Glossary · OT security engineering
Security monitoring
Also known as: Continuous security monitoring, OT security monitoring
German: Sicherheitsüberwachung
In cybersecurity, security monitoring is the continuous collection and analysis of logs, network traffic and system states to detect attacks, policy violations and anomalies in time to respond. In OT, it covers industrial networks, controllers, HMIs and remote access paths.
- Security engineering
- OT security
In one sentence
Security monitoring continuously collects and analyzes logs, network traffic and system states to detect attacks and anomalies in time to respond.
Example
Security monitoring shows that a controller's program changed outside a planned maintenance window, triggering an investigation that finds an unauthorized download from a contractor laptop.
How it applies
- Engineering: Monitoring sources include firewall and switch logs, OT intrusion detection, Windows events on HMIs and servers, remote access logs and controller change detection. IEC 62443 addresses this under the foundational requirement for timely response to events.
- Operation: Monitoring only helps if someone reviews alerts and can act, internally or through a Security operations center (SOC). Alerts must be linked to planned changes to avoid alarm fatigue.
- Safety: Monitoring systems should be passive or clearly separated from control, so that they cannot disturb control or safety communication.
- Documentation: Security manuals should describe which events a product logs, how monitoring tools can access them and which normal behavior to expect. Operators need their own documentation of monitored assets, gaps and escalation contacts.
Security monitoring vs. process monitoring
Process monitoring watches process values and machine states for production and safety purposes. Security monitoring watches for signs of compromise. An unusual process value can be a clue for security, so the two teams should talk.