The Order of Volatility

The Order of Volatility

RFC 3227 establishes the order of volatility, guiding collection priorities based on how quickly evidence may be lost:

  1. CPU Registers and Cache: Nanoseconds
  2. System Memory (RAM): Lost on power down
  3. Network State: Seconds to minutes
  4. Running Processes: Minutes to hours
  5. Disk Storage: Days to years
  6. Backup Media: Years to decades
  7. Printed Documentation: Decades

This hierarchy drives collection procedures, emphasizing the need to capture volatile data before moving to more persistent sources.