VPN Case Study

I have this case and I am wondering about the answer.

Nancy is the network administrator for a defense company. Many of its researchers do some work from home, particularly work on mathematics, algorithms and so on. The data they send must be absolutely secure. These remote users wish to use VPN connections to the company network. Nancy takes the following actions:

1. She implements a PPTP VPN using Windows XP as the VPN server.
2. All remote users are set up for compulsory tunneling.
3. All remote users are given very strong passwords that change every 30 days.

Are the steps nancy took adequate and appropriate? What other steps, should she have done?

Thank you
