An IS auditor is assessing an organization's vulnerability management program. Which metric is MOST useful for evaluating the program's effectiveness?
-
A
Total number of vulnerabilities discovered per scan
-
B
Mean time to remediate critical vulnerabilities
-
C
Number of security scans performed per quarter
-
D
Percentage of systems covered by the vulnerability scanner