One thing that this policy doesn't seem to cover is proper use of the trademarks by the project itself. Who can use the logo within the project, and how, and so on? How about fan sites, or local user groups, and other loosely-affiliated organizations?
We've been debating updating the Gentoo logo/trademark policy for a while now for similar reasons. Debian has been one of the projects we've been looking at as an example of how to try to balance community with protecting the mark.
Another element of policy is the interaction between trademark and copyright, as the logo at least would be protected by both. Could somebody incorporate the Debian logo into a desktop wallpaper that was CC Share-alike/etc?