Data Preservation

Learn about the data properties required to be admissible as evidence of a security incident and some techniques required to collect it.

Overview

It should be assumed that data collected from an incident will be requested at a later date by law enforcement to support a legal investigation. The data collected from the incident may need to be used as evidence that something did or didn’t occur or that an entity is or isn’t liable for a criminal or damaging act.

Properties of admissible data

For data to be admissible as evidence, it has to be credible. The integrity of the data needs to stand up to scrutiny. There should be no doubt about whether the data has been tampered with since its creation. Any reasonable doubt, such as if the data owner can’t prove that integrity was maintained throughout the chain of custody, could make the data inadmissible.

Therefore, a data-handling process should be defined and followed. Documentation surrounding any data movement from when the data was created should be used. The handling of the documentation also needs to follow a strict process to ensure its unquestionable integrity.

Get hands-on with 1200+ tech skills courses.