Skip to content

Glossary · Information security

Logging and Monitoring

The recording of system and security events and their ongoing review to detect anomalies and support investigations.

Logging captures events such as logins, configuration changes, and errors, while monitoring is the active review of those records to spot signs of trouble. Together they give visibility into what is happening across systems.

Good logging supports detection, alerting, and forensic investigation after an incident. Logs must themselves be protected against tampering and retained for an appropriate period.

Production and other OT environments invert the usual assumptions. Control systems often cannot carry an agent, they run for a decade or more without a patch window, and availability outranks confidentiality, so collection is typically passive: a mirror port or a data diode into a segmented collector rather than software on the machine. NIS2 counts these plants as in scope wherever they support an essential or important service, which makes the OT side of logging a compliance question and not only an engineering one.

Terms matter when they become defensible work.