If you use subinterfaces, you typically do not also want the physical interface to pass traffic, because the physical interface passes untagged packets. Because the physical interface must be enabled for the subinterface to pass traffic, ensure that the physical interface does not pass traffic by leaving out the nameif command. If you want to let the physical interface pass untagged packets, you can configure the nameif command as usual.
The configuration of security levels on sub-interface is the same as physical interfaces. Here's a document on security levels.
http://cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html
HTH