Definition
The Attack Surface includes all points, interfaces, services, devices, users and processes that may be used to gain unauthorised access or compromise a system's security.
Human Explanation
The more elements are externally accessible or usable by an attacker, the larger the Attack Surface.
Why it Matters
Reducing the Attack Surface limits the number of potential paths to a security breach.
Conceptual Boundary
The Attack Surface is not limited to Internet-facing systems. It may include internal networks, mobile devices, users and organisational processes.
Practical Perspective
Every new service, account, device or application increases the Attack Surface and should be managed deliberately.