ISO/IEC 27050-3:2020
Clause 6.2: ESI identification – ISO/IEC 27050-3:2020

ISO/IEC 27050-3:2020 6.2.4: 6.2.4 Requirements for ESI identification

Because identification happens early and in effect defines the universe of potentially relevant hardcopy and ESI, mistakes surface later as extra collections, processing, review, cost and delay, or as legal claims where key individuals or sources were overlooked or ESI was deleted; a plan covering the people, ESI sources, tools and procedures to deploy is the best protection. Seven requirements apply: a) the identification coordinator shall know the purposes the effort serves and understand the subject matter, scope and time frame; b) those responsible shall develop a plan to guide identification before carrying it out; c) those executing it shall be informed of the operative requirements governing identification, namely 1) legal requirements, 2) matter-specific requirements, 3) process-specific requirements and 4) the landscape of ESI that can fall within the matter; d) identification shall be transparent enough while under way for those responsible to judge progress and adjust; e) it shall be supported by appropriate methods and metrics; f) it shall be adapted as needed to changes in the governing requirements and to information learned along the way, such as further knowledgeable custodians, relevant sources or pertinent features of the ESI environment like auto-delete functions; g) the procedures shall be documented so as to reflect accurately 1) every procedure followed, 2) every significant decision taken and 3) any evaluation of the process's effectiveness.

Maintained by Gerard BlokdykControl text last updated

Other controls in Clause 6.2: ESI identification – ISO/IEC 27050-3:2020

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.