Did you define a support group for every CI then and just query off that to see if there are any associated vulnerable items?