TechKnowSurge
NIST CSF DE.CM CompTIA Security+ 4.4 ISC2 CISSP 7.2 NIST 800-53 CA-7 CompTIA CySA+ 1.1 NIST 800-53 SI-4 NIST CSF DE.CM-01
VideoSecurityFree

Monitoring

IT monitoring is the continuous observation of systems, networks, and data to mitigate risk, support compliance, and inform business decisions. Core monitoring functions include discovery, mapping, aggregation, alerting, reporting, and log management, all anchored to the CIA Triad of confidentiality, integrity, and availability.

Complete this video to capture a CTF flag worth 1 point.

About this video

IT monitoring is the systematic observation of technology environments to reduce risk, maintain compliance, and support informed operational and business decisions. At its core, monitoring serves to uphold the CIA Triad — confidentiality, integrity, and availability — by providing the visibility needed to detect problems early and respond to them quickly. The practice addresses risk in two ways: reducing the likelihood that an incident occurs by catching anomalies before they escalate, and reducing the impact of incidents that do occur by shortening detection and response times. Collected data also establishes performance benchmarks that make troubleshooting faster and more accurate over time. A mature monitoring program operates through a defined set of functions. Discovery identifies what exists in the environment and what warrants observation. Mapping provides a structural view of the network and infrastructure. Aggregation consolidates data from across the environment into a single platform, eliminating the need to manage dozens of separate systems. Alerting notifies the appropriate personnel when anomalies or threshold breaches occur. Reporting communicates system health and security status to stakeholders. Finally, log data must be archived or securely destroyed according to retention policies and regulatory requirements. The range of assets subject to monitoring is broad, covering infrastructure components such as endpoints, servers, and network devices, as well as applications, databases, web services, and cloud platforms. Security monitoring addresses vulnerability exposure, compliance status, and surveillance of user and system behavior. Data and asset monitoring applies scrutiny proportional to the sensitivity of the information involved, while process monitoring ensures that operational procedures are being executed efficiently and securely. Organizations typically begin by identifying what to monitor, configuring the appropriate tools and thresholds, and then maintaining an ongoing cycle of observation with regular adjustments to scope and sensitivity as the environment and threat landscape evolve.

What you'll learn

What's covered

Monitoring Overview

Aligned to

NIST CSF
DE.CM Continuous Monitoring — Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events.
DE.CM-01 Networks and network services are monitored to find potentially adverse events.
CompTIA Security+
4.4 Explain security alerting and monitoring concepts and tools.
ISC2 CISSP
7.2 Conduct logging and monitoring activities
NIST 800-53
CA-7 Continuous Monitoring
SI-4 System Monitoring
CompTIA CySA+
1.1 Explain the importance of system and network architecture concepts in security operations.

Key terms

CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Log Management
The process of collecting, storing, analyzing, and monitoring log data generated by systems and applications.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
IT Monitoring
The continuous observation and collection of data from IT infrastructure, applications, and services to ensure performance, security, and compliance.
Anomaly
An observable deviation from expected behavior in a system or network that may indicate a performance issue or security threat.
Aggregation
The process of consolidating monitoring data from multiple systems into a single platform for unified visibility and analysis.

Topics

It Monitoring Cia Triad Log Management Risk Mitigation Compliance Network Monitoring Security Operations

Transcript

Why We Monitor

The word monitoring just means that we're observing or checking the progress of something. We could be monitoring for mitigating risk, or we could be just collecting data so we can make production improvements, or we can be collecting data to make business level decisions, or data for marketing — we may actually take some of our data and then use it for some of our marketing material. We also might be monitoring just to meet some sort of compliance that we have; maybe it's a law, a regulation, or something that our customers are requiring us to do.

The main focus that we're going to focus on is mitigating risk. There are many different reasons why we mitigate risk, but a lot of it boils down to the CIA Triad: we're monitoring for confidentiality, integrity and availability.

Reducing Likelihood and Impact

To reduce risk, we're either reducing the likelihood that something's happening or the impact that it'll have if it does happen.

We can reduce the likelihood that something's going to happen just by identifying anomalies early and then fixing those anomalies so it doesn't become an issue. We could also reduce the impact, because if something were to happen we could get notified much quicker — we could have some sort of alert that notifies us, and that reduces the time it takes us to respond to an incident.

There's also the duration that the incident happens. We can actually shorten the incident duration, because all of this data that we're collecting creates benchmarks, so now we have some comparisons and understand what's happening on our network. Not to mention it can give us a lot of data for troubleshooting purposes.

The Functions of Monitoring

When it comes to monitoring, there are several functions that we carry out:

  • Discovery — we might need to figure out what's on our network, to figure out what it is that we want to monitor.
  • Mapping — we might also be able to map things out and have a map of what our network looks like, what our infrastructure looks like, a map of what we're monitoring.
  • Monitoring — we will of course do the monitoring of those devices.
  • Aggregation — we probably don't want to go to a hundred different systems to monitor everything; we want to aggregate them onto one system.
  • Alerting — we want to get alerted when there's something wrong happening on our network, when there are some sort of anomalies on our network.
  • Reporting — we also will pull a lot of reports to show what's going on.
  • Archiving or destruction — finally, we do have to archive or destroy or get rid of a lot of these log files after we're done with them.

What We Monitor

There are a lot of things that we would want to monitor. What are some examples of this?

First of all, there could be infrastructure items or systems that we want to monitor. Maybe it's the endpoints on our network, maybe it's servers that are on our network, maybe it's networking gear — we're going to want to monitor all of that.

There's also applications and services. There are a bunch of things like databases where we'll want to monitor specific aspects of those databases, or our web performance, or maybe it's some sort of software or services that we're monitoring, or maybe it's some sort of cloud services that we're subscribed to and that we're going to want to monitor.

We also want to do a lot of monitoring from a security standpoint: making sure that things are secure, making sure that there's no vulnerabilities on our network, that we're remaining compliant, and there's going to be some surveillance things that we're going to want to do. There's a lot of security aspects that we're going to want to monitor.

There's also assets and data aspects that we're going to monitor. For instance, we have a lot of data on our network and want to really specify what data is out there and what level we want to monitor that data at, depending on the sensitivity of it.

Then there's even processes that we're going to want to monitor — things that we are doing and carrying out, to make sure that we're carrying those things out in an efficient way and a secure way.

What We Look For

When it comes to monitoring, there are several things that we'll be looking for. We're going to be looking for the performance and the availability of whatever services that we're monitoring or the equipment that we're monitoring. We're going to want to monitor quality, and what kind of quality we have. There's also, once again, the anomalies, and if there's any kind of issues or events that are happening on this equipment and within our organization. We're going to look for trend lines and monitor for certain trend lines for certain security anomalies and events that are happening. And then there's a whole host of other things, like maybe a value of a product that we want to monitor.

The process for monitoring is going to be: we're going to identify what it is that we want to monitor, figure out how to monitor it and configure it, and then we'll go on with just the process of monitoring it.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →