An organization's incident response team has successfully contained a data breach incident. Which of the following actions is the MOST appropriate next step to ensure that the digital evidence remains intact for forensic analysis?
Turning off systems to ensure data is not tampered with
Performing secure backups of affected systems
Creating a forensic image of affected systems
Disconnecting compromised systems from the network