Skip to content

Logging and evidence preservation for security incidents

For IT administrators, MSP engineers and security analysts who set up logging or collect evidence when a security incident happens. Prerequisite: 'Incident response for the service desk: the first 15 minutes'; 'Security monitoring basics' helps too. You'll choose which logs to keep from the questions an investigation must answer, write a log management policy entry, protect and preserve logs, prioritise evidence collection by value, volatility and effort, and keep evidence verifiable with message digests and a chain of custody record. Based on NIST SP 800-86 and SP 800-92 (US federal guidance, 2006, still the published versions) and UK NCSC logging guidance. Evidence that may be used in legal or disciplinary proceedings needs your legal advisers and, often, a specialist; NIST itself says its guide is not legal advice, and neither is this course. It doesn't make you a qualified forensic examiner.

Level
Intermediate
Length
About 120 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Choose which logs to keep from the questions an incident investigation will need to answer
  • Write a log management policy entry covering what is logged, time source, transfer, storage, retention and disposal
  • Protect logs from tampering and loss, and preserve logs of interest separately from routine retention
  • Prioritise evidence collection by likely value, volatility and effort, and decide before changing a live system
  • Preserve evidence with integrity: verify copies with message digests and keep a chain of custody record

Course outline

  1. 1.Choose which logs to keep from the questions an incident investigation will need to answerLesson · 22 min
  2. 2.Write a log management policy entry for each sourceLesson · 20 min
  3. 3.Protect logs from tampering and loss, and preserve logs of interestLesson · 20 min
  4. 4.Prioritise evidence collection by likely value, volatility and effortLesson · 22 min
  5. 5.Preserve evidence with integrity: message digests and chain of custodyLesson · 14 min
  6. 6.Logging and evidence preservation for security incidents: knowledge checkKnowledge check · 14 questions
  7. 7.Logging and evidence preservation for security incidents: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.