Regulated data, incidents, and the chain of custody you may have to keep

Objective 4.1 · Operational procedures · 21% of the exam

Why this matters

This is the lesson where a technician's instinct to help is the wrong instinct. Everywhere else in this course, finding something unexpected means investigating it. Here, finding certain things means stopping — immediately, before looking further — and telling someone.

It is also the lesson with no hands-on lab, because every realistic exercise would involve handling regulated data or prohibited content, and the first rule of the objective is not to. The applied lab produces a written custody record for a stated scenario instead, which is the artefact a technician is actually asked to produce, and the one that decides whether anything found can be used.

The lesson

The data classes a technician meets: personal, health, financial, card and government

Technicians encounter regulated data constantly, usually without being told. Knowing the categories is how you recognise that a routine job has become a regulated one.

  • Personal data — anything identifying a living person: name, address, email, device identifiers, location. The broadest category and the one governing most day-to-day work. Under data-protection regimes it carries obligations about what it may be used for and how long it is kept.
  • Sensitive personal data — health, biometrics, ethnicity, religion, sexual orientation, trade union membership. A stricter subset, with a higher bar and worse consequences.
  • Health information, which in several jurisdictions has its own regime with specific breach reporting duties.
  • Financial data — bank details, transaction records.
  • Payment card data, governed by card industry rules rather than by law. The practical rule for a technician is that full card numbers should not be stored, and finding them stored in a spreadsheet is a finding.
  • Government-issued identifiers — passport, national insurance or social security numbers, driving licence — which are the raw material of identity theft.

What follows for a technician: treat any machine that might hold these as carrying regulated data. Do not copy data off "to be safe" without authorisation. Do not use production data for testing. Do not email it to yourself. And a disposal or repair that involves storage holding any of this is not a routine disposal — it is the sanitisation problem the environmental lesson covers.

Licensing, end-user agreements and personal use of corporate software

Licensing is the part of this objective that feels least like security and is the most likely to come up in an ordinary week.

The licence types, briefly, because the earlier editions lesson covered the Windows-specific versions: retail is transferable and belongs to a person; OEM belongs to the hardware; volume belongs to the organisation under an agreement; subscription lapses. Additionally open source licences grant broad rights with conditions attached, and those conditions are real obligations rather than a formality.

The end-user licence agreement is a contract. Nobody reads it and it still binds. The clauses that matter to a technician are the ones about how many devices, whether commercial use is permitted, and whether it may be transferred.

Personal use of corporate software is where technicians get into trouble. Installing the organisation's licensed software on a personal machine, or a user's personal licence on a work machine, is a licence breach in both directions. So is reusing an OEM licence from a decommissioned machine.

Personal licences on work machines raise the reverse problem: the organisation is now relying on software it does not own and cannot support.

The practical positions:

  • Install only what the organisation has a licence for, and check rather than assume.
  • If a user asks you to install something they bought personally, the answer is to ask whoever owns the policy, not to decide.
  • Record licences in the asset record, because an audit is a question about records rather than about machines.
  • Personal-use restrictions on free software are real: "free for personal use" on a business machine is a licence breach that costs money when noticed.

Prohibited content, and the first rule: stop and report rather than investigate

This is the shortest rule in the course and the most important one in this lesson.

If you find material that appears to be illegal — stop. Do not look further. Do not copy it. Do not delete it. Report it through the defined route, and write down what you saw and when.

The categories: material depicting the abuse of children, and anything else whose possession is itself an offence in the jurisdiction you are in.

Why "do not investigate" is the rule:

  • Continuing to look may itself be an offence, and your reasons will not change that.
  • Copying it creates another copy, in your possession.
  • Deleting it destroys evidence, and may be an offence.
  • Opening files changes timestamps, which damages the evidential record.
  • You are not the person who determines what it is. That judgement belongs to people with the training and the authority.

What to do instead:

  1. Stop work on the machine immediately.
  2. Leave it as it is. Do not power it down or up beyond what has already happened.
  3. Secure it physically so nobody else uses it.
  4. Report it to whoever the organisation says — a manager, a security officer, a legal contact — immediately and in person or by phone as well as in writing.
  5. Write down what you saw, the file path if you know it, the time, and what you did. Facts only.
  6. Tell nobody else. Discussing it with colleagues damages any investigation and may harm someone who turns out to be uninvolved.

