Who controls the affected system?¶
The organisation suffering the incident may not control every system or every useful record.
Cloud services, outsourced IT, security suppliers, identity providers and application vendors can split ownership, administration and evidence across several organisations.
If you send the request to the wrong place, you can lose time — and sometimes the evidence.
Map the control layers¶
For each important system, identify:
| Question | Example answer |
|---|---|
| Who owns or uses the service? | Northway Logistics |
| Who administers the tenant/account? | Northway IT |
| Who hosts the service? | Cloud provider |
| Who manages the endpoints? | Outsourced IT supplier |
| Who holds security telemetry? | MDR / EDR provider |
| Who can authorise collection? | System owner / incident lead |
| Who actually retains the source record? | Depends on the event |
That map tells you who to contact for each evidence source.
One provider may only hold part of the story¶
A security supplier may hold alerts and endpoint telemetry.
The application provider may hold the source audit log.
The customer organisation may hold identity and staff records.
The cloud provider may operate the infrastructure but not expose the customer-level event you need.
Control also matters for attribution¶
An administrator account appearing in a log does not automatically identify the administrator as the user.
The account may have been:
- shared;
- automated;
- compromised;
- used by a contractor;
- used through a management platform.
So identify who controlled the relevant session or process at the relevant time.
Get preservation to the right evidence holder quickly¶
If a cloud tenant owns the audit log, asking the infrastructure provider for the same record may simply result in a referral.
That can cost time.
Before sending an urgent request, work out who actually retains the data you need.
The practical point is: map ownership, administration and evidence retention separately. The affected organisation may be the victim without being the holder of every useful record.