Turning Compliance Evidence into an Audit-Ready Process
Audit readiness is a habit, not a sprint. Learn how to collect, review and retain compliance evidence continuously so audits stop being a scramble.

An external attack surface is everything about your organization that someone on the internet can reach or learn about: domains, hosts, services, applications, cloud storage, exposed credentials and third-party connections. It is rarely identical to the asset list in your inventory. Marketing launches a microsite, a developer leaves a test server running, an acquisition brings unknown domains. Each is a way in that nobody is watching.
This article sets out a simple cycle: discover, validate, prioritize, act and repeat.
Asset management is a named category in the NIST Cybersecurity Framework 2.0, covering inventories of hardware, software, services and data, and the prioritization of assets by importance to the organization's objectives and risk strategy [1]. Visibility is also the premise of continuous monitoring, which NIST describes as providing visibility into organizational assets and awareness of threats and vulnerabilities [2].
Government practice reflects the same logic. CISA's Binding Operational Directive 23-01, written for US federal agencies, requires automated asset discovery every 7 days, covering at minimum the agency's entire IPv4 space, and starting vulnerability enumeration on discovered assets every 14 days [3]. You are not bound by that directive, but it shows that discovery is expected to be frequent and systematic rather than occasional.
Start with what you know, then widen the search the way an outsider would.
OWASP defines an application's attack surface as the sum of all paths for data and commands into and out of it, including the code protecting those paths and the valuable data it handles, and notes that a first map will be incomplete and should be refined over time [4]. Apply the same mindset to the whole organization: list entry points, group them by type, and expect to revise.
Raw discovery output is noisy. Before ranking anything, confirm each item:
Example (fictional): a discovery run for a regional retailer finds 140 hostnames. The inventory lists 95. Of the 45 new ones, 30 are expired campaign pages, 10 are staging servers, 3 belong to a former supplier integration, and 2 are an old remote access gateway. Validation turns a long list into a short set of decisions: retire, secure, or transfer.
A severity score tells you how bad a flaw could be in general. It does not tell you how likely it is to be used against you. Combine several signals:
A simple model works well. Assign each finding a tier:
The best remediation for an unneeded asset is removal. Retiring a forgotten server closes every present and future flaw on it at once.
For each Tier 1 and Tier 2 item, create a ticket with the asset, the owner, the exposure, the recommended fix and a due date. When a vendor update is not immediately possible, CISA's guidance for known exploited vulnerabilities is to apply mitigations or workarounds as temporary protection and move to the official patch when it is released [5]. If a product is end-of-life and cannot be updated, plan to remove it from the network [5].
Keep a short record of each decision, including accepted risks with an expiry date. This also produces the evidence that auditors and regulators ask for.
Run discovery on a fixed schedule, for example weekly for the most exposed ranges, and compare each run with the last. New assets and new open ports should trigger review the same day. Track a few measures that show direction rather than perfection:
Integrate the process with change management so that launching a new domain or service automatically adds it to the inventory, and tie the results into your wider risk register.
No discovery method is complete. Some assets sit behind third parties, and attackers may know about things you do not. The aim is a surface that is smaller, better understood and watched continuously, with the most dangerous exposures closed first.
Organizations that want this run as an ongoing service rather than a periodic exercise can look at Valtrenix's Attack Surface Management capability.