I don’t have one, but would love to see one.
At a minimum, I’d think it would cover:
Service account security
If a WSS install, AD account creation mode?
SSL termination and alternate portal access mappings
Site Administration policies
My Site policies
Use of/mapping of AD groups to site groups
Other?
This is just off the top of my head. In a real sense, the extranet/internet piece is no different than an assessment of IIS.