Collected devices and acquired evidence are protected as far as possible against loss, tampering and spoliation; the central aim is to keep the evidence intact and authentic and its chain of custody unbroken. They are stored in an evidence preservation facility with physical security controls (access control, surveillance or intrusion detection) or another controlled environment, whose purpose is to prevent loss, damage and tampering and allow auditing. Devices are wrapped or placed in packaging suited to their nature before being moved, shock-resistant where needed; static-sensitive devices go in anti-static bags; system units and laptops go in suitable containers against tampering; and radio-shielded packaging (a Faraday bag) may drain a phone's battery faster, so auxiliary power may be needed.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.