RE: 2 and 5
I agree that backups should not be forgotten and it is true that they need [adult] supervision. One other practice that you should be engaged in on a regularly scheduled basis is to test your backups. Have a time set aside where you take a server offline and recover it from your backup on another box. If it doesn't work, adjust your backup/recovery settings and/or strategy until it does. It also doesn't hurt to virtualize - it can be a much quicker process to recover a virtual server vs a physical one.