How should an isolation decision be documented?¶
Document the risk, starting state, chosen control, observed effect and later handling.
“Device isolated” is too vague to explain what actually happened.
Record the starting state¶
Note the routes that existed before intervention:
- mobile;
- Wi-Fi;
- Ethernet;
- Bluetooth;
- VPN;
- cables;
- remote sessions; and
- active synchronisation.
Record the reason¶
State the specific risk being addressed, for example:
- remote wipe;
- continuing fraud;
- malware traffic;
- hostile remote access; or
- compromise spreading to another system.
Avoid generic language such as “for evidence preservation”.
Record the control and result¶
A useful timeline might be:
Also record:
- decision-maker;
- operator;
- location;
- advice received;
- independent time reference;
- uncertainty; and
- any evidence lost as a result.
Maintain the record after the first action¶
Document:
- charging;
- movement;
- storage;
- transfer;
- removal from containment; and
- every later reconnection.
If complete isolation could not be verified, say so.
The practical point is: a defensible isolation record explains the decision and the effect, not just the label applied to the device.