Skip to main content
Category: Incident Response and Skimming

Digital Evidence Preservation

Also known as: Preservation of Digital Evidence, DE Preservation
Simply put

Digital evidence preservation is the process of protecting electronic data so it can be relied upon later, for example in an investigation or legal proceeding. It typically involves making copies of storage devices and keeping the original data in secure, read-only conditions so it cannot be altered. This matters because digital evidence can be changed or lost more easily than traditional physical evidence.

Formal definition

Digital evidence preservation refers to the practices and controls used to maintain the integrity and availability of digital evidence (DE), including data on physical storage media and other digital objects, from collection through analysis and potential legal use. Per NIST guidance (NIST IR 8387), it addresses problems that go beyond traditional evidence preservation because digital data is volatile and readily modifiable. Common practices described in the evidence include creating forensic copies of relevant storage devices and retaining originals in secure, read-only or cold-storage environments that block unauthorized access, thereby helping to protect the evidentiary chain of custody. This term belongs to the digital forensics domain and is distinct from PCI DSS data-retention or storage requirements; the evidence provided does not specify particular procedural standards, tooling, or legal admissibility criteria beyond these general considerations.

Why it matters

Digital evidence is inherently more fragile than traditional physical evidence. As NIST notes in NIST IR 8387, the preservation of digital evidence presents unique problems that go beyond traditional evidence preservation, largely because digital data is volatile and can be modified or lost with relative ease. A single write operation, an unintended system boot, or ordinary use of a device can alter or overwrite data that may later be needed in an investigation or legal proceeding. Without disciplined preservation practices, the reliability of that evidence, and the ability to demonstrate it was not tampered with, can be undermined.

For payment security and fraud teams, preservation matters whenever an incident may lead to an internal investigation, a dispute, or a legal or regulatory process. Making forensic copies of relevant storage devices and retaining originals in secure, read-only or cold-storage environments helps protect the evidentiary chain of custody so that findings can be relied upon later. The value of any subsequent analysis depends on whether the underlying evidence was preserved soundly from the outset.

It is important to note that digital evidence preservation belongs to the digital forensics domain and is distinct from PCI DSS data-retention or storage requirements. Preserving evidence for an investigation is a different objective from retaining or storing cardholder data under PCI DSS controls, and the two should not be conflated. The evidence available here describes general considerations rather than specific procedural standards, tooling, or legal admissibility criteria.

Who it's relevant to

Incident Response and Security Engineers
Teams responding to suspected compromises need to preserve digital evidence early, before analysis begins, to avoid inadvertently altering source data. Creating forensic copies and keeping originals in read-only or cold-storage conditions helps ensure that any later investigation can rely on the preserved data.
Fraud Analysts and Investigators
When fraud cases may escalate to disputes, internal reviews, or legal proceedings, sound preservation supports the reliability of the evidence they work with. Analysts benefit from understanding that analysis should generally be performed against forensic copies rather than original media.
Compliance and Legal Teams
Compliance officers and legal counsel rely on a protected chain of custody so that digital evidence can be relied upon in an investigation or legal process. They should also recognize that evidence preservation is distinct from PCI DSS data-retention obligations, and confirm admissibility and procedural requirements with appropriate legal and forensic authorities, as these are not specified in the evidence provided here.
Acquirers, Processors, and Merchant Risk Teams
Organizations that may need to investigate incidents affecting payment systems benefit from preservation practices that maintain the integrity and availability of digital evidence from collection through potential legal use, supporting later analysis and dispute handling.

Inside Digital Evidence Preservation

Chain of Custody
A documented, chronological record of who collected, accessed, transferred, and stored each piece of digital evidence. In payment security investigations, this record is intended to demonstrate that evidence such as logs, disk images, or transaction records was not altered between collection and use, though its evidentiary weight ultimately depends on applicable legal and jurisdictional standards.
Forensic Imaging
The creation of a bit-for-bit copy of a storage medium or system state so that analysis can be performed on the copy rather than the original. This helps preserve the source in its collected condition. Note that imaging captures whatever data is present; if sensitive authentication data was improperly retained, that data may appear in the image and must be handled under appropriate controls.
Cryptographic Hashing for Integrity
Computing hash values over collected evidence to detect subsequent modification. In this context hashing is used as an integrity check, which is distinct from tokenization, encryption, truncation, or masking used to reduce data exposure. A matching hash indicates the evidence has not changed since the hash was recorded, but does not by itself authenticate the original source.
Log and Audit Trail Preservation
Retention of system, application, network, and access logs relevant to an incident. Because log content and retention practices vary, these should be preserved in a manner that protects them from tampering and that accounts for any cardholder data or sensitive authentication data they may inadvertently contain.
Evidence Storage and Access Controls
Secure storage of collected evidence with restricted, logged access. Where evidence includes stored cardholder data such as PAN, applicable protection and access controls still apply; sensitive authentication data must not be retained after authorization and its presence in evidence indicates a control failure requiring documented handling.
Documentation and Timeline
A written account of collection methods, tools, timestamps, personnel, and analytical steps taken. This supports repeatability and review, though the specific format and rigor required depend on the investigation's purpose and any governing legal or contractual obligations.

