you should check out Ms Security whitepapers at the knowledgebase.
I has all the guidelines you need.

http://support.microsoft.com/default...;en-us;Q298447