> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/dashboards/dashboards-discovery-exposure-management.md).

# Discovery and Exposure Management Dashboard

Learn more about discovering your internet-exposed, unmonitored cloud assets and secure them on Prisma Cloud.

The Discovery and Exposure Management (CDEM) dashboard utilizes advanced ML technology to scan and provide you with direct visibility into all the assets of your cloud infrastructure exposed to the internet.

With the CDEM dashboard, you can proactively manage and enhance your cloud security posture. Take action to swiftly convert exposed (unmanaged or unmonitored) assets to secure (managed) assets through seamless onboarding to Prisma Cloud with just one click.

Navigate to **Dashboards > Discovery and Exposure Management** to get a comprehensive view of your attack surface through various [**Unmanaged Asset Widgets**](#cdem-widgets) available on the dashboard.

1. The dashboard is only available if you have subscribed to Discovery and Exposure Management on Prisma Cloud. See [Subscribe to Discovery and Exposure Management](/content-collections/administration/subscribe-to-cdem.md) for more details.
2. If you have subscribed to CDEM but unable to view the dashboard, you must enable it. Go to **Dashboards > Dashboards Menu > Manage Dashboards** and make sure to enable **Discovery and Exposure Management**.
3. The dashboard availability is restricted to users with the System Administrator role on all stacks, with the exception of [app.gov](http://app.gov) and [app.cn](http://app.cn).

## Unmanaged Asset Widgets

The following widgets are available for visualization on the CDEM dashboard:

* [Internet Exposed Unmanaged Assets](#cdem-widget-1)
* [Unmanaged and Managed Asset Trend](#cdem-widget-2)
* [Top Risks From Unmanaged Assets](#cdem-widget-3)
* [Unmanaged Exposed Assets by Country](#cdem-widget-4)

### Internet Exposed Unmanaged Assets

<figure><img src="/files/VXwAQZzDoqsUSPxHrmfy" alt="cdem internet exposed unmanaged assets"><figcaption></figcaption></figure>

Displays a complete view of your cloud assets discovered across your attack surface, highlighting the contrast between unmanaged (exposed) and managed (secure) assets, tracking changes daily, and showcasing the success of your remediation efforts. It provides the following insights:

**Managed Assets—** Shows the count and corresponding percentage of managed assets successfully secured against internet exposure. Selecting **Managed Assets** will take you to the **Inventory > Assets** page, where you can view the latest information about all your secured cloud assets on Prisma Cloud.

**Unmanaged Exposed Assets—** Shows the count and corresponding percentage of unmanaged (exposed) assets that pose a risk due to internet exposure. Selecting **Unmanaged Exposed Assets** will take you to the **Inventory > Unmanaged Assets** page, where you can view the latest information about your unmanaged (or shadow IT) assets that are publicly exposed on the internet and attributed to your organization for further investigation.

**Remediated Findings—** Shows the count and corresponding percentage of assets that previously had identified vulnerabilities or issues but have been successfully remediated.

Additionally, the widget’s functionality is dynamic. It shows the count and corresponding percentage value indicating the change in unmanaged exposed assets, managed assets, and remediated findings on a daily basis, allowing you to understand the rate of improvement or degradation in your asset security posture at a glance.

### Unmanaged and Managed Asset Trend

<figure><img src="/files/w2lWUIHB3VJ7mtvpjjCG" alt="cdem historical trends"><figcaption></figcaption></figure>

Displays asset trends over the last 90 days with line graphs comparing **Managed Assets** and **Unmanaged Exposed Assets** asset volumes. You can also monitor the progress of **Remediated Findings** (conversion to secured assets) through a line graph. This way, the widget enables you to understand asset trends over time and keep track of the improvements made to secure your assets.

## Top Risks From Unmanaged Assets

<figure><img src="/files/s85AL3odm2xqxXe996Bi" alt="cdem top risks to remidiate"><figcaption></figcaption></figure>

Displays top risks that affect your security posture due to public exposure of assets on the internet. Each row highlights the risks based on categories, and the links in each row will help you explore and gain additional context on the affected assets, along with options to convert and inspect them. The risks are categorized as follows:

* **Critical—** Internet-exposed assets connected to a managed asset on Prisma Cloud, with exploitable vulnerabilities and available patches.
* **Exploited—** Internet-exposed assets discovered in the last two years, with exploitable vulnerabilities and available patches.
* **Patchable—** Internet-exposed assets discovered in the last two years, with vulnerabilities and available patches.
* **Vulnerable—** Internet-exposed assets with vulnerabilities that are susceptible to exploitation.
* **Exposed—** Assets that can be accessed over the internet.

