During an investigation, responders document every person who handled a seized drive, the date and time of each transfer, and the purpose of each transfer, so the evidence can be trusted in court. Which process are they maintaining?
Chain of custody is the process that tracks evidence through its lifecycle by documenting each handler, the date/time of each transfer, and the purpose of the transfer.
- AA legal hold preserves data from deletion once litigation is anticipated; it does not, by itself, document each custodian and transfer of a physical item.
- COrder of volatility prioritizes which evidence to collect first based on how quickly it is lost; it concerns collection sequence, not custodial documentation.
- DWrite blocking prevents modification of source media during imaging; it protects integrity technically but does not record who handled the evidence and when.