There's an assumption baked into most vulnerability management programs that nobody ever wrote down, because nobody had to.