Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is digital forensics and incident response?

Updated

DFIR is digital forensics plus incident response: identify potential evidence, preserve it in a forensically sound way, analyze a working copy, and report what the evidence supports. It sits inside IR; it does not replace it. This page is not legal advice.

Operational guidance, last verified 7 September 2026 against NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), NIST SP 800-61r2, and the SANS Incident Handler's Handbook. Identify / preserve / analyze / report is a teaching sequence on this page; NIST SP 800-86 names collection, examination, analysis, and reporting. Forensic soundness and chain of custody are how you keep evidence usable. This page does not rank DFIR firms, does not start a notification clock, and is not a substitute for counsel, your insurer, or a retained DFIR firm. Not legal advice.

DFIR is a practice, not a vendor list

Audience: an engineering leader, founder, CTO, CISO, or incident commander who needs the term defined before the retain-or-not decision. The we've-been-breached page on this site is the first-moves hub. The who-to-call page on this site is the contact map. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. This page is the DFIR explainer: what the letters mean, the forensic sequence, forensic soundness, chain of custody, and how that work sits inside incident response. The when-you-need-dfir page on this site is the in-house-versus-firm decision tree. This page does not rank DFIR firms, does not name any, and is not a directory.

DFIR is a compound: digital forensics (how you identify, preserve, examine, analyze, and report digital evidence) plus incident response (how you detect, contain, eradicate, recover, and learn). NIST SP 800-86 is a guide to integrating forensic techniques into incident response — guidance, not a statute. NIST SP 800-61r2 is the Computer Security Incident Handling Guide this cluster cites — also guidance, not a statute. The SANS Incident Handler's Handbook is a practitioner checklist (PICERL: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned), not a standard. ISO/IEC 27037 is a standard of guidelines for identification, collection, acquisition, and preservation of digital evidence; it is not a law and this page does not reproduce it. Last verified 7 September 2026. Not legal advice.

  • Digital forensics is the application of science to potential evidence so another examiner can reconstruct what you did. Incident response is the operational lifecycle that uses those techniques when an incident is in play.
  • DFIR is not a fifth PICERL phase and not a replacement for NIST SP 800-61r2's four IR phases (preparation; detection and analysis; containment, eradication, and recovery; post-incident activity).
  • A DFIR firm is a retained role on the contact map, not a ranking, not a panel, and not YOUR engagement letter. The who-to-call page on this site is that map. The when-you-need-dfir page on this site is the in-house-versus-firm decision tree.
  • Counsel-directed DFIR is common practice so working papers can sit under attorney-client privilege and work-product. That is practice, not a ruling that privilege will attach. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
  • This page does not rank DFIR firms, does not interpret YOUR policy, does not start a notification clock, and is not legal advice.

Identify, preserve, analyze, report

This page teaches four verbs: identify, preserve, analyze, report. They are a teaching sequence, not a statute. NIST SP 800-86's forensic process is collection, examination, analysis, and reporting. ISO/IEC 27037's evidence-handling activities are identification, collection, acquisition, and preservation. The lists overlap; they are not the same list. Do not treat a teaching heading as a compliance checkbox. Last verified 7 September 2026. Not legal advice.

Teaching sequence mapped to NIST SP 800-86 (guidance — not a statute, not a ranking)
Teaching stepWhat you doNIST SP 800-86 nameWhat this page is not saying
IdentifyLocate potential evidence: hosts, memory, disk, logs (auth, cloud, network, endpoint), accounts, tickets, mail. Write down what you have not found. Unknowns belong on the list.Collection — identify possible sources of relevant data, then label, record, and acquire.Identifying a source is not a finding that an incident occurred, not a notification determination, and not permission to seize anything. Scope is the commander's call with counsel.
PreserveAcquire without altering originals when you can. Work from a working copy. Record chain of custody. Take volatile evidence first (memory before disk; live state before you power off). Do not reimage, rotate logs, or 'clean up'.Collection — acquire while following procedures that preserve integrity. NIST SP 800-61r2: acquire, preserve, secure, and document.Preservation is not containment by destruction. Isolate, don't wipe. The first-15-minutes page on this site is the do-not-power-down checklist. The preserve-evidence page on this site is the order-of-volatility checklist.
AnalyzeExamine the working copy (extract, filter, reconstruct), then analyze what the artifacts support and what they do not. Hash, tool versions, and methods go in the notes so another examiner can repeat the work.Examination, then analysis. NIST SP 800-86 keeps those as two steps: process the collected data, then draw legally justifiable conclusions from it.Analysis is not a legal conclusion, not a notification filing, and not a press statement. 'Access' is not 'exfiltration'. Counsel owns what you may say.
ReportWrite what the evidence supports, what it does not, the methods, the limitations, and who handled what. Need-to-know, on the out-of-band channel. CISA: do not tip the actor.Reporting — the final phase of the NIST SP 800-86 process. NIST SP 800-61r2 post-incident activity is where lessons learned and follow-up live.A forensic report is not a GDPR Article 33 notice, not a CRA Article 14 filing, and not insurer notice. Mapping those clocks is counsel's work. This page does not start one.

