{"id":99008,"date":"2026-08-25T09:00:00","date_gmt":"2026-08-25T07:00:00","guid":{"rendered":"https:\/\/locaterisk.com\/?post_type=wissen&#038;draft=easm-im-ctem-prozess"},"modified":"2026-08-06T16:22:12","modified_gmt":"2026-08-06T14:22:12","slug":"easm-in-the-ctem-process","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/easm-in-the-ctem-process\/","title":{"rendered":"EASM in the CTEM Process: What Role Does External Attack Detection Play?"},"content":{"rendered":"<h1 class=\"wp-block-heading\">EASM in the CTEM Process: What Role Does External Attack Detection Play?<\/h1>\n\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li><strong>Continuous Threat Exposure Management (CTEM)<\/strong> is a continuous management approach, not a single product.<\/li><li>Gartner breaks down CTEM into scoping, discovery, prioritization, validation, and mobilization.<\/li><li><strong>External Attack Surface Management (EASM)<\/strong> It can, above all, make external assets and exposures visible for scoping and discovery.<\/li><li>EASM alone does not automatically validate a realistic attack path, nor does it coordinate cross-functional remediation.<\/li><li>An effective CTEM process feeds insights from remediation and validation back into the scope, prioritization, and metrics.<\/li><\/ul>\n<h2 class=\"wp-block-heading\">CTEM is a program for continuous exposure control<\/h2>\n<p>Continuous Threat Exposure Management (CTEM) describes a recurring process that organizations use to identify, assess, and mitigate relevant cyber exposures. Gartner defines CTEM as an integrated, iterative approach to prioritizing and continuously improving the security posture. The term shifts the focus beyond individual vulnerabilities to the question of which exposures are actually relevant for the company to address.<\/p>\n<p>An exposure can be a technical vulnerability, but it can also be a misconfiguration, unprotected access, unclear asset assignment, or a gap in a security control. CTEM links this technical information to business criticality, threat context, and feasibility. The program is not intended to generate as many findings as possible. It is designed to help teams focus their limited resources on risks that have been prioritized in a transparent manner.<\/p>\n<p>Gartner divides the process into five phases: scoping, discovery, prioritization, validation, and mobilization. This framework is an analyst model, not a technical standard. Organizations can align their existing processes with it without adopting each term verbatim. What\u2019s important is the cycle: insights from one round shape the scope and prioritization of the next.<\/p>\n<p>In this model, EASM is a potential data and discovery component. It examines the external attack surface from an outside-in perspective. The knowledge article provides an introduction to this approach <a href=\"https:\/\/locaterisk.com\/en\/know\/what-is-easm\/\">What is EASM?<\/a>. However, EASM does not automatically cover all CTEM phases.<\/p>\n<figure class=\"wp-block-table\"><table><thead><tr><th>CTEM Phase According to Gartner<\/th><th>Key Question<\/th><th>Possible EASM Contribution<\/th><th>Additional needs<\/th><\/tr><\/thead><tbody><tr><td>Scoping<\/td><td>Which business areas, assets, and consequences are the focus?<\/td><td>References to external domains, hosts, services, and dependencies<\/td><td>Business Processes, Risk Tolerance, Responsible Parties<\/td><\/tr><tr><td>Discovery<\/td><td>What exposures are present within the selected scope?<\/td><td>Outside-in identification and observation of achievable technical characteristics<\/td><td>Internal scans, cloud, identity, and configuration data<\/td><\/tr><tr><td>Prioritization<\/td><td>Which findings should be addressed first?<\/td><td>Availability, Observed Safety Characteristics, and Changes Over Time<\/td><td>Asset Criticality, Threat Level, Impact, and Effort<\/td><\/tr><tr><td>Validation<\/td><td>Is the assumed exposure realistic and usable, and is the measure effective?<\/td><td>Re-examination of Selected Characteristics by an External Party<\/td><td>Controlled tests, penetration tests, or breach-and-attack simulations<\/td><\/tr><tr><td>Mobilization<\/td><td>How does a prioritized diagnosis lead to effective treatment?<\/td><td>Verifiable Evidence and Monitoring Following the Change<\/td><td>Owners, Ticketing, Deadlines, Exceptions, and Management Decisions<\/td><\/tr><\/tbody><\/table><\/figure>\n<h2 class=\"wp-block-heading\">Scoping and Discovery: Where EASM Is Especially Useful<\/h2>\n<p>Scoping defines which areas will be examined and which impacts are relevant to the business. A scope that is too broad will yield many findings without clear accountability. A scope that is too narrow may overlook important dependencies. The starting point should therefore be a business function, such as a customer portal, a production site, or a critical service provider. From there, digital assets and the responsible teams can be identified.