Your monthly SLA compliance report shows overdue critical vulnerabilities concentrated in Finance and Marketing. Which reporting action most directly drives remediation discipline?
Select an answer to reveal the explanation.
Short Explanation
Think of an SLA report like a scoreboard, not a suggestion box. If critical vulnerabilities are overdue, you need to point the scoreboard at the business unit owner and make the breach visible. That escalation is what moves remediation, not another pile of raw scanner data.
Full Explanation
Vulnerability management reporting is a governance mechanism, not just a technical dashboard. When an SLA compliance report identifies overdue critical vulnerabilities by business unit, the analyst should communicate breach details to the accountable owners so remediation deadlines become a management issue rather than a backlog item. Targeted escalation preserves ownership, applies pressure at the correct organizational level, and creates an audit trail for risk acceptance or exception review. Aggregating all overdue findings into a broad weekly email dilutes accountability because no business unit sees its own exposure as a named obligation. Publishing raw scanner output to a SOC wiki may help technical investigation, but it does not move business owners to remediate and can expose sensitive vulnerability data unnecessarily. Changing SLA thresholds to match current remediation rates weakens the control; SLAs should reflect acceptable risk and be revised through governance, not lowered to make performance look acceptable. Exam caveat: choose the reporting action that assigns ownership and escalates exceptions, not the action that simply produces more data. Operational check: confirm each overdue critical item in the report lists asset owner, due date, business unit, and escalation contact before sending breach notices.