Correct Answer: D
The correct answer is D. The organization's systems inventory is kept up to date.
The completeness of vulnerability scanning depends first on whether the organization knows all systems that should be scanned. If the inventory is incomplete or outdated, some servers, endpoints, databases, cloud assets, applications, or network devices may be excluded from scanning. This creates a false sense of security because the vulnerability scan may appear successful while critical assets were never assessed.
A current inventory supports scan coverage, scope definition, vulnerability ownership, remediation tracking, and risk prioritization. ISACA's CISA Exam Content Outline includes threat and vulnerability management, information asset security, network and endpoint security, and security testing tools and techniques under the protection of information assets area.
Option A is important for access control over the scanning tool, but it does not prove the scan included all relevant systems. Option B is useful for governance and reporting, but reporting results to the CISO does not prove completeness. Option C is not relevant because whether the scanning tool is cloud-hosted or on- premises does not determine whether the full environment is scanned.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA Interactive Glossary, "Vulnerability scanning" and "Vulnerability management."