Answer:
The most specific answer may be that if you have risks in these areas, they should all be audited at one time or another with penetration testing based on the degree of risk.
It wouldn't be so much an issue as to what audit was conducted, but rather that an audit was conducted.
First published on BankersOnline.com date 1/6/03