Here at work, we're using a program called Sanctuary that blocks USB drives/keys from being used by employees. We also could not enforce the No-personal-pda policy, so we use Sanctuary to block any Palm devices from being used. But that's all through the installed OS and it kicks in after someone logs in. So, I would worry more about someone walking in with a bootable USB drive with either BartPE or Linux on it, though.
I tagged the nmap tutorial part 1 in Google Reader. I was planning to follow it at home after getting off work. I get home, clicked the link and the site tells I can no longer access it.