Mention example from [Implementing S4 - Source-code Security Scanning Services - v0.5.pdf](https://github.com/DinisCruz/Security-Research/blob/master/pdfs/Implementing%20S4%20-%20Source-code%20Security%20Scanning%20Services%20-%20v0.5.pdf)  Here is a good post on this topic ["Mr Security Consultant: 'Are You Doing A Good Job' for your clients?"](http://blog.diniscruz.com/2009/11/mr-security-consultant-are-you-doing.html)