NIST Forensic process – Collection: Collection is a key stage in the NIST Forensic Process, which involves gathering relevant digital evidence from various sources, like hard drives, network logs, system memory, etc. This stage must be done in a systematic, careful, and legally acceptable manner to ensure the integrity and admissibility of the evidence in potential legal proceedings. This may include creating exact copies of hard drives or other storage media (imaging), logging network traffic, or systematically documenting the physical scene of an incident.
Categories: CC D5: Security Operations | CCSP D5: Cloud Security Operations | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D4: Security Operations | SSCP D4: Incident Response and Recovery
« Back to Glossary Index