How does audit validate the pentest program? - What should audit independently test? - How does audit report to the board?