Users continue to ignore security policies, while security organizations are overlooking non-technical controls
IT Compliance Institute had an article posted this morning that reinforces the point; "it's not the software/hardware/infrastructure/etc but the people and processes that expose the biggest risks to a company
The article doesn't reveal who/where the survey was taken but it does highlight some key security items that people usually cut corners...