Forensic soundness

Forensic soundness is the property that your handling would let another trained examiner reconstruct what you did and trust that the original was not silently changed. NIST SP 800-86 treats it as a principle of the forensic process, not a certification mark and not a vendor feature. ISO/IEC 27037's preservation activity is the same idea in standard language. Neither source is a ruling that YOUR copy will be admitted in court. Not legal advice.

  • Do not alter original evidence if you can avoid it. Acquire a working copy and examine that. NIST SP 800-86: collection should preserve the integrity of the data.
  • If you must access the original (live memory, a cloud API with no snapshot, a host you cannot image), document how, why, who, and when. The gap is the record.
  • Use write-blocking on media you can write-block. Hash the original and the copy (MD5, SHA-1, or SHA-256 as YOUR procedure names) and record the values. A matching hash is an integrity check, not a legal conclusion.
  • Personnel should be trained for the method they are using. Untrained 'just copy the disk' is how originals get written.
  • Document tools, versions, command lines, and deviations. Another examiner should be able to repeat the work from the notes.
  • The SANS Incident Handler's Handbook is a practitioner checklist: do not power down a live system to 'preserve' it — volatile memory is gone when power is. That is handbook practice, not a statute.
  • Forensic soundness is guidance and method, not a guarantee of admissibility. Counsel tells you what YOUR forum requires. This page does not.

Chain of custody

Chain of custody is the chronological record of evidence: who collected it, when, where, how, why, who it was transferred to, and where it was stored. NIST SP 800-86 describes it as tracking movement through collection, safeguarding, and analysis by documenting each person who handled the evidence, the date and time of collection or transfer, and the purpose of the transfer. The chain is itself evidence. A broken chain is how a later examiner — or opposing counsel — cannot tell the copy in the report is the copy that was taken. Last verified 7 September 2026. Not legal advice.

  • Record at collection: what it is, unique ID, source system, UTC time, collector, method, hashes, where it now lives.
  • Record every transfer: from whom, to whom, when, why, and the receiving storage. A Slack 'fyi' is not a chain.
  • Limit handlers. NIST SP 800-61r2 wants designated people, not a blast. Wide distribution of the image is how the chain and privilege both fray.
  • Store so the working copy cannot be silently overwritten. Access logs on the evidence store are part of the chain.
  • The report should be able to point at the chain. If it cannot, the analysis is a story about a file whose origin you cannot show.
  • Chain of custody is a handling record, not a notification filing and not a ranking of forensic shops. This page does not rank DFIR firms.

How DFIR relates to incident response

Incident response is the program. Digital forensics is a set of techniques used inside that program. NIST SP 800-86 exists because organizations were treating forensics as a separate lab exercise; the guide's job is to put forensic techniques into each IR phase. DFIR as a label is the combined practice — people and retainers who do both. It is not a third framework. Last verified 7 September 2026.

Where forensic work sits in IR (NIST SP 800-61r2 phases — guidance, not a statute)
IR phase (NIST SP 800-61r2)What forensic work is doingLimit
PreparationCapability, procedures, trusted images of tools, logging that will actually exist, retainers and panel names on paper before you need them, out-of-band channels.A runbook is not a chain of custody. Naming a firm is not a ranking and not YOUR engagement. The when-you-need-dfir page on this site is the in-house-versus-firm decision tree.
Detection and analysisIdentify sources, preserve volatile and durable evidence, examine and analyze a working copy so containment decisions rest on artifacts, not a hunch.Detection is not a legal determination that a notifiable breach occurred. Analysis is not a press statement. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
Containment, eradication, and recoveryContain in a way that does not destroy the evidence you still need. Image before you reimage. Eradicate after identification, not instead of it. NIST SP 800-61r2 and SANS both put eradication after you know what you are eradicating.Isolation is not wiping. The we've-been-breached page on this site is the do-not-reimage warning. A dedicated 'what not to delete' guide is not on this site yet.
Post-incident activityReport what the evidence supported, lessons learned, follow-up actions, and the chain that shows how you got there. NIST SP 800-86 reporting is the forensic write-up; NIST SP 800-61r2 post-incident is the IR review.A forensic report is not a regulator filing. A post-incident review is not on this site yet. This page does not start a notification clock.

Glossary

Terms as this page uses them. Where a source names the idea, the kind of source is in the third column so a guidance document is not mistaken for a statute. Last verified 7 September 2026.

