Have you ever encountered a situation in which a policy was not in line with observed or accepted behavior? Describe the situation to some degree and explain how the situation came to be? How could non-compliance to the policy have been avoided? (Information Security Management)