As the CIO, your Information Security Policy (ISP) is set forth at your organization. The new policy was distributed three months ago, has been provided to each department in written text format and is available on the company's website. You have held mandatory training with each department to explain the policy and highlight the changes that have occurred. What if an employee refuses to explicitly agree to comply with the policy? Is there any laws an employee breaks by not complying with a company's ISP?