The same posture applies in weaker form to other prohibited content — material breaching policy, stolen data, evidence of fraud. Stop, preserve, report.

Chain of custody: what it is, who starts it, and what breaking it costs

Chain of custody is the documented history of an item of evidence: who had it, when, and what they did with it. Its purpose is to let someone demonstrate that what is being examined is what was found, unaltered.

What it records, for every transfer:

  • What the item is, identified specifically — make, model, serial number, asset tag.
  • Where and when it was found, and by whom.
  • Every person who has had it since, with dates and times.
  • Every action taken on it.
  • Where it is stored between those events.

Who starts it: the person who finds the item. That is the part people get wrong. It is not begun later by an investigator; it begins at the moment of discovery, and a support technician is very often that person. A gap at the beginning cannot be filled in afterwards.

What breaking it costs: evidence that cannot be relied on. If nobody can show where a machine was for two days, its contents can be challenged as having been altered, and the whole matter may fail on that alone — regardless of what is on the disk. A dismissal, a prosecution or an insurance claim can turn on it.

In practice, for a technician:

  • Use a form or a notebook — anything contemporaneous and in ink.
  • Seal the item in a tamper-evident bag if one is available, and sign across the seal.
  • Lock it away and record where.
  • Hand it over in person and record the handover, with both names.
  • Never leave a gap. "It was in my car overnight" recorded honestly is far better than a missing day.

Preserving evidence on a machine you have been asked to fix

The common case is not a dramatic discovery. It is an ordinary repair on a machine that turns out to matter, and the question is what to do differently once you realise.

The moment it changes: you find something suggesting misconduct, a compromise involving someone else's data, or anything that may be investigated. From that moment, the machine is potentially evidence and your job changes from fixing it to preserving it.

What preserving means:

  • Stop making changes. No cleaning, no reinstalling, no deleting, no defragmenting, no "tidying up".
  • Do not power it off if it is on, and do not power it on if it is off, without asking. Memory contents are lost on shutdown and may matter; booting changes hundreds of files and timestamps.
  • Do not open files to check. Opening changes access times and may be the offence.
  • Record what you have already done. You were working on it, so changes exist. Documenting them honestly is far better than hoping nobody asks.
  • Isolate it, physically and from the network.
  • Start the custody record.

What to hand over: the machine, the record, your written account of what you observed and when, and anything you already captured — logs, screenshots, notes. Facts, not conclusions.

And the professional judgement: if you are unsure whether something crosses this line, treat it as though it does and ask. The cost of preserving a machine unnecessarily is a delayed repair. The cost of the reverse is evidence that no longer proves anything, and it cannot be undone.

Practise what you just read

1. Which category of personal data carries the higher obligations?

Select one

  1. Contact details
  2. Health, biometric and similar sensitive categories
  3. Financial records, because they are the category most frequently targeted by criminals seeking to commit fraud
  4. Employment records
Show answer

B. Sensitive categories have a higher bar and worse consequences when they are mishandled. Recognising that a routine job has become a regulated one is most of what this objective asks.

2. What is the practical rule about payment card numbers found stored in a spreadsheet?

Select one

  1. They must be encrypted
  2. They should be moved to a secure folder
  3. It is a finding to report rather than something to tidy up
  4. They should be deleted immediately, since retaining full card numbers is prohibited by the card industry rules
Show answer

C. Card industry rules govern this rather than law, and the judgement about what happens next is not a technician’s to make alone. Deleting it unilaterally also destroys evidence of a possible breach.

3. An OEM licence from a decommissioned machine is reused on a replacement. What is that?

Select one

  1. Permitted where the original machine has been disposed of and the licence has been deactivated with the vendor first
  2. Good practice
  3. A support issue
  4. A licence breach, because the licence belongs to the original hardware
Show answer

D. OEM licences are tied to the board they shipped on and are not transferable. It is one of the easiest breaches to commit with entirely good intentions.

8 more questions on this objective are part of the full course.

Practise the full question bank in the exam simulator

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA A+ Core 2 220-1202 and is not produced by or endorsed by CompTIA.