Attack Surface Management
An independent analysis project, being built in the open
This domain is becoming a research project about the attack surface management category — how these platforms differ, what the capability classes actually are, and how to evaluate one without taking a vendor's word for it.
It is not ready. Rather than leave a placeholder pretending otherwise, here is what it will be.
What will be published
- An evaluation methodology, dated and fixed before any platform is assessed against it.
- What the capability classes are, and which of them most buyers actually need.
- Guidance on scoping a procurement: the questions worth asking, and the answers worth distrusting.
- A map of the category, including where its boundaries are genuinely contested.
Nothing on this domain should be cited until the methodology above is published.