Great advice! You sound like you have a lot of experience in server security.
What is your recommendation on strong passwords? Also, should all passwords on a system be different (login passwords for different servers, email passwords, etc...), and if so, how do you keep track of all of them?
Thanks