I would also add IP restrictions so that only your SNMP management servers can talk to your workstations over the SNMP protocol. You can do this in the registry, same place you enable SNMP to run and setup the community strings, etc...