The CIS benchmarks are a great place to start for hardening a system (https://www.cisecurity.org/cis-benchmarks/) and there's also OpenSCAP gives you a nice way to scan systems for compliance against a set of hardening rules (https://www.open-scap.org/).