Subscribe to the Non-Human & AI Identity Journal
Home Glossary Cyber Security Analysis custody
Cyber Security

Analysis custody

← Back to Glossary
By NHI Mgmt Group Updated August 1, 2026 Domain: Cyber Security

The degree to which an organisation retains control over security telemetry, investigative context, and evidence instead of handing those assets to a platform provider. Strong custody supports compliance, forensics, and reuse of data across tools and teams.

Expanded Definition

Analysis custody describes how much control an organisation keeps over its security telemetry, investigative context, and evidentiary records while using external platforms, managed services, or shared workflows. In practice, it is about whether logs, alerts, case notes, enrichment data, and chain-of-custody records remain under the organisation’s control, or become difficult to export, verify, or reuse once they are inside a provider’s environment. The concept overlaps with data governance, incident response, and legal hold obligations, but it is not the same as generic data ownership. The focus is operational control during detection and investigation, especially when multiple tools, analysts, or third-party services touch the same evidence. NIST control guidance such as NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant because retention, auditability, and integrity controls shape whether analysis data remains trustworthy and portable. Definitions vary across vendors because some treat custody as exportability, while others frame it as contractual access rights or storage location.

The most common misapplication is treating “data available in a dashboard” as sufficient custody, which occurs when an organisation cannot independently retrieve, preserve, or verify the underlying evidence after the provider changes retention settings or access terms.

Examples and Use Cases

Implementing analysis custody rigorously often introduces operational friction, requiring organisations to weigh investigative speed against retention, portability, and evidentiary assurance.

  • A security team retains raw endpoint telemetry in an organisation-controlled archive while a managed detection service only receives a working copy for triage.
  • An incident response lead preserves immutable logs, timestamps, and analyst notes so the evidence can support internal review or external legal proceedings.
  • A SOC exports alert history from a cloud analytics platform into an internal case management system to avoid losing context if the subscription ends.
  • A regulated business aligns custody expectations with logging and retention controls described in NIST SP 800-53 Rev 5 Security and Privacy Controls so investigations remain auditable across tools.
  • A provider-managed SIEM is configured with customer-owned encryption keys and export paths so analysts can reconstruct an incident without waiting for vendor support.

Why It Matters for Security Teams

Analysis custody matters because a security team may be able to detect an issue quickly but still fail to investigate it fully if the underlying evidence is locked behind provider workflows, limited retention, or restrictive export formats. That creates gaps in forensics, weakens incident reconstruction, and can undermine compliance obligations that depend on demonstrable control over records. It also affects cross-team reuse: threat hunting, legal review, risk reporting, and post-incident lessons all depend on being able to preserve and revisit the same evidence set. For identity-heavy environments, custody is especially important when logs include administrator actions, authentication events, or non-human identity activity, because those records often become the only trustworthy source for attribution and timeline analysis. Organisations also need to distinguish custody from simple access. Having a login to a platform is not the same as retaining durable control over the data itself. Practitioners typically encounter the consequences only after a provider outage, contract dispute, or incident response deadline, at which point analysis custody becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.PT-1Protective technology and data management support retaining control of investigative evidence.
NIST SP 800-53 Rev 5AU-6Audit review and analysis depends on preserving logs and related evidence under customer control.
NIST SP 800-63Identity records and authentication evidence need durable custody for attribution and investigation.
OWASP Non-Human Identity Top 10NHI telemetry and service credentials need custody to support incident response and reuse.
DORAOperational resilience requirements make evidence retention and control over outsourced services relevant.

Keep telemetry portable and protected so investigations do not depend on one provider's UI or retention defaults.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org