The other misconception is that by strictly following policies and procedures an Information Security Officer (ISO) can create a “perfect” environment where the risk of a security breach is nonexistent. This evidences itself in ISO's that pursue compliance with information security with an almost religious zeal. All rules must be strictly followed, regardless of risk or resource demands on the business. All violations are treated as threats to the very existence of the business. The security patch management system must be upgraded, because that is what is required by policy.