mwryder55 :
Many security policies are mandated by outside forces, ...
Those mandates typically regulate what to protect and what to protect it from. How to implement those protections are usually up to the user (company or equivalent). The user must be able to show that the protection is good enough.
Many of the requirements of PCI (Credit Card Processing) compliance dictate what we have to do. We can choose what programs to use but they have to be approved by the auditors. A lot of our practices are controlled the same way. Things like hardening the computers have a very long checklist and we have to justify every single deviance. If we let everyone do what they wanted there is no way we could pass the audits. Proving that employee owned electronics were really secure is impossible, look at all the breaches at very big companies and government agencies.