web server
セキュリティ対策
Webサーバをセキュアに保つ設定のまとめ - Qiita
SSL
の設定
https://ssl-config.mozilla.org/
plesk
の場合
sslの古いversionを使わない
How to enable/disable TLS protocol versions in Plesk for Linux – Plesk Help Center
xPowered-Byの削除
How to remove/modify the header X-Powered-By for all websites hosted in Plesk for Linux? – Plesk Help Center