ANONYMOUS Some helpful info takes a bit of digging to get to. http://www.apple.com/support/downloads/commoncriteriatools_readme.html
The above page has some important links. The Admin Guide link near the bottom of the page should be required reading for someone configuring a system for security.
After all is said and done, it still seems that an admin installing an app with some unknown functionality is all it might take to compromise a system. (see user comments for iDeFrag and you may see why some want all tools to be open-source)
(Version 1.0)