Why have people with a job description that's explicitly about information security, when that should be everyone's responsibility, right? The reality is that some concern just won't ever be considered at all unless you put someone explicitly in charge and supply them with enough formal rank that they can't be ignored, as they inevitably would be without.