454.3964 207.25 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.4471 195.25 Tm -.005 Tc (in scope. )Tj ET EMC /LBody <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 266.4471 177.25 Tm .04 1 .83 0 k (Step 3: Risk analysis)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 349.236 177.25 Tm 0 0 0 1 k [(The risk fact)9.8(ors wer)9.3(e then)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 458.7811 177.25 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 255.4471 177.25 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 266.4471 165.25 Tm 0 0 0 1 k -.005 Tc [(deriv)6.4(ed fr)9.8(om the contr)9.8(ol weaknesses identied in)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 460.1743 165.25 Tm 0 Tc ( )Tj ET EMC /P <>BDC /GS3 gs BT /F5 1 Tf 30 0 0 30 36.9999 675.894 Tm .73 .19 0 0 k -.02 Tc [(E)12.7(v)7.3(olving F)12.7(r)9.8(om Qualitativ)6.4(e t)9.8(o)]TJ ET EMC /P <>BDC BT 30 0 0 30 384.7146 675.894 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 30 0 0 30 36.9999 641.8941 Tm -.02 Tc [(Quantitativ)6.4(e Risk Assessment )]TJ ET EMC /P <>BDC BT 18 0 0 18 36.9999 614.8942 Tm [(A Pr)19.5(actitioner)-7.8()54.7(s)0( Dilemma)]TJ ET EMC /Artifact <>BDC .72 .13 .67 .01 k 471.593 58.938 131.467 350.385 re f EMC /P <>BDC BT /F3 1 Tf 11 0 0 11 481.5229 395.202 Tm 0 0 0 0 k (Benoit )Tj ET EMC /P <>BDC BT 11 0 0 11 481.5229 383.202 Tm [(He)6.4(ynderickx,)]TJ ET EMC /P <>BDC BT /F1 1 Tf 11 0 0 11 543.1805 383.202 Tm ( )Tj ET EMC /P <>BDC BT 11 0 0 11 481.5229 371.202 Tm (CISA, CRISC )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 360.402 Tm 0 Tc (Is a principal )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 349.602 Tm [(r)9.3(esear)9.3(ch analyst at )]TJ ET EMC /P <>BDC BT 9 0 0 9 481.5229 338.802 Tm (the Information )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 328.002 Tm [(Security F)10.3(orum \(ISF\). )]TJ ET EMC /P <>BDC BT 9 0 0 9 481.5229 317.202 Tm [(He is the pr)9.8(oject lead )]TJ ET EMC /P <>BDC BT 9 0 0 9 481.5229 306.4019 Tm [(for the ISF)54.7(s Supply )]TJ ET EMC /P <>BDC BT 9 0 0 9 481.5229 295.602 Tm [(Chain suite of t)9.8(ools )]TJ ET EMC /P <>BDC BT 9 0 0 9 481.5229 284.802 Tm (and methodologies )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 274.002 Tm [(and a r)9.3(esear)9.3(ch lead )]TJ ET EMC /P <>BDC BT 9 0 0 9 481.5229 263.202 Tm (in cloud security )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 252.4019 Tm [(matters. He)6.4(ynderickx )]TJ ET EMC /P <>BDC BT 9 0 0 9 481.5229 241.6019 Tm (is an experienced )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 230.802 Tm (security risk and )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 220.002 Tm -.03 Tc [(assur)19.5(ance pr)9.8(of)11.7(essional)]TJ ET EMC /P <>BDC BT 9 0 0 9 568.7296 220.002 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 209.202 Tm [( who has work)9.8(ed)]TJ ET EMC /P <>BDC BT 9 0 0 9 548.8119 209.202 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 198.4019 Tm [(acr)9.8(oss v)7.3(arious)]TJ ET EMC /P <>BDC BT 9 0 0 9 539.8822 198.4019 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 187.6019 Tm (industries and)Tj ET EMC /P <>BDC BT 9 0 0 9 538.0936 187.6019 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 176.802 Tm [(or)9.3(ganizations prior t)9.8(o)]TJ ET EMC /P <>BDC BT 9 0 0 9 566.8295 176.802 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 166.002 Tm [(joining the ISF)114.3(. While)]TJ ET EMC /P <>BDC BT 9 0 0 9 563.683 166.002 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 155.202 Tm [(completing his r)9.3(ecent)]TJ ET EMC /P <>BDC BT 9 0 0 9 567.7479 155.202 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 144.4019 Tm (master of science in)Tj ET EMC /P <>BDC BT 9 0 0 9 562.5404 144.4019 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 133.6019 Tm (information security)Tj ET EMC /P <>BDC BT 9 0 0 9 561.7186 133.6019 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 122.8019 Tm [(and risk, He)6.4(ynderickx)]TJ ET EMC /P <>BDC BT 9 0 0 9 566.2714 122.8019 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 112.002 Tm [(also de)6.4(v)6.4(eloped a)]TJ ET EMC /P <>BDC BT 9 0 0 9 548.7943 112.002 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 101.202 Tm [(special inter)9.3(est in the)]TJ ET EMC /P <>BDC BT 9 0 0 9 566.6229 101.202 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 90.4019 Tm [(quantitativ)6.4(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 528.6146 90.4019 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 79.6019 Tm (techniques in risk)Tj ET EMC /P <>BDC BT 9 0 0 9 551.5717 79.6019 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 481.5229 68.8019 Tm (analysis.)Tj ET EMC /Artifact <>BDC 515.45 692.116 53.716 54.884 re f EMC /Figure <>BDC Q /GS3 gs BT /F6 1 Tf 9 0 0 9 515.4503 721.5889 Tm .72549 .12941 .67059 .007843 k .0249 Tc 0 Tw (FEATURE)Tj ET q 1 i 515.575 747 53.591 -54.759 re W n q 1 0 0 1 569.166 747 cm 0 0 m 0 -54.884 l -9.375 -54.884 l -9.375 -9.945 l -49.977 -9.945 l -49.977 0 l 0 0 l f Q EMC /Figure <>BDC Q q 1 i 37 145.454 426 -86.391 re W n 37 145.454 426 -86.516 re W n 37 145.454 423.001 -86.516 re W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .14118 .027451 .13333 0 k 37 59.063 423.02 71.641 re f Q q 1 i 37 145.454 426 -86.516 re W n 37 145.454 423.001 -86.516 re W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .74118 .19608 .007843 0 k 37 130.704 423.02 14.75 re f Q q 1 i 37 145.454 426 -86.391 re W n 37 145.454 426 -86.516 re W n 37 145.454 423.001 -86.516 re W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 2 w 10 M [] 0 d q 1 0 0 1 37 130.704 cm 0 0 m 426 0 l S Q Q q 1 i 37 145.454 426 -86.516 re W n 37 145.454 423.001 -86.516 re W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n BT /F7 1 Tf 9 0 0 9 115.3837 135.5523 Tm 0 0 0 0 k 0 Tc [(Figur)9.6(e).1( 1Model for P)7.2(e).5(r)-9.6(forming a Qualitativ)6.1(e Risk Assessment \(Method A\))]TJ ET .26275 .078431 .007843 0 k q 1 0 0 1 332.234 117.813 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.658 -45.958 l 0 -45.958 l 21.929 -22.979 l 0 0 l f Q 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d q 1 0 0 1 332.234 117.813 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.658 -45.958 l 0 -45.958 l 21.929 -22.979 l 0 0 l s Q .41961 .12157 .015686 0 k q 1 0 0 1 238.816 117.813 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.928 -22.979 l 0 0 l f Q q 1 0 0 1 238.816 117.813 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.928 -22.979 l 0 0 l s Q .56078 .16471 .019608 0 k q 1 0 0 1 145.698 117.813 cm 0 0 m 92.957 0 l 114.885 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.927 -22.979 l 0 0 l f Q q 1 0 0 1 145.698 117.813 cm 0 0 m 92.957 0 l 114.885 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.927 -22.979 l 0 0 l s Q .74118 .19608 .007843 0 k q 1 0 0 1 52.88 117.813 cm 0 0 m 92.957 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 0 0 l f Q q 1 0 0 1 52.88 117.813 cm 0 0 m 92.957 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 0 0 l s Q BT 13 0 0 13 75.0996 96.9337 Tm 0 0 0 1 k .0001 Tc (1Business)Tj -.7224 -1 TD -.0001 Tw (impact analysis)Tj 8.5672 1 TD -.0001 Tc 0 Tw [(2Contr)18.3(o).2(l)]TJ -.3443 -1 TD 0 Tc (assessment)Tj 8.1801 1 TD (3Risk)Tj -.1938 -1 TD .0001 Tc (analysis)Tj 6.9235 1 TD 0 Tc (4Action)Tj 1.031 -1 TD .0001 Tc (plan)Tj ET EMC Q endstream endobj 70 0 obj <>/ExtGState<>>> endobj 104 0 obj <> endobj 123 0 obj <> endobj 128 0 obj <> endobj 133 0 obj <> endobj 134 0 obj <> endobj 135 0 obj <>stream /P <>BDC q 1 i 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS2 gs BT /F1 1 Tf 7 0 0 7 414.6031 23.0228 Tm 0 0 0 1 k 0 Tc 0 Tw [( 2019 ISA)5.4(CA. All rights r)9.3(eser)-8.8(v)6.4(ed. )]TJ ET EMC /P <>BDC BT /F2 1 Tf 7 0 0 7 522.0879 23.0228 Tm [(www)60.6(.isaca.or)9.3(g)]TJ ET EMC /P <>BDC BT /F1 1 Tf 7 0 0 7 39.7789 24.9858 Tm [(ISA)5.4(CA )]TJ ET EMC /P <>BDC BT 7 0 0 7 61.2198 24.9858 Tm [(JOURN)-8.8(AL)]TJ ET EMC /P <>BDC /GS3 gs BT 7 0 0 7 92.1285 24.9858 Tm .73 .19 0 0 k [( V)6.4(OL 3)]TJ ET EMC /P <>BDC BT 7 0 0 7 13.2407 24.9858 Tm (2)Tj ET EMC /Artifact <>BDC 0 0 0 1 K 0 J 0 j .75 w 10 M [] 0 d /GS2 gs q 1 0 0 1 30.704 33.462 cm 0 0 m 0 -39.377 l S Q EMC /LBody <>BDC BT 9 0 0 9 155.0823 673.5671 Tm 0 0 0 1 k -.005 Tc [(the pr)9.3(e)6.4(vious step and r)19.5(ated on a nominal scale of)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 349.1467 673.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 155.0823 661.5671 Tm -.005 Tc [(1 t)9.8(o)0( 5 in terms of lik)9.8(elihood and business impact. )]TJ ET EMC /P <>BDC BT 9 0 0 9 154.9066 643.5671 Tm [(The lik)9.8(elihood was r)19.5(ated accor)9.3(ding t)9.8(o)0( the exper)-24.4(t)]TJ ET EMC /P <>BDC BT 9 0 0 9 344.1512 643.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 155.0823 631.5671 Tm -.005 Tc (judgment of the risk assessor and the system)Tj ET EMC /P <>BDC BT 9 0 0 9 334.9926 631.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 155.0823 619.5671 Tm -.02 Tc [(owner and based upon the contr)9.8(ol weaknesses.)]TJ ET EMC /P <>BDC BT 9 0 0 9 337.1521 619.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 155.0823 607.5671 Tm -.02 Tc [(Figur)9.3(e 2 )]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 188.6627 607.5671 Tm (shows an example of a highlighted risk. )Tj ET EMC /P <>BDC BT 9 0 0 9 155.0823 499.5671 Tm [(The risk r)19.5(ating was determined using a risk matrix)]TJ ET EMC /P <>BDC BT 9 0 0 9 344.6591 499.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 155.0823 487.5671 Tm -.02 Tc [(and, in this case, was r)19.5(ated as high. In t)9.8(otal, 11 risk)]TJ ET EMC /P <>BDC BT 9 0 0 9 346.6728 487.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 155.0823 475.5671 Tm -.02 Tc [(fact)9.8(ors identied wer)9.3(e r)19.5(ated low t)9.8(o)0( high.)]TJ ET EMC /P <>BDC BT 9 0 0 9 307.8093 475.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 155.0823 451.5671 Tm .04 1 .83 0 k -.005 Tc (Step 4: Action plan)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 230.7848 451.5671 Tm 0 0 0 1 k (The action plan was initially)Tj ET EMC /LBody <>BDC BT 9 0 0 9 346.6726 451.5671 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 144.0823 451.5671 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 155.0823 439.5671 Tm 0 0 0 1 k -.005 Tc [(de)6.4(v)6.4(eloped b)5.4(y)0( the risk assessor and subsequently)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 348.3534 439.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 155.0823 427.5671 Tm -.005 Tc [(agr)9.3(eed t)9.8(o)0( b)5.4(y)0( the system owner)60.1(. When it came)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 334.1017 427.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 155.0823 415.5671 Tm -.005 Tc [(time t)9.8(o)0( decide whether t)9.8(o)0( r)9.3(emediate risk 01 vs.)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 339.4808 415.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 155.0823 403.5671 Tm -.005 Tc [(risk 03, ther)9.3(e was a lack of meaningful data for)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 339.5765 403.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 155.0823 391.5671 Tm -.005 Tc (facilitating the analysis, especially when most of)Tj ET EMC /LBody <>BDC BT 9 0 0 9 345.5114 391.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 155.0823 379.5671 Tm -.005 Tc [(the risk fact)9.8(ors wer)9.3(e r)19.5(ated high. )]TJ ET EMC /P <>BDC BT 9 0 0 9 144.0823 361.5671 Tm [(When it comes t)9.8(o)0( a risk assessment of a specic)]TJ ET EMC /P <>BDC BT 9 0 0 9 337.2611 361.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 349.5671 Tm -.005 Tc [(critical I)14.2(T)19.5( system, the analysis is pur)9.3(ely qualitativ)6.4(e.)]TJ ET EMC /P <>BDC BT 9 0 0 9 342.5527 349.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 337.5671 Tm -.005 Tc [(While method A would appear r)9.3(elativ)6.4(ely simple t)9.8(o)]TJ ET EMC /P <>BDC BT 9 0 0 9 338.1962 337.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 325.5671 Tm -.005 Tc [(apply)52.3(, ther)9.3(e is little e)6.4(vidence of its benets and)]TJ ET EMC /P <>BDC BT 9 0 0 9 327.4275 325.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 313.5671 Tm -.005 Tc [(outcome o)7.3(v)6.4(er time. )]TJ ET EMC /P <>BDC /GS3 gs BT /F3 1 Tf 11 0 0 11 144.0823 287.567 Tm .72 .13 .67 .01 k [(Method B: Quantitativ)6.4(e Risk A)23.5(nalysis )]TJ ET EMC /P <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 144.0823 269.567 Tm 0 0 0 1 k [(The quantitativ)6.4(e method \(method B\) was applied t)9.8(o)]TJ ET EMC /P <>BDC BT 9 0 0 9 346.4832 269.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 257.567 Tm -.005 Tc [(the same system in scope t)9.8(o)0( be able t)9.8(o)0( compar)9.3(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 335.6011 257.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 245.567 Tm -.005 Tc [(with the output of the pr)9.3(e)6.4(viously used qualitativ)6.4(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 335.1047 245.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 233.567 Tm -.005 Tc [(method. )19.5(The quantitativ)6.4(e model was built following)]TJ ET EMC /P <>BDC BT 9 0 0 9 345.7306 233.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 221.567 Tm -.005 Tc [(some of the k)9.8(e)6.4(y concepts giv)6.4(en b)5.4(y)0( both Hubbar)9.3(d)]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 336.5679 224.267 Tm 0 Tc (5)Tj ET EMC /P <>BDC BT 9 0 0 9 339.5552 221.567 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 209.567 Tm -.005 Tc [(and the F)83(AIR methodology)52.3(,)]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 249.1472 212.267 Tm 0 Tc (6)Tj ET EMC /P <>BDC BT 9 0 0 9 252.1345 209.567 Tm -.005 Tc ( following a simple step-)Tj ET EMC /P <>BDC BT 9 0 0 9 144.0823 197.567 Tm [(b)5.4(y-step appr)9.8(oach as pr)9.3(esented in )]TJ ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 277.1497 197.567 Tm [(gur)9.3(e 3)]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 307.9525 197.567 Tm (. )Tj ET EMC /P <>BDC BT /F8 1 Tf 9 0 0 9 362.3144 673.5671 Tm [(Step 1: Loss E)12.7(v)6.4(ent )]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 362.3144 661.5671 Tm [(In method B, the loss e)6.4(v)6.4(ent was quantied b)5.4(y)]TJ ET EMC /P <>BDC BT 9 0 0 9 540.1023 661.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 649.5671 Tm -.005 Tc [(making use of two impor)-24.4(tant techniques in)]TJ ET EMC /P <>BDC BT 9 0 0 9 531.2679 649.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 637.5671 Tm -.005 Tc [(quantitativ)6.4(e risk: calibr)19.5(ation and decomposition.)]TJ ET EMC /P <>BDC BT 9 0 0 9 551.8481 637.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 625.5671 Tm -.005 Tc [(Calibr)19.5(ation begins with the absur)9.3(d scenario of, for)]TJ ET EMC /P <>BDC BT 9 0 0 9 558.196 625.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 613.5671 Tm -.005 Tc [(example, losing the maximum amount b)5.4(y)]TJ ET EMC /P <>BDC BT 9 0 0 9 524.6012 613.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 601.5671 Tm -.005 Tc [(experiencing a data br)9.3(each. )19.5(The analyst then r)9.3(enes)]TJ ET EMC /P <>BDC BT 9 0 0 9 567.3676 601.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 589.5671 Tm -.005 Tc [(the initial estimate t)9.8(o)0( obtain a mor)9.3(e r)9.3(ealistic r)19.5(ange,)]TJ ET EMC /P <>BDC BT 9 0 0 9 561.5197 589.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 577.5671 Tm -.005 Tc [(often called the 90 per)9.3(cent condence inter)-8.8(v)7.3(al.)]TJ ET EMC /P <>BDC BT 9 0 0 9 547.0601 577.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 565.5671 Tm -.005 Tc [(Decomposition is used t)9.8(o)0( r)9.3(ene the r)19.5(ange inter)-8.8(v)7.3(als.)]TJ ET EMC /P <>BDC BT 9 0 0 9 564.5287 565.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 553.5671 Tm -.005 Tc [(Some wide-r)19.5(ange estimates ar)9.3(e v)6.4(e)0(r)-8.8(y)0( often giv)6.4(en,)]TJ ET EMC /P <>BDC BT 9 0 0 9 553.2301 553.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 541.5671 Tm -.005 Tc [(such as a loss estimate of US$0 t)9.8(o)0( US$500 million.)]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 563.4486 544.267 Tm 0 Tc (7)Tj ET EMC /P <>BDC BT 9 0 0 9 566.4359 541.5671 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 529.5671 Tm -.005 Tc [(If such extr)9.3(eme losses wer)9.3(e of concern, mor)9.3(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 541.6711 529.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 517.5671 Tm -.005 Tc [(analysis would be r)9.3(equir)9.3(ed t)9.8(o)0( deriv)6.4(e diff)11.7(er)9.3(ent)]TJ ET EMC /P <>BDC BT 9 0 0 9 538.9446 517.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 505.5671 Tm -.005 Tc [(scenarios and diff)11.7(er)9.3(ent r)19.5(ange-of-loss estimates. )]TJ ET EMC /P <>BDC BT 9 0 0 9 362.3144 481.5671 Tm [(During the pilot analysis, the following loss e)6.4(v)6.4(ent)]TJ ET EMC /P <>BDC BT 9 0 0 9 553.9816 481.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 469.5671 Tm -.005 Tc [(statements wer)9.3(e obser)-8.8(v)6.4(ed: )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 373.3144 451.5671 Tm (The application manager estimated the loss at)Tj ET EMC /LBody <>BDC BT 9 0 0 9 556.6516 451.5671 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 362.3144 451.5671 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 373.3144 439.5671 Tm 0 0 0 1 k -.005 Tc [(US$1 per cust)9.8(omer r)9.3(ecor)9.3(d loss, r)9.3(epr)9.3(esenting a)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 555.698 439.