<\/p>\n<p>EASM supports this phase by examining the publicly visible technical relationships associated with known starting points. Microsoft lists domains, IP ranges, hosts, autonomous system numbers, and organizational information as potential discovery seeds. Observed connections yield candidates for further mapping. Such candidates must not be treated as belonging to the organization without verification.<\/p>\n<p>During the discovery phase, exposures within the selected scope are identified. EASM can identify unknown hosts, exposed services, certificate relationships, and observable configuration characteristics. It is particularly well-suited for Internet exposures that are not captured by an internal inventory. This approach generally does not require agents on the systems being analyzed.<\/p>\n<p>The external view remains only a partial picture. Internal attack vectors, identity-based access controls, local software versions, and unreachable systems require different data sources. CTEM therefore often combines EASM with vulnerability scanners, cloud security posture management, identity data, asset inventories, and manual audits. The scope determines which sources are required.<\/p>\n<h2 class=\"wp-block-heading\">Prioritization: From a List to a Justified Order<\/h2>\n<p>Discovery can generate more findings than a team can address at one time. Gartner cites urgency, severity, fixability, and the risk to the organization, among other factors, for prioritization. A CVSS score alone is not sufficient for this purpose. It describes the characteristics and severity of a vulnerability, but does not automatically reflect the importance of a specific asset to a business process.<\/p>\n<p>EASM can support prioritization based on context. An administration portal accessible from the Internet warrants different attention than an internal test service. A publicly visible, outdated service may still be relevant if it is associated with a critical business process. External monitoring can also reveal whether an issue has newly emerged, is recurring, or remains visible after a change has been made.<\/p>\n<p>A robust prioritization scheme combines at least four perspectives: technical severity, actual exposure, business criticality, and current threat. For technical classification, a <a href=\"https:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> Provide recurring measurement values. The rating is a decision-making indicator, not the sole basis for approving actions.<\/p>\n<p>LocateRisk cross-checks reports from multiple sources on relevant vulnerability topics against the observed attack surface, even if a final NVD assessment is not yet available. This preemptive intelligence can help ensure that prioritization remains up to date. However, it does not in every case prove that a specific software version is vulnerable. Reports must be validated using vendor information, internal version data, and, if necessary, a controlled test.<\/p>\n<h2 class=\"wp-block-heading\">Validation: Systematically Testing Assumptions and Measures<\/h2>\n<p>Gartner describes validation as a controlled simulation or emulation of an attack to understand how an attacker might exploit a vulnerability. Manual penetration tests, red team exercises, or automated breach-and-attack simulations can be used for this purpose. The choice depends on risk, scope, and the acceptable level of testing depth.<\/p>\n<p>EASM can provide both a preliminary assessment and a follow-up review. It identifies which publicly visible characteristics warrant validation. After a configuration change, a new external observation can verify whether the service remains accessible or whether the reported issue still appears. This is not confirmation of an exploit and does not replace an authorized security test.<\/p>\n<p>Validation also applies to the planned treatment. A technical measure may be effective but could disrupt a business process. Conversely, a simple organizational change may only reduce the risk to a small extent. The CTEM process should therefore clarify, prior to implementation, what effects are expected and how they can be measured. Suitable metrics include, for example, the removal of public accessibility, the activation of a security control, or documented risk acceptance.<\/p>\n<p>With third-party service providers, the scope of the audit is limited. External evidence may prompt an inquiry and lead to prioritization, but the supplier must confirm internal causes and corrective actions. The page <a href=\"https:\/\/locaterisk.com\/en\/landing\/third-party-risk-management\/\">Third-party risk management<\/a> shows how technical observations can be linked to a supplier process.