Question for security management and overhead and concerns

Hi, experts

We have a new project to place one of our linux servers outside our private network to provide public access to our web-based application. But I know how to setup iptables, but do not have much experience for security management to protect this box from security threat through application servers like apache/tomcat.

So, I would like to have advices/recommendations/warnings for the following issues [I am planning to install AS4.0 onto this machine] and install both apache/tomcat:
I am inclined to turn-off ssh/ftp access.

1. any good security management software tools ?
2. other concerns by owning a server in public domain beside security
3. how many hours per day sys admin should expect to spend to mange such a machine
4. any web resources to manage such a machine

Thank you,

