Knowledgebase

Handling Cloud and Hosted Systems Print

  • 0

Evidence you do not control.

WHY IT DIFFERS

The systems are not yours and you cannot preserve them directly.

WHAT TO ESTABLISH

What the provider retains For how long How to request it What process is required

WHY IN ADVANCE

Requests during an incident are slow and the retention period may pass.

WHAT TO DO IMMEDIATELY ON AN INCIDENT

Contact the provider and request preservation.

WHY

It stops the retention clock on relevant records.

WHAT TO REQUEST

Logs for the relevant period Authentication records Administrative actions Any snapshots or backups from before the incident

WHY EARLIER BACKUPS

They may show the system before compromise.

WHAT TO PRESERVE YOURSELF

Anything you can export Configuration as it currently stands Your own records of access

WHAT TO ESTABLISH

Whether the provider will assist, and what they require.

WHAT MANY REQUIRE

Formal requests Verification of authority Sometimes legal process

WHAT TO ESTABLISH ABOUT SHARED INFRASTRUCTURE

That your investigation does not affect others.

WHY

Shared systems host other customers.

WHAT TO AVOID

Testing or examining infrastructure that is not yours.

WHAT TO ESTABLISH ABOUT SNAPSHOTS

Taking one before changing anything.

WHY

It preserves the state, and it is usually simple.

WHAT TO RECORD

What was taken, when, and its identifier.

WHAT TO ESTABLISH ABOUT DELETION

That evidence is not deleted by automatic processes during the investigation.

WHAT TO DO

Suspend lifecycle rules that would remove it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot