# SP-046 External Attack Surface Management

Status: active. Release 2.0. Modified 2026-02-13. Licence: CC BY-SA 4.0.

Scope: Comprehensive pattern for discovering, monitoring, and managing an organisation's internet-facing digital assets. Covers automated asset discovery, DNS and domain hygiene, continuous exposure assessment, cloud and API surface management, certificate lifecycle, third-party surface monitoring, risk-based remediation, and programme governance.
Use when: Every organisation with internet-facing assets should practice some form of EASM. It is particularly critical for: organisations that have grown through acquisition (inherited infrastructure is a major source of unknown exposure), organisations with significant cloud deployments across multiple providers, regulated industries where external exposure creates compliance risk (financial services, healthcare,...
Not when: Very small organisations with a handful of well-understood internet-facing services (a single website, an email service) may not justify commercial EASM tooling -- manual monitoring with free tools (Shodan, crt.sh, SecurityTrails) may suffice.

## Controls (28, NIST SP 800-53 ids)
- Critical (6): CA-07, CM-08, PM-05, RA-03, RA-05, SC-20
- Important (20): AC-17, AC-20, AU-02, AU-12, CA-02, CM-02, CM-03, CM-11, IA-09, IR-04, PM-14, PM-16, RA-07, RA-09, SA-09, SC-07, SC-23, SI-02, SI-04, SI-05
- Standard (2): CM-13, SA-04

## What each critical control mitigates (6)
- CA-07 Continuous Monitoring: T-EASM-001, T-EASM-002, T-EASM-004
- CM-08 System Component Inventory: T-EASM-002, T-EASM-005, T-EASM-006
- PM-05 System Inventory: T-EASM-002
- RA-03 Risk Assessment: none of the threats below
- RA-05 Vulnerability Monitoring and Scanning: T-EASM-003, T-EASM-005, T-EASM-006, T-EASM-010
- SC-20 Secure Name/Address Resolution Service (Authoritative Source): T-EASM-001, T-EASM-004, T-EASM-009

## Threats and the controls that mitigate them (10)
- T-EASM-001 Subdomain takeover via dangling DNS records pointing to deprovisioned cloud services: SC-20, CM-02, CM-03, CA-07
- T-EASM-002 Shadow IT exposure — unknown internet-facing assets deployed outside change management: CM-08, CM-11, PM-05, CA-07
- T-EASM-003 Cloud resource misconfiguration exposing sensitive data publicly (open storage, databases, APIs): AC-20, SC-07, CM-02, RA-05
- T-EASM-004 Expired or misconfigured TLS certificates enabling interception or service disruption: SC-23, SC-20, IA-09, CA-07
- T-EASM-005 Orphaned services running unpatched software with known exploitable vulnerabilities: RA-05, SI-02, CM-08, RA-09
- T-EASM-006 API sprawl exposing undocumented or unsecured endpoints to the internet: CM-08, AC-17, SC-07, RA-05
- T-EASM-007 Credential leakage discovered on public repositories, paste sites, or dark web markets: PM-16, SI-05, IR-04, AU-02
- T-EASM-008 Supply chain surface exposure through compromised or misconfigured third-party services: SA-09, SA-04, PM-16, SC-07
- T-EASM-009 Phishing infrastructure using lookalike domains or hijacked subdomains of the organisation: SC-20, PM-16, IR-04, CM-02
- T-EASM-010 Information leakage through HTTP headers, error pages, DNS records, and document metadata: SI-04, RA-05, CM-02, AU-12

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-046/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-046/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 35 KB: /api/v1/patterns/SP-046
- Page for people: /patterns/sp-046/
- Related: SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-038 Vulnerability Management and Patching; SP-030 API Security; SP-036 Incident Response

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
