Procedures are to be set up and followed for identifying, collecting, acquiring and preserving evidence connected with information security events. Purpose: handle incident evidence consistently and effectively so it can support disciplinary or legal action. Guidance: internal procedures govern evidence intended for disciplinary or legal use and take account of the rules in each relevant jurisdiction so the evidence has the best chance of being accepted. They should explain how to identify, collect, acquire and preserve evidence for different storage media and devices and for devices that are powered on or off. Evidence generally has to be gathered in a way a national court or other disciplinary forum will accept, which means being able to show that records are complete and untouched, that copies of electronic evidence are very likely identical to the originals, and that the systems it came from were working properly when it was recorded. Where possible, personnel and tools should hold certification or other qualification, strengthening the preserved evidence. When digital evidence crosses organizational or jurisdictional lines, the organization must make sure it is entitled to collect it. Other information: whether an event will lead to court action is often unclear at first, so evidence can be lost, deliberately or not, before the seriousness is understood; seek legal or law enforcement advice early; ISO/IEC 27037 covers digital evidence handling and the ISO/IEC 27050 series covers electronic discovery.
This control maps to 78 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.