1.5 Security Investigations
Security Investigations at a glance
Security incidents can lead to very different types of investigation. The purpose, authority, evidence requirements and potential consequences depend heavily on what kind of investigation is taking place.
A cybersecurity professional should therefore understand the context before collecting evidence, interviewing people or taking actions that could affect an investigation.
Purpose
Understand why the investigation is being conducted.
What are we trying to establish?Authority
Understand who authorised the investigation and which rules apply.
Under whose authority?Evidence
Preserve information in a way appropriate to the investigation.
Can the evidence be trusted?Why investigation type matters
Imagine that security monitoring identifies an employee downloading a large amount of confidential information.
That single event could lead to several very different investigations.
Did the employee violate organisational policy?
Was a criminal offence committed?
Did another party suffer loss and seek compensation or another remedy?
Did the organisation breach a regulatory obligation?
Does an industry scheme require a particular form of investigation?
The same security incident can trigger more than one investigation.
For example, a data breach could simultaneously result in an internal disciplinary investigation, a police investigation, regulatory scrutiny and civil litigation.
The five investigation types
| Type | Primary purpose | Typical authority | Possible outcome |
|---|---|---|---|
| Administrative | Investigate internal policy or employment matters | Organisation | Disciplinary or corrective action |
| Criminal | Determine whether criminal law was violated | Law enforcement / criminal justice system | Criminal prosecution and sanctions |
| Civil | Resolve disputes between parties | Civil courts / legal process | Damages, injunctions or other remedies |
| Regulatory | Determine compliance with regulatory requirements | Regulator or supervisory authority | Orders, remediation, restrictions or penalties |
| Industry Standard | Determine compliance or cause under an industry scheme | Industry body / contractual framework | Remediation, reporting or programme consequences |
1 Administrative Investigations Internal organisational investigations
What is an administrative investigation?
An administrative investigation is typically conducted within an organisation to determine whether policies, procedures, employment obligations or internal rules have been violated.
These investigations may involve:
Common triggers
- misuse of organisational systems;
- violation of acceptable-use policies;
- inappropriate access to confidential information;
- employee misconduct;
- policy violations;
- unauthorised software installation;
- abuse of privileged accounts;
- suspected insider activity.
Possible outcomes
Depending on organisational policy and applicable employment law, outcomes might include:
Security monitoring shows an administrator repeatedly accessing employee salary records even though those records are unrelated to their work.
The organisation investigates whether the administrator violated acceptable-use and access-control policies.
This begins as an administrative investigation.An administrative investigation is not automatically a criminal investigation.
However, information discovered during the investigation could potentially lead to referral to law enforcement if suspected criminal activity is identified.
2 Criminal Investigations Potential violations of criminal law
What is a criminal investigation?
A criminal investigation seeks to determine whether conduct violating criminal law occurred and potentially identify the person or persons responsible.
Examples of activity that may result in a criminal investigation include:
Illegally accessing computer systems or accounts.
Using systems or information dishonestly for financial gain.
Stealing sensitive or proprietary information.
Extorting victims by disrupting systems or threatening disclosure.
Deliberately damaging systems, information or services.
Misusing identity information for unlawful purposes.
Law enforcement involvement
Criminal investigations may involve law enforcement agencies, prosecutors, specialist cybercrime units and forensic investigators.
Legal processes may govern how evidence can be obtained, searched, seized or disclosed.
Actions that alter or destroy relevant information may damage the organisation's ability to support a criminal investigation.
Standard of proof
Legal standards depend on jurisdiction.
As a useful example, in the United States a criminal conviction requires proof beyond a reasonable doubt, which is a higher standard than generally applies in ordinary civil cases.
An attacker compromises an organisation and steals millions of customer records.
Investigators identify evidence suggesting that a specific individual conducted the intrusion.
The matter may become a criminal investigation handled in cooperation with law enforcement.If criminal activity is suspected, security professionals should follow established organisational procedures and involve appropriate legal and law-enforcement expertise rather than improvising a private criminal investigation.
3 Civil Investigations Disputes, liability and compensation
What is a civil matter?
