Defense & Operations
Attack Surface Management (ASM)
Also known as: ASM
Definition
Continuous discovery, inventory, classification, and monitoring of all assets that expose an organization to potential cyberattack.
Examples
- An ASM platform that discovers a forgotten staging server exposing an admin interface to the internet.
- ASM correlating a newly registered look-alike domain with an existing brand-protection workflow.
Related terms
External Attack Surface Management (EASM)
Continuous discovery and monitoring of all internet-facing assets that belong to an organization, viewed from an outside-in attacker perspective.
Asset Management
Asset Management — definition coming soon.
Vulnerability Scanning
Automated process that probes systems, applications, or containers against known vulnerability signatures to produce a list of potential weaknesses.
Threat Intelligence
Evidence-based knowledge about threats and threat actors — including indicators, TTPs and context — used to guide security decisions and detection.
CSPM (Cloud Security Posture Management)
A category of tools that continuously assess cloud accounts against best-practice and compliance baselines to detect and remediate misconfigurations.
Security Posture
Security Posture — definition coming soon.