← Cybersecurity Alphabet Soup

NSM

Network Security Monitoring

operationshard

NSM is the practice of collecting and analyzing network data, including flows, sessions, and full packets, to detect and investigate intrusions. Unlike simple alerting, NSM emphasizes keeping rich network evidence so analysts can reconstruct attacker activity after the fact. Because detection will never be perfect, this ensures you have the data to investigate what your alerts missed.

Sources

More in operations