This evidence aims to establish a clear framework to mitigate the risks of sensitive information leakage within entities or institutions. The evidence lists the policies that must be followed to protect internal data, such as information classification, access regulations, monitoring mechanisms, and incident reporting. It also defines the responsibilities of employees and management in handling information and explains preventive procedures, such as training, encryption, and compliance verificat...