ISO/IEC 27037:2012
Clause 7: Instances by device type – ISO/IEC 27037:2012

ISO/IEC 27037:2012 7.1.3.4: 7.1.3.4 Partial acquisition

Partial acquisition may be chosen because the storage is too large (a database server), the system is too critical to stop, the data wanted is mixed with irrelevant data on the same system, or legal authority such as a warrant limits the scope. When chosen, the activities include at least identifying the folders, files or proprietary system options that give access to the data wanted, and then acquiring that data logically.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 1 control

  • 9.4 9.4 Potential digital evidence acquisition process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 7: Instances by device type – ISO/IEC 27037:2012

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.