http://it.toolbox.com/blogs/itmanagement/is-your-security-program-based-on-hard-evidence-or-compliance-voodoo-75586