https://github.com/OWASP/www-project-devsecops-verification-standard/pull/9
OWASP/www-project-devsecops-verification-standard#9