Common questions

Answers to the questions practitioners most commonly ask about Digital Evidence Preservation.

Does digital evidence preservation mean I should keep full track data or CVV2 values captured during a suspected fraud incident?
No. The obligation to preserve digital evidence does not override the prohibition on retaining sensitive authentication data. Full track data, CAV2/CVC2/CVV2/CID values, and PINs or PIN blocks must not be stored after authorization, even when encrypted, and even for investigative purposes. Preservation efforts should focus on logs, system images, network captures, and other artifacts that do not require retaining prohibited data. Where an artifact incidentally contains sensitive authentication data, work with your compliance and legal teams to handle it under defined controls rather than treating an investigation as an exception to storage rules.
Is digital evidence preservation just a matter of making a backup of the affected systems?
No. A routine backup and forensically sound evidence preservation are not the same thing. Preservation is intended to maintain the integrity and authenticity of artifacts so they can support later analysis or proceedings, which typically involves controlled acquisition, integrity verification such as hashing, chain-of-custody documentation, and avoiding changes to the original data. A standard backup may alter timestamps, omit volatile data, or lack the documentation needed to demonstrate that the evidence was not tampered with. The label 'backup' does not by itself establish evidentiary integrity.
What types of artifacts are typically preserved during a payment security incident?
Commonly preserved artifacts may include system and application logs, authentication and access logs, network flow data or packet captures, firewall and IDS/IPS records, disk or memory images of affected systems, and relevant configuration data. The specific set depends on the incident, the environment, and applicable legal or contractual requirements. Preservation should exclude prohibited sensitive authentication data and should be handled in a way that limits exposure of any cardholder data present in the artifacts.
How should chain of custody be documented for preserved evidence?
Chain of custody documentation is intended to record who handled evidence, when, and for what purpose, along with how integrity was verified. Practices commonly include recording acquisition time and method, generating and recording cryptographic hashes at collection, logging every transfer or access, and storing evidence with restricted access. The goal is to be able to demonstrate that the evidence has not been altered since collection. Requirements and acceptable methods can vary by jurisdiction and by contractual or card brand obligations, so confirm specifics with legal counsel.
Who should be involved in evidence preservation during an incident?
Evidence preservation typically involves incident response and forensics personnel, along with legal counsel, compliance officers, and, where relevant, external forensic investigators. In payment environments, coordination with your acquirer, payment processor, or card brands may be required under their rules, and those requirements can vary by network and region. Involving the right stakeholders early helps ensure that preservation supports both investigative and regulatory needs without creating new compliance exposure.
How does evidence preservation interact with the requirement to avoid storing sensitive authentication data?
Preservation activities must be designed so they do not become a channel for retaining prohibited data. Before and during collection, teams should identify where cardholder data or sensitive authentication data may reside in artifacts, apply appropriate controls such as access restriction and, where feasible, minimization or masking of cardholder data, and ensure that sensitive authentication data is not retained. Handling should align with your organization's data protection controls and be reviewed by compliance and legal functions, since the effect on scope and obligations depends on implementation rather than intent.

Common misconceptions

Encrypting evidence is the same as preserving its integrity.
Encryption protects confidentiality by restricting who can read data, while integrity preservation relies on mechanisms such as cryptographic hashing to detect change. These are distinct functions; encrypting an image does not by itself prove the image was not altered, and hashing does not by itself keep the contents confidential.
If sensitive authentication data appears in a forensic image, it is acceptable because the evidence is secured.
Sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, or PINs and PIN blocks must not be stored after authorization, even when encrypted. Its presence in collected evidence typically signals a control failure and requires documented, controlled handling rather than being treated as normal retained data.
A documented chain of custody guarantees evidence will be accepted and prevents disputes.
A chain of custody is intended to support the reliability and admissibility of evidence, but it does not guarantee acceptance. Evidentiary standards are governed by applicable legal and jurisdictional rules that vary, and readers should confirm requirements against the relevant authority rather than assuming a fixed outcome.

Best practices

Create forensic images and work from copies, preserving the original source in its collected state whenever feasible.
Record cryptographic hash values at the time of collection and re-verify them before analysis to detect any change to the evidence.
Maintain a complete, timestamped chain of custody documenting every person who collected, accessed, or transferred each item of evidence.
Identify and appropriately handle any cardholder data or sensitive authentication data captured in evidence, applying required controls and treating retained sensitive authentication data as a control failure to be documented.
Restrict and log access to stored evidence, keeping it separate from production systems and protected against tampering.
Confirm collection and retention procedures against current applicable legal, contractual, and card brand or network requirements rather than assuming fixed rules, since these vary by region and change over time.