Deliberate or accidental actions that could spoil evidence held on devices are avoided (magnetic fields damaging magnetic media, for instance), and the DEFR does not access a device, for example to dump memory from a live system, without the required competency and reliable, validated processes. Collection or acquisition may be impractical, and the DEFR weighs among other cases: no legal right or authority to take the device; a duty to use other means (such as not interrupting a business); a wish to observe how a suspect is misusing a system; a covert operation, where lawful; a mission-critical device that cannot go down; a device physically too large (a data-centre server or RAID array); a safety-critical device whose stopping would endanger life; and a device that also serves innocent parties.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.