Penetration test resultsprovide direct evidence of the vendor's technical security posture and ability to defend against real-world attacks. This is more effective than reviewing contracts or benchmarking, which are indirect measures. Reference:CRISC Manual - Domain 2, Slide 174-176