Skip to content

Evidence request lists

ISO 27043

Evidence request list. 52 controls, 52 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Acquisitive

ISO27043-7.2
First Response Procedures

Procedures for responders to preserve volatile data and secure the scene.

Artefacts an auditor will ask for
  • Responder checklists
  • Volatile data scripts
  • Scene securing protocol
  • Responder training records
Where this commonly fails
  • Responders untrained
  • Volatile data lost
  • No scene protocol

Concluding

ISO27043-10.1
Storage and Retention of Evidence

Define retention periods and secure storage for closed-case evidence.

Artefacts an auditor will ask for
  • Retention schedule
  • Storage location register
  • Access logs
  • Disposal certificates
Where this commonly fails
  • No retention schedule
  • Evidence on shared drives
  • No disposal record
ISO27043-10.2
Evidence Disposal

Securely dispose of evidence when retention period ends.

Artefacts an auditor will ask for
  • Disposal procedure
  • Sanitization certificates
  • Destruction logs
  • Witness signoff
Where this commonly fails
  • Disposal informal
  • No certificate
  • Media reused without wiping
ISO27043-9.1
Presentation of Findings

Prepare findings reports suitable for technical, management, and legal audiences.

Artefacts an auditor will ask for
  • Report templates
  • Final reports
  • Executive summaries
  • Expert witness statements
Where this commonly fails
  • Reports too technical
  • No executive summary
  • No legal review
ISO27043-9.2
Closure of Investigation

Close investigation with documented outcomes, lessons, and evidence disposal plan.

Artefacts an auditor will ask for
  • Closure reports
  • Lessons learned records
  • Disposal schedule
  • Stakeholder signoff
Where this commonly fails
  • Cases left open
  • No lessons captured
  • Evidence retained indefinitely

Cross-cutting

ISO27043-11.1
Investigator Competence and Training

Ensure investigators have required skills, training, and certifications.

Artefacts an auditor will ask for
  • Training records
  • Certification copies
  • Competence matrix
  • Refresher schedule
Where this commonly fails
  • No certifications
  • Training stale
  • No competence assessment
ISO27043-11.2
Tool Validation

Validate forensic tools before use and re-validate after updates.

Artefacts an auditor will ask for
  • Tool validation records
  • Test datasets
  • Version control
  • Re-validation log
Where this commonly fails
  • Tools not validated
  • No test datasets
  • Updates unverified
ISO27043-11.3
Quality Assurance for Investigations

Apply QA review across investigation lifecycle to ensure rigor.

Artefacts an auditor will ask for
  • QA checklist
  • Reviewer signoff
  • Audit records
  • Continuous improvement notes
Where this commonly fails
  • No QA
  • Reviewer is investigator
  • No audit trail

ISO 27043: Access Control

ISO27043-11
Access control policy and enforcement

Access control policy and enforcement. Control from ISO 27043 framework, domain: ISO 27043: Access Control.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale
ISO27043-12
User access management and provisioning

User access management and provisioning. Control from ISO 27043 framework, domain: ISO 27043: Access Control.

Artefacts an auditor will ask for
  • Access control policy
  • Joiner/mover/leaver procedure
  • Privileged access register
  • Recertification report
Where this commonly fails
  • Orphan accounts persist
  • Recertification skipped
  • Privileged accounts not vaulted
ISO27043-13
Authentication and password management

Authentication and password management. Control from ISO 27043 framework, domain: ISO 27043: Access Control.

Artefacts an auditor will ask for
  • Access control policy
  • Joiner/mover/leaver procedure
  • Privileged access register
  • Recertification report
Where this commonly fails
  • Orphan accounts persist
  • Recertification skipped
  • Privileged accounts not vaulted
ISO27043-14
Privileged access management

Privileged access management. Control from ISO 27043 framework, domain: ISO 27043: Access Control.

Artefacts an auditor will ask for
  • Access control policy
  • Joiner/mover/leaver procedure
  • Privileged access register
  • Recertification report
Where this commonly fails
  • Orphan accounts persist
  • Recertification skipped
  • Privileged accounts not vaulted
ISO27043-15
Access review and recertification

Access review and recertification. Control from ISO 27043 framework, domain: ISO 27043: Access Control.

