{"id":1166,"date":"2026-09-11T06:46:01","date_gmt":"2026-09-11T06:46:01","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1166"},"modified":"2026-09-11T06:46:01","modified_gmt":"2026-09-11T06:46:01","slug":"easm","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/easm\/","title":{"rendered":"EASM"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: EASM (EXTERNAL ATTACK SURFACE MANAGEMENT)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">EASM answers a question no internal tool can: what does your company look like from the outside, to someone with no credentials and no invitation?<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Detection<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>EASM stands for external attack surface management. It continuously discovers every internet-facing asset associated with an organisation, attributes them back to the company, assesses their exposure and watches for change. The defining characteristic is that it works without credentials and without an inventory, because the assets that matter most are the ones nobody remembered to list.<\/p>\n<\/div>\n\n<p>Every other security control assumes you know what you are protecting. This is the one that questions the assumption.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#surface\">What sits on an external attack surface<\/a><\/li>\n    <li><a href=\"#stages\">The four EASM stages<\/a><\/li>\n    <li><a href=\"#versus\">EASM, CSPM and vulnerability scanning<\/a><\/li>\n    <li><a href=\"#drift\">Why the surface grows on its own<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles EASM<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"surface\">What sits on an external attack surface<\/h2>\n\n<p>Rarely the production application. Almost always the things around it.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Asset<\/th><th>How it ends up exposed<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Forgotten subdomains<\/td><td>A campaign site, an old marketing page or a DNS record pointing at infrastructure that no longer exists<\/td><\/tr>\n    <tr><td>Staging and dev environments<\/td><td>Stood up for a sprint, left reachable, usually with weaker controls and real data<\/td><\/tr>\n    <tr><td>Undocumented APIs<\/td><td>Endpoints shipped faster than the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API inventory<\/a> was updated<\/td><\/tr>\n    <tr><td>Cloud storage buckets<\/td><td>Made public for one legitimate reason and never reverted<\/td><\/tr>\n    <tr><td>Expiring or misissued certificates<\/td><td>A certificate lapses and a service either breaks or quietly drops to something weaker<\/td><\/tr>\n    <tr><td>Exposed admin interfaces<\/td><td>A management console or database port reachable from the internet rather than behind <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">private access<\/a><\/td><\/tr>\n    <tr><td>Shadow infrastructure<\/td><td>A subscription opened on a personal card, or infrastructure inherited through an acquisition<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"stages\" class=\"c-sage\">The four EASM stages<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 176\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Four EASM stages: discover, attribute, assess and monitor.\">\n  <defs><marker id=\"ea\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#6b4576\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"22\" width=\"164\" height=\"80\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"94\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Discover<\/text>\n  <text x=\"94\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">Domains, IPs, certs,<\/text>\n  <text x=\"94\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">services, endpoints<\/text>\n  <line x1=\"180\" y1=\"62\" x2=\"198\" y2=\"62\" stroke=\"#6b4576\" stroke-width=\"2\" marker-end=\"url(#ea)\"\/>\n\n  <rect x=\"204\" y=\"22\" width=\"164\" height=\"80\" rx=\"13\" fill=\"#3f4796\"\/>\n  <text x=\"286\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Attribute<\/text>\n  <text x=\"286\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#c7cceb\">Decide what is<\/text>\n  <text x=\"286\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#c7cceb\">actually yours<\/text>\n  <line x1=\"372\" y1=\"62\" x2=\"390\" y2=\"62\" stroke=\"#6b4576\" stroke-width=\"2\" marker-end=\"url(#ea)\"\/>\n\n  <rect x=\"396\" y=\"22\" width=\"164\" height=\"80\" rx=\"13\" fill=\"#6b4576\"\/>\n  <text x=\"478\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Assess<\/text>\n  <text x=\"478\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#e3cbe6\">Exposure, weakness,<\/text>\n  <text x=\"478\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#e3cbe6\">priority<\/text>\n  <line x1=\"564\" y1=\"62\" x2=\"582\" y2=\"62\" stroke=\"#6b4576\" stroke-width=\"2\" marker-end=\"url(#ea)\"\/>\n\n  <rect x=\"588\" y=\"22\" width=\"160\" height=\"80\" rx=\"13\" fill=\"#3a6f5d\"\/>\n  <text x=\"668\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Monitor<\/text>\n  <text x=\"668\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#c9e5d8\">Catch what appears<\/text>\n  <text x=\"668\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#c9e5d8\">next week<\/text>\n\n  <rect x=\"12\" y=\"114\" width=\"736\" height=\"44\" rx=\"13\" fill=\"#efe4f0\"\/>\n  <text x=\"380\" y=\"134\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Attribute is the hard stage, and the one that decides whether the output is useful.<\/text>\n  <text x=\"380\" y=\"150\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#6b4576\">A tool that claims a shared CDN address as yours produces noise nobody will read twice.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"versus\" class=\"c-plum\">EASM, CSPM and vulnerability scanning<\/h2>\n\n<p>All three look for weaknesses. They differ on where they stand when they look.