A hat tip to an (unnamed) pal at Microsoft, who sent me (working) links for three useful documents:
The Windows Server 2003 Security Guide describes best practices for securing WIndows Server 2003 member servers, DCs, file servers, and IIS boxes. Well worth reading, if only to get an appreciation for what's new in 2003.