Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.28

Collection of Evidence: A Practical Implementation Guide

Collect and preserve reliable evidence so incidents, disputes and legal actions can be supported.

This control concerns procedures for identifying, collecting, acquiring and preserving evidence related to information security events.

Practical interpretation: Evidence handling must protect integrity, provenance and legality. Copying logs into a ticket without documenting source, time and custody may make them unreliable.

What should the control achieve?

  • Potential evidence is recognized early.
  • Collection uses repeatable authorized methods.
  • Integrity and chain of custody are preserved.
  • Legal, privacy and retention requirements are considered.

Step-by-step implementation

1

Define evidence scenarios

Identify likely digital, physical and testimonial evidence.

2

Set authority and escalation

Specify who may collect, when specialists or Legal are required and jurisdiction limits.

3

Prepare procedures and tools

Document acquisition, imaging, export, hashing, labeling and secure storage.

4

Record chain of custody

Track collector, date, source, transfer, purpose and every handler.

5

Protect integrity

Use read-only methods, hashes, access restrictions and synchronized time.

6

Retain and dispose

Apply legal holds, retention and approved destruction.

What this could look like in practice

Following account compromise, a trained responder exports cloud audit logs through the provider’s validated function, records source and time range, calculates hashes and stores copies in a restricted evidence repository. Every transfer is logged.

ActivityPractical implementationEvidence
Log exportSource, query, time zone and hash are recorded.Evidence form
Device imageQualified responder uses approved imaging method.Image and tool log
Physical itemTamper-evident packaging and custody record are used.Custody form

Implementation evidence

  • Evidence procedure
  • Authorized collector list
  • Collection forms
  • Hashes
  • Chain-of-custody records
  • Restricted repository logs
  • Time-synchronization evidence
  • Retention and legal-hold records

Useful metrics

  • Incident evidence with complete custody
  • Unauthorized evidence access
  • Collection procedure tests
  • Evidence integrity verification failures

Common mistakes

  • Changing the original system during collection.
  • Missing time zone and clock context.
  • Using unapproved personal storage.
  • Collecting excessive personal data.
  • Failing to involve Legal when proceedings are possible.

Questions an auditor may ask

  • Who is authorized to collect evidence?
  • Show chain of custody for a recent case.
  • How is integrity verified?
  • How are legal holds and privacy handled?
Implementation test: Have a trained responder collect a sample cloud log and verify another person can reproduce provenance, integrity and custody.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.