How do I implement this?
The answer to the question How do I implement this? does not have a single answer. The truthful response is It’s complicated. Maintaining compliance has many touchpoints. It starts at the design table, where you must identify what standards will impact the overall solution. Some can argue that the significant amounts of research time are the greatest amount of time spent on this effort. I disagree. I believe (and I suspect you will too soon enough) that maintaining compliance from release to release long after the measures have been originally implemented in your product is the true heavy lift.
There’s also a catch to all of this. Maintaining adherence is not a one-and-done process. Brace for the upcoming frustration because here it comes. Setting a server profile, whether during installation or later on, is not the end but the beginning. Every time you make a change to the configuration, albeit small or large, you must re-scan and confirm...