To take action to secure the assets, you can select the **Convert Unmanaged Assets** button and initiate a bulk conversion of all the unmanaged (exposed) assets to managed (secure) ones simultaneously. Alternatively, you can individually convert assets using the **Convert** button in each row to secure specific assets. This feature is available only for accounts associated with the parent account or organizational unit (OU) accounts on Prisma Cloud. In cases where such mapping is not feasible, you can **Inspect Unmanaged Assets** (issues related to exposed assets) and send an email to your inbox containing the summary of the exposed assets.

Selecting the **Convert to Managed** button will onboard the assets to Prisma Cloud. Once the unmanaged assets convert to managed assets, Prisma Cloud will monitor these assets for vulnerabilities, misconfigurations, compliance issues, and so on.

In addition to conversion options, the **Inspect Unmanaged Assets** column lists the scanned asset findings, enabling you to review the exposed assets. Select a link to view the side panel. The panel includes a comprehensive list of assets, risk types, and associated cloud providers. Further exploration of each asset provides detailed information as follows:

* **Overview—** This default tab provides a comprehensive overview of the selected asset, including details such as server name, resource type, expiry date, and so on.
* **Exposed Service—** Displays the list of exposed services that are running on the selected asset, such as HTTP servers and other relevant services. Select a listed service to access granular information on the **IPs** and **Certificates** associated with it.
* **Vulnerabilities—** Displays Common Vulnerabilities and Exposures (CVE) discovered on the asset. The severity levels of the CVEs are categorized based on the Common Vulnerability Scoring System (CVSS) scores. The **Impacted Distros** section, also provides more details on the affected versions of a particular package.
* **Findings—** Displays findings which are security issues. If you have exposed information for the asset from Prisma Cloud and third-party sources, the findings from Prisma Cloud are prioritized and displayed.
* **Network Flow Log—** Provides a visual representation of the relationship between an internet-exposed (unmanaged) asset and secured (managed) assets over a 24-hour period. It displays the direction of the traffic flow and the number of bytes exchanged between them.

While you **Inspect Unmanaged Assets**, you can choose to snooze your known internet-exposed assets, such as test assets or vendor-exposed assets, as follows:

1. Select one or multiple assets from the **Inspect Unmanaged Assets** side panel.
2. Select the **Snooze** button.
3. Choose to **Snooze Temporarily** or **Snooze Forever**.
4. If snoozing temporarily, set a time limit.
5. **Select a Reason** to snooze the asset.
6. Select **Snooze Unmanaged Asset**.

Once snoozed, Prisma Cloud will provide the flexibility to view your **Active** assets separately from the **Snoozed** assets on the **Inventory > Unmanaged Assets** page, simplifying asset management.

### Unmanaged Exposed Assets by Country

<figure><img src="/files/xrZo6Q1dNYVzL5Dzboef" alt="cdem unmanaged assets map"><figcaption></figcaption></figure>

Displays a geographical view of your exposed assets on a map. Each pointer on the map represents the exposed asset’s location. Once you identify a region to secure, select the appropriate button to **Convert** or **Inspect** the unmanaged assets for better security.

The **Convert** button is enabled only for accounts associated with the parent account or organizational unit (OU) accounts on Prisma Cloud. Selecting the **Convert** button will onboard the assets to Prisma Cloud. Once the unmanaged assets convert to managed assets, Prisma Cloud will monitor these assets for vulnerabilities, misconfigurations, compliance issues, and so on.

In cases where such mapping is not feasible, use the **Inspect** button to identify issues related to exposed assets and **Send email** to your inbox containing the summary of the exposed assets. Select **Inspect** button to view a side panel. The panel includes a comprehensive list of exposed assets, risk categories, and associated cloud providers. Further exploration of each asset provides detailed information such as asset **Overview**, **Exposed Services**, **Vulnerabilities**, **Findings**, and **Network Flow Log** visualizations.

While inspecting the unmanaged assets, you can choose to **Snooze Temporarily** or **Snooze Forever** your known internet-exposed assets such as test assets, vendor-exposed assets, and so on. Snoozing assets will provide the ability to view your **Active** assets separately from the **Snoozed** assets in the **Inventory > Unmanaged Assets** page, simplifying asset management.

**Next Step**: Use the [**Unmanaged Assets Inventory**](/content-collections/cloud-and-software-inventory/cdem-unmanaged-assets-inventory.md) page to review the list of unmanaged (or shadow IT) assets publicly exposed on the internet and associated with your organization.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/dashboards/dashboards-discovery-exposure-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
