The DEFR can account for all data and devices acquired while they are in the DEFR's custody. A chain of custody record, one or several related documents started at collection or acquisition, traces each item's movement and handling from when the team identified, collected or acquired it to its present state and location, so that access and movement can be established at any moment, and names who was responsible for it (for digital data or paper notes alike). For digital evidence it includes a contemporaneous record of acquiring data onto a given device, that device's movements, and later extracts or copies made for analysis. At minimum it holds: a unique identifier for the evidence; who accessed it, when and where; who checked it into and out of the preservation facility and when; why it was checked out (case, purpose, authority where relevant); and any unavoidable change, who made it and why. The chain is kept intact for the evidence's whole life and retained afterwards for a period set by the jurisdiction, and any special local requirements are followed.
This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.