# What is Attack Surface Management (ASM)?

> Attack surface management (ASM) is an ongoing practice of discovering, attributing, tracking, and reducing assets and exposures that contribute to an organization’s attack surface.

- Canonical URL: https://yellowcube.eu/glossary/attack-surface-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It is an industry umbrella term rather than a standardized capability: products and programs differ substantially in what they can observe and manage.

External attack surface management (EASM) focuses on assets and exposures observable from the internet, including forgotten domains, cloud services, temporary deployments, acquired infrastructure, and exposed management interfaces. Broader programs may combine external findings with internal assets, SaaS, identities, cloud relationships, or attack-path information. Discovery reduces risk only when findings are attributed correctly, assigned to an accountable owner, validated proportionately, and remediated.

### Key points

- **Typical operational cycle:** Discover, attribute, enrich, prioritize, assign, remediate, and verify.
- **Useful context:** Business owner, environment, data or service supported, reachability, identity exposure, weakness, threat activity, and compensating controls.
- **Change focus:** New, altered, and re-exposed assets often deserve more attention than a static total count.
- **Safety caution:** Discovery does not authorize exploitation. Active validation needs explicit scope, rate limits, stop procedures, and permission from the responsible asset owner; connected supplier and SaaS assets may belong to another party.
- **Important limitation:** Internet observations can be incomplete or misattributed, and a discovered service is not automatically vulnerable or unauthorized.

### Related terms

[Attack surface](<https://yellowcube.eu/glossary/attack-surface/>) · [External attack surface management (EASM)](<https://yellowcube.eu/glossary/external-attack-surface-management/>) · [Continuous threat exposure management (CTEM)](<https://yellowcube.eu/glossary/continuous-threat-exposure-management/>) · [Operational technology (OT) asset inventory](<https://yellowcube.eu/glossary/operational-technology-asset-inventory/>) · [Vulnerability management](<https://yellowcube.eu/glossary/vulnerability-management/>)

### Sources

[CISA: Internet Exposure Reduction Guidance](https://www.cisa.gov/resources-tools/resources/exposure-reduction) · [NIST glossary: Attack Surface](https://csrc.nist.gov/glossary/term/attack_surface)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

