1. Purpose
The Evidence Collection Form is used to formally record the collection of information-security evidence during an incident, investigation, security event, audit, assessment, or other authorized activity.
The form creates a traceable record showing:
What was collected → Where it came from → Who collected it → When → How → Integrity → Where it was stored → Who accessed it
This form should be used together with the Evidence Collection Procedure and, where applicable, the Evidence Preservation Procedure and Chain of Custody Record.
2. Evidence Collection Record
Evidence ID
EV-YYYY-0001
Incident / Investigation ID
Event ID
Related Record
Incident / Security Event / Audit / Investigation / Security Test / Other
Collection Date
Collection Time
Time Zone
Collected By
Role
Approved By
3. Collection Objective
Why is this evidence being collected?
Investigation Question
What question is the evidence expected to help answer?
Example:
Determine whether the compromised AWS identity accessed customer S3 data.
4. Evidence Description
Evidence Title
Evidence Description
Evidence Type
Select one or more:
- Authentication
- Identity / IAM
- Cloud
- Network
- Endpoint
- Application
- Database
- Source Code
- CI/CD
- Security Alert
- Configuration
- Backup
- Communication
- Physical
- Audit
- Other
5. Evidence Source
Source Organization
Source System
Hostname / Resource ID
Account / Tenant / Environment
Application / Service
Original Location
Source Owner
Source Contact
6. Evidence Time Period
Start Date/Time
End Date/Time
Time Zone
Source-System Time
Time Synchronization Considerations
Record any known difference between the source-system clock and the investigation timeline.
7. Collection Method
Collection Method
- System export
- Security-tool export
- API
- Log download
- Screenshot
- File copy
- Forensic image
- Database export
- Email export
- Cloud-platform export
- Supplier-provided evidence
- Physical collection
- Other
Collection Procedure Used
Tool / Platform Used
Tool Version
Command / Query / Filter Used
Where appropriate, record the query or filter used to obtain the evidence so the collection can be reproduced or reviewed.
8. Original Evidence Information
Original File / Record Name
File Type / Format
File Size
Number of Records
Original Location
Original System
Original Timestamp
Read-Only / Original Preserved?
- Yes
- No
- Not Applicable
If No, Explain
9. Evidence Integrity
Integrity Verification Required?
- Yes
- No
Hash Algorithm
Example:
SHA-256
Hash Value
Hash Calculated By
Hash Date/Time
Hash Reverified?
- Yes
- No
- Not Applicable
Reverification Result
10. Evidence Classification
Information Classification
- Public
- Internal
- Confidential
- Restricted
Does the Evidence Contain Personal Data?
- Yes
- No
- Unknown
Does the Evidence Contain Customer Data?
- Yes
- No
- Unknown
Does the Evidence Contain Sensitive Security Information?
- Yes
- No
- Unknown
Does the Evidence Contain Credentials or Secrets?
- Yes
- No
- Unknown
If credentials or secrets are identified, do not record the secret value in this form. Follow the organization’s credential-compromise and secret-rotation process.
11. Evidence Relevance
Relevance to Investigation
Explain why the evidence is relevant.
Related Activity
Related System
Related Identity
Related Information
Related Timeline Event
12. Evidence Priority
Priority
- Critical / Volatile
- High
- Normal
- Supporting
Reason for Priority
Was Volatile Evidence Considered?
- Yes
- No
- Not Applicable
If Not Collected
13. Evidence Storage
Storage Location
Repository / System
Storage Classification
Encryption Applied?
- Yes
- No
- Not Applicable
Access Restricted?
- Yes
- No
Authorized Access Group
Backup Required?
- Yes
- No
14. Evidence Access
Record significant access to sensitive evidence.
| Date/Time | Person | Evidence ID | Action | Purpose |
|---|---|---|---|---|
| View | ||||
| Copy | ||||
| Analyze | ||||
| Transfer |
Actions may include:
- View
- Copy
- Export
- Analyze
- Transfer
- Restore
- Verify
- Dispose
15. Chain of Custody
Complete this section when the evidence requires formal chain-of-custody tracking.
| Date/Time | Evidence ID | Released By | Received By | Purpose | Location | Integrity Verified |
|---|---|---|---|---|---|---|
Current Evidence Custodian
Current Storage Location
16. Evidence Transfer
Transfer Required?
- Yes
- No
Transferred From
Transferred To
Transfer Date/Time
Transfer Method
Transfer Reason
Integrity Verified After Transfer?
- Yes
- No
Verification Result
17. Third-Party Evidence
Evidence Provided By
Organization
Provider Contact
Provider Reference / Ticket
Date Received
Method Received
Provider Integrity Information
Restrictions on Use
Examples:
- Confidentiality restriction
- Customer restriction
- Legal restriction
- Contractual restriction
- Provider terms
18. AWS / Cloud Evidence
Complete where the evidence comes from AWS or another cloud environment.
Cloud Provider
Account / Subscription / Project
Region
Service
Examples:
- CloudTrail
- IAM
- GuardDuty
- Security Hub
- S3
- RDS
- EC2
- ECS
- EKS
- Lambda
- VPC
- WAF
- KMS
- Secrets Manager
Resource ID
Cloud Evidence Type
Relevant Activity
Cloud Timestamp
Export Method
Cloud Evidence Integrity
19. Email Evidence
Complete when collecting email-related evidence.
Mailbox / Account
Sender
Recipient
Subject
Message ID
Date/Time
Attachment
URL / Link
Full Headers Preserved?
- Yes
- No
Original Message Preserved?
