GASP: AICF

Search controls

Search by control ID, name or domain

INC-007 Evidence Collection and Preservation

Tier 2+

Description

Procedures are in place to identify, collect, and preserve digital evidence related to security incidents. Evidence is collected in a manner that maintains chain of custody and supports potential legal proceedings. Evidence is stored securely and retained for a period consistent with regulatory and legal requirements.

Rationale

Evidence collected without chain of custody may be inadmissible in legal proceedings and insufficient for regulatory investigations. Establishing procedures before an incident ensures disciplined collection under pressure.

Framework Mappings (4)

SEF-09Incident Records Managementfull
GDPR-Art.33.5Internal Breach Documentationfull
5.28Collection of evidencefull
IR-4Incident Handlingpartial

Evidence (2)

policymanual

Evidence collection and preservation procedure defining how digital evidence is identified, collected, and stored with chain of custody to support legal proceedings.

Example: Digital Evidence Collection Procedure or IRP forensics annex (version-controlled, reviewed within last 12 months) specifying collection tools, chain of custody form, storage location, access controls, and retention period

Test: Request the evidence collection procedure. Verify: (1) a chain of custody process is defined with a named custodian role; (2) approved collection tools and methods are specified; (3) evidence storage requirements (integrity, access restriction, retention) are documented; (4) the procedure covers both cloud and endpoint evidence collection; (5) the document has been reviewed within the last 12 months.

recordmanual

Completed chain of custody records for evidence collected during past incidents, demonstrating the procedure was followed in practice.

Example: Chain of custody form or evidence register entry for the most recent incident requiring evidence collection, showing item description, collection date, collector identity, storage location, and access log

Test: Request chain of custody records for the last two incidents where evidence was collected. Verify: (1) a chain of custody form or register entry exists for each evidence item; (2) records include collection date, collector identity, and storage location; (3) evidence is stored in a restricted location with an access log; (4) evidence retention period is within regulatory and legal requirements.

Questions (2)

boolean

Are procedures in place to identify, collect, and preserve digital evidence related to security incidents in a manner that maintains chain of custody and supports potential legal proceedings?

Evidence collection procedures should specify approved tools, chain of custody requirements, storage location, access controls, and retention period aligned to legal and regulatory requirements.

multi

Which elements are included in your evidence collection and preservation procedure?

Defined chain of custody process with a named custodian roleApproved collection tools and methods specifiedSecure evidence storage with restricted access and access loggingDefined evidence retention period aligned to regulatory requirementsCoverage of cloud-based evidence (e.g. log exports, API call records, cloud resource snapshots)Coverage of endpoint evidence (e.g. memory capture, disk imaging)

Chain of custody and secure storage are the minimum requirements. Cloud-based evidence collection procedures are essential for SaaS incident response.