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 373.3144 427.5671 Tm -.005 Tc [(maximum t)9.8(otal loss of US$60 million. )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 373.3144 409.5671 Tm [(The security ocer r)9.3(e)0(f)11.7(err)9.3(ed t)9.8(o)0( the intr)9.8(oduction of)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 567.0306 409.5671 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 362.3144 409.5671 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 373.3144 397.5671 Tm 0 0 0 1 k -.005 Tc [(the EU Gener)19.5(al Data Pr)9.8(otection Regulation)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 539.4731 397.5671 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 373.3144 385.5671 Tm -.005 Tc (\(GDPR\) with potential nes of US$3 billion. )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 367.5671 Tm [(This was a wide r)19.5(ange of estimates, fr)9.8(om US$60)]TJ ET EMC /P <>BDC BT 9 0 0 9 552.884 367.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 355.5671 Tm -.005 Tc [(million t)9.8(o)0( US$3 billion maximum loss, r)9.3(einfor)9.3(cing)]TJ ET EMC /P <>BDC BT 9 0 0 9 554.8936 355.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 343.5671 Tm -.005 Tc [(the need for fur)-24.4(ther calibr)19.5(ation and decomposition)]TJ ET EMC /P <>BDC BT 9 0 0 9 560.7943 343.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 331.5671 Tm -.005 Tc [(t)9.8(o)0( establish a mor)9.3(e r)9.3(ealistic r)19.5(ange inter)-8.8(v)7.3(al of loss)]TJ ET EMC /P <>BDC BT 9 0 0 9 555.9188 331.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 319.5671 Tm -.005 Tc [(e)6.4(v)6.4(ents, which was subsequently per)-7.3(formed as)]TJ ET EMC /P <>BDC BT 9 0 0 9 544.2386 319.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 307.567 Tm -.005 Tc (shown in )Tj ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 399.975 307.567 Tm [(gur)9.3(e 4)]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 430.7779 307.567 Tm (. )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 283.567 Tm [(The minimum br)9.3(each was set at 10,000 r)9.3(ecor)9.3(ds,)]TJ ET EMC /P <>BDC BT 9 0 0 9 551.8215 283.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 271.567 Tm -.005 Tc [(estimating that any smaller br)9.3(each would har)9.3(dly be)]TJ ET EMC /P <>BDC BT 9 0 0 9 563.1849 271.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 259.567 Tm -.005 Tc [(noticed b)5.4(y)0( the or)9.3(ganization; mor)9.3(eo)7.3(v)6.4(e)0(r)60.1(,)0( malicious)]TJ ET EMC /P <>BDC BT 9 0 0 9 552.6094 259.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 247.567 Tm -.005 Tc [(act)9.8(ors would not go thr)9.8(ough the tr)9.8(ouble of stealing)]TJ ET EMC /P <>BDC BT 9 0 0 9 561.9579 247.567 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 235.5671 Tm -.005 Tc [(less than 10,000 r)9.3(ecor)9.3(ds. )19.5(The most lik)9.8(ely v)7.3(alue of)]TJ ET EMC /P <>BDC BT 9 0 0 9 556.4701 235.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 223.5671 Tm -.005 Tc [(25,000 r)9.3(ecor)9.3(ds br)9.3(eached, as used in )]TJ ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 506.4353 223.5671 Tm [(gur)9.3(e 4)]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 537.2382 223.5671 Tm 0 Tc (,)Tj ET EMC /P <>BDC BT 9 0 0 9 538.9597 223.5671 Tm ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 211.5671 Tm -.005 Tc [(r)9.3(e)0(f)11.7(e)0(r)9.3(ences t)9.8(o)0( the 2018 )]TJ ET EMC /P <>BDC BT /F2 1 Tf 9 0 0 9 453.3893 211.5671 Tm [(Cost of Data Br)9.3(each Study:)]TJ ET EMC /P <>BDC BT 9 0 0 9 557.1831 211.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 362.3144 199.5671 Tm -.005 Tc (Global Analysis)Tj ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 421.9019 199.5671 Tm 0 Tc (.)Tj ET EMC /P <>BDC BT 5.4 0 0 5.4 424.2256 202.267 Tm -.0083 Tc (8 )Tj ET EMC /Figure <>BDC Q q 1 i 143.939 595.443 208.675 -74.875 re W n 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .73 .19 0 0 k /GS3 gs 143.939 579.943 205.441 15.5 re f .72 .13 .67 .01 k 143.814 579.943 94.3 -24.75 re 238.114 579.943 33 -24.75 re 271.114 579.943 45 -24.75 re 316.114 579.943 36 -24.75 re f .012 .3 .249 0 k 143.814 555.193 94.3 -34.75 re 238.114 555.193 33 -34.75 re 271.114 555.193 45 -34.75 re 316.114 555.193 36 -34.75 re f 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d q 1 0 0 1 238.114 520.443 cm 0 0 m 0 34.25 l S 1 0 0 1 33 0 cm 0 0 m 0 34.25 l S 1 0 0 1 45 0 cm 0 0 m 0 34.25 l S 1 0 0 1 36 0 cm 0 0 m 0 34.25 l S Q 2 w q 1 0 0 1 143.814 579.943 cm 0 0 m 94.3 0 l S Q Q q 1 i 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 2 w 10 M [] 0 d /GS3 gs q 1 0 0 1 238.114 579.943 cm 0 0 m 33 0 l S 1 0 0 1 33 0 cm 0 0 m 45 0 l S Q Q q 1 i 143.939 595.443 208.675 -74.875 re W n 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 2 w 10 M [] 0 d /GS3 gs q 1 0 0 1 316.114 579.943 cm 0 0 m 36.5 0 l S Q Q q 1 i 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 238.114 555.693 cm 0 0 m 0 23.25 l S 1 0 0 1 33 0 cm 0 0 m 0 23.25 l S 1 0 0 1 45 0 cm 0 0 m 0 23.25 l S Q Q q 1 i 143.939 595.443 208.675 -74.875 re W n 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 352.114 555.693 cm 0 0 m 0 23.25 l S 1 0 0 1 -208.3 -.5 cm 0 0 m 94.3 0 l S Q Q q 1 i 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 238.114 555.193 cm 0 0 m 33 0 l S 1 0 0 1 33 0 cm 0 0 m 45 0 l S Q Q q 1 i 143.939 595.443 208.675 -74.875 re W n 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 316.114 555.193 cm 0 0 m 36.5 0 l S Q Q q 1 i 143.814 595.443 208.8 -75 re W n 143.814 595.443 205.5 -75 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS3 gs BT /F7 1 Tf 10 0 0 10 154.2387 583.943 Tm 0 0 0 0 k -.0141 Tc .0221 Tw [(Figur)9.9(e 2Example of an Individual Risk A)23.2(n).3(alysis)]TJ 9 0 0 9 183.2773 559.193 Tm -.0097 Tc 0 Tw [(Risk)-4877.4(Impact)-956.1(Lik)10.2(e)1.4(lihood)]TJ 15.906 1.111 TD [(Risk)-9.7( )]TJ -.41 -1.111 TD (Rating)Tj ET /GS2 gs BT /F9 1 Tf 9 0 0 9 147.8173 544.442 Tm 0 0 0 1 k -.0094 Tc -.0007 Tw [(Unauthoriz)7.1(ed access)-9.2( )]TJ T* -.0096 Tc -.0005 Tw [(fr)9.2(om de)5.6(v)6.2(e)-.3(lopers int)8.8(o)-9.4( )]TJ T* -.0095 Tc .0005 Tw [(pr)9.5(oduction envir)9.5(o).3(nment)]TJ 11.62 2.222 TD 3.8393 Tc 0 Tw [(44)484(H)3852.6(i)3849.6(g)3847.3(h)]TJ ET EMC /Figure <>BDC Q q 1 i 141.814 175.924 426 -86.391 re W n 141.814 175.924 426 -86.516 re W n 141.814 175.924 426 -84.366 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .14118 .027451 .13333 0 k /GS3 gs 141.814 91.44 425.93 69.734 re f Q q 1 i 141.814 175.924 426 -86.516 re W n 141.814 175.924 426 -84.366 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .74118 .19608 .007843 0 k /GS3 gs 141.814 161.174 425.93 14.75 re f Q q 1 i 141.814 175.924 426 -86.391 re W n 141.814 175.924 426 -86.516 re W n 141.814 175.924 426 -84.366 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 2 w 10 M [] 0 d /GS3 gs q 1 0 0 1 141.814 161.174 cm 0 0 m 426 0 l S Q Q q 1 i 141.814 175.924 426 -86.516 re W n 141.814 175.924 426 -84.366 re 428.55 202.267 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS3 gs BT /F7 1 Tf 9 0 0 9 214.1733 166.0223 Tm 0 0 0 0 k 0 Tc 0 Tw [(Figur)9.6(e).1( 3A Model for P)6.4(e).5(r)-9.6(forming a Quantitativ)6.1(e).5( Risk Assessment \(Method B\))]TJ ET .26275 .078431 .007843 0 k q 1 0 0 1 437.048 148.283 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.658 -45.958 l 0 -45.958 l 21.929 -22.979 l 0 0 l f Q 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d q 1 0 0 1 437.048 148.283 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.658 -45.958 l 0 -45.958 l 21.929 -22.979 l 0 0 l s Q .41961 .12157 .015686 0 k q 1 0 0 1 343.63 148.283 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.928 -22.979 l 0 0 l f Q q 1 0 0 1 343.63 148.283 cm 0 0 m 92.958 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.928 -22.979 l 0 0 l s Q .56078 .16471 .019608 0 k q 1 0 0 1 250.512 148.283 cm 0 0 m 92.957 0 l 114.885 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.927 -22.979 l 0 0 l f Q q 1 0 0 1 250.512 148.283 cm 0 0 m 92.957 0 l 114.885 -22.528 l 92.657 -45.958 l 0 -45.958 l 21.927 -22.979 l 0 0 l s Q .74118 .19608 .007843 0 k q 1 0 0 1 157.694 148.283 cm 0 0 m 92.957 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 0 0 l f Q q 1 0 0 1 157.694 148.283 cm 0 0 m 92.957 0 l 114.886 -22.528 l 92.657 -45.958 l 0 -45.958 l 0 0 l s Q BT 13 0 0 13 191.3145 127.4037 Tm 0 0 0 1 k -.0001 Tc (1Loss)Tj .4287 -1 TD -.0067 Tc [(eve)-6(n)-6.8(t)]TJ 6.6975 1 TD 0 Tc [(2Thr)9.4(e)-.2(at)]TJ .1716 -1 TD .0001 Tc (scenario)Tj 6.2211 1 TD 0 Tc [(3Loss e)7(v)5.9(ent)]TJ .6311 -1 TD (simulation)Tj 7.3832 1 TD -.0001 Tc (4Action)Tj 1.031 -1 TD .0001 Tc (plan)Tj ET EMC Q endstream endobj 136 0 obj <>/ExtGState<>>> endobj 162 0 obj <> endobj 167 0 obj <> endobj 172 0 obj <> endobj 183 0 obj <> endobj 188 0 obj <> endobj 193 0 obj <> endobj 196 0 obj <> endobj 199 0 obj <> endobj 200 0 obj <>stream /P <>BDC q 1 i 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS2 gs BT /F1 1 Tf 7 0 0 7 36.9471 23.0228 Tm 0 0 0 1 k 0 Tc 0 Tw [( 2019 ISA)5.4(CA. All rights r)9.3(eser)-8.8(v)6.4(ed. )]TJ ET EMC /P <>BDC BT /F2 1 Tf 7 0 0 7 144.4321 23.0228 Tm [(www)60.6(.isaca.or)9.3(g)]TJ ET EMC /P <>BDC BT /F1 1 Tf 7 0 0 7 488.5055 23.0228 Tm [(ISA)5.4(CA )]TJ ET EMC /P <>BDC BT 7 0 0 7 509.9464 23.0228 Tm [(JOURN)-8.8(AL)]TJ ET EMC /P <>BDC /GS3 gs BT 7 0 0 7 540.8551 23.0228 Tm .73 .19 0 0 k [( V)6.4(OL 3)]TJ ET EMC /P <>BDC BT 7 0 0 7 584.9167 23.0228 Tm (3)Tj ET EMC /Artifact <>BDC 0 0 0 1 K 0 J 0 j .75 w 10 M [] 0 d /GS2 gs q 1 0 0 1 570.156 31.289 cm 0 0 m 0 -39.376 l S Q EMC /P <>BDC BT 9 0 0 9 36 673.5671 Tm 0 0 0 1 k -.005 Tc [(Meanwhile, the cost per r)9.3(ecor)9.3(d was deemed less)]TJ ET EMC /P <>BDC BT 9 0 0 9 228.0768 673.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 661.5671 Tm -.005 Tc [(signicant for the higher impact e)6.4(v)6.4(ent of a br)9.3(each)]TJ ET EMC /P <>BDC BT 9 0 0 9 231.8739 661.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 649.5671 Tm -.005 Tc [(of 60 million r)9.3(ecor)9.3(ds. )19.5(This could be explained b)5.4(y)0( the)]TJ ET EMC /P <>BDC BT 9 0 0 9 240.5105 649.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 637.5671 Tm -.005 Tc [(analysis of the numer)9.8(ous publiciz)7.8(ed data br)9.3(eaches.)]TJ ET EMC /P <>BDC BT 9 0 0 9 238.4657 637.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 625.5671 Tm -.005 Tc [(Indeed, ther)9.3(e has r)19.5(a)0(r)9.3(ely been a case of a)]TJ ET EMC /P <>BDC BT 9 0 0 9 194.2881 625.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 613.5671 Tm -.005 Tc [(megabr)9.3(each ex)9.8(ceeding US$210 million in t)9.8(otal)]TJ ET EMC /P <>BDC BT 9 0 0 9 219.0349 613.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 601.5671 Tm -.005 Tc [(costs. )19.5(This was, for instance, the case of the)]TJ ET EMC /P <>BDC BT 9 0 0 9 210.9732 601.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 589.5671 Tm -.005 Tc [(E)9.3(quifax br)9.3(each, in which up t)9.8(o)0( 145 million cust)9.8(omer)]TJ ET EMC /P <>BDC BT 9 0 0 9 239.014 589.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 577.5671 Tm -.005 Tc [(r)9.3(ecor)9.3(ds wer)9.3(e st)9.8(olen, which r)9.3(epor)-24.4(tedly cost the)]TJ ET EMC /P <>BDC BT 9 0 0 9 217.1872 577.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 565.5671 Tm -.005 Tc (company US$240 million.)Tj ET EMC /P <>BDC BT 5.4 0 0 5.4 136.8042 568.267 Tm 0 Tc (9)Tj ET EMC /P <>BDC BT 9 0 0 9 139.7914 565.5671 Tm -.005 Tc [( )19.5(Ther)9.3(efor)9.3(e, the maximum)]TJ ET EMC /P <>BDC BT 9 0 0 9 238.6754 565.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 553.5671 Tm -.005 Tc [(loss e)6.4(v)6.4(ent could still be r)9.3(egar)9.3(ded as a high estimate)]TJ ET EMC /P <>BDC BT 9 0 0 9 240.1282 553.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 541.5671 Tm -.005 Tc (of US$210 million. )Tj ET EMC /P <>BDC BT 9 0 0 9 36 517.5671 Tm [(Ov)6.4(er)19.5(all, the 90 per)9.3(cent condence inter)-8.8(v)7.3(al for )]TJ ET EMC /P <>BDC BT 9 0 0 9 36 505.5671 Tm [(the loss e)6.4(v)6.4(ent was estimated with the following)]TJ ET EMC /P <>BDC BT 9 0 0 9 223.0616 505.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 493.5671 Tm -.005 Tc [(r)19.5(ange v)7.3(alues: )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 47 475.5671 Tm [(Minimum: US$1.57 million for 10,000 r)9.3(ecor)9.3(ds )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 36 475.5671 Tm .04 1 .83 0 k 0 Tc ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 47 457.5671 Tm 0 0 0 1 k -.005 Tc [(Most lik)9.8(ely: US$3.18 million for 25,000 r)9.3(ecor)9.3(ds )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 36 457.5671 Tm .04 1 .83 0 k 0 Tc ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 47 439.5671 Tm 0 0 0 1 k -.005 Tc [(Maximum: US$210 million for 60 million r)9.3(ecor)9.3(ds )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 36 439.5671 Tm .04 1 .83 0 k 0 Tc ()Tj ET EMC /P <>BDC /GS2 gs BT /F8 1 Tf 9 0 0 9 36 415.5671 Tm 0 0 0 1 k -.005 Tc [(Step 2: )29.3(Thr)9.3(eat Scenario )]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 36 403.5671 Tm [(The use of detailed thr)9.3(eat scenarios was r)9.3(equir)9.3(ed t)9.8(o)]TJ ET EMC /P <>BDC BT 9 0 0 9 240.6257 403.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 36 391.5671 Tm -.005 Tc [(apply pr)9.8(obabilities t)9.8(o)0( the loss e)6.4(v)6.4(ent. As a)]TJ ET EMC /P <>BDC BT 9 0 0 9 197.0282 391.5671 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.1168 494.3106 Tm -.005 Tc [(pr)9.3(er)9.3(equisite t)9.8(o)0( this phase, a description of the)]TJ ET EMC /P <>BDC BT 9 0 0 9 435.1549 494.3106 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.1168 482.3106 Tm -.005 Tc (system in scope was needed, typically including: )Tj ET EMC /LBody <>BDC BT 9 0 0 9 266.1168 464.3106 Tm (Data ows )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 255.1168 464.3106 Tm .04 1 .83 0 k 0 Tc ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 266.1168 446.3106 Tm 0 0 0 1 k -.005 Tc [(Thr)9.3(eat act)9.8(ors \(internal, external, malicious\) )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 255.1168 446.3106 Tm .04 1 .83 0 k 0 Tc ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 266.1168 428.3106 Tm 0 0 0 1 k -.005 Tc [(Networking and data center envir)9.8(onment )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 255.1168 428.3106 Tm .04 1 .83 0 k 0 Tc ()Tj ET EMC /P <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 255.1168 410.3106 Tm 0 0 0 1 k -.005 Tc [(A simple data ow diagr)19.5(am \()]TJ ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 368.3755 410.3106 Tm [(gur)9.3(e 5)]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 399.1783 410.3106 Tm [(\) was cr)9.3(eated)]TJ ET EMC /P <>BDC BT 9 0 0 9 452.5979 410.3106 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 255.1168 398.3106 Tm -.005 Tc [(t)9.8(o)0( better determine the thr)9.3(eat scenarios. )]TJ ET EMC /Figure <>BDC Q q 1 i 255.117 680.317 349.502 -172.5 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS3 gs q 349.788 0 0 -174.047 254.372 681.092 cm /Im2 Do Q EMC /Figure <>BDC Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .73 .19 0 0 k /GS3 gs 35.22 358.214 421.443 15.5 re f Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .72 .13 .67 .01 k /GS3 gs 35.163 358.214 126.7 -14.75 re 161.863 358.214 49.9 -14.75 re 211.763 358.214 52.633 -14.75 re 264.396 358.214 57.767 -14.75 re 322.163 358.214 134.5 -14.75 re f .012 .3 .249 0 k 35.163 343.464 126.7 -24.75 re 161.863 343.464 49.9 -24.75 re 211.763 343.464 52.633 -24.75 re 264.396 343.464 57.767 -24.75 re 322.163 343.464 134.5 -24.75 re 35.163 293.964 126.7 -44.75 re 161.863 293.964 49.9 -44.75 re 211.763 293.964 52.633 -44.75 re 264.396 293.964 57.767 -44.75 re 322.163 293.964 134.5 -44.75 re 35.163 234.464 126.7 -14.75 re 161.863 234.464 49.9 -14.75 re 211.763 234.464 52.633 -14.75 re 264.396 234.464 57.767 -14.75 re 322.163 234.464 134.5 -14.75 re 35.163 204.964 126.7 -14.75 re 161.863 204.964 49.9 -14.75 re 211.763 204.964 52.633 -14.75 re 264.396 204.964 57.767 -14.75 re 322.163 204.964 134.5 -14.75 re 35.163 165.464 126.7 -24.75 re 161.863 165.464 49.9 -24.75 re 211.763 165.464 52.633 -24.75 re 264.396 165.464 57.767 -24.75 re 322.163 165.464 134.5 -24.75 re 35.163 115.964 126.7 -14.75 re 161.863 115.964 49.9 -14.75 re 211.763 115.964 52.633 -14.75 re 264.396 115.964 57.767 -14.75 re 322.163 115.964 134.5 -14.75 re f .182 .048 0 0 k 35.163 318.714 126.7 -24.75 re 161.863 318.714 49.9 -24.75 re 211.763 318.714 52.633 -24.75 re 264.396 318.714 57.767 -24.75 re 322.163 318.714 134.5 -24.75 re 35.163 249.214 126.7 -14.75 re 161.863 249.214 49.9 -14.75 re 211.763 249.214 52.633 -14.75 re 264.396 249.214 57.767 -14.75 re 322.163 249.214 134.5 -14.75 re 35.163 219.714 126.7 -14.75 re 161.863 219.714 49.9 -14.75 re 211.763 219.714 52.633 -14.75 re 264.396 219.714 57.767 -14.75 re 322.163 219.714 134.5 -14.75 re 35.163 190.214 126.7 -24.75 re 161.863 190.214 49.9 -24.75 re 211.763 190.214 52.633 -24.75 re 264.396 190.214 57.767 -24.75 re 322.163 190.214 134.5 -24.75 re 35.163 140.714 126.7 -24.75 re 161.863 140.714 49.9 -24.75 re 211.763 140.714 52.633 -24.75 re 264.396 140.714 57.767 -24.75 re 322.163 140.714 134.5 -24.75 re 35.163 101.214 126.7 -14.75 re 161.863 101.214 49.9 -14.75 re 211.763 101.214 52.633 -14.75 re 264.396 101.214 57.767 -14.75 re 322.163 101.214 134.5 -14.75 re f 0 0 0 0 K 0 J 0 j 2 w 10 M [] 0 d q 1 0 0 1 35.163 358.214 cm 0 0 m 229.233 0 l S 1 0 0 1 229.233 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 2 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 358.214 cm 0 0 m 135 0 l S Q 1 w q 1 0 0 1 456.663 343.964 cm 0 0 m 0 13.25 l S 1 0 0 1 -421.5 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -59.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -39.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 -.5 -.5 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 86.464 cm 0 0 m 294.8 0 l S 1 0 0 1 0 257.5 cm 0 0 m 0 13.25 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -59.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -39.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 49.9 257 cm 0 0 m 0 13.25 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -59.