diff --git a/tech/cia-do-dont.wiki b/tech/cia-do-dont.wiki index 92376c8..e9fb4b9 100644 --- a/tech/cia-do-dont.wiki +++ b/tech/cia-do-dont.wiki @@ -40,3 +40,9 @@ This is the CIA list of dos and donts. communications * DONOT send data with fixed size and timing * DO properly clean up network connections + +== Disk I/O == + +* DO document disk forensic footprint that could created by tool +* DONOT read, write, or cache data to disk for no reason +* DONOT write plain text collected data to the disk