Tim Semchenko discusses documenting acceptance of risks and implementing compensating controls as options when pentest[…]