Originally posted here by ZomBieMann77
Public and corporate policy both play signficant roles in data security, and indeed some of the largest breaches of data integrety that have taken place in recenty history weren't due to architectural issues, but rather SOP related ones.

Need I mention the recent loss of millions of private records from the US Department of Veteran Affairs as an example? With all of their security, the data ended up being lost because an employee took the files home to his apartment to work on. While they publicly claimed it was against policy to do so, it appears that such incidents were part of an informal SOP of the agency.

