Designing and Implementing Security Policy in Siloed Organizations

How do you write a security policy in an enterprise where you have a parent business unit and semi-autonomous business units underneath? You have to balance the "how" and the "what" correctly and there is a not-so-secret formula that I believe works ...

