# What is External Attack Surface Management (EASM)?

> External attack surface management is the continuous discovery and monitoring of an organization’s internet-facing assets and exposures — the view an outside attacker sees without internal access.

- Canonical URL: https://yellowcube.eu/glossary/external-attack-surface-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

EASM finds domains, IP ranges, cloud services, exposed storage, certificates, forgotten sites, and shadow infrastructure attributable to the organization, then flags exposures such as open services, expired certificates, leaked credentials, and misconfigurations. Because it observes from outside, it can discover assets internal inventories miss — but it cannot see internal context, ownership, or compensating controls.

### Key points

- **Unknown-asset discovery:** EASM’s primary value is discovery of unmanaged or forgotten assets, not re-measuring what internal tools already track.
- **Ownership assignment:** An exposed asset without an accountable owner is a report, not remediation; tie discoveries to inventory and ticketing.
- **Important limitation:** Outside-in scanning sees exposure hints, not exploitability or business criticality. Confirm findings internally before treating them as confirmed risk.

### Related terms

[Attack surface management (ASM)](<https://yellowcube.eu/glossary/attack-surface-management/>) · [Attack surface](<https://yellowcube.eu/glossary/attack-surface/>) · [Continuous threat exposure management (CTEM)](<https://yellowcube.eu/glossary/continuous-threat-exposure-management/>) · [Vulnerability scanning](<https://yellowcube.eu/glossary/vulnerability-scanning/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>)

### Sources

[CISA, Internet Exposure Reduction Guidance](https://www.cisa.gov/resources-tools/resources/exposure-reduction) · [NIST SP 800-216, Recommendations for Federal Vulnerability Disclosure Guidelines](https://csrc.nist.gov/pubs/sp/800/216/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

