WebAppSec-Guidelines This repo has some high level documents you could use to build your application security program.