Drupal 8's end of life is coming 2 November, so make sure to prepare ahead of time and use our detailed guide to upgrade now to Drupal 9 - easiest upgrade ever!This section provides security configuration advice for site administrators and includes both "things you should actively do" and "things you shouldn't do". The order of chapters is an attempt at identifying the priority of the configuration based upon the likelihood that it will be helpful, and the potential benefit/harm of the configuration.
There is also a page elsewhere on reporting a security issue.
Site administrators should also sign up for the security mailing list. People interested in discussing security should join Best Practices in Security Group.
There are a number of contributed modules which can help with security, not all of which are documented in this handbook. One such is the Security Review module which provides an analysis of your security configuration.
You can also read documentation for writing secure code and about the security implications of translations from localize.drupal.org.
The key to security is eternal vigilance. Updating code, both within Drupal and across your hosting infrastructure, is a necessary process to ensure you stay secure. Setting up a secure Drupal web application server and walking away is not sufficient. Be aware of the update process for your systems (The Drupal Security Team releases Security Updates each Wednesday), and ensure someone is keeping on top of this, with sufficient time allocated to perform updates to Drupal, your web server software, database software, and all other packages installed on your systems.
Security updates can be followed through the Drupal Security page.
RSS feeds are also available for core, contrib, and public service announcements.
You can also follow @drupalsecurity on Twitter.
In addition all security announcements are posted to an email list. To subscribe to email: log in, go to your user profile page and subscribe to the security newsletter on the Edit » My newsletters tab.












Comments
Securing government sites - best practices
During DrupalCon 2012 in Denver four speakers presented "Building And Securing Government Drupal Sites In The Cloud". I found this to be a nice wrap-up of security best practices. Hope it is of use: http://denver2012.drupal.org/program/sessions/building-and-securing-government-drupal-sites-cloud
Video Removed
Unfortunately the video presentation featured at this link is no longer available, it was removed from Blip last November.
The DrupalCon Denver 2012
The DrupalCon Denver 2012 Presentation on BUILDING AND SECURING GOVERNMENT DRUPAL SITES IN THE CLOUD has been moved to the Drupal Association YouTube channel:
http://www.youtube.com/watch?v=rH4Kb3EQXu8
Drupal Security Best Practices - A Guide for Governments ...
OpenConcept Consulting Inc. has developed a guide titled Drupal Security Best Practices - A Guide for Governments and Nonprofits.
https://openconcept.ca/drupal-security-best-practices-guide-governments-...
While it was originally directed at Canadian Government departments, it is our hope that this document will alleviate the time necessary to secure Drupal sites for everyone in all sectors.