IT monitoring is the continuous observation of systems, networks, and data to mitigate risk, support compliance, and inform business decisions. Core monitoring functions include discovery, mapping, aggregation, alerting, reporting, and log management, all anchored to the CIA Triad of confidentiality, integrity, and availability.
Monitoring Overview
The word monitoring just means that we're observing or checking the progress of something. We could be monitoring for mitigating risk, or we could be just collecting data so we can make production improvements, or we can be collecting data to make business level decisions, or data for marketing — we may actually take some of our data and then use it for some of our marketing material. We also might be monitoring just to meet some sort of compliance that we have; maybe it's a law, a regulation, or something that our customers are requiring us to do.
The main focus that we're going to focus on is mitigating risk. There are many different reasons why we mitigate risk, but a lot of it boils down to the CIA Triad: we're monitoring for confidentiality, integrity and availability.
To reduce risk, we're either reducing the likelihood that something's happening or the impact that it'll have if it does happen.
We can reduce the likelihood that something's going to happen just by identifying anomalies early and then fixing those anomalies so it doesn't become an issue. We could also reduce the impact, because if something were to happen we could get notified much quicker — we could have some sort of alert that notifies us, and that reduces the time it takes us to respond to an incident.
There's also the duration that the incident happens. We can actually shorten the incident duration, because all of this data that we're collecting creates benchmarks, so now we have some comparisons and understand what's happening on our network. Not to mention it can give us a lot of data for troubleshooting purposes.
When it comes to monitoring, there are several functions that we carry out:
There are a lot of things that we would want to monitor. What are some examples of this?
First of all, there could be infrastructure items or systems that we want to monitor. Maybe it's the endpoints on our network, maybe it's servers that are on our network, maybe it's networking gear — we're going to want to monitor all of that.
There's also applications and services. There are a bunch of things like databases where we'll want to monitor specific aspects of those databases, or our web performance, or maybe it's some sort of software or services that we're monitoring, or maybe it's some sort of cloud services that we're subscribed to and that we're going to want to monitor.
We also want to do a lot of monitoring from a security standpoint: making sure that things are secure, making sure that there's no vulnerabilities on our network, that we're remaining compliant, and there's going to be some surveillance things that we're going to want to do. There's a lot of security aspects that we're going to want to monitor.
There's also assets and data aspects that we're going to monitor. For instance, we have a lot of data on our network and want to really specify what data is out there and what level we want to monitor that data at, depending on the sensitivity of it.
Then there's even processes that we're going to want to monitor — things that we are doing and carrying out, to make sure that we're carrying those things out in an efficient way and a secure way.
When it comes to monitoring, there are several things that we'll be looking for. We're going to be looking for the performance and the availability of whatever services that we're monitoring or the equipment that we're monitoring. We're going to want to monitor quality, and what kind of quality we have. There's also, once again, the anomalies, and if there's any kind of issues or events that are happening on this equipment and within our organization. We're going to look for trend lines and monitor for certain trend lines for certain security anomalies and events that are happening. And then there's a whole host of other things, like maybe a value of a product that we want to monitor.
The process for monitoring is going to be: we're going to identify what it is that we want to monitor, figure out how to monitor it and configure it, and then we'll go on with just the process of monitoring it.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →