Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.5.28 Collection of Evidence

Control Objective

The organisation shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.

Policy Statement

anDREa enforces standardized procedures to identify, collect, and preserve digital evidence resulting from security events. This ensures operational accountability, regulatory compliance with NIS 2 and GDPR, and the legal admissibility of evidence if an incident escalates to forensic or judicial proceedings.


Evidence Intake and Registration

  • Centralized Logging: All security incidents and associated evidence are tracked via the Issues and Risk Logging system.
  • Email Ingestion: Incident reports received via direct email or sent to security@andrea-cloud.com are forwarded to the ticketing system. Responsibility for this registration lies with Quality & Assurance, under the supervision of the Management Team.
  • Workflow Activation: Registering a ticket triggers an automated workflow that assigns containment and evidence-gathering tasks to the response team. The response team is required to attach all relevant logs, communications, and digital artifacts directly to the active ticket.

Forensic Readiness & Chain of Custody

When an incident carries potential legal, regulatory, or forensic implications, anDREa invokes strict forensic preservation controls:

  • Isolation and Hashing: Affected assets (e.g., event logs, virtual machine snapshots) are isolated immediately to prevent modification. A cryptographic hash (e.g., SHA-256) is generated at the moment of collection to verify data integrity.
  • Forensic Preservation: When technically feasible, analysis is conducted exclusively on a bit-for-bit forensic image, keeping the original source media untouched.
  • Legal Hold: Standard automated data deletion policies and log rotation cycles are suspended for all assets relevant to the investigation. This hold remains in place until formally lifted by the Director.
  • Chain of Custody Tracking: Every transfer, review, or modification of the evidence is logged using a Chain of Custody Form attached to the ticket. This log mandatorily includes:
    • Date and timestamp of the action.
    • Full name and role of the handler.
    • Explicit purpose of access.
    • Cryptographic hash verification upon both receipt and release.

Data Retention & Archive Management

To protect the historical integrity of compliance evidence:

  • Immutability: Security incident logs within Issues and Risk Logging are permanent and cannot be deleted. They remain visible to the Management Team and the Support Team.
  • Accessing Archived Evidence: Inactive tickets are archived automatically over time. These records remain fully retrievable by navigating to the relevant department and selecting All Views > Archived > Archived tickets.