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th><\/th><th>EASM<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a><\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability scanning<\/a><\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Vantage point<\/td><td>Outside, unauthenticated<\/td><td>Inside your cloud accounts<\/td><td>Against a defined target list<\/td><\/tr>\n    <tr><td>Needs credentials<\/td><td>No<\/td><td>Yes<\/td><td>Usually<\/td><\/tr>\n    <tr><td>Finds unknown assets<\/td><td>Yes, that is the purpose<\/td><td>Only within accounts you connected<\/td><td>No, it scans what you gave it<\/td><\/tr>\n    <tr><td>Blind to<\/td><td>Anything not reachable from the internet<\/td><td>Assets outside the connected accounts<\/td><td>Everything absent from the list<\/td><\/tr>\n    <tr><td>Core question<\/td><td>What do we even have out there?<\/td><td>Is what we built configured safely?<\/td><td>Does this known thing have a known flaw?<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Vulnerability scanning inherits your blind spots<\/p>\n  <p>A scanner tests the targets you point it at, so a clean report means the assets on your list are healthy. It says nothing about the staging box a contractor stood up in a different account eighteen months ago. That is the gap EASM exists to close, and it is why a clean <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">vulnerability management<\/a> programme and an unknown exposed asset coexist comfortably.<\/p>\n<\/div>\n\n<h2 id=\"drift\" class=\"c-sky\">Why the surface grows on its own<\/h2>\n\n<p>Nobody decides to expand an attack surface. It happens as a side effect of ordinary work: a launch that needed a landing page, a demo environment for a prospect, an integration that required an endpoint, a team that moved fast because moving fast was the instruction.<\/p>\n\n<p>Two forces make it worse over time. Cloud infrastructure is trivial to create and easy to forget, so the cost of leaving something running is low enough to ignore. And staff turnover means the person who knows why a host exists is often no longer there to ask. The surface does not shrink by itself, which is why the fourth stage, monitoring, matters more than the first. A one-off discovery exercise is accurate for about a week.<\/p>\n\n<h2 id=\"osto\">How Osto handles EASM<\/h2>\n\n<p>Discovery runs as part of the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web and API protection<\/a> layer rather than as a separate scanning product. Applications and APIs are found automatically and brought under protection once identified, so discovery leads directly to a control rather than to a ticket. Certificate lifecycle is tracked in the same place, which closes the most common quiet failure on the list above.<\/p>\n\n<p>What a single stack adds is the assessment stage. A newly discovered host is evaluated against <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture<\/a>, scanned for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">known weaknesses<\/a>, and its activity correlated in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a> as identity and endpoint events. Finding an unknown asset is useful. Knowing within minutes whether it is dangerous, and protecting it without a separate deployment, is the part that changes what a small team can actually do. That inventory also answers the asset management questions in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and the Identify function of <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nist-csf\/\">NIST CSF<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Discovery that ends in protection<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Applications and APIs discovered automatically and brought under protection once found, with certificates, cloud posture and correlation in the same stack. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Auto-discovery, auto-protection &middot; Built for lean teams &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is EASM?<\/summary>\n  <p>External attack surface management. It discovers every internet-facing asset belonging to an organisation, attributes them, assesses their exposure and monitors for change, all without credentials or a pre-existing inventory.<\/p>\n<\/details>\n\n<details>\n  <summary>How is EASM different from vulnerability scanning?<\/summary>\n  <p>A scanner tests targets you supply. EASM finds the targets. A clean scan report covers only the assets on your list, which is why an organisation can have healthy vulnerability management and still have an unknown host exposed.<\/p>\n<\/details>\n\n<details>\n  <summary>Is EASM the same as CSPM?<\/summary>\n  <p>No. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> works inside the cloud accounts you connect and checks configuration. EASM works from outside with no credentials and can find assets in accounts nobody told you about. They are complementary rather than overlapping.<\/p>\n<\/details>\n\n<details>\n  <summary>Do small companies need EASM?<\/summary>\n  <p>Often more than large ones. Small teams create infrastructure quickly, document it lightly and lose institutional memory when someone leaves. The surface is smaller but the proportion of it that is undocumented is usually higher.<\/p>\n<\/details>\n\n<details>\n  <summary>Is a one-off discovery scan enough?<\/summary>\n  <p>No. An attack surface changes as fast as the engineering team ships. A point-in-time inventory is accurate for about a week, which is why continuous monitoring is the stage that produces the value.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability Scanning<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/xdr\/\">XDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nist-csf\/\">NIST CSF<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>EASM answers a question no internal tool can: what does your company look like from the outside, to someone with\u2026<\/p>\n","protected":false},"author":8,"featured_media":1168,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[573,571,574,572],"class_list":["post-1166","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-attack-surface-management","tag-easm","tag-easm-vs-cspm","tag-external-attack-surface-management"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1166"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1166\/revisions"}],"predecessor-version":[{"id":1169,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1166\/revisions\/1169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1168"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}