External Attack Surface Management

Also known as:EASM

External Attack Surface Management: Identifies and monitors assets and risks accessible from the Internet. This topic facilitates the transparent assessment and management of cyber risksCyber RiskThe possibility that a cyber threat will cause harm to systems, data, people, or business objectives.. Decisions should be based on protection requirementsProtection RequirementThe required level of protection derived from the value and sensitivity of an asset or process., likelihoodLikelihoodAn estimate of how likely it is that a defined risk scenario will occur. of occurrence, impactImpactThe consequence a security event or risk scenario would have for an organization or system., controls, and accepted residual riskResidual RiskThe risk remaining after controls and treatment measures have been applied..

How it works and where it fits

External Attack Surface Management denotes a technical component or operating environment with its own trust boundaries, identities, interfaces, and dependencies. Security is determined not only by the product, but by architecture, configuration, and the way data and privileges cross component boundaries. Management planes and production processing should be considered separately.

Practical security relevance

Secure operation depends on complete inventory, hardened baselines, least privilege, patchability, and centralized telemetry. Changes should be reproducible and reviewable. Exposed interfaces, default access, secrets, and supply-chain dependencies need particular attention; isolation, backup, and recovery must also be exercised in realistic conditions.

  • Attack SurfaceAttack SurfaceThe totality of all potentially vulnerable entry points of a system.: The totality of all potentially vulnerable entry points of a system.
  • Risk AssessmentRisk AssessmentIdentifies, analyzes, and assesses threats, vulnerabilities, and impacts.: Identifies, analyzes, and assesses threats, vulnerabilities, and impacts.
  • Governance, Risk and ComplianceGovernance, Risk and ComplianceIntegrated approach to managing policies, risks, controls, and evidence.: Integrated approach to managing policies, risks, controls, and evidence.
  • Information Security Management SystemInformation Security Management SystemManagement system for the risk-based planning, implementation, and improvement of information security.: Management system for the risk-based planning, implementation, and improvement of information security.