Glossary
Attack Surface Management
The continuous process of identifying, assessing, and managing the various points of an organization's attack surface.
What Is an Attack Surface?
An attack surface refers to all the points, interfaces, and avenues through which a bad actor can try to enter or extract information from a system, network, or application. These include:
- Cloud infrastructure: Components of cloud-based systems, including configurations, access controls, and data storage
- Software: Applications, operating systems, and software dependencies
- Network interfaces: Network devices, ports, protocols, and services
- Web applications: Websites, web services, and web-based platforms
- Hardware devices: Physical devices connected to a network, such as IoT devices, servers, routers, and other hardware components
- Endpoints: Devices (computers, smartphones, tablets) that connect to a network
- Human factors: Human users are often targeted through social engineering, phishing attacks, or other methods
- Third-party services or integrations: Dependencies on external services or integrations that may introduce vulnerabilities if those services lack proper security measures
What Is Attack Surface Management?
Attack surface management refers to the continuous process of identifying, assessing, and managing the various points of an organization's attack surface. The process includes:
Asset Discovery
Automatically and continuously scans for and identifies internet-facing hardware, software, and cloud assets that could act as entry points.
- Known assets are all IT infrastructure and resources the organization is aware of and actively managing
- Unknown digital assets are devices, systems and applications that an organization is unaware of
- Vendor assets the organization doesn't own but are part of its IT infrastructure or digital supply chain
- Rogue assets created or stolen by threat actors to target the company
Risk Assessment and Prioritization
Evaluating the potential impact and likelihood of exploitation, with prioritization focusing efforts on addressing the most critical vulnerabilities.
Remediation Planning and Implementation
Developing strategies and action plans to mitigate or eliminate identified vulnerabilities through patches, configuration changes, software updates, or other security measures.
Continuous Monitoring and Adaptation
An ongoing and iterative process involving regular scans, assessments, and updates to adapt to evolving threats and changes in the organization's IT environment.
Why Attack Surface Management Is Important
- Reducing vulnerabilities by identifying and mitigating weaknesses before attackers exploit them
- Comprehensive visibility into potential risks and points of vulnerability
- Proactive security measures to stay ahead of cyber threats
- Data-driven decision-making supported by actionable insights
Threat Modeling in Attack Surface Management
Threat modeling plays a critical role in ASM by helping organizations proactively identify and mitigate potential security defects at key stages: discovery and mapping, risk assessment, design and development, continuous monitoring, and incident response planning.
Threat Modeling Methodologies
Various frameworks are used to identify and address potential vulnerabilities, including OCTAVE, PASTA, STRIDE, Trike, and VAST.
Choosing the Right Threat Modeling Solution
An ideal solution offers scalability, automatic threat identification, suggested security controls, and cloud integration.
