A vulnerability management analyst is reporting program maturity to leadership. The report already lists open critical vulnerabilities, but leadership asks whether the program process itself is failing. Which report element best communicates a program-level weakness rather than individual technical findings?
Select an answer to reveal the explanation.
Short Explanation
Think of a vulnerability report like a scoreboard: counting open bugs tells you the game is busy, but missing owners tells you nobody is playing your position. You need to show leadership where the process breaks, not just which hosts are leaking. That's why an ownership gap is the maturity signal here.
Full Explanation
Program maturity reporting evaluates whether the vulnerability management lifecycle operates reliably, not merely how many findings exist. Missing remediation owners is a program-level weakness because it shows a broken accountability process: findings may be detected, but no accountable person or team is assigned to close them. That gap undermines SLA enforcement, exception handling, and continuous improvement, so it belongs in a maturity report. A list of open critical CVEs sorted by exploit availability is a tactical findings list; it may support prioritization, but it does not explain whether the program process is failing. A count of hosts with missing scan credentials on one subnet is an operational data-quality issue tied to a limited technical condition, not a program-level weakness unless it is generalized across the enterprise. A list of top ten vulnerabilities affecting internet-facing assets is also a prioritized technical exposure view, useful for triage but not a process maturity indicator. Exam caveat: maturity questions ask for governance, ownership, SLA, exception, or coverage process gaps rather than raw finding counts. Operational check: review a sample of closed and open findings to confirm each has an assigned owner, SLA clock, and documented exception when closure is delayed.