ISO/IEC 27041:2015
Clause 5: Method development and assurance – ISO/IEC 27041:2015

ISO/IEC 27041:2015 5.6.3: 5.6.3 Uncertainty and risk evaluation

Every tool, hardware or software, carries some error that can be controlled and accounted for but never removed, and an investigator's unfamiliarity with a tool or process adds further uncontrolled error, reduced by training and routine proficiency testing. These uncertainty characteristics (a process's strengths and weaknesses) tend to add up along a linear chain of processes, so overlapping, proportionate processes are designed to reinforce the provenance of evidence found. Ahead of relying on a favoured tool or method, investigators consider the combined weaknesses of the whole chosen sequence, controlled through correct process selection and a documented risk analysis; validated atomic elements make this easier. A process with unknown or high weakness is not ruled out on that ground alone, and may be invaluable where nothing else can do the task.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.28 Collection of evidence

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 5: Method development and assurance – ISO/IEC 27041:2015

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.