What distinguishes an 'information security objective' from a general security policy statement?
-
A
Objectives are vague aspirations while policies are measurable
-
B
Objectives are specific, measurable targets aligned with the security policy
-
C
Objectives only apply to technical controls, not process controls
-
D
Objectives are set by auditors, not by the organization