Related link: http://www.infosecwriters.com/texts.php?op=display&id=117
The article covers the typical mistakes organizations make while while planning and deploying the intrusion detection systems. In addition to the obvious mistake (0th, I guess :-)) of not evaluating and deploying the IDS technology at all, the issues we cover often decrease or even eliminate the added value the companies might otherwise derive from running an intrusion detection system.


Self-promotion
... so do you ever link to anything you didn't write?
Self-promotion
Yes, sure, see "SANS Top 20 Vulnerabilities is out", "IDS is dead (at least, according to Gartner)" and "Key security questions that every executive should be able to answer" and some others blog entries. On the other hand, do you think that what I write is bad content and doesn't belong on O'Reilly?
Self-promotion
>>do you think that what I write is bad content and doesn't belong on O'Reilly