Artefacts an auditor will ask for
  • Access control policy
  • Joiner/mover/leaver procedure
  • Privileged access register
  • Recertification report
Where this commonly fails
  • Orphan accounts persist
  • Recertification skipped
  • Privileged accounts not vaulted

ISO 27043: Asset Management

ISO27043-06
Asset inventory and ownership

Asset inventory and ownership. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.

Artefacts an auditor will ask for
  • Asset inventory
  • Classification scheme
  • Acceptable use policy
  • Media handling procedure
Where this commonly fails
  • Inventory drift vs CMDB
  • Classification labels missing
  • Disposal records incomplete
ISO27043-07
Acceptable use of assets

Acceptable use of assets. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.

Artefacts an auditor will ask for
  • Asset inventory
  • Classification scheme
  • Acceptable use policy
  • Media handling procedure
Where this commonly fails
  • Inventory drift vs CMDB
  • Classification labels missing
  • Disposal records incomplete
ISO27043-08
Information classification and labeling

Information classification and labeling. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.

Artefacts an auditor will ask for
  • Asset inventory
  • Classification scheme
  • Acceptable use policy
  • Media handling procedure
Where this commonly fails
  • Inventory drift vs CMDB
  • Classification labels missing
  • Disposal records incomplete
ISO27043-09
Asset handling procedures

Asset handling procedures. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.

Artefacts an auditor will ask for
  • Asset inventory
  • Classification scheme
  • Acceptable use policy
  • Media handling procedure
Where this commonly fails
  • Inventory drift vs CMDB
  • Classification labels missing
  • Disposal records incomplete
ISO27043-10
Media management and disposal

Media management and disposal. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.

Artefacts an auditor will ask for
  • Asset inventory
  • Classification scheme
  • Acceptable use policy
  • Media handling procedure
Where this commonly fails
  • Inventory drift vs CMDB
  • Classification labels missing
  • Disposal records incomplete

ISO 27043: Communications Security

ISO27043-27
Network security management

Network security management. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.

Artefacts an auditor will ask for
  • Network architecture diagram
  • Segmentation policy
  • Data transfer agreement
  • Secure messaging standard
Where this commonly fails
  • Flat network in legacy zones
  • Transfer agreements missing for third parties
  • Messaging encryption not enforced
ISO27043-28
Network service security

Network service security. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.

Artefacts an auditor will ask for
  • Network architecture diagram
  • Segmentation policy
  • Data transfer agreement
  • Secure messaging standard
Where this commonly fails
  • Flat network in legacy zones
  • Transfer agreements missing for third parties
  • Messaging encryption not enforced
ISO27043-29
Segregation in networks

Segregation in networks. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.

Artefacts an auditor will ask for
  • Network architecture diagram
  • Segmentation policy
  • Data transfer agreement
  • Secure messaging standard
Where this commonly fails
  • Flat network in legacy zones
  • Transfer agreements missing for third parties
  • Messaging encryption not enforced
ISO27043-30
Information transfer policies

Information transfer policies. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale
ISO27043-31
Secure messaging

Secure messaging. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.

Artefacts an auditor will ask for
  • Network architecture diagram
  • Segmentation policy
  • Data transfer agreement
  • Secure messaging standard
Where this commonly fails
  • Flat network in legacy zones
  • Transfer agreements missing for third parties
  • Messaging encryption not enforced

ISO 27043: Cryptography

ISO27043-16
Cryptographic policy and key management

Cryptographic policy and key management. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale
ISO27043-17
Encryption of data at rest

Encryption of data at rest. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.

Artefacts an auditor will ask for
  • Cryptographic policy
  • Key management procedure
  • Certificate inventory
  • Algorithm catalogue
Where this commonly fails
  • No defined key rotation cadence
  • Self-signed certs in production
  • Algorithm catalogue not updated
ISO27043-18
Encryption of data in transit

Encryption of data in transit. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.

