A bit dated, but still a good read with thought-provoking ideas about things not to do in the name of security.
- Default Permit
- Enumerating Badness
- Penetrate and Patch
- Hacking is Cool
- Educating Users
- Action is Better Than Inaction
http://www.ranum.com/security/computer_security/editorials/dumb/