Contemporary information systems (IS) development within organizations involves multiple interconnected systems, a variety of development practices and also outsources responsibilities to third parties. It hence introduces new threats, new vulnerabilities and in consequence new security problems for the IS. In this paper we propose a theoretical framework to facilitate the implementation of secure IS into this contemporary, particularly complex, organisational environment. We start our study by examining organisational and systems development issues, such as the involved stakeholders and their security requirements. We then relate this theory to practice by identifying all those concepts that materialise the stakeholders’ security understanding to specific security objectives and the tools in which they are manifested. Finally, we inspect various published cases in order to examine the use of these tools within organisations, so as to realise our theoretical design and prescribe its further use.