ISO/IEC 27037:2012
Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

ISO/IEC 27037:2012 6.4: 6.4 Competency

DEFRs and DESs hold the technical and legal competencies needed (Annex A gives examples) and can show they are properly trained and understand enough, technically and legally, to handle evidence correctly, including the processes and methods suited to each kind of source; good tools do not make up for an incompetent handler. Where a jurisdiction prescribes how qualifications are established, DEFRs inform themselves of it. When asked, they can demonstrate competence with the tools and methods chosen and provide evidence that it is current. DEFRs are trained to handle devices in an investigative setting, show and keep up their skills to the appropriate authorities, and both the individual and the employer are responsible for training and for keeping competence up to date.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27042:2015 · 3 controls

  • 10.1 10.1 Overview
  • 10.2 10.2 Demonstration of competence
  • 10.3 10.3 Recording competence

ISO 27002:2022 · 1 control

  • 6.3 Information security awareness, education and training

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.