Civil proceedings generally concern disputes between parties rather than the state prosecuting someone for a criminal offence.
Cybersecurity-related civil disputes might involve:
Possible outcomes
Civil proceedings may seek remedies such as:
Financial compensation for loss or harm.
A court order requiring or preventing particular actions.
Enforcement of obligations arising from a contract.
The parties may resolve the dispute without completing a trial.
Standard of proof
Standards differ between jurisdictions and types of proceeding.
As a US example, ordinary civil cases generally use the preponderance of the evidence standard โ essentially whether the claim is more likely than not to be true.
A supplier suffers a major security breach and a customer claims that the supplier failed to implement security controls required under their contract.
The customer seeks compensation for resulting financial losses.
This may lead to civil litigation.Criminal vs Civil memory aid
Crime โ Punishment | Harm โ Remedy
4 Regulatory Investigations Was a regulatory obligation breached?
What is a regulatory investigation?
Regulatory investigations are conducted by, or under the authority of, bodies responsible for supervising compliance with particular legal or regulatory requirements.
They may examine whether an organisation:
- protected information appropriately;
- complied with required security controls;
- reported an incident appropriately;
- maintained appropriate governance;
- managed risk adequately;
- met sector-specific obligations;
- provided accurate information to regulators.
Regulators may have investigative powers
Depending on the applicable legal framework, regulatory authorities may have powers to request information, require records, conduct enquiries or compel cooperation.
A financial organisation suffers a serious cyber incident that causes prolonged disruption to customer services.
Its sector regulator investigates whether the organisation complied with applicable operational-resilience and security requirements.
This is a regulatory investigation.Potential consequences
Regulatory and criminal investigations are different processes, although the same conduct may sometimes create both regulatory and criminal concerns.
5 Industry-Standard Investigations Requirements created by industry programmes and standards
Not every investigation comes directly from government
Organisations may participate in industry schemes or contractual frameworks that establish specific investigation requirements.
These requirements may define:
- who may conduct the investigation;
- what qualifications investigators require;
- how evidence should be preserved;
- who must receive reports;
- what investigation methodology should be followed;
- which stakeholders must be involved.
PCI Forensic Investigator example
The payment-card industry provides a useful example.
If a cardholder-data compromise occurs or is suspected, payment organisations may require an investigation by a qualified PCI Forensic Investigator (PFI).
PFIs specialise in investigating payment-card compromises and work under requirements established by the PCI Security Standards Council programme.
A retailer discovers evidence that payment-card information may have been stolen from its environment.
Its payment relationships require an independent PFI investigation.
This is an example of an industry-driven investigation requirement.Industry requirements may still be mandatory for an organisation even though they are not themselves criminal law.
๐ One incident, multiple investigations Investigation types can overlap
Real incidents frequently trigger several investigative processes at once.
Scenario: insider data theft
An employee downloads a confidential customer database and sells the information.
The employer investigates violation of internal policies and employment obligations.
Law enforcement investigates potential criminal offences.
A regulator may investigate whether the organisation protected the information adequately.
Affected individuals or business partners may seek remedies.
An incident responder may initially believe they are simply fixing a technical problem.
Their actions could later affect a disciplinary case, regulatory investigation, lawsuit or criminal prosecution.
๐ฆ Evidence Preservation Do not accidentally destroy what the investigation needs
Evidence can be fragile
Digital evidence can be altered very easily.
Simply opening a file, restarting a system or running a command may change:
Security teams therefore need established procedures for preserving information that may become evidence.
An administrator discovers malware on a server and immediately reformats the disk so that the service can be rebuilt.
The service may be restored, but potentially valuable evidence has been destroyed.The organisation follows its incident and investigation procedures, preserves required evidence and coordinates containment and recovery with the appropriate investigation stakeholders.
Evidence requirements should be considered before taking destructive remediation actions.
๐ Chain of Custody Documenting control of evidence
What is chain of custody?
Chain of custody documents the possession, handling and transfer of an item of evidence from the time it is collected through subsequent stages of the investigation.
Records should allow investigators to understand:
What evidence was collected?
Who collected, possessed or accessed it?
When was it collected or transferred?
Where was the evidence stored?
Why was it transferred or accessed?
How was its integrity protected?
Chain of custody = the documented history of who had the evidence and what happened to it.
#๏ธโฃ Protecting Evidence Integrity Demonstrating that evidence has not been changed
Investigators need confidence that evidence has not been improperly modified after collection.
Controls may include:
Cryptographic hashes can help demonstrate whether digital evidence has changed.
Limit who can access evidence.
Protect evidence from accidental or deliberate modification.
Record collection, handling and transfers.
Investigators acquire a forensic image of a storage device and calculate a cryptographic hash.
The hash can later be compared to confirm whether the evidence has changed.
โ Legal Hold and Preservation Normal deletion processes may need to stop
What is a legal hold?
When litigation or another legal process requires relevant information to be preserved, an organisation may need to suspend normal deletion or destruction processes for that information.
This is commonly referred to as a legal hold or litigation hold.
An organisation normally deletes email logs after 90 days.
A legal dispute begins and those logs may contain relevant evidence.
The normal deletion schedule may need to be suspended for the information covered by the legal hold.Security teams should not independently decide what must legally be preserved.
Legal counsel and established organisational processes should define the preservation requirements.
๐ป eDiscovery Electronic information in legal proceedings
Modern organisations hold enormous amounts of electronically stored information.
During litigation, potentially relevant electronic information may need to be identified, preserved, collected and produced.
Examples might include:
Good asset inventories, logging, retention policies and data governance make it much easier to locate relevant information when an investigation or legal process occurs.
๐ Privacy during investigations Authority does not mean unlimited access
Investigations may require access to sensitive information.
Investigators may encounter:
Access should remain appropriate to the purpose and authority of the investigation.
An investigator is authorised to examine an employee laptop for evidence of malware.
During analysis they discover unrelated private information.
Investigative access should not automatically be treated as permission to examine or distribute unrelated personal information.Investigations should respect applicable privacy, employment, legal and organisational requirements.
๐จ Incident Response vs Investigation Restore service without destroying evidence
Incident response and investigation often occur at the same time, but their immediate priorities can differ.
Focuses on containing the incident, reducing harm and restoring normal operations.
Focuses on understanding what happened, establishing facts and preserving relevant evidence.
The conflict
Operations wants a compromised server rebuilt immediately.
Investigators need information from the server before it is changed.
Investigation, incident response, legal, business and technical teams may need to coordinate so that evidence is preserved while risk is contained and services are recovered.
๐งฐ Forensic Readiness Prepare before an investigation happens
Organisations should prepare for investigations before an incident occurs.
Useful capabilities include:
Ensure important events are recorded.
Consistent timestamps help reconstruct events.
Keep relevant logs and records for appropriate periods.
Define how evidence should be collected and preserved.
Know who needs to become involved.
Ensure appropriate investigation and forensic capabilities exist.
Staff should understand how to respond without destroying evidence.
Establish routes for obtaining legal advice quickly.
A six-month investigation cannot reconstruct events if the organisation automatically deletes all useful security logs after seven days.
๐ Documentation and Reporting Investigations must be reproducible and understandable
Investigation records should clearly document what occurred during the investigative process.
Depending on the investigation, documentation may include:
Investigators should distinguish observed facts from assumptions, hypotheses and conclusions.
"The employee definitely stole the customer database."
"Logs show the employee's account downloaded the database at 14:32. Additional investigation is required to determine who was operating the account and why the download occurred."
๐ฃ Escalation and specialist involvement Know when the investigation has moved beyond security
Security teams should have defined escalation paths.
Depending on the situation, an investigation may require involvement from:
An analyst begins investigating suspicious administrator activity.
Evidence emerges suggesting that a senior employee may have committed fraud.
The investigation should be escalated through appropriate organisational channels rather than being quietly pursued by the analyst alone.โ ๏ธ Common mistakes Investigation concepts that are easy to get wrong
Many incidents remain internal administrative matters or lead to regulatory, civil or industry investigations instead.
