When a running device is to be collected, the DEFR in every case: considers capturing its volatile data and current state before power-down, since encryption keys and other key data may be in active memory or memory not yet cleared, considering logical acquisition where encryption is suspected and using trusted, validated tools because the live operating system may not be trustworthy; decides, with a DES where needed, whether the device's configuration calls for a normal shutdown or pulling the plug, and if pulling it, removes the cable from the device end rather than the wall (a device on a UPS may otherwise change data), having captured volatile data first because encrypted volumes become unreadable and valuable live data (corporate systems, devices running medical equipment) may be lost; notes that hardware exists to move a running device onto portable power and that mouse jigglers stop the screen saver engaging, in which case packing and transport must deal with cooling and shock; labels, disconnects and secures all cables and labels ports so the system can be rebuilt; and tapes over the power switch where needed, after recording its state.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.