A5.28 Collection of evidence
3 min read
When a security incident occurs, properly collecting and preserving digital evidence is crucial for investigations, legal actions, and compliance. ISO 27001 emphasizes that organizations must have a structured process to ensure that evidence is reliable, admissible in court, and free from tampering.
Evidence collection is essential in cases of:
- Cybercrime (hacking, phishing, ransomware, fraud)
- Insider threats (data leaks, unauthorized access)
- Regulatory investigations (GDPR, HIPAA violations, financial fraud)
A well-defined evidence collection strategy ensures accurate attribution, prevents evidence tampering, and supports internal audits or legal proceedings.
Implementation Guide #
Step 1: Define an Evidence Collection Policy
- Establish clear guidelines for collecting, handling, and preserving digital evidence.
- Assign roles and responsibilities for IT, security, and legal teams.
- Ensure compliance with legal requirements (e.g., GDPR, ISO 27037, NIST 800-86).
Step 2: Secure the Scene (Digital or Physical)
- Isolate affected systems to prevent further damage or evidence loss.
- Preserve logs, network activity, and user access records.
- If necessary, disconnect a compromised device but do not power it off (to avoid losing volatile memory data).
Step 3: Capture and Preserve Digital Evidence
- Log Files: Preserve SIEM logs, firewall logs, system access records.
- Hard Drive & Storage Data: Use forensic imaging tools to create an exact copy (write-blockers ensure data integrity).
- Memory Dump: Capture RAM contents to analyze malware, encryption keys, or active sessions (Tools: Volatility, FTK Imager).
- Network Traffic: Use packet capture tools (Wireshark, tcpdump) to trace suspicious activities.
- Emails & Communications: Secure copies of phishing emails, chat logs, and insider messages.
Step 4: Maintain Chain of Custody
To ensure evidence remains credible, document every step:
- Who collected the evidence?
- Where and when was it collected?
- How was it stored?
- Who accessed it?
Use digital forensic tools like Autopsy, EnCase, X-Ways Forensics to generate reports.
Step 5: Analyze and Report Findings
- Conduct forensic analysis to determine attack origin, techniques, and impact.
- Correlate evidence with security logs, access records, and incident timelines.
- Prepare a detailed report outlining the findings, supporting legal or internal investigations.
Example Scenario #
Incident: A company discovers that sensitive customer data was leaked online.
Actions Taken:
- Logs are secured from the affected database and application servers.
- Forensic imaging of compromised systems is performed using Autopsy.
- Email records of employees with database access are collected.
- Network traffic analysis confirms an external connection to an unknown IP.
- Evidence is documented and shared with legal authorities.
Common Mistakes in Evidence Collection #
- Tampering with original data – Always work on forensic copies.
- Failing to document the chain of custody – This can render evidence inadmissible in court.
- Not preserving volatile data – RAM and network logs can be lost if not captured immediately.
- Ignoring legal requirements – Ensure compliance with data protection laws and corporate policies.
Templates for Implementation #
- Digital Evidence Collection Checklist
- Incident Chain of Custody Form
- Forensic Analysis Report Template
How to Pass an Audit #
Key Documents to Prepare:
- Logs of past security incidents and forensic reports.
- Chain of custody documentation for all collected evidence.
- List of tools and methods used for evidence collection.
What the Auditor Will Check:
- Does the organization have a structured approach to collecting and preserving evidence?
- Are legal and compliance requirements met when handling digital evidence?
- Is the chain of custody well-documented?
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.5.28 Collection of Evidence | Detective, Corrective, Legal, Compliance-Based |
| Purpose | Ensure proper collection, preservation, and handling of digital evidence |
| Applicability | Organizations handling sensitive or regulated data |
| ISO 27001 Domains | Incident Response, Forensics, Compliance, Risk Management |
Without proper evidence collection, organizations risk legal challenges, compliance violations, and repeated security incidents. Implementing a forensically sound evidence collection process strengthens cybersecurity resilience and ensures accountability.