ISO27001:2022 – A5.28 Collection of Evidence
Introduction to ISO 27001 – A5.28
ISO 27001 – A5.28 should not be read in isolation. It is closely related to:
- A5.24 – Information security incident management planning and preparation
- A5.25 – Assessment and decision on information security events
- A5.26 – Response to information security incidents
- A5.27 – Learning from information security incidents
- A5.29 – Information security during disruption
- A5.30 – ICT Readiness for Business Continuity
What does ISO 27001 – A5.28 require?
“The organisation shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.”
(ISO 27001 – A5.28 – Collection of Evidence)
Why is this required?
If your organisation is ever involved in a cyber incident or internal security breach, having accurate and verifiable evidence is critical. Whether it’s for an internal disciplinary, insurance claim, or legal proceedings, you must be able to prove what happened — and that depends on a secure and reliable process for collecting and preserving evidence.
What the auditor is looking for
Auditors will expect to see a documented procedure covering:
- Who is responsible for collecting evidence
- Rules and tools for acquiring digital evidence
- Steps taken to preserve the integrity of evidence
- Examples or case studies (if available) of past incident responses
What do you need to do?
Although not mandated, we strongly recommend a separate evidence collection procedure to accompany your Incident Response Plan or BCP. Your document should include:
Types of Evidence to Consider:
- CCTV footage
- Telephone call recordings
- System and access logs
- Audit trails
- Malware samples or infected files
- Screenshots or screen recordings
- Witness statements or interviews
Key Guidelines to Include:
- Only trained personnel may collect or access digital evidence
- Digital forensic tools or procedures should be outlined
- Clearly define what constitutes integrity and how it’s maintained
- Log all actions and restrict access to original sources
Remember: even copying a log file can alter metadata. So procedures must be detailed and followed precisely to ensure evidence holds up under scrutiny — internally or in court.
Q & A
Does this need to be documented?
Yes — even though not explicitly required, a clearly documented process will ensure consistency and prepare you for potential legal or regulatory inquiries.
How can we ensure the integrity of information?
Quarantine affected devices. Ensure access is restricted. Take logs, screenshots, or downloads only using approved tools or forensic methods. Chain-of-custody tracking is essential for maintaining the trustworthiness of evidence.
Difficulty Rating
3 out of 5 – While the requirement is conceptually simple, implementation can be technically demanding. You’ll need input from IT, legal, and operational teams to ensure the evidence chain is sound and legally defensible.
More Questions?
Don’t forget — ISO27001 controls are interconnected. For broader context, check out our guide and related posts. And if you’re stuck, feel free to contact us directly.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” — available now on Amazon.
