There used to be a web page that was a giant howto on securing Linux. Actually had scripts you could run that did most of the things it recommended; it was called "Trinity" or "Trinity OS". Now I see that "TrinityOS" is a project to build a secure Linux distribution, and I can't find a link to the old Trinity site that's not dead. Of course, this comes just as I've been asked to set up a webserver for a NPO I work with, and here I was counting on Trinity to cover my butt.