Preventive controls eventually fail. A password is phished, a patch is late, a trusted insider misuses access. Organizations must therefore be able to detect attacks and misuse quickly, because the longer an attacker stays unnoticed, the more damage they do. Security monitoring collects and analyzes events from across the environment and turns them into alerts that people investigate. For the auditor, the question is not whether a monitoring tool has been bought, but whether it sees the right things and whether anyone acts on what it finds.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.