How security is built into the way you design and ship software.
Do you have a documented secure SDLC policy that developers are aware of?
Are security requirements defined during design, before code is written?
Do you perform security reviews before major releases?
How are security bugs tracked relative to functional bugs?
Do you have a secure coding standard for your primary languages/frameworks?