Is the server behind NAT, or with a globally visible IP? In both cases (but
especially the last!), you'll want to set up some
firewalling on the box. Dunno about security for Apache per se, unless you're talking
.htaccess.
The worst security holes are going to be in the web-app, anyway... there's so much vulnerable PHP code out there >_<