Built my parents a XP box and I've noticed a few security holes.
I found this url, but it didn't answer all of my questions:

Win XP Security

1. How do I set it up so end users can't launch .exe files?

2. How do I keep end-users out of each other's directories? It seems like there are only
two account types: Admin and Super Users

3. How do I give access to programs and keep others away from other programs on the machine?

thanks