Cyber asset attack surface management (CAASM) or external attack surface management (EASM) solutions are designed to quantify the attack surface and minimize and harden it. The goal with CAASM tools is to give the adversary as little information about the security posture of the business as possible while still maintaining critical business services.
If you’ve ever watched a heist film, step one in executing the score of the century is casing the place: observing security measures, measuring response times, and mapping out escape routes. Similar to both attacking and protecting enterprise IT resources, gaining knowledge of what resources are publicly visible on the internet, what makes up their technology stack, and whether any vulnerabilities or weaknesses exist.