What it means
ASM helps an organization discover and track the systems, services, and access points that make up its attack surface. The external subset, often called EASM, looks outward at internet-facing assets; broader programs may also include internal and cloud resources. Product boundaries vary, so clarify the scope. Discovery is valuable because inventory can lag behind acquisitions, experiments, and supplier changes. A discovered hostname or address is a lead, not automatic proof of ownership, vulnerability, or authorization to test it aggressively.
AN ILLUSTRATIVE SCENARIO
A forgotten campaign site still accepts logins
A retailer finds a campaign subdomain created by a former marketing agency. The main website inventory did not include it. The team verifies who owns the hosting account, what data the site holds, and whether any staff still need it. They retire the service through the responsible owner and update DNS and inventory. Merely removing the hostname from a dashboard would have hidden the problem without resolving the underlying asset.
Put it to work
- Start with known domains, address ranges, cloud accounts, and business entities. Combine technical discovery with owner interviews and existing inventory, noting uncertain ownership.
- Validate discovered assets and assign accountable owners. Establish which services are necessary, what they expose, and whether the organization is authorized to inspect or change them.
- Track remediation or retirement and monitor for reappearance. Keep evidence of ownership decisions, approved exceptions, and dependencies that could make a shutdown disruptive.
How to check your work
Choose a newly discovered asset and reconcile it with an owner and inventory record. After an approved change, verify the actual external state and any affected business function, rather than relying only on a finding disappearing.
Connect the ideas
- Asset
Anything whose disclosure, alteration, destruction, or downtime would harm a person or organization.
- Exposure
Whether and how a vulnerability or service can actually be reached in this environment.
- DNS
The lookup system that maps a name people type to an address a computer can contact.
- CTEM
A program for repeatedly finding, prioritizing, and reducing exposed attack surface rather than running a yearly scan.