The InfoSec measurement development process recommended by NIST is divided into two major activities. Which of the following is one of them?
A) identification and definition of the current InfoSec program
B) development and selection of qualified personnel to gauge C) the implementation, effectiveness, efficiency, and impact of the security controls
D) maintenance of the vulnerability management program
comparison of organizational practices against similar organizations