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -39.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 52.633 207.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -59.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -39.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 57.767 257 cm 0 0 m 0 13.25 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -59.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 0 -39.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -49.5 cm 0 0 m 0 23.75 l S 1 0 0 1 0 -29.5 cm 0 0 m 0 13.75 l S 1 0 0 1 -287 256.5 cm 0 0 m 229.233 0 l S 1 0 0 1 126.7 -24.25 cm 0 0 m 0 23.75 l S 1 0 0 1 49.9 0 cm 0 0 m 0 23.75 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 34.663 318.714 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 318.714 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 24.75 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 343.464 cm 0 0 m 135 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 319.214 cm 0 0 m 0 23.75 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 456.663 319.214 cm 0 0 m 0 23.75 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 264.396 318.714 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 318.714 cm 0 0 m 135 0 l S 1 0 0 1 -287.5 -24.75 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 293.964 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 293.964 cm 0 0 m 135 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 249.714 cm 0 0 m 0 43.75 l S 1 0 0 1 49.9 0 cm 0 0 m 0 43.75 l S 1 0 0 1 52.633 0 cm 0 0 m 0 43.75 l S 1 0 0 1 57.767 0 cm 0 0 m 0 43.75 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 456.663 249.714 cm 0 0 m 0 43.75 l S 1 0 0 1 -422 -.5 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 249.214 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 249.214 cm 0 0 m 135 0 l S 1 0 0 1 -287.5 -14.75 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 234.464 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 234.464 cm 0 0 m 135 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 220.214 cm 0 0 m 0 13.75 l S 1 0 0 1 49.9 0 cm 0 0 m 0 13.75 l S 1 0 0 1 52.633 0 cm 0 0 m 0 13.75 l S 1 0 0 1 57.767 0 cm 0 0 m 0 13.75 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 456.663 220.214 cm 0 0 m 0 13.75 l S 1 0 0 1 -422 -.5 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 219.714 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 219.714 cm 0 0 m 135 0 l S 1 0 0 1 -287.5 -14.75 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 204.964 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 204.964 cm 0 0 m 135 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 190.714 cm 0 0 m 0 13.75 l S 1 0 0 1 49.9 0 cm 0 0 m 0 13.75 l S 1 0 0 1 52.633 0 cm 0 0 m 0 13.75 l S 1 0 0 1 57.767 0 cm 0 0 m 0 13.75 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 456.663 190.714 cm 0 0 m 0 13.75 l S 1 0 0 1 -422 -.5 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 190.214 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 190.214 cm 0 0 m 135 0 l S 1 0 0 1 -287.5 -24.75 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 165.464 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 165.464 cm 0 0 m 135 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 141.214 cm 0 0 m 0 23.75 l S 1 0 0 1 49.9 0 cm 0 0 m 0 23.75 l S 1 0 0 1 52.633 0 cm 0 0 m 0 23.75 l S 1 0 0 1 57.767 0 cm 0 0 m 0 23.75 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 456.663 141.214 cm 0 0 m 0 23.75 l S 1 0 0 1 -422 -.5 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 140.714 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 140.714 cm 0 0 m 135 0 l S 1 0 0 1 -287.5 -24.75 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 115.964 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 115.964 cm 0 0 m 135 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 101.714 cm 0 0 m 0 13.75 l S 1 0 0 1 49.9 0 cm 0 0 m 0 13.75 l S 1 0 0 1 52.633 0 cm 0 0 m 0 13.75 l S 1 0 0 1 57.767 0 cm 0 0 m 0 13.75 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 456.663 101.714 cm 0 0 m 0 13.75 l S 1 0 0 1 -422 -.5 cm 0 0 m 127.2 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 161.863 101.214 cm 0 0 m 102.533 0 l S 1 0 0 1 102.533 0 cm 0 0 m 57.767 0 l S Q Q q 1 i 457.163 373.714 -422.5 -287.75 re 34.663 373.714 m W n 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 322.163 101.214 cm 0 0 m 135 0 l S Q Q q 1 i 34.663 373.714 422.5 -287.75 re W n 35.233 374.854 423.767 -287.75 re 416.019 398.311 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d /GS3 gs q 1 0 0 1 264.396 343.964 cm 0 0 m 0 13.25 l S 1 0 0 1 0 -24.75 cm 0 0 m 0 23.75 l S Q BT /F7 1 Tf 10 0 0 10 131.3912 362.2143 Tm 0 0 0 0 k -.015 Tc .022 Tw [(Figur)9.7(e 4Estimates for the Loss E)12.5(v)6(ent for the CRM System)]TJ 9 0 0 9 170.2982 347.4643 Tm -.0097 Tc -.0003 Tw [(Minimum)-1606.2(Most Lik)10.4(e)1.2(ly)-1954.9(Maximum)-6654.9(Comments)]TJ ET /GS2 gs BT /F9 1 Tf 9 0 0 9 39.1686 332.7133 Tm 0 0 0 1 k -.0005 Tw [(Number of cust)8.8(omer r)9.2(e)-.4(cor)9.2(ds)-9.5( )]TJ 0 -1.111 TD -.0095 Tc 0 Tw [(br)9.3(eached)]TJ 14.0781 1.111 TD [(10,000)-2934.4(25,000)-3238.3(60,000,000)]TJ -14.0781 -2.75 TD .0005 Tw [(Primar)-8.6(y)-.4( r)9.4(esponse)-7333.8($8,250)-9.1( )-2706($10,250)-9.1( )-2525.3($22,000)-9.1( )-3096.3(Minimum 50h Maximum 400h *)-8.8( )25.7( )]TJ 31.889 -1.111 TD [(US$55/h a)8.1(v)6.2(er)19.3(age cost per emplo)7.7(y)6.7(ee)]TJ -31.889 -1.639 TD .0004 Tw [(Primar)-8.5(y)-.3( r)9.5(e)-.1(placement)-6091.5($30,000)-9( )-2221.4($30,000)-9( )-2525.3($50,000)-9( )-3096.3(Cost of terminated emplo)7.9(y)6.9(ee\(s\))-10.2( )]TJ 31.889 -1.111 TD .0005 Tw [(for insider br)9.6(each; cost of hiring/)]TJ T* .0004 Tw [(tr)19.6(aining new r)9.7(e).2(sour)9.8(ces for external)-9.8( )]TJ T* 0 Tw [(br)9.4(each)]TJ -31.889 -1.639 TD -.0096 Tc -.0005 Tw [(Primar)-8.7(y)-.5( cost \(1\))-7884.9($38,250)-2449.9($40,250)-9.2( )-2525.8($72,000)-9.2( )]TJ T* -.0095 Tc .0005 Tw [(Notification t)9(o)-.1( cust)9(omers)-4259($10,000)-9.1( )-2221($25,000)-9.1( )-2525($60,000,000)-9.1( )-1455.8(US$1 per cust)9.1(omer)]TJ T* [(Cust)8.9(omer suppor)-23.7(t)-7134.1($10,000)-9.2( )-2221($10,000)-9.2( )-2525($60,000,000)-9.2( )-1455.8(US$1 per cust)9(omer)]TJ T* -.0006 Tw [(Cr)9.4(edit monit)9(oringInsur)19.4(a)-.5(nce)-2962.6($10,000)-9.1( )-2221.4($10,000)-9.1( )-2525.4($60,000,000)-9.1( )-1456.2(US$1 per cust)9.1(omer)]TJ T* .0004 Tw [(System downtime)-7210.8($400,000)-1965.1($1,000,000)-1598.2($1,000,000)-2169.1(Cost of halting the system for)-9.6( )]TJ 31.889 -1.111 TD .0005 Tw [(for)9.5(e)-.1(nsic purposes)]TJ -31.889 -1.639 TD .0004 Tw [(Legal)-9.8( )-11753.1($1,000,000)-8.9( )-1065.3($2,500,000)-8.9( )-1369.3($20,000,000)-8.9( )-1455.7(Estimated costs of E)9.9(q).7(uifax br)9.6(each:)-9.5( )]TJ 31.889 -1.111 TD [(US$240M \(t)9.3(otal\))]TJ -31.889 -1.639 TD [(Public r)9.6(e)0(lations)-8114.1($100,000)-8.9( )-1736($200,000)-8.9( )-2040($20,000,000)-8.9( )-1455.5(Estimated costs of E)9.7(q).7(uifax br)9.6(each:)-9.5( )]TJ 31.889 -1.111 TD [(US$240M \(t)9.2(otal\))-10.2( )]TJ -31.889 -1.639 TD -.0006 Tw [(Secondar)-8.5(y)-.3( cost \(2\))-10.2( )-6580.8($1,530,000)-9( )-1065.7($3,775,000)-9( )-1369.7($210,000,000)-9( )]TJ T* [(Gr)19.4(and t)9(otal \(1\) + \(2\))-10.3( )-6258.3($1,568,250)-1294.3($3,815,250)-9.1( )-1369.8($210,072,000)-9.1( )-971.4(Range estimate)-10.1( )]TJ ET EMC Q endstream endobj 201 0 obj <>/XObject<>/ExtGState<>>> endobj 225 0 obj <> endobj 230 0 obj <> endobj 235 0 obj <> endobj 252 0 obj <> endobj 257 0 obj <> endobj 262 0 obj <> endobj 267 0 obj <> endobj 268 0 obj <>stream /P <>BDC q 1 i 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS2 gs BT /F1 1 Tf 7 0 0 7 414.6031 23.0228 Tm 0 0 0 1 k 0 Tc 0 Tw [( 2019 ISA)5.4(CA. All rights r)9.3(eser)-8.8(v)6.4(ed. )]TJ ET EMC /P <>BDC BT /F2 1 Tf 7 0 0 7 522.0879 23.0228 Tm [(www)60.6(.isaca.or)9.3(g)]TJ ET EMC /P <>BDC BT /F1 1 Tf 7 0 0 7 39.7789 24.9858 Tm [(ISA)5.4(CA )]TJ ET EMC /P <>BDC BT 7 0 0 7 61.2198 24.9858 Tm [(JOURN)-8.8(AL)]TJ ET EMC /P <>BDC /GS3 gs BT 7 0 0 7 92.1285 24.9858 Tm .73 .19 0 0 k [( V)6.4(OL 3)]TJ ET EMC /P <>BDC BT 7 0 0 7 13.2407 24.9858 Tm (4)Tj ET EMC /Artifact <>BDC 0 0 0 1 K 0 J 0 j .75 w 10 M [] 0 d /GS2 gs q 1 0 0 1 30.704 33.462 cm 0 0 m 0 -39.377 l S Q EMC /P <>BDC BT 9 0 0 9 142.0529 424.1248 Tm 0 0 0 1 k -.005 Tc (In this case, the system in scope was not)Tj ET EMC /P <>BDC BT 9 0 0 9 303.5401 424.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 412.1248 Tm -.005 Tc [(accessible t)9.8(o)0( the public, and the internal thr)9.3(eat was)]TJ ET EMC /P <>BDC BT 9 0 0 9 343.9134 412.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 400.1248 Tm -.005 Tc [(deemed most signicant. Howe)6.4(v)6.4(e)0(r)60.1(,)0( external thr)9.3(eats)]TJ ET EMC /P <>BDC BT 9 0 0 9 344.3175 400.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 388.1248 Tm -.005 Tc [(wer)9.3(e not dismissed because cust)9.8(omer data ar)9.3(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 329.0648 388.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 376.1248 Tm -.005 Tc [(alwa)7.3(ys an attr)19.5(activ)6.4(e tar)9.3(get t)9.8(o)0( any malicious act)9.8(ors)]TJ ET EMC /P <>BDC BT 9 0 0 9 339.9518 376.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 364.1248 Tm -.005 Tc [(outside of the or)9.3(ganization and o)7.3(v)6.4(er)19.5(all, ther)9.3(e ar)9.3(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 334.9243 364.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 352.1248 Tm -.005 Tc [(mor)9.3(e [malicious] folks out ther)9.3(e.)83()]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 271.6475 354.8248 Tm -.0083 Tc (10 )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 328.1248 Tm -.005 Tc [(In t)9.8(otal, four thr)9.3(eat scenarios wer)9.3(e identied and)]TJ ET EMC /P <>BDC BT 9 0 0 9 332.438 328.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 316.1248 Tm -.005 Tc (documented as follows: )Tj ET EMC /LBody <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 153.0529 298.1248 Tm .04 1 .83 0 k (Scenarios 1 and 2)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 224.6177 298.1248 Tm 0 0 0 1 k (Internal users access the)Tj ET EMC /LBody <>BDC BT 9 0 0 9 330.4594 298.1248 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 142.0529 298.1248 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 153.0529 286.1248 Tm 0 0 0 1 k -.005 Tc [(sensitiv)6.4(e PII and extr)19.5(act the data for r)9.3(esell and)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 335.3795 286.1248 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 153.0529 274.1248 Tm -.005 Tc (misuse, applicable for privileged user \(scenario)Tj ET EMC /LBody <>BDC BT 9 0 0 9 338.6588 274.1248 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 153.0529 262.1248 Tm -.005 Tc [(1\) or gener)19.5(al user \(scenario 2\). )]TJ ET EMC /LBody <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 153.0529 244.1248 Tm .04 1 .83 0 k (Scenario 3)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 195.7222 244.1248 Tm 0 0 0 1 k [(Thir)9.3(d-par)-24.4(ty user extr)19.5(acts the data via)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 347.1259 244.1248 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 142.0529 244.1248 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 153.0529 232.1248 Tm 0 0 0 1 k -.005 Tc [(scr)9.3(eenshots for sharing with competit)9.8(ors. )]TJ ET EMC /LBody <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 153.0529 214.1248 Tm .04 1 .83 0 k (Scenario 4)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 195.7222 214.1248 Tm 0 0 0 1 k [(Hack)9.8(ers access data for nancial)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 334.3882 214.1248 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 142.0529 214.1248 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 153.0529 202.1248 Tm 0 0 0 1 k -.005 Tc (gain, ideology or espionage. )Tj ET EMC /P <>BDC BT /F8 1 Tf 9 0 0 9 142.0529 178.1248 Tm [(Step 3: Loss E)12.7(v)6.4(ent Simulation )]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 142.0529 166.1248 Tm [(Each of the afor)9.3(ementioned thr)9.3(eat scenarios wer)9.3(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 339.1417 166.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 154.1248 Tm -.005 Tc [(then assigned a pr)9.8(obability of occurring based upon)]TJ ET EMC /P <>BDC BT 9 0 0 9 346.5873 154.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 142.1248 Tm -.005 Tc [(external r)9.3(esear)9.3(ch material. F)10.3(or instance, the 2018)]TJ ET EMC /P <>BDC BT 9 0 0 9 336.8105 142.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT /F2 1 Tf 9 0 0 9 142.0529 130.1248 Tm -.005 Tc [(Cost of Data Br)9.3(each Study: Global Analysis)]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 307.5952 130.1248 Tm [( ga)7.3(v)6.4(e)0( an)]TJ ET EMC /P <>BDC BT 9 0 0 9 340.5019 130.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 118.1248 Tm -.005 Tc [(estimated 28 per)9.3(cent of pr)9.8(obability of any type of)]TJ ET EMC /P <>BDC BT 9 0 0 9 335.791 118.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 106.1248 Tm -.005 Tc [(data br)9.3(each t)9.8(o)0( occur in the coming two y)6.4(ears for)]TJ ET EMC /P <>BDC BT 9 0 0 9 333.0773 106.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 94.1248 Tm -.005 Tc [(any or)9.3(ganization.)]TJ ET EMC /P <>BDC BT 5.4 0 0 5.4 209.7725 96.8248 Tm -.0083 Tc (11)Tj ET EMC /P <>BDC BT 9 0 0 9 215.747 94.1248 Tm -.005 Tc [( )19.5(The four thr)9.3(eat scenarios wer)9.3(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 338.3839 94.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.0529 82.1248 Tm -.005 Tc [(deemed as r)9.3(epr)9.3(esentativ)6.4(e of all possible scenarios)]TJ ET EMC /P <>BDC BT 9 0 0 9 342.1191 82.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 424.1248 Tm -.005 Tc [(that would lead t)9.8(o)0( the e)6.4(v)6.4(ent of a data br)9.3(each, and)]TJ ET EMC /P <>BDC BT 9 0 0 9 553.6997 424.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 412.1248 Tm -.005 Tc [(the)6.4(y wer)9.3(e tr)9.3(eated as independent of one another)60.1(. )]TJ ET EMC /P <>BDC BT 9 0 0 9 359.5529 382.1248 Tm [(Based upon this information, it was then possible t)9.8(o)]TJ ET EMC /P <>BDC BT 9 0 0 9 563.7655 382.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 370.1248 Tm -.005 Tc [(deriv)6.4(e the thr)9.3(eat scenarios as giv)6.4(en in )]TJ ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 510.5602 370.1248 Tm [(gur)9.3(e 6)]TJ ET EMC /P <>BDC BT 9 0 0 9 541.363 370.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 359.5529 358.1248 Tm -.005 Tc [(intr)9.8(oducing pr)9.8(obabilities. )]TJ ET EMC /P <>BDC BT 9 0 0 9 359.5529 334.1248 Tm [(F)10.3(or the risk analysis that follows, expected v)7.3(alue)]TJ ET EMC /P <>BDC BT 9 0 0 9 550.0259 334.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 322.1248 Tm -.005 Tc [(r)9.3(e)0(f)11.7(ers t)9.8(o)0( the pr)9.8(obability-weighted a)7.3(v)6.4(er)19.5(age of all)]TJ ET EMC /P <>BDC BT 9 0 0 9 544.446 322.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 310.1248 Tm -.005 Tc [(possible v)7.3(alues, and geometric mean indicates the)]TJ ET EMC /P <>BDC BT 9 0 0 9 558.8467 310.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 298.1248 Tm -.005 Tc [(centr)19.5(al tendency or typical v)7.3(alue of a set of)]TJ ET EMC /P <>BDC BT 9 0 0 9 528.4012 298.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 286.1248 Tm -.005 Tc (numbers.)Tj ET EMC /P <>BDC BT 5.4 0 0 5.4 396.8806 288.8248 Tm -.0083 Tc (12 )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 262.1248 Tm -.005 Tc [(The outcome of the loss e)6.4(v)6.4(ent simulation could)]TJ ET EMC /P <>BDC BT 9 0 0 9 546.9583 262.