The process of monitoring the events occurring in a computer system or network, analyzing them for signs of possible incidents, and attempting to stop detected possible incidents.
Source(s):
CNSSI 4009-2015
from
NIST SP 800-94