{"id":99023,"date":"2026-09-24T09:00:00","date_gmt":"2026-09-24T07:00:00","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=99023"},"modified":"2026-08-06T16:22:12","modified_gmt":"2026-08-06T14:22:12","slug":"check-it-security-service-providers","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/check-it-security-service-providers\/","title":{"rendered":"Check IT Security of Service Providers: Questionnaire, Evidence and External Signals"},"content":{"rendered":"<h1 class=\"wp-block-heading\">Check IT Security of Service Providers: Questionnaire, Evidence and External Signals<\/h1>\n\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li>First, check performance, data, access, and impact of failures. This defines the scope and depth of the audit.<\/li><li>A questionnaire explains internal controls; certificates and reports can substantiate statements for a defined scope.<\/li><li>External signals complement the internal view and show reachable systems or changes. They require attribution and context.<\/li><li>A deviation is clarified with the service provider before the decision. Evidence, measures, deadlines, and residual risk belong in the file.<\/li><li>Approval and monitoring are based on criticality. Not every service provider requires the same audit effort.<\/li><\/ul>\n<h2 class=\"wp-block-heading\">An audit path for a specific service provider decision<\/h2>\n<p class=\"wp-block-paragraph\">An IT service provider receives access to data, systems, or business-critical processes depending on the contract. Therefore, the security audit must consider the specific service. A general questionnaire or a certificate without an appropriate scope is not sufficient for a reliable decision. Similarly, a technical external view does not reflect internal processes.<\/p>\n<p class=\"wp-block-paragraph\">A practicable audit path connects business context, self-disclosure, evidence, and external signals. It separates observed facts from assumptions and leads open points to a documented approval. This article focuses on conducting a single service provider audit. The organization-wide framework for inventory, roles, and portfolio monitoring is described in the <a href=\"https:\/\/locaterisk.com\/en\/landing\/third-party-risk-management\/\">Third-party risk management<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Step 1: Define Criticality and Audit Scope<\/h2>\n<p class=\"wp-block-paragraph\">Do not start with a long list of questions. First, describe what service the provider offers and how it is integrated into your processes. Relevant information includes affected business processes, types of data, technical interfaces, administrative rights, operational locations, subcontractors, and expected availability. An internal owner must confirm this information.<\/p>\n<p class=\"wp-block-paragraph\">Criticality determines the depth of the audit. A provider with privileged remote access to production systems requires different evidence than a service provider that creates publicly available content. Interchangeability and possible concentrations also count. If several important processes depend on the same cloud or support provider, a single event can affect multiple areas.<\/p>\n<p class=\"wp-block-paragraph\">Next, define the scope. Which company, which service, which environment, and which timeframe will be audited? Which subcontractors are essential for the service? Which domains or brands belong to the technical external view? The scope prevents two common mistakes: Evidence is transferred to a service not covered, or an external resource is attributed to the provider without adequate allocation.<\/p>\n<p class=\"wp-block-paragraph\">The audit also needs a decision threshold. Specify in advance who may approve a service, when information security or data protection should be included, and which deviations require a management decision. This way, a tight project deadline does not unnoticed change the risk tolerance.<\/p>\n<h2 class=\"wp-block-heading\">Step 2: Request Self-Disclosure and Evidence Purposefully<\/h2>\n<p class=\"wp-block-paragraph\">The security questionnaire should close information gaps. Only inquire about controls that fit the service and access paths. Typical topics include identity and access management, secure development, vulnerability handling, logging, incident management, data backup, recovery, and management of subcontractors. Open questions are useful when processes and responsibilities need to be clarified. Standardized response fields make comparison easier.<\/p>\n<p class=\"wp-block-paragraph\">Request suitable evidence for important statements. An ISO\/IEC 27001 certification refers to an information security management system within a specified scope. Check the certificate, issuing body, validity, and scope. A SOC 2 report can provide information about controls of a service organization. For cloud services, an audit report based on the BSI criteria catalog C5 may be relevant. The certification is conducted by independent external auditors and is not a BSI certification. Which evidence is suitable depends on service, region, and audit objective.<\/p>\n<p class=\"wp-block-paragraph\">A document title alone is not sufficient. Check the period, covered systems, excluded locations, findings, management reactions, and controls the customer must implement themselves. A current report for another service may be less informative than a targeted technical statement about the actually used product.<\/p>\n<figure class=\"wp-block-table\"><table><thead><tr><th>Examination Question<\/th><th>Suitable information source<\/th><th>What to pay attention to?<\/th><\/tr><\/thead><tbody><tr><td>What internal processes apply?<\/td><td>Questionnaire, policy, interview<\/td><td>Responsibility, scope, status<\/td><\/tr><tr><td>Has a management system been audited?<\/td><td>Certificate and scope<\/td><td>Company, service, location, validity<\/td><\/tr><tr><td>How did controls perform during the audit period?<\/td><td>SOC, C5, or other audit report<\/td><td>Type, period, exceptions, customer controls<\/td><\/tr><tr><td>How are technical risks managed?<\/td><td>Penetration test summary, vulnerability process<\/td><td>Scope, age, open significant findings, re-examination<\/td><\/tr><tr><td>What is currently externally visible?