1. NIST Special Publication 800-218, Secure Software Development Framework (SSDF) Version 1.1. The practice PW.5, "Test executable code to identify vulnerabilities and verify compliance with security requirements," explicitly states that testing activities like penetration testing "may be performed by an independent third-party organization to provide a higher level of independence and objectivity." (Section 2, Practice PW.5, Page 16).
2. OWASP Software Assurance Maturity Model (SAMM) v2.0. The "Security Testing" business function includes the "Penetration Testing" security practice. It describes how organizations can "engage external penetration testers to get an independent view of the application’s security posture." This aligns directly with hiring external experts for reviews. (Security Practices, Security Testing (ST), Penetration Testing (ST3.2), Page 61).
3. McGraw, G. (2006). Software Security: Building Security In. Addison-Wesley Professional. Chapter 8, "Penetration Testing," discusses the value of using external, independent teams (often called "tiger teams") to perform security reviews and penetration tests. The text emphasizes that "an external review provides an unbiased 'fresh eyes' perspective." (Chapter 8, Page 189).