Skip to content

Forensic Readiness

Definition

The organisational state in which people, processes, and technology are prepared to collect and preserve digital evidence with minimum disruption to business operations. Defined by Tan (2001) and referenced in ISO/IEC 27037 and the UK ACPO Good Practice Guide.

Coined by
Tan (2001)
Referenced in
ISO/IEC 27037 and the UK ACPO Good Practice Guide
Scope
People, process, and technology, not tools alone
Goal
Evidence collection with minimum disruption to operations

Common questions

What does a forensically ready organisation actually have in place?+

Typically it has defined logging policies that retain the right data for long enough, staff trained to preserve evidence rather than destroy it by rebooting or reimaging systems, a documented escalation path to investigators, and pre-agreed legal authority to collect evidence without delay.

Why does forensic readiness matter if an incident never happens?+

Without it, the first response to an incident is improvised: logs may already have rotated out, volatile memory is lost on shutdown, and chain of custody starts late. Readiness shifts the cost of preparation earlier, which is cheaper than reconstructing evidence after the fact.

Related terms

Breach Notification
The legal obligation to inform regulators and affected individuals when personal data is compromised in a security incident. Timelines and thresholds differ...
Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Dwell Time
The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
Incident Response (IR)
The organised methodology for handling and managing the aftermath of a security breach or cyberattack. IR encompasses preparation, detection, containment, eradication, recovery,...
ISO/IEC 27037
An international standard providing guidelines for the identification, collection, acquisition, and preservation of digital evidence. Published by ISO in 2012. Used by...
Jump Bag
A pre-packed kit containing the hardware and media required for immediate on-site forensic response: write-blockers, imaging drives, bootable USB, cables, evidence labels,...
Order of Volatility
The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
Pre-Positioned Agent
Lightweight endpoint software deployed across the organisation before any incident occurs. When an incident is declared, the IR team tasks agents remotely...
Proportionality
The legal principle, central to European human rights law and to many constitutional systems, that any interference with a fundamental right must...
Write Blocker
A hardware or software device interposed between a digital storage medium and the forensic workstation that prevents any write commands from reaching...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.