scasc said: So all in all it depends on the problem domain, what the root cause issues are.
JDMurray said: A vision statement for an entire org or just for the CISO's part of it?Off the top of my head: "It's all about risk: mitigate what is reasonable, transfer what you can afford, and accept what you must."