cAP ac security best practices question

Good day.

Some time ago I did a project for myself on Mikrotik. Nothing special RB 3011 + CAPsMAN + 4X cAP XL ac. Now i got some spare time to make a revision, update the OS version, etc. RB 3011 is carefully configured in terms of security, the Wi-Fi network works normally, no issues. The CAPsMAN on RB handles all traffic from AC (Local Forwarding turned off). Where do i see problem - ACs was configured minimally. I updated the RouterOS version, deleted the standard configuration, set the password, changed the Identity and like immediately did set up the CAP.

What are my questions here:

I do not know which security settings are better to make on cap ac in this mode of operation. Please advise me on the best practices or materials that can be read and studied on this topic.

Are there any options to centrally update the Router OS configuration for devices like cap ac, for example, to apply new security settings.

The main motivation here is to just educate myself.

Thank you in advance.