Following an incident, an administrator is gathering forensic evidence from a server for a human resources investigation.
Which of the following best practices is MOST important to document throughout the process to maintain integrity of the findings?
- Acceptable use policy violations
- Server configuration
- Chain of custody
- Data loss incidents