Security is dynamic, situational, and consists of trade-offs. I consider the information here a starting point for reaching your own informed decision, or reviewing an existing policy or decision. Never take any security advice unconditionally.
Auditing your Drupal Website - A Checklist
Kiran Singh, Specbee, May 17, 2022
Drupal Security Modules and Best Practices for Your Website
Jakub Woźniak, Droptica, Sep 24, 2021
Files directory getting out of control? Audit it!
Michael Anello, DrupalEasy
Top Security Modules for Your Drupal 9 Website
The Drop Times, Jul 6, 2022
Keeping track of upstream security issues
James Oakley, oakleys.org.uk, Aug 26, 2022
audit and Drush