I usually find those levels OK without being too agressive. You could also have a look at setting 'rules_du_jour' for adding some more filtering with spamassassin, see the links in this
thread. There are lots more tests you can apply to Spamassassin but the trick (if you can call it that) is for it not to get rid of legitimate email. If you do use the rules_du_joru or add any of your own rules then relax the tag and kill percentages again and monitor what sort of email is getting tagged as spam, if there are no false positives you can change the tag/kill levels as you need.