<\/td><td>External IT risk analysis<\/td><td>Attribution, timestamp, technical limit<\/td><\/tr><\/tbody><\/table><\/figure>\n<h2 class=\"wp-block-heading\">Step 3: Use external signals as a second perspective<\/h2>\n<p class=\"wp-block-paragraph\">An external analysis examines identified or reachable systems without installing software at the service provider. It can reveal domains, services, certificate and configuration features as well as indications of deployed software. A <a href=\"https:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> condensed selection of observations is categorized into understandable categories or key figures.<\/p>\n<p class=\"wp-block-paragraph\">This external view answers a different question than the questionnaire. It does not show how an internal access review is conducted or whether a recovery plan has been tested. It may also not necessarily recognize the specific vulnerable version of a software. Thus, a visible product characteristic or a potential vulnerability relationship is initially an audit indication.<\/p>\n<p class=\"wp-block-paragraph\">Check the attribution before the assessment. Shared hosting, content delivery networks, and outsourced mail services can lead to misassignments. Document why a resource is attributed to the service provider or the acquired service. If security is low, the candidate belongs in clarification and not as a confirmed finding in the release decision.<\/p>\n<p class=\"wp-block-paragraph\">The external perspective is especially useful when self-reports and observed states do not match. If a provider reports a regulated certificate process, but the external view shows an expired certificate, a specific follow-up question arises. The answer may indicate a misattribution, a non-productive service, or a process deviation. Only then is the risk assessed.<\/p>\n<h2 class=\"wp-block-heading\">Step 4: Clarify deviations and assess evidence<\/h2>\n<p class=\"wp-block-paragraph\">Compile open points in a structured finding list. Each entry includes requirement, observed state, source, date, affected service, and desired clarification. Distinguish between missing information, insufficient control, and technical findings. These categories lead to different responses.<\/p>\n<p class=\"wp-block-paragraph\">Provide the service provider with an appropriate opportunity to respond. Share technical evidence via a secure channel and do not state any further conclusions than the data supports. A response should address the specific resource and the audit time. General marketing materials do not resolve a specific finding.<\/p>\n<p class=\"wp-block-paragraph\">Evaluate the evidence based on origin, timeliness, scope, and depth of examination. An independent audit can create more trust than a self-report, but is also limited to its scope. Internal records can document a specific process, but must be verifiable and sufficiently current. Contradictions remain visible as uncertainties until they are clarified.<\/p>\n<p class=\"wp-block-paragraph\">The clarification ends with a professional classification: confirmed, disproven, compensated, or open. With a confirmed risk, actions, responsible parties, deadlines, and expected evidence are agreed upon. A temporary exception requires justification, approver, and re-submission. This allows for later traceability of the basis on which the service was initiated or continued.<\/p>\n<h2 class=\"wp-block-heading\">Step 5: Make risk-based release decisions<\/h2>\n<p class=\"wp-block-paragraph\">The decision connects criticality and audit results. Possible outcomes are release, release with conditions, in-depth audit, change in scope, or rejection. A calculated score should not obscure hard minimum requirements. An unresolved privileged access may require a condition or technical restriction, even if other areas are well documented.<\/p>\n<p class=\"wp-block-paragraph\">The department confirms benefits and operational impact. Information security assesses cyber risks, procurement and legal examine contractual measures. Data protection evaluates the processing of personal data in a separate audit path. The business decision rests with the designated risk owner within their authority.<\/p>\n<p class=\"wp-block-paragraph\">The release file should include scope, data status, sources, key findings, open measures, and residual risk. Refer to original evidence without unnecessarily duplicating confidential reports. Also document which internal controls the customer must take on. In the case of cloud or SaaS services, this often involves configuration, roles, and secure usage.<\/p>\n<p class=\"wp-block-paragraph\">A stage-gate in the procurement process prevents productive use before the intended decision. Urgent exceptions remain possible as conscious risk decisions. However, they require a time limit and compensatory measures. This ensures that time pressure does not result in a permanently unexamined state.<\/p>\n<h2 class=\"wp-block-heading\">Step 6: Transfer review into monitoring and contract management<\/h2>\n<p class=\"wp-block-paragraph\">The approval represents a point in time. Therefore, define update triggers: significant changes in performance, new data access, security incidents, change of a critical subcontractor, expiration of evidence, or noticeable technical changes. Critical service providers require tighter controls than easily replaceable providers without sensitive access.<\/p>\n<p class=\"wp-block-paragraph\">Contractual regulations support the process. They can address reporting paths, collaboration, security requirements, evidence, subcontractors, and exit services. The specific wording belongs in the legal review. Operationally, each obligation requires a recipient and a process. An incident report is of little use if no one is responsible for evaluation and response.<\/p>\n<p class=\"wp-block-paragraph\">Technical external assessments can indicate changes between formal reviews. For continuous use, notifications, validation, and escalation should be defined. A single score does not determine the business relationship. Trends and individual findings provide signals for a re-evaluation.<\/p>\n<p class=\"wp-block-paragraph\">LocateRisk supports external, agentless analyses of the accessible attack surface and KPI-based classification. The results complement questionnaires and evidence but do not replace internal auditing or legal reviews. For a defined entry point, you can use the <a href=\"https:\/\/locaterisk.com\/en\/landing\/it-risk-analysis\/\">Security Rating<\/a> ; for portfolios, the <a href=\"https:\/\/locaterisk.com\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management Approach<\/a> is recommended.