What are the top three areas that an organization should work on to respond to the issues raised in the de Villiers (2010) article? Why are these areas critical to the organization? Is the author's assessment correct? Explain why or why not. Choose a specific organization to illustrate your argument.
What is the value and effect of a good business impact analysis (BIA)? How can using this help an organization develop an effective information security policy?