This objective ensures your organization has formally documented how flaws and vulnerabilities are identified in systems and applications that handle Controlled Unclassified Information (CUI). Your documentation must show what tools, methods, and processes are used for vulnerability detection.