@my detractors, re: no AV software
First off thanks for responding. It wasn't as uncivil as I expected, and I'm consistently surprised at the non-flame content I'm seeing.
Steve Foster is right in that it's possible to detect and stop malware without conventional anti-virus software. I manage security SYSTEMS, not security PRODUCTS. These systems consist of more than one product, more than one measure (ie: blocking port 25) and a lot of common sense. I do more than JUST remove admin access from the desktop. But it achieves the intended goal of No Unauthorized Software.
And so what if something comes along and runs as some user? I've mitigated that threat. Even if it somehow gets past every step along the way that I've put up (and there are a few!), it then has to somehow run. And then I've stopped that, too:
http://www.antiwindowscatalog.com/?mode=rant&id=7
Add to that package roaming profiles, and you have nothing that can stay on the local computer, or needs to be on the local computer. Everything that IS on the local computer is authorized.
The only things left that can run from the net are Java and Flash. Java's so stupidly paranoid about security, that if something goes horribly wrong the OS will stop it (Java runs as the user that runs it) and then I can blame the applet's developer -- that's a good use for code signing. Ditto with Flash, though not quite as paranoid, and IE7 stops misbehaving Flash. Yes, I read the pwn2own results, but couldn't help but wonder if the perp was running as Admin.
No metrics, eh? How do I know how many viruses are running rampant? I should ask you the same question, if you're running an enterprise AV product that collects data and then turns around and DELETES it:
http://www.vmyths.com/column/1/1999/9/27/
All you have are anecdotes and what-ifs. I at least have uptime statistics.
Who is more irresponsible? The flaming idiot with five years of virus-proofing to back him up, or the "comparably sane" folks running their security blankets expecting the AV industry alone to save them?