A.5.28
    Organizational Controls

    Collection of evidence

    The organization should establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.

    Purpose

    To ensure evidence is properly handled for potential legal or disciplinary proceedings.

    Implementation Guidance

    Define procedures for evidence collection and handling

    Maintain chain of custody documentation

    Ensure evidence integrity through proper preservation

    Train incident response team on forensics procedures

    Understand legal and regulatory evidence requirements

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.28 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.28 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.28 Collection of evidence. Built for compliance professionals.

    Try ISMS Copilot free