Posted 26 July 2011 - 09:07 PM
Well it depends on the company and the type of information stored there. If you have reasonably few users as you say, and you trust them to know partially what they're doing, then you should just impose some rules and not make it too strict. I'm taking my MCITP certification training right now, and they teach you to control anything and everything, but it really depends on the company and the nature of the work performed there. As for Antivirus on the server, I'd recommend GFI VIPRE premium home edition only unless you want centrally managed antivirus meaning that you deploy the AV solution out to all of the workstations, but if you trust that your users will keep the program up to date, you don't need to deploy it via GPOs. And by the way, are you using anything like Sharepoint, Exchange, or any of the others? If so, then you'll need to either look at GFI's options for Exchange at least, or you can go for Forefront, but I recommend the former regardless if it has Sharepoint 2010 integration (which it doesn't), since a custom solution for AV scanning in Sharepoint can be developed quite easily via the Service Application Framework.
The AccessCop Network is just me and my crew.
Some call me The Queen of Cambridge