Direct answer
Retain the vulnerability and score source/date, affected asset and business service, internet or trust exposure, known-exploitation status, exploit-probability signal where used, technical severity, business consequence, compensating controls, accountable owner, target date and exception rationale.
Evidence to retain
Finding identity
EvidenceCVE/finding identifier
EvidenceScanner or source
EvidenceScore/vector and source
EvidenceDiscovery and last-seen date
Asset context
EvidenceAffected asset/service
EvidenceBusiness owner
EvidenceInternet/trust exposure
EvidencePrivilege/data/operational consequence
Threat context
EvidenceCISA KEV status where relevant
EvidenceEPSS score and date where used
EvidenceExploit evidence
EvidenceCurrent threat notes
Decision evidence
EvidencePriority/treatment
EvidenceOwner and due date
EvidenceCompensating control
EvidenceException/residual-risk rationale
Relevant Cybatar sources
Cybatar sourcehttps://crgexplore.com/platform/exposure-vulnerability-managementCybatar sourcehttps://crgexplore.com/security-problems/vulnerability-prioritisation-backlogCybatar sourcehttps://crgexplore.com/control-evidence/vulnerability-managementCybatar sourcehttps://crgexplore.com/evidence
External references
CISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalogFIRST EPSShttps://www.first.org/epss/FIRST CVSS v4.0https://www.first.org/cvss/v4.0/
Claim boundary
Prioritisation evidence explains a decision at a point in time. It does not prove future exploitation, complete asset discovery or the absence of other attack paths.