Earlier quoted context omitted.
My comment assumes that the IT department (including its executive) gets to make these sort decisions - why wouldn't they?
In many mature orgs, corporate IT rolls up to the CIO and security will roll up to the CISO The CISO and security ops will demand to be completely independent from corp IT, for legit reasons, as the security team needs to treat IT as potential insider threat actors with elevated privileges. They will also demand the ability to push out updates everywhere at any time in response to real-time threats, and per the previ…
IMO there are no legit reasons except politics, empire building, NIH and toxic relationships for such a such a crazy state of affairs.