There exist an interesting model for measuring Software Security called BSIMM.
Their Software Security Framework covers 4 domains and 12 practises.
The maturity is described with levels, and one can compare own result agains the average.
Main links
- Facts
- Community with list of companies
- Software Security Framework