The process of monitoring the events occurring in a computer system or network and analyzing them for signs of possible incidents.
Source(s):
CNSSI 4009-2015
from
NIST SP 800-94