ISO/IEC 27037:2012
Clause 5: Overview, principles and handling processes – ISO/IEC 27037:2012

ISO/IEC 27037:2012 5.2: 5.2 Principles of digital evidence

Three principles govern digital evidence in most jurisdictions and apply to every investigation, not only court cases: relevance (it helps prove or disprove an element of the matter), reliability (it is what it claims to be) and sufficiency (enough has been gathered for the matter to be examined properly; a full copy of everything is not always needed, which lets effort be prioritised when time or money is short). Gathering follows local law. Every process DEFRs and DESs use is validated before use; where someone else validated it, they check that the validation fits their own use, environment and circumstances. They also record every action, set and apply a way of showing the copy is accurate and reliable against the original source, and accept that preserving evidence cannot always avoid some intrusion.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27041:2015 · 3 controls

  • 5.10 5.10 Confirmation
  • 5.9.4 5.9.4 Fully validated processes
  • 6.3 6.3 External assurance

ISO 27002:2022 · 1 control

  • 5.28 Collection of evidence

ISO/IEC 27043:2015 · 1 control

  • 5.1 5.1 General principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 5: Overview, principles and handling processes – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.