Attack Surface
What is Attack Surface?
The total number of possible entry points for unauthorised access to a system. Reducing the attack surface through hardening, patching, and removing unnecessary services is a core security practice.
Terms that appear alongside attack surface
Each of these is named in at least one of the same controls as attack surface. The number is how many controls name both.
- hardening 6 shared controls
- mitre 3 shared controls
- reconnaissance 2 shared controls
- least privilege 2 shared controls
- asset inventory 2 shared controls
- cybersecurity 2 shared controls
- encryption 2 shared controls
- integrity 2 shared controls
Frameworks that govern attack surface
What the standards actually require on attack surface
Requirements naming attack surface across 6 standards, quoted from the control text.
Isolate ICS networks from any untrusted networks, especially the Internet; lock down all unused ports and turn off all unused services. Allow real-time external connectivity only where there is a defined business or control requirement;
CISA-ICS-7S-3 · Reduce Your Attack Surface Area →Consumer IoT devices shall minimise exposed attack surfaces by adopting the principle of least functionality: unused services and ports shall be disabled by default; hardware shall not be unnecessarily exposed;
EN303645-5.6 · Minimize exposed attack surfaces →Per SWIFT CSCF Objective 2: Internal Data Flow Security + Security Updates + Hardening + System Integrity Verification + Application Hardening + Vulnerability Scanning + Logging + Anti-Virus.
SWIFTCSCF-2 · Reduce Attack Surface and Vulnerabilities (Objective 2) →Manufacturers should disable unused interfaces, services and accounts and ensure debug interfaces are not accessible in production.
PSTI-12 · Minimisation of Exposed Attack Surfaces →Employ physical isolation techniques, logical isolation techniques, or both across organizational systems and system components, so that CUI is separated into security domains behind managed interfaces, the attack surface is reduced and adversary movement betw...
3.13.4e · Physical and Logical Isolation Techniques →Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load...
MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot · MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot →Questions people ask about attack surface
What is Attack Surface?
Why is Attack Surface important for compliance?
Which compliance frameworks address Attack Surface?
Where can I learn more about Attack Surface?
See how Attack Surface applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.