This article on the 10 worst security practices and what to do instead is excellent. The article accurately reflects real life and I highly recommend it as a must read if you are involved in enterprise level security. I agree with every single point made by the author, which is rare.

http://www.securitypipeline.com/159900223