Collection of Evidence: The process of collecting evidence involves systematically gathering data and information that can help investigate and resolve a security incident or breach. This can include log files, network traffic data, copies of malicious software, or user access records. Proper handling and storage of collected evidence is crucial to maintaining its integrity and usability, especially if it is needed for legal proceedings.
Categories: CC D5: Security Operations | CCSP D6: Legal - Risk and Compliance | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D5: Security Program Management and Oversight | SSCP D4: Incident Response and Recovery
« Back to Glossary Index