Episode 13 — Preserve Evidence Correctly: Chain of Custody, Logging, and Forensics Readiness episode artwork

EPISODE · Feb 10, 2026 · 16 MIN

Episode 13 — Preserve Evidence Correctly: Chain of Custody, Logging, and Forensics Readiness

from Certified: The GIAC GSLC Audio Course · host Jason Edwards

This episode focuses on preserving evidence so investigations remain credible and actionable, a key exam theme that connects incident response, monitoring, and governance. You will define chain of custody as the documented control of evidence from collection through analysis and storage, then learn what “forensics readiness” looks like before an incident occurs, including centralized logging, time synchronization, and access controls that protect integrity. We discuss how to identify high-value evidence sources across endpoints, servers, identity providers, cloud services, and network infrastructure, and how to capture volatile data early without contaminating artifacts. You will also learn troubleshooting considerations such as recognizing log gaps, handling overwritten data, managing privileged access during investigations, and ensuring investigative activity is traceable and separable from routine administration. A realistic scenario ties it together by showing how an organization can lose the ability to prove what happened when evidence handling is informal, and how disciplined procedures preserve clarity even under pressure. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

NOW PLAYING

Episode 13 — Preserve Evidence Correctly: Chain of Custody, Logging, and Forensics Readiness

0:00 16:07

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Certified: The GIAC GSLC Audio Course?

This episode is 16 minutes long.

When was this Certified: The GIAC GSLC Audio Course episode published?

This episode was published on February 10, 2026.

What is this episode about?

This episode focuses on preserving evidence so investigations remain credible and actionable, a key exam theme that connects incident response, monitoring, and governance. You will define chain of custody as the documented control of evidence from...

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Certified: The GIAC GSLC Audio Course episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!