The following security guidance is now available on MSDN:

Guidelines:

Checklists: