While I've tried to give you a general and summarized overview of the procedures when collecting and preserving evidence, there are several official documents that I highly recommend you read and become familiar with, as they all give good details and guidelines on documentation of the scene, evidence collection, and data acquisition.
The SWGDE (Scientific Working Group on Digital Evidence) Best Practices for Computer Forensics, Version 3.1, published in September 2014, outlines best practices for computer forensics in the following areas:
- Evidence collection and handling
- Evidence acquisition and transport
- Guidelines for investigating powered-on and powered-off systems media and servers
- Examination and reporting
The full SWGDE best practices for computer forensics document can be downloaded from here:
The SWGDE Capture of Live Systems...