The city CISO must update leadership on open vulnerabilities, remediation progress, and residual risk for critical citizen services. Which vulnerability-management activity does this communication fulfill?
Select an answer to reveal the explanation.
Short Explanation
Leaders need the story, not a raw dump of scanner noise—how many open vulns, what is fixed, and what risk is left on citizen services. That status roll-up is reporting, and it does not mean turning scanners off or posting exploit kits.
Full Explanation
Reporting communicates vulnerability status, trends, and risk in business context so stakeholders can fund and prioritize remediation. Effective reports pair metrics with exposure and service impact rather than only raw counts. Suppressing scans, omitting technical work, or releasing exploit details are not substitutes for responsible vulnerability reporting.