My personal preference is to have stability, low or no problems, high compatibility, low maintanance. Since I don't feel the need to be on the bleeding edge, I have stuck with RH9.
As to additional software, boy that is a potentially long laundry list....
But I am way too tired to write my long list..
My own choices: (short list)
-Firewall FIRST!!!
-Security lockdown SECOND!!!
-Do not use Dr Web
-Do not pay Plesk for Spamassassin
-Use other AV alternatives which work better for less $$ (ART or 4PSA)
-Use other SA alternatives (ART or 4PSA)
-Chrootkit and Rootkit Hunter (minimum)
-Server hardening
-Secure Kernel
-Many Qmail add-ons
-Many many many many other things.