Despite years of investments in technology and processes, protecting enterprise-wide data remains a maddeningly elusive goal for chief information security officers. Software-as-a-service (SaaS), Web 2.0 technologies, and consumerized hardware increase the number of escape routes for sensitive information. Hordes of vendors confuse CISOs with innumerable sales pitches. IT security should be primarily responsible only for deploying data protection technologies that require minimal or no customization. Instead of beating your head against the wall, devolve responsibility to the business, keeping controls closest to the people who use the data.
Source: https://threatpost.com/data-security-whose-job-it-really-033009/72457/

