What you will learn
- What each template contains
- Which columns are required vs optional
- How the templates connect stage to stage
Explanation
Templates included
- Scope statement — one page: service, crown jewels, assets, owners, boundaries.
- Exposure register — ID, source, asset, exposure type, description, business service, status, owner, priority, evidence link.
- Prioritization matrix — business impact, exploitability, threat activity, control gap, total, rationale.
- Validation worksheet — method, evidence, controls tested, result, safe-to-run notes.
- Mobilization tracker — ticket, owner, deadline, blocker, closure date, re-test result.
- Executive report — top exposures, risk reduction, closed vs opened, blockers, next month focus.
- Maturity checklist — one line per capability, current level, evidence, next action.
How they connect
Scope feeds the register. The register feeds the matrix. The matrix feeds validation. Validation feeds mobilization. Mobilization feeds the executive report. The maturity checklist reviews it all quarterly.
How to apply this
- Copy the exposure register into your document tool this week
- Fill in one scope statement with a business owner
- Rank ten exposures using the prioritization matrix
- Send your first monthly executive report
Common mistakes
- Adding fields the team will never fill in
- Using multiple registers per tool instead of one source of truth
- Ignoring the maturity checklist and never reviewing progress
Frequently asked questions
Related pages
Resources
Free CTEM Resources: Templates, Labs, Checklists, Case Studies
A free resource library for CTEM practitioners: templates, hands-on labs, checklists, case studies, glossary, and study plans.
CTEM Scope Stage
CTEM Scope Stage: Define What Matters
How to run the Scope stage of CTEM: pick business services, list critical assets, map attack surfaces, and name owners.
CTEM Discover Stage
CTEM Discovery Stage: Find Assets and Exposures
Practical guide to the Discovery stage of CTEM covering assets, identities, cloud, misconfigurations, external surface, and third parties.
Metrics & Reporting
CTEM Metrics and Reporting: What to Measure and Share
Operational metrics, risk reduction metrics, executive reporting, board reporting, and common CTEM reporting mistakes to avoid.
Author
LearnCTEM Editorial Team
Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.
Reviewed by
Senior CTEM Practitioner Panel
Reviewed for accuracy against public CTEM guidance and real-world program experience.
