Attack Surface
The total set of reachable points, interfaces, identities, assets, and trust relationships that an attacker could attempt to exploit.
Reducing unnecessary exposure limits opportunities for compromise and helps security teams focus on the assets and paths with the greatest potential impact.
An organisation discovers an obsolete public API, unused administrator accounts, and a supplier integration with excessive permissions, then removes or restricts them.
No inventory remains complete without continuous maintenance. A smaller surface is not automatically secure, and counting assets alone does not reflect exploitability, controls, or business impact.
It includes internet-facing services, APIs, endpoints, software dependencies, cloud resources, accounts, permissions, physical interfaces, suppliers, data flows, and human processes. Attack-surface management combines inventory, exposure discovery, prioritisation, remediation, and continuous monitoring.
Systems Architecture
NIST CSF 2.0 — https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf; CISA Known Exploited Vulnerabilities — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
