Chain of Custody
What is Chain of Custody?
The documented process of maintaining and tracking evidence from collection through presentation. In digital forensics, chain of custody ensures that evidence is admissible and has not been tampered with.
Terms that appear alongside chain of custody
Each of these is named in at least one of the same controls as chain of custody. The number is how many controls name both.
- nist 25 shared controls
- integrity 17 shared controls
- audit 15 shared controls
- incident response 13 shared controls
- ransomware 9 shared controls
- lessons learned 9 shared controls
- remediation 8 shared controls
- policy 8 shared controls
Frameworks that govern chain of custody
What the standards actually require on chain of custody
Requirements naming chain of custody across 6 standards, quoted from the control text.
Maintain media inventory and tracking per NIST SP 800-88 Rev 1 Chapter 3 (Information Sanitization Process) + Chapter 4 (Decision Flow).
NISTSP88-5 · Media Inventory, Tracking, Chain of Custody, and Sanitization Records →Per RMAP: chain of custody + reporting. Requirements include (a) chain of custody documentation + (b) supplier documentation + (c) annual reporting + (d) maintain records.
RMIRMA-3 · Chain of Custody, Documentation, Reporting →Collect and preserve evidence following forensic principles including write protection, hashing, documentation of acquisition, and maintenance of chain of custody for potential legal proceedings.
PICERL-I-03 · Identification: Evidence Collection and Chain of Custody →Preserve identified ESI through legal holds, suspension of routine deletion and protection of metadata and chain of custody.
27050-3.2 · Preservation of ESI →Conduct Post-Incident Activity per NIST SP 800-61 Rev 2 Section 3.4. Tasks include (a) Lessons Learned Meeting per Section 3.4.1: held within several days of the end of every major incident with attendees including the handlers + management + appropriate exter...
NISTSP61-6 · Post-Incident Activity: Lessons Learned, Evidence Retention, Metrics →Per PTES Exploitation phase: leverage vulnerabilities. Requirements include (a) execute exploits within scope + rules of engagement + (b) maintain stealth + minimise impact + (c) document exploitation including evidence + screenshots + (d) capture credentials...
PTESPHASE-5 · Exploitation →Questions people ask about chain of custody
What is Chain of Custody?
Why is Chain of Custody important for compliance?
Which compliance frameworks address Chain of Custody?
Where can I learn more about Chain of Custody?
See how Chain of Custody applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.