Maintaining Integrity of Evidence in Investigations
Investigators keep evidence intact by documenting actions, ensuring custody, and following law enforcement guidance.
Plain language
When investigating a cyber incident, it's crucial to keep evidence untouched and properly documented. If evidence is mishandled, it could lead to the wrong conclusions, legal issues, or the culprit remaining unidentified.
Framework
ASD Information Security Manual (ISM)
Control effect
Responsive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
The integrity of evidence gathered during an investigation is maintained by investigators: - recording all their actions - maintaining a proper chain of custody - following all instructions provided by relevant law enforcement agencies.
Why it matters
If investigation evidence isn't preserved properly, it can lead to failed prosecutions, mishandled incidents, and loss of trust with stakeholders.
Operational notes
Regularly check that staff adhere to evidence handling procedures and update them on any changes in legal requirements or best practices.
Implementation tips
- Investigators should keep a detailed log of every action they take during an investigation. Document each step immediately to avoid forgetting details; use a digital or physical logbook.
- The office manager should assign a responsible person to oversee the chain of custody for evidence. Ensure this person is trained in documenting who handles evidence, from first collection to storage.
- IT staff should consult closely with law enforcement when handling evidence. Follow explicit instructions to ensure evidence is admissible in court if needed, maintaining communication through clear channels.
- Managers need to set up a regular review process of evidence handling procedures. This involves scheduling bi-annual meetings to update staff on best practices and any changes in policy or law.
- The HR team should provide staff training on the importance of evidence integrity. This could be part of an induction program or an annual refresher course, highlighting real-world consequences of negligence.
Audit / evidence tips
- Askthe detailed log of actions taken during a specific investigationLook atthe completeness and timeliness of the entriesGoodAll actions are described clearly, with times and dates
- GoodClear, consistent record showing every person involved
- Askto see communication records between the organisation and law enforcementLook atacknowledgement from law enforcement of instructions givenGoodDocumented guidelines and dates of communication
- Look atattendance records and training materialsGoodRegular sessions with high staff attendance and comprehensive content
- Askthe policy document governing evidence integrityLook atrecent updates and approval signaturesGoodDocument is current, with a clear review history and compliance with legal standards
Cross-framework mappings
How ISM-0138 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 5.28 | ISM-0138 requires investigators to preserve the integrity of investigation evidence by recording actions, maintaining chain of custody, a... | |
handshakeSupports(3)expand_less | ||
| Annex A 5.5 | ISM-0138 mandates that investigators maintain evidence integrity and follow instructions from law enforcement | |
| Annex A 5.26 | ISM-0138 ensures evidence integrity through documented actions and chain of custody in line with law enforcement directions | |
| Annex A 8.15 | ISM-0138 mandates evidentiary integrity through documentation of actions and chain of custody | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| E8-AH-ML2.13 | E8-AH-ML2.13 requires protecting event logs from unauthorised modification and deletion, helping ensure logs can be relied on during inci... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security incidents
See all Guidelines for cyber security incidents controls, or browse the full ASD ISM library.