I meant "additional" more like "optional". Things you would do after doing the bare minimum. It shouldn't displace things that are of higher importance. Running a currently patched sshd, disabling password auth, etc, would be higher priority than running on a non-standard port.