openskills.info
Course Preview

Attack Surface Management

Attack surface management is the continuous process of discovering, inventorying, and reducing the external-facing assets and exposures that an attacker could target. It maps what an organization exposes to the internet and prioritizes risks based on exploitability and business impact.

itDefensive security and security operations

Don't Panic — Attack Surface Management

Attack surface management, or ASM, is the recurring task of finding the ways an attacker can reach systems and deciding which routes deserve to disappear. Before that, teams often had inventories, scanners, and ticket queues that each held a different corner of the map. None of them reliably answered whether a public thing was still there, belonged to anyone, or mattered. A surprisingly popular arrangement, right up until it is not.

The useful mental model is a loop: discover, attribute, enrich, prioritize, remediate, and verify. Discovery finds names, addresses, services, certificates, and other clues. Attribution asks whether a clue is owned, a dependency, worth monitoring, or unrelated. That pause matters because a hostname that resembles an organization is evidence, not a deed of ownership.

Then add the awkward details. An outside-in view can see a reachable route but not its business value, data sensitivity, owner, or compensating controls. That is enrichment: joining the observation to the records that explain what it serves and who can change it. A finding without an accountable owner is not a remediation plan. It is a very organized form of waiting.

The common surprise is that a patched issue can leave the exposure intact. A public administration route might run a supported version tomorrow and still have no reason to be public. Prioritize the plausible path, not the loudest severity label. Reachability, exploit evidence, control weakness, privilege path, business impact, and available treatment each answer a different question.

The last step is verification. A closed ticket is useful evidence that work happened, but it does not prove the route stopped responding. Reobserve from the same vantage point, check alternate names and routes, and keep before-and-after evidence. Then watch for recurrence, because cloud templates and old DNS records have an unfortunate talent for remembering things you hoped they had forgotten.

Read the Intro for the full operating loop and its limits. Use the Cheatsheet when you need the asset, exposure, finding, and treatment distinctions close at hand. The Practice Reference turns the loop into a safe record-making exercise, and the Quiz checks whether a scanner result has tempted you into treating evidence as certainty.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources