Security Baseline “13+2”
- SFTP locked to user chroot
- Fail2Ban basic jail(s)
- UFW deny‑by‑default; allow SSH mgt only
- TLS hardening (OQS/OpenSSL config)
- Docs — capture configs and evidence
+2. Key/cert rotation playbook; Backups with test restore
+2. Key/cert rotation playbook; Backups with test restore