External attack-surface management is the practice of discovering, monitoring, and reducing Internet-exposed assets and risks that an attacker could target.
Security teams use EASM to find unknown domains, exposed services, misconfigurations, certificates, and vulnerabilities outside the protected internal network view.
Additional Resource: Authoritative source.