To prioritise, the DEFR must understand why the evidence is being gathered. The general aim is to preserve as much data as possible, but items may need ranking by volatility and by relevance or likely evidential value (items most likely to hold data directly about the incident). Ranking by volatility applies only where the case needs it: volatile data is easily lost (for example when power is removed), while non-volatile data survives power loss. Where it is unclear which devices hold evidence or matter most, they may be examined first under a process that sets priority. Devices to consider include IT equipment and storage media, CCTV, personal electronic devices, vehicle systems, control systems and improvised electronics. The most volatile material (RAM, swap space, running processes) is acquired first, and the DEFR knows enough to rank by volatility. On identification the DEFR prioritises what power removal would destroy and captures it quickly with validated methods; volatile data that may change with location, time or nearby devices is secured before a device is moved; physical evidence such as fingerprints or DNA on devices is protected and coordinated with its collectors; volatile data is examined where encryption or malware is suspected; and when time is short, evidence relevant to the specific incident comes first.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.