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 250.1248 Tm -.005 Tc [(r)9.3(ead as follows: )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 370.5529 232.1248 Tm [(Ther)9.3(e is a 28 per)9.3(cent pr)9.8(obability that a loss e)6.4(v)6.4(ent)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 563.9252 232.1248 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 359.5529 232.1248 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 370.5529 220.1248 Tm 0 0 0 1 k -.005 Tc [(would occur within the next two y)6.4(ears impacting)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 560.761 220.1248 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 370.5529 208.1248 Tm -.005 Tc [(the CRM system with a r)19.5(ange of US$1.5 million)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 555.384 208.1248 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 370.5529 196.1248 Tm -.005 Tc [(t)9.8(o)0( US$210 million. )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 370.5529 178.1248 Tm [(The a)7.3(v)6.4(er)19.5(age loss e)6.4(v)6.4(ent o)7.3(v)6.4(er the next two y)6.4(ears)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 554.5394 178.1248 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 359.5529 178.1248 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 370.5529 166.1248 Tm 0 0 0 1 k -.005 Tc (could be estimated at US$51.09 million. )Tj ET EMC /LBody <>BDC BT 9 0 0 9 370.5529 148.1248 Tm [(The most lik)9.8(ely v)7.3(alue or geometric mean was)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 548.5483 148.1248 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 359.5529 148.1248 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 370.5529 136.1248 Tm 0 0 0 1 k -.005 Tc (estimated at US$4.05 million. )Tj ET EMC /P <>BDC BT /F8 1 Tf 9 0 0 9 359.5529 112.1248 Tm (Step 4: Action Plan )Tj ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 359.5529 100.1248 Tm [(One pr)9.8(oposed action inv)7.3(olv)6.4(ed the str)9.3(engthening of)]TJ ET EMC /P <>BDC BT 9 0 0 9 558.2579 100.1248 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 359.5529 88.1248 Tm -.005 Tc [(contr)9.8(ols r)9.3(elating t)9.8(o)0( sensitiv)6.4(e user access. If)]TJ ET EMC /P <>BDC BT 9 0 0 9 530.5667 88.1248 Tm 0 Tc ( )Tj ET EMC /Figure <>BDC Q q 1 i 139.053 710.625 426 -264.875 re W n 139.053 710.625 426 -265 re W n 142 710.625 423.053 -264.889 re 532.795 88.125 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .14118 .027451 .13333 0 k /GS3 gs 141.9 445.75 423.083 250.125 re f Q q 1 i 139.053 710.625 426 -265 re W n 142 710.625 423.053 -264.889 re 532.795 88.125 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .74118 .19608 .007843 0 k /GS3 gs 141.9 695.875 423.083 14.75 re f Q q 1 i 139.053 710.625 426 -264.875 re W n 139.053 710.625 426 -265 re W n 142 710.625 423.053 -264.889 re 532.795 88.125 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 0 0 0 0 K 0 J 0 j 2 w 10 M [] 0 d /GS3 gs q 1 0 0 1 139.053 695.875 cm 0 0 m 426 0 l S Q Q q 1 i 139.053 710.625 426 -265 re W n 142 710.625 423.053 -264.889 re 532.795 88.125 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS3 gs BT /F7 1 Tf 9 0 0 9 304.1229 700.7229 Tm 0 0 0 0 k -.0001 Tc .0001 Tw [(Figur)9.4(e)0( 5CRM Data Flows)]TJ ET 0 0 0 .25 k 280.053 506.958 251 182.051 re f 0 0 0 .5 k 289.386 520.958 129.722 100.367 re f .34902 .10196 .019608 0 k q 1 0 0 1 258.303 550.125 cm 0 0 m -51.785 0 l -56.734 0 -60.785 4.05 -60.785 9 c -60.785 87.25 l -60.785 92.2 -56.734 96.25 -51.785 96.25 c 0 96.25 l 4.95 96.25 9 92.2 9 87.25 c 9 9 l 9 4.05 4.95 0 0 0 c f Q 0 0 0 1 k q 1 0 0 1 330.486 678.768 cm 0 0 m 0 -3.965 -3.215 -7.18 -7.181 -7.18 c -11.146 -7.18 -14.361 -3.965 -14.361 0 c -14.361 3.965 -11.146 7.18 -7.181 7.18 c -3.215 7.18 0 3.965 0 0 c f Q q 1 0 0 1 332.154 658.605 cm 0 0 m .18 7.067 l -2.04 11.747 -9.223 11.764 v -9.223 11.76 l -16.403 11.925 -18.741 7.303 y -18.741 .234 l 0 0 l f Q q 1 0 0 1 343.412 673.063 cm 0 0 m 0 -3.965 -3.214 -7.18 -7.18 -7.18 c -11.146 -7.18 -14.36 -3.965 -14.36 0 c -14.36 3.966 -11.146 7.18 -7.18 7.18 c -3.214 7.18 0 3.966 0 0 c f Q q 1 0 0 1 345.081 652.9 cm 0 0 m .18 7.067 l -2.041 11.747 -9.223 11.764 v -9.223 11.76 l -16.403 11.925 -18.741 7.303 y -18.741 .234 l 0 0 l f Q q 1 0 0 1 459.346 614.904 cm 0 0 m 0 -4.474 -3.626 -8.1 -8.101 -8.1 c -12.574 -8.1 -16.201 -4.474 -16.201 0 c -16.201 4.474 -12.574 8.1 -8.101 8.1 c -3.626 8.1 0 4.474 0 0 c f Q q 1 0 0 1 461.229 592.157 cm 0 0 m .202 7.973 l -2.302 13.252 -10.405 13.272 v -10.405 13.267 l -18.505 13.453 -21.143 8.239 y -21.143 .264 l 0 0 l f Q q 1 0 0 1 473.929 608.468 cm 0 0 m 0 -4.473 -3.626 -8.1 -8.1 -8.1 c -12.574 -8.1 -16.2 -4.473 -16.2 0 c -16.2 4.474 -12.574 8.1 -8.1 8.1 c -3.626 8.1 0 4.474 0 0 c f Q q 1 0 0 1 475.812 585.722 cm 0 0 m .202 7.972 l -2.302 13.252 -10.405 13.271 v -10.405 13.266 l -18.505 13.453 -21.143 8.238 y -21.143 .263 l 0 0 l f Q .027451 .98039 .8 .003922 K 0 J 0 j 1 w 10 M [] 0 d q 1 0 0 1 411.97 586.104 cm 0 0 m 36.958 0 l S Q .027451 .98039 .8 .003922 k q 1 0 0 1 447.761 582.114 cm 0 0 m 6.908 3.99 l 0 7.979 l 0 0 l f Q q 1 0 0 1 440.086 597.402 cm 0 0 m -20.97 0 l S Q q 1 0 0 1 420.283 601.392 cm 0 0 m -6.907 -3.99 l 0 -7.978 l 0 0 l f Q q 1 0 0 1 330.151 636.769 cm 0 0 m 0 -19.146 l S Q q 1 0 0 1 326.161 618.79 cm 0 0 m 3.99 -6.908 l 7.979 0 l 0 0 l f Q q 1 0 0 1 341.449 605.381 cm 0 0 m 0 26.147 l S Q q 1 0 0 1 345.439 630.36 cm 0 0 m -3.99 6.908 l -7.978 0 l 0 0 l f Q q 1 0 0 1 304.549 576.882 cm 0 0 m -107.047 0 l S Q q 1 0 0 1 198.669 580.871 cm 0 0 m -6.908 -3.989 l 0 -7.978 l 0 0 l f Q q 1 0 0 1 186.447 599.912 cm 0 0 m 112.361 0 l S Q q 1 0 0 1 297.64 595.923 cm 0 0 m 6.909 3.989 l 0 7.978 l 0 0 l f Q .74118 .19608 .007843 0 k q 1 0 0 1 360.32 565.098 cm 0 0 m -8.904 -8.815 l -55.108 -8.815 l -55.108 46.204 l -.601 46.204 l 0 0 l f Q 0 0 0 0 K q 1 0 0 1 360.32 565.098 cm 0 0 m -8.904 -8.815 l -55.108 -8.815 l -55.108 46.204 l -.601 46.204 l 0 0 l h S 1 0 0 1 -8.267 -8.815 cm 0 0 m 0 8.694 l 8.267 8.694 l S Q q 1 0 0 1 411.97 564.001 cm 0 0 m 0 -2.923 -8.27 -5.294 -18.47 -5.294 c -28.67 -5.294 -36.94 -2.923 -36.94 0 c -36.94 42.803 l 0 42.803 l 0 0 l f Q q 1 0 0 1 411.97 564.001 cm 0 0 m 0 -2.923 -8.27 -5.294 -18.47 -5.294 c -28.67 -5.294 -36.94 -2.923 -36.94 0 c -36.94 42.803 l 0 42.803 l 0 0 l s Q .38431 .11373 .023529 0 k q 1 0 0 1 411.97 606.792 cm 0 0 m 0 -2.762 -8.27 -5 -18.47 -5 c -28.67 -5 -36.94 -2.762 -36.94 0 c -36.94 2.761 -28.67 5 -18.47 5 c -8.27 5 0 2.761 0 0 c f Q .985 w q 1 0 0 1 411.97 606.792 cm 0 0 m 0 -2.762 -8.27 -5 -18.47 -5 c -28.67 -5 -36.94 -2.762 -36.94 0 c -36.94 2.761 -28.67 5 -18.47 5 c -8.27 5 0 2.761 0 0 c s Q 0 0 0 0 k q 1 0 0 1 197.518 613.947 cm 0 0 m 0 -4.973 -3.503 -9.005 -7.824 -9.005 c -12.146 -9.005 -15.648 -4.973 -15.648 0 c -15.648 4.973 -12.146 9.005 -7.824 9.005 c -3.503 9.005 0 4.973 0 0 c f Q .027451 .98039 .8 .003922 K 1 w q 1 0 0 1 197.518 613.947 cm 0 0 m 0 -4.973 -3.503 -9.005 -7.824 -9.005 c -12.146 -9.005 -15.648 -4.973 -15.648 0 c -15.648 4.973 -12.146 9.005 -7.824 9.005 c -3.503 9.005 0 4.973 0 0 c s Q q 1 0 0 1 209.624 588.397 cm 0 0 m 0 -4.973 -3.503 -9.005 -7.824 -9.005 c -12.146 -9.005 -15.648 -4.973 -15.648 0 c -15.648 4.974 -12.146 9.005 -7.824 9.005 c -3.503 9.005 0 4.974 0 0 c f Q q 1 0 0 1 209.624 588.397 cm 0 0 m 0 -4.973 -3.503 -9.005 -7.824 -9.005 c -12.146 -9.005 -15.648 -4.973 -15.648 0 c -15.648 4.974 -12.146 9.005 -7.824 9.005 c -3.503 9.005 0 4.974 0 0 c s Q 0 0 0 1 k q 1 0 0 1 174.477 602.214 cm 0 0 m 0 -4.473 -3.626 -8.1 -8.1 -8.1 c -12.574 -8.1 -16.2 -4.473 -16.2 0 c -16.2 4.474 -12.574 8.1 -8.1 8.1 c -3.626 8.1 0 4.474 0 0 c f Q q 1 0 0 1 176.36 579.468 cm 0 0 m .203 7.972 l -2.302 13.252 -10.404 13.271 v -10.404 13.266 l -18.505 13.453 -21.143 8.239 y -21.143 .263 l 0 0 l f Q q 1 0 0 1 189.06 595.779 cm 0 0 m 0 -4.474 -3.627 -8.1 -8.101 -8.1 c -12.574 -8.1 -16.201 -4.474 -16.201 0 c -16.201 4.473 -12.574 8.1 -8.101 8.1 c -3.627 8.1 0 4.473 0 0 c f Q q 1 0 0 1 190.943 573.032 cm 0 0 m .203 7.973 l -2.302 13.252 -10.404 13.272 v -10.404 13.267 l -18.504 13.453 -21.143 8.239 y -21.143 .264 l 0 0 l f Q BT 9 0 0 9 310.9809 644.7908 Tm [(I)14.3(T)13.1(Corp Emplo)7.7(y)6.2(ees)]TJ 13.5902 -8.4202 TD .0002 Tc .0009 Tw [(I)14.7(T)29.1( Admin Users)]TJ 0 0 0 0 k -.9042 -6.3098 TD .0001 Tc .001 Tw [(I)14.6(T)29( Corp. internal network)]TJ -4.5984 7.3227 TD .0002 Tc 0 Tw (CRM)Tj -6.6327 .7552 TD -.0146 Tc [(We)-14.6(b)]TJ -1.4198 -1 TD -.0001 Tc [(A)23.4(pplication)]TJ 1.1684 -1 TD .0005 Tc [(\(A)24.2(pp\))]TJ 11 0 0 11 311.2949 542.1098 Tm .0002 Tc -.0002 Tw [(Cust)14.1(omer Database)]TJ .946 -1 TD [(\(60M Recor)11.3(d)-.2(s\))]TJ 9 0 0 9 145.9211 556.2828 Tm 0 0 0 1 k .0001 Tc 0 Tw [(Thir)9(d-P)5.6(a)0(r)-24.2(t).4(y)-7.2()]TJ 1.2824 -1 TD -.0001 Tc (Agents)Tj 5.4436 9.6663 TD .0001 Tc -.0001 Tw [(Vir)-24.2(t).4(ual Priv)7.1(ate)]TJ .0176 -1 TD 0 Tc 0 Tw [(Network\()-9.2(VPN\))]TJ -.5053 -1.6628 TD .0001 Tc (Queries)Tj 8 0 0 8 150.4255 486.0118 Tm 0 Tc [(1Queries cust)14.5(omer data r)10.5(e).2(cor)10(d)-.2(s \(PII r)9.3(e).2(cor)10.1(d)-.3(s\))]TJ 0 -1 TD [(2View/download fr)19.4(om CRM DB cust)12.4(omer r)10.2(e).2(cor)10.1(d)-.3(s \(r)8.6(estrictions apply t)13.4(o).5( number of r)9.4(e).2(cor)10.1(d)-.3(s\))]TJ 0 -2 TD .0001 Tc -.0001 Tw [(The CRM web app is not publicly accessible thr)17.1(ough the Internet, only appr)17.1(o)8.4(v)6.5(ed connections)]TJ ET 0 0 0 1 K .391 w q 1 0 0 1 217 461.426 cm 0 0 m 37.375 0 l s Q BT 9 0 0 9 187.4176 610.3138 Tm 0 Tc 0 Tw (1)Tj 1.3451 -2.69 TD [(2)-1221.3(V).2(iew/Downloads)]TJ ET EMC Q endstream endobj 269 0 obj <>/ExtGState<>>> endobj 293 0 obj <> endobj 298 0 obj <> endobj 303 0 obj <> endobj 308 0 obj <> endobj 315 0 obj <> endobj 316 0 obj <> endobj 317 0 obj <>stream /P <>BDC q 1 i 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS2 gs BT /F1 1 Tf 7 0 0 7 36.9471 23.0228 Tm 0 0 0 1 k 0 Tc 0 Tw [( 2019 ISA)5.4(CA. All rights r)9.3(eser)-8.8(v)6.4(ed. )]TJ ET EMC /P <>BDC BT /F2 1 Tf 7 0 0 7 144.4321 23.0228 Tm [(www)60.6(.isaca.or)9.3(g)]TJ ET EMC /P <>BDC BT /F1 1 Tf 7 0 0 7 488.5055 23.0228 Tm [(ISA)5.4(CA )]TJ ET EMC /P <>BDC BT 7 0 0 7 509.9464 23.0228 Tm [(JOURN)-8.8(AL)]TJ ET EMC /P <>BDC /GS3 gs BT 7 0 0 7 540.8551 23.0228 Tm .73 .19 0 0 k [( V)6.4(OL 3)]TJ ET EMC /P <>BDC BT 7 0 0 7 584.9167 23.0228 Tm (5)Tj ET EMC /Artifact <>BDC 0 0 0 1 K 0 J 0 j .75 w 10 M [] 0 d /GS2 gs q 1 0 0 1 570.156 31.289 cm 0 0 m 0 -39.376 l S Q EMC /P <>BDC BT 9 0 0 9 35 415.7111 Tm 0 0 0 1 k -.005 Tc [(str)9.8(onger contr)9.8(ols wer)9.3(e implemented, this would)]TJ ET EMC /P <>BDC BT 9 0 0 9 222.5811 415.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 403.7111 Tm -.005 Tc [(r)9.3(educe the r)19.5(ange inter)-8.8(v)7.3(al for one of the thr)9.3(eat)]TJ ET EMC /P <>BDC BT 9 0 0 9 213.0792 403.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 391.7111 Tm -.005 Tc (scenarios \(scenario 1: privileged users\). )Tj ET EMC /P <>BDC BT /F3 1 Tf 9 0 0 9 35 379.7111 Tm [(Figur)9.3(e 7 )]TJ ET EMC /P <>BDC BT /F1 1 Tf 9 0 0 9 69.7953 379.7111 Tm [(shows how the a)7.3(v)6.4(er)19.5(age loss e)6.4(v)6.4(ent o)7.3(v)6.4(er the)]TJ ET EMC /P <>BDC BT 9 0 0 9 238.8149 379.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 367.7111 Tm -.005 Tc [(next two y)6.4(ears could be r)9.3(educed fr)9.8(om US$51.09)]TJ ET EMC /P <>BDC BT 9 0 0 9 224.2126 367.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 355.7111 Tm -.005 Tc [(million t)9.8(o)0( US$13.86 million. )19.5(This would r)9.3(epr)9.3(esent )]TJ ET EMC /P <>BDC BT 9 0 0 9 35 343.7111 Tm [(a signicant r)9.3(eduction in the le)6.4(v)6.4(el of risk b)5.4(y)]TJ ET EMC /P <>BDC BT 9 0 0 9 204.7834 343.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 331.7111 Tm -.005 Tc [(impr)9.8(o)7.3(ving a small number of I)14.2(T)19.5( contr)9.8(ols with limited)]TJ ET EMC /P <>BDC BT 9 0 0 9 240.0609 331.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 319.7111 Tm -.005 Tc (additional costs. )Tj ET EMC /P <>BDC BT 9 0 0 9 35 301.7111 Tm [(In summar)-8.8(y)52.3(,)0( the pr)9.8(oposition for impr)9.8(o)7.3(ving the)]TJ ET EMC /P <>BDC BT 9 0 0 9 214.4173 301.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 289.7111 Tm -.005 Tc [(contr)9.8(ol envir)9.8(onment for sensitiv)6.4(e users would be)]TJ ET EMC /P <>BDC BT 9 0 0 9 226.8155 289.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 277.7111 Tm -.005 Tc [(cost ecient because it inv)7.3(olv)6.4(es simple measur)9.3(es,)]TJ ET EMC /P <>BDC BT 9 0 0 9 235.0015 277.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 35 265.7111 Tm -.005 Tc (such as: )Tj ET EMC /LBody <>BDC BT 9 0 0 9 46 247.7111 Tm [(Tightening of user access, r)9.3(e)6.4(v)7.3(alidating)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 197.7379 247.7111 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 35 247.7111 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 46 235.7111 Tm 0 0 0 1 k -.005 Tc [(justication for sensitiv)6.4(e user access )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 46 217.7111 Tm [(Securing computing envir)9.8(onment with lock)9.8(down)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 236.0179 217.7111 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 35 217.7111 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 46 205.7111 Tm 0 0 0 1 k -.005 Tc [(of univ)6.4(ersal serial bus \(USB\) por)-24.4(ts and r)9.3(estricted)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 236.9037 205.7111 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 46 193.7111 Tm -.005 Tc [(Internet access for sensitiv)6.4(e users )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 264.5 415.7111 Tm [(Incr)9.3(eased monit)9.8(oring \(e.g., security e)6.4(v)6.4(ent)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 426.7509 415.7111 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 253.5 415.7111 Tm .04 1 .83 0 k ()Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 264.5 403.7111 Tm 0 0 0 1 k -.005 Tc [(monit)9.8(oring\) of I)14.2(T)19.5( contr)9.8(ols for sensitiv)6.4(e users )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 264.5 385.7111 Tm [(Regular r)9.3(ecer)-24.4(tication pr)9.8(ogr)19.5(am )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F4 1 Tf 12 0 0 12 253.5 385.7111 Tm .04 1 .83 0 k 0 Tc ()Tj ET EMC /P <>BDC BT /F3 1 Tf 11 0 0 11 253.5 359.7111 Tm .72 .13 .67 .01 k -.005 Tc (Comparing the Outcome of the)Tj ET EMC /P <>BDC BT 11 0 0 11 404.0056 359.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 11 0 0 11 253.5 345.7111 Tm -.005 Tc [(Qualitativ)6.4(e and Quantitativ)6.4(e Methods )]TJ ET EMC /P <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 253.5 327.7111 Tm 0 0 0 1 k [(The quantitativ)6.4(e method inv)7.3(olv)6.4(ed a lar)9.3(ger effor)-24.4(t t)9.8(o)]TJ ET EMC /P <>BDC BT 9 0 0 9 450.7968 327.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 315.7111 Tm -.005 Tc (gather the input data such as the system data)Tj ET EMC /P <>BDC BT 9 0 0 9 433.9411 315.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 303.7111 Tm -.005 Tc [(ows, incidents and r)9.3(eliable sour)9.3(ces of information)]TJ ET EMC /P <>BDC BT 9 0 0 9 454.888 303.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 291.7111 Tm -.005 Tc [(for past data br)9.3(eaches. Meanwhile, the richness of)]TJ ET EMC /P <>BDC BT 9 0 0 9 452.5467 291.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 279.7111 Tm -.005 Tc [(information giv)6.4(en in the quantitativ)6.4(e method ga)7.3(v)6.4(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 449.0103 279.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 267.7111 Tm -.005 Tc [(mor)9.3(e informed and meaningful information for the)]TJ ET EMC /P <>BDC BT 9 0 0 9 451.9951 267.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 255.7111 Tm -.005 Tc [(decision mak)9.8(ers, as opposed t)9.8(o)0( the qualitativ)6.4(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 436.3439 255.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 243.7111 Tm -.005 Tc [(method, which r)9.3(elied on intuition and judgments)]TJ ET EMC /P <>BDC BT 9 0 0 9 442.7281 243.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 231.7111 Tm -.005 Tc [(pr)9.8(o)7.3(vided b)5.4(y)0( the stak)9.8(eholders. )]TJ ET EMC /P <>BDC BT 9 0 0 9 253.5 207.7111 Tm (The decomposition and in-depth analysis of the)Tj ET EMC /P <>BDC BT 9 0 0 9 440.6461 207.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 195.7111 Tm -.005 Tc [(loss e)6.4(v)6.4(ent was well underst)9.8(ood b)5.4(y)0( all stak)9.8(eholders)]TJ ET EMC /P <>BDC BT 9 0 0 9 453.0259 195.7111 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 253.5 183.7111 Tm -.005 Tc [(at the end of the r)9.3(e)6.4(view)60.6(. In fact, it ga)7.3(v)6.4(e)0( a signicant)]TJ ET EMC /P <>BDC BT 9 0 0 9 454.6773 183.7111 Tm 0 Tc ( )Tj ET EMC /Figure <>BDC Q .73 .19 0 0 k /GS3 gs 36.553 695.125 423 15.5 re f .72 .13 .67 .01 k 1 i 36.553 695.125 84.6 -54.75 re 121.153 695.125 84.6 -54.75 re 205.753 695.125 84.6 -54.75 re 290.353 695.125 84.6 -54.75 re 374.953 695.125 84.6 -54.75 re f .012 .3 .249 0 k 36.553 640.375 84.6 -44.75 re 121.153 640.375 84.6 -44.75 re 205.753 640.375 84.6 -44.75 re 290.353 640.375 84.6 -44.75 re 374.953 640.375 84.6 -44.75 re 36.553 550.875 84.6 -54.75 re 121.153 550.875 84.6 -54.75 re 205.753 550.875 84.6 -54.75 re 290.353 550.875 84.6 -54.75 re 374.953 550.875 84.6 -54.75 re f .182 .048 0 0 k 36.553 595.625 84.6 -44.75 re 121.153 595.625 84.6 -44.75 re 205.753 595.625 84.6 -44.75 re 290.353 595.625 84.6 -44.75 re 374.953 595.625 84.6 -44.75 re 36.553 496.125 84.6 -64.75 re 121.153 496.125 84.6 -64.75 re 205.753 496.125 84.6 -64.75 re 290.353 496.125 84.6 -64.75 re 374.953 496.125 84.6 -64.75 re f 0 0 0 0 K 0 J 0 j 1 w 10 M [] 0 d q 1 0 0 1 36.553 640.375 cm 0 0 m 253.8 0 l S 1 0 0 1 253.8 0 cm 0 0 m 84.6 0 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 374.953 640.375 cm 0 0 m 85.1 0 l S 1 0 0 1 84.6 -44.25 cm 0 0 m 0 43.75 l S 1 0 0 1 -423 -44.75 cm 0 0 m 0 43.75 l S Q Q q 1 0 0 1 121.153 551.375 cm 0 0 m 0 43.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 43.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 43.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 43.75 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 459.553 551.375 cm 0 0 m 0 43.75 l S 1 0 0 1 -423 -119.5 cm 0 0 m 0 63.75 l S Q Q q 1 0 0 1 121.153 431.875 cm 0 0 m 0 63.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 63.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 63.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 63.75 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 459.553 431.875 cm 0 0 m 0 63.75 l S 1 0 0 1 -423.5 -.5 cm 0 0 m 85.1 0 l S Q Q q 1 0 0 1 121.153 431.375 cm 0 0 m 169.2 0 l S 1 0 0 1 169.2 0 cm 0 0 m 84.6 0 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 374.953 431.375 cm 0 0 m 85.1 0 l S 1 0 0 1 -338.9 164.25 cm 0 0 m 85.1 0 l S Q Q q 1 0 0 1 121.153 595.625 cm 0 0 m 169.2 0 l S 1 0 0 1 169.2 0 cm 0 0 m 84.6 0 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 374.953 595.625 cm 0 0 m 85.1 0 l S 1 0 0 1 -338.9 -44.75 cm 0 0 m 85.1 0 l S Q Q q 1 0 0 1 121.153 550.875 cm 0 0 m 169.2 0 l S 1 0 0 1 169.2 0 cm 0 0 m 84.6 0 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 374.953 550.875 cm 0 0 m 85.1 0 l S Q Q q 1 0 0 1 121.153 496.625 cm 0 0 m 0 53.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 53.