In our opinion, this has to do with the various and confusing outlines of different information security frameworks and laws such as ISO 27002, HIPAA,PCI-DSS and NIST. People who (quite naturally) want to base their security policies on an established standard fall into a trap.