Verities wrote: » SELinux is set to enforcing on all of our servers, least privilege access is used for anyone who thinks they need access to my systems, and I routinely audit my access and sudoers logs. Logwatch is a bit of a PiTA to navigate through when you have anything more than 50 systems but its a very handy tool and I've caught a few people doing things they shouldn't have been doing using it. I think our process is pretty forward thinking as most people are afraid to automatically push updates to their environment, but Red Hat is really good at keeping their patches stable. I'd like to see an increase in adherence to STIGs, since there are too many damn exceptions in my experience, an increase in use of configuration management tools (prevent people from making changes that create vulnerabilities), a removal of Java from everything, and would like OWASP to be the standard for web related vulnerability management.