https://www.sans.org/reading-room/whitepapers/analyst/assessing-application-security-buyers-guide-37000