Chris,
You asked what I recommend, not what is "recommended". There isn't a page that I based that info off of -- it's from personal experience. I have yet to see a major drupal installation that has been routinely hacked, cracked and used to host child porn, IRC (eggbot anyone?), phishing scams, etc., or provide a way to test privilege escalation attacks after gaining shell access as the Apache system account user. As for Mambo/Joomla, I see these literally every night I am at work. Many times it is the same sites again and again.
A number of sysadmins I know from work or from other associations use Drupal. That's how I learned of it, myself.
Perhaps I should put up a page. But then it would be drowned out by pages with expertise like "
Why chmod 777 is NOT a security risk". Ya know?