And good points they are, too. To number 3 I might add a suggestion: KISS. By making certain that your policies have a common sense feel to them, and your procedures are practical rather than obstructive, you will make helping your staff remember to follow them much easier. Look to procedure simplification--- generally speaking, if a security measure requires more than one or two extra steps, the end user will either forget to use it, or find a way to circumvent it. And in either case, the user will resent it.
