Yet still basics are missing - updates straight from Google, even if at least for the parts of the system, and FIREWALL. And a working system-wide backup. It's these 3 things that are most often reason for rooting as well, so it would take care of the 4th security concern by itself.
Myself, first thing to do with new Android is root it, and install Droidwall, and blacklist/whitelist apps acces to web via WiFi and/or cellular. Then install more apps. And when done with that, install Titanium Backup and/or Root Uninstaller to get rid of "system apps" I don't need. Now that "systen app" thing should also be a user managable, because I'm pretty sure that Baidu or Google search are neither needed by system to run 😛 and each phone, no matter the brand, always has at least few of these...
Now, all of these are way easier to implement then some features in N and M, and some have been solved by 3rd party tools for 6 years or more. There's really no excuse that modern OS doesn't have an user configurable firewall!!!!