Show why the vulnerability came first—and what changed when it was treated
Strong vulnerability-management evidence connects the finding to asset and threat context, then preserves treatment, implementation and validation records through closure.
Vulnerability Prioritisation Evidence
Retain the vulnerability and score source/date, affected asset and business service, internet or trust exposure, known-exploitation status, exploit-probability signal where used, technical severity, business consequence, compensating controls, accountable owner, target date and exception rationale.
Open evidence pattern →Evidence domainVulnerability Remediation & Closure Evidence
Retain the affected scope, approved treatment, implementation/change evidence, failed or deferred assets, post-change validation, remaining exposure, exception or residual-risk decision, reviewer and closure date. The closure record should be reproducible enough to explain what changed and how that was verified.
Open evidence pattern →Exposure guides
Connect evidence to KEV, EPSS, CVSS and risk-based prioritisation decisions.
Exposure ManagementControl evidence
Compare exposure evidence with broader vulnerability-management control evidence.
Vulnerability evidenceMethodology
See the rules used to avoid overstating scores, exploit signals or remediation results.
Read methodology