A good vulnerability assessment program has many elements including risk prioritized endpoint groups and scheduled vulnerability scans followed by result reviews. However what differentiates a good program from a great program is a strong integration of the vulnerability management program with other key business and technical systems and processes. A truly powerful and great vulnerability program will tie into three of these critical systems and business processes: inventory management, patch management, risk management, application security and application security. If the systems to be scanned do not show up on the inventory management system then the system will not be patched.”]