Following an internal investigation regarding unauthorized data exfiltration, an IT technician is tasked with transferring a seized storage drive to an external digital forensics expert. To maintain a legally defensible chain of custody during this transfer, which of the following details MUST be recorded on the evidence log?
- The date, time, and signatures of both the relinquishing and receiving partiesAnswer
- BThe master BitLocker recovery key and file system decryption credentials
- CThe structural rating and lock specifications of the facility where the evidence is kept
- DThe threat vector classification and social engineering methodology identified in the attack
Answer
The date, time, and signatures of both the relinquishing and receiving parties
Maintaining an unbroken chain of custody requires logging the precise date and time of evidence transfer, along with the printed names and signatures of both the party relinquishing custody and the party accepting it. This ensures full accountability and evidence integrity for judicial proceedings.
Step-by-Step Solution
Key Concept
Chain of Custody Evidence Transfer Protocols