Good practices with SQL Servers

What are Fsecure's recommendations for setting up Fsecures profiles for Microsoft SQL Servers. Do you have any recommendations in terms of Policy for the analysis?
