The National Institute of Standards and Technology (NIST) Computer Security Resource Center (CSRC) has released five new documents:

SP 800-64: Security Considerations in the Information System Development Life Cycle

SP 800-50: Building an Information Technology Security Awareness and Training Program

SP 800-42: Guideline on Network Security Testing

SP 800-36: Guide to Selecting Information Security Products

SP 800-35: Guide to Information Technology Security Services

I haven't read them myself yet so I can't vouch for them, but NIST docs are usually decent reference material. They can't be too bad for free.