Comment whitelist (Score 3, Interesting) 396
Run a program that only allows whitelisted applications, and block all removable media. It's the only way you can be absolutely certain there is nothing running on your network that shouldn't be there.
http://en.wikipedia.org/wiki/Whitelist#Application_whitelists