The Book, The Report
Cracking Drupal: A Drop in the Bucket
Written by a Drupal expert, this is the first book to reveal the vulnerabilities and security issues that exist in the sites that have been built with Drupal and how to prevent them from continuing.
Drupal Security White Paper
Curious about Drupal's security? Consider Drupal but want to make sure it's good enough? Read the Drupal Security Report
Security Review Module
If you are concerned about whether your site is secure, consider using the Security Review Module to get a free review of your site's security health. Did it find problems? Consider hiring a security expert from Drupal Scout to audit your site.