Skip to content
arrow_back
search
Annex A 5.28 verified ISO/IEC 27001:2022

Procedures for Collecting and Preserving Evidence

Set up clear steps to gather and maintain evidence of security incidents securely.

record_voice_over

Plain language

This control is about making sure your organisation has clear steps to collect and keep evidence when a security incident happens, like a data breach. If you don't do this, you might lose important information that could help solve the problem or even use in court if needed.

Framework

ISO/IEC 27001:2022

Control effect

Detective

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

The organization shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.
verified ISO/IEC 27001:2022 Annex A 5.28
priority_high

Why it matters

Without documented evidence handling (chain of custody), incident artefacts may be altered, lost, or rejected in legal or disciplinary action.

settings

Operational notes

Maintain evidence procedures: identify sources, collect and label artefacts, record chain of custody, use write-blocking, and store securely with integrity checks.

Mapping detail

Mapping

Direction

Controls