This document discusses securing Apache web servers using Mod Security and the Center for Internet Security (CIS) benchmark. It begins with an introduction of the speaker and an agenda. It then covers establishing a secure foundation by hardening the operating system, securing DNS, and using a dedicated Apache user account. It discusses minimizing the attack surface by disabling unnecessary modules, access controls, and limiting HTTP request methods. Finally, it provides an overview of the Mod Security web application firewall and its configuration.