Finding and Prioritizing Your External Attack Surface
You cannot defend what you cannot see. A practical guide to discovering internet-facing assets and ranking exposures by real-world risk.

Most audit stress has the same cause: evidence is gathered when the auditor asks, not when the control operates. Screenshots are recreated from memory, owners are chased by email, and the team discovers gaps while the audit clock is running. A better approach treats evidence as a by-product of normal operations, collected on a schedule and reviewed before anyone external sees it.
This article describes a practical way to build that process, whether you are preparing for ISO/IEC 27001, a SOC 2 examination, or a national requirement such as the NCA Essential Cybersecurity Controls or the SAMA Cyber Security Framework.
An auditor is not judging whether you have a policy. They are testing whether a control exists, is designed sensibly, and operates as described. NIST's assessment guidance frames this as a methodology and set of procedures for assessing security and privacy controls, with plans and results analysis as part of the work [1]. In practice that means evidence of three kinds:
Teams often have design evidence and little else. Operating and population evidence are where findings tend to occur, so they deserve the most attention.
The core tool is a simple register, one row per control. Spreadsheet or platform, the fields matter more than the tool:
Example (fictional): a mid-sized firm records "Quarterly user access review" as a control. The owner is the IT operations lead. Evidence is the exported access list, the manager sign-off per department, and tickets for each removal. Frequency is quarterly, the reviewer is the compliance analyst, and retention follows the firm's records policy. When an auditor samples one quarter, all three artifacts are in one folder with consistent naming.
Frameworks overlap heavily. Access reviews, change approvals, backup tests and incident exercises appear in almost every one. The ISO/IEC 27001 standard specifies requirements for an information security management system and applies to organizations of any size or sector [2]. SOC 2 reports cover controls relevant to areas such as security, availability, processing integrity, confidentiality or privacy [5]. The NCA ECC aims to safeguard the information and technological assets of national entities [3], and the SAMA CSF applies to banking, insurance and financing companies in Saudi Arabia [4].
Rather than keeping one evidence set per framework, tag each register row with every framework it supports. One well-formed access review then answers several requirements. Where a framework adds a specific need, such as SAMA's expectation that regulated entities assess their current status, plan toward a target maturity level and report progress [4], add a note or an extra artifact instead of duplicating the whole control.
Collection should follow the rhythm of the control, not the audit calendar.
This is the same idea behind continuous monitoring in NIST guidance: an ongoing program that gives visibility into assets and threats and insight into whether deployed controls are working [6]. Applied to compliance, it means checking control health regularly instead of once a year.
An internal evidence review is the highest-value step in the process. Each quarter, the reviewer samples the register and asks:
Treat failures as normal and useful. A missed review or late approval found internally becomes a corrective action with an owner and a date. The same issue found by an external party is a finding. Keep a short log of exceptions and fixes, because auditors generally respond well to a clear trail showing that you identified and addressed gaps yourself.
When an audit is announced, the work should be assembly, not creation.
After each audit or internal review, record what took the longest to produce. Those items are candidates for automation or for a better evidence source. Review the register when systems, vendors or scope change, because a control that moved to a new platform often has evidence that no longer exists in the old place.
Compliance evidence will never make an organization secure on its own, and a well-organized audit pack does not guarantee a favorable result. What it does is make your actual control operation visible, testable and repeatable, which is what a sound assurance process depends on.
If you want help structuring a register across frameworks, Valtrenix's Governance, Risk & Compliance capability is built around exactly that kind of work.