<\/p>\n<h2 class=\"wp-block-heading\">Mobilization: Translating Findings into Appropriate Actions<\/h2>\n<p>Mobilization links the prioritized finding with an actionable remedy. Gartner emphasizes collaboration between security, IT, and business units. A finding requires an owner, a clear risk context, a decision, and a deadline. Without these elements, even a good technical analysis will have no impact.<\/p>\n<p>A practical data set includes the affected asset, external evidence, potential impacts, recommended next steps, the responsible department, and the status. Interfaces with ticketing or workflow systems minimize data discontinuities. However, automation should not force unverified asset assignments or actions. Responsible approval remains necessary, especially for production systems.<\/p>\n<p>EASM supports communication because screenshots, timestamps, and observable characteristics can provide a common factual basis. A management dashboard should not merely count open findings. More helpful are metrics on processing time, recurrence rates, the exposure of critical services, and demonstrated risk reduction.<\/p>\n<p>To gain an initial structured outside perspective, one can <a href=\"https:\/\/locaterisk.com\/en\/landing\/it-risk-analysis\/\">Security Rating<\/a> Highlight relevant exposures and responsibilities. The subsequent workflow determines whether this results in a CTEM capability. Responsibility, however, remains with the program.<\/p>\n<h2 class=\"wp-block-heading\">The feedback loop makes CTEM continuous<\/h2>\n<p>CTEM does not end with the closure of a ticket. The results of one round provide data for the next. If unknown cloud hosts frequently appear, the new scope should incorporate the deployment process. If findings recur, a centralized configuration policy may be more effective than individual corrections. If a validation refutes the assumed impact, the prioritization model must be adjusted.<\/p>\n<p>The feedback loop consists of three levels. At the asset level, a review is conducted to determine whether the exposure has been eliminated or accepted. At the process level, an assessment is made of why the exposure arose and whether controls are effective. At the program level, an analysis is conducted to determine whether the scope, data sources, and key performance indicators adequately reflect the relevant risks. EASM provides recurring outside-in observations for this purpose and makes changes measurable over time.<\/p>\n<p>A good place to start is with a limited, business-oriented scope that clearly defines who is responsible. Document the five phases, establish input and output criteria, and measure the time from discovery to verified resolution. After a few cycles, it will become clear which additional data sources or validation procedures are actually needed.<\/p>\n<p>In addition, define a fixed schedule. Critical external changes can trigger an immediate review, while the program level is evaluated, for example, on a monthly or quarterly basis. A scheduled review should address open exceptions, recurring findings, overdue actions, and changes in scope. The frequency should be based on the risk and the rate of change in the environment. A static annual report does not meet the requirement for continuous monitoring, even if the underlying data collection is automated.<\/p>\n<p>A few clear metrics are suitable for measuring success: time to assign an owner, time to validation, percentage of prioritized exposures addressed on time, and recurrence rate. A declining number of findings alone does not prove success, because a narrower scope or a failed data source can also reduce that number. Key metrics therefore always require scope, data status, and technical context.<\/p>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is CTEM a product or a software category?<\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">CTEM is a continuous management approach. Tools such as EASM, vulnerability scanners, CAASM, or validation solutions can support individual phases. Responsibilities, prioritization rules, and risk management remain organizational tasks.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Which CTEM phases does EASM support?<\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">EASM is particularly useful for scoping and discovering the external attack surface. It can also provide exposure data for prioritization and external follow-up after corrective actions have been taken. Validation and mobilization require additional procedures and clearly defined responsible parties.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does EASM replace penetration tests in the CTEM process?