Cybersecurity GRC 14 items
External Attack Surface Management (EASM) Review
Reviews an external attack surface management program covering continuous discovery, exposure identification, prioritization, and remediation of internet-facing assets.
NIST 800-53CISCISA
Free PDF · enter your email to download.
Discovery
- Is the internet-facing asset inventory discovered continuously rather than periodically? *
- Are unknown and shadow-IT assets (forgotten domains, cloud instances) identified? *
- Are subsidiary, acquisition, and third-party-hosted assets included in scope?
- Is asset ownership attributed so findings can be routed to the right team? *
Exposure Identification
- Are exposed services, open ports, and admin interfaces identified? *
- Are expired/misconfigured certificates and weak TLS detected? *
- Are known vulnerabilities on exposed assets correlated (e.g., CISA KEV)? *
- Are leaked credentials and exposed secrets monitored across external sources?
Prioritization
- Are findings risk-prioritized by exploitability and business criticality? *
- Are actively exploited exposures escalated for urgent remediation? *
- Is attack surface size trended over time as a program metric?
Remediation
- Are findings routed to owners with remediation SLAs? *
- Is there a process to decommission unnecessary internet-facing exposure? *
- Are EASM findings integrated with the vulnerability management and ticketing workflow?
Download the full External Attack Surface Management (EASM) Review checklist
Get it as a clean, printable PDF — free.
