home/glossary/attack surface

attack surface

nounid 1553·updated May 9, 2026
candidate

The set of ways in which an adversary can enter a system and potentially cause damage.

MWE

Classifications

Entity Type

Vulnerability85%llm-generatedllm:claude-haiku-4-5

Sensitivity

95%llm-generatedllm:claude-haiku-4-5

Information Class

95%llm-generatedllm:claude-haiku-4-5

Variants

plural
attack surfaces
possessive
attack surface's
pluralpossessive
attack surfaces'

Framework definitions

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1 · extended_definition_available
The set of ways in which an adversary can enter a system and potentially cause damage.
CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures1 senseview framework →
§1
The sum of an information system’s characteristics in the broad categories (software, hardware, network, processes and human) which allows an attacker to probe, enter, attack or maintain a presence in the system and potentially cause damage to an FMI. A smaller attack surface means that the FMI is less exploitable and an attack less likely.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.