ISO/IEC 27001:2022 Annex A · Control 5.28
Collection of Evidence: A Practical Implementation Guide
Collect and preserve reliable evidence so incidents, disputes and legal actions can be supported.
This control concerns procedures for identifying, collecting, acquiring and preserving evidence related to information security events.
What should the control achieve?
- Potential evidence is recognized early.
- Collection uses repeatable authorized methods.
- Integrity and chain of custody are preserved.
- Legal, privacy and retention requirements are considered.
Step-by-step implementation
Define evidence scenarios
Identify likely digital, physical and testimonial evidence.
Set authority and escalation
Specify who may collect, when specialists or Legal are required and jurisdiction limits.
Prepare procedures and tools
Document acquisition, imaging, export, hashing, labeling and secure storage.
Record chain of custody
Track collector, date, source, transfer, purpose and every handler.
Protect integrity
Use read-only methods, hashes, access restrictions and synchronized time.
Retain and dispose
Apply legal holds, retention and approved destruction.
What this could look like in practice
Following account compromise, a trained responder exports cloud audit logs through the provider’s validated function, records source and time range, calculates hashes and stores copies in a restricted evidence repository. Every transfer is logged.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Log export | Source, query, time zone and hash are recorded. | Evidence form |
| Device image | Qualified responder uses approved imaging method. | Image and tool log |
| Physical item | Tamper-evident packaging and custody record are used. | Custody form |
Implementation evidence
- Evidence procedure
- Authorized collector list
- Collection forms
- Hashes
- Chain-of-custody records
- Restricted repository logs
- Time-synchronization evidence
- Retention and legal-hold records
Useful metrics
- Incident evidence with complete custody
- Unauthorized evidence access
- Collection procedure tests
- Evidence integrity verification failures
Common mistakes
- Changing the original system during collection.
- Missing time zone and clock context.
- Using unapproved personal storage.
- Collecting excessive personal data.
- Failing to involve Legal when proceedings are possible.
Questions an auditor may ask
- Who is authorized to collect evidence?
- Show chain of custody for a recent case.
- How is integrity verified?
- How are legal holds and privacy handled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.