Skip to content
Skip to main content
Cloud Services Operational Explainer

What should I record when collecting cloud records?

Create an acquisition record that lets another person identify the source, reproduce the selection where possible and distinguish the untouched material from later working copies. Saving an export without its collection context leaves important questions unanswered.

Describe the collection event

Record:

  • provider, product, tenant and account or resource identifiers;
  • collector, role, permissions and applicable authority or organisational process;
  • collection date, time and zone;
  • interface, API, administrator console, security platform or disclosure route;
  • query, filters, date range, event categories, pagination and export type; and
  • original filenames, archive structure, file counts and accompanying definitions.

Screenshots can preserve settings and the pre-collection display, but should supplement a structured export rather than replace it.

Separate originals, transformations and effects

Give each staged collection a clear reference and keep separate exports distinct. Preserve the source files before combining, converting or opening them in software that may alter dates, delimiters, encoding or long identifiers. Record every tool and transformation used to make the analysis copy.

Note any action that changed the live environment: opening a file, restoring a deleted item, generating a report or signing in may create new records. Mark those collection-generated events in the timeline.

Do not rewrite provider labels in the source copy. Interpretations and merged fields belong in a traceable working product linked back to the original event.

The point to remember

Record who collected what, from where and with which settings, preserving an untouched source and a traceable account of every transformation or live-system effect.

Reference: CLD-137Cloud Services