https://www.sans.org/reading-room/whitepapers/critical/triaging-enterprise-application-security-assessments-37387