Artefacts an auditor will ask for
  • Cryptographic policy
  • Key management procedure
  • Certificate inventory
  • Algorithm catalogue
Where this commonly fails
  • No defined key rotation cadence
  • Self-signed certs in production
  • Algorithm catalogue not updated
ISO27043-19
Certificate management

Certificate management. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.

Artefacts an auditor will ask for
  • Cryptographic policy
  • Key management procedure
  • Certificate inventory
  • Algorithm catalogue
Where this commonly fails
  • No defined key rotation cadence
  • Self-signed certs in production
  • Algorithm catalogue not updated
ISO27043-20
Key lifecycle management

Key lifecycle management. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.

Artefacts an auditor will ask for
  • Cryptographic policy
  • Key management procedure
  • Certificate inventory
  • Algorithm catalogue
Where this commonly fails
  • No defined key rotation cadence
  • Self-signed certs in production
  • Algorithm catalogue not updated

ISO 27043: Information Security Policies

ISO27043-01
Information security policy framework

Information security policy framework. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale
ISO27043-02
Management direction and commitment

Management direction and commitment. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale
ISO27043-03
Policy review and update procedures

Policy review and update procedures. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale
ISO27043-04
Roles and responsibilities definition

Roles and responsibilities definition. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale
ISO27043-05
Contact with authorities and special interest groups

Contact with authorities and special interest groups. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.

Artefacts an auditor will ask for
  • Information security policy
  • Policy review log
  • Roles and responsibilities matrix
  • Authority contact register
Where this commonly fails
  • Policy not reviewed annually
  • Roles unclear at the working level
  • External contacts stale

ISO 27043: Operations Security

ISO27043-21
Operational procedures and responsibilities

Operational procedures and responsibilities. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.

Artefacts an auditor will ask for
  • Operations runbook
  • Backup test report
  • SIEM log review
  • Vulnerability scan report
Where this commonly fails
  • Backup restores not tested
  • Log coverage gaps
  • Vulnerabilities not remediated within SLA
ISO27043-22
Protection from malware

Protection from malware. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.

Artefacts an auditor will ask for
  • Operations runbook
  • Backup test report
  • SIEM log review
  • Vulnerability scan report
Where this commonly fails
  • Backup restores not tested
  • Log coverage gaps
  • Vulnerabilities not remediated within SLA
ISO27043-23
Backup and recovery procedures

Backup and recovery procedures. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.

Artefacts an auditor will ask for
  • Operations runbook
  • Backup test report
  • SIEM log review
  • Vulnerability scan report
Where this commonly fails
  • Backup restores not tested
  • Log coverage gaps
  • Vulnerabilities not remediated within SLA
ISO27043-24
Logging and monitoring

Logging and monitoring. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.

Artefacts an auditor will ask for
  • Operations runbook
  • Backup test report
  • SIEM log review
  • Vulnerability scan report
Where this commonly fails
  • Backup restores not tested
  • Log coverage gaps
  • Vulnerabilities not remediated within SLA
ISO27043-25
Technical vulnerability management

Technical vulnerability management. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.

Artefacts an auditor will ask for
  • Operations runbook
  • Backup test report
  • SIEM log review
  • Vulnerability scan report
Where this commonly fails
  • Backup restores not tested
  • Log coverage gaps
  • Vulnerabilities not remediated within SLA
ISO27043-26
Audit considerations

Audit considerations. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.

Artefacts an auditor will ask for
  • Operations runbook
  • Backup test report
  • SIEM log review
  • Vulnerability scan report
Where this commonly fails
  • Backup restores not tested
  • Log coverage gaps
  • Vulnerabilities not remediated within SLA

Improvement

ISO27043-12.1
Continuous Improvement of Investigation Process

Capture lessons and update processes, tools, and training continuously.

Artefacts an auditor will ask for
  • Lessons register
  • Process updates
  • Training updates
  • Metrics dashboard
Where this commonly fails
  • Lessons not actioned
  • Process static
  • No metrics

Initialization

ISO27043-7.1
Incident Detection Trigger

Defined triggers that initiate a digital investigation process.

