Evidence kit

Cloud and SaaS Incident Evidence Checklist

Prepare collection authority, identify useful cloud and SaaS records, and document evidence exports without exposing secrets.

Cloud and SaaS Incident Evidence Checklist visual for DefendArm Security guidance
Preview before download

Prepare access before collection

Use authorized accounts and your approved incident process. This is a collection planning aid, not a forensic certification or a substitute for specialist advice.

Sample decisions
  • Which event sources are available, and which may expire before collection?
  • Who can export evidence through a trusted administrative path?
  • What can the available records prove, and what remains unknown?
Common mistakes
  • Assuming data-access events were enabled because administration logs exist.
  • Changing or deleting the suspected account before preserving relevant records.
  • Sharing a broad evidence export through an unrestricted link.
What is inside

Cloud and SaaS Incident Evidence Checklist

Prepare collection authority, identify useful cloud and SaaS records, and document evidence exports without exposing secrets. Includes a fillable PDF with worked examples and decision records.

Fillable PDF. Reviewed 2026-09-21. Includes practical guidance and reusable review records.

  • Prepare access before collection: Use authorized accounts and your approved incident process. This is a collection planning aid, not a forensic certification or a substitute for specialist advice.
  • Worked collection / Suspicious grant: Fictional example: a finance user reports unexpected access after approving a new application. The responder must determine what changed and which data was reachable.
  • Evidence collection record: Use one record per export. Store this workbook with the evidence under the same access restrictions.

References

Examples are fictional. Adapt these materials to your environment; completing a worksheet is not a certification.

Questions teams ask

Practical questions before you decide.

Who should use the Cloud and SaaS Incident Evidence Checklist?

This resource is built for incident responders, cloud administrators, and SaaS owners who need a clear way to turn security guidance into owners, evidence, and next actions.

What should a team prepare before using it?

Prepare current system owners, relevant policies, available logs or configuration evidence, and any known exceptions that affect the control area.

When should this turn into a deeper review?

Bring in the relevant specialist when the work exposes missing evidence, unclear authority, or controls your team cannot validate. Keep the unresolved issue, owner, and next decision recorded.