Acquisition may happen with devices on, off, or on and unable to be turned off (mission-critical); in each the DEFR makes an accurate copy of the storage suspected of holding evidence, or, if no image can be made, accurate copies of the specific files suspected. Ideally a verified master is made together with separate working copies, and the master is not used again except to check a working copy or replace a damaged one. Running systems may fall into screen saver or auto-lock, and anything done to prevent it has consequences (a mouse jiggler, for example, adds a USB entry to the registry), which reliable methods should keep to a minimum.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.