Windows Vista: Security Tweaks
Advanced Windows Firewall: Turn on outbound filtering
Create an Account Lockout Policy
Disable UAC (User Account Control)
Disable USB storage device write (make them read-only)
Disable User Account Control (UAC) only for Administrators
Start Menu Privacy Tweaks
Turn on auditing to monitor account attacks
Tweak User Account Control (UAC) with Security Policies
Use BitLocker Drive Encryption without TPM chip
Windows Vista Group Policy Reference