Risk-based vulnerability management according to a CISO