I saw this link on CERTs website and thought that it had some worthwhile points that people may not always think of/remember.

http://www.cert.org/info_assurance/principles.html