http://www.nsa.gov/ia/_files/os/redhat/NSA_RHEL_5_GUIDE_v4.2...
and TLDR version: http://www.nsa.gov/ia/_files/factsheets/rhel5-pamphlet-i731....
It is starting to get a little bit dated (RHEL 5 is quite old), but general rules still apply and usually they explain their reasoning.