A.5.28 Collection of evidence
Have procedures to identify, collect, acquire and preserve evidence related to security events.
12
artefacts
3
held by a system
1
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Security incident ticket records · SIEM / log platform
- Hash verification logs · SIEM / log platform
- Custody transfer logs · SIEM / log platform
periodic reviewEvidence produced at each review
- Signed acknowledgment sheets · HR system / LMS
governing documentDocuments that govern the control
- Documented evidence collection procedure · Policy repository / GRC workspace
- Roles and responsibilities matrix for evidence handling · Policy repository / GRC workspace
- Approved evidence handling workflow diagram · Policy repository / GRC workspace
- Event timeline entries from SIEM · Policy repository / GRC workspace
- Incident summary reports · Policy repository / GRC workspace
- Digital forensic imaging report · Document repository
- Media preservation checklist · Policy repository / GRC workspace
- Completed chain of custody forms for seized devices · Policy repository / GRC workspace
First move
Start with the 3 of 12 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Procedures not aligned with legal requirements
- Missing documented chain of custody
- Inconsistent preservation of volatile data
- Lack of regular review and testing of evidence collection process
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.27 Learning from information security incidents · A.5.29 Information security during disruption