
IT should be a 'business enabler'
You might want to have a look at http://www.keylength.com/ (overview of all 'official' recommendations regarding protocols and minimal keylengths).
If you work for banks: take into account the Payment Card Industry standard (https://www.pcisecuritystandards.org/ - strictly speeking only valid for credit card handling systems) and look at national compliancy requirements
It is even worse: description of companies in Google Places cannot use certain words anymore (I perform penetration tests and 'penetration' is now in that list of forbidden words). Crazy enough 'penetration' is allowed as Adword!
See http://blog.astyran.sg/2010/11/google-term-penetration-is-not-allowed.html.
Space tells matter how to move and matter tells space how to curve. -- Wheeler