1. Mitre. 2011 CWE/SANS Top 25 Most Dangerous Software Errors.
http://cwe.mitre.org/top25/
, 2011. Site visited on 2014-01-06.
2. National Institute of Standards and Technology (NIST). National Vulnerability Database.
http://nvd.nist.gov/
. Site visited on 2014-01-06.
3. M.P. Gallaher and B.M. Kropp. The Economic Impacts of Inadequate Infrastructure for Software Testing. Technical Report Planning Report 02-03, National Institute of Standards & Technology, May 2002.
4. Howard, Michael; Lipner, Steve (June 2006). The Security Development Lifecycle: SDL: A Process for Developing Demonstrably More Secure Software. Microsoft Press.
5. Achim D. Brucker and Uwe Sodan. Deploying Static Application Security Testing on a Large Scale. In GI Sicherheit 2014. Lecture Notes in Informatics, GI, 2014.