An employee caught temporarily storing an MP3 file in his workstation will not receive an IR.
What would be the reference for you to know who should have access to data/document?
Below is Purpose of "Integrity", which is one of the Basic Components of Information Security
Implement plan on a test basis - this comes under which section of PDCA