712-50 Question 378
Single answerDevelop and manage an organizational digital forensic programA newly appointed CISO is formalizing an enterprise digital forensics program after several investigations were challenged by external counsel due to inconsistent evidence handling across regions. The organization operates in multiple countries, relies heavily on cloud services, and uses a mix of internal responders and outside forensic firms. The CISO's primary objective is to make investigative results defensible while preserving the ability to respond quickly to major incidents. Which action should the CISO prioritize FIRST when developing the program?
- A
Establish a governance framework that defines forensic authority, evidence handling standards, chain-of-custody requirements, legal/regulatory escalation paths, and approved procedures for internal and third-party investigators
- B
Purchase a single enterprise forensic toolset and require all regional teams and external firms to use it so that investigative outputs are technically consistent
- C
Centralize all forensic acquisitions and analysis within the headquarters security team to reduce variation in investigative practices
- D
Require incident responders to collect as much endpoint and cloud data as possible during every event so that evidence is available for later legal review
Show answer and explanation
Correct answer: A
Explanation
The best answer is to establish a governance framework first because a digital forensics program must be defensible, repeatable, and legally informed before it is scaled operationally. In practice, that means documented policy and standards for evidence identification, preservation, collection, transport, storage, analysis, reporting, and disposition; formal chain-of-custody procedures; role definitions; training and competency expectations; legal/regulatory escalation; and rules for engaging external forensic firms. This is especially important in multinational organizations where privacy laws, labor rules, breach notification requirements, and cross-border data transfer restrictions may affect what investigators can collect and how they can handle it.
Best-practice sources consistently emphasize process integrity over tool uniformity. NIST guidance on incident response and forensic integration highlights the need for policies, procedures, evidence handling, and documentation to maintain integrity and support legal or disciplinary action. ISO/IEC 27037 similarly focuses on identification, collection, acquisition, and preservation of digital evidence in a manner suitable for later use. A CISO developing the program should therefore begin with governance and legal alignment, then select tooling, operating models, and staffing approaches that support those standards.
- A. Correct.
Correct. For a defensible digital forensics program, the first priority is governance: clearly documented authority, roles, evidence handling procedures, chain of custody, legal hold and privacy considerations, standards for collection and preservation, and criteria for using third parties. This addresses the root cause of challenged investigations, process inconsistency, while still allowing decentralized execution under controlled standards. In a multinational environment, governance also ensures regional legal requirements, data transfer restrictions, and engagement with counsel are built into the program.
- B. Incorrect.
Incorrect. Standardizing tools can help consistency, but tool choice alone does not make evidence defensible. Courts, regulators, and opposing counsel generally focus on whether evidence was properly identified, preserved, documented, and handled by authorized personnel using repeatable procedures. Different cases may also require different tools, especially in cloud and mobile environments. This option reflects the common misconception that technical uniformity can substitute for governance and process control.
- C. Incorrect.
Incorrect. Centralization may reduce some variability, but it is not the best first step and may slow response, create bottlenecks, and be impractical across jurisdictions and time zones. In many organizations, especially global ones, a federated operating model is necessary. What matters most is that all parties operate under consistent policy, evidence handling standards, and legal oversight. Centralization without governance can still produce challenged evidence if procedures are unclear or legal requirements are overlooked.
- D. Incorrect.
Incorrect. Collecting excessive data by default can create legal, privacy, cost, and proportionality problems, particularly in cross-border and cloud investigations. A mature forensic program should define what to collect, when, by whom, and under what authority, with attention to data minimization and relevance. Overcollection can actually increase risk if personal data, privileged information, or regulated records are gathered unnecessarily.