Artefacts an auditor will ask for
  • Detection use cases
  • Trigger criteria document
  • SOC handoff procedure
  • Investigation initiation form
Where this commonly fails
  • No formal trigger
  • SOC keeps cases
  • No initiation record

Investigative

ISO27043-8.1
Planning the Investigation

Plan investigation scope, objectives, resources, and timeline.

Artefacts an auditor will ask for
  • Investigation plan template
  • Approved plans
  • Resource assignment
  • Objective statements
Where this commonly fails
  • No plan
  • Scope creep
  • Resources insufficient
ISO27043-8.2
Evidence Identification and Collection

Identify, prioritize, and collect digital evidence using sound methods.

Artefacts an auditor will ask for
  • Collection logs
  • Tool validation records
  • Write blocker use evidence
  • Acquisition images
Where this commonly fails
  • No write blockers
  • Tool versions unrecorded
  • Collection order arbitrary
ISO27043-8.3
Chain of Custody

Maintain unbroken chain of custody for all evidence items.

Artefacts an auditor will ask for
  • Chain of custody forms
  • Evidence bag seals
  • Hash values
  • Transfer logs
Where this commonly fails
  • Forms incomplete
  • No hashing
  • Transfers undocumented
ISO27043-8.4
Evidence Preservation

Preserve evidence integrity throughout the investigation lifecycle.

Artefacts an auditor will ask for
  • Evidence safe access logs
  • Hash verification at each step
  • Environmental controls
  • Backup of evidence
Where this commonly fails
  • No safe
  • Hashes not reverified
  • Evidence shared by email
ISO27043-8.5
Evidence Analysis

Analyze evidence using validated tools and reproducible methods.

Artefacts an auditor will ask for
  • Analysis notes
  • Tool output
  • Reproducibility evidence
  • Peer review records
Where this commonly fails
  • No peer review
  • Tools not validated
  • Methods not documented
ISO27043-8.6
Investigation Documentation

Document each step, decision, and observation during the investigation.

Artefacts an auditor will ask for
  • Investigator notebooks
  • Timestamped logs
  • Decision register
  • Photo records
Where this commonly fails
  • Notes informal
  • No timestamps
  • Decisions undocumented

Readiness

ISO27043-5.1
Forensic Readiness Policy

Establish a forensic readiness policy stating objectives, scope, and management commitment.

Artefacts an auditor will ask for
  • Approved forensic readiness policy
  • Management endorsement
  • Review schedule
  • Scope statement
Where this commonly fails
  • No standalone policy
  • Policy not reviewed
  • Scope excludes cloud
ISO27043-5.2
Roles and Responsibilities for Investigations

Define roles for investigators, custodians, legal counsel, and management.

Artefacts an auditor will ask for
  • RACI for investigations
  • Investigator appointment letters
  • Legal contact list
  • Custodian register
Where this commonly fails
  • No investigator role
  • Legal not engaged early
  • Custodians unidentified
ISO27043-5.3
Forensic Capability Assessment

Assess in-house and external forensic capabilities and identify gaps.

Artefacts an auditor will ask for
  • Capability matrix
  • Tool inventory
  • External provider contracts
  • Gap analysis
Where this commonly fails
  • No external retainer
  • Tools unlicensed
  • Capability untested
ISO27043-6.1
Pre-incident Readiness Processes

Implement processes to prepare evidence sources before incidents occur.

Artefacts an auditor will ask for
  • Logging architecture
  • Retention policy
  • Time sync evidence
  • Evidence source map
Where this commonly fails
  • Logs overwritten
  • No NTP
  • Evidence sources unmapped
ISO27043-6.2
Identification of Potential Digital Evidence

Identify systems and data likely to contain evidence relevant to investigations.

Artefacts an auditor will ask for
  • Evidence source catalogue
  • Data flow diagrams
  • Application log map
  • Cloud evidence sources
Where this commonly fails
  • SaaS evidence unknown
  • Mobile excluded
  • Endpoint logs missing
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27043 framework page.