Are development teams ultimately responsible for insecure software?
The default responsibility for preventing security vulnerabilities in source code often falls to the development organization. However, no matter how hard you try to write or approve only secure code, we cannot forget that security holes, or “bugs,” can be introduced even when secure programming is practiced. Still it is important, to the extent possible, to minimize the introduction of security vulnerabilities in code.