Everyday use of cloud services has exponentially increased primarily because of its popular price and because it is more convenient than the alternative physical computing services. Unfortunately, good marketing and lack of knowledge have lead many companies to enter the cloud without first performing a risk and security analysis. What happens when the cloud gets compromised is that you suffer a breach, and you find yourself in a position of having to conduct digital forensics and collect some data? What to do then? Is there an option to acquire data? Do you even know the location of your data? Can you tell if someone else has access to your data? Is the data located in the cloud service provider’s data center or they have a data storage service with the 3rd party? It is recommended to consider these issues before the actual incident has happened. But what can you actually do? This paper shows the standards that can be implemented in Cloud forensics and procedures and contracts that will facilitate analysis on a daily basis.


