The analyst should first establish a legal hold because the suspected breach involves personnel records and evidence that may become relevant to regulatory, disciplinary, civil, or other legal proceedings. A legal hold prevents potentially relevant information from being deleted, overwritten, modified, rotated out under normal retention schedules, or otherwise destroyed before the organization's legal and investigative obligations are understood.
Preservation must precede destructive or potentially evidence-altering actions. NIST describes digital forensics as retrieving, storing, and analyzing electronic information while ensuring that evidence is captured reliably without alteration. RFC 3227 similarly emphasizes preserving evidence, following proper collection procedures, documenting handling, and maintaining chain of custody.
Log correlation and timeline construction are important investigative activities, but they should occur after preservation requirements have been established. Resetting credentials may subsequently be required for containment, but the scenario first raises an evidence-preservation obligation. Restoring files from backup would be especially premature because it could alter timestamps, overwrite artifacts, or otherwise complicate forensic analysis.
The examination principle is therefore preserve first when legal implications are reasonably foreseeable; analyze and remediate afterward under controlled procedures .
Study Guide Reference: Incident Response and Management → Evidence Acquisition → Legal Hold → Evidence Preservation → Chain of Custody → Timeline Analysis → Regulatory/Legal Considerations.
Submit