Collection of evidence
Purpose
Set up and apply procedures to identify, collect, acquire and preserve evidence relating to security events.
How to meet this control
In short: Establish procedures for identification, collection and preservation of evidence.
- Step 01Document evidence-handling procedures and chain-of-custody steps in the incident response plan for legal defensibility
- Step 02Define how to handle different media and device states (powered on, powered off, cloud-hosted)
- Step 03Use write-blockers, forensic imaging and hashing to show copies match the originals and remain untampered
- Step 04Use qualified or certified personnel and tools to strengthen evidential value
- Step 05Engage legal counsel or law enforcement early where court action is possible
Tip: Document chain-of-custody steps in your IR plan for legal defensibility.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Develop internal evidence-handling procedures aimed at disciplinary and legal use
- ›Consider the admissibility rules of the different jurisdictions involved
- ›Give clear instructions for handling different storage media and device states
- ›Ensure records are complete and demonstrably untampered with
- ›Show that copies of electronic evidence match the originals
- ›Confirm that any system the evidence came from was operating correctly at the time
- ›Use qualified, certified personnel and tools to strengthen evidential value
- ›Involve legal advice or law enforcement early when court action is possible
Audit evidence to keep
- - Documented evidence collection and chain-of-custody procedures
- - Records of evidence preservation (forensic images, hashes) from incidents
- - Evidence that qualified personnel or tools are used for collection
- - Records of legal or law enforcement engagement where applicable
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.28. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.