How should preservation requests be prioritised?¶
Prioritise records by how quickly they may disappear, how central they are to sequence or attribution, and whether another source could reconstruct them. Unique, short-lived records should normally be preserved before durable or duplicated material.
Preservation prevents loss while the appropriate disclosure process is considered; it does not itself provide the records.
Rank volatility, value and replaceability¶
High-priority material may include short-retention authentication and cloud audit events, active-session data, dynamic address assignments, temporary account or object metadata, provider abuse records and deletion history.
For each proposed source, establish:
- the provider and product holding it;
- known or likely retention period;
- exact identifiers and time range required;
- relevance to the investigative question;
- whether containment may rotate or delete it; and
- whether equivalent evidence survives elsewhere.
A local copy of a file may be recoverable from several systems, while one provider session record or dynamic address allocation may be unique. That difference should influence priority.
Keep the plan responsive¶
Do not wait for every question to be resolved before preserving an identified volatile source. Equally, avoid imprecise requests that cannot be mapped to a stable account, object or event.
Review priorities as new accounts, wallets, services and infrastructure emerge. The initial list reflects what was known at one time and should not become a fixed boundary when later evidence changes the risk of loss.
Key takeaway
Preserve short-lived, unique and decision-critical provider records first, using precise identifiers, and update the priority as the incident and available evidence develop.