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 53.75 l S 1 0 0 1 84.6 0 cm 0 0 m 0 53.75 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 459.553 496.625 cm 0 0 m 0 53.75 l S 1 0 0 1 -423.5 -.5 cm 0 0 m 85.1 0 l S Q Q q 1 0 0 1 121.153 496.125 cm 0 0 m 169.2 0 l S 1 0 0 1 169.2 0 cm 0 0 m 84.6 0 l S Q q 460.053 710.625 -424 -279.75 re 36.053 710.625 m W n 36.053 710.625 424 -279.75 re W n q 1 0 0 1 374.953 496.125 cm 0 0 m 85.1 0 l S Q Q 2 w q 1 0 0 1 36.553 695.125 cm 0 0 m 338.4 0 l S 1 0 0 1 338.4 0 cm 0 0 m 84.6 0 l S Q 1 w q 1 0 0 1 121.153 640.875 cm 0 0 m 0 53.25 l S 1 0 0 1 0 -44.75 cm 0 0 m 0 43.75 l S 1 0 0 1 84.6 44.75 cm 0 0 m 0 53.25 l S 1 0 0 1 0 -44.75 cm 0 0 m 0 43.75 l S 1 0 0 1 84.6 44.75 cm 0 0 m 0 53.25 l S 1 0 0 1 0 -44.75 cm 0 0 m 0 43.75 l S 1 0 0 1 84.6 44.75 cm 0 0 m 0 53.25 l S 1 0 0 1 0 -44.75 cm 0 0 m 0 43.75 l S Q BT /F7 1 Tf 10 0 0 10 139.2028 699.1248 Tm 0 0 0 0 k -.015 Tc .022 Tw [(Figur)9.8(e 6Thr)9.7(eat Scenario and Loss E)12.5(v)6.1(ent Quantification)]TJ 9 0 0 9 54.7462 644.3748 Tm -.0098 Tc -.0002 Tw [(Thr)9.7(e)1.1(at Act)13.6(o).1(rs)-10( )-3160.5(Thr)9.7(e)1.2(at Scenarios)-10( )]TJ 17.847 4.444 TD -.0001 Tw [(Impact-Loss E)12.3(v)6.1(ent)-9.6( )]TJ -.072 -1.111 TD -.0096 Tc -.0004 Tw [(Low-High Estimate)-9.6( )]TJ 1.5761 -1.111 TD [(90 P)7(e)1.3(r)10.2(c)-.2(ent)-10.1( )]TJ -.1011 -1.111 TD 0 Tw (Confidence)Tj .736 -1.111 TD -.01 Tc [(Inter)-8.5(v)7(al)]TJ 7.221 2.222 TD -.0093 Tc .0004 Tw [(Pr)18.4(obability of Loss)-9.3( )]TJ 1.103 -1.111 TD -.0099 Tc -.0001 Tw [(E)12.4(v)6.1(ent in Next)-6.1( )]TJ .544 -1.111 TD -.0096 Tc .0007 Tw [(T)22.5(w)-.3(o Y)31.2(e)1.3(ars)-5275.4(C).5(omments)]TJ ET /GS2 gs BT /F9 1 Tf 9 0 0 9 40.5441 629.6238 Tm 0 0 0 1 k -.0094 Tc -.0007 Tw [(1. I)15.1(T)20.5( sensitiv)6.5(e users)-1749.1(E)-.2(xtr)19.5(a)-.4(ct data for)-9.5( )]TJ 9.4 -1.111 TD .0004 Tw [(malicious use ont)9.4(o)-8.9( )]TJ T* -.0096 Tc -.0005 Tw [(memor)-8.8(y driv)6.1(e)]TJ 9.4 2.222 TD .0006 Tw (US$3.8M $210M)Tj 0 -1.111 TD [(\(25,000 60M)-10.1( )]TJ T* 0 Tw [(r)9.5(e)0(cor)9.6(ds\))]TJ 9.4001 2.222 TD -.0093 Tc .0003 Tw [(Medium lik)9.3(elihood)]TJ 0 -1.111 TD -.0095 Tc .0005 Tw [(10 per)9.4(c)-.1(ent minimum)-9.7( )]TJ 9.4 1.111 TD -.0092 Tc .0002 Tw [(Dir)9.9(e)-.1(ct access t)9.7(o).4( PII;)-8.5( )]TJ 0 -1.111 TD -.0008 Tw [(external consultants)-9( )]TJ T* -.0094 Tc .0004 Tw [(working as database)-10.1( )]TJ T* -.0307 Tw [(administr)19.4(a)-.4(t)9.3(o).4(rs \(DBAs\))]TJ -37.6001 -1.639 TD .0005 Tw [(2. Gener)19.3(a)1(l users)-3168.1(G).4(ener)19.4(al user)-9.7( )]TJ 9.4 -1.111 TD .0003 Tw [(manages t)9.4(o).1( obtain)-9( )]TJ T* -.0006 Tw [(unauthoriz)7.1(ed higher)-9.5( )]TJ T* 0 Tw [(privileges)-9.1( )]TJ 9.4 3.333 TD -.0096 Tc .0006 Tw (US$1.5M $3.8M)Tj 0 -1.111 TD [(\(10,000 25,000)-9.2( )]TJ T* 0 Tw [(r)9.5(e)0(cor)9.6(ds\))-10.2( )]TJ 9.4001 2.222 TD -.0093 Tc .0003 Tw [(Low lik)9.5(elihood)]TJ 0 -1.111 TD -.0095 Tc .0005 Tw [(5 per)9.4(c)-.1(ent minimum)]TJ 9.4 1.111 TD -.0092 Tc .0002 Tw [(Little ability t)9.4(o)-8.9( )]TJ 0 -1.111 TD -.0094 Tc .0004 Tw [(download mor)9.6(e than)-9( )]TJ T* -.0097 Tc .0007 Tw [(25,000 r)9.3(e)-.2(cor)9.5(ds)-9.2( )]TJ -37.6001 -2.75 TD [(3. )20(Thir)9.2(d par)-23.8(t)-.2(ies)-3588.3(L).1(imited access, view)-9.1( )]TJ 9.4 -1.111 TD -.0095 Tc -.0006 Tw [(only t)9(o)-.2( PII. P)6.4(ossibility)-9.3( )]TJ T* -.0096 Tc -.0005 Tw [(t)9(o)-.1( tak)10.2(e)-.2( scr)9.4(e)-.1(enshots)-9.3( )]TJ T* [(with camer)19.5(a).1( phone or)-9.5( )]TJ T* -.0092 Tc 0 Tw [(similar)-9.1( )]TJ 9.4 4.444 TD -.0096 Tc .0006 Tw (US$1.5M $3.8M)Tj 0 -1.111 TD [(\(10,000 25,000)-9.2( )]TJ T* 0 Tw [(r)9.5(e)0(cor)9.6(ds\))]TJ 9.4001 2.222 TD -.0093 Tc .0003 Tw [(Medium lik)9.3(elihood)]TJ 0 -1.111 TD -.0095 Tc .0005 Tw [(10 per)9.4(c)-.1(ent minimum)]TJ 9.4 1.111 TD .0004 Tw [(Dir)9.6(e)-.3(ct access t)9.4(o).1( DB)-9.8( )]TJ 0 -1.111 TD -.0093 Tc [(with r)9.5(estricted views)-9( )]TJ -37.6001 -4.972 TD -.0098 Tc -.0003 Tw [(4. )218.6(External users,)-10.6( )]TJ .956 -1.111 TD -.0096 Tc 0 Tw [(hack)10(ers,)-10.2( )]TJ T* -.0093 Tc [(cyber)9.6(c).1(riminals)]TJ 8.444 2.222 TD -.0096 Tc .0006 Tw [(System intrusion at)-10.2( )]TJ 0 -1.111 TD -.0093 Tc .0003 Tw [(or)9.9(ganization)40.2()54.8(s internal)-9.5( )]TJ T* -.0095 Tc .0005 Tw [(network or thir)9.4(d par)-23.6(t)-.1(y;)-8.9( )]TJ T* -.0093 Tc -.0008 Tw [(later)19.8(al mo)8.1(v)6.7(e).1(ments)-9( )]TJ T* .0003 Tw [(t)9.4(o).3( gain access t)9.4(o)-8.8( )]TJ T* 0 Tw [(cr)9.7(edentials)]TJ 9.4 5.556 TD -.0096 Tc .0006 Tw (US$3.8M $210M)Tj 0 -1.111 TD (\(25,000 60M )Tj 0 -1.2 TD 0 Tw [(r)9.5(e)0(cor)9.6(ds\))]TJ 9.4001 2.311 TD -.0093 Tc .0003 Tw [(Low lik)9.5(elihood)]TJ 0 -1.111 TD -.0095 Tc .0005 Tw [(3 per)9.4(c)-.1(ent)]TJ 9.4 1.111 TD .0004 Tw [(Hack)10.3(er will mostly be)-10( )]TJ 0 -1.111 TD -.0093 Tc -.0008 Tw [(inter)9.7(e)-.2(sted in lar)9.6(ger)-9.4( )]TJ T* .0004 Tw [(amounts of data)-9.9( )]TJ ET EMC /Figure <>BDC q 34.053 167.375 426 -95 re W n 34.053 167.375 424.947 -95 re 456.905 183.711 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .73 .19 0 0 k /GS3 gs 34.053 151.875 425.007 15.5 re f .72 .13 .67 .01 k 34.053 117.125 201 34.75 re f .04 1 .83 0 k 259.053 117.125 200.007 34.75 re f Q q 34.053 167.375 426 -94.875 re W n 34.053 167.375 426 -95 re W n 34.053 167.375 424.947 -95 re 456.905 183.711 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n .216 .039 .201 .003 k /GS3 gs 34.053 72.5 201 44.625 re f .012 .3 .249 0 k 259.053 72.5 200.007 44.625 re f 2 w q 1 0 0 1 34.053 151.875 cm 0 0 m 201 0 l S Q Q q 34.053 167.375 426 -95 re W n 34.053 167.375 424.947 -95 re 456.905 183.711 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 2 w /GS3 gs q 1 0 0 1 235.053 151.875 cm 0 0 m 24 0 l S Q Q q 34.053 167.375 426 -94.875 re W n 34.053 167.375 426 -95 re W n 34.053 167.375 424.947 -95 re 456.905 183.711 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n 2 w /GS3 gs q 1 0 0 1 259.053 151.875 cm 0 0 m 201 0 l S Q Q q 34.053 167.375 426 -95 re W n 34.053 167.375 424.947 -95 re 456.905 183.711 m W* n 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS3 gs BT /F7 1 Tf 10 0 0 10 107.7589 155.8751 Tm 0 0 0 0 k -.015 Tc .023 Tw [(Figur)9.9(e 7A)24.2(v)6.2(e)0(r)14.9(age Cost of Data Br)9.9(each for CRM System and Action Plan)]TJ 9 0 0 9 38.0528 141.1251 Tm -.0098 Tc -.0291 Tw [(Ov)6.4(er)14.7(all Thr)9.7(eat )-30(Le)7.1(v)6.4(e)1.1(l)]TJ T* -.0001 Tw [(WI)14.9(TH CURREN)14(T)29.2( LEVEL OF CON)14(T)-.2(ROLS)]TJ T* .0008 Tw [(Pr)17.8(obability28 per)9.8(c)-.5(ent o)8.1(v)6.4(er the next two y)5.5(e)1(ars)]TJ 25 2.222 TD -.0281 Tw [(Ov)6.4(er)14.7(all Thr)9.7(e)0(at )-29.8(Le)7(v)6.3(e)1.2(l)]TJ 0 -1.111 TD -.0003 Tw [(WI)14.9(TH A)9.7(C)14.3(TION PL)-8.9(ANADDED CON)14.2(T)-.8(ROLS)]TJ T* [(Pr)18(obability28 per)9.8(c)-.4(ent o)8.2(v)6.5(er the next two y)5.6(e)1.1(ars)]TJ ET /GS2 gs BT /F9 1 Tf 9 0 0 9 56.0528 106.3761 Tm 0 0 0 1 k -.0096 Tc .0006 Tw [(Minimum US$1.568 M \(Loss e)6.7(v)7.3(ent\))]TJ T* -.0098 Tc -.0003 Tw (Maximum US$210 M)Tj /F7 1 Tf T* [(A)23.7(v)6.6(er)14.9(age US$51.09 M)]TJ T* -.0096 Tc [(Most lik)10.4(ely US$4.05 M)]TJ /F9 1 Tf 25 3.333 TD -.0095 Tc .0005 Tw [(Minimum US$1.568 M \(Loss e)5.7(v)6.5(ent\))]TJ 0 -1.111 TD -.0097 Tc .0007 Tw (Maximum US$210 M)Tj /F7 1 Tf T* -.0003 Tw [(A)23.8(v)6.6(er)14.9(age US$13.86 M)]TJ T* -.0095 Tc -.0005 Tw [(Most lik)9.4(ely US$1.46 M)]TJ ET 0 0 0 .6 K 16 w 4 M /GS3 gs q 1 0 0 1 223.053 93.595 cm 0 0 m 35.001 0 l S Q 0 0 0 .6 k q 1 0 0 1 270.453 93.595 cm 0 0 m -19.985 18.58 l -19.985 -18.58 l 0 0 l f Q EMC Q endstream endobj 318 0 obj <>/ExtGState<>>> endobj 350 0 obj <> endobj 355 0 obj <> endobj 360 0 obj <> endobj 365 0 obj <> endobj 370 0 obj <> endobj 375 0 obj <> endobj 380 0 obj <> endobj 385 0 obj <> endobj 390 0 obj <> endobj 395 0 obj <> endobj 400 0 obj <> endobj 405 0 obj <> endobj 410 0 obj <> endobj 415 0 obj <> endobj 416 0 obj <> endobj 417 0 obj <>stream /P <>BDC q 1 i 0 783 603 -783 re 301.5 391.56 m W n .059998 783 603 -783 re W n /GS2 gs BT /F1 1 Tf 7 0 0 7 414.6031 23.0228 Tm 0 0 0 1 k 0 Tc 0 Tw [( 2019 ISA)5.4(CA. All rights r)9.3(eser)-8.8(v)6.4(ed. )]TJ ET EMC /P <>BDC BT /F2 1 Tf 7 0 0 7 522.0879 23.0228 Tm [(www)60.6(.isaca.or)9.3(g)]TJ ET EMC /P <>BDC BT /F1 1 Tf 7 0 0 7 39.7789 24.9858 Tm [(ISA)5.4(CA )]TJ ET EMC /P <>BDC BT 7 0 0 7 61.2198 24.9858 Tm [(JOURN)-8.8(AL)]TJ ET EMC /P <>BDC /GS3 gs BT 7 0 0 7 92.1285 24.9858 Tm .73 .19 0 0 k [( V)6.4(OL 3)]TJ ET EMC /P <>BDC BT 7 0 0 7 13.2407 24.9858 Tm (6)Tj ET EMC /Artifact <>BDC 0 0 0 1 K 0 J 0 j .75 w 10 M [] 0 d /GS2 gs q 1 0 0 1 30.704 33.462 cm 0 0 m 0 -39.377 l S Q EMC /P <>BDC BT 9 0 0 9 142.4978 674.9802 Tm 0 0 0 1 k -.01 Tc [(e)6.4(v)7.3(olution fr)9.8(om the qualitativ)6.4(e model. With the)]TJ ET EMC /P <>BDC BT 9 0 0 9 319.5203 674.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 662.9802 Tm -.01 Tc [(qualitativ)6.4(e method, the business impact was)]TJ ET EMC /P <>BDC BT 9 0 0 9 316.1514 662.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 650.9802 Tm -.01 Tc [(implicitly dened as being high, wher)9.3(eas in the)]TJ ET EMC /P <>BDC BT 9 0 0 9 323.3062 650.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 638.9802 Tm -.01 Tc [(quantitativ)6.4(e method, the analysis of the loss e)6.4(v)6.4(ent)]TJ ET EMC /P <>BDC BT 9 0 0 9 337.6638 638.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 626.9802 Tm -.01 Tc [(ga)7.3(v)6.4(e)0( a mor)9.3(e r)9.3(ealistic r)19.5(ange inter)-8.8(v)7.3(al, pr)9.8(o)7.3(viding an)]TJ ET EMC /P <>BDC BT 9 0 0 9 330.0853 626.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 614.9802 Tm -.01 Tc [(inter)9.3(esting and v)7.3(aluable outcome. Most impor)-24.4(tantly)52.3(,)]TJ ET EMC /P <>BDC BT 9 0 0 9 345.0598 614.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 602.9802 Tm -.01 Tc [(the use of se)6.4(v)6.4(e)0(r)19.5(al nancial indicat)9.8(ors demonstr)19.5(ated)]TJ ET EMC /P <>BDC BT 9 0 0 9 344.3743 602.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 590.9802 Tm -.01 Tc [(t)9.8(o)0( stak)9.8(eholders that a rigor)9.8(ous r)9.3(e)6.4(view has been)]TJ ET EMC /P <>BDC BT 9 0 0 9 326.8968 590.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 578.9802 Tm -.01 Tc [(per)-7.3(formed t)9.8(o)0( determine a r)19.5(ange inter)-8.8(v)7.3(al for the )]TJ ET EMC /P <>BDC BT 9 0 0 9 142.4978 566.9802 Tm [(loss e)6.4(v)6.4(ent. )]TJ ET EMC /P <>BDC BT 9 0 0 9 186.5283 566.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 542.9802 Tm -.005 Tc [(While the thr)9.3(eat scenario focused pur)9.3(ely on the data)]TJ ET EMC /P <>BDC BT 9 0 0 9 347.6992 542.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 530.9802 Tm -.005 Tc [(br)9.3(each, it could be followed up b)5.4(y)0( analyzing mor)9.3(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 336.4788 530.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 518.9802 Tm -.005 Tc [(thr)9.3(eats such as r)19.5(ansomwar)9.3(e or malwar)9.3(e aff)11.7(ecting)]TJ ET EMC /P <>BDC BT 9 0 0 9 338.6342 518.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 506.9802 Tm -.005 Tc [(the CRM system in scope. In such cases, diff)11.7(er)9.3(ent)]TJ ET EMC /P <>BDC BT 9 0 0 9 338.9089 506.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 494.9802 Tm -.005 Tc [(input data for the analysis should be consider)9.3(ed)]TJ ET EMC /P <>BDC BT 9 0 0 9 331.5271 494.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 482.9802 Tm -.005 Tc [(such as past incident data, and the or)9.3(ganization)]TJ ET EMC /P <>BDC BT 9 0 0 9 331.0041 482.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 470.9802 Tm -.005 Tc [(should ha)7.3(v)6.4(e)0( such information at hand. )]TJ ET EMC /P <>BDC BT 9 0 0 9 142.4978 302.9802 Tm [(The loss e)6.4(v)6.4(ent simulations only intr)9.8(oduced some)]TJ ET EMC /P <>BDC BT 9 0 0 9 335.4921 302.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 290.9802 Tm -.005 Tc [(simple indicat)9.8(ors such as a)7.3(v)6.4(er)19.5(age \(expected v)7.3(alue\))]TJ ET EMC /P <>BDC BT 9 0 0 9 344.155 290.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 278.9802 Tm -.005 Tc [(and most lik)9.8(ely \(geometric mean\). )19.5(This was)]TJ ET EMC /P <>BDC BT 9 0 0 9 314.421 278.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 266.9802 Tm -.005 Tc [(intended t)9.8(o)0( demonstr)19.5(ate that v)6.4(e)0(r)-8.8(y)0( simple indicat)9.8(ors)]TJ ET EMC /P <>BDC BT 9 0 0 9 345.7711 266.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 254.9802 Tm -.005 Tc [(can be used for per)-7.3(forming a quantitativ)6.4(e risk)]TJ ET EMC /P <>BDC BT 9 0 0 9 321.9008 254.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 242.9802 Tm -.005 Tc [(assessment e)6.4(v)6.4(en though mor)9.3(e adv)7.3(anced)]TJ ET EMC /P <>BDC BT 9 0 0 9 304.7549 242.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 230.9802 Tm -.005 Tc (simulation techniques can be used at this stage,)Tj ET EMC /P <>BDC BT 9 0 0 9 332.3752 230.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 218.9802 Tm -.005 Tc (such as Monte Carlo simulations.)Tj ET EMC /P <>BDC BT 5.4 0 0 5.4 274.5422 221.6801 Tm -.0083 Tc (13 )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 194.9802 Tm -.005 Tc [(Ov)6.4(er)19.5(all, the quantitativ)6.4(e method was well accepted)]TJ ET EMC /P <>BDC BT 9 0 0 9 342.4103 194.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 182.9802 Tm -.005 Tc [(because it pr)9.8(o)7.3(vided a sound basis for fur)-24.4(ther)]TJ ET EMC /P <>BDC BT 9 0 0 9 318.9707 182.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 170.9802 Tm -.005 Tc [(discussions with the stak)9.8(eholders, giving them the)]TJ ET EMC /P <>BDC BT 9 0 0 9 341.2018 170.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 158.9802 Tm -.005 Tc [(ability t)9.8(o)0( mak)9.8(e well-informed decisions on the)]TJ ET EMC /P <>BDC BT 9 0 0 9 323.1356 158.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 146.9802 Tm -.005 Tc (action plan. )Tj ET EMC /P <>BDC /GS3 gs BT /F3 1 Tf 11 0 0 11 142.4978 120.9802 Tm .72 .13 .67 .01 k (Conclusion )Tj ET EMC /P <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 142.4978 102.9802 Tm 0 0 0 1 k [(Risk quantication inv)7.3(olving nancial indicat)9.8(ors and)]TJ ET EMC /P <>BDC BT 9 0 0 9 346.8291 102.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 90.9802 Tm -.005 Tc (estimates of the potential losses should be clearly)Tj ET EMC /P <>BDC BT 9 0 0 9 340.2691 90.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 142.4978 78.9802 Tm -.005 Tc [(communicated t)9.8(o)0( decision mak)9.8(ers. Such an)]TJ ET EMC /P <>BDC BT 9 0 0 9 315.5173 78.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 674.9802 Tm -.005 Tc [(appr)9.8(oach r)9.3(equir)9.3(es a lar)9.3(ger effor)-24.4(t in analyzing data)]TJ ET EMC /P <>BDC BT 9 0 0 9 557.2794 674.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 662.9802 Tm -.005 Tc [(fr)9.8(om internal and external sour)9.3(ces and building)]TJ ET EMC /P <>BDC BT 9 0 0 9 546.6751 662.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 650.9802 Tm -.005 Tc [(simple pr)9.8(obabilistic models. Hence, a quantitativ)6.4(e)]TJ ET EMC /P <>BDC BT 9 0 0 9 557.2057 650.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 638.9802 Tm -.005 Tc [(risk assessment pr)9.8(o)7.3(vides a mor)9.3(e sound appr)9.8(oach)]TJ ET EMC /P <>BDC BT 9 0 0 9 557.689 638.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 626.9802 Tm -.005 Tc [(that is rich in meaningful data, as opposed t)9.8(o)0( the)]TJ ET EMC /P <>BDC BT 9 0 0 9 553.0001 626.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 614.9802 Tm -.005 Tc [(lightweight and judgmental qualitativ)6.4(e-based)]TJ ET EMC /P <>BDC BT 9 0 0 9 537.7748 614.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 602.9802 Tm -.005 Tc [(method. )19.5(The additional effor)-24.4(t in bringing fur)-24.4(ther)]TJ ET EMC /P <>BDC BT 9 0 0 9 548.8044 602.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 590.9802 Tm -.005 Tc [(quantication is r)9.3(equir)9.3(ed t)9.8(o)0( impr)9.8(o)7.3(v)6.4(e information)]TJ ET EMC /P <>BDC BT 9 0 0 9 551.1347 590.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 578.9802 Tm -.005 Tc [(risk assessments. Quantitativ)6.4(e analysis is used)]TJ ET EMC /P <>BDC BT 9 0 0 9 547.3519 578.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 566.9802 Tm -.005 Tc [(extensiv)6.4(ely and is pr)9.8(o)7.3(v)6.4(en in many other elds, such)]TJ ET EMC /P <>BDC BT 9 0 0 9 562.3287 566.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 554.9802 Tm -.005 Tc [(as nance, healthcar)9.3(e and insur)19.5(ance, so ther)9.3(e is no)]TJ ET EMC /P <>BDC BT 9 0 0 9 561.9156 554.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 542.9802 Tm -.005 Tc [(r)9.3(eason why the same appr)9.8(oach cannot be applied)]TJ ET EMC /P <>BDC BT 9 0 0 9 557.0077 542.9802 Tm 0 Tc ( )Tj ET EMC /P <>BDC BT 9 0 0 9 360.9978 530.9802 Tm -.005 Tc [(t)9.8(o)0( help manage information risk. )]TJ ET EMC /P <>BDC /GS3 gs BT /F3 1 Tf 11 0 0 11 360.9978 504.9802 Tm .72 .13 .67 .01 k (Endnotes )Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 378.3614 486.9802 Tm 0 0 0 1 k [(National Institute of Standar)9.3(ds and )19.5(T)48.4(echnology)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 563.7366 486.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 486.9802 Tm .04 1 .83 0 k (1)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 377.9978 474.9802 Tm 0 0 0 1 k -.005 Tc (\(NIST\), Guide for Conducting Risk)Tj ET EMC /LBody <>BDC BT 9 0 0 9 513.301 474.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 462.9802 Tm -.005 Tc [(Assessments,)83( NIST)19.5( Special Publication \(SP\))]TJ ET EMC /LBody <>BDC BT 9 0 0 9 554.2486 462.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 450.9802 Tm -.005 Tc [(800-30 Re)6.4(v)52.3(.)0( 1, USA, 2012, )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 479.8448 450.9802 Tm [(https:/)109.4(/csr)9.3(c.nist.go)7.3(v/ )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 438.9802 Tm [(publications/detail/sp/800-30/r)9.3(e)6.4(v-1/nal )]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 378.3614 426.9802 Tm [(International Or)9.3(ganization for Standar)9.3(dization,)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 560.066 426.