Here is a new paper I wrote for ComputerWorld called 'Five basic mistakes of security policy." The actual mistakes are:

Not having a policy
Not updating the security policy
Not tracking compliance with the security policy
Having a "tech only" policy
Having a policy that is large and unwieldy





