ISO/IEC 27037:2012
Clause 7: Instances by device type – ISO/IEC 27037:2012

ISO/IEC 27037:2012 7.1.2.1.2: 7.1.2.1.2 Baseline activities: powered on digital device collection

When a running device is to be collected, the DEFR in every case: considers capturing its volatile data and current state before power-down, since encryption keys and other key data may be in active memory or memory not yet cleared, considering logical acquisition where encryption is suspected and using trusted, validated tools because the live operating system may not be trustworthy; decides, with a DES where needed, whether the device's configuration calls for a normal shutdown or pulling the plug, and if pulling it, removes the cable from the device end rather than the wall (a device on a UPS may otherwise change data), having captured volatile data first because encrypted volumes become unreadable and valuable live data (corporate systems, devices running medical equipment) may be lost; notes that hardware exists to move a running device onto portable power and that mouse jigglers stop the screen saver engaging, in which case packing and transport must deal with cooling and shock; labels, disconnects and secures all cables and labels ports so the system can be rebuilt; and tapes over the power switch where needed, after recording its state.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 1 control

  • 9.3 9.3 Potential digital evidence collection process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 7: Instances by device type – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.