There is some work on how to achieve good software security in an organization, e.g.: - [BSIMM](https://bsimm.com/), overview in [Computer 2016:1](http://dx.doi.org/10.1109/MC.2016.30). Other material on software security can be found here: - Wheeler's [Secure Programs](http://www.dwheeler.com/secure-programs/) - Viega and McGraw's [Building Secure Software: How to Avoid Security Problems the Right Way](https://books.google.se/books/about/Building_Secure_Software.html) - McGraw's [Software Security: Building Security In](http://www.swsec.com/book/)