ISO 27043
Evidence request list. 52 controls, 52 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Acquisitive
Procedures for responders to preserve volatile data and secure the scene.
- Responder checklists
- Volatile data scripts
- Scene securing protocol
- Responder training records
- Responders untrained
- Volatile data lost
- No scene protocol
Concluding
Define retention periods and secure storage for closed-case evidence.
- Retention schedule
- Storage location register
- Access logs
- Disposal certificates
- No retention schedule
- Evidence on shared drives
- No disposal record
Securely dispose of evidence when retention period ends.
- Disposal procedure
- Sanitization certificates
- Destruction logs
- Witness signoff
- Disposal informal
- No certificate
- Media reused without wiping
Prepare findings reports suitable for technical, management, and legal audiences.
- Report templates
- Final reports
- Executive summaries
- Expert witness statements
- Reports too technical
- No executive summary
- No legal review
Close investigation with documented outcomes, lessons, and evidence disposal plan.
- Closure reports
- Lessons learned records
- Disposal schedule
- Stakeholder signoff
- Cases left open
- No lessons captured
- Evidence retained indefinitely
Cross-cutting
Ensure investigators have required skills, training, and certifications.
- Training records
- Certification copies
- Competence matrix
- Refresher schedule
- No certifications
- Training stale
- No competence assessment
Validate forensic tools before use and re-validate after updates.
- Tool validation records
- Test datasets
- Version control
- Re-validation log
- Tools not validated
- No test datasets
- Updates unverified
Apply QA review across investigation lifecycle to ensure rigor.
- QA checklist
- Reviewer signoff
- Audit records
- Continuous improvement notes
- No QA
- Reviewer is investigator
- No audit trail
ISO 27043: Access Control
Access control policy and enforcement. Control from ISO 27043 framework, domain: ISO 27043: Access Control.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
User access management and provisioning. Control from ISO 27043 framework, domain: ISO 27043: Access Control.
- Access control policy
- Joiner/mover/leaver procedure
- Privileged access register
- Recertification report
- Orphan accounts persist
- Recertification skipped
- Privileged accounts not vaulted
Authentication and password management. Control from ISO 27043 framework, domain: ISO 27043: Access Control.
- Access control policy
- Joiner/mover/leaver procedure
- Privileged access register
- Recertification report
- Orphan accounts persist
- Recertification skipped
- Privileged accounts not vaulted
Privileged access management. Control from ISO 27043 framework, domain: ISO 27043: Access Control.
- Access control policy
- Joiner/mover/leaver procedure
- Privileged access register
- Recertification report
- Orphan accounts persist
- Recertification skipped
- Privileged accounts not vaulted
Access review and recertification. Control from ISO 27043 framework, domain: ISO 27043: Access Control.
- Access control policy
- Joiner/mover/leaver procedure
- Privileged access register
- Recertification report
- Orphan accounts persist
- Recertification skipped
- Privileged accounts not vaulted
ISO 27043: Asset Management
Asset inventory and ownership. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.
- Asset inventory
- Classification scheme
- Acceptable use policy
- Media handling procedure
- Inventory drift vs CMDB
- Classification labels missing
- Disposal records incomplete
Acceptable use of assets. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.
- Asset inventory
- Classification scheme
- Acceptable use policy
- Media handling procedure
- Inventory drift vs CMDB
- Classification labels missing
- Disposal records incomplete
Information classification and labeling. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.
- Asset inventory
- Classification scheme
- Acceptable use policy
- Media handling procedure
- Inventory drift vs CMDB
- Classification labels missing
- Disposal records incomplete
Asset handling procedures. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.
- Asset inventory
- Classification scheme
- Acceptable use policy
- Media handling procedure
- Inventory drift vs CMDB
- Classification labels missing
- Disposal records incomplete
Media management and disposal. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.
- Asset inventory
- Classification scheme
- Acceptable use policy
- Media handling procedure
- Inventory drift vs CMDB
- Classification labels missing
- Disposal records incomplete
ISO 27043: Communications Security
Network security management. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.
- Network architecture diagram
- Segmentation policy
- Data transfer agreement
- Secure messaging standard
- Flat network in legacy zones
- Transfer agreements missing for third parties
- Messaging encryption not enforced
Network service security. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.
- Network architecture diagram
- Segmentation policy
- Data transfer agreement
- Secure messaging standard
- Flat network in legacy zones
- Transfer agreements missing for third parties
- Messaging encryption not enforced
Segregation in networks. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.
- Network architecture diagram
- Segmentation policy
- Data transfer agreement
- Secure messaging standard
- Flat network in legacy zones
- Transfer agreements missing for third parties
- Messaging encryption not enforced
Information transfer policies. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
Secure messaging. Control from ISO 27043 framework, domain: ISO 27043: Communications Security.
- Network architecture diagram
- Segmentation policy
- Data transfer agreement
- Secure messaging standard
- Flat network in legacy zones
- Transfer agreements missing for third parties
- Messaging encryption not enforced
ISO 27043: Cryptography
Cryptographic policy and key management. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
Encryption of data at rest. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.
- Cryptographic policy
- Key management procedure
- Certificate inventory
- Algorithm catalogue
- No defined key rotation cadence
- Self-signed certs in production
- Algorithm catalogue not updated
Encryption of data in transit. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.
