Pervasive Security Monitoring

I am beginning to formulate my thoughts on what I'm calling Pervasive Security Monitoring. I don't have a formal definition yet, but the concept will extend past NSM data sources (traffic) into reports on the state of platforms, OS, applications, and data. The dictionary definition, to become spread throughout all parts of, captures the concept fairly well at this stage.
I noticed Cisco and a few others used the term pervasive security awareness, but it's used as a way to encourage employees to become security conscious. That's not what I mean. I see pervasive security monitoring as a way to achieve pervasive security awareness, in the form of collecting data to inform the decision-making process.
I considered using the term "enterprise security monitoring," but I don't think that term as previously used covers everything I have in mind. As I develop these thoughts I will discuss them here.
Comments
Let's not leave the notion of service providers/delivery networks out in the cold. Many of these folks tune out when they hear "enterprise" yet every enterprise is connected to them.
Likewise, some of the biggest enterprises look like closed-circuit service providers to their partners, customers and constituents...
/Hoff