- hardening (restrict access to proc to owner) - removing files covered by abstractions - indentation per apparmor profile style