## Purpose

Use this log to record important evidence collected during a cybersecurity incident.

The objective is to preserve enough information to support investigation, legal or insurance review, reporting, and post-incident analysis.

Formal forensic investigations may require additional evidence handling procedures provided by qualified specialists.

## Incident Information

Incident ID: ____________________

Evidence coordinator: ____________________

## Evidence Record

Evidence ID: ____________________

Date/time collected: ____________________

Collected by: ____________________

Source system/device/account: ____________________

Description:

---

## Evidence Type

- Log file
- Email
- Screenshot
- Disk image
- Device
- File
- Malware sample
- Cloud audit record
- Authentication record
- Network record
- Chat/message
- Configuration export
- Other: ____________________

## Original Location

---

## Collection Method

---

## Storage Location

---

## Integrity Information

File name: ____________________

File size: ____________________

Hash where appropriate: ____________________

Read-only/original preserved: 

- Yes / No / N/A

## Access and Handling

Person receiving evidence: ____________________

Date/time transferred: ____________________

Reason: ____________________

## Notes

---

## Evidence Handling Principles

- Preserve originals where practical.

- Work from copies where appropriate.

- Avoid unnecessary modification.

- Restrict access.

- Record who collected important evidence.

- Record where it is stored.

- Avoid deleting logs or affected accounts before evidence needs are considered.

- Seek specialist advice where legal proceedings or formal forensic investigation may be involved.

## Practical Rule

Evidence should help answer:

What happened, when did it happen, what was affected, and what actions were taken?
