Awesome! Thanks much for providing the link MsM.

This may actually help in a discussion we are having here. Someone in our audit organization has suggested that we (internal Audit) start performing "sample penetration testing" and rely on tests from our internal IT security organization as part of our sampling. Does that seem feasible? Objective? Logical? Let me know if I need to clarify.

Thanks again MsM!