The other little nugget that should be mentioned is that no good can come when developing a security policy while the security team (assuming that they are tasked with the job) is positioned under the IT branch in the org chart.
We have battled this for years - with some of us suggesting that IT Security should actually be reporting up through Corporate Security, separated from IT.