> For the complete documentation index, see [llms.txt](https://docs.monolithforensics.com/monolith/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.monolithforensics.com/monolith/monolith-features/storage-items.md).

# Storage Items

### What are storage items?

Storage items represent the physical devices or storage systems used to preserve forensic data that has been collected, processed, or provided to your organization.

Monolith tracks storage items separately from evidence items so teams can document where forensic data is stored, associate storage with cases, and manage the item throughout its lifecycle.

### Examples of Storage Items

Storage items may include:

* External Hard Drives
* USB Drives
* Network-attached storage devices
* FTP Servers
* Cloud storage systems
* Other physical or digital storage used for forensic data

### Examples of stored data include:

* Forensic images
* Mobile device extractions
* Case data
* Working files
* Forensic reports

### Evidence Items vs. Storage Items

Evidence and storage items serve different purposes in Monolith.

**Evidence items** represent the original source of forensic evidence or data. Examples may include smartphones, computers, email accounts, cloud accounts, removable media, or other original sources.

**Storage items** represent the device or system where collected or processed forensic data is stored. Examples may include an external hard drive containing a forensic image or a network storage system containing data from multiple cases.

A useful distinction is:

* Evidence is the original source or item being examined.
* Storage is where collected or processed data is preserved.

### Storage Item Categories

Monolith supports two categories of storage items:

* **General**
* **Assigned**

#### General Storage Items

General storage items represent shared or permanent storage systems that may contain data from multiple cases.

A common example is a network-attached storage system used to preserve forensic images and case data for the lab.

General storage items:

* Cannot be assigned to a specific case
* May contain data from multiple cases
* Do not use case-specific chain of custody tracking
* Typically remain in a fixed location
* Are commonly used for long-term or shared data storage

#### Assigned Storage Items

Assigned storage items represent storage associated with a specific case.

These items are often smaller or portable devices that contain data for one case, such as an external hard drive prepared for a forensic examination or client delivery.

Assigned storage items:

* Must be assigned to a case before they can be used within that case
* Can contain data for only one assigned case at a time
* Support chain of custody while assigned to a case
* Can be removed from a case and reused when appropriate
* May be reassigned, recycled, or destroyed according to your organization’s process

{% hint style="warning" %}
Review the item’s acquisitions, chain of custody, and case association before removing or reassigning an assigned storage item. Removing an item from a case may affect its linked records and custody history.
{% endhint %}

### Create or Assign a Storage Item

There are two ways to associate a storage item with a case:

* Create a new storage item
* Assign an existing storage item

#### Create a New Storage Item

To create and assign a storage item from a case:

1. Open the case.
2. Select the **Storage Items** tab.
3. Create a new storage item.
4. Enter the storage item details.
5. Save the item.

The new storage item is created and assigned to the current case.

#### Assign an Existing Storage Item

To assign an existing storage item:

1. Open the case.
2. Select the **Storage Items** tab.
3. Choose the option to assign an existing item.
4. Select the storage item.
5. Confirm the assignment.

An existing item may also be assigned through the available **Actions** menu.

<figure><img src="/files/3M9Sa6Mf0P8TqoPOhzjY" alt=""><figcaption><p>Assigning Storage Items</p></figcaption></figure>

### Storage Item Lifecycle

Storage items may move through several stages during their use.

Depending on your organization’s workflow, an assigned storage item may be:

* Created for a case
* Assigned to an existing case
* Used to store one or more acquisitions
* Moved between physical locations
* Removed from a case
* Reassigned for future use
* Destroyed when it should no longer remain in service

### Best Practices

* Use clear storage numbers and descriptions.
* Record make, model, serial number, capacity, and location when available.
* Use General storage for shared systems that contain data from multiple cases.
* Use Assigned storage for devices dedicated to a specific case.
* Review linked acquisitions before removing, reassigning, or destroying an item.
* Maintain chain of custody for assigned storage when required.
* Follow your organization’s retention and media destruction policies.
