Whenever information security is mentioned within most organisations there is a collective groan; the board don’t want to engage, staff don’t want to be encumbered and the IT department sometimes lack the guidance to implement anything effective. From a security professional’s perspective the most disappointing factor is the board’s unwillingness to participate in this vital part of their busines …[more]