What is the recommended practice for classifying sensitive ICS security reports?
-
A
Share all reports publicly to promote transparency
-
B
Apply classification labels (e.g., Confidential, Restricted) and limit distribution on a need-to-know basis
-
C
Store reports unencrypted on shared network drives for easy access
-
D
Classify all reports as 'Top Secret' regardless of content