No setuid programs in /var -> mount -o nodev,nosuid Adding "noexec" in various places may cause too much damage (e.g. for running DEINSTALL scripts from /var/db/pkg, configure scripts, etc). Inspired by OpenBSD's afterboot(8) manpage.
and mfs-based /tmp into their own files. Hint at them in the existing files. (fstab needs an #include statement :)