Skip to content
arrow_back
search
ISM-0138 policy ASD Information Security Manual (ISM)

Ensure Integrity of Evidence in Investigations

Investigators ensure evidence stays intact during investigations by documenting actions and following legal guidelines.

record_voice_over

Plain language

When you're investigating something like a cyber incident, it's crucial that any evidence you gather stays exactly as it was found. If this evidence gets tampered with, even accidentally, it can weaken your case or make it inadmissible if legal action is needed. Think of it as making sure no one moves or messes with anything at a crime scene until the investigation is complete.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The integrity of evidence gathered during an investigation is maintained by investigators: - recording all of their actions - maintaining a proper chain of custody - following all instructions provided by relevant law enforcement agencies.
policy ASD Information Security Manual (ISM) ISM-0138
priority_high

Why it matters

Compromised evidence can sabotage investigations, leading to failed legal actions and damaged organisational reputation.

settings

Operational notes

Train investigators on evidence handling, chain of custody and action logging; use tamper-evident storage and follow any law enforcement instructions.

Mapping detail

Mapping

Direction

Controls