- Yes
- No
20. Endpoint Evidence
Device / Hostname
Device ID
User
Operating System
EDR / Security Tool
Relevant Process
File / Artifact
Network Connection
Collection Method
21. Application / Database Evidence
Application / Database
Environment
- Production
- Staging
- Development
- Other
Account / User
Relevant Activity
Log / Query Source
Query / Filter Used
Data Exposure Consideration
Avoid copying actual customer or personal data unless necessary and authorized.
22. Evidence Gaps
Was Any Required Evidence Unavailable?
- Yes
- No
Evidence Not Available
Reason
- Log not enabled
- Log expired
- System unavailable
- Access unavailable
- Supplier limitation
- Technical limitation
- Data overwritten
- Evidence destroyed before preservation
- Other
Impact on Investigation
Compensating Evidence
23. Evidence Quality Assessment
Evaluate the reliability of the evidence.
| Question | Assessment |
|---|---|
| Source known? | Yes / No |
| Collector known? | Yes / No |
| Collection time known? | Yes / No |
| Time zone known? | Yes / No |
| Collection method documented? | Yes / No |
| Integrity verified? | Yes / No / N/A |
| Evidence complete? | Yes / No / Unknown |
| Evidence relevant? | Yes / No |
| Evidence protected? | Yes / No |
| Corroborated by another source? | Yes / No / Unknown |
Evidence Reliability Notes
24. Analysis Notes
Facts Established From Evidence
Observations
Hypotheses
Unknowns
Preliminary Conclusion
Important:
A hypothesis should not be recorded as a confirmed fact until supported by sufficient evidence.
25. Evidence Relationships
Link the evidence to related ISMS records.
Incident ID:
Security Event ID:
Investigation ID:
Timeline Record:
Root Cause Analysis ID:
Data Breach Assessment ID:
Corrective Action ID:
Lessons Learned ID:
Risk ID:
26. Collection Validation
The collector confirms:
- Evidence source was identified.
- Collection was authorized.
- Relevant time period was defined.
- Collection method was recorded.
- Original evidence was preserved where practical.
- Evidence ID was assigned.
- Integrity was considered.
- Evidence was securely stored.
- Access was restricted.
- Sensitive information was handled appropriately.
- Chain of custody was established where required.
- Evidence gaps were documented.
27. Collector Declaration
I confirm that the evidence described in this form was collected using the documented method and, to the best of my knowledge, the information recorded accurately represents the collection activity.
Collected By:
Role:
Signature / Electronic Approval:
Date:
28. Evidence Reviewer
Reviewed By
Role
Review Date
Review Result
- Accepted
- Accepted With Limitations
- Additional Evidence Required
- Collection Repeated
- Rejected
Reviewer Comments
29. Evidence Closure
Investigation Complete?
- Yes
- No
Further Collection Required?
- Yes
- No
Evidence Retention Requirement
Retention Until
Legal / Regulatory Hold?
- Yes
- No
- Unknown
Disposal Authorized?
- Yes
- No
- Not Yet
30. Evidence Disposition
Complete when evidence is no longer required.
Disposition
- Retained
- Archived
- Securely Deleted
- Returned to Source
- Transferred
- Other
Disposal / Transfer Date
Authorized By
Method
Evidence Register Updated?
- Yes
- No
31. Example — AWS Account Compromise
Evidence ID
EV-2026-0042
Incident ID
INC-2026-0017
Evidence
AWS CloudTrail records covering the suspected compromised administrator identity.
Source
AWS CloudTrail
Account
Production AWS Account
Time Period
30 September 2026 09:00–14:00 IST
Collection Method
Authorized CloudTrail export using approved administrative access.
Investigation Objective
Determine whether the compromised identity created unauthorized IAM resources and accessed customer information.
Related Evidence
- IAM role changes
- GuardDuty finding
- S3 access activity
- Security Group changes
- CI/CD activity
Integrity
SHA-256 hash recorded in the Evidence Register.
Storage
Restricted incident evidence repository.
Access
Incident Response Team only.
Analysis
The CloudTrail evidence is correlated with IAM and S3 records to establish:
Identity → Authentication → Privilege → Resource → Data Access → Timeline
32. Minimum Evidence Collection Form
For smaller incidents, the organization may use a simplified form:
| Field | Information |
|---|---|
| Evidence ID | |
| Incident ID | |
| Evidence Description | |
| Source | |
| System | |
| Collected By | |
| Date/Time | |
| Time Zone | |
| Collection Method | |
| Original Location | |
| Classification | |
| Hash | |
| Storage Location | |
| Access Restrictions | |
| Related Finding | |
| Evidence Gaps | |
| Reviewer | |
| Status |
This provides a lightweight starting point while retaining basic traceability.
33. Relationship With the Evidence Collection Procedure
The Evidence Collection Procedure defines how evidence should be collected.
The Evidence Collection Form records what was actually collected.
The relationship is:
Procedure → Collection Activity → Evidence Collection Form → Evidence Register → Investigation → Findings → Root Cause → Corrective Action → Closure
34. Audit Trail
Investigation Authorized → Evidence Requirement Identified → Collection Scope Defined → Evidence Source Identified → Collector Authorized → Time Window Defined → Evidence Collected → Evidence ID Assigned → Source Recorded → Collection Method Recorded → Integrity Verified → Evidence Classified → Evidence Secured → Access Restricted → Chain of Custody Recorded → Evidence Reviewed → Findings Linked → Evidence Gaps Recorded → Retention Determined → Evidence Disposed/Archived → Record Closed
Final Principle
Every Important Piece of Evidence Should Have an Identity, a Source, a Collector, a Time, a Method, an Integrity Record, a Secure Location, and a Traceable Relationship to the Investigation.
Identify → Collect → Record → Verify → Protect → Analyze → Trace → Retain → Dispose.
