1.5 Security Investigations

CISSP Domain 1 ยท 1.5

Security Investigations at a glance

Security incidents can lead to very different types of investigation. The purpose, authority, evidence requirements and potential consequences depend heavily on what kind of investigation is taking place.

A cybersecurity professional should therefore understand the context before collecting evidence, interviewing people or taking actions that could affect an investigation.

๐ŸŽฏ

Purpose

Understand why the investigation is being conducted.

What are we trying to establish?
โš–๏ธ

Authority

Understand who authorised the investigation and which rules apply.

Under whose authority?
๐Ÿ”

Evidence

Preserve information in a way appropriate to the investigation.

Can the evidence be trusted?

Why investigation type matters

Imagine that security monitoring identifies an employee downloading a large amount of confidential information.

That single event could lead to several very different investigations.

Administrative

Did the employee violate organisational policy?

Criminal

Was a criminal offence committed?

Civil

Did another party suffer loss and seek compensation or another remedy?

Regulatory

Did the organisation breach a regulatory obligation?

Industry Standard

Does an industry scheme require a particular form of investigation?

Important

The same security incident can trigger more than one investigation.

For example, a data breach could simultaneously result in an internal disciplinary investigation, a police investigation, regulatory scrutiny and civil litigation.

The five investigation types

TypePrimary purposeTypical authorityPossible outcome
AdministrativeInvestigate internal policy or employment mattersOrganisationDisciplinary or corrective action
CriminalDetermine whether criminal law was violatedLaw enforcement / criminal justice systemCriminal prosecution and sanctions
CivilResolve disputes between partiesCivil courts / legal processDamages, injunctions or other remedies
RegulatoryDetermine compliance with regulatory requirementsRegulator or supervisory authorityOrders, remediation, restrictions or penalties
Industry StandardDetermine compliance or cause under an industry schemeIndustry body / contractual frameworkRemediation, reporting or programme consequences
1 Administrative Investigations Internal organisational investigations

What is an administrative investigation?

An administrative investigation is typically conducted within an organisation to determine whether policies, procedures, employment obligations or internal rules have been violated.

These investigations may involve:

HR Security Management Legal Compliance Internal Audit

Common triggers

  • misuse of organisational systems;
  • violation of acceptable-use policies;
  • inappropriate access to confidential information;
  • employee misconduct;
  • policy violations;
  • unauthorised software installation;
  • abuse of privileged accounts;
  • suspected insider activity.

Possible outcomes

Depending on organisational policy and applicable employment law, outcomes might include:

No Action Training Warning Access Changes Disciplinary Action Termination Referral
Example

Security monitoring shows an administrator repeatedly accessing employee salary records even though those records are unrelated to their work.

The organisation investigates whether the administrator violated acceptable-use and access-control policies.

This begins as an administrative investigation.
Important distinction

An administrative investigation is not automatically a criminal investigation.

However, information discovered during the investigation could potentially lead to referral to law enforcement if suspected criminal activity is identified.

2 Criminal Investigations Potential violations of criminal law

What is a criminal investigation?

A criminal investigation seeks to determine whether conduct violating criminal law occurred and potentially identify the person or persons responsible.

Examples of activity that may result in a criminal investigation include:

Unauthorised System Access

Illegally accessing computer systems or accounts.

Fraud

Using systems or information dishonestly for financial gain.

Data Theft

Stealing sensitive or proprietary information.

Ransomware

Extorting victims by disrupting systems or threatening disclosure.

Sabotage

Deliberately damaging systems, information or services.

Identity Crime

Misusing identity information for unlawful purposes.

Law enforcement involvement

Criminal investigations may involve law enforcement agencies, prosecutors, specialist cybercrime units and forensic investigators.

Legal processes may govern how evidence can be obtained, searched, seized or disclosed.

Evidence becomes especially important

Actions that alter or destroy relevant information may damage the organisation's ability to support a criminal investigation.

