Why: The practice's ranking inputs — exploitability, exposure, asset criticality — are risk-assessment reasoning applied at the finding level, and its outputs (exposure trends, open known-exploited findings) are among the concrete inputs a periodic organizational risk assessment should consume.
What this does not claim: The requirement is a full organizational assessment — plausible threats and the consequences of CUI exposure for operations, assets, and individuals — which no vulnerability-management program performs. The practice informs one input to that assessment; the assessment itself, its cadence, and its record are separate governance work that must exist independently.
- Feed scan findings and exposure trends into the periodic risk assessment as evidence
- Use the assessment's asset-criticality judgments to weight remediation ranking, closing the loop in both directions
- Risk-assessment records citing vulnerability data among their inputs
- Ranking criteria that reference assessment-derived asset criticality
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06