Includes designing the organization’s specific protective objectives that address the necessities and potential risks involved in the theft or damage to the hardware, software or the information on them.