http://secure45nbquibuw6thmenrfamhobdkkrllgxrtayn4sgmnexremexyd.onion/guides/linux-hardening.html
This alone will not
be sufficient for high quality profiles though; seek the AppArmor documentation for more details. If you want to take it a step further, you can setup a full system MAC policy that confines every single user space process by implementing an initramfs hook which enforces
a MAC policy for the init system.