CAASM (Cyber Asset Attack Surface Management)

Cyber Asset Attack Surface Management: consolidating the inventory of internal and external assets by integrating with existing tools to provide unified visibility of posture.

What the category does

CAASM stands for cyber asset attack surface management. The category describes tools that consolidate, over APIs, the asset inventory already scattered across a company's other tools: endpoint agent, cloud provider, identity directory, configuration management system, virtualization platform.

The value is in consolidation. Each of those sources knows a slice, none knows the whole, and reconciling the views by hand is work nobody does at the frequency required.

Where the data comes from

This is the difference that matters, and it decides what each category can see.

CAASM reads from inside. It asks the tools the company already runs, so it sees everything those tools cover: a machine with an agent installed, a resource in a connected cloud account, a user in the directory. In exchange, it inherits their blind spots. An asset no tool instrumented does not appear, by definition.

EASM reads from outside. It starts at the root domain and observes what answers on the internet, depending on no credential and no installation. It sees the asset nobody registered, and sees nothing that is not published.

| | CAASM | EASM |
|---|---|---|
| data origin | internal tool APIs | external observation |
| finds | what the tools already cover | what answers on the internet |
| blind spot | uninstrumented asset | internal asset |
| question | is everything reconciled | what exists that I do not know about |

The two questions

CAASM answers whether what the company already knows is consistent. It is the hygiene question: how many machines carry an agent, how many cloud accounts sit under policy, where the sources disagree with each other.

EASM answers what exists that the company does not know exists. It is the coverage question, and it is the one the adversary asks.

Both are legitimate and neither replaces the other. A company with mature CAASM and no external view reconciles an incomplete set very well. One with an external view and no CAASM knows the boundary and does not know the internal state of what sits behind it.

On our own scope

CSURFACE operates on the external side. The platform starts at the root domain, with no agent and no integration with the customer's internal tools, which means it finds the asset outside the inventory and does not see excessive cloud permissions or a valid credential used by the wrong person.

That internal coverage remains with CAASM and with identity and cloud tooling. They are distinct layers of one program, and a vendor promising both halves in a single product is selling the category name.

Veja isso na sua superfície

Análise preliminar gratuita