Evidence Collection Log
Purpose
Use this log to record important evidence collected during a cybersecurity incident.
The objective is to preserve enough information to support investigation, legal or insurance review, reporting, and post-incident analysis.
Formal forensic investigations may require additional evidence handling procedures provided by qualified specialists.
Incident Information
Incident ID: ____________________
Evidence coordinator: ____________________
Evidence Record
Evidence ID: ____________________
Date/time collected: ____________________
Collected by: ____________________
Source system/device/account: ____________________
Description:
Evidence Type
- Log file
- Screenshot
- Disk image
- Device
- File
- Malware sample
- Cloud audit record
- Authentication record
- Network record
- Chat/message
- Configuration export
- Other: ____________________
Original Location
Collection Method
Storage Location
Integrity Information
File name: ____________________
File size: ____________________
Hash where appropriate: ____________________
Read-only/original preserved:
- Yes / No / N/A
Access and Handling
Person receiving evidence: ____________________
Date/time transferred: ____________________
Reason: ____________________
Notes
Evidence Handling Principles
-
Preserve originals where practical.
-
Work from copies where appropriate.
-
Avoid unnecessary modification.
-
Restrict access.
-
Record who collected important evidence.
-
Record where it is stored.
-
Avoid deleting logs or affected accounts before evidence needs are considered.
-
Seek specialist advice where legal proceedings or formal forensic investigation may be involved.
Practical Rule
Evidence should help answer:
What happened, when did it happen, what was affected, and what actions were taken?