One thing I've not seen people mention:
Expect it to be hacked - or at least _plan_ for it (especially with
if PHP is involved).
Backups (tested).
HIDS (I use osiris) - tells you _when_ the box has been hacked.
Chkrootkit (ditto).
Adrian
--
Email: adrian@??? -*- GPG key available on public key servers
Debian GNU/Linux - the maintainable distribution -*-
www.debian.org