When managing software security governance, which document should define the organization's high-level security expectations for all software development projects?
This is the governance-level document that sets expectations.
Why this answer
A Software Security Policy (SSP) establishes the enterprise-wide standards, expectations, and mandatory controls for all software lifecycles.