ISO/IEC 27037:2012
Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

ISO/IEC 27037:2012 6.3: 6.3 Roles and responsibilities

The DEFR identifies, collects, acquires and preserves evidence at the scene, writes the collection and acquisition report (not necessarily the analysis report), and is responsible for keeping evidence intact and authentic, so needs sufficient experience, skill and knowledge. The DES gives the DEFR specialist technical support in the same four activities at the scene, and the DEFR may also draw on other technical support staff. The Annex A competency matrix helps place each at the right level; where an incident response team exists, ISO/IEC 27035 covers the DEFR and DES as its members.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.24 Information security incident management planning and preparation

ISO/IEC 27043:2015 · 1 control

  • 8.5 8.5 Preparation process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.