Skip to content

Attack Surface

What is Attack Surface?

The total number of possible entry points for unauthorised access to a system. Reducing the attack surface through hardening, patching, and removing unnecessary services is a core security practice.

Information Security

Each of these is named in at least one of the same controls as attack surface. The number is how many controls name both.

What the standards actually require on attack surface

Requirements naming attack surface across 6 standards, quoted from the control text.

Isolate ICS networks from any untrusted networks, especially the Internet; lock down all unused ports and turn off all unused services. Allow real-time external connectivity only where there is a defined business or control requirement;

CISA-ICS-7S-3 · Reduce Your Attack Surface Area

Consumer IoT devices shall minimise exposed attack surfaces by adopting the principle of least functionality: unused services and ports shall be disabled by default; hardware shall not be unnecessarily exposed;

EN303645-5.6 · Minimize exposed attack surfaces
SWIFT CSCF1 control

Per SWIFT CSCF Objective 2: Internal Data Flow Security + Security Updates + Hardening + System Integrity Verification + Application Hardening + Vulnerability Scanning + Logging + Anti-Virus.

SWIFTCSCF-2 · Reduce Attack Surface and Vulnerabilities (Objective 2)

Manufacturers should disable unused interfaces, services and accounts and ensure debug interfaces are not accessible in production.

PSTI-12 · Minimisation of Exposed Attack Surfaces
NIST SP 800-1723 controls

Employ physical isolation techniques, logical isolation techniques, or both across organizational systems and system components, so that CUI is separated into security domains behind managed interfaces, the attack surface is reduced and adversary movement betw...

3.13.4e · Physical and Logical Isolation Techniques
MITRE D3FEND2 controls

Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load...

MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot · MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot

Questions people ask about attack surface

What is Attack Surface?
The total number of possible entry points for unauthorised access to a system. Reducing the attack surface through hardening, patching, and removing unnecessary services is a core security practice.
Why is Attack Surface important for compliance?
Attack Surface is a key concept in Information Security. Understanding attack surface helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Attack Surface?
Attack Surface appears in the requirement text of CISA Industrial Control Systems (ICS) Security Guidance, ETSI EN 303 645, SWIFT CSCF, UK Product Security and Telecommunications Infrastructure Act (PSTI), NIST SP 800-172. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Attack Surface?
Explore our compliance framework pages to see how attack surface applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Attack Surface applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.