1.
The methods that will most effectively minimize the ability of intruders to compromise information security are comprehensive user training and education. Enacting policies and procedures simply won't suffice. Even with oversight the policies and procedures may not be effective: my access to Motorola, Nokia, ATT, Sun depended upon the willingness of people to bypass policies and procedures that were in place for years before I compromised them successfully.
Kevin Mitnick
3.
I am accountable for all the actions at my laboratory. I am accountable for all of the policies and procedures of security systems, and I am accountable for the training of the individuals working in the lab. We can't excuse them if they ignore these policies, if they are negligent, we have to hold them accountable as well.
John Browne, Baron Browne of Madingley