ISO/IEC 27037:2012
Clause 5: Overview, principles and handling processes – ISO/IEC 27037:2012

ISO/IEC 27037:2012 5.4.5: 5.4.5 Preservation

Preservation protects potential evidence and the devices holding it from tampering and spoliation so it stays useful to the investigation. It starts when the devices are identified and continues through every handling process. Ideally neither the data nor its metadata (such as date and time stamps) is changed at all; the DEFR can show the evidence is unchanged since collection or acquisition, or explain and record any unavoidable change. Where confidentiality is a business or legal requirement (privacy, for example), evidence is preserved in a way that protects it.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27042:2015 · 1 control

  • 6.2 6.2 General principles

ISO/IEC 27043:2015 · 1 control

  • 11.6 11.6 Preserving digital evidence process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 5: Overview, principles and handling processes – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.