Is an incorrectly implemented security program better than a non-existent one ?
Think carefully before you answer that one. A large majority of you would be inclined to give a resounding 'yes' - but I really want you to think carefully on this one. Think long term. Think about implementation hurdles, think about project documentation
The answer to this IMHO is a big "DEPENDS
To explain
Imagine you're working in a company...
