"Every wise old system and network administrator knows that security is a multilayer process. You have your firewalls and other border security, perhaps some internal network segmentation, and application and operating system security. However, locking down the operating system is probably the most crucial link in this chain. An excellent utility to help you probe, assess, and harden your Linux system is Bastille Linux.
"Bastille operates in two modes: hardening, and assessment..."