Definition
A security management approach that continuously discovers and assesses exposed assets and vulnerabilities from an attacker’s perspective and remediates risks to reduce cyberattack risk
Visual IT Encyclopedia › Information Security
Definition
A security management approach that continuously discovers and assesses exposed assets and vulnerabilities from an attacker’s perspective and remediates risks to reduce cyberattack risk
The attack surface is every point an attacker could use to gain entry, steal data or disrupt services.
Example: a test admin page allows customer records to be read without authentication
Points an attacker could reach
Even if only the website and storage are inventoried, an abandoned test server can still be reachable from outside.
Find assets and weaknesses an attacker could target, reduce risk and keep tracking changes.
Connected exampleA test server is missing from the managed inventory
Explore domains, IP addresses, servers and APIs to identify known and unknown assets.
Discover an abandoned test server at test.example.com.
Identify owners and assess exposure, vulnerabilities, exploitability and business impact.
Identify the owner and prioritize an admin page that is accessible without authentication.
Apply patches, restrict access, fix configurations or retire unnecessary assets.
Restrict access to the admin page and retire the test server if it is no longer needed.
Verify fixes and reassess new assets, exposure changes and emerging vulnerabilities.
Check that the admin page is no longer exposed and keep watching for new exposures.
Feed monitoring results back into asset discovery and risk assessment.
ASMManage attack surfaces across internal and external assets.
EASM (External Attack Surface Management) focuses on internet-facing external assets within ASM.
SaaS: software delivered over the internet · Shadow IT: IT assets used outside organizational approval and oversight