Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› Data Acquisition
Cyber Security

Data Acquisition

← Back to Glossary
By NHI Mgmt Group Updated September 24, 2026 Domain: Cyber Security

Data acquisition is the controlled extraction of evidence from a device or system for later examination. Forensic teams typically create verified copies, often through imaging, so the original data remains unchanged while investigators work on the duplicate in a secure environment.

What Data Acquisition Covers

Data acquisition is the controlled extraction of evidence from a device or system for later examination. The core requirement is preserving evidentiary value while obtaining usable copies, not simply copying data as quickly as possible.

In practice, that means the process is governed by integrity, chain of custody, and repeatability. Forensic teams need to know what was acquired, how it was acquired, when it was acquired, and whether the copy can be shown to match the source.

Why Controlled Acquisition Matters

Controlled acquisition is what makes the resulting material defensible in an investigation. A verified image or export lets analysts inspect artefacts without repeatedly touching the original system, which reduces the chance of contamination, alteration, or accidental loss of volatile state.

This matters because data acquisition often sits at the boundary between response and evidence handling. If the acquisition method is too invasive, too incomplete, or poorly documented, the resulting artefacts may still be useful for triage but far less reliable for formal examination or legal use.

Common trade-offs include speed versus completeness, live capture versus powered-off imaging, and breadth of collection versus minimizing operational impact on the source system.

How Acquisition Is Typically Performed

Most acquisition workflows rely on creating a copy, then verifying it with hashes or similar integrity checks. Disk imaging is common when investigators need a broad snapshot of storage, while targeted acquisition may be used when the subject is a smaller set of files, logs, or volatile artefacts.

Live acquisition can preserve memory, running processes, and active connections, but it may also change the system state as the collection tool runs. Static acquisition is often cleaner from an evidence perspective, but it can miss short-lived artefacts that disappear after shutdown. The right method depends on the investigation goal and the condition of the source.

Good practice also depends on keeping the source protected during and after collection. The original device or system should remain as untouched as possible, while the working copy is examined in a controlled environment.

What Makes Acquisition Trustworthy

Trustworthy acquisition is not defined by the tool alone. It depends on demonstrable integrity, repeatable handling, and clear provenance from source to working copy. Documentation needs to explain who collected the data, what scope was collected, what validation was performed, and how the original evidence was safeguarded.

When those controls are weak, the problem is usually not that the data is unavailable, but that confidence in the data is reduced. Forensic conclusions become harder to defend when acquisition steps cannot be reconstructed or when the copy cannot be tied back to the source with confidence.

Because acquisition quality shapes everything that follows, it is one of the most consequential steps in digital forensics and incident investigation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-9 — Protection of Audit InformationData acquisition depends on preserving evidence integrity and tamper resistance.
CM-3 — Configuration Change ControlControlled acquisition requires documenting and limiting changes to the source during collection.
SI-7 — Software, Firmware, and Information IntegrityVerification of copied evidence relies on integrity assurance for the collected material.
Recommendation — Protect acquired evidence and logs so collection and later review remain trustworthy. Control and document any change made during acquisition to preserve evidentiary value. Verify acquired data integrity before analysis and retain validation results with the evidence.
NIST CSF 2.0PR.DS-01 — Data-at-rest is protectedAcquired evidence must be protected while stored and examined as a copied dataset.
ID.RA-05 — Threats, vulnerabilities, likelihoods, and impacts are used to understand riskAcquisition choices depend on risk from volatile state loss, source alteration, and evidentiary degradation.
Recommendation — Protect copied evidence so the working set remains intact during analysis. Select the acquisition method that best balances evidence fidelity and operational risk.
ISO/IEC 27001:2022A.8.13 — Information backupForensic acquisition is closely related to creating reliable preserved copies of information.
Recommendation — Maintain reliable copies and verify they can be restored or examined without altering the source.
CIS Controls v8CIS-8 — Audit Log ManagementAcquisition often relies on logs and trace artefacts that must be preserved for examination.
Recommendation — Preserve logging artefacts so acquisition outputs can be traced and validated.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org