Legal Cyber Academy
Standard or guidanceFreeCurrent

Guide to Integrating Forensic Techniques into Incident Response

Karen Kent, Suzanne Chevalier, Tim Grance, Hung Dang · National Institute of Standards and Technology · August 2006 (final, published 1 September 2006) · 2006

Identifier: NIST SP 800-86

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.

Who it is for, and when

Read it if you are standing up or auditing a corporate or government DFIR capability and need a citable federal reference for policy, staffing and data-source priority. It is also the document to cite when you need to justify a collection order of volatility to a court or a client. Newcomers can use chapters 4-7 as a checklist of where evidence lives on a host or network.

What it does not cover

It has not been revised since 2006, so it predates full-disk encryption as a default, cloud-hosted workloads, smartphones, SSD trim behaviour and modern Windows artefacts; the tool and OS specifics are obsolete even though the process model is not. It gives no legal analysis of admissibility and no US or foreign procedural law.

Go to the source

Open at csrc.nist.gov (opens in a new tab)

https://csrc.nist.gov/pubs/sp/800/86/final

Details

Type
Standard or guidance
Written for
New to the fieldWorking examinerNew to the field, Working examiner
Author
Karen Kent, Suzanne Chevalier, Tim Grance, Hung Dang
Publisher
National Institute of Standards and Technology
Version verified
August 2006 (final, published 1 September 2006)
Year
2006
Identifier
NIST SP 800-86
Topics
incident-response, evidence-handling, imaging, network, log-analysis, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.