I came across this workstation security 'checklist' on the Linux Foundation's github page. Its pretty clearly written, and pretty objective I think. Most useful for users with a higher threat model, but there is a lot of useful info for users of any threat model really.

