During a recent security incident investigation, a security analyst mistakenly turned off the infected machine prior to consulting with a forensic analyst. upon rebooting the machine, a malicious script that
was running as a background process was no longer present. As a result, potentially useful evidence was lost. Which of the following should the security analyst have followed?
A legal hold is a process by which an organization instructs its employees or other relevant parties to preserve specific data for potential litigation. A legal hold is triggered when litigation is reasonably anticipated, such as when law enforcement officials inform an organization that an investigation has begun. The first step the organization should take is to initiate a legal hold to ensure that relevant evidence is not deleted, destroyed, or altered. A legal hold also demonstrates the organization's good faith and compliance with its duty to preserve evidence. Verified Reference:
https://percipient.co/litigation-hold-triggers-and-the-duty-to-preserve-evidence/
Clorinda
1 months agoMadalyn
16 days agoSlyvia
1 months agoKiera
13 days agoJenelle
14 days agoIsidra
18 days agoAlline
2 months agoMichell
12 days agoXuan
16 days agoCyndy
20 days agoRhea
2 months agoPeggy
2 months agoDanica
3 days agoEric
20 days agoRemedios
1 months agoTammi
1 months agoGlory
2 months agoBettye
3 months agoCassandra
3 months ago