<\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. EASM monitors external assets and technical characteristics. A penetration test, with the appropriate authorization, can examine specific attack vectors in greater depth. CTEM can use both methods in a targeted manner to address different issues.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How does a medium-sized company get started with CTEM?<\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">A limited scope focused on a critical business process is appropriate. Define assets, responsible parties, prioritization criteria, a validation procedure, and a mandatory remediation workflow. The results of the first round will improve the next round.<\/p><\/div><\/div><\/div><\/div>\n\n<p>Would you like to test external discovery as a component of your exposure management process? <a href=\"https:\/\/locaterisk.com\/en\/landing\/it-risk-analysis\/\">Schedule an IT risk assessment with LocateRisk<\/a> and work with us to define a clear scope.<\/p>","protected":false},"excerpt":{"rendered":"<p>CTEM combines scoping, discovery, prioritization, validation, and mobilization. EASM provides an external perspective on this, but does not cover the entire process on its own.<\/p>","protected":false},"author":6,"featured_media":0,"template":"","wissen_thema":[818],"class_list":["post-99008","wissen","type-wissen","status-publish","hentry","wissen_thema-easm-angriffsflaeche"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>EASM im CTEM-Prozess erkl\u00e4rt \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"Wie EASM den CTEM-Prozess unterst\u00fctzt: externe Discovery, Priorisierung, Validierung, Mobilisierung und eine kontinuierliche Feedbackschleife.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/know\/easm-in-the-ctem-process\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"EASM im CTEM-Prozess erkl\u00e4rt \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"Wie EASM den CTEM-Prozess unterst\u00fctzt: externe Discovery, Priorisierung, Validierung, Mobilisierung und eine kontinuierliche Feedbackschleife.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/know\/easm-in-the-ctem-process\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/easm-im-ctem-prozess\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/easm-im-ctem-prozess\\\/\",\"name\":\"EASM im CTEM-Prozess erkl\u00e4rt \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-25T07:00:00+00:00\",\"description\":\"Wie EASM den CTEM-Prozess unterst\u00fctzt: externe Discovery, Priorisierung, Validierung, Mobilisierung und eine kontinuierliche Feedbackschleife.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/easm-im-ctem-prozess\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/easm-im-ctem-prozess\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/easm-im-ctem-prozess\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"EASM im CTEM-Prozess: Welche Aufgabe \u00fcbernimmt die externe Angriffserkennung?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"EASM Explained in the CTEM Process \u2013 LocateRisk","description":"How EASM supports the CTEM process: external discovery, prioritization, validation, mobilization, and a continuous feedback loop.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/know\/easm-in-the-ctem-process\/","og_locale":"en_US","og_type":"article","og_title":"EASM im CTEM-Prozess erkl\u00e4rt \u2013 LocateRisk","og_description":"Wie EASM den CTEM-Prozess unterst\u00fctzt: externe Discovery, Priorisierung, Validierung, Mobilisierung und eine kontinuierliche Feedbackschleife.","og_url":"https:\/\/locaterisk.com\/en\/know\/easm-in-the-ctem-process\/","og_site_name":"LocateRisk","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/wissen\/easm-im-ctem-prozess\/","url":"https:\/\/locaterisk.com\/wissen\/easm-im-ctem-prozess\/","name":"EASM Explained in the CTEM Process \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-25T07:00:00+00:00","description":"How EASM supports the CTEM process: external discovery, prioritization, validation, mobilization, and a continuous feedback loop.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/wissen\/easm-im-ctem-prozess\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/wissen\/easm-im-ctem-prozess\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/wissen\/easm-im-ctem-prozess\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"EASM im CTEM-Prozess: Welche Aufgabe \u00fcbernimmt die externe Angriffserkennung?"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99008","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/6"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99008\/revisions"}],"predecessor-version":[{"id":99018,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99008\/revisions\/99018"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=99008"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=99008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}