ISO/IEC 27043:2015
SC 27's harmonized model of digital investigation: readiness before an incident, initialization when one is detected, acquisition of potential digital evidence, investigation to a presented result, and the concurrent duties of authorization, documentation, chain of custody and preservation that run through all of it. 37 process leaves on the standard's own contents page; the held preview stops at clause 4, so the leaves sit at 60 to 70 with their basis on every node.
ISO/IEC 27043:2015 is a compliance framework from International (ISO/IEC JTC 1/SC 27) with 8 domains and 37 controls that map to 242 other frameworks. The largest domains are Clause 7: Readiness processes – ISO/IEC 27043:2015 (12 controls), Clause 10: Investigative processes – ISO/IEC 27043:2015 (6 controls), Clause 11: Concurrent processes – ISO/IEC 27043:2015 (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Clause 10: Investigative processes – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::10.2 | 10.2 Potential digital evidence acquisition process |
| iso-iec-27043-2015::10.3 | 10.3 Potential digital evidence examination and analysis process |
| iso-iec-27043-2015::10.4 | 10.4 Digital evidence interpretation process |
| iso-iec-27043-2015::10.5 | 10.5 Reporting process |
| iso-iec-27043-2015::10.6 | 10.6 Presentation process |
| iso-iec-27043-2015::10.7 | 10.7 Investigation closure process |
Clause 11: Concurrent processes – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::11.2 | 11.2 Obtaining authorization process |
| iso-iec-27043-2015::11.3 | 11.3 Documentation process |
| iso-iec-27043-2015::11.4 | 11.4 Managing information flow process |
| iso-iec-27043-2015::11.5 | 11.5 Preserving chain of custody process |
| iso-iec-27043-2015::11.6 | 11.6 Preserving digital evidence process |
| iso-iec-27043-2015::11.7 | 11.7 Interaction with physical investigation process |
Clause 12: Process model schema – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::12 | 12 Digital investigation process model schema |
Clause 5: Digital investigation principles – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::5.1 | 5.1 General principles |
| iso-iec-27043-2015::5.2 | 5.2 Legal principles |
Clause 6: Digital investigation processes – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::6.2 | 6.2 Classes of digital investigation processes |
Clause 7: Readiness processes – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::7.10 | 7.10 Implementing pre-incident analysis of data representing potential digital evidence process |
| iso-iec-27043-2015::7.11 | 7.11 Implementing incident detection process |
| iso-iec-27043-2015::7.12 | 7.12 Assessment of implementation process |
| iso-iec-27043-2015::7.13 | 7.13 Implementation of assessment results process |
| iso-iec-27043-2015::7.2 | 7.2 Scenario definition process |
| iso-iec-27043-2015::7.3 | 7.3 Identification of potential digital evidence sources process |
| iso-iec-27043-2015::7.4 | 7.4 Planning pre-incident gathering, storage and handling of data representing potential digital evidence process |
| iso-iec-27043-2015::7.5 | 7.5 Planning pre-incident analysis of data representing potential digital evidence process |
| iso-iec-27043-2015::7.6 | 7.6 Planning incident detection process |
| iso-iec-27043-2015::7.7 | 7.7 Defining system architecture process |
| iso-iec-27043-2015::7.8 | 7.8 Implementing system architecture process |
| iso-iec-27043-2015::7.9 | 7.9 Implementing pre-incident gathering, storage and handling of data representing potential digital evidence process |
Clause 8: Initialization processes – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::8.2 | 8.2 Incident detection process |
| iso-iec-27043-2015::8.3 | 8.3 First response process |
| iso-iec-27043-2015::8.4 | 8.4 Planning process |
| iso-iec-27043-2015::8.5 | 8.5 Preparation process |
Clause 9: Acquisitive processes – ISO/IEC 27043:2015
| Code | Title |
|---|---|
| iso-iec-27043-2015::9.2 | 9.2 Potential digital evidence identification process |
| iso-iec-27043-2015::9.3 | 9.3 Potential digital evidence collection process |
| iso-iec-27043-2015::9.4 | 9.4 Potential digital evidence acquisition process |
| iso-iec-27043-2015::9.5 | 9.5 Potential digital evidence transportation process |
| iso-iec-27043-2015::9.6 | 9.6 Potential digital evidence storage and preservation process |
Your Compliance Coverage
If you comply with ISO/IEC 27043:2015, you already cover:
SLSA
20%
18 controls mapped
Compare →SIG (Shared Assessments)
20%
18 controls mapped
Compare →PTES
20%
18 controls mapped
Compare →+ 239 more: OWASP SAMM (20%), OWASP MASVS (20%)
See all 242 mapped frameworks ↓Maps to 242 other frameworks
Coverage is not the same as your position
This page shows what ISO/IEC 27043:2015 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ISO/IEC 27043:2015 and who does it apply to?
ISO/IEC 27043:2015 is a compliance framework from International (ISO/IEC JTC 1/SC 27) with 8 domains and 37 controls. SC 27's harmonized model of digital investigation: readiness before an incident, initialization when one is detected, acquisition of potential digital evidence, investigation to a presented result, and the concurrent duties of authorization, documentation, chain of custody and preservation that run through all of it. 37 process leaves on the standard's own contents page; the held preview stops at clause 4, so the leaves sit at 60 to 70 with their basis on every node. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27043:2015 actually require?
ISO/IEC 27043:2015 has 37 controls organised across 8 domains. The largest domains are Clause 7: Readiness processes – ISO/IEC 27043:2015 (12 controls), Clause 10: Investigative processes – ISO/IEC 27043:2015 (6 controls), Clause 11: Concurrent processes – ISO/IEC 27043:2015 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27043:2015 do I already cover?
ISO/IEC 27043:2015 maps to 242 other compliance frameworks. The top mapping partners are SLSA (20% coverage), SIG (Shared Assessments) (20% coverage), PTES (20% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 27043:2015?
Start your ISO/IEC 27043:2015 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27043:2015 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required