In a cyber use-of-force policy, the 'distinction' principle requires that offensive or active-defense actions:
-
A
Are kept secret from all non-security staff
-
B
Discriminate between legitimate military/attacker targets and civilian/innocent systems
-
C
Use only tools developed internally by the organization
-
D
Are completed within a defined time window