https://www.sans.org/reading-room/whitepapers/analyst/2015-state-application-security-closing-gap-35942