Study. uk . com
  1. Home
  2. All questions
  3. Question 791

CISM study material · question 791 of 1000

Formal chain-of-custody handling is not applied to a malware incident. Does NIST regard the collected data as evidence?

  1. Yes — collected incident data is still considered evidence, being grounds for belief or disbelief
  2. Only if the data was collected by an examiner who holds a recognised forensic certification for that kind of work
  3. No — data that was collected outside a formal chain of custody is not evidence of any kind at all in this case
  4. Only if the incident later leads to prosecution
Show the answer

Answer: A. Yes — collected incident data is still considered evidence, being grounds for belief or disbelief

SP 800-61r3 notes formal evidence gathering with chain-of-custody procedures might not be performed for every incident, since most malware incidents will not result in prosecution, but that collected incident data is still considered evidence.

Source: NIST SP 800-61 Rev. 3 (NIST) — Table 3 RS.AN-07.N1

Challenge yourself on this topic → Study as cards