% Daan: If you would have to do something like this again? (...)
We have noticed that, when doing an audit in a team, it is not feasible for
-everybody to have read all source code. Henceforth, trying this is just a bad
+everybody to have read all source code. Trying this is just a bad
idea. We are happy to have divided the project by ASVS category, instead of
program component. For each requirement the the ASVS, the
team had to verify that there were no mistakes in the code. This would have