That one is no good because it tries to normalize DRM and tivoization by pretending they're for "security". E.g., it says to set kernel.kexec_load_disabled=1, debugfs=off, module.sig_enforce=1, and lockdown=confidentiality, all of which only restrict the root user.
It's also terrible for other reasons, e.g.:
> net.ipv6.conf.all.accept_ra=0
> net.ipv6.conf.default.accept_ra=0
> Malicious IPv6 router advertisements can result in a man-in-the-middle attack, so they should be disabled.But that's the main way to configure IPv6. The IPv4 equivalent of that advice would be to disable your DHCP client, since malicious DHCP servers can result in a man-in-the-middle attack.
And it also has the same horrendous advice for PAM to require the kinds of passwords that we now know reduce security.