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 426.9802 Tm .04 1 .83 0 k (2)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 377.9978 414.9802 Tm 0 0 0 1 k -.005 Tc (ISO/IEC 27005:2011, )Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 462.0884 414.9802 Tm (Information technology)Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 552.3248 414.9802 Tm 0 Tc ()Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 377.9978 402.9802 Tm -.005 Tc (Security techniques)Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 454.0649 402.9802 Tm 0 Tc ()Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 461.0469 402.9802 Tm -.005 Tc (Information security risk)Tj ET EMC /LBody <>BDC BT 9 0 0 9 555.2222 402.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 390.9802 Tm -.005 Tc (management)Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 429.4211 390.9802 Tm (, 2011, )Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 457.2653 390.9802 Tm [(https:/)109.4(/www)60.6(.iso.or)9.3(g/ )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 378.9802 Tm [(standar)9.3(d/56742.html )]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 378.3614 366.9802 Tm [(Hubbar)9.3(d, D)49.8(.)0( W)60.1(.; R. Seiersen; )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 488.2034 366.9802 Tm [(How t)9.8(o)0( Measur)9.3(e)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 551.8174 366.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 366.9802 Tm .04 1 .83 0 k (3)Tj ET EMC /LBody <>BDC /GS2 gs BT /F2 1 Tf 9 0 0 9 377.9978 354.9802 Tm 0 0 0 1 k -.005 Tc (Anything in Cybersecurity Risk)Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 494.791 354.9802 Tm [(, Wile)6.4(y)52.3(,)0( USA, 2016 )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 378.3614 342.9802 Tm -.025 Tc [(Hubbar)9.3(d, D)49.8(.)0( W)60.1(.; )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 437.1602 342.9802 Tm [(The F)16.6(ailur)9.3(e of Risk Management:)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 558.7491 342.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 342.9802 Tm .04 1 .83 0 k (4)Tj ET EMC /LBody <>BDC /GS2 gs BT /F2 1 Tf 9 0 0 9 377.9978 330.9802 Tm 0 0 0 1 k -.025 Tc [(Why It)54.7(s Br)9.8(ok)9.8(en and How t)9.8(o)0( Fix It)]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 498.3676 330.9802 Tm [(, Wile)6.4(y)52.2(,)0( USA, 2009)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 564.4158 330.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 378.3614 318.9802 Tm -.005 Tc (Ibid)Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 392.6702 318.9802 Tm (. )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 318.9802 Tm .04 1 .83 0 k 0 Tc (5)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 378.3614 306.9802 Tm 0 0 0 1 k -.005 Tc [(F)12.7(r)9.3(eund, J.; J. Jones; )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 458.5916 306.9802 Tm (Measuring and Managing)Tj ET EMC /LBody <>BDC BT 9 0 0 9 557.1469 306.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 306.9802 Tm .04 1 .83 0 k (6)Tj ET EMC /LBody <>BDC /GS2 gs BT /F2 1 Tf 9 0 0 9 377.9978 294.9802 Tm 0 0 0 1 k -.005 Tc [(Information Risk: A F)83(AIR Appr)9.8(oach)]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 511.1487 294.9802 Tm [(, Else)6.4(vier)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 545.7013 294.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 282.9802 Tm -.005 Tc [(F)12.7(r)9.3(eedom Collection, UK, 2015 )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 378.3614 270.9802 Tm (Op cit )Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 403.1217 270.9802 Tm [(Hubbar)9.3(d 2016 )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 270.9802 Tm .04 1 .83 0 k 0 Tc (7)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 378.3614 258.9802 Tm 0 0 0 1 k -.005 Tc [(IBM and P)6.4(onemon Institute, )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 489.9325 258.9802 Tm (Cost of Data)Tj ET EMC /LBody <>BDC BT 9 0 0 9 538.3478 258.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 258.9802 Tm .04 1 .83 0 k (8)Tj ET EMC /LBody <>BDC /GS2 gs BT /F2 1 Tf 9 0 0 9 377.9978 246.9802 Tm 0 0 0 1 k -.005 Tc [(Br)9.3(each Study: Global Analysis)]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 492.9639 246.9802 Tm (, 2018,)Tj ET EMC /LBody <>BDC BT 9 0 0 9 518.625 246.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 377.9978 234.9802 Tm -.005 Tc [(https:/)109.4(/www-03.ibm.com/security/infogr)19.5(aphics/ )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 222.9802 Tm [(data-br)9.3(each/ )]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 378.3614 210.9802 Tm [(Hill, R.; Exposing 145m E)9.3(quifax Cust)9.8(omer)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 543.9531 210.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 365.9978 210.9802 Tm .04 1 .83 0 k (9)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 377.9978 198.9802 Tm 0 0 0 1 k -.005 Tc [(Deets: $240m. Legal F)10.3(ees: $28.9m. Insur)19.5(ance:)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 560.0528 198.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 186.9802 Tm -.005 Tc [(Priceless,)83( )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 420.5375 186.9802 Tm (The Register)Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 469.2693 186.9802 Tm (, 27 April 2018,)Tj ET EMC /LBody <>BDC BT 9 0 0 9 527.4231 186.9802 Tm 0 Tc ( )Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 377.9978 174.9802 Tm -.005 Tc [(https:/)109.4(/www)60.6(.ther)9.3(egister)60.1(.co.uk/2018/04/27/ )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 162.9802 Tm [(equifax_br)9.3(each_cost_240m_t)9.8(o_date/ )]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 378.525 150.9802 Tm [(V)21.5(eriz)7.8(on, )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 412.1338 150.9802 Tm [(2018 Data Br)9.3(each Inv)6.4(estigations)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 537.7106 150.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 360.9978 150.9802 Tm .04 1 .83 0 k (10)Tj ET EMC /LBody <>BDC /GS2 gs BT /F2 1 Tf 9 0 0 9 377.9978 138.9802 Tm 0 0 0 1 k -.005 Tc [(Repor)-24.4(t)]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 403.8929 138.9802 Tm (, 2018, )Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 431.7372 138.9802 Tm [(www)60.6(.v)6.4(eriz)7.8(onenterprise.com/ )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 377.9978 126.9802 Tm [(v)6.4(eriz)7.8(on-insights-lab/dbir/2018/ )]TJ ET EMC /LBody <>BDC BT 9 0 0 9 378.525 114.9802 Tm (Op cit )Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 403.2853 114.9802 Tm [(IBM and P)6.4(onemon Institute )]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 360.9978 114.9802 Tm .04 1 .83 0 k 0 Tc (11)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 378.525 102.9802 Tm 0 0 0 1 k -.005 Tc [(Rumse)6.4(y D)49.8(.)0( J.; )]TJ ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 433.6399 102.9802 Tm [(Pr)9.8(obability for Dummies)]TJ ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 527.2239 102.9802 Tm [(, Wile)6.4(y)52.3(,)]TJ ET EMC /LBody <>BDC BT 9 0 0 9 553.4773 102.9802 Tm 0 Tc ( )Tj ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 360.9978 102.9802 Tm .04 1 .83 0 k (12)Tj ET EMC /LBody <>BDC /GS2 gs BT /F1 1 Tf 9 0 0 9 377.9978 90.9802 Tm 0 0 0 1 k -.005 Tc (USA, 2006 )Tj ET EMC /LBody <>BDC BT /F2 1 Tf 9 0 0 9 378.525 78.9802 Tm (Op cit )Tj ET EMC /LBody <>BDC BT /F1 1 Tf 9 0 0 9 403.2853 78.9802 Tm [(Hubbar)9.3(d 2016)]TJ ET EMC /Lbl <>BDC /GS3 gs BT /F3 1 Tf 9 0 0 9 360.9978 78.9802 Tm .04 1 .83 0 k 0 Tc (13)Tj ET EMC /Artifact <>BDC .72 .13 .67 .01 k .32394 316.291 346.995 140.964 re f EMC /P <>BDC BT /F1 1 Tf 14 0 0 14 63.9496 427.6846 Tm 0 0 0 0 k .0351 Tc -.0175 Tw [(A)17.5( QU)10.7(AN)14.1(TI)14.1(T)38.5(A)63(TIVE)17.5( RISK)17.5( ASSESSMEN)14.1(T)]TJ ET EMC /P <>BDC BT 14 0 0 14 308.9087 427.6846 Tm 0 Tc 0 Tw ( )Tj ET EMC /P <>BDC BT 14 0 0 14 36.9496 409.6846 Tm .0351 Tc -.0175 Tw [(PRO)10.7(VIDES)17.5( A)17.5( MORE)17.5( SOUND)17.5( APPRO)10.2(A)5.3(C)0(H)17.5( )19.6(TH)-8.8(A)63(T)]TJ ET EMC /P <>BDC BT 14 0 0 14 335.1743 409.6846 Tm 0 Tc 0 Tw ( )Tj ET EMC /P <>BDC BT 14 0 0 14 36.9496 391.6846 Tm .0351 Tc -.0175 Tw [(IS)17.5( RICH)17.5( IN)17.5( MEANINGFUL)17.5( D)10.2(A)63(T)38.5(A)17.5(,)35.1( AS)]TJ ET EMC /P <>BDC BT 14 0 0 14 264.6548 391.6846 Tm 0 Tc 0 Tw ( )Tj ET EMC /P <>BDC BT 14 0 0 14 36.9496 373.6846 Tm .0351 Tc -.0371 Tw [(OPPPOSED)17.5( T)13.6(O)17.5( THE)17.5( )-19.6(LIGH)14.1(T)-7.4(WEIGH)14.1(T)37.1( )-19.6(AND)]TJ ET EMC /P <>BDC BT 14 0 0 14 297.5699 373.6846 Tm 0 Tc 0 Tw ( )Tj ET EMC /P <>BDC BT 14 0 0 14 36.9496 355.6846 Tm .0351 Tc -.0175 Tw [(JUDGMEN)14.1(T)38.5(A)0(L)17.5( QU)10.7(ALI)14.1(T)38.5(A)63(TIVE)17.5(-)17.5(BASED)]TJ ET EMC /P <>BDC BT 14 0 0 14 273.9995 355.6846 Tm 0 Tc 0 Tw ( )Tj ET EMC /P <>BDC BT 14 0 0 14 36.9496 337.6846 Tm .0351 Tc [(ME)-9.8(THOD)67.4(.)]TJ ET EMC /Figure <>BDC Q q 1 i 102.84 345.416 23 -23.75 re W n .027451 .98039 .8 .003922 k /GS3 gs q 1 0 0 1 120.944 335.128 cm 0 0 m -.099 -2.881 -.579 -5.075 -1.441 -6.582 c -2.301 -8.089 -3.643 -9.223 -5.464 -9.985 c -3.279 -13.462 l -.265 -12.104 1.937 -10.101 3.328 -7.452 c 4.389 -5.464 4.918 -2.252 4.918 2.186 c 4.918 10.382 l -4.67 10.382 l -4.67 0 l 0 0 l h -12.64 0 m -12.739 -2.881 -13.219 -5.075 -14.081 -6.582 c -14.941 -8.089 -16.283 -9.223 -18.104 -9.985 c -15.919 -13.462 l -12.905 -12.104 -10.703 -10.101 -9.312 -7.452 c -8.251 -5.464 -7.722 -2.252 -7.722 2.186 c -7.722 10.382 l -17.31 10.382 l -17.31 0 l -12.64 0 l f Q EMC /Figure <>BDC Q q 1 i 33.897 453.11 23 -23.75 re W n .027451 .98039 .8 .003922 k /GS3 gs q 1 0 0 1 38.815 439.742 cm 0 0 m .099 2.881 .579 5.075 1.441 6.582 c 2.301 8.089 3.643 9.223 5.464 9.985 c 3.279 13.462 l .265 12.104 -1.937 10.101 -3.328 7.452 c -4.389 5.464 -4.918 2.252 -4.918 -2.186 c -4.918 -10.382 l 4.67 -10.382 l 4.67 0 l 0 0 l h 12.64 0 m 12.739 2.881 13.219 5.075 14.081 6.582 c 14.941 8.089 16.283 9.223 18.104 9.985 c 15.919 13.462 l 12.905 12.104 10.703 10.101 9.312 7.452 c 8.251 5.464 7.722 2.252 7.722 -2.186 c 7.722 -10.382 l 17.31 -10.382 l 17.31 0 l 12.64 0 l f Q EMC Q endstream endobj 418 0 obj <>/ExtGState<>>> endobj 6 0 obj <> endobj 5 0 obj <> endobj 197 0 obj <>stream AdobedC         #"""#'''''''''' k" s!1AQa"q2B#R3b$r%C4Scs5D'6Tdt& EFVU(eufv7GWgw8HXhx)9IYiy*:JZjz?f͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳf͛6lٳ endstream endobj 198 0 obj <>stream Adobed         #"""#''''''''''     !! !!''''''''''k""  s!1AQa"q2B#R3b$r%C4Scs5D'6Tdt& EFVU(eufv7GWgw8HXhx)9IYiy*:JZjzm!1AQa"q2#BRbr3$4CS%cs5DT &6E'dtU7()󄔤euFVfvGWgw8HXhx9IYiy*:JZjz?q#8y:ϟf͌(oM{f͛1.QqL`rG;6l؏0ی>;X86lڮ028qN G]6ll7C[skfͅQ}Hxa#o ~S]6l/k=8ZdƖ=!qc ;6l /;crS>:)Xɾ#k68E!o1߁pBI|0wգZ}.L~L;+W.Zi|E}Yqi)|_<nr߆oV~?HcyHy =tɈPH^c#H~,! 70NPٍ~r9:GYȯx$r8cG?>f;>A?J_ŏ@q[`n/L7fXڕGӀRrC㓎H9ɺ~D[N`8i1A#f'c+J`Jz_'7>sz8鴣>eO7wQUpX $#c#/ׄt8=78ಷvytpӈ5g+]ܟW1 x~ٍGr *`NڵYI~9dc?҆iXޔWܓbME{@~ԊկHGW,}ߎܕݗhQ5:isHc ;H>*"}ϥ|(7z-*DF}OF[g1@ n5֭[A(dzg^Ah,1PsMB"M`<#g<,|an- /*`ʜɈfg#6(La1rS\!!t Sv;z/]0RxPۜ1ՠߔ29@z2?6w.͛6=MqQ*e'U܎Qvlt0?>D~}`8k$Zp jGrI=qliͱ0&;ԇ8 1Ri9`ef@j \cxN&Eא#up'/o [*:(_\=eY"cl!}^\Oѐ8[ᙯؓ\M9pnc,zhىF5 _zeT}8 '(`d[#Z9{ Rqc8NWz0 mGW,&Oñtcg/|>p4un4h9_X# iXɏe O$:R}/рw'waE?! inʣ+=,?1-@tA'F 7!LLLz+@R}șʇ2v B1$em~2/wOcL'rrO8y~=fjf%|IY1ܜx+Wg~pxwḆ:/DzvNEsvpSL]Gj` j]+~-Nc|1^eœ}2["ԝʜD7G˨=y$2d#yH9uU ެA11O*=*aV3cj<~fWI~fG/>fV,Nc/v'P: `(M e3Tbqב؀71ޤFɉB,wSUb~XG/?~ Tv4y\ 6a*22\`G/Ьuىiz\!~xUP A释Rnecq*yIZcIcr'?3Q~ӁЖ gҟ@좿_X1x3c=E!rp~ዯ"xxMCc4 {$ _j;tw##|V+nmfDJ9ЦAsc,t3؃P@@:NA@>U1I㈜͋riw >d#j0n$' k\M&F(qܸ|.M].He OfLt uqTO F4bl6t>減 ZLH帱>&2}{ec+8ck1DGF͛/ 1òecX~ 8xz]l9x5n B̐107gd)7\gLsesw1EGiRNZL?S\NY87\v`bѾ8 cr6SEڸj9D THU(o6Vlk1eĂwZ%rv>,Y˦&⨘DkJ`홻e0?H2Hi K`:tȝDcA4@2Io1a3U@eeb^#Olyi9'޻r,|1ƻul!ciuّ#=ˋp-ޣ;6s-kQ NI-Qjt *Do1e?2]Tc!Ƙ/?p׹KI%Qwx/Hej2FI qa=1prW1vvURq:/߈|i ݉!-DϗP'BO~doqsp azOCX,}+\#1YRdULx~|>5@eb~Ɨߘz>XTԜR+>)FWĚk5}b?^nIܟ+c'(#Gă{y?ٶA\w(潗/2GtZ>|>; cJefe9cWQᩓOe3I:CfC5 ޿ N8MI> |Uw/AF?q~1D#+>5M3n{f3WP|헬=Ӿʧ?'∋N1ظ)3]G|fX ?ًң#FKIWy]f,rx'Sp=XzUodD$O3Op+=ˡqaX1NJ݅9_$cDr~Ӆ:H!{QwHBH?xW/|j(>PHQ$weǦp@_yCg"8:߾&“(o,lZ˰|E׌*h?SP27ncHpfW;sYuߩ5?<:lVK':\pInI$qњ~u)#Ffizk<8VX$uM24acNkrV(9ȸ=GV6N5*A3.;wtlGx(&\I,`k$=F& qc$nqr2M2eTVlظlz`pآ6N;y`r RP`D8"&s7($'[č݆?8e[pf ܩ `ԌUʸlk6ٴOclIZ$K%w=OX,ًNيgiœ b0T\sfĘ15/r6cg\HX708Lˮ$}k؋ܱ|Bd#;VlUʹ|q2%[4z;6lٔQEs*튢aeٲe\US7N3.W_ӏHѹkͮ{6Ur',~8F"H͹1keFfGwpL@p+76 v+A#zb䡪2Ry̷&r9`2닊0>;e n@!S606:r\%Yens@k6l>Ɲ8އ Lq14D#aNMN̚P_@˷z048rlq}k%@#Q9 JKCr SD#j0 I\xNJѶ8evMb`ی0)".o(b~^KAt`9 Bh94;Bg^Rt`3h˸K͈y, u I/~(!hV = @|c~|ؑN`9&ĎK96$I*:N;W6IbJQrq2ǶU[XO4˧cҔs\mNVz1S?NcJ`'R/'>A?q-2mC?뚣|d~z8@ Q?_`N77#яEIƕ'U H{JvsG>k*P_* e[+HړR_~GfC6_yqO@_ؾ:3OA}9R~iq1@#=#l'幐D᜷3a]Um6yķe|=؜[_` ʩ|Q?3-6;j>ۏ1*M3^x?aǴY|@P?ҁ腛exbOvQ+O9DYe?nsOa1ټM)Ds۸?tx˂#~k72QMOc~mkܜTG|.?մc(K5O|tʡ¯zW1b /k%`1u~IP>e횧U p~%N/vQ,z (\"6?>eT`K%r?7UqA ,1>M388Vo\h*;Wr'/;_זeSEDeNDd%%^@ ΝG,$)+.Ez~OŸp[3'_@>!fͅ|C{͆ߡuSOߕ~Bg^~0(2W10YPaŰ|mPuǨ'.o+ BlY/c_V`Oׇ0+F3@M³7^⾬+#_d()b(ȧG$=w7CՎLI Pk]Q4d0@ǖv!ᝀ\#_H܊%:d=&j$zt"n1%4}9DKeݳ#!;|= !d=Gc#)p^40&s|Hpuy!a&a:q1'Y en1&I=q"9Cb0 0#c]r nGq.*n|T*܇C*>CQ2H`!q6]oOG30eS#+7]z,ztˋ 8"2hȃCF>J@ph)eul]l7b©\`sN zyd%(r2!86zUcĤxc318#ƗoSM@{7f͛t;;fOyq##r$7f͛FS+fDgN^9ӳf͂O|Ye!_ A\jvlٰe lj{fT5uravj͆Pq_~;DuV:\s`Pq\ $ɯlח] 땛6D6m j랟$W =1}o)scΙ>t㑸AX$Mmo 9}$ng(:#.maW*9aO+?UsP{U}c|P ȎW'QUi,3I(27 ǐh. Q]Ι+0d@x&uZ-F8^S`08™z?hiǴ4ߛ6q=ӎSh^翚A[|PBr?P ӓy>{c[]*QTHHq0#lccj0u3;!87D]oоx*@l1 Pa,Io4H8qhpv)bc>w͌;5H}cJ¯QGE湽Q(fag/,y)_%tQ\;(\϶;^ӁIur~XJCڙ^Hm+a"zcȕiՆoĜ ƝN;4$;Զ5S?b%/c&EOEFfCdLZW=l㾥ܬypx>ዴe!((hʿf_x=QqAa=*brv "iۓqA%)o㓏e;c/;;N9# ~fÑ.i$bOLQo ZpT7)߉?~Ha^+q#$`Y#x|(&gC,{|R~=҂LPKOƸw쌭(@6⪪O\CX1POD *hu J)4ڈ3"Du/tNvo(}>l|Fn3?J>u>'+ÎA CSZbӑ2j@~7.:(s1Nr`d;iNsE}+;rƂz3唽S5}KTY=7ȞY`^*z=(Eq˩#|j /,H ',̰5F}B2?3xv] W %Ԯ|!#6$+E'#N}F]'l9Nl o_s9┷,l/o!n͛%gbGe((A ysvlٱiA&A+r;LxS^vYqF[\4v%ۧ6l MJ݇Mm$05吅&h>t%*1*>vhG,U-ʝ3@;o6652C#aai.}@+oT"swxPOQl j$WF8ghM'15sqp Ihq%N gNj_W  UN1nn,@vClA\i c?p}G@:5Ś0R4#_u_j!KsFnP+*֟1G<5/^9qDd$Q@%)$#'}Lŕ7Yq2+}[@HH6%Á@8Sw8$@AQҽi3|~qFv871r>K.ӖJ (rT➃8srqM16&}1t"9 9?w ?Jp|9spL~TBGuרU *r±04~]-`CPlȇcOג9p=iB/Tɬ~Ty$֔$Ǡ6QZ-L"i)E8)41blQ.IdzIdz!c+UoHFB8ii\U#ֵ5GL=XpPS֣c.He0}3'c?:rop|o|د'J;q湲K{9e/1G&˦GݸOF c W*K/+,Tf͋UCc&ٳf&زLPK[6ldx0ś{V6l3xbgɌEٳf!'lި]Yd͛6bms|LԞ՞ٳfql:9v=D]6n05?R}sp:FLoL} =.(b"608#%G^f%t +5p SƧ،S"[5j aqXA~¿h)^Q(1~9!MR'݇L4 {8mst뙰'gci弽ޘgJuHO`ރǮ'Zaq;SwLZ amm \q-H/l;q\wAP?bN$8̍efs={+ڌќ_T[g=&hChq+?m[NnYE#tl߈ݼ)Vs~l۩[ gƹ2P‡6_.h͝a_W=xէlB"FJͅT?Tu͚s=tzQu>N|ƜY ,N]zm\ jo﫩Ol^/21!{~=>6_zX ?xPT=JTIr@ H[7 IƹH*/`6bҽMhi_O<c`dhQËxccҧܪAn' 2]0\9{r/,guH4w8rF0_Qs̺.r@nTM4o{MgjwM1d;?:.OV$ c6#(JvS<"eO`"d?/73k#{s.GMB8>>Y6'EOSLx dz_M+|U=lzSӉTφX7幩۾aH˧QCڸN"|rBFIrwrǖ`A![`:ʡPHh:h{5 ïo/ju]v Sr:˗V>UBu^T'`ҽV7+Tݪ65j7qezĐpZ@=)æ[sނ1~\8j'oBYum"@},vJ}8bCĦₛT׌C[(XYʅo]9/4%+ߨNYVD3y\zٳsB)OǨr:Ŀ'uWg5%`m# sE9琢ݷ'T4٧Q㰔 #py>K݋m`rq@d8%HGmdX6ţ`»ㄘng5\ndvlٰ`%~2]6lKaS;6l7>9lf珊W.͛6 \ ).͛6 }N=}F"*U,=? 93jO?Ddc:e?Չʁv>,K9Mxb7dd'%J⭌|@pA};ڣ-@?N2FBR>!Ս6\`KTx+_Z_8s;+r$|{u='T¨+_`F? A,oq&n) L^bEvǩ9@~83"3|kwڞqm0# qL(2g?ѰA ~)ΉBfou!sbhj>yMma?O)~ǗRc6VPA휛:"quǷsӰ­v>䄶cM fZrVqfvm70%ʺtu֥huj8n؀;mZ֧%'/uP[`M>QXrN^ڽ~Uz:o|=v=t/<0P"=_(u,II,gDM͉3e3be!4i: =Z M=^&lOsh掏G&CǙ?e 7٦.v42A7`3|w.hh7*#QF_Š6&Ɵ<0C</#f>9U~/u yڃe`QlǟN$GSܟӹƱ62KŃD>6MM֝|=5=\='ZY1aj#"yNYIGy#w>^Asòc0?l3mAGSY9tfæ))"Fp5/fѼGrj aEk CJ0,2;H@MǶ(ֹ3ǭw~vQQJAnyֵؑ@FƦae$QMrO,", elˈ LE a~i[cM$qcsfs}o&6GLJOPxraP~і:`AnNM; @wic(lbM̜$7bPDN,^M'%Nr6έulvs3ڹ,u-ɢν?xg3I˪džRÇ7R7_FjjaRË =|ϟ-OP=q~ӮmE?mnl1!]WB.l#M/'Nouf]i\,SѸeŰӴݱN^zc(`ҹtm@ 7;8`:mE8p-ɯ5#剱c? 5G7Vo<@4 -z h>~J(rS1ht 빢UVM».S zH錩{z}w R7k+ze7.U?&K)9čI9 (nn6RobN^֘Ǎ>a82Co4@wvu\3}ۮƒv,2ҽb64ס=r{r19OF^S/ i֙57{v<9a׭:bbqv GSLȁ9+7Dz]r|MxWa\Q8_hLKsǩtz}~x} ފJ!NNܤD[ ƫ[|1&@[UTEP+F%wʂz tۮ=Vuj۾j54l$^qXvYE9(w!*u\0nMy}j͛1u5]vcKhıPLv^:B$YGŨ}qCu1z>ӬL. ~#(dž4ۀ=6] ~'H6pM(ؓi=5͹;ƛu>Ő܊i@z -27 ҔƈKt`F7a옉zÏ` vl7a¯B<@OAFrX Y߿C*`l8*1ʭqu1“d,ro;`t^8wͦC)|-i#@˧%$vcL ٶʢsf;҈9Rkc˹IblHŹ {n jЃ^! p7LZmZ8x2Wt1ɉ@h76Z$o9\i t҄k$ |}e4pg9ُ3xR1>A';KnjH^By:X Hƽa~$ k0 pĎٯj@ ;͔T.GmN~~$A15:eW. [1Nz=kgQyQǤG59G@=sYYbI,GlTD 5HǁM[K41'ӳ^9d*$nyDH`gj}i9;arU wPP{gINz~'j4 N&#OL۩#" lE2w^|1A둋O0H%ņ[_**{t]DDOa6<z;KɚDn>CWztȝ*Qg^k68sgZ ڇ0#lH>BWrcyVv >-A QV8o.e n:eB2ly)MAl~xeu^[R6]9G0;~r_oz@؁Ӛ ꧷5\ǔTw1WWæ?N! S| z# @ 5P'5+txN5 c!cD N"߃P}! jӨ΂J:7CP) SȞwZO&HCl @z:u d0 yo{8qgF]??6QIy(D8 o`j{MQd+߄}0(?_ׂ@1emj߮'/ ~*b3EE~Cloo娮Rk">(r˫(rn(2`"'jPCj@95 Lj(15Aǎ?%#@lj3!ָ{cbMM+Q˵Asa,*O">2z9l9*Bv(?̌i6RIANĴIX(1qJWu}U"H#qy21+ϧŔp刕 ݌J]ZTnQuM+W%~OGNЭfo_sdv"ɽ_Pq^7|S?5Czx=xy} .4y -nOZn_lڵM NX]+H62|kÌH bJ#At=1A /Q)n4+@OdB7'&0#Sc-0RsHZWcA5>')T߯ST39G,trYK{FϹ"Fk {{9:ժNYJ /2ۖ0єх<;mᓎ9gn~SSF0/}W޵GZvsTbV Ǜ)q#|=<-``7#+:G$~vvo^5Gӂ"kbiRԯALB\xSQTٹL#u 6!8E.*(MjR ɪZee$TSuܰZ iȝ&H&?3?r[}e]?.m1(SV4^`vCݎ-E*~>翻F{S ^|Ǖ"^/:XT:WaEe\LG=IypF؃N,P:$8gG{IX퀙)bf${0qèQ8Gn|?͞3 Dz>\NaӧшTem{ @c>uN>e')8v'fce,dwq+E2K`x Zpitp]bƵsz] 뒿/H׶$V1Iq2;)cTxMd֡^~8^rOml֦GZ,FA`r8ҀBxcd@7[`y-8w4P(|!/oIk3zx\Pܘ|f0G]0ӆ*6U}%z@vs;;%5; NvMȠP27;/R1~|rLe(qq8zJx2y%kn48Z|xʾH$rf;Kn )˰:SvU T*?v)_|B :e07iƣP9 bH̜Q$5Ze& ipK97qHw9#=)Z|]fjG^_!:a עS47^$E+Int\ $fi?'s^}( *E0;5wɎ:yT@6.ga{=,& Ϧ0p[s 1Rzx;XEMpBA ^;Mܜ 1'vf&]L2sXeۍϐQfؓ$ \LK:(f\g&;6P̨jh1=1i XuS͏3!Ǥ:N?`:kP; ;M ; nWM:)vl3,zG򳔳Q0(1}OrfJub1Mc&@D]161qS;6lb?czI4cvv1cr 6yٳb8=qv-fI<{<ϛ)T|(I=>;yvlٱDZoJ!îevl6OhV9Q2χ8="1vn3fڕսgNX$ r>O{c2M[s]s/jV8rzb?ϋQ߄sFwr~oc.ȿNsN/du`G)Q@2)#G: 3RuZKΟ(XgVA7jqN*&c.p|(k+)զrn%nPUGrj8#+WсQ|$P Fmbc8㐔OX#DnŖzmOlu Dt* ? o\rn@ƓP{哄zP.6Q*j ]`- 1F4~ZB:|[}'(2GH"{  dU`>NF.kG 'ue]`L4p|=}*xPw M8q~a=NsAGQeccA-6BhTE;{q7<۾c{د@X{x~= E({0eEq ccB_xb`"N5R(ce@NO}\Ѫd.Tbg8Y㦉¶v&%a'ƿ12JMV*j: o}qŸ@>Ȼd#sMB5q(Jj7p zÈxE@xCk|]c$6ؕ(}Fcޞ)@9҇ؔx,|K3 U.2e z6]sE=i͸JMŸ U=W*qN bǹC{G?eqv L %%7qKh# aN ѫ63 qsS*e\I ;xs<9l7NX؍0j1~1߶&1ĉ9N$MߚKӽ;wyPȫ+rdjwܜkcz k5ُ3P.@uƁE$->!Q@:0UqGSN__IDOi5:{˛s# Fǔ Fƅ,~[nI;N.:1~g iNjv8R3jj.]}0?d.1cB^٩c~l(J[T7f͛0OOc\ PC,6GX< g "D#|6lm=kc\y* |tWaHtٳe\U*vJ xl۞Ur1*:;6lؿ1N+{#\H e;|)JBGj:g)HH¶͛6/\ZolE`; ~_sLb/sF0$n:,p!{|]*U㩍 45ʵ;9p5?lRkn뼻 u=lպV(LxG hLZ;Z8;͆9ex1އ w{ɏ|Sh?X*: m5FΞ~0)]f+WsE|2>2 kNW[ q@7XaλF9ub12;:9fs8zC*EǍzL@ᒫPcP IփJwںpQ=[)}Q< )2LaǞˠy8*L i>9L.cHrXCN]0 HK^Y *5 q "=RHF?t*? $o R)WCFSCn&1g{g케hi/x|fc-~y>^wlEX 0pLtji{VBiCsf5| 6lٳb͛6^_Q^*ٳd@?HioHaF~&Ft )s푭Ќe=B]?'=푭Ќe=BG/КiLh~XxیE#D"S;;\ZV"֘!UG|qUa|absߕIߐDdv ,tkT)5@%yۂ/a>en-HxqR <@uN fj&eөbE]*L z`*/sSȫ\4žX5aD܏،D܊gnđAZ\4VR:xa-ߘ!FnBu-RkYbksf7FWhO]9 9œxS^*z Ž(Fނ8?bۿ|] l\Lnnde5F9t="1-Xh+\hI(Hzq:e@B@rk# U7<@)B0;q:4;ṽ zχPyy Bn1q`ç|Ѳ~ q wS1yBþ~5EODž*H=F?