Standard of proof

Legal standards depend on jurisdiction.

As a useful example, in the United States a criminal conviction requires proof beyond a reasonable doubt, which is a higher standard than generally applies in ordinary civil cases.

Example

An attacker compromises an organisation and steals millions of customer records.

Investigators identify evidence suggesting that a specific individual conducted the intrusion.

The matter may become a criminal investigation handled in cooperation with law enforcement.
CISSP mindset

If criminal activity is suspected, security professionals should follow established organisational procedures and involve appropriate legal and law-enforcement expertise rather than improvising a private criminal investigation.

3 Civil Investigations Disputes, liability and compensation

What is a civil matter?

Civil proceedings generally concern disputes between parties rather than the state prosecuting someone for a criminal offence.

Cybersecurity-related civil disputes might involve:

Data Breaches Contract Disputes Negligence Intellectual Property Privacy Business Loss

Possible outcomes

Civil proceedings may seek remedies such as:

Damages

Financial compensation for loss or harm.

Injunction

A court order requiring or preventing particular actions.

Contractual Remedy

Enforcement of obligations arising from a contract.

Settlement

The parties may resolve the dispute without completing a trial.

Standard of proof

Standards differ between jurisdictions and types of proceeding.

As a US example, ordinary civil cases generally use the preponderance of the evidence standard โ€” essentially whether the claim is more likely than not to be true.

Example

A supplier suffers a major security breach and a customer claims that the supplier failed to implement security controls required under their contract.

The customer seeks compensation for resulting financial losses.

This may lead to civil litigation.

Criminal vs Civil memory aid

Criminal Was a CRIME committed?
Civil Was another party HARMED?
Criminal Potential punishment
Civil Potential remedy or compensation

Crime โ†’ Punishment | Harm โ†’ Remedy

4 Regulatory Investigations Was a regulatory obligation breached?

What is a regulatory investigation?

Regulatory investigations are conducted by, or under the authority of, bodies responsible for supervising compliance with particular legal or regulatory requirements.

They may examine whether an organisation:

  • protected information appropriately;
  • complied with required security controls;
  • reported an incident appropriately;
  • maintained appropriate governance;
  • managed risk adequately;
  • met sector-specific obligations;
  • provided accurate information to regulators.

Regulators may have investigative powers

Depending on the applicable legal framework, regulatory authorities may have powers to request information, require records, conduct enquiries or compel cooperation.

Example

A financial organisation suffers a serious cyber incident that causes prolonged disruption to customer services.

Its sector regulator investigates whether the organisation complied with applicable operational-resilience and security requirements.

This is a regulatory investigation.

Potential consequences

Remediation Enforcement Action Restrictions Monitoring Orders Financial Penalties
Regulatory โ‰  Criminal

Regulatory and criminal investigations are different processes, although the same conduct may sometimes create both regulatory and criminal concerns.

5 Industry-Standard Investigations Requirements created by industry programmes and standards

Not every investigation comes directly from government

Organisations may participate in industry schemes or contractual frameworks that establish specific investigation requirements.

These requirements may define:

  • who may conduct the investigation;
  • what qualifications investigators require;
  • how evidence should be preserved;
  • who must receive reports;
  • what investigation methodology should be followed;
  • which stakeholders must be involved.

PCI Forensic Investigator example

The payment-card industry provides a useful example.

If a cardholder-data compromise occurs or is suspected, payment organisations may require an investigation by a qualified PCI Forensic Investigator (PFI).

PFIs specialise in investigating payment-card compromises and work under requirements established by the PCI Security Standards Council programme.

Example

A retailer discovers evidence that payment-card information may have been stolen from its environment.

Its payment relationships require an independent PFI investigation.

This is an example of an industry-driven investigation requirement.
Key CISSP point

Industry requirements may still be mandatory for an organisation even though they are not themselves criminal law.

