Tell that to PCI-DSS auditors.
rofl. Yes, I understand. I was talking about reality, though.
I have to deal with vuln reports all the time, and all the time, I have to put those auditors in their place. They don't actually know what they are doing.