I'm not going to disagree with this at all, however I would point out
that standards are one thing, implementation entirely another. It's
nice to have standards that provide guidance in security structuring,
but without the tools to implement those guidelines, they're guidelines
and not much more. Only in the past couple of years have we seen any
really useful tools in this area, and the prices are out of reach of
many organizations. (Like other things in technology, it would be nice
if those prices would come down over time.)