CIS-benchmark hardening for RHEL/Ubuntu fleets: SSH lockdown, least-privilege sudo, auditd, firewall policy, patch baselines, verified with automated re-scans. Deliverables: hardened baseline, Ansible role, compliance scan report. Timeline: two weeks.