Hello @Madura Malwatte ,
Your question is quite old, but better late than never, and it may also help some other people coming to this post.
We have just released a Cisco ACI Hardening Guide with the best practices in this area. https://www.cisco.com...