ASM
Attack Surface Management (ASM) is a cybersecurity practice that involves identifying, analyzing, and reducing an organization’s attack surface.
Reducing the
attack surface
An attack surface refers to the collection of all possible ways that an attacker can enter or exploit a system or network, including vulnerabilities in hardware, software, configurations, and user behavior. Attack surface management involves reducing the attack surface by identifying and mitigating potential vulnerabilities before they can be exploited by attackers.
ASM includes various techniques and processes, such as
Asset
discovery
Identifying all the assets (e.g., hardware, software, network infrastructure) of an organization that are connected to the internet.
Vulnerability
assessment
Identifying and evaluating potential vulnerabilities in the assets, systems, and networks.
Threat
modeling
Analyzing how an attacker might exploit vulnerabilities to gain access to the organization's systems and networks.
Risk
management
Prioritizing and addressing identified vulnerabilities to reduce the overall risk of a successful attack.
Continuous
monitoring
Regularly assessing and reviewing the attack surface to ensure that it is always up to date.
Improved
compliance
Security regulations compliance is enabled by a centralized repository of attack surface data and automated vulnerability scanning and risk assessment.



































