Having a separate AWS account for forensic investigations is ideal for helping you diagnose and isolate the affected resource. By utilizing a separate account, you can architect the environment in a more secure manner that's appropriate to its forensic use. You could even use AWS organizations to provision these accounts quickly and easily in addition to using a preconfigured, approved, tried and tested CloudFormation template to build out the required resources and configuration. This allows you to build the account and environment using a known configuration without having to rely on a manual process that could be susceptible to errors and undesirable in the early stages of a forensic investigation. While performing your investigations, you should ensure that your steps and actions are auditable through the use of logging mechanisms provided by managed AWS services, in addition to services such as AWS CloudTrail.
Another benefit of moving the affected resource...