A regional library consortium runs many APs and controllers but has no process to watch CVE or vendor advisories for WLAN gear. What gap should be called out?
Select an answer to reveal the explanation.
Short Explanation
If nobody is watching the CVE firehose, the consortium is flying blind. Standing up continuous WLAN vulnerability monitoring is the gap—not prettier SSIDs or fewer policy reviews.
Full Explanation
Continuous monitoring of vulnerability information sources is required to keep WLAN components current against newly published issues. Absence of a CVE/advisory watch process is itself a control gap under Domain 2.1.1. Aesthetic SSID choices and analyzer use are unrelated; policy review cadence does not replace technical vulnerability intelligence.