Software Buyer Brief
Attack Surface Management Software Checklist Before Buying
Short answer: buy attack surface management software only if it can continuously discover internet-facing assets you own, identify unknown owners, validate real exposure, prioritize exploitable risk, route remediation, track exceptions, and prove that the external attack surface is shrinking over time.

CISA Binding Operational Directive 23-01 focuses federal agencies on asset discovery and vulnerability enumeration. Even for private buyers, the core idea is useful: security teams cannot protect internet-facing systems they do not know exist.
NIST SP 800-137 frames continuous monitoring as an ongoing strategy for visibility into assets, vulnerabilities, and control effectiveness. Attack surface management should provide that visibility from the outside-in.
Start With Discovery Scope
Ask how the product discovers domains, subdomains, IP ranges, cloud services, storage buckets, certificates, exposed admin panels, VPN endpoints, email infrastructure, APIs, development environments, and third-party hosted assets.
Then ask how it proves ownership. Discovery can create noise if the product cannot distinguish your assets from lookalike domains, abandoned acquisitions, partner systems, and unrelated internet hosts.
Identify Unknown Owners
The most useful finding is often not a CVE. It is an asset no one owns. The tool should map discoveries to business units, repositories, cloud accounts, DNS records, tags, certificates, tickets, or application owners.
Unknown assets should create an ownership workflow, not just sit in a dashboard.
Validate Exposure Before Prioritizing
Ask how the platform confirms that a service is reachable, what protocol is exposed, whether authentication is required, whether a vulnerability is exploitable, and whether the finding is externally observable.
Do not buy a product that floods teams with theoretical findings without validation or business context.
Prioritize With Business Context
Exposure priority should combine internet reachability, exploit status, asset criticality, data sensitivity, identity exposure, certificate status, service age, and whether an owner exists.
Ask whether the tool can treat an exposed test server differently from a production login portal, even if both show the same CVE.
Connect Remediation And Exceptions
The platform should create tickets, assign owners, set due dates, track closure, verify fixes, and reopen issues when exposure returns. Exceptions should require reason, owner, expiration, compensating control, and review date.
External exposure changes constantly. A closed ticket is not enough; the tool should rescan and prove the exposure is gone.
Attack Surface Management Review Table
| Requirement | Demo question | Buying signal |
|---|---|---|
| Discovery | Can it find domains, IPs, cloud services, APIs, and certificates? | Internet assets become visible. |
| Ownership | Can discoveries map to teams and systems of record? | Findings reach accountable owners. |
| Validation | Can the tool prove exposure and reduce false positives? | Teams trust priorities. |
| Remediation | Can it create tickets and verify closure? | Risk moves out of dashboards. |
| Reporting | Can leaders see exposure trend and risk drivers? | Executives understand progress. |
Questions To Ask Before Buying
- Which discovery methods are passive, active, authenticated, and cloud-integrated?
- Can the tool discover assets outside known IP ranges?
- How does it prove an asset belongs to us?
- Can it map findings to owners, tickets, cloud accounts, and repositories?
- How are internet reachability, exploit status, and business criticality combined?
- Can remediation be verified automatically after closure?
- Do exceptions expire and return for review?
- Can reports show exposure reduction, not just finding counts?
Red Flags In An ASM Demo
- The vendor only scans a list of assets you already know.
- Unknown ownership is not treated as a workflow.
- Risk scores are opaque and cannot be explained.
- Findings are not validated from the internet perspective.
- Tickets close without rescan verification.
- Executive reports show volume but not risk trend or remediation progress.
Demo move: give the vendor one domain, one cloud account, and one known staging system. Ask the product to discover related assets, identify an unknown owner, prioritize exposure, open a ticket, and verify closure.
Source Links
- CISA BOD 23-01: Improving Asset Visibility and Vulnerability Detection
- NIST SP 800-137: Information Security Continuous Monitoring
- NIST SP 800-137A: Assessing ISCM Programs
- CISA: Internet Exposure Reduction Guidance
- CISA: Known Exploited Vulnerabilities Catalog
FAQ
Is attack surface management the same as vulnerability scanning?
No. Vulnerability scanning checks known assets for weaknesses. ASM also discovers unknown internet-facing assets, maps ownership, validates exposure, and tracks remediation.
Should ASM scan assets we do not own?
No. Buyers should confirm legal scope, ownership proof, and scan authorization. The tool should help avoid scanning unrelated systems.
What is the most important ASM metric?
Exposure reduction over time is more useful than raw finding count. Track unknown assets, critical exposed services, remediation age, and reopened exposures.
How often should discovery run?
External attack surfaces change constantly. Continuous or frequent discovery is usually better than quarterly snapshots.
Who owns ASM?
Security usually owns the program, but IT, cloud, DevOps, product, and business owners must own remediation for their assets.