Which three components should be included in a security policy? (Choose three.)
A.
Security best practice
B.
Incident handling procedure
C.
Software Specifications
D.
Statement of authority and scope
E.
Security product recommendation
F.
Identification and authentication policy