For a device found off: make sure it really is off; where appropriate take out its storage if not already removed, label it as suspect storage and record make, model, serial number and capacity; prepare the target disk; and image the suspect disk with a validated imaging tool to create the evidence copy, then seal the target (Figure 5). Storage generally stays in the device until acquisition to avoid damage or confusion, with local procedures on removing disks written and followed.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.