<\/p>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How does the security assessment of an IT service provider begin?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">First, describe the service, data, technical access, affected processes, and impact of failure. From this, derive criticality, scope, required evidence, and decision-making roles. Also, name an internal owner responsible for the information and subsequent actions.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is an ISO\/IEC 27001 certification sufficient for approval?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Not alone. Check whether the company, location, and related service fall within the scope. Depending on the risk, supplement the evidence with questionnaires, additional evidence, and technical signals.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What role does an external IT risk analysis play?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">It shows selected features of identified or accessible systems and can make changes or contradictions to self-disclosure visible. Internal controls and specific software versions are often not fully recognized externally.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How are open findings handled before approval?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">The service provider receives the specific finding for clarification. It is then confirmed, dismissed, compensated, or documented as open. Confirmed risks require measures, responsible parties, deadlines, and possibly a temporary exception.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">When must a service provider be re-evaluated?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">In addition to a risk-based regular schedule, events such as changes in performance, new accesses, incidents, new critical subcontractors, expiring evidence, or noticeable technical changes are suitable.<\/p><\/div><\/div><\/div><\/div>\n\n<p class=\"wp-block-paragraph\">Do you want to include the external security situation of a service provider in your assessment? <a href=\"https:\/\/locaterisk.com\/en\/landing\/free-rating\/\">Request a free security rating<\/a> and clarify the results along your assessment scope.<\/p>","protected":false},"excerpt":{"rendered":"<p>A practical assessment path for IT service providers: define scope, evaluate evidence, clarify external signals, and document decisions.<\/p>","protected":false},"author":6,"featured_media":0,"template":"","wissen_thema":[820],"class_list":["post-99023","wissen","type-wissen","status-publish","hentry","wissen_thema-lieferantenrisiko-tprm"],"yoast_head":"<title>IT-Sicherheit von Dienstleistern pr\u00fcfen \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"IT-Sicherheit von Dienstleistern pr\u00fcfen: Kritikalit\u00e4t, Fragebogen, Nachweise, externe Signale, Kl\u00e4rung, Freigabe und Monitoring.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/know\/check-it-security-service-providers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"IT-Sicherheit von Dienstleistern pr\u00fcfen \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"IT-Sicherheit von Dienstleistern pr\u00fcfen: Kritikalit\u00e4t, Fragebogen, Nachweise, externe Signale, Kl\u00e4rung, Freigabe und Monitoring.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/know\/check-it-security-service-providers\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/it-sicherheit-dienstleister-pruefen\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/it-sicherheit-dienstleister-pruefen\\\/\",\"name\":\"IT-Sicherheit von Dienstleistern pr\u00fcfen \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-09-24T07:00:00+00:00\",\"description\":\"IT-Sicherheit von Dienstleistern pr\u00fcfen: Kritikalit\u00e4t, Fragebogen, Nachweise, externe Signale, Kl\u00e4rung, Freigabe und Monitoring.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/it-sicherheit-dienstleister-pruefen\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/it-sicherheit-dienstleister-pruefen\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/it-sicherheit-dienstleister-pruefen\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"IT-Sicherheit von Dienstleistern pr\u00fcfen: Fragebogen, Nachweise und externe Signale\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>","yoast_head_json":{"title":"Check IT Security of Service Providers \u2013 LocateRisk","description":"Check IT security of service providers: criticality, questionnaire, evidence, external signals, clarification, approval, and monitoring.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/know\/check-it-security-service-providers\/","og_locale":"en_US","og_type":"article","og_title":"IT-Sicherheit von Dienstleistern pr\u00fcfen \u2013 LocateRisk","og_description":"IT-Sicherheit von Dienstleistern pr\u00fcfen: Kritikalit\u00e4t, Fragebogen, Nachweise, externe Signale, Kl\u00e4rung, Freigabe und Monitoring.","og_url":"https:\/\/locaterisk.com\/en\/know\/check-it-security-service-providers\/","og_site_name":"LocateRisk","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/wissen\/it-sicherheit-dienstleister-pruefen\/","url":"https:\/\/locaterisk.com\/wissen\/it-sicherheit-dienstleister-pruefen\/","name":"Check IT Security of Service Providers \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-09-24T07:00:00+00:00","description":"Check IT security of service providers: criticality, questionnaire, evidence, external signals, clarification, approval, and monitoring.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/wissen\/it-sicherheit-dienstleister-pruefen\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/wissen\/it-sicherheit-dienstleister-pruefen\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/wissen\/it-sicherheit-dienstleister-pruefen\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"IT-Sicherheit von Dienstleistern pr\u00fcfen: Fragebogen, Nachweise und externe Signale"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/6"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99023\/revisions"}],"predecessor-version":[{"id":99031,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99023\/revisions\/99031"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=99023"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=99023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}