The information-security policy record should show which control objectives implement its requirements. What relationship should the implementer establish?
Select an answer to reveal the explanation.
Short Explanation
Policies say what; control objectives say how you prove it. Link the info-sec policy to those objectives so the chain is obvious. PDFs on every entity, audit-only links, and orphaned URLs leave a gap in the middle.
Full Explanation
Policy and Compliance maintains relationships from internal policy records to control objectives that operationalize policy intent. Relating the information-security policy to relevant control objectives creates navigable traceability for owners and examiners. Cloning policy PDFs per entity, linking only to audits, or storing URLs without objective relationships does not establish the policy-to-control-objective content chain.