Acquisition makes a digital evidence copy (a whole disk, a partition, selected files) and records the methods and activities. The DEFR chooses a method suited to the situation, cost and time, records why, documents it in detail so another competent DEFR can reproduce or verify it as far as practicable, and works as unintrusively as possible, recording any unavoidable change to the data. Original and copy are both checked with a verification function proven accurate at the time and acceptable to whoever will use the evidence, and must give the same output. Where verification cannot be done (a running system, error sectors, limited time) the best available method is used and justified, and an unverified image is recorded and justified; readable parts may be verified where errors prevent verifying all of it. Where needed the method captures both allocated and unallocated space. Where a full copy is not feasible or allowed (a very large source, a system that cannot be shut down), a logical acquisition of chosen data types, directories or locations may be made, which may miss deleted files and unallocated space. Some jurisdictions require special handling such as sealing in the owner's presence.
This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.