{"id":12751,"date":"2026-04-22T19:44:37","date_gmt":"2026-04-22T19:44:37","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/23\/cis-benchmarks-2026-how-security-teams-are-adapting\/"},"modified":"2026-07-09T16:58:03","modified_gmt":"2026-07-09T16:58:03","slug":"cis-benchmarks-2026-how-security-teams-are-adapting","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/04\/22\/cis-benchmarks-2026-how-security-teams-are-adapting\/","title":{"rendered":"CIS Benchmarks: Security Teams Adapt Hardening for M365 Copilot"},"content":{"rendered":"<p style=\"display:inline-block;background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px;\">8 min read<\/p>\n<p style=\"color:#b8c5ce;font-size:0.85em;margin:0 0 16px;\"><span class=\"article-date\">As of: 22 April 2026<\/span><\/p>\n<p><strong>In its April 2026 revision of the Microsoft 365 Benchmarks, the Center for Internet Security has directly addressed the Copilot attack vector. The new controls cover mandatory managed devices, Purview DLP policies for Copilot prompts, Conditional Access rules for Graph API access, and audit logging. For security teams, this means: the existing Zero Trust posture only partially applies to Copilot \u2013 the missing controls must be added in the coming quarters.<\/strong><\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Key takeaways<\/h2>\n<ul>\n<li><strong>CIS Microsoft 365 Benchmark v4.0.0:<\/strong> New controls for Copilot prompts, expanded Entra ID guidance, and stricter managed device requirements. Unmanaged devices are no longer permitted as valid authenticators.<\/li>\n<li><strong>Purview DLP for Copilot now GA:<\/strong> Since Ignite 2025 and the 2026 rollout, DLP policies can scan prompt content in real time for sensitive information types \u2013 a completely new control point.<\/li>\n<li><strong>Graph API as the data highway:<\/strong> Copilot retrieves responses via Microsoft Graph. Without least-privilege Graph permissions, the assistant accesses more data than the user typically opens in daily use.<\/li>\n<li><strong>Conditional Access gap:<\/strong> Most companies have Conditional Access properly configured for Outlook and Teams \u2013 but the rules often only partially apply to Copilot endpoints because the app identity differs.<\/li>\n<\/ul>\n<div style=\"background:#f0f9fa;border-left:4px solid #69d8ed;padding:20px 24px;margin:32px 0;border-radius:4px;\">\n<p><strong>What is a CIS Benchmark?<\/strong> A CIS Benchmark is a consensus-based security configuration profile from the Center for Internet Security. It outlines concrete, actionable hardening measures for common platforms like Microsoft 365, Windows, Linux, or Kubernetes. For Microsoft 365, the Benchmark provides tiered hardening profiles (Level 1 and Level 2) for Entra ID, Exchange Online, SharePoint, Teams, Defender, and \u2013 since version 4.0.0 \u2013 Copilot. It serves as a practical technical foundation for ISO 27001, NIST CSF, and BSI Grundschutz.<\/p>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Why Copilot needs its own control framework<\/h2>\n<p>Microsoft 365 Copilot isn\u2019t a traditional SaaS feature \u2013 it\u2019s an agent that taps into the full information surface of a user account. Emails, documents, calendars, chat histories, SharePoint files, OneDrive content, Teams meetings, Dynamics records \u2013 anything the user *could* theoretically see, Copilot can pull into its responses. The difference from past Microsoft 365 usage lies in the default behavior: Copilot proactively reads what humans would typically only open reactively.<\/p>\n<p>This architecture has two major implications for security teams. First, every misconfigured SharePoint permission becomes a data leak. If a finance folder is accidentally shared with all employees, it used to go unnoticed because people wouldn\u2019t actively access it. Copilot finds it instantly and incorporates content into responses. Second, prompt content becomes a new data class: what employees type into the prompt field *can* be sensitive \u2013 customer data, salary details, M&#038;A specifics. Without controls, this information leaves the context where it should remain.<\/p>\n<p>These are precisely the gaps the CIS v4.0.0 revision addresses. Mandatory managed devices prevent BYOD employees from processing Copilot responses on personal devices. Purview DLP policies for prompts detect sensitive information types in real time. For the first time, Copilot is integrated into the rule-based DLP world, which previously focused only on email and file uploads.<\/p>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#f0f9fa;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em;\">v4.0.0<\/div>\n<div style=\"font-size:15px;color:#444;margin-top:8px;\">Current CIS Microsoft 365 Foundations Benchmark, March 2026. Expanded to include Copilot controls, Power BI Fabric, and updated Entra ID guidance.