# Attack Surface
**Source:** https://glossary.keenfunnel.com/terms/attack-surface
**Language:** German

---

## Technische Erklärung

It includes internet-facing services, APIs, endpoints, software dependencies, cloud resources, accounts, permissions, physical interfaces, suppliers, data flows, and human processes. Attack-surface management combines inventory, exposure discovery, prioritisation, remediation, and continuous monitoring.

## Geschäftliche Relevanz

Reducing unnecessary exposure limits opportunities for compromise and helps security teams focus on the assets and paths with the greatest potential impact.

## Implementierungsbeispiel

An organisation discovers an obsolete public API, unused administrator accounts, and a supplier integration with excessive permissions, then removes or restricts them.

## Einschränkungen und häufige Missverständnisse

No inventory remains complete without continuous maintenance. A smaller surface is not automatically secure, and counting assets alone does not reflect exploitability, controls, or business impact.

## Themen

Cybersicherheit Systemarchitektur

## Quellen

NIST CSF 2.0 — CISA Known Exploited Vulnerabilities — https://www.cisa.gov/known-exploited-vulnerabilities-catalog

## Besprechen Sie Ihre Systeme

Benötigen Sie Hilfe bei der Implementierung oder Bewertung dieses Konzepts? Keenfunnel entwirft vernetzte KI-, Automatisierungs- und Datensysteme.

Discovery-Session buchen