Immediate remediation may destroy evidence. Containment, evidence requirements and business impact need to be coordinated.
Security professionals establish technical facts and support investigations. Final disciplinary, legal or criminal decisions belong to the appropriate authority.
Internal investigations can still have serious consequences and should follow appropriate organisational and legal procedures.
Reliable evidence handling can also be important in civil, regulatory, administrative and industry investigations.
Investigative authority and privacy expectations depend on policy, law, jurisdiction and the purpose of the investigation.
Evidence discovered internally may result in escalation to law enforcement.
Regulatory and industry investigations generally have different purposes, authorities and consequences from criminal prosecution.
First identify what kind of investigation is occurring
CISSP questions may describe an investigation without explicitly naming its type.
Look at who is conducting it, why it is happening and what outcome is being sought.
๐ข Administrative clues
๐ Criminal clues
โ๏ธ Civil clues
๐๏ธ Regulatory clues
๐ญ Industry clues
๐ Evidence clues
๐ Practice scenarios Identify the investigation type
Scenario 1
HR asks security to determine whether an employee deliberately accessed confidential salary information in violation of company policy.
Primary investigation type:
Administrative.
Scenario 2
Police request preserved logs after identifying an organisation's server as part of a ransomware investigation.
Primary investigation type:
Criminal.
Scenario 3
A customer sues a supplier after a security incident allegedly caused significant financial losses.
Primary investigation type:
Civil.
Scenario 4
A financial supervisory authority requests evidence concerning how an organisation managed a serious cybersecurity incident.
Primary investigation type:
Regulatory.
Scenario 5
Following suspected payment-card theft, a merchant is required to engage a PCI Forensic Investigator.
Primary investigation type:
Industry-standard investigation.
Scenario 6
An incident responder discovers malware and wants to immediately reinstall the operating system.
Management says that law enforcement may become involved.
What should happen first?
Follow established incident and investigation procedures and consider evidence preservation before performing destructive remediation.
Scenario 7
An investigation begins as an internal employee misconduct case. Investigators later discover evidence suggesting large-scale fraud.
What should happen?
Escalate through appropriate legal and organisational channels because the matter may now require criminal investigation.
Scenario 8
A technician collected a laptop as evidence but cannot identify who handled the device during the following three days.
What control is weak?
Chain of custody.
Investigation thinking flow
Before acting, work through the context.
Quick memory aid
Company. Crime. Harm. Regulator. Industry.
Evidence memory aid
Preserve. Protect. Document.
Key takeaways
CISSP Domain 1.5 identifies five investigation types: administrative, criminal, civil, regulatory and industry standards.
Administrative investigations normally concern internal policy, employment or organisational matters.
Criminal investigations concern potential violations of criminal law and may involve law enforcement and prosecution.
Civil investigations relate to disputes where one party may seek compensation, an injunction or another remedy.
Regulatory investigations determine whether organisations have complied with applicable regulatory obligations.
Industry-standard investigations arise from requirements established by industry programmes or standards, such as payment-card forensic investigations.
A single cybersecurity incident can result in multiple investigation types at the same time.
Evidence should be preserved appropriately because remediation actions can accidentally alter or destroy information required for an investigation.
Chain of custody provides a documented history of who possessed and handled evidence.
Security professionals should document facts accurately, understand the limits of their authority and involve legal, HR, compliance, regulatory or law-enforcement specialists when appropriate.
Most importantly: before investigating, understand the purpose, authority and rules governing the investigation.
๐ Sources & Further Reading Authoritative references
Investigation and evidence requirements vary by jurisdiction. CyberPrepHub provides learning material rather than legal advice.
- ISC2 โ CISSP Certification Exam Outline
View official CISSP exam outline - United States Courts โ Criminal Cases
View US Courts guidance - United States Courts โ Civil Cases
View US Courts guidance - Federal Trade Commission โ Privacy & Security Enforcement
View regulatory enforcement examples - PCI Security Standards Council โ Responding to a Data Breach
View PCI investigation guidance
