CSF 2.0 outcome: incident data and metadata are collected, and their integrity and provenance are preserved. Priority High. N1: most responses collect incident data and metadata; formal chain of custody may not be used for every incident (most malware incidents will not be prosecuted), but collected data is still evidence, defined in SP 800-160v1 as grounds for belief or disbelief, data on which to base proof or to establish truth or falsehood. R1: collect and retain incident evidence under the organization's evidence preservation procedures and data retention policies, weighing the possibility of prosecution and the cost of retaining the data and the hardware and software needed to read it later.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.