Legal Cyber Academy
Standard or guidanceFreeCurrent

NIST Cloud Computing Forensic Reference Architecture

Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Anand Kumar Mishra, Nancy Landreville, Yien Wang · National Institute of Standards and Technology · July 2024 (final; initial public draft February 2023) · 2024

Identifier: NIST SP 800-201

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The successor work to NISTIR 8006: a forensic reference architecture that maps the challenges onto the NIST cloud computing reference architecture and identifies where forensic readiness has to be designed in, with mitigation strategies tied to specific architectural elements. It includes a methodology plus a preliminary worked implementation.

Who it is for, and when

For architects and senior examiners who have to make a cloud estate investigable before an incident, and for advisers reviewing whether a provider or tenant configuration would support a defensible investigation. It gives the structure for a forensic-readiness assessment you can actually hand to a cloud engineering team.

What it does not cover

It is architecture, not procedure: there are no step-by-step acquisition instructions, no AWS/Azure/GCP console walkthroughs and no tool guidance, and NIST explicitly expects organisations to adapt it rather than apply it as-is. It also does not address the legal process for compelling provider-held data.

Go to the source

Open at csrc.nist.gov (opens in a new tab)

https://csrc.nist.gov/pubs/sp/800/201/final

Details

Type
Standard or guidance
Written for
AdvancedAdvanced
Author
Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Anand Kumar Mishra, Nancy Landreville, Yien Wang
Publisher
National Institute of Standards and Technology
Version verified
July 2024 (final; initial public draft February 2023)
Year
2024
Identifier
NIST SP 800-201
Topics
cloud, cloud-forensics, standards-development, incident-response, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • A catalogue produced by the NIST Cloud Computing Forensic Science Working Group that aggregates and categorises the forensic challenges of investigating incidents in cloud ecosystems — multi-tenancy, data location, provider dependency, chain of custody across parties, and the rest. The draft circulated from 2014; the final was issued in August 2020.

  • Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.

  • CyberDefenders

    Partly free

    A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.

  • A commercial digital forensics platform that acquires, processes, and reports on computer, mobile, cloud, and vehicle data in a single case, organised around artefact recovery rather than raw file system browsing. AXIOM Cyber is the variant aimed at corporate incident response, internal investigations, and ediscovery, adding remote endpoint collection.

  • Magnet Forensics' online DFIR conference, delivered over several weeks of sessions. The 2026 edition has taken place and its recordings are published as a free replay library, searchable by speaker, theme, language and week, covering mobile forensics, cloud investigations, video analysis and corporate investigations.