Static analysis examines potential digital evidence by inspection alone to judge its value (finding artefacts, building timelines, reviewing file contents and deleted data), viewing data raw or through suitable viewers without running any executable code, and normally on a copy made per ISO/IEC 27037 so the original is not spoiled or obscured by accident. It suits consequential data (log files, network packets, memory dumps) and metadata (permissions, timestamps), though it may not reveal the full significance of some evidence on its own (for example malware-driven intrusion or exfiltration).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.