Most settings for security have been applied in Keystone already. However there are several files that need to be patched manually. For a summary of changes needed please consult /App_Config/Include/Any.All.WebConfig.Hardening.config.example
/App_Config/Include/Any.All.WebConfig.Hardening.config.example