Expose only the services that are necessary for users to be able to perform
While all the above concerns are very valid, I think we should look at this phrase... "Expose only the services that are necessary for users to be able to perform their duties." This line is so blurred these days that you stand the risk of exposing your enterprize or to the other extreme angering your work force by messing with their sacred Facebook. Reducing the number of vectors to attack always makes things easier. Blending the growth (number of attack vectors) with actual business related gains can be close to impossible.