For clarification:
Internet - the World Wide Web. Accessible from any computer not located in North Korea. Number one delivery method of pornography and shady Mexican Viagra.
Intranet - Internal, shielded from public access, only accessible from within organisational computers. Probably not going to get much porn on it, unless you slip with the camera while taking your photo.
This is not accessible to anyone who doesn't work for the company. And to be perfectly honest, if I worked in a large company, I'd be less suspicious of someone using my photo for shady purposes, than I would be of someone who didn't have a photo on our internal directory. Putting a face to the name establishes humanity - you're less likely to go off on one with someone you can associate with as a person, rather than as just a string of words in an email.
From an organisational point of view, it shows disobedience in what is a relatively small detail. You've given your company your address, date of birth, full educational history, bank details, you trust them to keep you safe and secure in the workplace each and every day...
It's also worth mentioning that if anyone's ever uploaded a photo of you to Facebook at all, the data-harvesting machine there has a lifetime transferrable licence to use that photo in any way it wants, royalty-free. Instagram can bank that image and use it any way they want, too (and vice versa). The NSA will have a copy, too. Not to mention Google caches.
Has anyone ever taken a photo of you at a birthday party on a digital camera? Or a photo on a phone (in which case there'll be an auto-backup with the phone account, possibly a cloud storage service like Dropbox, and again, the NSA) with you in the background? A friend, colleague, family member, child?
Security of data is only as strong as the weakest point. Believe me, your company's internal directory is the LAST place that's likely to be a leak.