This is the beginning of a great list, but to apply everything without careful understanding / adapting to your situation would just end up confusing people and causing them problems. Some things are also very distro/environment specific (like the mounts layout).
There are tools which will verify the situation for you, but not force a specific solution.
There are already some automation packages around, in dev-sec project we have them for ansible/puppet/chef including automated compliance tests for inspec.