Where imaging or copying is impossible for technical or operational reasons (unique hardware, harm to the business), or risks losing potential digital evidence (such as copying from a live device with tools on the suspect system), live analysis may have to proceed without first following ISO/IEC 27037. Investigators then take great care to minimise risk to the evidence and keep a full, detailed record of every process performed, and investigative leads ensure that anyone doing it is fully competent and can explain their processes and any changes to data, evidence or systems their actions may have caused.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.