pattern & practices are working on a new guide, called "Improving Web Services Security"k which is now available as a beta on codeplex. I haven't read it yet, but by just browsing throught the index and some of the initial chapters I can say that it looks very interesting. WCF is a more complex environment, than the old stacks that it replaces, and security can be really hard so it is great that they have choosen to publish a guide for that. Unfortunately they don't cover Federation, Claims Authorization or Security Token Services.