>By having a security policy, they are in the security business
This is not true. A company should only be considered to be in the security business if their profit is driven or at least depends upon offering security to others.
By the logic of your post, any company that has computers that they have to manage would be in the 'IT' business.
The reality is that to run a company, a variety of things must be done to allow it to exist that do not define the business of the company.