Defense & Operations
External Attack Surface Management (EASM)
Also known as: EASM
Definition
Continuous discovery and monitoring of all internet-facing assets that belong to an organization, viewed from an outside-in attacker perspective.
Examples
- EASM discovering an unmanaged Azure tenant created by a marketing team that hosts production data.
- EASM flagging a soon-to-expire wildcard certificate on a customer-facing subdomain.
Related terms
Attack Surface Management (ASM)
Continuous discovery, inventory, classification, and monitoring of all assets that expose an organization to potential cyberattack.
Asset Management
Asset Management — definition coming soon.
Threat Intelligence
Evidence-based knowledge about threats and threat actors — including indicators, TTPs and context — used to guide security decisions and detection.
Vulnerability Scanning
Automated process that probes systems, applications, or containers against known vulnerability signatures to produce a list of potential weaknesses.
CSPM (Cloud Security Posture Management)
A category of tools that continuously assess cloud accounts against best-practice and compliance baselines to detect and remediate misconfigurations.
Security Posture
Security Posture — definition coming soon.