1.Change port group security default settings ForgedTransmits and MACAddressChanges to Reject unless the application requires the defaults. As well ensure promiscuous mode kept its default setting of reject unless your application require it. 

2. Consider limiting host visibility to datastores it requires. 

3. Size with VMware HA host failure considerations. Don't disable admission control.

4. Maintain configuration consistency across hosts in a single cluster. Using Host Profiles, vCenter Configuration Center or PowerCLI scripts

5. Utilize VMware HA Priorities. Set proper restart priority on your VMs