ISO 27001A.5 — Collection of evidence
A.5.28
Collection of evidence
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Collect, retain, and present evidence related to information security events and incidents for investigations and actions.
Points of focus
- Evidence sources identified
- Preservation steps in IR runbooks
- Chain-of-custody / access control to evidence
- Retention aligned to legal and operational needs
Implementation notes
Document where authoritative evidence lives (SIEM, IdP, cloud audit trails, tickets). Train responders to snapshot before remediation when feasible. Restrict evidence stores to IR/legal roles. Coordinate with counsel on holds. Align retention with A.8.15 logging and privacy limits — keep what investigations need, not everything forever.
Audit tip: Walk how you would freeze logs and access records for a suspected account takeover.
Evidence auditors typically request:
- IR evidence-handling procedure
- Log retention configuration
- Sample evidence package from an incident
- Legal hold process reference
Common gaps
- Logs rotated away before investigation finishes
- Everyone has write access to evidence buckets
- No guidance on cloud snapshot preservation
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.28 | This control |
| SOC 2 | CC7.4 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.28)
Frequently Asked Questions
Not required by 27001 for all teams. Have a procedure and specialist retainer for serious cases.
Yes as part of the package — pair them with immutable technical logs where available.
Evidence containing personal data still needs purpose limitation; involve privacy when packaging exports.