...ineffective is because organisations focus on ticking the compliance boxes rather than taking the holistic approach to securitythat's needed. There's enough ranting on this subject elsewhere - the best being on Anton Chuvakin's blog - and I...
http://www.computerweekly.com/blogs/stuart_king