- Cryptographic policy
- Key management procedure
- Certificate inventory
- Algorithm catalogue
- No defined key rotation cadence
- Self-signed certs in production
- Algorithm catalogue not updated
Certificate management. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.
- Cryptographic policy
- Key management procedure
- Certificate inventory
- Algorithm catalogue
- No defined key rotation cadence
- Self-signed certs in production
- Algorithm catalogue not updated
Key lifecycle management. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.
- Cryptographic policy
- Key management procedure
- Certificate inventory
- Algorithm catalogue
- No defined key rotation cadence
- Self-signed certs in production
- Algorithm catalogue not updated
ISO 27043: Information Security Policies
Information security policy framework. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
Management direction and commitment. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
Policy review and update procedures. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
Roles and responsibilities definition. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
Contact with authorities and special interest groups. Control from ISO 27043 framework, domain: ISO 27043: Information Security Policies.
- Information security policy
- Policy review log
- Roles and responsibilities matrix
- Authority contact register
- Policy not reviewed annually
- Roles unclear at the working level
- External contacts stale
ISO 27043: Operations Security
Operational procedures and responsibilities. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.
- Operations runbook
- Backup test report
- SIEM log review
- Vulnerability scan report
- Backup restores not tested
- Log coverage gaps
- Vulnerabilities not remediated within SLA
Protection from malware. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.
- Operations runbook
- Backup test report
- SIEM log review
- Vulnerability scan report
- Backup restores not tested
- Log coverage gaps
- Vulnerabilities not remediated within SLA
Backup and recovery procedures. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.
- Operations runbook
- Backup test report
- SIEM log review
- Vulnerability scan report
- Backup restores not tested
- Log coverage gaps
- Vulnerabilities not remediated within SLA
Logging and monitoring. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.
- Operations runbook
- Backup test report
- SIEM log review
- Vulnerability scan report
- Backup restores not tested
- Log coverage gaps
- Vulnerabilities not remediated within SLA
Technical vulnerability management. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.
- Operations runbook
- Backup test report
- SIEM log review
- Vulnerability scan report
- Backup restores not tested
- Log coverage gaps
- Vulnerabilities not remediated within SLA
Audit considerations. Control from ISO 27043 framework, domain: ISO 27043: Operations Security.
- Operations runbook
- Backup test report
- SIEM log review
- Vulnerability scan report
- Backup restores not tested
- Log coverage gaps
- Vulnerabilities not remediated within SLA
Improvement
Capture lessons and update processes, tools, and training continuously.
- Lessons register
- Process updates
- Training updates
- Metrics dashboard
- Lessons not actioned
- Process static
- No metrics
Initialization
Defined triggers that initiate a digital investigation process.
- Detection use cases
- Trigger criteria document
- SOC handoff procedure
- Investigation initiation form
- No formal trigger
- SOC keeps cases
- No initiation record
Investigative
Plan investigation scope, objectives, resources, and timeline.
- Investigation plan template
- Approved plans
- Resource assignment
- Objective statements
- No plan
- Scope creep
- Resources insufficient
Identify, prioritize, and collect digital evidence using sound methods.
- Collection logs
- Tool validation records
- Write blocker use evidence
- Acquisition images
- No write blockers
- Tool versions unrecorded
- Collection order arbitrary
Maintain unbroken chain of custody for all evidence items.
- Chain of custody forms
- Evidence bag seals
- Hash values
- Transfer logs
- Forms incomplete
- No hashing
- Transfers undocumented
Preserve evidence integrity throughout the investigation lifecycle.
- Evidence safe access logs
- Hash verification at each step
- Environmental controls
- Backup of evidence
- No safe
- Hashes not reverified
- Evidence shared by email
Analyze evidence using validated tools and reproducible methods.
- Analysis notes
- Tool output
- Reproducibility evidence
- Peer review records
- No peer review
- Tools not validated
- Methods not documented
Document each step, decision, and observation during the investigation.
- Investigator notebooks
- Timestamped logs
- Decision register
- Photo records
- Notes informal
- No timestamps
- Decisions undocumented
Readiness
Establish a forensic readiness policy stating objectives, scope, and management commitment.
- Approved forensic readiness policy
- Management endorsement
- Review schedule
- Scope statement
- No standalone policy
- Policy not reviewed
- Scope excludes cloud
Define roles for investigators, custodians, legal counsel, and management.
- RACI for investigations
- Investigator appointment letters
- Legal contact list
- Custodian register
- No investigator role
- Legal not engaged early
- Custodians unidentified
Assess in-house and external forensic capabilities and identify gaps.
- Capability matrix
- Tool inventory
- External provider contracts
- Gap analysis
- No external retainer
- Tools unlicensed
- Capability untested
Implement processes to prepare evidence sources before incidents occur.
- Logging architecture
- Retention policy
- Time sync evidence
- Evidence source map
- Logs overwritten
- No NTP
- Evidence sources unmapped
Identify systems and data likely to contain evidence relevant to investigations.
- Evidence source catalogue
- Data flow diagrams
- Application log map
- Cloud evidence sources
- SaaS evidence unknown
- Mobile excluded
- Endpoint logs missing
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27043 framework page.