Most large organizations maintain a detailed corporate security policy document that spells out the “dos and don’ts” of information security. Once the policy is in place, the feeling is of having achieved ‘nine-tenths of the law’, that is, that the organization is in effect covered. This is a dangerous misconception. Because much like in the world of law and order, while creation of law is f …[more]