DFIR glossary (definitions for this page — not legal advice, not a ranking)
TermMeaning on this pageKind of source
DFIRDigital forensics and incident response as one practice: forensic techniques used inside an IR lifecycle. Also used for the retained firm that does that work. The letters are a label, not a standard.Practitioner usage. NIST SP 800-86 does not define the acronym; it defines integrating forensic techniques into IR.
Digital forensicsThe application of science to potential digital evidence: identify, collect, examine, analyze, report, with integrity and a reconstructable method.NIST SP 800-86 (guidance). ISO/IEC 27037 (standard of guidelines for identification, collection, acquisition, preservation).
Incident response (IR)The operational lifecycle for a computer-security incident: preparation; detection and analysis; containment, eradication, and recovery; post-incident activity.NIST SP 800-61r2 (guidance). SANS PICERL is a practitioner checklist covering the same ground with different phase names.
Forensic soundnessHandling that does not silently alter originals, is documented, and can be reconstructed by another examiner. Often: working copy, write-blocking, hashes, trained people.NIST SP 800-86 principle (guidance). Not a certification. Not a guarantee of admissibility.
Chain of custodyThe chronological record of who handled the evidence, when, where, how, why, and where it was stored, including transfers.NIST SP 800-86 (guidance). The record is itself evidence. This page does not draft YOUR form.
Working copyThe duplicate you examine so the original stays unchanged. Hashes of original and copy should match at acquisition.NIST SP 800-86 collection / examination (guidance).
Order of volatilityCapture the most perishable evidence first (registers and memory before disk; live state before power-off; logs before rotation).Practitioner method used with NIST SP 800-86 collection. RFC 3227 is the classic list; the preserve-evidence page on this site is that checklist.

Where this shows up in ShipReady Metrics

The signed-in app does not image hosts, keep a chain of custody, produce a forensic report, retain a DFIR firm, or file with a regulator. It does not rank forensic vendors. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

NIST SP 800-86 (August 2006), Guide to Integrating Forensic Techniques into Incident Response, is the current final guide this page cites for the forensic process (collection, examination, analysis, reporting), forensic principles including integrity and chain of custody, and how those techniques sit inside IR — guidance, not a statute, last verified still final on 7 September 2026. NIST SP 800-61 Revision 2 (August 2012) is the Computer Security Incident Handling Guide this cluster cites — guidance, not a statute; four IR phases; acquire, preserve, secure, and document. The SANS Incident Handler's Handbook (Patrick Kral) is a practitioner PICERL checklist, not a standard. ISO/IEC 27037 is a standard of guidelines for identification, collection, acquisition, and preservation of digital evidence; it is not reproduced here and is not a law. Identify / preserve / analyze / report is this page's teaching sequence, not a fourth source.

Frequently asked questions

What is DFIR?

Digital forensics and incident response: forensic techniques (identify, preserve, examine, analyze, report) used inside an IR lifecycle (NIST SP 800-61r2). NIST SP 800-86 is the guide for integrating those techniques into IR. DFIR is also used for the retained firm that does that work. This page does not rank firms. Not legal advice.

What does identify, preserve, analyze, report mean?

A teaching sequence on this page. Identify potential evidence; preserve it without altering originals (working copy, chain of custody, volatile first); analyze the working copy (NIST SP 800-86 splits this into examination then analysis); report what the evidence supports and does not. NIST SP 800-86's own names are collection, examination, analysis, and reporting. Not a statute.

What is forensic soundness?

Handling that does not silently change original evidence, is documented, and can be reconstructed by another examiner. NIST SP 800-86: preserve integrity during collection; use trained people; document. Typical methods: working copy, write-blocking, hashes. Soundness is guidance, not a guarantee of admissibility. Not legal advice.

What is chain of custody?

The chronological record of evidence: who collected it, when, where, how, why, who it was transferred to, and where it was stored. NIST SP 800-86 tracks movement through collection, safeguarding, and analysis. The chain is itself evidence. A Slack ping is not a chain. Not legal advice.

How does DFIR relate to incident response?

IR is the program (NIST SP 800-61r2; SANS PICERL). Digital forensics is a set of techniques used inside that program (NIST SP 800-86). DFIR is the combined practice, not a replacement for IR and not a fifth PICERL phase. The when-you-need-dfir page on this site is the in-house-versus-firm decision tree. Not legal advice.

Is this legal advice?

No. It is operational guidance distilled from NIST SP 800-86, NIST SP 800-61r2, and the SANS Incident Handler's Handbook, with ISO/IEC 27037 named as a standard of guidelines. Whether privilege attaches, whether a copy is admissible, whether a notification duty applies, and which firm to retain are questions for counsel on YOUR facts. This page does not rank DFIR firms and does not start a notification clock.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.