ISO/IEC 27050-3:2020
Clause 6.2: ESI identification – ISO/IEC 27050-3:2020

ISO/IEC 27050-3:2020 6.2.5: 6.2.5 Guidance for ESI identification

Seven recommendations: a) develop an identification plan with clear assignments and expectations so the process is repeatable and defensible, since even simple cases benefit from a plan that accounts for every eventuality; b) develop and use standard interview-question and survey templates reusable across cases; c) where possible, before any discovery event, build a list or inventory of systems or a data map giving one central view of the kinds of ESI held and where they sit (local computers, servers, cloud, backup, external media, portable devices, home computers, intranets, extranets and the like), understand the application portfolio, systems, data flows and capabilities and how they map to business units, and keep that knowledge current; d) review and, where needed, revise litigation hold materials and processes once the potentially relevant sources are known; e) create documentation confirming the processes, tools and methods used, to show the identification was reasonable and defensible; f) report status and progress regularly; g) create quality-control and validation plans throughout so the identification is thorough and defensible.

Maintained by Gerard BlokdykControl text last updated

Other controls in Clause 6.2: ESI identification – ISO/IEC 27050-3:2020

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.