๐Ÿ”€ One incident, multiple investigations Investigation types can overlap

Real incidents frequently trigger several investigative processes at once.

Scenario: insider data theft

An employee downloads a confidential customer database and sells the information.

Administrative

The employer investigates violation of internal policies and employment obligations.

Criminal

Law enforcement investigates potential criminal offences.

Regulatory

A regulator may investigate whether the organisation protected the information adequately.

Civil

Affected individuals or business partners may seek remedies.

This changes how security teams should think

An incident responder may initially believe they are simply fixing a technical problem.

Their actions could later affect a disciplinary case, regulatory investigation, lawsuit or criminal prosecution.

๐Ÿ“ฆ Evidence Preservation Do not accidentally destroy what the investigation needs

Evidence can be fragile

Digital evidence can be altered very easily.

Simply opening a file, restarting a system or running a command may change:

Timestamps Logs Memory Temporary Files Processes Network Connections

Security teams therefore need established procedures for preserving information that may become evidence.

Bad response

An administrator discovers malware on a server and immediately reformats the disk so that the service can be rebuilt.

The service may be restored, but potentially valuable evidence has been destroyed.
Better response

The organisation follows its incident and investigation procedures, preserves required evidence and coordinates containment and recovery with the appropriate investigation stakeholders.

Important

Evidence requirements should be considered before taking destructive remediation actions.

๐Ÿ”— Chain of Custody Documenting control of evidence

What is chain of custody?

Chain of custody documents the possession, handling and transfer of an item of evidence from the time it is collected through subsequent stages of the investigation.

Records should allow investigators to understand:

What?

What evidence was collected?

Who?

Who collected, possessed or accessed it?

When?

When was it collected or transferred?

Where?

Where was the evidence stored?

Why?

Why was it transferred or accessed?

How?

How was its integrity protected?

Memory aid

Chain of custody = the documented history of who had the evidence and what happened to it.

#๏ธโƒฃ Protecting Evidence Integrity Demonstrating that evidence has not been changed

Investigators need confidence that evidence has not been improperly modified after collection.

Controls may include:

Hashing

Cryptographic hashes can help demonstrate whether digital evidence has changed.

Controlled Access

Limit who can access evidence.

Secure Storage

Protect evidence from accidental or deliberate modification.

Documentation

Record collection, handling and transfers.

Example

Investigators acquire a forensic image of a storage device and calculate a cryptographic hash.

The hash can later be compared to confirm whether the evidence has changed.

โ›” Legal Hold and Preservation Normal deletion processes may need to stop

What is a legal hold?

When litigation or another legal process requires relevant information to be preserved, an organisation may need to suspend normal deletion or destruction processes for that information.

This is commonly referred to as a legal hold or litigation hold.

Example

An organisation normally deletes email logs after 90 days.

A legal dispute begins and those logs may contain relevant evidence.

The normal deletion schedule may need to be suspended for the information covered by the legal hold.
Governance matters

Security teams should not independently decide what must legally be preserved.

Legal counsel and established organisational processes should define the preservation requirements.

๐Ÿ’ป eDiscovery Electronic information in legal proceedings

Modern organisations hold enormous amounts of electronically stored information.

During litigation, potentially relevant electronic information may need to be identified, preserved, collected and produced.

Examples might include:

Email Documents Chat Messages Logs Database Records Cloud Data Backups
Security connection

Good asset inventories, logging, retention policies and data governance make it much easier to locate relevant information when an investigation or legal process occurs.

๐Ÿ” Privacy during investigations Authority does not mean unlimited access

Investigations may require access to sensitive information.

Investigators may encounter:

Employee Communications Customer Data Authentication Records Location Information Financial Records Personal Files

Access should remain appropriate to the purpose and authority of the investigation.

Example

An investigator is authorised to examine an employee laptop for evidence of malware.

During analysis they discover unrelated private information.

