- Home
- All questions
- Question 791
CISM study material · question 791 of 1000
Formal chain-of-custody handling is not applied to a malware incident. Does NIST regard the collected data as evidence?
Show the answer
Answer: A. Yes — collected incident data is still considered evidence, being grounds for belief or disbelief
SP 800-61r3 notes formal evidence gathering with chain-of-custody procedures might not be performed for every incident, since most malware incidents will not result in prosecution, but that collected incident data is still considered evidence.
Source: NIST SP 800-61 Rev. 3 (NIST) — Table 3 RS.AN-07.N1