Assignment Help-Evidence Collection Policy
Ken 7 Windows Limited has decided to form a computer security incident response team (CSIRT). When making any security-related changes, they know the first step is to modify the security policy. As a security administrator, you have been assigned the responsibility of developing a CSIRT policy that addresses incident evidence collection and handling.
Answer the following questions for collecting and handling evidence:
1. What are the main concerns when collecting evidence?
2. What precautions are necessary to preserve evidence state?
3. How do you ensure evidence remains in its initial state?
4. What information and procedures are necessary to ensure evidence is admissible i