Reasonably? That's pretty much good. Add what another comment said about not giving out personal information, but having a good AV like MSSE, using automated Windows Updates, use an updated browser (even if it's just the latest version of IE), don't run untrusted software, and having strong passwords (using something like LastPass to remember them all but still retain convenience) is basically all you can reasonably ask an average user to do. And for the most part, that's good enough.
Sure, there's evolving threats, there's drive-bys that will slip around all of this, there's ways attackers could still get through. But as scary as it all is, anything beyond these steps gets into the territory of major inconvenience. The problem with that is, the more intrusive and inconvenient the security becomes, the less likely people are going to be to actually use and remember their security practices. If mom can't repeat it at her book club, it's not going to be effective. And to be honest, these types of attacks that bypass these restrictions are exceedingly rare when it comes to mom and grandma. The biggest threat there is phishing and malware. Corporate security has professionals enforcing a policy that meets the business's own requirements.
So to answer your question, yes, that's all you can reasonably do. In most cases, you'll be pretty well protected with just that, and those steps aren't too complicated to follow or remember.