This document discusses Drupal security best practices. It begins with introducing Mediacurrent and its vision to empower people with open source technology. It then provides an agenda on Drupal security covering Security-First planning, the Drupal security team and resources, common vulnerabilities, and Drupal best practices such as module selection, patching, and API usage. The document emphasizes automating security processes, monitoring advisories, and cultivating a security-focused culture.