The following pdf depicts about how we can maintain ongoing web application security from blackbox testing perspectives.
http://yehg.net/lab/pr0js/view.php/OWA-SM.pdf