There's already a "Securing Your Installation" section of Installation Guide at http://guides.dataverse.org/en/4.4/installation/config.html#securing-your-installation but its focus is installation time, not ongoing security.
How should institutions who run Dataverse be alerted that they should upgrade as soon as possible to new versions of Dataverse that have security fixes?
Both @Venki18 and @lwo have mentioned that perhaps there should be some sort of mailing list that they and others could subscribe to who are interested in security (I'm looking at you @donsizemore).
Should the mailing list be "announce" style where people can't reply? This would be the Dataverse team sending security advisories. If the list is private, perhaps a pre-release announcement could be made that a security hole has been found and that a fix is being tested. This would give sysadmins a heads up that they should upgrade soon, once the release comes out.
Should the mailing list be "discussion" style instead, where subscribers could privately share findings related to security, such as results from security scans? (These should absolutely be sent first to security@dataverse.org to open a private ticket as explained in CONTRIBUTING.md to start some tracking around the issue. This was originally discussed on the dataverse-community mailing list.)
Should there be a page at http://dataverse.org dedicated to security that the Installation Guide links to? That's really what this issue is about... what resources to link to about ongoing security, how to subscribe to advisories, etc.
First we need to decide if we should create any of the mailing lists or pages mentioned above. I'm sure others have ideas as well. Please leave comments here if you have any thoughts or suggestions!