The "Kernel Self Protection Project" (a group of developers working on enhancing security features in the Linux kernel, e.g. by merging changes from the grsecurity patch set) has published a wiki page of recommended settings in the kernel build and sysctl:
http://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project#Recommended_settings
Since we're building a custom jessie kernel based on 4.4 anyway, these are worth investigating. Also, some might be worth to be enabled in the Debian kernel (for the eventual stretch kernel)