make sure that you only allow the necessary traffic in (ports), nothing more
ASA should take care of the rest
^
--heed the rest of this post with caution--
as far as Auditing security, one useful tool from an inside LAN client would be to browse to a website like http://www.grc.com and use their 'Sheild's Up' test to check for open ports through your firewall (although it only checks basic ports). There are other sites that can do this and check for more openings. If you have the permission to do so you can also use a tool like 'nmap' to scan your PIX outside interface for leaks from a remote location (i.e. send TCP SYN packets to different ports and report the responce to you).