ISO/IEC 27037:2012
Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

ISO/IEC 27037:2012 6.5: 6.5 Use reasonable care

Deliberate or accidental actions that could spoil evidence held on devices are avoided (magnetic fields damaging magnetic media, for instance), and the DEFR does not access a device, for example to dump memory from a live system, without the required competency and reliable, validated processes. Collection or acquisition may be impractical, and the DEFR weighs among other cases: no legal right or authority to take the device; a duty to use other means (such as not interrupting a business); a wish to observe how a suspect is misusing a system; a covert operation, where lawful; a mission-critical device that cannot go down; a device physically too large (a data-centre server or RAID array); a safety-critical device whose stopping would endanger life; and a device that also serves innocent parties.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 2 controls

  • 11.2 11.2 Obtaining authorization process
  • 11.6 11.6 Preserving digital evidence process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.