{qHz`v:I0. Wlio#a0ڸ96g( FL!'45ĘӮ$ثS|EjLYa \EY'|NMrcs $HeQwϓD⇮Qƣ(QRw=0$Wݻf>P2c8MsPc<Ew퉜h$1O~h~؏*w~^VOQ]Σ<v@φ_; ?I]uSƟ~7`J9=DM٩LLl:1)٠\oƴ\eUF&*UfVCژ\ /*m\@)=3CM(jeR6o&J&n5Z׌{2I|ǧL9%n4\LĘȑO1=0%ĕ DGl/1ቶٯ.nM4 ĶݰLƿ;wYP1)+\I@{4 tC9 c:u %bw*rU.5.7'//dx更O29K釟yY R.QSs;<4AS˟nw5bh{,l+߶8q+6\.y܏!176O4'ϐݱcis9EQ[TvrCy{vlٲ$Wa84P|}16`3uۧ!˳f͍P:zenQiwq6#.sf͖}rBP~l>_( zDt@d#הaGvlٱO^'S^Mۓ\u?y=͕1VIOvlٱAON0$_ ((=xyb=}ٳf*ĐP8 #86Pő;q<]h"G[u̢yӈjV^k}[A,.ܻeyNJ6IȞ7a؈{ VB]t"+\4Hc!)VIXWsһᕵCG◭{) iqAA8a; O͜*.dwňnd~_kvx@ \W\irs4^mLN8܏NU˨qB1#GAzybD5eJEq?Igns9b|I?9,қ#^淼i-!wږ {A„ucU\Rp$0yi{ y2f8d1'_A M罣4.m.a9 r_A lA"pr^1$k5;PWG6fMنr+Լt/Mͼr`^XFdh]P9k3Y_)s.Of'aL_՗H`ɬ$> : Q2 vlٳu5O^+ FC KYxM3v7jdl50>$;.Lǩ9#gN>0[ti|e{wQq0ZhualR%;=T5a8DUޘ4KQϨ` F*(;bB9/w"( b e``VwLp:kYUkqG[Ad~hֻqH;8ĵ5ce8c1sr 6TIW+T,槰kj[U›.vU9-Sc%Yr2 WbA$ps.l4W|q͊cr$9]TTvH⪤b\ve$#̦ q^تQc \㩚2#"\$k\YTbl 7?l_GD)LE݈bkKS%"ޥ6v\P̑π*B7߾9EqG~PS6c E2,W5h}F+Lc֘oAŚkT tuW=U$a_:3i1]N&:\yw낚3gmě;St'r3 zy]|:Tj68Z8SZi{{XzbͱG_F:y f19c-R(r:E5ˍ L&ʔ'-^~r5@%ΉqLH{򆿯()>АOQKE[GGv=!.v4Hޅ@i ɵ x0`FWY?eic~ب Tb>DyS8GSNpC1'%}9 -XW$1A@a\{tZÚŋfZcf>~ÖUebDTLSY.c*tw)xb?  $F?굺c\R*#$+5Oq +4?!V1^?D>\ |~쾙hy6g9͐$̥#rr;ꔀ9 ܤw#Unloۧs|Q_JW ,,UqWHCq ~ᆵ؞3%ǧxc/6LC2c5pk;b=\G\'ej`]CM##Dv~Mp@c9Gei58Q9#1F2?hMN)acHꌅ#d{]K2 8燰E/Ȝ纾u1IΣzpufUedu ( ،kY۝朦K^x_%Y^{s>҇1׽i͠h#,~r<>҇O7vmIWΑsGq)U5FB=@Fۊ)b{ Mg>NJ4+!5춻\\NSuƻ\IߊcGb##oqNyjSvYEHnt#$s瞕v:lY'MurOv>vv:heAMϥj!O=QLPP`54ǫS|_Ͼ!(3o"lmM䙎0+c#41B \lzgX'cS펒o7,KPlƉ4|,F&rʮ ǔb@P|M89^-CPfăfŃcbYuiLe ?Ź}|1 q3"mEbώF8! qX$cA0r QHc\ L}q|msW3 \gG b )bLӱrCyeDs q'c3\c+,erD` VҝִWrSrX#/( %2+`y,~Ҡ|G?v"c pGZ<$4=$- 눶SL<0IҔ``*䁁5LSnweHKAjCT:J _Rzlc'۶I$>?3~+u )\l v/ߘ"9= W"F@d*Q$W)hš:Gp|2FgCOCFZ?.#Z5߫'l0v݆7Q,4Gf-M؎9t`**&4f4D $)"ߕD=D8bƔ#1>ˡ  1 1xzg G94}YH%YqU5܃:`(M2í M@Zƀᅲzr2Yypc^ؔwXmNp߭*)qȦy !t"o:}V\Sc}5d 3>ZcQ\2DB$H'"DƢ$mGPm@>cN LsD3ȓ,bq1 Ew\=#P=g?x54irbQ$|r|InS<ϐtrӐ=!ӻHܘsfAZTWP?w4D|w"?;6l1vAI -)O pP߾.`~r"z;6lf SLqp#FG޹6l#QFB H͛6ZA?MvzPu˄c9w xH\ovlٱ|+|Q+D/eNYԸ@F??cf͘m:ܞL9^Yċ{cQ;;kf͛s~.惹q:D-dnNjsQ 80|Lǟ`K?kpvteґXEyGٳb\4 ) 㜾l3L#)kuڝnyjuye$]rwf͛.wHBHFv@ Aٳdu 4J? ?e_+=RuIO4 ;=>>v|I~:oelv#$ yGSܟ}3!Kp NB=MT3); 5w"Gw?7q ~||Wy|u/(6ʨG$Dֻ-*<H%ucx튫N`:ycx,R.Id~', lYNfa# 6уzQA%Hqdǁ܂eIq)I9؇HzMYE` HYa*/bāD(1{dzalili9\9"rTfX홛-'\e'-i͊cFY.-qYNS&[e+6cS f3buFeQHɰ;᫖Z`xM+@2æ,4}Br{bJ `;ƨi|6v䎆UNF;tE Om8bGek&fZ4lq7.&cME˜@|3|[З@oN 5'!۸5ӊG3)n| Ğ#-0繯§|b>OdS3KPesf1f9l $]UWSۨ): rSEGkӦ wP7: Z# A}  K>UQ8?eYL5U"^&aA6|pZ`ָs4vv*be0S(ː{ȒY,NoEɩz 1jEԻ mo1AZ|qY)s5zWlfcVa`dWͤks,.T^r5SWo8O+K6NQAs ;dg{,z} 1;NQfm>xї@GF؏C\U[ Lew.Dc3 "%V@TЏ z(vL 8d noHM_vN*i"IuHS~&=(O|$'Yj OqVλϛG( e^;CEljߡ'Rx㕊 _ƅo q<рiKDSa ᮩ?p/0@zg195f=ut:̤vab1~.g 6~ Ko\OPw̠٬7GjR⣵ 6lS@;l V$ 'mٳflw߮XZSMFrﭾ%ٳf̪햣3-=h~[U6&BNf͛wڛ#~:,(Qɰ]zW.ٳe"mSf`;tr˞kpDF; wٳfƋC46 -OL2l7' rpy'> qH@͛6PeݱrWauw]xF/A환 yK=T/͛6bKV]3i9;dIw$vlٲ52;6lن^P—f͛6HWvtYu,m( %vv9:N!잞΂TҔ|evҀn݀7Jl~=?h飨-B]c!Wfv($9CM=>cO i8$E'OdTt`cI̼ܣzl}rb`匨DN8V1qkm)ǃq3*Lrbj7ǃ vi=.[:oQvF;aZaYn]jAncKw%?͓fZUQGmNycW Z ɦ˳ܝcw37|^U1H lV?+\VtP3=bRwFOߋFx=)qPG)2ԝ$=Lrr;{""lأߺ3/0ЕЍ/2X$܏Iv ,W~ O쉜Q=O V4#ޤT(E1HC1"~۱U_@u$BTW(H7>M|]"1s@w h$( Ln=le3zc f#| &[>\;qBPv,s 28%R35++1Hrxyaّb?z"~ :0l7[4I*mt@/p%bkwlG^앭sw-Aj.2e2kʼn!)]ʶ#)X',MlH_ZPZrGJD'bqtFb` [;sXR'jAz1#Li&PA+mOV#,;' 0渌ybFw c`A(`PwƜ $i3>ڃnvN,aSUƘ#9IŚc2+cߑk8#|DVǭ/7=[ʪL] ݼ*KF{c: d'Lއʄ5P~d(yws* MrF#ITBv˒ UdarHoO|y Dqr܆5CƨFmTVJq;caڧ<ڵ1o=ii7|菳?ao(\JF`> ă 7"椓 5n=+}t5cq]F1aShH$ef5_ɱ_M;}!-9,y >ci9D Őߥ|3½c@T1t`EZMHT`0x; HT-L+bIgIǫ-yәǮP:cSg*d%T YS I1:R )n1f\q f͎(1S|pߧLk#~p{f͛*UXMs绳f͘tlq1*;ɰVwvlٱN\7b!Ε=qNSڠ߽p7>d:\ q}  6 %Qx;acsŮ8ӊ[*֥(,@glՎcĎ[P seǶcbu߹m;YcH@Ĩ: @y;^͍BsH20@,+b|aLNoSQ3sBǗn hEbR+y񚊏5#`xg'f0޸W4ՒF2"~~]Zr:bMu04 CutqOUV?~(OSp>8 0a[Ž_بfߋKN"kLZtM0/HzJGNFY/ p|"A LJ@'">o3L?o\c }$ T?#\Ld'bNdןn|@8z+jw 1GTTГֆBAx'Qz V+#Eё-.[ y zjx۷"qBHsƲoj: Ʋ;lwۘ abǦ4H3y& j1!w[m)-bm)I''xcĴ?f9G\@w͕D1dt( P?wʝjM1U+^1 +\ Z]Gfk)J/!ԌY%rW"k" v >J2r~uG5kz$/@3D~g))<^ *-F?_mgV9:( Zlqf^-Ӂ8v۲' c?ø6lؗ.b2";`6]6lpP2+0NQ#k ٳf'ȝ_a2lzݛ6lƒ-rh3;,kRw2}]zX}S?:{kjYu>s?ٳf&͚SQ˞fy V<H;6l^y8N͛6VlLUٳff6lٳe]6lٱWf͛6lٱWf͛/6lRٳenF]eat#&Ne?x!t`kY)"nG߰g/fjFAr=`n t2G!0uQx9jHe4#ɻ1Wvx][{c3j>bćWشk0CQbpB`q2+:)V]qǏyeiLrbN}fO+*cESLq9wAD@ך'O)+%牐kS j ^&zǬ"lcw_*+<^u%9 _((ґ@7įXUQjk\Z󕽶*_)ڣu>4h%Ւ [c֧֮Mu7f 5I=sQ\9Plj6*$yWeg V\#|rU:pxgDXvK,Ǹ#jTLP8o}r mt+U r⎸ pBvc'|. G{qaq1A|iS ԮS)]2;{Bgn6WLqя&XPoC5>]U@~ع4-]凡^(fXF\d#u^U<1'،DlhsC^w|,MXHE;Q^I"ݺ'Z2ֵ]j{BC]1dsj h R@QX}刊=6sP>I >X\:rC4\ x.qˏ1@ (wˡf%|p?bA҃6"}'1Nф?Oߍ:ς't@WG|\B#Ϣ)bzr0wאfsjj퉝JKї<-$}R7EX7QޫW6/21ni)'۸MGp-ZT"I y~Z  0#ʼnܘSj52Ɍu&7W~4-~'o*=n.^ D S%E円SOU1V?~S;8IMvVn$q͒Zu?y1v{T4dNCv~';b5LA="9AӉ?3LfnΟdzǁ]FC1.3{ϳ3x9ɖ!g %%YnYFHəZ {ٹ#u+y\Y'lHDqeèؤ' MH =&LY%?1:cq؀Q(1._jx{G&-z J9oi*ePcQ.epclqDed0{~mGLP U1*Xw[JʡS66; eO6Laa\ٳe / 0W*W!,ȖNű]q:僕ի1rbbu͕x񍪗lDح{`Ǧ"QB%ݨBgMYaY8) /Ygc8b8Ĩ|> E؎Γ&r]#cQt%Vέ%ڷSX<$"E*Jy8$ܜCvZ[ˎQzՎ̗sv7`2jI |&`ŇCs+䦤}_U~JrШ r#jE GƅG}'̤d ܠ# 5&YaZIހb*G\Qۮ8BNeX-HPb3\_s3DO!ԕSnL#r8pK ݏ) DCCMjqâĞfOHw.1H )_lԦsyI#87pNݩڧ3QFu & $gcϹ;S(F @WbF#;S @퉰=@U(vyPA78{:ZYò_lN5d"rYWVVP#WPteqNS_fB;fKV)+V7"pHTt1MDh>̣p#Ņ EG qxY D2!7q'~bR%V鏚6q]Ԋdq^ t"xb)Z8CѨhzV}Fi׃kLTeRwƇMuc;:g~AmzWc9^푇cȏzѢF QzG$2+~t䄸*x-E=F0؜pw9*6Vc2o5^;7('9& RY@L8NIR$cv*ݗCcWV<_e,zR)!`Hݗ@2WgĂwY=F_ȨSᒰt:v18C?S*HS͊#_N"9tˆ;钺) -c~G,x#j9N.1E3܎؜AL~V:d5=!+1Ä%*m慡8<2=kˤ}e-H3Æ j,aDo%ٳcjGĞ]1U;V?tQ.2CԻ6lذ낚 yp{\:ٳb2xU'"قaϞ9;_Mc>AW/ٳfcǮ g$3 ~}A^%,8 łrvlٳf͗vlٲe]6lٱWf͛6lٱWf͛6lٱWf͛6lثf͕/6*ٳf͛7|)vlٳe]6l2f͛6lٳaCf͛/6lUٳf6Wzma&}8~T~6)B,.cwVSB3}~{2|bz.Gw#]97,DCrSq(Fف 8SiZZb9K7K0-ff:6A8LtPGB:t["Q͗LoL6H}\e5Gь-6j'(`olx];|lrvƳ*KS/q'(Ɠ]Ջ o,LN49 dR*j%gqlo,rYU͕JwQNUre6jd%erf;lߚ+wf͛ JsLCa2J y~#+6l_lF8\G`nYD : |5Y7ݲ%;cīq0M 8xflɎ X=9cU#A@iN=d>˶;;S_ >+_a?HF'߀jr/VO%/Ҹ?,qgfq4M(8#.W3N8?gD|#ұ}^=U~h-/Mة܌oT$jYxxrd#2(V1w\ *8tR{WŽ`;f Q9F7~~X[Nʝx8ż2/_1*GU0Y0;(0&[Jb핃=H(DlFv0r 3G8e>a,ۆBЙAH3= ָ^F@16%iOeaSٱW#9e|[QsVy}9e._lt`~I{?~QdA8Zڐ7ȫJߴqz9>r&_u8vÂ#Rcsd{USfȸ/O+`q#rOrr#Q! wYic)}d{]**a|3Q#7GďH D,sXRcVcoك ֘5_knA7 +}͏i211ˣ8+0}d6;Uq]%ͲýrBQldȻ|Se0frzu1w213̈vS7u̳F~@g;8gHSȌx{bc=,(/qU;d&=Ke#h9M&xvʠBXLJPcF1俘 !qORݿf08bM7*ƽqC["=ͱct-儌)C`LƷSYۦ;O38܌0)Z `rv6mqX>>@Upcz `o P\8NǨľFZ۶-,Ii^ց kJbީ=č^[0pP|;1yY8cAgf}NNFpX|#p@z8mQ;rj Z/@kNDK@G?bjxusJU?׏k6l؈Cb 3+}gٳfU8.A4DFnOL&Dqwk#g$c2;6l  fl_o~͛6͛/9vlٳee—f͛6jf]6le/6*ٳeS6^lUٳf͛6lPٳf͛51Kf͛6jf͛6lyWf͛6l٩]6lٲaCf͛53evlٳee.͛6V^lثf͛6lثf͛6lثf͛G}{W( id&3Ŏr1?cbp6fǵJ"?$G;J"G^$q7a.J)\$yLʼn8ٍWl#/Ϭ>Lב͕Lyf͛53f];͛6V]2^vlٲ.b͛6lٳb͛6Jy/B('ce'q#=g'n(Ký2𾣺<1ޠ'3#7 H{7d.9c#䓇V?|(hF{1:CmSb a=y/ڏM7"@fLkZ> 8S'8aOF'A_ i\oNacw~K> |&|x0C|c8W?u9f0Ƙ +z 3Vao|2#჊ ޹ /@P,,yh8)tj,mG!+Qe?PNn8*wʨ 6/#zea7 T9d|lG+ӯliw3 \D̀'qMS1r1/X1`q%̜ZKޢo9qY  i UU=F*`&D1n5LDÿL.b{\t :e $$v}3Ƕ`pJ ZeI5xŒCqaP 1VZEiJ$2O68m3 Hcc@F2,٧eqP}¸l!s/B1;ă'/!d M2? _Lf9|B 甬q3\|s] ÎM]gmDC+P|PF'&je;cZ)'m> b%WX, J3/ٳaub1?F[>3/?&W+6 .y]Ef@{#oUuQG8/ypgu w+3 xlbOwW+pg/YeWZ88fG>J/֯|kJ<1Q}`e,+{Lz<2{`$x`oTE]rTvT䙹GW+C)Fɕ@d8)<#WQ# IdW*9㐌{(/řYp/7-+(B8X>8Wa>rR$ Ȭh]ʢN; VHˎtq#qV͛65Yz9~_,8y"Cf͉͛9ǁvlٳf͗6lYb͛6Vl.͛6V]2SvlٲS/51Wf͛*6lT͗vlٲe]6lyf͛+/6lSN͛6ly6lt͊6lYb͛6Vlثf͕Lf˥qvlٲ pLSN͛6W|.x;6loL N͛66LV6ltLSN͛6U3SLiٳfʦl.͛6Vlvl4f͛0karQ_⿫?߆==|J; <)?? a"8qU tw [-!hsq81}??S =0q'v?-@"?Ԗ9|pz_S >Xh8_OaDGY Z}=8%\}q8eǷOv#mR?W+q8;>ƣ'IťIx8x}:2U8S qx8*r&phzjqe͒K*v8W<PyF˗.~9bWC!lǏMG)I+ƿ O8uUO_㏃0B_c %9t>$MŸr/ų-au8cP #=~8"s/rW oO.8T9*` 14'=),RZeף'?æWWiGWn|py16#(v`'/P_)$y<0通;=cG#ɣE'2b3SnTcd030?izKij6YFGLaԩ6"TpX#vj͆H³޿~{ n5NVl6.݆o9DнS#9|Vl6/&oaVl=Ke|srog.-#o a1u1?3bU؇9JU:ƶl=rfʓ鈎4ܨ6lؼ~xbIFnc;7&a1JQ؃{f͏ 39C7-8=:YKcf͏`:/\kN4)qA ۬' > endobj 420 0 obj <> endobj 421 0 obj <> endobj 422 0 obj <> endobj 423 0 obj <> endobj 78 0 obj <> endobj 79 0 obj <> endobj 424 0 obj <> endobj 425 0 obj <>stream HU{Tewf֨3*[Qy+>PPP^+,]\V!!iKՊD* ""jXHi4Jqܙ}ݫ"4NJbgF̍NДkV%N%i$~ oh+?,זB#]~ٴBGAhsמC8TAQ1 sQA=$(8=d*(w2/}fI!Q||c:@1j# ML*" b " f"Eg N&bTU*dQ;_hRaS")ʢji7:B9lud9^! ɮ$oi3^,4:cck^'xcvH7PC^ǢRC Iަh=YBۻ1e4<`ltŎi4H3 !6j1|r aqAj^67\+G P(1HWHV(t?YLOME Ɖhp3,08 ! `$v v18vb,)b” D)фK{X[훒p)>B̂4E94.tsݙf*8fѼب3,i2 榖Wowa ÖJ=cRJ1I,_*%acRB? K($Q̧JY`!>(yˉ`x<́l|)U Y^$ފćfK򒎳papsaI)H[ 51X(%a󐆳8,$ cр DXG5 x{l܀ bq璿wwGɣ-KiOاB~l-}ٽBvȠϽ9j]G& stt&阻 `4HyVAJ>ؼ*3TECUiXM^2QLX(ט5$ww5:5B,xp,Vb;2_F!LuCh" K&sLtY  66 zPAA'p0h9,D#\ssos|L嶮ƫ[zXAynH-=/g!|o@DWp&ゲQ$D99Px6 ,Sɳrô"[AmXኰ6/ { a<ǔJ-zʻgovs_޿gK$\t0inR%{8=+yŘj_S_hQ$!)+8H:r5K̺jyjtM+F܋| DWUAE}3hliP Eb] Ĝ$ }F %"cOfXKnre'H&e-]ۭ%Gk6w_ q]zQ?ߖ"\-ޭnUbi{^ˢég455&/iԖ4Vn@ߊ AY/؀VA+H:K{W_wcmec/fLVxLxLa0 v+K#^TcMEe@"Y%7yP1Ա}TX~!y ƝT뫓 N$n$M 4Cb-h+_%EdXzD 'JT endstream endobj 426 0 obj <> endobj 427 0 obj <>stream HUkTT>qf3"OqE%5(SXADL"*I[clL110F*b|ĔH}uߙs!vZq9gϷeuW,[V(+kNQ̬2@XOz".Zf͛ybPg?Zҏb٘qeXpA2[l̈ ee J2:6ĖZj˛t<2Äx1bpfb 3S8fyeJ{c5QL ST2]-`ϳx-Ƿg|By!dŝެw!'>};Mo0\Řd|Ӹ^v puTwSO܁=x܂zע# ݾTۭ,—Oc>M<6WJ8eOFcUVp1i=-㫒%&/T9ג oa\ KsP\HuTH 9&Ts T f" eJDZ>X 6Sh6xΊ'֜z3!jt7hm/TQ{Ohxp8dbyl0rǕ;䴢"8QkB#0T"DHhg`Tw%*GW4D`5<8"&LOV,.h^a~xZmm7pJk)v9*^̐|5ׂ;")~C}2I71>z*2bM)p+8^&56,_e!Lz|祦ɟQkĝXӞR ok@ SP [;{~2=(aT],Z(Cݞj(CTGLJ'dK~o"vٮ4fD@v$cafg!D$ƌ4` ck$/Wg/.K*}ZկL>} vdTNB>T@Z#\攜ARaz"TA,cnx>st9v07˙*EȅTƇum2K18_{8*08cz٨E_H1Y]o>Όӑ 'ue3bg \CrqW4y3^ݯIL\WsNBҀj2v(y܀, nCOu2v )2SVrk!27!][EMx>xQ@Rk>ϘXo%Z"έTHiD2SpXlfLiOEm3ley1yI3mLm,lXAM,t.xV}%T= zdnû{8M4OZُgve.myjV:9 LMa$ݕ}Xم7xzC~%k_NОs|2EXi6oM4=*e:G}x(]>~aZStv>*Ό#e JYdž5u7# i ?ȅ-]ĺ譡"8*':>ۻb &C(h*XCA]Xh,U92eBETw\@ "SNf]_oޝ{?Lx938I&D)M7 >,h37kod褅pR\qmZ §8 ṳ JBQfn,mެ 9-LIDl_y0A=V勼rZ <&D[_Iz6];z aiqTJVA,.jExiŀ T `"VSlt4mTyyE1[ZECn_>zMن"mz:N᧤h0_F(» %2rdwTq┅Qi(յWxp1lMס.%]0"$#^A@®DC:^tѪuVUًPґy)Va,.[O|F+r{>B6s%ʒ=.8Դ g:1+|-E]z\EQne=Bc8DvS֢XV8Ӷ8xDו<",--Z$z݁*Ugό'_=tnT߿:PqX_ݤxd`DΐH]3?%Lk;N޳O#8$d^D,io}eB\IkJ7P|o@/"Na olEu|˺ 4\> Gihll0m~v~LIPݓ-ᅛE#~8>LD\EiUk z0ъdTnL#Uzp8ם|P(xnsĭ)BzIQ bK]{WP@#r%,ef21{D:[ 2]Or%׵sJژ4'F상S3w`j='9'/7m.L.xdE,A̤0u+<.&xZP5]GH/V2?975zwcI2NhRwlpH5o{, qkA-2'hW:k=2ϪS]~'87CHy*><΂#v$(vXMlMx0w39|Dl01D endstream endobj 428 0 obj <> endobj 429 0 obj <>stream HTTyPwAFVcz(xD!BE6jB<EA<6n%^auSh]ݰ9иF&Sjꊪ2GUUiPcZY]YϘ$0 :d3LLb<33X)FLlcLcL>||nN4WO/l5{ p_󡼓S`;g=UC E?IDǟZ=Vn~̟ء>NC{G$8:KX1z, N?g@5SYFy|Dtj9p>@^a|:\\7zX`l<ķaD$fr>AcT`g'8k i ݱQOذ/tn ߓ^7"8=mZ/\r/ƉzY?fDӜ4\R*:20FH <.o"@+C0QZ#~v}-\Dz *z*=͹䲸";7 II*W4R4(FFgGRpQ |-._Ў["w)⨍(TrR4HF, (ES,TR0ƇݜΨ?sao3x!b/!3Q c+n05哝D9au0vqKV@QJ$ M#81a)M xQ SҜ]z[Qw1Q4+XH9LHBH)8q"U(m CJJhZ%N]ZL(Wj)O]UtTOe/N|,sS*k A Q/Ý%DarP b:MN+ʒ OKif{ٚpj|j엓^b)]=i{\ TMyΣa@$|F='6t"{eTPL IŒDF$3Y')RD 螂Dɘ+(F R.fB߈Kp&C=-oiZi[(--\iҴl{T۰Iij\&$ iQf17h:W-b)bI`݋jw3Ƌ G(ŵsUcwHi]Kvb_(+SOGÊ'2$r<> endobj 431 0 obj <>stream HUkP=. xPh1ܼVk3U+mMbx!^1,Udj**hϞ]L8;}3Nj1 f)ӜʅuU+^ZVE;m[+Y-[^l_ Thлֈ``ͮɊ F%UQ//OrVUEZ_rE}eEda1CLÌe~0FY0 `4&O0E? نCWWWW׿kw{Y쳎pn |#׌&!iom~Z!Pp?+02pKAAMiŠmHcHGР)kCυ>dF.=)\;"uc+]C"Z< `>OfukCkH:9z UH)v)gSLi*G[Ghi:c:11u[.?~dh[lK:Jv.)O{( )T_F Q5O+kBéZ0QȘU&IH]pPG;.l3|QZ4KMU,lETBH-Nlr)c) C6=2_p4`X"rD"8\:Q}]Ć_u!;t1bZ)J 3EIKp=i~^ם[}oࣈ4u.P$x qIߗp ::<߫"ljyA;GbUr}k--;-ͻKml[_i~Qi_STh5& Q}jXJgV_X$s{ b-ZG(FTe)69ǂ^DBT#YέK%+MT;WABް`Zr^KE,e/"Y+4^p_4UIMg11ަ $.ru9ZdL^'P] YDY HzuN#i$?e]wLihG\؄xSa=XltF%gJήrWnKw_=uJ>?mfiTIc$N-T:w:%g]ynI^9O)F>~XYp]w.atW Ԃw i"V1{F}YS6;wAqAfcɾY?}Vf,E Bu ͔WM?tv~'O>Eĥ"h7 zA7Wo0xCV KUE3ig:u볇E!HĪ9 I"62d_p.LY ˺F "݆V QnkVG0Õ) ӿM(>W[8$8cQ PJZ&L. C-R0 qO' (!Vɘ|myB539E1˜Hk<:tX%aš>Oz{= M50戳Ƴ#gX%geMyEu^qRZ{sA#TT(QA*("huF_S>b"jh*Ft+1T|(1ȹg%Lgvvv{s~'B17B c93dJi/, zj<sT{( ,<ўehls)H7o tɺv0qa;6%= 0@ z+I']c,tl$Ÿ͑K#y!|Q-q!xJ$ՠ,sˋu,h:Ph0h{5OwfdOE> p1c`2>od[bߋ S-R Fr.p.imdvp5?( pV0ɜ8!T Ng[+2\|yH-whNfFu;T ;rjm˝Up* ViJ@|{XpKFPL0$5 50(ѯA9s~O I0Na@hx~F[D" % dB:}+THFQmXZ;ˎ]%~"ÿFwJU">8Y" ẽV;"e'ʓh-wѪֆɲ&*x}?eT`@Y"ş4\B/M` 2TC5xhެd4T8S v)^C "3bթH!'lq nxB?|y3g|e?!ZP {z=dPWVyv dOIH`qU!DK XX"DI5TiJE @}"ɍ[Thj[ }dc-X>qET%&-%17BvDIɸ-*S"M7gp:~^dXE xRkuzN?{(Vq { >C4żӻ7 dE)8C6D8Ln<'uuS"O{Œ$':kp''8`j 'ڝRIf?^j/ ZJu0F3ڄ D,2{ &;[ aV+UJ?xmT}3[we˖̓-)';h{H4eL/ܲD Sk%#䨲 q f\mIM,m"TW ?F0j1=7]lq:_ 8^Da:8fزt):Al@= i*`)}l8%hMH?A]2gxHkgұu`Mf}ӗ'7a`96DϋQz3;BQoƫ>(*}MC{ 2 8cDjJ#i b%" SV&E4Z$ ~&a5̖I.NJ6`er۳t-;>}$fL0bTjQgk? 5☏c>5VԾ՗@CD) 2.&F,q.BFˀK3>_9 W!hG*$\L} 4 8UfU8]z,#%)*ū!;.LJs۬ sТP4F۩e}2dTnY`B[s{g<ظ]ZfGVLNF)Qv6S.{ο~Y+Z*c7{_Ժqu3Jw_=I̯!F8 bg]A]ϯyD[TpW|ڲN/=Z)YR@ʲ  $ i~nM6׾/jiPDS۹n ʛ hc,NE͙űHs+ǫK5Yp`< b# c]KMNIn Ba[ t ]w;, t2)hN-CgX&8El2`?AfArj:J#na`Dr?JQ| W 633Uבr<1]~`~m<`f@=-pj^{ KFAV0A@Ya0]}h ( B,F -Cha< 2}Z{-{^SGmbmo䕱6-?ir%VŚv]b~_M4/G7bXrFB(^hi{z,`9{H *rwrx-8`V8 w81R)hL]@2H~P E$9MH(9>c*E5Erx*{byW8wP y  0Էvke~p&Rve+㉕J~PtReŲ$.ބ+G7ztw,n=[;F3k ZBIş: i?]fܕ`I^`e؝ endstream endobj 432 0 obj <> endobj 433 0 obj <>stream HUyPg.g6'rQP( KH;`8*Yx`\4kMڸ+.I,Xƭ`uqqMeTuUw #؅RӳRW<4lC#xNOs9N)+ vfy޽޹/w${Ox˫ccW,"65|lXFe@TDdde%ipU*(R]z?FƨLwe2a !c]xIaEJ&݃Q2[ %q|.&ȼ\->up?'Lh[RQT){jP夙OjQ,O'k'VWijg`*Z?lsa_wql!OM S CN,؝nhwNXqs|Bt?B``Q2Q-nMIvXN7a0˩ZCᄫ⩚/aXyA~zpۙz@"ZlxcJ1z=n״l77ƅèg98P:\ҩE[=,1.q Ni>A!g$kƌJ5/_pC&cn.#+|H$8WS _h [mQm u e-ݤoeAo)m87 8!$c$s_Ԉľ* $hy[oza z0c'4!v#@z!|LFyHP>hP&ڬX+eŏb0+1ڀ \Cw Q ,si]5AC# r&0_,$bra3 A_}vC"wX>0Q5~SbD]ԛ`#j/K)g) zvdq[C8bk5ؖcRfX oMc[mZIP {'[FD_a5@MH3aPэ]wͮJ,~>cdO@@ Yl?}q/5i՜d@lZ!DPa@>%q*cކ6|Ρb<$w=kp+ĢlR=F(~^W!K4E6 F?>H_ [ BP^ʛB'"곎T=z7a1= Q)CMA.1]F8yGci/B hb Azi®&-$އJȤpL{,mƖ܈)AAE@mCƖ>{PbhhͪwHlB+D©H΁YSOu| /ѡC(ÉY2æ,1 (hmH<8!PlZZ _2)ͤKi V{3F1*=V lUI3 hhgHiLiLrʐGM8Дھ-Ws-./| DLz}Cйq~{Y@ 2f=0h8CUUoĝQ1M &|L>/}]E 5i#aTՙ$bLpM:GdH Khw &˄b6޲B 2Qm7` Vf`C"fC8pmPcb( ;DY"E_玅DZwk3bcGp֡+aQ<[=~}E+337.ܝ*pCVDۃ9\M܁z9Xă+ 'Hem0mP l!^,jӬxNw^S+e80ۈNz7E/ w8Kce}U:ŏmZSmSKӆ5}e`t?>b}y)KS+ѣ> ({ (Tʈv `,%k \ p"IEC?=Nq/6'#Ff$auE%\ҩad76goz}TcZWVpkI`ICfDw;IV&}P(aBOpFC ="0[SH" -KTz=Ym_><+7*Ky[y.Sll`#2 *bQ1a7r>9:4TnjgN+K)m1F D](f#9!=!=K9׷0g/MIm.I_yׁ L/HB5$XlVH 7/Z SɃzl `uUxHSU?f !1A"e^d4a86gj :l=Lo=;|14YZY/rW)SoD7>Eoa;+jF /~Q`dO*NhF1N 켚lN[#9%atԟ `8NIIVwңCqpD#,OX_شu8{Г-yg^I -޲~\ݹ][ҋҋuU >VY}YT19Y<-7mmul$=uo*J(D[ApP Xֲ+sSAA{Y-Z< STZ(U&#a8ќla+ *Ęo-$(&q}p،."P)E 5AdDI2{IRlYm2MԵ-wmѠ  Z^d {BfάBoùq>ﳥĎ>YM$%ns00ݷtۉӣK13cY0ҖN 6arԶa+pNW?ǫrLEJY4l@%W0bTod#oFV58MQ{@t};a[\^łm*W\]cisRF)kĮ?u&U[^ !fC/Zi`!1z#eŠV%:KA-f QV1bAʢܦnLKq!p%R.e@:x8!X4  q :Lpp*TS%$eӂ s_`ȗµAy422 tN=Q^SK&'FQ < I&*:h`vAUBLh9bL>$lva-\+j]ٮUwH6 _-f)H;(2XsJjG#/q3ihI;]%+g} .m endstream endobj 434 0 obj <> endobj 435 0 obj <>stream Hbd`ad`ddvtrwv,LuIL [f!CG_լr > endobj 437 0 obj <>stream HTOOHQvhij̷l.,NH&YZwNxC$"u7 @"#!aw.w=&dv劁 *lJa>p??w)n@["W_ endstream endobj 438 0 obj <> endobj 439 0 obj <>stream HlkPd[Q0vGlJqTL*]h,bPP f7C<[XX =bf@ n]&!LR*RT [=u[+*l_yXՑT+:ePԮ wW*xE/ٴ } +l|5$^A~<^i)o; N<g'y}CL͂'PBga`MњؚO-sїI s)C ]νnxbqqMŋ%++V:PPpF<__~zdC놾eeeexOZiS 涂y+s{$ڞ6&ia+i G@beZ{ہ|N)$9\ΏZ-FGua]H)t1CQ,q)L/LW9nbgUjR;A]>D!5$nWM YaȐc4`DLn S 6!Ays(p=\Le:!g]{% ?1y#R/T VV~>Ї+eRNZn;SzDԄ5>h:߻ S{l?W$ҩlnp =<]Zn{'z^ :0 dj0F9$Q3t`d(qĠW7i2&c^1ki|7!NrD/>!pNJJ};0/b>?K9v5Ƒ BKmEkaivM}Cx4`V U_ ?Qy9y 'ʹ/ٻ-I}]"RQYeh%[ %%A(* _(۩|)Fi])Vp;s?mpn%$N&)3e'`!-3_xtVD;nlh!6a7Ƥ&"L0p Ԍ8MuoqA+H9WeFA_q/z%pi4AY)?7c%!ε,q@=wm&%>oyz| yx"LG;j p/ߗv POGm1Pc){0ʐ؂񓶫 \S*v!)5_R3zHiV!*_cO'ꉺ9C|2#CI6پb>OH=~VLI2:r?蠶W.DNEKh͔UwPޘ4\l z/Q֪$̖+9d!Nބn/Ƚ5UxU#%2)u8&3*Q:v|rȄ1TVL33 I ;p#E?fIwby1l{И9Ocv^k6\oV J-v x]=~tK~'dqvA{HA:;M ~*U-+fŞԍȍlj4?;YziQdH.BCN J"{S#V?1D4^Sc56+QB-CX=MqjQyI-nĎbS7j%ӹl!N6CfvAY=>v֡\/ MOo,M`qjܓF8 /'qNnp;vkw,Fh18[(v}ܫkN(۫ # np)Ӭpʗ0Ƹ0=HŸMXW'CvzN!໐~2Ryqu9\W3UKNS?u5vcG{]Mv瞙{Ep\wNnkBEE H $%!!En %1(Vq|Ti]Ng;\{LυN_btϭ֧$再ϲ~GCpI<9'JٜK@Gp;mГ48&,VT &ކkD?< +q#$&IKH <0/-1&ØiEE#zS{`޿ 6dE)k3,V&fM/r#H']"-0säՂSv¡*$/ׅv/UO B^@*顊LȬ"Zb&5I>I#|G~K_nƿv,'wH K:)dF{8Hfc n.fv|v i8H"q/E(| #ϤQRc) LnwS}ak}l,t VCR)e!}C^g'@cNTPd˖i&^ b yyi9`0%P|{|IXR_!pFb ~2h IY}'rrw񝈔L]lrYđJtɉj%bk󉝁 >a#g(dz8]QPF]ֲ˛6$󇦹 11 QHE _2-W~@Cl-2!7߅RȪb#Ԝz j=斍z_eE_ 1K*C Om(ұMb↗Z?R7=W١wi-&u]SUo@7sByBA0\kS)Q CzE3(*VT͋(G`˞~4cԿhq [.-3%ovܜEe+k8jVm$}dׯq憵KJ&/ ^2xF)mSK1uܔ)'̒^?4A6gYA!q5cnUjTEr 6)TnZ# RYUr|T-|Zv՞O-ퟲHkgsCWtuCV3H}uw1v`&8'] ԖfKgU-%o߯ؽG-ɒZj6SnJl,a.]Pu!+@YM6{c53]~ؾ34HE86 پ["lg[m b~[!+wz :V6d564I67TJWf`k]0c;,3+hO+얜|) {N߱h&ܚ zbxd~}7qUtɫWJ`ޕPWw*Ebygn GOZqGȏ h endstream endobj 440 0 obj <> endobj 441 0 obj <>stream HU{PSW<e]].X  @MHB [j] ' <*V>1UשL;={wgs89~~ C"Ñ0.usZ+kӊʒ=fJB ?ŀű~Ǹ7;$L D!L$Y$#d3AI )HmXt؁/¾ _'|2ADRąG"D~N`z+|P'+#_{QIQۢN/Xt4}gaڅQd"c4ń^]dlDXcl[7?E0<ɦ\6 B9) +hgEY $qCIMRF>Ӣʽttm+Ӎ'c9[sWhYuַnpzNd6iw8AU/9L?¦4?n]˗eZZEkiդVFe͛KY~ CN?}-y ~pe:wOp;N-HQC2a<*.\#pTgMwyvN.'K4j=mBR>k w׈жP ?bT7f{zS7n IR!8\a:8X$-ur9(!xZ3c ;4XY?&^"p6޲7&%ѵ8X>ξ|i ``58N~}d@a/~,$Yذ5^gSszExJVtRÉ%8 6ܤ#&Yy)+T1E{L"w /1Î9X:W/v mn袯Fqr{}!C{D\AKf=?y7 Lr许g2\ZL* &4 `xxJ0U:xfa;Vtr.}Д_dzUQX]p]5:.ݑ|"sy5u'oӷE<ǕHLJNY(~?$x!yrE!幺Dn4 gԓ̥n.0(|raO*1sw]=睓{z6+"cz%k*,J{L× nim8xKΑLTOŢO1pbfJfVQ\a8o<˛fKjWhr 7N`-ҋȇb!{죟}nwhZ6jn#lm }8"suJkPWĶ煹>k鲋Dsxt2~o95<:\ײ&X:ZŨt ngt{KM$Z#jZr\aԉ 8e{}=Qf_q=Wx쓂~0˵Iy[fҵy Pbn;~d]O. sC<`\{;vxMni IM3\;ߔB8wB<.b*kߛ]8@-ȩHA&`UVSXo=T{uܣ;iiRFɶ4nْ[y%H ؀}m'?o06JI5L* h:*\tAq{@ԟiUYIk=$*{q`V_5ѮKD6PR!_h統D]QdmylX[=_5_ ?C}iи~?O0 yc]m<.찊Cqh+`wy^G0.7e09ZR 'tڷ|ĬPw LZoIAJ ^OO~>ƽ 7Rh8 nH +ut]=s:)P)WK@EufEbH1~0CMQJwXkK0~I~́ߴkTNZE(Ѻm:NWei:3:`ptr%:R9q}SV%W)565M& cl!--M6>xQop0bcnmh0)z^TFVjMTS4m^Kٱtܯ ,` h&r=2n01Vh;@pYhO*sTN) Vɳ?ۼج\p6AsOɳ]kv7LR l.4 ̓l܌yPX@  a61޳?ʂA ){ħXb1yK;ښAl(:O缅S5TMjE,zht'}s+9!5 jW|"4 z.z&ĄhbNctu'3\˩rpZ+jEƂ7Ƀ͡9_yԊhΏrHT6D[$:{@atSvF $ WDKk&96qT1Cdo AAF@ .=oJRRBZ= }[0 , ёi0j=4’+N(v;Pw >kklMbG)Qx#!W,A璧8QC %l0륿RoUaBƤy2A75E'SG$wURPR#ĦwϑF_t _U|h 3/cΐ%@v~@YCr/pxQ(kE2t%x 2oFKM.lkA68ޑ~ =%ݝ#2b5f0眎ǖ9|a:^~Ays<؊]/xP 3vEY~@{2zU])ebTNw7_? n4B}g,Bⴈ5.;lsc|!)D֝c(7aq)Ysߺ#[^@Y6A"\^ X(VwX$n ls :X< J"FEJ<0Xs`ڤBPu1Whqd.]7x95f+!1TwgAvB' 4.mU0(_k)6&[{M@,ӊ[5ϐ{X>-=B߆ mPȪ#A*)9Z0nYwtyҋdڒh Q!Q7am&Ýn/9>uQ.w` Bvu˘Q$fTJLJ9PE_;dzw7%̌>ft y#Cj mfK={+{.j_Ē@@yX`M p ܳ3G?bH+vCܕvы-}h +3_g ?Q~ʹiajY/}]ڌ+wb ʿgV==Q/~Gc}w3Y ~)|gg~U@Sn}ymd}myktE/{YӥW.hs; }6?"@~HH=mX={;u?dD;h v~4X `Ɗ endstream endobj 71 0 obj <> endobj 72 0 obj <> endobj 73 0 obj <> endobj 74 0 obj <> endobj 75 0 obj <> endobj 76 0 obj <> endobj 77 0 obj <> endobj 137 0 obj <> endobj 138 0 obj <> endobj 442 0 obj <> endobj 444 0 obj <> endobj 446 0 obj <> endobj 448 0 obj <> endobj 450 0 obj <> endobj 452 0 obj <> endobj 443 0 obj <>stream HTMo0 >v@i RUaZ`:@mH'mNvѶ#$/7'imq ZH3[3N5vP6mӃR"y06ҹ|[{[AvhGPUPc#ݣvOCHTn! tjqpڠdVeh1QĊsc>1󰕋JLKIq9'^/u=q9L9Kb6 1ON؆ .$Ev$)rbV,uV,LљKq_J'hȓegkFXy]x~oVW endstream endobj 445 0 obj <>stream HTQn0+*!HRCjމYRb,C(mY2Nvv$~0'lq Y L.|M_;HH|GHި8NMxL y ^`.?>8])T4؊dTGHK7^c 6k{A*@Yh5skj/4E8Λ=:`ZU,>lSY ߽V4{9>stream HTn0EYR;E* $}=r‚6Rk;8fn55 ϝ4Wb2޶u8+5ow cAh'Hi`ś'UqN! m)^3B% ԫ\TO#Y$4k qa[VxG\iBzN-q/ *rRpBK$% % KV",I(RdK\ bN jM"cABIЅXeDzGn=H8qug?qka endstream endobj 449 0 obj <>stream HTPN0 +|ܴCڈBa%nDM{ dK{œ,닅,o >d[kk endstream endobj 451 0 obj <>stream HTMo0 >v!@RTi4>v`QCuR'v^P=TAQq7i\F8chz=롶 I|L3iGPJ7rN.|l݀|q t9d8.~f{hTz@Կ"$e Nj!$ڃ*iC[V[Y;/80BysƜy. %sISҟ\JSz1%UUY /'?-ǽ'CK98Gq^yv#K| 0 endstream endobj 453 0 obj <>stream HTQMo0 +|Chh+!Ӥu= C! ?;f݆~Nj@qsMqps ˡ4ƃ":N\;@U%ꕊgYwCsgXe8^)54&jhoxfC7qg*Oke d+Sk?MH3M)$Ua".vWYk'[Je!