I don't usually recommend reading the comments on reddit, but I think we as security practitioners should read the comments on this thread and reflect on how we can do a better job of collaborating, communicating, and delivering value.

https://www.reddit.com/r/sysadmin/comments/16uqyi1/does_your_security_team_not_want_to_be/

Does your security team not want to be responsible or own ANYTHING?

Password policy? No we don’t own that. Configuration hardening standards? Nope don’t own that. Vulnerability response process? Not us....

reddit
@accidentalciso The problem is that when you make the security team responsible for the topics, the other teams will consider everything that has remotely to do with security their job. And how should that work out with 20 development teams and one security team. Sure, you can make the security team responsible for the actual doing of things, but then please scale the team to an appropriate size. I think having dedicated sec people in the dev teams and only a core sec team is way more efficient.