However I disable the service - as it is primarily required for NFS. 'chkconfig --level 0123456 portmap off'
Agreed. If you aren't using any RPC services (You probably aren't if you aren't doing NFS.. I'd disable netfs, portmap, statd..
RPC services have a long history of getting owned.