`,\ i "*\d;O> endobj 81 0 obj <> endobj 139 0 obj <> endobj 202 0 obj <> endobj 270 0 obj <> endobj 319 0 obj <> endobj 454 0 obj <> endobj 455 0 obj <> endobj 80 0 obj <> endobj 413 0 obj <> endobj 411 0 obj <> endobj 408 0 obj <> endobj 406 0 obj <> endobj 403 0 obj <> endobj 401 0 obj <> endobj 398 0 obj <> endobj 396 0 obj <> endobj 393 0 obj <> endobj 391 0 obj <> endobj 388 0 obj <> endobj 386 0 obj <> endobj 383 0 obj <> endobj 381 0 obj <> endobj 378 0 obj <> endobj 376 0 obj <> endobj 373 0 obj <> endobj 371 0 obj <> endobj 368 0 obj <> endobj 366 0 obj <> endobj 363 0 obj <> endobj 361 0 obj <> endobj 358 0 obj <> endobj 356 0 obj <> endobj 353 0 obj <> endobj 351 0 obj <> endobj 348 0 obj <> endobj 346 0 obj <> endobj 344 0 obj <> endobj 342 0 obj <> endobj 340 0 obj <> endobj 338 0 obj <> endobj 336 0 obj <> endobj 334 0 obj <> endobj 332 0 obj <> endobj 330 0 obj <> endobj 328 0 obj <> endobj 326 0 obj <> endobj 324 0 obj <> endobj 322 0 obj <> endobj 320 0 obj <> endobj 313 0 obj <><><><><><><><><><><><><><><><><><><>]/Pg 270 0 R>> endobj 311 0 obj <> endobj 309 0 obj <> endobj 306 0 obj <> endobj 304 0 obj <> endobj 301 0 obj <> endobj 299 0 obj <> endobj 296 0 obj <> endobj 294 0 obj <> endobj 291 0 obj <> endobj 289 0 obj <> endobj 287 0 obj <> endobj 285 0 obj <> endobj 283 0 obj <> endobj 281 0 obj <> endobj 279 0 obj <> endobj 277 0 obj <> endobj 275 0 obj <> endobj 273 0 obj <> endobj 271 0 obj <> endobj 265 0 obj <><><><><>]/Pg 202 0 R>> endobj 263 0 obj <> endobj 260 0 obj <> endobj 258 0 obj <> endobj 255 0 obj <> endobj 253 0 obj <> endobj 250 0 obj <> endobj 248 0 obj <> endobj 246 0 obj <> endobj 244 0 obj <> endobj 242 0 obj <> endobj 240 0 obj <> endobj 238 0 obj <> endobj 236 0 obj <> endobj 233 0 obj <> endobj 231 0 obj <> endobj 228 0 obj <> endobj 226 0 obj <> endobj 223 0 obj <> endobj 221 0 obj <> endobj 219 0 obj <> endobj 217 0 obj <> endobj 215 0 obj <> endobj 213 0 obj <> endobj 211 0 obj <> endobj 209 0 obj <> endobj 207 0 obj <> endobj 205 0 obj <> endobj 203 0 obj <> endobj 194 0 obj <> endobj 191 0 obj <> endobj 189 0 obj <> endobj 186 0 obj <> endobj 184 0 obj <> endobj 181 0 obj <> endobj 179 0 obj <> endobj 177 0 obj <> endobj 175 0 obj <> endobj 173 0 obj <> endobj 170 0 obj <> endobj 168 0 obj <> endobj 165 0 obj <> endobj 163 0 obj <> endobj 160 0 obj <> endobj 158 0 obj <> endobj 156 0 obj <> endobj 154 0 obj <> endobj 152 0 obj <> endobj 150 0 obj <> endobj 148 0 obj <> endobj 146 0 obj <> endobj 144 0 obj <> endobj 142 0 obj <> endobj 140 0 obj <> endobj 131 0 obj <> endobj 129 0 obj <> endobj 126 0 obj <> endobj 124 0 obj <> endobj 121 0 obj <> endobj 119 0 obj <> endobj 117 0 obj <> endobj 115 0 obj <> endobj 113 0 obj <> endobj 111 0 obj <> endobj 109 0 obj <> endobj 107 0 obj <> endobj 105 0 obj <> endobj 102 0 obj <> endobj 100 0 obj <> endobj 98 0 obj <> endobj 96 0 obj <> endobj 94 0 obj <> endobj 92 0 obj <> endobj 90 0 obj <> endobj 88 0 obj <> endobj 86 0 obj <> endobj 84 0 obj <> endobj 82 0 obj <> endobj 65 0 obj <> endobj 63 0 obj <> endobj 61 0 obj <> endobj 59 0 obj <> endobj 57 0 obj <> endobj 55 0 obj <> endobj 52 0 obj <><><>]/Pg 7 0 R>> endobj 50 0 obj <> endobj 47 0 obj <> endobj 45 0 obj <> endobj 42 0 obj <> endobj 40 0 obj <> endobj 38 0 obj <> endobj 36 0 obj <> endobj 34 0 obj <> endobj 32 0 obj <> endobj 30 0 obj <> endobj 28 0 obj <> endobj 26 0 obj <> endobj 24 0 obj <> endobj 22 0 obj <> endobj 20 0 obj <> endobj 18 0 obj <> endobj 16 0 obj <> endobj 14 0 obj <> endobj 12 0 obj <> endobj 10 0 obj <> endobj 8 0 obj <> endobj 456 0 obj [10 0 R 10 0 R 14 0 R 14 0 R 14 0 R 18 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 22 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 24 0 R 26 0 R 26 0 R 26 0 R 26 0 R 26 0 R 26 0 R 26 0 R 26 0 R 26 0 R 26 0 R 26 0 R 28 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 30 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 32 0 R 34 0 R 36 0 R 36 0 R 36 0 R 36 0 R 36 0 R 36 0 R 36 0 R 42 0 R 42 0 R 42 0 R 44 0 R 42 0 R 42 0 R 42 0 R 42 0 R 42 0 R 47 0 R 47 0 R 47 0 R 49 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 47 0 R 52 0 R 52 0 R 52 0 R 54 0 R 52 0 R 52 0 R 57 0 R 57 0 R 57 0 R 59 0 R 63 0 R 63 0 R 63 0 R 63 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 65 0 R 67 0 R 68 0 R] endobj 457 0 obj [84 0 R 84 0 R 88 0 R 88 0 R 88 0 R 92 0 R 52 0 R 52 0 R 52 0 R 94 0 R 94 0 R 94 0 R 94 0 R 94 0 R 94 0 R 94 0 R 94 0 R 96 0 R 96 0 R 96 0 R 96 0 R 96 0 R 96 0 R 102 0 R 102 0 R 102 0 R 104 0 R 102 0 R 102 0 R 102 0 R 102 0 R 102 0 R 102 0 R 102 0 R 102 0 R 102 0 R 102 0 R 102 0 R 105 0 R 105 0 R 105 0 R 105 0 R 105 0 R 105 0 R 105 0 R 105 0 R 105 0 R 107 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 109 0 R 111 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 113 0 R 115 0 R 115 0 R 115 0 R 121 0 R 121 0 R 123 0 R 121 0 R 121 0 R 121 0 R 126 0 R 126 0 R 128 0 R 126 0 R 126 0 R 126 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 129 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 131 0 R 133 0 R 134 0 R] endobj 458 0 obj [142 0 R 142 0 R 146 0 R 146 0 R 146 0 R 150 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 152 0 R 154 0 R 154 0 R 154 0 R 154 0 R 160 0 R 162 0 R 165 0 R 167 0 R 170 0 R 172 0 R 173 0 R 175 0 R 175 0 R 175 0 R 175 0 R 175 0 R 175 0 R 175 0 R 181 0 R 183 0 R 186 0 R 188 0 R 191 0 R 193 0 R 194 0 R 194 0 R 194 0 R 194 0 R 194 0 R 196 0 R 199 0 R] endobj 459 0 obj [205 0 R 205 0 R 209 0 R 209 0 R 209 0 R 213 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 215 0 R 217 0 R 217 0 R 217 0 R 223 0 R 223 0 R 223 0 R 225 0 R 223 0 R 223 0 R 223 0 R 223 0 R 223 0 R 228 0 R 228 0 R 228 0 R 230 0 R 228 0 R 233 0 R 233 0 R 233 0 R 235 0 R 233 0 R 236 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 238 0 R 240 0 R 240 0 R 240 0 R 240 0 R 240 0 R 240 0 R 242 0 R 242 0 R 242 0 R 242 0 R 242 0 R 242 0 R 242 0 R 242 0 R 242 0 R 242 0 R 244 0 R 244 0 R 244 0 R 250 0 R 250 0 R 252 0 R 250 0 R 250 0 R 250 0 R 250 0 R 250 0 R 255 0 R 255 0 R 257 0 R 255 0 R 260 0 R 260 0 R 262 0 R 260 0 R 263 0 R 265 0 R 265 0 R 265 0 R 265 0 R 267 0 R] endobj 460 0 obj [273 0 R 273 0 R 277 0 R 277 0 R 277 0 R 281 0 R 265 0 R 265 0 R 265 0 R 265 0 R 265 0 R 283 0 R 283 0 R 283 0 R 283 0 R 283 0 R 283 0 R 283 0 R 283 0 R 283 0 R 283 0 R 283 0 R 285 0 R 285 0 R 285 0 R 285 0 R 285 0 R 285 0 R 285 0 R 291 0 R 291 0 R 293 0 R 291 0 R 296 0 R 296 0 R 298 0 R 296 0 R 296 0 R 296 0 R 301 0 R 301 0 R 303 0 R 301 0 R 306 0 R 308 0 R 309 0 R 309 0 R 309 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 311 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 315 0 R 316 0 R] endobj 461 0 obj [322 0 R 322 0 R 326 0 R 326 0 R 326 0 R 330 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 313 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 332 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 334 0 R 336 0 R 336 0 R 336 0 R 336 0 R 336 0 R 336 0 R 336 0 R 336 0 R 336 0 R 338 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 340 0 R 342 0 R 348 0 R 348 0 R 350 0 R 348 0 R 348 0 R 348 0 R 348 0 R 348 0 R 348 0 R 348 0 R 353 0 R 353 0 R 355 0 R 353 0 R 353 0 R 353 0 R 353 0 R 353 0 R 353 0 R 353 0 R 353 0 R 353 0 R 353 0 R 353 0 R 358 0 R 358 0 R 358 0 R 360 0 R 358 0 R 358 0 R 363 0 R 363 0 R 363 0 R 365 0 R 363 0 R 363 0 R 363 0 R 368 0 R 368 0 R 370 0 R 373 0 R 373 0 R 373 0 R 375 0 R 373 0 R 373 0 R 373 0 R 373 0 R 378 0 R 378 0 R 380 0 R 383 0 R 383 0 R 383 0 R 385 0 R 383 0 R 383 0 R 383 0 R 383 0 R 383 0 R 388 0 R 388 0 R 390 0 R 388 0 R 388 0 R 388 0 R 388 0 R 388 0 R 388 0 R 388 0 R 388 0 R 393 0 R 393 0 R 393 0 R 395 0 R 393 0 R 393 0 R 393 0 R 393 0 R 398 0 R 398 0 R 400 0 R 403 0 R 403 0 R 403 0 R 403 0 R 405 0 R 403 0 R 408 0 R 408 0 R 410 0 R 413 0 R 413 0 R 413 0 R 413 0 R 413 0 R 413 0 R 413 0 R 413 0 R 413 0 R 413 0 R 413 0 R 415 0 R 416 0 R] endobj 462 0 obj <> endobj 4 0 obj <>/K 5 0 R>> endobj 463 0 obj << /Dt (D:20190702063752) /JTM (Distiller) >> endobj 464 0 obj /This endobj 465 0 obj << /CP (Distiller) /Fi 464 0 R >> endobj 466 0 obj << /JTF 0 /MB [ 0.000 0.000 603.000 783.000 ]/W [ 0 5 ]>> endobj 467 0 obj << /Fi [ 465 0 R ]/P [ 466 0 R ]>> endobj 468 0 obj << /Dm [ 603.000 783.000 603.000 783.000 ]>> endobj 469 0 obj << /Me 468 0 R >> endobj 470 0 obj << /D [ 467 0 R ]/MS 469 0 R /Type /JobTicketContents >> endobj 471 0 obj << /A [ 463 0 R ]/Cn [ 470 0 R ]/V 1.100 >> endobj 3 0 obj <> endobj 472 0 obj <>stream 2019-07-02T06:37:40-06:00 2019-07-02T06:37:40-06:00 QuarkXPress(R) 14.02 QuarkXPress(R) 14.02 %%DocumentProcessColors: Cyan Magenta Yellow Black %%EndComments Sally Kennedy Layout 1 endstream endobj 1 0 obj <>/QXPr:DeviceNColorants 2 0 R/Lang(en-US)/ViewerPreferences<>>> endobj 2 0 obj <<>> endobj xref 0 473 0000000000 65535 f 0000248837 00000 n 0000249059 00000 n 0000245135 00000 n 0000244488 00000 n 0000131446 00000 n 0000131153 00000 n 0000224565 00000 n 0000238233 00000 n 0000000000 00000 f 0000238184 00000 n 0000000000 00000 f 0000238138 00000 n 0000000000 00000 f 0000238086 00000 n 0000000000 00000 f 0000238040 00000 n 0000000000 00000 f 0000237993 00000 n 0000000000 00000 f 0000237549 00000 n 0000000000 00000 f 0000237468 00000 n 0000000000 00000 f 0000237308 00000 n 0000000000 00000 f 0000237229 00000 n 0000000000 00000 f 0000237181 00000 n 0000000000 00000 f 0000237081 00000 n 0000000000 00000 f 0000236992 00000 n 0000000000 00000 f 0000236943 00000 n 0000000000 00000 f 0000236869 00000 n 0000000000 00000 f 0000236811 00000 n 0000000000 00000 f 0000236759 00000 n 0000000000 00000 f 0000236677 00000 n 0000000000 00000 f 0000000016 00000 n 0000236625 00000 n 0000000000 00000 f 0000236511 00000 n 0000000000 00000 f 0000000067 00000 n 0000236459 00000 n 0000000000 00000 f 0000236299 00000 n 0000000000 00000 f 0000000118 00000 n 0000236245 00000 n 0000000000 00000 f 0000236187 00000 n 0000000000 00000 f 0000236138 00000 n 0000000000 00000 f 0000236084 00000 n 0000000000 00000 f 0000236022 00000 n 0000000000 00000 f 0000235808 00000 n 0000000000 00000 f 0000000169 00000 n 0000000232 00000 n 0000000295 00000 n 0000021721 00000 n 0000216054 00000 n 0000216893 00000 n 0000217524 00000 n 0000218153 00000 n 0000218323 00000 n 0000218941 00000 n 0000219151 00000 n 0000184494 00000 n 0000184653 00000 n 0000225980 00000 n 0000224787 00000 n 0000235762 00000 n 0000000000 00000 f 0000235711 00000 n 0000000000 00000 f 0000235665 00000 n 0000000000 00000 f 0000235612 00000 n 0000000000 00000 f 0000235566 00000 n 0000000000 00000 f 0000235518 00000 n 0000000000 00000 f 0000235448 00000 n 0000000000 00000 f 0000235383 00000 n 0000000000 00000 f 0000235339 00000 n 0000000000 00000 f 0000235284 00000 n 0000000000 00000 f 0000235189 00000 n 0000000000 00000 f 0000021876 00000 n 0000235114 00000 n 0000000000 00000 f 0000235064 00000 n 0000000000 00000 f 0000234965 00000 n 0000000000 00000 f 0000234915 00000 n 0000000000 00000 f 0000234783 00000 n 0000000000 00000 f 0000234726 00000 n 0000000000 00000 f 0000234672 00000 n 0000000000 00000 f 0000234616 00000 n 0000000000 00000 f 0000234545 00000 n 0000000000 00000 f 0000021929 00000 n 0000234489 00000 n 0000000000 00000 f 0000234416 00000 n 0000000000 00000 f 0000021982 00000 n 0000234316 00000 n 0000000000 00000 f 0000234188 00000 n 0000000000 00000 f 0000022036 00000 n 0000022101 00000 n 0000022166 00000 n 0000042949 00000 n 0000219836 00000 n 0000220352 00000 n 0000225012 00000 n 0000234140 00000 n 0000000000 00000 f 0000234086 00000 n 0000000000 00000 f 0000234038 00000 n 0000000000 00000 f 0000233982 00000 n 0000000000 00000 f 0000233934 00000 n 0000000000 00000 f 0000233883 00000 n 0000000000 00000 f 0000233763 00000 n 0000000000 00000 f 0000233702 00000 n 0000000000 00000 f 0000233640 00000 n 0000000000 00000 f 0000233584 00000 n 0000000000 00000 f 0000233528 00000 n 0000000000 00000 f 0000043107 00000 n 0000233472 00000 n 0000000000 00000 f 0000233416 00000 n 0000000000 00000 f 0000043161 00000 n 0000233360 00000 n 0000000000 00000 f 0000233304 00000 n 0000000000 00000 f 0000043215 00000 n 0000233253 00000 n 0000000000 00000 f 0000233183 00000 n 0000000000 00000 f 0000233121 00000 n 0000000000 00000 f 0000233065 00000 n 0000000000 00000 f 0000233009 00000 n 0000000000 00000 f 0000043269 00000 n 0000232953 00000 n 0000000000 00000 f 0000232897 00000 n 0000000000 00000 f 0000043323 00000 n 0000232841 00000 n 0000000000 00000 f 0000232785 00000 n 0000000000 00000 f 0000043377 00000 n 0000232721 00000 n 0000000000 00000 f 0000043431 00000 n 0000131505 00000 n 0000135651 00000 n 0000043496 00000 n 0000043561 00000 n 0000070077 00000 n 0000225238 00000 n 0000232673 00000 n 0000000000 00000 f 0000232619 00000 n 0000000000 00000 f 0000232571 00000 n 0000000000 00000 f 0000232515 00000 n 0000000000 00000 f 0000232467 00000 n 0000000000 00000 f 0000232416 00000 n 0000000000 00000 f 0000232329 00000 n 0000000000 00000 f 0000232271 00000 n 0000000000 00000 f 0000232209 00000 n 0000000000 00000 f 0000232153 00000 n 0000000000 00000 f 0000232075 00000 n 0000000000 00000 f 0000070285 00000 n 0000232019 00000 n 0000000000 00000 f 0000231953 00000 n 0000000000 00000 f 0000070339 00000 n 0000231897 00000 n 0000000000 00000 f 0000231831 00000 n 0000000000 00000 f 0000070393 00000 n 0000231780 00000 n 0000000000 00000 f 0000231665 00000 n 0000000000 00000 f 0000231598 00000 n 0000000000 00000 f 0000231519 00000 n 0000000000 00000 f 0000231461 00000 n 0000000000 00000 f 0000231399 00000 n 0000000000 00000 f 0000231343 00000 n 0000000000 00000 f 0000231268 00000 n 0000000000 00000 f 0000070447 00000 n 0000231212 00000 n 0000000000 00000 f 0000231149 00000 n 0000000000 00000 f 0000070501 00000 n 0000231093 00000 n 0000000000 00000 f 0000231030 00000 n 0000000000 00000 f 0000070555 00000 n 0000230978 00000 n 0000000000 00000 f 0000230757 00000 n 0000000000 00000 f 0000070609 00000 n 0000070675 00000 n 0000089271 00000 n 0000225464 00000 n 0000230709 00000 n 0000000000 00000 f 0000230655 00000 n 0000000000 00000 f 0000230607 00000 n 0000000000 00000 f 0000230551 00000 n 0000000000 00000 f 0000230503 00000 n 0000000000 00000 f 0000230452 00000 n 0000000000 00000 f 0000230370 00000 n 0000000000 00000 f 0000230300 00000 n 0000000000 00000 f 0000230230 00000 n 0000000000 00000 f 0000230174 00000 n 0000000000 00000 f 0000230111 00000 n 0000000000 00000 f 0000089418 00000 n 0000230055 00000 n 0000000000 00000 f 0000229986 00000 n 0000000000 00000 f 0000089472 00000 n 0000229930 00000 n 0000000000 00000 f 0000229867 00000 n 0000000000 00000 f 0000089526 00000 n 0000229811 00000 n 0000000000 00000 f 0000229755 00000 n 0000000000 00000 f 0000089580 00000 n 0000229697 00000 n 0000000000 00000 f 0000229597 00000 n 0000000000 00000 f 0000228926 00000 n 0000000000 00000 f 0000089634 00000 n 0000089699 00000 n 0000089764 00000 n 0000107819 00000 n 0000225690 00000 n 0000228878 00000 n 0000000000 00000 f 0000228824 00000 n 0000000000 00000 f 0000228776 00000 n 0000000000 00000 f 0000228720 00000 n 0000000000 00000 f 0000228672 00000 n 0000000000 00000 f 0000228621 00000 n 0000000000 00000 f 0000228533 00000 n 0000000000 00000 f 0000228436 00000 n 0000000000 00000 f 0000228360 00000 n 0000000000 00000 f 0000228309 00000 n 0000000000 00000 f 0000228167 00000 n 0000000000 00000 f 0000228116 00000 n 0000000000 00000 f 0000227974 00000 n 0000000000 00000 f 0000227918 00000 n 0000000000 00000 f 0000227831 00000 n 0000000000 00000 f 0000107966 00000 n 0000227775 00000 n 0000000000 00000 f 0000227669 00000 n 0000000000 00000 f 0000108020 00000 n 0000227613 00000 n 0000000000 00000 f 0000227539 00000 n 0000000000 00000 f 0000108075 00000 n 0000227483 00000 n 0000000000 00000 f 0000227405 00000 n 0000000000 00000 f 0000108130 00000 n 0000227349 00000 n 0000000000 00000 f 0000227287 00000 n 0000000000 00000 f 0000108185 00000 n 0000227231 00000 n 0000000000 00000 f 0000227149 00000 n 0000000000 00000 f 0000108240 00000 n 0000227093 00000 n 0000000000 00000 f 0000227031 00000 n 0000000000 00000 f 0000108295 00000 n 0000226975 00000 n 0000000000 00000 f 0000226889 00000 n 0000000000 00000 f 0000108350 00000 n 0000226833 00000 n 0000000000 00000 f 0000226739 00000 n 0000000000 00000 f 0000108405 00000 n 0000226683 00000 n 0000000000 00000 f 0000226601 00000 n 0000000000 00000 f 0000108460 00000 n 0000226545 00000 n 0000000000 00000 f 0000226483 00000 n 0000000000 00000 f 0000108515 00000 n 0000226427 00000 n 0000000000 00000 f 0000226353 00000 n 0000000000 00000 f 0000108570 00000 n 0000226297 00000 n 0000000000 00000 f 0000226235 00000 n 0000000000 00000 f 0000108625 00000 n 0000226187 00000 n 0000000000 00000 f 0000226093 00000 n 0000000000 00000 f 0000108680 00000 n 0000108746 00000 n 0000108812 00000 n 0000131037 00000 n 0000183948 00000 n 0000184125 00000 n 0000184218 00000 n 0000184310 00000 n 0000184402 00000 n 0000184814 00000 n 0000185080 00000 n 0000187179 00000 n 0000187522 00000 n 0000191122 00000 n 0000191376 00000 n 0000193372 00000 n 0000193899 00000 n 0000199312 00000 n 0000199707 00000 n 0000204595 00000 n 0000204791 00000 n 0000205101 00000 n 0000205307 00000 n 0000205832 00000 n 0000206284 00000 n 0000211072 00000 n 0000211529 00000 n 0000221043 00000 n 0000222343 00000 n 0000221452 00000 n 0000222734 00000 n 0000221728 00000 n 0000223127 00000 n 0000221963 00000 n 0000223524 00000 n 0000222023 00000 n 0000223814 00000 n 0000222175 00000 n 0000224184 00000 n 0000225916 00000 n 0000225942 00000 n 0000238278 00000 n 0000239648 00000 n 0000240796 00000 n 0000241311 00000 n 0000242178 00000 n 0000242781 00000 n 0000244400 00000 n 0000244637 00000 n 0000244700 00000 n 0000244724 00000 n 0000244775 00000 n 0000244850 00000 n 0000244902 00000 n 0000244964 00000 n 0000244999 00000 n 0000245074 00000 n 0000245422 00000 n trailer << /Size 473 /Root 1 0 R /Info 3 0 R /ID[] >> startxref 249079 %%EOF