Skip to content
arrow_back
ISM-0138policyASD Information Security Manual (ISM)

Maintaining Integrity of Evidence in Investigations

Investigators keep evidence intact by documenting actions, ensuring custody, and following law enforcement guidance.

record_voice_over

Plain language

When investigating a cyber incident, it's crucial to keep evidence untouched and properly documented. If evidence is mishandled, it could lead to the wrong conclusions, legal issues, or the culprit remaining unidentified.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The integrity of evidence gathered during an investigation is maintained by investigators: - recording all their actions - maintaining a proper chain of custody - following all instructions provided by relevant law enforcement agencies.
policyASD Information Security Manual (ISM)ISM-0138
priority_high

Why it matters

If investigation evidence isn't preserved properly, it can lead to failed prosecutions, mishandled incidents, and loss of trust with stakeholders.

settings

Operational notes

Regularly check that staff adhere to evidence handling procedures and update them on any changes in legal requirements or best practices.

build

Implementation tips

  • Investigators should keep a detailed log of every action they take during an investigation. Document each step immediately to avoid forgetting details; use a digital or physical logbook.
  • The office manager should assign a responsible person to oversee the chain of custody for evidence. Ensure this person is trained in documenting who handles evidence, from first collection to storage.
  • IT staff should consult closely with law enforcement when handling evidence. Follow explicit instructions to ensure evidence is admissible in court if needed, maintaining communication through clear channels.
  • Managers need to set up a regular review process of evidence handling procedures. This involves scheduling bi-annual meetings to update staff on best practices and any changes in policy or law.
  • The HR team should provide staff training on the importance of evidence integrity. This could be part of an induction program or an annual refresher course, highlighting real-world consequences of negligence.
fact_check

Audit / evidence tips

  • Askthe detailed log of actions taken during a specific investigationLook atthe completeness and timeliness of the entriesGoodAll actions are described clearly, with times and dates
  • GoodClear, consistent record showing every person involved
  • Askto see communication records between the organisation and law enforcementLook atacknowledgement from law enforcement of instructions givenGoodDocumented guidelines and dates of communication
  • Look atattendance records and training materialsGoodRegular sessions with high staff attendance and comprehensive content
  • Askthe policy document governing evidence integrityLook atrecent updates and approval signaturesGoodDocument is current, with a clear review history and compliance with legal standards
link

Cross-framework mappings

How ISM-0138 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 5.28ISM-0138 requires investigators to preserve the integrity of investigation evidence by recording actions, maintaining chain of custody, a...
handshakeSupports(3)expand_less
Annex A 5.5ISM-0138 mandates that investigators maintain evidence integrity and follow instructions from law enforcement
Annex A 5.26ISM-0138 ensures evidence integrity through documented actions and chain of custody in line with law enforcement directions
Annex A 8.15ISM-0138 mandates evidentiary integrity through documentation of actions and chain of custody

E8

ControlNotesDetails
handshakeSupports(1)expand_less
E8-AH-ML2.13E8-AH-ML2.13 requires protecting event logs from unauthorised modification and deletion, helping ensure logs can be relied on during inci...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security incidents controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls