ISO/IEC 27000 Collection of Evidence, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to collection of evidence.

Assessment Step

1
Collection of Evidence (CollectionofEvidence)
Has the organization established and implemented procedures for the identification, collection, acquisition, and preservation of evidence related to information security events?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Collection of Evidence
The organization shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.
Citations
27001
Annex A, Control 5.28
27002
Section 5.28