Skip to content
Skip to main content
First Response & Preservation Operational Explainer

How should an isolation decision be documented?

Document the risk, starting state, chosen control, observed effect and later handling.

“Device isolated” is too vague to explain what actually happened.

The record you want
Why we intervened → what was connected → what we changed → what actually happened afterwards.

Record the starting state

Note the routes that existed before intervention:

  • mobile;
  • Wi-Fi;
  • Ethernet;
  • Bluetooth;
  • VPN;
  • cables;
  • remote sessions; and
  • active synchronisation.

Record the reason

State the specific risk being addressed, for example:

  • remote wipe;
  • continuing fraud;
  • malware traffic;
  • hostile remote access; or
  • compromise spreading to another system.

Avoid generic language such as “for evidence preservation”.

Record the control and result

A useful timeline might be:

Isolation decision record
14:03 — Remote session observed14:05 — Decision: disable Wi-Fi14:06 — Wi-Fi disabled by DC Smith14:06 — Remote session ended14:07 — Bluetooth remains on

Also record:

  • decision-maker;
  • operator;
  • location;
  • advice received;
  • independent time reference;
  • uncertainty; and
  • any evidence lost as a result.

Maintain the record after the first action

Document:

  • charging;
  • movement;
  • storage;
  • transfer;
  • removal from containment; and
  • every later reconnection.

If complete isolation could not be verified, say so.

The practical point is: a defensible isolation record explains the decision and the effect, not just the label applied to the device.

Reference: FRP-059First Response & Preservation