1.
What is the greatest risk for an organization if no information security policy has been defined?
2.
What is the objective of classifying information?
3.
What do employees need to know to report a security incident?