Complete the steps in this section to set up Exposure Management and begin to customize it to meet your organization's unique requirements. All of these steps are optional, but recommended.
| Step | Description | More information |
| --------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Step 1: Configure the Cortex Network Scanner and other Palo Alto Networks sensors | These sensors scan your environment and ingest vulnerabilities so you can review, prioritize, and take action on them from one central location. | <ul><li><a href="../attack-surface-management/attack-surface-management-detections/attack-surface-testing">Attack Surface Testing</a></li><li><a href="../../onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents">Cortex XDR agents</a></li><li>Cortex Cloud Agentless Scanner</li><li><a href="../../../configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sources/container-registry-scanning#container-registry-scanning">Container Registry Scanning</a></li><li>Cortex Serverless Function Scanner</li></ul> |
| Step 2: Configure third-party integrations | Exposure Management can ingest vulnerabilities from Tenable.io, Tenable.sc, Rapid7 InsightVM, and Qualys VMDR scanners. | [Ingest assets and vulnerabilities from third-party applications](ingest-assets-and-vulnerabilities-from-third-party-applications) |
| Step 3: Ingest assets and vulnerabilities using the API | The Vulnerability Ingest API imports vulnerabilities and assets from your third-party tools directly into your asset inventory and vulnerability management workflows. | [Ingest assets and vulnerabilities from third-party applications](ingest-assets-and-vulnerabilities-from-third-party-applications) |
| Step 4 Enable Attack Surface Testing (AST) | AST validates that vulnerabilities are exposed to the internet and provides additional context for compensating controls. | [Attack Surface Testing](../attack-surface-management/attack-surface-management-detections/attack-surface-testing) |
| Step 5: Review vulnerability policies | Review the out-of-the-box vulnerability policies and create custom policies to define which vulnerabilities trigger creation of an issue or other actions. | [Vulnerability policies](../vulnerability-management/vulnerability-policies) |
| Step 6: Review attack surface rules | Attack surface rules determine which attack surface management (ASM) findings create issues. Review the default enabled attack surface rules and enable or modify rules as needed. | [Attack surface rules](../attack-surface-management/attack-surface-management-detections/attack-surface-rules) |
| Step 7: Set up asset groups | <p>Asset groups can be used to:</p><ul><li>define the scope of vulnerability policies</li><li>configure scope-based access control (SBAC), so users only see vulnerabilities for the assets they own</li></ul> | [Asset Groups](../asset-management/asset-groups) |
| Step 8: Enable issue enrichment and remediation automation | Install the Exposure Management Content pack to enable remediation owner information to be added to some issues automatically and automated remediation of some ASM issues. | [Deploy ASM and Exposure Management enrichment and remediation automation functionality](../attack-surface-management/deploy-asm-and-exposure-management-enrichment-and-remediation-automation) |