Posted on Thursday, 7 August 2008
People put in charge of implementing a security policy are more concerned with following the letter of the policy than they are about improving security. So even if what they do makes no sense — and they know it makes no sense — they have to do it in order to follow ‘policy.’
Bruce Schneier, Security Idiocy Story (full read recommended)
