Most organisations wouldn't feel comfortable with:
a) Not having locks on their buildings
b) Having known-defective locks on their building
c) Not doing regular audits of the locks their using vs. what criminals can crack
d) Not having reasonable organisation-wide policies to make sure the locks are used properly and kept secure
Yet I don't think that there is quite enough attention given to IT security. It still seems like primarily a "box ticking" exercise, or a case of throwing rules and regulations at the problem which make sense at face value, but are inherently flawed.