ISO/IEC 27037:2012
Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

ISO/IEC 27037:2012 6.9.4: 6.9.4 Transporting potential digital evidence

Collected devices and acquired evidence are protected in transit: never left unattended, kept under the chain of custody to prevent tampering or spoliation and keep them intact and authentic, and encrypted where someone other than the DEFR or DES carries them. Sensitive or personal data is gathered in line with local data protection law. The DEFR guards against electrostatic discharge, packs devices securely against shock and vibration, keeps moisture, humidity and temperature suitable, avoids leaving evidence in vehicles for long periods or exposed to UV, and where the DEFR cannot travel with it, uses suitable authorised shipping; the transport paperwork and a check that the package arrived intact are added to the custody record.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.14 Information transfer

ISO/IEC 27043:2015 · 1 control

  • 9.5 9.5 Potential digital evidence transportation process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 6: Key components of evidence handling – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.