How should incident records and digital evidence be protected?
For records used only to manage the case, preserve authenticity, access control, version history, timestamps, and links to the incident register. For potential digital evidence, use procedures suited to the intended investigation or proceeding, including identification, collection, acquisition, preservation, integrity verification, access logs, and chain of custody.
Do not describe every operational log as forensic evidence. Apply the stronger handling process when legal prosecution, disciplinary action, litigation, regulatory review, or another evidential purpose is reasonably possible.
- Record who collected or exported the material, when, from which source, by what method, and where it is stored.
- Protect original data where feasible and record examinations, copies, transfers, transformations, and integrity checks.
- Restrict sensitive logs and evidence by role, and keep access records for the full retention period.
ISO/IEC 27035-2 supports planning, preparation, and lessons-learned records that retained logs should preserve for incident response review.
ISO/IEC 27035-3 supports ICT incident-response operations where operational logs, triage records, and response evidence are used.