The practice of building secure applications has been challenging for decades for research community and industries as highlighted by news and statistics. The main reasons are the lack of knowledge and guidance for developers, and the fact that software security has traditionally been treated as an afterthought leading to a cycle of “penetrate and patch”. This thesis proposes a framework that supports the integration and the improvement of security in the Software Delivery Life Cycle (SDLC) based on the Object-Oriented paradigm, the UML standards, the development life cycle and the Software Assurance Maturity Model (SAMM). We have defined an asset as an “object” and we have built the Object Based Access Control (OBAC) model from which we have refined the security concepts. This brings more granularities in the protection of the asset. Based on this model, we have reviewed security concepts like Misuse Cases and Security Use Cases. They have been formalized and positioned on the UML meta-model to make sure security is taken into account at the beginning of the SDLC. To deal with the regulation and corporate standards that extend the security requirements, we have introduced the Upper Security Specification Layer (USSL)and the Application Security Specification Layer (ASSL) in the security process. All these concepts are integrated in the SAMM and a SDLC model to constitute our framework. Finally, a case study demonstrates the improvement of maturity levels by using this framework.