One of the rather interesting features of FreeBSD 10 should be Capsicum. It has been shipping since 9.0 but wasn't enabled by default. It should be enabled by default in 10.0 and ship along with Capsicum enhanced applications.
Capsicum uses capabilities (not traditional POSIX capabilities) for security and sandboxing rather than the legacy UNIX MAC and DAC model.
This offers increased flexibility and reliability for defining security policies.
Anyone interested can read further: http://www.cl.cam.ac.uk/research/security/capsicum/