Investigative access should not automatically be treated as permission to examine or distribute unrelated personal information.
Remember

Investigations should respect applicable privacy, employment, legal and organisational requirements.

๐Ÿšจ Incident Response vs Investigation Restore service without destroying evidence

Incident response and investigation often occur at the same time, but their immediate priorities can differ.

Incident Response

Focuses on containing the incident, reducing harm and restoring normal operations.

Investigation

Focuses on understanding what happened, establishing facts and preserving relevant evidence.

The conflict

Operations wants a compromised server rebuilt immediately.

Investigators need information from the server before it is changed.

The answer is coordination

Investigation, incident response, legal, business and technical teams may need to coordinate so that evidence is preserved while risk is contained and services are recovered.

๐Ÿงฐ Forensic Readiness Prepare before an investigation happens

Organisations should prepare for investigations before an incident occurs.

Useful capabilities include:

Logging

Ensure important events are recorded.

Time Synchronisation

Consistent timestamps help reconstruct events.

Retention

Keep relevant logs and records for appropriate periods.

Procedures

Define how evidence should be collected and preserved.

Roles

Know who needs to become involved.

Tools

Ensure appropriate investigation and forensic capabilities exist.

Training

Staff should understand how to respond without destroying evidence.

Legal Coordination

Establish routes for obtaining legal advice quickly.

Why preparation matters

A six-month investigation cannot reconstruct events if the organisation automatically deletes all useful security logs after seven days.

๐Ÿ“ Documentation and Reporting Investigations must be reproducible and understandable

Investigation records should clearly document what occurred during the investigative process.

Depending on the investigation, documentation may include:

Timeline Evidence Actions Taken People Involved Findings Decisions Conclusions
Stick to facts

Investigators should distinguish observed facts from assumptions, hypotheses and conclusions.

Weak statement

"The employee definitely stole the customer database."

More defensible statement

"Logs show the employee's account downloaded the database at 14:32. Additional investigation is required to determine who was operating the account and why the download occurred."

๐Ÿ“ฃ Escalation and specialist involvement Know when the investigation has moved beyond security

Security teams should have defined escalation paths.

Depending on the situation, an investigation may require involvement from:

Legal HR Compliance Privacy Internal Audit Senior Management Law Enforcement Regulators External Forensics
Example

An analyst begins investigating suspicious administrator activity.

Evidence emerges suggesting that a senior employee may have committed fraud.

The investigation should be escalated through appropriate organisational channels rather than being quietly pursued by the analyst alone.
โš ๏ธ Common mistakes Investigation concepts that are easy to get wrong
"Every security incident is a criminal investigation."

Many incidents remain internal administrative matters or lead to regulatory, civil or industry investigations instead.

"Fix the compromised machine first."

Immediate remediation may destroy evidence. Containment, evidence requirements and business impact need to be coordinated.

"The security team should decide whether someone is guilty."

Security professionals establish technical facts and support investigations. Final disciplinary, legal or criminal decisions belong to the appropriate authority.

"Administrative means informal."

Internal investigations can still have serious consequences and should follow appropriate organisational and legal procedures.

"Chain of custody only matters in criminal investigations."

Reliable evidence handling can also be important in civil, regulatory, administrative and industry investigations.

"If the employee uses a company device, investigators can examine anything on it."

Investigative authority and privacy expectations depend on policy, law, jurisdiction and the purpose of the investigation.

"An internal investigation can never become a criminal matter."

Evidence discovered internally may result in escalation to law enforcement.

"Compliance investigations and criminal investigations are the same."

Regulatory and industry investigations generally have different purposes, authorities and consequences from criminal prosecution.

CISSP Exam Perspective

First identify what kind of investigation is occurring

CISSP questions may describe an investigation without explicitly naming its type.

Look at who is conducting it, why it is happening and what outcome is being sought.

