Spring Security 3.2 has a new annotation @EnableWebMvcSecurity that we should use if MVC is being used.