Skip to content

Chain of Custody

What is Chain of Custody?

The documented process of maintaining and tracking evidence from collection through presentation. In digital forensics, chain of custody ensures that evidence is admissible and has not been tampered with.

Information Security

Each of these is named in at least one of the same controls as chain of custody. The number is how many controls name both.

What the standards actually require on chain of custody

Requirements naming chain of custody across 6 standards, quoted from the control text.

NIST SP 800-885 controls

Maintain media inventory and tracking per NIST SP 800-88 Rev 1 Chapter 3 (Information Sanitization Process) + Chapter 4 (Decision Flow).

NISTSP88-5 · Media Inventory, Tracking, Chain of Custody, and Sanitization Records

Per RMAP: chain of custody + reporting. Requirements include (a) chain of custody documentation + (b) supplier documentation + (c) annual reporting + (d) maintain records.

RMIRMA-3 · Chain of Custody, Documentation, Reporting

Collect and preserve evidence following forensic principles including write protection, hashing, documentation of acquisition, and maintenance of chain of custody for potential legal proceedings.

PICERL-I-03 · Identification: Evidence Collection and Chain of Custody

Preserve identified ESI through legal holds, suspension of routine deletion and protection of metadata and chain of custody.

27050-3.2 · Preservation of ESI
NIST SP 800-613 controls

Conduct Post-Incident Activity per NIST SP 800-61 Rev 2 Section 3.4. Tasks include (a) Lessons Learned Meeting per Section 3.4.1: held within several days of the end of every major incident with attendees including the handlers + management + appropriate exter...

NISTSP61-6 · Post-Incident Activity: Lessons Learned, Evidence Retention, Metrics
PTES3 controls

Per PTES Exploitation phase: leverage vulnerabilities. Requirements include (a) execute exploits within scope + rules of engagement + (b) maintain stealth + minimise impact + (c) document exploitation including evidence + screenshots + (d) capture credentials...

PTESPHASE-5 · Exploitation

Questions people ask about chain of custody

What is Chain of Custody?
The documented process of maintaining and tracking evidence from collection through presentation. In digital forensics, chain of custody ensures that evidence is admissible and has not been tampered with.
Why is Chain of Custody important for compliance?
Chain of Custody is a key concept in Information Security. Understanding chain of custody helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Chain of Custody?
Chain of Custody appears in the requirement text of NIST SP 800-88, Responsible Minerals Initiative (RMI) - Responsible Minerals Assurance Process, SANS Incident Handler's Handbook and PICERL Methodology, ISO/IEC 27050 - Electronic Discovery (Parts 1-4), NIST SP 800-61. Across these standards we have identified 16 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Chain of Custody?
Explore our compliance framework pages to see how chain of custody applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Chain of Custody applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.