ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.28: Collection of evidence

Requires procedures to be established and used for identifying evidence relating to information security events, then collecting, acquiring and preserving it.

What else in your programme already covers this

This control maps to 79 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 10 controls

  • NIST800-AU-10 Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined]
  • NIST800-AU-11 Audit record retention
  • NIST800-AU-12 Audit record generation
  • NIST800-AU-16 Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries
  • NIST800-AU-6 Audit record review, analysis, and reporting
  • NIST800-AU-9 Protection of audit information
  • NIST800-CA-2 Control assessments
  • NIST800-IR-4 Incident handling
  • NIST800-IR-9 Information Spillage Response. Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific information involved in the system contamination; Alerting [organization-defined] of the information spill using a
  • SP800-53-AU Audit and Accountability Family
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.MI-02 Incidents are eradicated

SOC 2 · 7 controls

  • SOC2-CC2.1 COSO principle 13: Obtains and generates relevant, quality information
  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC7.3 Evaluates security events to determine incident status
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-P6.2 Records of personal information disclosures are maintained
  • SOC2-P6.3 Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which

FedRAMP High · 5 controls

  • AU-11 Audit Record Retention
  • AU-9 Protection of Audit Information
  • IR-2 Incident Response Training
  • IR-6 Incident Reporting
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]

FedRAMP Moderate · 5 controls

  • AU-11 Audit Record Retention
  • AU-9 Protection of Audit Information
  • IR-2 Incident Response Training
  • IR-6 Incident Reporting
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]
  • AU-11 Audit Record Retention
  • AU-9 Protection of Audit Information
  • IR-2 Incident Response Training
  • IR-6 Incident Reporting
  • AU-11 Audit Record Retention
  • AU-9 Protection of Audit Information
  • IR-2 Incident Response Training
  • IR-6 Incident Reporting
  • AU-11 Audit Record Retention
  • AU-9 Protection of Audit Information
  • IR-2 Incident Response Training
  • IR-6 Incident Reporting
  • ISM-0043 Systems have a cyber security incident response plan that covers the following: - guidelin
  • ISM-0137 Legal advice is sought before allowing intrusion activity to continue on a system for the
  • ISM-0138 The integrity of evidence gathered during an investigation is maintained by investigators:
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence
  • ASBv3-LT-6 Configure log storage retention

ISO 27701:2019 · 3 controls

  • 6.13.1 Management of information security incidents and improvements
  • 6.9.4 Logging and monitoring
  • 8.5.4 Notification of PII disclosure requests

NIS2 Directive · 3 controls

  • Art.23.4.b Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise
  • Art.23.4.d Submit a final report within one month, and a progress report where the incident is still running
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

CMMC 2.0 · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

  • ASD37-33 Capture network traffic (Limited)

C5 (Germany) · 1 control

  • C5-SIM-03 Documentation and reporting of security incidents
  • CFTC-SS-20 Production of System Safeguards Books and Records

CIS Controls v8 · 1 control

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.28 Collection of evidence

ISO 27018:2019 · 1 control

PCI DSS 4.0 · 1 control

  • 12.10.7 Response procedures for PAN detection in unexpected locations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 79 it maps to, and the evidence behind each claim, over MCP and REST.