{"id":99024,"date":"2026-09-22T09:00:00","date_gmt":"2026-09-22T07:00:00","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=99024"},"modified":"2026-08-06T16:22:12","modified_gmt":"2026-08-06T14:22:12","slug":"security-questionnaire-vs-security-rating","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/security-questionnaire-vs-security-rating\/","title":{"rendered":"Security Questionnaire vs. Security Rating: Strengths, Limitations and Combination"},"content":{"rendered":"<h1 class=\"wp-block-heading\">Security Questionnaire vs. Security Rating: Strengths, Limitations and Combination<\/h1>\n\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li>The questionnaire provides an internal view of policies, roles, and non-public controls.<\/li><li>The Security Rating provides a standardized external view and can indicate changes in reachable systems.<\/li><li>Self-disclosures can be outdated or overly positive; external data can be misattributed or misunderstood without business context.<\/li><li>Evidence, technical validation, and supplier dialogue increase the resilience of both methods.<\/li><li>The combination is based on criticality and information needs, not on a generalized ranking.<\/li><\/ul>\n<h2 class=\"wp-block-heading\">Two perspectives on the same service provider relationship<\/h2>\n<p class=\"wp-block-paragraph\">The Security Questionnaire and Security Rating assess the IT security of a service provider from different angles. The questionnaire captures self-disclosures about internal processes and controls. The rating evaluates selected, externally observable characteristics according to a defined model. No method is superior for every decision.<\/p>\n<p class=\"wp-block-paragraph\">The meaningful comparison begins with the information question: what does the company need to know, how current must the statement be, and what evidence supports the decision? This article compares both tools. The entire audit path from scope to release belongs in the specific service provider review.<\/p>\n<h2 class=\"wp-block-heading\">What type of information both tools provide<\/h2>\n<p class=\"wp-block-paragraph\">A Security Questionnaire asks about characteristics that are hardly visible from the outside. These include responsibilities, policies, access controls, secure development, incident management, recovery, and subcontractor control. The responses may relate to the specific service or the entire organization. Therefore, the questionnaire must specify the desired scope.<\/p>\n<p class=\"wp-block-paragraph\">One <a href=\"https:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> processes technical observations on identified or reachable resources. Examples include certificate characteristics, visible services, email protection configurations, or indications of deployed software. The service assigns findings to categories and can derive key figures from them. The models of different providers are not identical.<\/p>\n<p class=\"wp-block-paragraph\">The questionnaire provides explanatory context: how should a control function? The rating provides observed condition: what is externally recognizable at a given time? An answer in the questionnaire is not automatically effectively implemented. Conversely, an external finding does not prove that the entire internal process is unsuitable. Both tools require contextualization.<\/p>\n<p class=\"wp-block-paragraph\">The object of investigation also differs. A questionnaire can refer precisely to a SaaS service, a development service, or an administrative support access. A company rating may potentially capture a broader external attack surface depending on attribution. For the decision, it must be clear which parts actually belong to the acquired service.<\/p>\n<h2 class=\"wp-block-heading\">Strengths and limitations of the Security Questionnaire<\/h2>\n<p class=\"wp-block-paragraph\">The strength of the questionnaire lies in its adaptability. A company can derive questions from criticality, data flow, and access model. The service provider can explain processes, name responsible individuals, and describe special architectures. Follow-up questions enable a professional deepening. For internal controls, this internal view is indispensable.<\/p>\n<p class=\"wp-block-paragraph\">However, the quality of statements depends on questions, knowledge, and diligence of the answering individuals. Ambiguous terms lead to different interpretations. A central sales team can provide an answer that does not apply to the product in question. Yes-No fields obscure maturity levels, exceptions, and compensating controls. Additionally, an answer ages when processes or services change.<\/p>\n<p class=\"wp-block-paragraph\">Manipulation risk does not mean that every provider intentionally answers incorrectly. Self-disclosures, however, have a conflict of interest: the service provider wants to maintain the business relationship. Therefore, critical statements should be supported by certificates, audit reports, policy excerpts, technical evidence, or interviews. Missing evidence should be documented as uncertainty.<\/p>\n<p class=\"wp-block-paragraph\">The effort increases with length and customization. A very extensive standard questionnaire may be disproportionate for less critical providers. Modular question blocks help: a short base part and in-depth modules for cloud, software development, privileged access, or sensitive data. Reusable evidence reduces duplicate work as long as scope and currency are appropriate.<\/p>\n<h2 class=\"wp-block-heading\">Strengths and limitations of the Security Rating<\/h2>\n<p class=\"wp-block-paragraph\">The rating creates a consistent external view across multiple companies. The collection can occur without installation at the rated service provider and can be repeated for portfolios. New external resources or changed configurations can become visible between formal audits. This supports pre-selection and prioritization.<\/p>\n<p class=\"wp-block-paragraph\">The currency depends on the data source and audit interval. A timestamp indicates when a feature was observed. A total score can highlight trends but can also obscure relevant individual findings. Users should be able to view the underlying evidence, weighting, and model changes. A number without explanation is of little help for treatment.