ISO/IEC 27042:2015
Clause 7: Analytical models – ISO/IEC 27042:2015

ISO/IEC 27042:2015 7.1: 7.1 Static analysis

Static analysis examines potential digital evidence by inspection alone to judge its value (finding artefacts, building timelines, reviewing file contents and deleted data), viewing data raw or through suitable viewers without running any executable code, and normally on a copy made per ISO/IEC 27037 so the original is not spoiled or obscured by accident. It suits consequential data (log files, network packets, memory dumps) and metadata (permissions, timestamps), though it may not reveal the full significance of some evidence on its own (for example malware-driven intrusion or exfiltration).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 1 control

  • 10.3 10.3 Potential digital evidence examination and analysis process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 7: Analytical models – ISO/IEC 27042:2015

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.