ISO/IEC 27050-1:2019
ISO/IEC 27050-1:2019 is the overview and concepts part of the electronic discovery series: the terminology of ESI, custodians, legal holds, spoliation, provenance and chain of custody; the objectives and the five foundation principles of competency, candour, cooperation, completeness and proportionality; governance with its risk, compliance and privacy aspects; ICT readiness through long-term retention, confidentiality and controlled destruction of ESI; planning and budgeting a project; the types (active, inactive, residual, legacy), sources (custodian, non-custodian, potentially excluded) and representations (native, near-native, image, hardcopy) of ESI and non-ESI material; the seven process elements of identification, preservation, collection, processing, review, analysis and production; and presentation, chain of custody and provenance. Informative: no requirements; the requirements are in part 3, the governance guidance in part 2 and technical readiness in part 4. The foundation for legal hold, preservation and evidence-handling controls across the privacy, records and security frameworks.
ISO/IEC 27050-1:2019 is a compliance framework from International with 4 domains and 37 controls. The largest domains are Clause 6: Overview of electronic discovery – ISO/IEC 27050-1:2019 (15 controls), Clause 7: Electronically Stored Information (ESI) – ISO/IEC 27050-1:2019 (12 controls), Clause 8: Electronic discovery process – ISO/IEC 27050-1:2019 (8 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Clause 6: Overview of electronic discovery – ISO/IEC 27050-1:2019
| Code | Title |
|---|---|
| iso-iec-27050-1-2019::6.1 | Background: why electronic discovery matters and what the series does |
| iso-iec-27050-1-2019::6.2 | Basic concepts: the issues to consider in advance |
| iso-iec-27050-1-2019::6.3 | Objectives of electronic discovery |
| iso-iec-27050-1-2019::6.4.2 | Competency |
| iso-iec-27050-1-2019::6.4.3 | Candour |
| iso-iec-27050-1-2019::6.4.4 | Cooperation |
| iso-iec-27050-1-2019::6.4.5 | Completeness |
| iso-iec-27050-1-2019::6.4.6 | Proportionality |
| iso-iec-27050-1-2019::6.5.2 | Risk and environmental factors |
| iso-iec-27050-1-2019::6.5.3 | Compliance and review |
| iso-iec-27050-1-2019::6.5.4 | Privacy and data protection |
| iso-iec-27050-1-2019::6.6.2 | Long-term retention of ESI |
| iso-iec-27050-1-2019::6.6.3 | Maintaining ESI confidentiality |
| iso-iec-27050-1-2019::6.6.4 | Destruction of ESI |
| iso-iec-27050-1-2019::6.7 | Planning and budgeting an electronic discovery project |
Clause 7: Electronically Stored Information (ESI) – ISO/IEC 27050-1:2019
| Code | Title |
|---|---|
| iso-iec-27050-1-2019::7.2.2 | Active data |
| iso-iec-27050-1-2019::7.2.3 | Inactive data |
| iso-iec-27050-1-2019::7.2.4 | Residual data |
| iso-iec-27050-1-2019::7.2.5 | Legacy data |
| iso-iec-27050-1-2019::7.3.2 | Custodian data sources |
| iso-iec-27050-1-2019::7.3.3 | Non-custodian data sources |
| iso-iec-27050-1-2019::7.3.4 | Potentially excluded sources of ESI |
| iso-iec-27050-1-2019::7.4.2 | Native formats |
| iso-iec-27050-1-2019::7.4.3 | Near-native formats |
| iso-iec-27050-1-2019::7.4.4 | Image (near-paper) formats |
| iso-iec-27050-1-2019::7.4.5 | Hardcopy |
| iso-iec-27050-1-2019::7.5 | Non-ESI as part of discovery |
Clause 8: Electronic discovery process – ISO/IEC 27050-1:2019
| Code | Title |
|---|---|
| iso-iec-27050-1-2019::8.1 | Overview of the electronic discovery process |
| iso-iec-27050-1-2019::8.2 | ESI identification |
| iso-iec-27050-1-2019::8.3 | ESI preservation |
| iso-iec-27050-1-2019::8.4 | ESI collection |
| iso-iec-27050-1-2019::8.5 | ESI processing |
| iso-iec-27050-1-2019::8.6 | ESI review |
| iso-iec-27050-1-2019::8.7 | ESI analysis |
| iso-iec-27050-1-2019::8.8 | ESI production |
Clause 9: Additional considerations – ISO/IEC 27050-1:2019
| Code | Title |
|---|---|
| iso-iec-27050-1-2019::9.1 | Presentation of ESI |
| iso-iec-27050-1-2019::9.2 | Chain of custody and provenance |
What is ISO/IEC 27050-1:2019 and who does it apply to?
ISO/IEC 27050-1:2019 is a compliance framework from International with 4 domains and 37 controls. ISO/IEC 27050-1:2019 is the overview and concepts part of the electronic discovery series: the terminology of ESI, custodians, legal holds, spoliation, provenance and chain of custody; the objectives and the five foundation principles of competency, candour, cooperation, completeness and proportionality; governance with its risk, compliance and privacy aspects; ICT readiness through long-term retention, confidentiality and controlled destruction of ESI; planning and budgeting a project; the types (active, inactive, residual, legacy), sources (custodian, non-custodian, potentially excluded) and representations (native, near-native, image, hardcopy) of ESI and non-ESI material; the seven process elements of identification, preservation, collection, processing, review, analysis and production; and presentation, chain of custody and provenance. Informative: no requirements; the requirements are in part 3, the governance guidance in part 2 and technical readiness in part 4. The foundation for legal hold, preservation and evidence-handling controls across the privacy, records and security frameworks. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27050-1:2019 actually require?
ISO/IEC 27050-1:2019 has 37 controls organised across 4 domains. The largest domains are Clause 6: Overview of electronic discovery – ISO/IEC 27050-1:2019 (15 controls), Clause 7: Electronically Stored Information (ESI) – ISO/IEC 27050-1:2019 (12 controls), Clause 8: Electronic discovery process – ISO/IEC 27050-1:2019 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27050-1:2019 do I already cover?
ISO/IEC 27050-1:2019 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO/IEC 27050-1:2019?
Start your ISO/IEC 27050-1:2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27050-1:2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required