Who should be involved in securing a Drupal Site?

Events happening in the community are now at Drupal community events on www.drupal.org.
VinceW's picture

A lot of attention is given to writing secure code for drupal. But is securing a drupal site only a matter of writing/using correct coding, or are other roles as much responsible for securing a Drupal Site?

What's the role and task regarding security of:

  • A coder
  • A developper
  • A site admin
  • drupal.org
  • Endusers
  • Organisations