<\/div>\n<div style=\"font-size:12px;color:#888;margin-top:8px;\">Source: Center for Internet Security, cisecurity.org<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">The five core control areas of v4.0.0<\/h2>\n<p>The latest revision covers a wide range of hardening topics, five of which are operationally critical for Copilot environments. First: identity hardening via Entra ID. Phishing-resistant MFA, managed devices as authenticator requirements, and strict conditional access policies for high-risk users and sessions. Without this foundation, you lose your first line of defense before Copilot even enters the picture.<\/p>\n<p>Second: data protection through Purview. SharePoint and OneDrive permissions are audited, public links restricted, and sensitivity labels made mandatory for specific document types. Purview DLP policies are extended to cover Copilot prompt content \u2013 every prompt is scanned in real time against defined sensitive information types. While the feature is now generally available, configuring it requires careful planning, as overly strict rules can significantly hinder daily use.<\/p>\n<p>Third: Graph API access. Copilot retrieves context via Microsoft Graph, not through direct file-read operations. The benchmark recommends least-privilege access for all Graph scopes, regular reviews of granted permissions, and automatic revocation of unused permissions after 90 days. Without this hygiene, permission sprawl accumulates, becoming a stumbling block in the event of an incident.<\/p>\n<p>Fourth: audit logging. Copilot interactions are logged by default in the Unified Audit Log, but only at a basic level. For security teams with serious detection needs, the benchmark recommends Audit Standard, which provides prompt metadata, accessed sources, and response IDs. This data feeds into SIEM systems, forming the basis for Copilot-specific detection rules.<\/p>\n<p>Fifth: administrative separation. Global admin roles are reduced, privileged identity management becomes mandatory for Copilot admin roles, and break-glass accounts are isolated and secured with hardware tokens. The benchmark applies the zero-standing-access principle to Copilot environments.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333;\"><p>\nCopilot shifts the default assumption around access: what was theoretically accessible to a human yesterday is practically readable by the agent today. If you don\u2019t clean up your permission structures before activating Copilot, you\u2019ll be forced to do it under pressure afterward.\n<\/p><\/blockquote>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">The operational challenge: Level 1 or Level 2<\/h2>\n<p>The CIS Benchmarks are structured into two implementation tiers. Level 1 represents the operational baseline \u2013 noticeable security without compromising productivity. Level 2 goes significantly further, accepting trade-offs in convenience for measurably higher security. For Copilot environments, this choice is more pressing today than in traditional Microsoft 365 scenarios. The regulations differ in scope and user impact.<\/p>\n<p>Level 1 typically includes: phishing-resistant MFA, sensitivity labels, DLP policies for standard documents, audit logging at standard levels, and conditional access for risky signals. For most mid-sized companies and smaller enterprise environments, this is the realistic target for the next two quarters. The rollout has a manageable impact on daily operations, while establishing a compliance foundation.<\/p>\n<p>Level 2 adds: mandatory managed devices for all Microsoft 365 logins, zero standing access with PIM, stricter session controls, automatic blocking of unconfigured OAuth apps, and advanced DLP rules with AI-based classification. This is the level regulated industries \u2013 finance, healthcare, critical infrastructure \u2013 must aim for. However, it\u2019s also the level where typically 15 to 25 percent of users initially experience productivity losses before the organization adapts.<\/p>\n<div style=\"margin:28px 0;border:1px solid rgba(230,227,218,0.12);border-radius:6px;overflow:hidden;\">\n<div style=\"background:#003340;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">CIS Benchmark v4.0.0 Rollout Roadmap<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">March 2026<\/div>\n<div style=\"color:#333;line-height:1.55;\">CIS v4.0.0 released. New sections on Copilot, expanded Entra ID guidance, Power BI Fabric.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">April 2026<\/div>\n<div style=\"color:#333;line-height:1.55;\">Purview DLP for Copilot prompts in general availability. First quarterly patch for Microsoft Defender telemetry for Copilot.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">Q2\/Q3 2026<\/div>\n<div style=\"color:#333;line-height:1.55;\">Majority of managed device policies live in DACH enterprise environments. Recommended implementation phase for Level 1.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">Q4 2026<\/div>\n<div style=\"color:#333;line-height:1.55;\">Agent 365 as central control plane for AI agents in GA \u2013 additional controls will be managed through this layer.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;\">\n<div style=\"min-width:130px;font-weight:700;color:#69d8ed;\">2027<\/div>\n<div style=\"color:#333;line-height:1.55;\">Level 2 becomes the default expectation for regulated industries. Successor benchmark CIS v5 expected in Q2.