External audit of DevSecOps implementation and external penetration test/red team not provided. Is it acceptable to propose a change request?