๐Ÿข Administrative clues

Employee HR Policy Misconduct Discipline

๐Ÿš” Criminal clues

Police Crime Prosecution Criminal Law Offence

โš–๏ธ Civil clues

Lawsuit Damages Plaintiff Contract Compensation

๐Ÿ›๏ธ Regulatory clues

Regulator Compliance Enforcement Supervision Penalty

๐Ÿญ Industry clues

PCI Industry Body PFI Standard Programme

๐Ÿ” Evidence clues

Preserve Document Integrity Custody Authorisation
๐Ÿ“ Practice scenarios Identify the investigation type

Scenario 1

HR asks security to determine whether an employee deliberately accessed confidential salary information in violation of company policy.

Primary investigation type:

Administrative.

Scenario 2

Police request preserved logs after identifying an organisation's server as part of a ransomware investigation.

Primary investigation type:

Criminal.

Scenario 3

A customer sues a supplier after a security incident allegedly caused significant financial losses.

Primary investigation type:

Civil.

Scenario 4

A financial supervisory authority requests evidence concerning how an organisation managed a serious cybersecurity incident.

Primary investigation type:

Regulatory.

Scenario 5

Following suspected payment-card theft, a merchant is required to engage a PCI Forensic Investigator.

Primary investigation type:

Industry-standard investigation.

Scenario 6

An incident responder discovers malware and wants to immediately reinstall the operating system.

Management says that law enforcement may become involved.

What should happen first?

Follow established incident and investigation procedures and consider evidence preservation before performing destructive remediation.

Scenario 7

An investigation begins as an internal employee misconduct case. Investigators later discover evidence suggesting large-scale fraud.

What should happen?

Escalate through appropriate legal and organisational channels because the matter may now require criminal investigation.

Scenario 8

A technician collected a laptop as evidence but cannot identify who handled the device during the following three days.

What control is weak?

Chain of custody.

Investigation thinking flow

Before acting, work through the context.

๐ŸŽฏ Purpose โ†’ Why are we investigating?
โš–๏ธ Authority โ†’ Who authorised it?
๐Ÿ“‹ Requirements โ†’ Which rules apply?
๐Ÿ” Evidence โ†’ What must be preserved?
๐Ÿ‘ฅ Stakeholders โ†’ Who needs to be involved?
๐Ÿ“ Documentation โ†’ Can we demonstrate what happened?

Quick memory aid

Administrative Did someone break COMPANY rules?
Criminal Was a CRIME committed?
Civil Was another party HARMED?
Regulatory Were REGULATORY rules broken?
Industry Were INDUSTRY requirements triggered?

Company. Crime. Harm. Regulator. Industry.

Evidence memory aid

Preserve Don't destroy it
Protect Don't alter it
Document Record what happened
Custody Know who handled it
Escalate Involve the right people

Preserve. Protect. Document.

Key takeaways

CISSP Domain 1.5 identifies five investigation types: administrative, criminal, civil, regulatory and industry standards.

Administrative investigations normally concern internal policy, employment or organisational matters.

Criminal investigations concern potential violations of criminal law and may involve law enforcement and prosecution.

Civil investigations relate to disputes where one party may seek compensation, an injunction or another remedy.

Regulatory investigations determine whether organisations have complied with applicable regulatory obligations.

Industry-standard investigations arise from requirements established by industry programmes or standards, such as payment-card forensic investigations.

A single cybersecurity incident can result in multiple investigation types at the same time.

Evidence should be preserved appropriately because remediation actions can accidentally alter or destroy information required for an investigation.

Chain of custody provides a documented history of who possessed and handled evidence.

Security professionals should document facts accurately, understand the limits of their authority and involve legal, HR, compliance, regulatory or law-enforcement specialists when appropriate.

Most importantly: before investigating, understand the purpose, authority and rules governing the investigation.

๐Ÿ“š Sources & Further Reading Authoritative references

Investigation and evidence requirements vary by jurisdiction. CyberPrepHub provides learning material rather than legal advice.