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">How security teams should prioritise their transformation<\/h2>\n<p>A pragmatic four-step roadmap helps security teams in DACH SMEs and smaller enterprise organisations focus their efforts. The key is not to tackle everything at once, but to prioritise in the right sequence.<\/p>\n<div style=\"margin:28px 0;\">\n<div style=\"display:flex;gap:16px;padding:16px 20px;background:#f0f9fa;border-left:3px solid #69d8ed;margin-bottom:8px;border-radius:4px;\">\n<div style=\"min-width:32px;font-size:1.4em;font-weight:800;color:#69d8ed;\">1<\/div>\n<div style=\"color:#333;line-height:1.6;\"><strong>Harden the identity foundation.<\/strong> Phishing-resistant MFA for every user, managed-device policies for all logins from Copilot contexts. This is the non-negotiable entry barrier \u2013 without it, further steps are pointless.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;padding:16px 20px;background:#f0f9fa;border-left:3px solid #69d8ed;margin-bottom:8px;border-radius:4px;\">\n<div style=\"min-width:32px;font-size:1.4em;font-weight:800;color:#69d8ed;\">2<\/div>\n<div style=\"color:#333;line-height:1.6;\"><strong>Clean up permissions.<\/strong> Systematically review SharePoint shares, OneDrive links, and Teams channel permissions. Eliminate public links, outdated guest access, and oversized permission groups before rolling out Copilot at scale. Tools like Purview\u2019s permissions reports or third-party solutions such as Varonis can help.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;padding:16px 20px;background:#f0f9fa;border-left:3px solid #69d8ed;margin-bottom:8px;border-radius:4px;\">\n<div style=\"min-width:32px;font-size:1.4em;font-weight:800;color:#69d8ed;\">3<\/div>\n<div style=\"color:#333;line-height:1.6;\"><strong>Configure DLP policies for prompts.<\/strong> Start with a narrow scope \u2013 financial data, HR records, sensitive project files \u2013 and expand in weekly cycles. Run the initial policy in audit mode first, then switch to block mode.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;padding:16px 20px;background:#f0f9fa;border-left:3px solid #69d8ed;border-radius:4px;\">\n<div style=\"min-width:32px;font-size:1.4em;font-weight:800;color:#69d8ed;\">4<\/div>\n<div style=\"color:#333;line-height:1.6;\"><strong>Build detection rules.<\/strong> Elevate the Unified Audit Log to standard, set up Copilot-specific detection rules in Sentinel, Defender, or an external SIEM. Watch for patterns like unusual prompt frequency per user, access to rarely used sources, or Copilot usage outside normal working hours.<\/div>\n<\/div>\n<\/div>\n<p>A fifth layer \u2013 often overlooked \u2013 is organisational. Deploying technical Copilot controls without bringing stakeholders along creates resistance and workarounds. Employees who hit Copilot blocks without understanding why may turn to personal accounts, third-party tools, or copy sensitive content into non-Copilot spaces. The technical benchmark is necessary, but not sufficient.<\/p>\n<p>From an architecture perspective, it\u2019s worth examining how CIS v4 interacts with other frameworks. The NIST AI Risk Management Framework, ISO 42001 (AI Management Systems), and NIS-2 will all receive Copilot-specific interpretations by 2026. The CIS benchmark provides the operational levers, while the other frameworks offer governance structure. Failing to align these layers risks either technical overkill without strategic direction or policies without operational backing.<\/p>\n<p>The third aspect is evolution. Microsoft has announced Agent 365 as a central control plane for AI agents, expanded Purview with DSPM features, and integrated credential scanning into the Defender stack. Each of these updates will be reflected in future CIS benchmark revisions. Security teams should track these developments rather than wait for a final, stable baseline. By 2026, Copilot will be a moving target \u2013 and so will the controls.<\/p>\n<p>For companies developing their own Copilot plugins or connecting to internal agents, a close look at scope assignment and OAuth configurations is particularly worthwhile. Mistakes here can lead to silent data leaks, often only discovered during external audits. A clean initial setup is far more cost-effective than fixing issues later.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What the benchmark doesn\u2019t cover \u2013 and where external components step in<\/h2>\n<p>The CIS Benchmark v4.0.0 excels at configuration hardening, but it\u2019s not a complete AI governance framework. Three key areas fall outside its scope and must be addressed separately. First: prompt injection and jailbreak defenses. The benchmark governs permissions and data flows, yet it can\u2019t block manipulative prompt phrasing. That requires additional guardrails at the application layer.<\/p>\n<p>Second: model drift monitoring. The responses Copilot generates shift with each new model release. The CIS Benchmark controls configuration, not output quality. For security-critical use cases, a dedicated test suite with known input-output pairs \u2013 run automatically before and after model updates \u2013 is recommended. Any deviations are logged and assessed.