Chain of Custody Part 1

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

1 hour 2 minutes
Video Transcription
Hello. My name is David,
and welcome to you managing. And it
over Matthew managing an incident. So we just finished up the first steps in as the response in an institute on one of the things we talked about was identifying, reserving, collecting habits. Um,
because it's gonna be necessary for your announcements about internally and maybe even
externally if both worsen it were a regulatory body may possibly get involved. So
dealing with
I kind of stumbled saying this, some people do take it, take some offensive this, but I'm gonna say it anyway. In the civilian I he wore often times
the chain of custody and evidence are thought up when an incident occurs, the only thing that is thought of his recovery and remediation, they skip over those initial steps in the incident response process and move directly into
you're continue mentor remediation
on and sad to say, that is changing a CZ. People become more aware incidence and especially as breaches get larger and bigger and more publicized, more people and I fear becoming aware of me not just jump immediately that however, however
Jim patient is there.
So you as innocent respondent Nate to keep that in mind as well. Don't let yourself get pressured into skipping this step of viewing with Evans.
Now, after the initial shock, we don't panic. Button get pushed. We saw people screaming the yelling in the hallway, uh, cowering under their desks, sucking their thumb in fetal position where they found out to be possibly ranged.
But once the incident response process is start, one of the very first things that we need to start doing in this process is identify possible evidence. Of course, that
is a corollary to the entire thing. If you get a say in alert for possible their long in multiple Bill Mauldin attempts on you started researching that and you begin C I p addresses ranges that have nothing to do. Business
Ugo Threat Intelligence on those two virus turnovers. San's I. C. S
and they're coming back to them. Hacking groups. You've got a problem now you've already identified your exchange server would be impossible Social evidence or Officer six. By just depending on how you read that
or if a usual contacts out test and says, Hey, I keep getting these pop ups on my system. I don't understand what's going on. Sometimes my mouse moves by itself.
He does,
doesn't reply. He s paying and boards that over the hero on stock analysts who looks at it and see some really strange points and then Fords it onto that here to slash re analysts, You got an end user system that's gonna need analyzed. But once you've made that identification,
you have to keep it in the front of your mind
that even if there is the remotest possibility of criminal action, were possibly internal action against an impolite, and you should complete the chain of custody to cover yourself in the entire process.
What is the Jane cost? Simply put, it's a paper trip tracking the evidence.
You need your Caesar recovered. I anybody touches it. Anybody who handles it, anybody who takes possession of it, their name should be on that chain of custody.
Ah, lot of industry regulations actually require Jean custody for just practically
any incident that would occur hip being one example that any legal action could require James Pastilles.
Any employee
disciplinary actions could require
a chain of custody, say an employee. I was serving bad things on the Internet through the company network and using a couple just down the investigation proceeds,
the Human Resources Board decides that this person's fire's a fire his person. And then that person files a wrongful termination suit against the company.
You could very well have to get testify in court. He did the forensic analysis of shiing or say even longer analysis.
Do you have a chain of custody to document the system who have it where it was store a dates and times of when it was access and then put back? Because if you don't, that evidence could be excluded in court and the entire case could be lost.
Worst case scenario. Um, I pass by in many, many criminal cases in civil cases recording digital evidence. And that is one of the go tubes
for defense terms. Is this chain out house They will look that thing over with a fine thio
looking for gaps in times, dates, missing people. Um, we had one case. It wasn't a digital case. I in both drugs. But the defense attorney subpoenaed every single person on the chain of custody to a jury trial
when he came in
his first thing that morning was he got out his listen. Witnesses. He started going down and calling out means just Smith, Jane Doe,
Then Underhill, a Zen. Each person said they were there. He said, Your excuse, your excused, your excuse years. It was every single name that was on the chain of custody. Oh, he was trying to do is get one person on the chain of custody not to show up the court.
And then he would be able to exclude the Alex when everybody showed up.
You haven't seen me was going to be admitted.
No purpose and even pursuing jury child, that at that point he wanted to get a plea bargain pregnant. So they are extremely important to document the evidence. And what is going on with? So now, while we're here, let's go out here into
the world and take a look at the sample.
Jane in custody, They're not truly difficult, So don't Don't overblow them in your mind. Please. Now we would do search warrants.
One of the things that we would do is labeled each one with a number. So room first room, we went in to get a label put on the door at the letter a on mention bees. Edie on down the alphabet,
whether in room description, kitchen, living room, dining back from whatever might happen to be. And then these forms in and of themselves contain it'd entry log. So if an investigator way into over, he had to sign on this form. But the time in that he went into the room
the time you left the room. And if he are took in any evidence being seized,
he had to identify why evidence he sees from that room. This may seem a little overwhelming to some people,
but it didn't protect us in several complaints when defendants and so and so stole something during the execution of surf or whatever
on we had these forms that we could bring out and say that investigator never even entered that room. According to this form on. One thing you'll find out in court cases is if it's written down and documented like this,
this pretty much held to be true.
However, if you have to go, just be a word of mouth, Then comes a little trickier because I don't know about you, but I can't remember every single person they've come into a room.
So if they can put one person on the stand and says, Hey, do you remember it? Jane Smith came into the room during the execution of Search one. No, I I really cannot say I remember seeing that person here in the room or not. There's room for evidence of how so This kind of form
can l come
now? They're not necessary. All the times that you were working in an office environment on your searching cubicle, of course you're just in the cubicle, but you still want to keep along who was there on what they do while they were there in order to help
protect yourself and the evidence in case off court.
Now, this is a digital evidence. Jane, Dustin, for some places have different forms for physical evidence, visual evidence,
um, bodily fluids, all kinds of stuff. I committed place. So since we're focused on its response is basically visual evidence. This is just an example that a case number, depending upon what format your company decides to use force. However many pages were needed to cover the chain of custody form
I identification of the computer sell a CZ best you can. I know many computers don't have, ah, visible serial number. A little number that you need to make a good description of it.
I, the important parts of who obtained it,
the date time and if anybody who they got that from it is imaged. Then of course, you put your passion where it was stored and you did the imaging and all that. And then any other time that piece of evidence is removed or touched by somebody else, this
section of warm that gets filled in
to ensure that it is adequately That's a real brief and simple introduction to you. Chain of custody. Like I said, it's not too overblown or too complicated. I'll put up a copy of the chain of custody on, uh,
lesson science so that you can access it and modified everyone. Every questions hit me up, Davey. 135 homes. I'm very
afforded talking to you by
Up Next