What is the chain of custody and why is it important in forensics?
CISSP Flashcards: Security Operations, Incident Response, Forensics, Logging
Audio flashcard · 0:26Nortren·
What is the chain of custody and why is it important in forensics?
0:26
The chain of custody is a documented record tracking the possession, handling, and movement of evidence from the time it is collected until it is presented in court or disposed of. It records who collected the evidence, when and where it was collected, who had possession at each point, and how it was stored and protected from tampering. A broken chain of custody can render evidence inadmissible in court because its integrity cannot be verified. Every transfer of evidence must be documented with signatures, dates, times, and reasons.
csrc.nist.gov