Australian Information Security Manual
Guidelines for cyber security incidents

Australian Information Security Manual ISM-0138: Maintaining the integrity of evidence

The integrity of evidence gathered during an investigation is maintained by investigators: - recording all of their actions - maintaining a proper chain of custody - following all instructions provided by relevant law enforcement agencies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • 7.3.11.C.01 7.3.11.C.01 Preserve evidence and record investigation actions
  • 7.3.12.C.01 7.3.12.C.01 Prompt NCSC assistance requests without disturbing evidence

ISO 27002:2022 · 1 control

  • 5.28 Collection of evidence

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Guidelines for cyber security incidents

Query this from an agent

The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.