<\/p>\n<p>Third: plugin supply-chain risks. Third-party Copilot plugins receive their own Graph permissions and intervene in response flows. While the benchmark advocates strict app governance, the actual risk assessment must be conducted per plugin \u2013 similar to traditional SaaS rollouts, just with a faster deployment cycle.<\/p>\n<p>For security teams, this makes a two-pronged approach worthwhile: the CIS Benchmark as the technical foundation, paired with an organizational AI governance framework. NIST AI RMF or ISO 42001 fill the gaps the CIS Benchmark intentionally leaves open. Without this second layer, controls remain effective for configuration but incomplete for Copilot\u2019s overall risk profile.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently asked questions<\/h2>\n<h3>What exactly changed in CIS Benchmark version 4.0.0?<\/h3>\n<p>Version 4.0.0 expands the benchmark with explicit Copilot controls, new Entra ID guidance mandating managed devices, enhanced Purview DLP recommendations for prompt content, and additional sections on Power BI Fabric and Defender for Cloud Apps. In total, around 40 to 50 new individual recommendations were added, with some existing ones tightened.<\/p>\n<h3>Is Purview DLP for Copilot prompts production-ready?<\/h3>\n<p>Yes. Microsoft announced the feature at Ignite 2025 and rolled it out to general availability in 2026. It\u2019s activatable for all Microsoft 365 Copilot and Copilot Chat users, with policies built on Sensitive Information Types and real-time prompt scanning.<\/p>\n<h3>How much effort is Level 1 implementation realistically?<\/h3>\n<p>For a typical 1,000-employee organization with a solid Microsoft 365 foundation, expect eight to twelve weeks to reach Level 1. This assumes a security team experienced in Purview, Entra ID, and Defender. Without that baseline expertise, add another four to six weeks of preparation.<\/p>\n<h3>What happens if Copilot is deployed without DLP?<\/h3>\n<p>The most common consequence is a surge in minor data leakage incidents. Salary details in Copilot prompts, customer data in responses, confidential project info in summaries \u2013 individual cases rarely make headlines, but collectively, they create a risk profile that auditors or data protection officers will flag.<\/p>\n<h3>What role does BSI C5 play in this context?<\/h3>\n<p>BSI C5 is Germany and Austria\u2019s certification standard for cloud services with heightened security requirements. CIS Benchmark measures cover much of C5\u2019s configuration-level controls. For full C5 compliance, however, you\u2019ll also need process documentation, role concepts, and regular audits \u2013 the CIS Benchmark provides the technical backbone.<\/p>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/22\/aws-ec2-c8in-and-c8\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-aws-ec2-c8in-c8ib-600-gbps-netzwerk-date-82814925.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">AWS EC2 C8in and C8<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/bitkom-ai-study-2026-41-of-companies-use-ai-smes-catch-up\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-bitkom-ki-studie-2026-41-prozent-unterne-84045783-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Bitkom AI Study 2026: 41% of Companies Use AI, SMEs Catch Up<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/sustainable-it-2026-how-cios-can-accurately-measure-scope-3-it-emissions-for\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-sustainable-it-2026-cios-scope-3-emissio-76884520-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Sustainable IT 2026: How CIOs Can Accurately Measure Scope 3 IT Emissions for CSRD<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"CIS Microsoft 365 Benchmark v4.0.0 introduces Copilot-specific controls. Managed devices, Purview-DLP for prompts, and Graph API hygiene become mandatory.","protected":false},"author":10,"featured_media":12730,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Security Teams Copilot Prompts","_yoast_wpseo_title":"CIS Benchmarks 2026: How Security Teams Are Adapting Hardening Standards for Mic","_yoast_wpseo_metadesc":"CIS Microsoft 365 Benchmark v4.0.0: New Copilot controls, Purview DLP for prompts, managed device mandates, and Graph API hardening. Implementation roadmap for security teams.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-12751","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":12,"wpml_language":"en","wpml_translation_of":12731,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12751","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=12751"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12751\/revisions"}],"predecessor-version":[{"id":21529,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12751\/revisions\/21529"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/12730"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=12751"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=12751"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=12751"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}