| ▲ | regularfry an hour ago | |
Any org large enough to have separated the people responsible for the security exposure of the organisation from the developers with familiarity of what's deployed is likely to have done exactly this. The thing you have to remember is that CVEs can be a) scanned for without exerting mental effort, and b) counted. | ||