View Categories

A5.28 Collection of evidence

3 min read

When a security incident occurs, properly collecting and preserving digital evidence is crucial for investigations, legal actions, and compliance. ISO 27001 emphasizes that organizations must have a structured process to ensure that evidence is reliable, admissible in court, and free from tampering.

Evidence collection is essential in cases of:

  • Cybercrime (hacking, phishing, ransomware, fraud)
  • Insider threats (data leaks, unauthorized access)
  • Regulatory investigations (GDPR, HIPAA violations, financial fraud)

A well-defined evidence collection strategy ensures accurate attribution, prevents evidence tampering, and supports internal audits or legal proceedings.

Implementation Guide #

Step 1: Define an Evidence Collection Policy

  • Establish clear guidelines for collecting, handling, and preserving digital evidence.
  • Assign roles and responsibilities for IT, security, and legal teams.
  • Ensure compliance with legal requirements (e.g., GDPR, ISO 27037, NIST 800-86).

Step 2: Secure the Scene (Digital or Physical)

  • Isolate affected systems to prevent further damage or evidence loss.
  • Preserve logs, network activity, and user access records.
  • If necessary, disconnect a compromised device but do not power it off (to avoid losing volatile memory data).

Step 3: Capture and Preserve Digital Evidence

  • Log Files: Preserve SIEM logs, firewall logs, system access records.
  • Hard Drive & Storage Data: Use forensic imaging tools to create an exact copy (write-blockers ensure data integrity).
  • Memory Dump: Capture RAM contents to analyze malware, encryption keys, or active sessions (Tools: Volatility, FTK Imager).
  • Network Traffic: Use packet capture tools (Wireshark, tcpdump) to trace suspicious activities.
  • Emails & Communications: Secure copies of phishing emails, chat logs, and insider messages.

Step 4: Maintain Chain of Custody

To ensure evidence remains credible, document every step:

  • Who collected the evidence?
  • Where and when was it collected?
  • How was it stored?
  • Who accessed it?

Use digital forensic tools like Autopsy, EnCase, X-Ways Forensics to generate reports.

Step 5: Analyze and Report Findings

  • Conduct forensic analysis to determine attack origin, techniques, and impact.
  • Correlate evidence with security logs, access records, and incident timelines.
  • Prepare a detailed report outlining the findings, supporting legal or internal investigations.

Example Scenario #

Incident: A company discovers that sensitive customer data was leaked online.

Actions Taken:

  1. Logs are secured from the affected database and application servers.
  2. Forensic imaging of compromised systems is performed using Autopsy.
  3. Email records of employees with database access are collected.
  4. Network traffic analysis confirms an external connection to an unknown IP.
  5. Evidence is documented and shared with legal authorities.

Common Mistakes in Evidence Collection #

  • Tampering with original data – Always work on forensic copies.
  • Failing to document the chain of custody – This can render evidence inadmissible in court.
  • Not preserving volatile data – RAM and network logs can be lost if not captured immediately.
  • Ignoring legal requirements – Ensure compliance with data protection laws and corporate policies.

Templates for Implementation #

  • Digital Evidence Collection Checklist
  • Incident Chain of Custody Form
  • Forensic Analysis Report Template

How to Pass an Audit #

Key Documents to Prepare:

  • Logs of past security incidents and forensic reports.
  • Chain of custody documentation for all collected evidence.
  • List of tools and methods used for evidence collection.

What the Auditor Will Check:

  • Does the organization have a structured approach to collecting and preserving evidence?
  • Are legal and compliance requirements met when handling digital evidence?
  • Is the chain of custody well-documented?

ISO 27001 Controls and Attribute Values #

Control Attribute Value
A.5.28 Collection of Evidence Detective, Corrective, Legal, Compliance-Based
Purpose Ensure proper collection, preservation, and handling of digital evidence
Applicability Organizations handling sensitive or regulated data
ISO 27001 Domains Incident Response, Forensics, Compliance, Risk Management

Without proper evidence collection, organizations risk legal challenges, compliance violations, and repeated security incidents. Implementing a forensically sound evidence collection process strengthens cybersecurity resilience and ensures accountability.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now