Evidence Collection Log

Purpose

Use this log to record important evidence collected during a cybersecurity incident.

The objective is to preserve enough information to support investigation, legal or insurance review, reporting, and post-incident analysis.

Formal forensic investigations may require additional evidence handling procedures provided by qualified specialists.

Incident Information

Incident ID: ____________________

Evidence coordinator: ____________________

Evidence Record

Evidence ID: ____________________

Date/time collected: ____________________

Collected by: ____________________

Source system/device/account: ____________________

Description:


Evidence Type

  • Log file
  • Email
  • Screenshot
  • Disk image
  • Device
  • File
  • Malware sample
  • Cloud audit record
  • Authentication record
  • Network record
  • Chat/message
  • Configuration export
  • Other: ____________________

Original Location


Collection Method


Storage Location


Integrity Information

File name: ____________________

File size: ____________________

Hash where appropriate: ____________________

Read-only/original preserved:

  • Yes / No / N/A

Access and Handling

Person receiving evidence: ____________________

Date/time transferred: ____________________

Reason: ____________________

Notes


Evidence Handling Principles

  • Preserve originals where practical.

  • Work from copies where appropriate.

  • Avoid unnecessary modification.

  • Restrict access.

  • Record who collected important evidence.

  • Record where it is stored.

  • Avoid deleting logs or affected accounts before evidence needs are considered.

  • Seek specialist advice where legal proceedings or formal forensic investigation may be involved.

Practical Rule

Evidence should help answer:

What happened, when did it happen, what was affected, and what actions were taken?