SaaS security solutions such as "WhiteHat Sentinal" and "Fortify on Demand" are getting popular now a days. Methodologies of both describe them involving manual verification. Does this qualify the Application security assessment report produced by them as Penetration test report. or would they just still be considered a VA (Vulnerability assessment) report. Does anyone have an understanding on the working of these solutions.
Also, Are there any proper Standards defined by any established organization such as NIST, OWASP, SANS, etc for qualifying an assessment as a Penetration test.
Thanks
PS. I do know the difference between a VA and a PT.