<\/p>\n<p class=\"wp-block-paragraph\">Misattributions are a central risk. Shared cloud infrastructure, old domains, or external service providers can be incorrectly credited to a company. Conversely, short-lived or hard-to-recognize resources can be missing. Verify ownership and service reference before an exception is escalated. The rated provider needs a traceable correction path.<\/p>\n<p class=\"wp-block-paragraph\">The external view does not recognize internal policies and not necessarily the specifically vulnerable version of visible software. Therefore, a good rating does not prove comprehensive security. A weaker rating is also not an automatic reason for rejection. It indicates the need for review, the significance of which arises from evidence, criticality, and supplier response.<\/p>\n<h2 class=\"wp-block-heading\">Comparison by evidence, currency, effort and sources of error<\/h2>\n<figure class=\"wp-block-table\"><table><thead><tr><th>Dimension<\/th><th>Security Questionnaire<\/th><th>Security Rating<\/th><\/tr><\/thead><tbody><tr><td>Type of Information<\/td><td>Declared internal processes and controls<\/td><td>Externally observable technical features<\/td><\/tr><tr><td>Timeliness<\/td><td>Status of response or proof<\/td><td>Depending on observation time and interval<\/td><\/tr><tr><td>Evidence<\/td><td>Self-disclosure, supplemented by documents and interviews<\/td><td>Technical observation with attribution and assessment model<\/td><\/tr><tr><td>Effort<\/td><td>Response, follow-up questions, and assessment per provider<\/td><td>Scalable data collection, expert validation for relevant signals<\/td><\/tr><tr><td>Typical source of error<\/td><td>Unclear question, inappropriate scope, outdated or embellished response<\/td><td>Misattribution, outdated finding, lack of business context<\/td><\/tr><tr><td>Appropriate Use<\/td><td>Understanding of control and service-related due diligence<\/td><td>External perspective, comparison, and change indicator<\/td><\/tr><\/tbody><\/table><\/figure>\n<p class=\"wp-block-paragraph\">The comparison shows no ranking. A current, service-related questionnaire with appropriate evidence can be very meaningful for internal controls. A rating can indicate technical changes more quickly. The quality in both depends on scope, data status, and audit process.<\/p>\n<p class=\"wp-block-paragraph\">Manipulation and misallocation are also not equivalent risks. A self-disclosure can be incorrect, whether deliberately or unintentionally. An external observation occurs independently of the provider's response, but it can be attributed to the wrong company or service. A suitable process checks both types of errors before drawing conclusions.<\/p>\n<h2 class=\"wp-block-heading\">Combine both methods by criticality<\/h2>\n<p class=\"wp-block-paragraph\">For a low-criticality service without sensitive data, a basic screening with a few questions and an external review may suffice. For a provider with access to production systems, the company needs in-depth self-disclosure, robust evidence, external signals, and possibly interviews or further technical audits. The risk class dictates the combination.<\/p>\n<p class=\"wp-block-paragraph\">In onboarding, the rating can provide early indications before extensive documentation is available. The questionnaire then clarifies controls and service-specific context. Contradictions are specifically followed up. For example: A provider explains a regulated certificate management system while an expired certificate is visible externally. The clarification shows whether resource, process, and related performance are interconnected.<\/p>\n<p class=\"wp-block-paragraph\">In ongoing operations, the roles change. The questionnaire is updated at defined occasions or in a risk-based rhythm. The rating can indicate technical changes more frequently. A signal does not trigger an automatic reassessment, but rather an audit loop of attribution, validation, supplier response, and decision.<\/p>\n<p class=\"wp-block-paragraph\">Link both sources in a common dataset. Record date, scope, evidence, and status. A dashboard must not present a self-disclosure as external confirmation. Similarly, a technical note should not appear as a answered process question. Clear provenance protects against pseudo-accuracy.<\/p>\n<h2 class=\"wp-block-heading\">Create a fair and robust decision-making process<\/h2>\n<p class=\"wp-block-paragraph\">Define before the assessment what minimum information is needed for each risk class. Describe when evidence is accepted and when follow-up questions are necessary. The supplier should be aware of the evaluation criteria and be able to comment on technical findings. This enhances data quality and traceability.<\/p>\n<p class=\"wp-block-paragraph\">Separate observation, risk, and action. \u201eA certificate has expired\u201c is an observation. The risk depends on system function, availability, and additional controls. The action can be renewal, decommissioning, or another technical correction. This structure prevents a score or response from being used unchecked in a business decision.<\/p>\n<p class=\"wp-block-paragraph\">Document exceptions with an expiration date. A provider may implement a control differently than expected in the questionnaire and still achieve a comparable goal. Compensating measures require evidence. In cases of unidentified high risks, the designated risk owner decides on conditions, restrictions, or rejection.<\/p>\n<p class=\"wp-block-paragraph\">LocateRisk provides an agentless external view and KPI-based assessments of identified or reachable systems. For the internal view, self-disclosures, evidence, and internal audits are required. Information on incorporating it into a portfolio can be found at <a href=\"https:\/\/locaterisk.com\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management<\/a>; a single external analysis describes the <a href=\"https:\/\/locaterisk.com\/en\/landing\/it-risk-analysis\/\">Security Rating<\/a>.<\/p>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What is more meaningful: Security questionnaire or Security rating?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">It depends on the question. The questionnaire explains internal controls, while the rating shows selected external characteristics. For critical vendors, the combination with appropriate evidence is usually more reliable than a single source. Key factors are a suitable scope, a documented data status, and a professional clarification of contradictions.