openskills.info
Course Preview

Attack Surface Management

Attack surface management is the continuous process of discovering, inventorying, and reducing the external-facing assets and exposures that an attacker could target. It maps what an organization exposes to the internet and prioritizes risks based on exploitability and business impact.

itDefensive security and security operations

Attack Surface Management

Your attack surface is the set of paths an attacker could use to reach assets, affect operations, or take data. It includes more than known vulnerabilities. An unnecessary service, forgotten domain, exposed administration page, weak cloud policy, or abandoned application can all create an opening.

Attack surface management, or ASM, is the continuous work of finding those openings, deciding which ones matter, and reducing the resulting risk.

Use this mental model:

discover → attribute → enrich → prioritize → remediate → verify
    ↑                                                   ↓
    └──────────────── observe change ───────────────────┘

The loop matters more than any scanner. Infrastructure changes, cloud resources appear, acquisitions add domains, and teams retire systems incompletely. A one-time inventory starts aging as soon as discovery ends.

Scope the surface before you measure it

ASM can cover digital and physical assets. Most security programs begin with the digital attack surface because it can be observed and changed through repeatable technical processes.

The digital surface has several views:

  • External attack surface — internet-accessible domains, hosts, addresses, services, applications, certificates, and third-party dependencies.
  • Internal attack surface — systems, identities, trust relationships, management planes, and services reachable after an attacker gains an internal position.
  • Application attack surface — input and output paths, privileged functions, APIs, files, valuable data, and the controls that protect them.
  • Cloud attack surface — public endpoints, control-plane identities, storage exposure, workload identities, and configuration relationships across cloud accounts.
  • Human attack surface — identities and workflows that an attacker may target through credential theft or social engineering.

External attack surface management, or EASM, is a subset of ASM. It observes your organization from outside the network. This view can reveal assets that internal inventories or endpoint agents miss.

No single view is complete. External discovery cannot see every internal trust relationship. An endpoint inventory cannot see an abandoned domain with no agent. Application analysis cannot prove who owns every public host.

Define the scope in operational terms. Record which organizations, subsidiaries, brands, networks, cloud accounts, and suppliers belong in the program. Also record exclusions and the authority under which discovery operates.

Build an evidence-backed inventory

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources

  • https://www.ncsc.gov.uk/guidance/external-attack-surface-management-buyers-guide
  • https://cheatsheetseries.owasp.org/cheatsheets/Attack_Surface_Analysis_Cheat_Sheet.html
  • https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks
  • https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://www.first.org/epss/user-guide.html
  • https://www.first.org/epss/faq
  • https://learn.microsoft.com/en-us/azure/external-attack-surface-management/what-is-discovery
  • https://www.ncsc.gov.uk/guidance/asset-management