Agree, security is layered approach, basically you should start from
1. Risk management, define which area contain high risk
2. Control the risk using appropriate approach e.g antivirus, firewall, biometric, kerberos.
3. Repeat the 1,2 step.

-Anjar Priandoyo-
http://securityprocedure.com