Evidence Requests
Evidence Handling
Evidence often contains sensitive operational, security, financial, or customer information. Handle it deliberately from request through retention or deletion.
Handling rules
- Request only evidence needed for the engagement.
- Prefer links to systems of record over exported copies.
- Store exports in approved client or engagement locations.
- Avoid copying secrets, tokens, PHI, or customer data into notes.
- Redact sensitive fields before sharing broadly.
- Record source, timestamp, and owner for important evidence.
- Delete local copies when they are no longer needed.
Sensitive evidence
Treat these as sensitive by default:
- IAM exports and privileged access lists.
- Network diagrams and firewall rules.
- Vulnerability findings.
- Incident timelines involving customers or security events.
- Cloud cost reports.
- Logs, traces, and database exports.
- Screenshots containing user or patient information.
Evidence lifecycle
Watchouts
- Screenshots can contain more sensitive data than expected.
- AI tools must be approved for the data they receive.
- Personal downloads folders are not evidence repositories.
- Evidence should outlive the engagement only when retention is agreed.