Darkreading has an interesting article on corporate security policies and why many employees say they must break the rules to get their jobs done:

“Current IT security policies frequently don’t reflect the reality of how employees use their computers, according to a report published today by Cisco Systems.

The report, a deeper analysis of internal threat data collected by Cisco earlier this year, indicates that many users break their companies’ security policies because following those policies would prevent them from doing their jobs

What this says is that security policymakers need to rethink the way they are developing those policies,” says Marie Hattar, vice president of network systems and security solutions at Cisco. “IT people think that users aren’t following them because they are apathetic or don’t understand the risks. But the users are telling us that the policies aren’t realistic.”

Click the picture for the rest of the article.