An insurance company has created a set of policies to handle data breaches. The security team has been given this set of requirements based on these policies:
• Access records from all devices must be saved and archived
• Any data access outside of normal working hours must be immediately reported
• Data access must only occur inside of the country
• Access logs and audit reports must be created from a single database
Which of the following should be implemented by the security team to meet these requirements? (Select THREE)