Summary
External attack surface management (EASM) is the process of identifying, monitoring, and reducing vulnerabilities within assets that are accessible from the internet. This guidance will help system owners to choose an EASM product that is appropriate for their organisation. Vendors may also find this guidance useful when designing and developing EASM Attackers constantly scan organisations' IT systems (the hardware, software, services and cloud assets), looking for weaknesses they can use to gain access, or to steal data. The sum of potential access points is known as the ‘attack surface’, and attack surface management (ASM) is the process of identifying, monitoring, and reducing vulnerabilities across the entirety of an organisation's digital and physical assets. External attack surface management (EASM) is a subset of ASM, and focuses on protecting online assets that are accessible from the internet.