Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.27 Collecting evidence

Control Overview

This control mandates that the organization establishes structured procedures for the identification, collection, and preservation of digital evidence following a security incident. To prevent organizational, financial, or legal damage caused by a lack of traceable data, evidence must be handled in a manner that protects its integrity, availability, and confidentiality. The process must follow strict forensic standards to ensure that logs, artifacts, and system states can be used to determine the root cause of an incident or be submitted as legally defensible evidence to competent authorities, courts, or third-party auditors.

note

Applicability Note: This control is fully applicable to the anDREa platform and governs forensic data collection across all internal corporate tools and virtual client environments.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement incorporates forensic preservation directly into our ISO/IEC 27001-based ISMS, moving beyond basic log storage to a state of comprehensive forensic readiness.

Rather than capturing evidence on an ad-hoc basis, anDREa enforces an explicit Forensic Readiness & Chain of Custody protocol. When an incident occurs, our tracking workflows mandate that all relevant logs, memory dumps, and communications are traceably attached to our secure ticketing system. To ensure compliance with legal and regulatory standards, the framework introduces rigorous forensic protections: compromised environments are isolated, cryptographic hashing is applied to prevent data tampering, bit-for-bit disk imaging is performed where applicable, and a formal Legal Hold mechanism is activated to immediately suspend automated data deletion or rotation schedules.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.28 - Collection of evidenceMandates that the organization establishes and implements procedures for the identification, collection, acquisition, and preservation of digital evidence.
ISO/IEC 27001A.05.29 - Information security during disruptionEnforces that information security baselines and data integrity controls are maintained even during active operational disruptions.
Forensic StandardsForensic Readiness & Chain of Custody ProtocolThe authoritative technical manual detailing isolation steps, cryptographic hashing, bit-for-bit imaging, and data-integrity verification tracking forms.
Legal FrameworkLegal Hold Activation ProcedureThe administrative workflow that overrides standard retention cycles, ensuring critical incident data cannot be purged automatically. (Retention & Destruction Policy)
Operational RegistryIssues and Risk LoggingThe secure, unalterable internal system where collected evidence files are centrally aggregated, timestamped, and archived.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Forensic readiness protocols, unalterable ticket attachments, cryptographic hashing baselines, and legal hold procedures are fully defined and active. Continuous Improvement: To ensure seamless execution during a crisis, incorporate specific chain-of-custody and evidence-handling training into the periodic training schedule for technical personnel who are likely to act as first responders.