What you will learn
- How to pick a business service to scope
- What belongs in a scope statement
- How to identify crown jewels
- How to handle shared services and third parties
Explanation
What a scope statement contains
- The business service name and one-line purpose
- The revenue, users, or data it protects
- Assets: applications, servers, containers, cloud accounts, databases
- Identities: human and machine, with privilege level
- Third parties and shared platforms
- The named scope owner and the CTEM program owner
- What is explicitly out of scope
Example
Service: online checkout. Crown jewels: payment tokens, order database. Owner: head of e-commerce. In scope: checkout web app, payments API, order DB, deployment pipeline, engineers with production access. Out of scope: marketing website, internal analytics.
How to apply this
- Interview the business owner and write the scope statement together
- Use the exposure register template to record scope assets
- Confirm crown jewels with data protection and legal
- Publish scope so discovery and prioritization stay focused
Common mistakes
- Scoping the whole company on the first pass
- Leaving identities out of scope
- Ignoring shared services (DNS, IAM, CI/CD)
- Writing scope in security-only language nobody else understands
Frequently asked questions
Related pages
Lifecycle Overview
CTEM Lifecycle: The Five Stages Explained
A practical walkthrough of the five-stage CTEM lifecycle with worked examples, common pitfalls, and links to a deep-dive page for each stage.
CTEM Discover Stage
CTEM Discovery Stage: Find Assets and Exposures
Practical guide to the Discovery stage of CTEM covering assets, identities, cloud, misconfigurations, external surface, and third parties.
Templates
Free CTEM Templates: Exposure Register, Prioritization, Reporting
Free CTEM templates: exposure register, prioritization matrix, validation worksheet, reporting template, maturity checklist, remediation tracker.
Checklists
CTEM Checklists: Practical Program Checklists
Practical CTEM checklists for scoping, discovery, prioritization, validation, mobilization, reporting, and maturity review.
Author
LearnCTEM Editorial Team
Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.
Reviewed by
Senior CTEM Practitioner Panel
Reviewed for accuracy against public CTEM guidance and real-world program experience.
