You need to categorize each of the identified security issues based on where the underlying problem exists. The categories are:
- People: There is a process or procedure, but employees are not following it.
- Process: There is a problem with the company’s process or procedure itself.
- Technology: There is a problem with how the company has implemented a technology.