JP Morgan put together an Executive Information Security Committee at the beginning of the 1990s. The committee was chaired by the Chief Financial Officer, and we had executive business heads sitting on the committee. The intent was to make take the mystery out of security; the questions sort of went this way: “Are you concerned with who is using the service? Is that a big deal or a little deal?” “Once you know who they are, do you want to limit their activities?” “We were talking about security, but what it really came down to what is the business issue we’re trying to solve?””]
Source: https://www.cuinfosecurity.com/blogs/asking-right-questions-p-198

