Night Mode LabsBlue Book
Evidence Requests

Evidence Handling

Evidence often contains sensitive operational, security, financial, or customer information. Handle it deliberately from request through retention or deletion.

Handling rules

  • Request only evidence needed for the engagement.
  • Prefer links to systems of record over exported copies.
  • Store exports in approved client or engagement locations.
  • Avoid copying secrets, tokens, PHI, or customer data into notes.
  • Redact sensitive fields before sharing broadly.
  • Record source, timestamp, and owner for important evidence.
  • Delete local copies when they are no longer needed.

Sensitive evidence

Treat these as sensitive by default:

  • IAM exports and privileged access lists.
  • Network diagrams and firewall rules.
  • Vulnerability findings.
  • Incident timelines involving customers or security events.
  • Cloud cost reports.
  • Logs, traces, and database exports.
  • Screenshots containing user or patient information.

Evidence lifecycle

Watchouts

  • Screenshots can contain more sensitive data than expected.
  • AI tools must be approved for the data they receive.
  • Personal downloads folders are not evidence repositories.
  • Evidence should outlive the engagement only when retention is agreed.

On this page