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Can a service provider manipulate a security questionnaire?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Self-disclosures can be inaccurate, either intentionally or unintentionally. Critical responses should therefore be supported by suitable evidence, interviews, or technical examinations. A conflict of interest is not proof of a false statement. Also, unclear terms or a response for the wrong product area can lead to an inaccurate result.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What errors can occur in a security rating?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Possible errors include incorrect asset allocation, outdated observations, or technical conclusions without appropriate context. Check ownership, timestamps, evidence, and relation to the obtained service. A correction process should take into account the statement of the evaluated company and document changes transparently.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How do you combine questionnaires and ratings in onboarding?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Use the rating for an early external view and the questionnaire for service-related internal controls. Clarify contradictions, request evidence, and document the joint assessment in the approval process. The depth of the audit should be based on data access, technical connection, criticality, and potential impact of failure.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does continuous rating replace the update of the questionnaire?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. Technical external view does not reliably recognize internal process changes. Update self-disclosures and evidence based on risk or with significant changes; external signals can trigger additional audits. For both sources, keep the date, scope, and responsible review body documented, so that later decisions remain traceable.<\/p><\/div><\/div><\/div><\/div>\n\n<p class=\"wp-block-paragraph\">Do you want to complement a questionnaire with a current external perspective? <a href=\"https:\/\/locaterisk.com\/en\/landing\/free-rating\/\">Request a free security rating<\/a> and review the findings together with your evidence.<\/p>","protected":false},"excerpt":{"rendered":"<p>Security questionnaire and security rating comparison: type of information, currency, evidence, effort, sources of error, and sensible combination.<\/p>","protected":false},"author":6,"featured_media":0,"template":"","wissen_thema":[820],"class_list":["post-99024","wissen","type-wissen","status-publish","hentry","wissen_thema-lieferantenrisiko-tprm"],"yoast_head":"<title>Security-Fragebogen vs. Security Rating \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"Security-Fragebogen und Security Rating vergleichen: St\u00e4rken, Grenzen, Aktualit\u00e4t, Evidenz, Aufwand und Kombination nach Kritikalit\u00e4t.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/know\/security-questionnaire-vs-security-rating\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security-Fragebogen vs. Security Rating \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"Security-Fragebogen und Security Rating vergleichen: St\u00e4rken, Grenzen, Aktualit\u00e4t, Evidenz, Aufwand und Kombination nach Kritikalit\u00e4t.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/know\/security-questionnaire-vs-security-rating\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/security-fragebogen-vs-security-rating\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/security-fragebogen-vs-security-rating\\\/\",\"name\":\"Security-Fragebogen vs. Security Rating \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-09-22T07:00:00+00:00\",\"description\":\"Security-Fragebogen und Security Rating vergleichen: St\u00e4rken, Grenzen, Aktualit\u00e4t, Evidenz, Aufwand und Kombination nach Kritikalit\u00e4t.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/security-fragebogen-vs-security-rating\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/security-fragebogen-vs-security-rating\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/security-fragebogen-vs-security-rating\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Security-Fragebogen vs. Security Rating: St\u00e4rken, Grenzen und Kombination\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>","yoast_head_json":{"title":"Security Questionnaire vs. Security Rating \u2013 LocateRisk","description":"Compare security questionnaire and security rating: strengths, limitations, currency, evidence, effort, and combination by criticality.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/know\/security-questionnaire-vs-security-rating\/","og_locale":"en_US","og_type":"article","og_title":"Security-Fragebogen vs. Security Rating \u2013 LocateRisk","og_description":"Security-Fragebogen und Security Rating vergleichen: St\u00e4rken, Grenzen, Aktualit\u00e4t, Evidenz, Aufwand und Kombination nach Kritikalit\u00e4t.","og_url":"https:\/\/locaterisk.com\/en\/know\/security-questionnaire-vs-security-rating\/","og_site_name":"LocateRisk","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/wissen\/security-fragebogen-vs-security-rating\/","url":"https:\/\/locaterisk.com\/wissen\/security-fragebogen-vs-security-rating\/","name":"Security Questionnaire vs. Security Rating \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-09-22T07:00:00+00:00","description":"Compare security questionnaire and security rating: strengths, limitations, currency, evidence, effort, and combination by criticality.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/wissen\/security-fragebogen-vs-security-rating\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/wissen\/security-fragebogen-vs-security-rating\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/wissen\/security-fragebogen-vs-security-rating\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"Security-Fragebogen vs. Security Rating: St\u00e4rken, Grenzen und Kombination"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99024","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/6"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99024\/revisions"}],"predecessor-version":[{"id":99032,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99024\/revisions\/99032"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=99024"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=99024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}