A.5.28 Organizational
Collection of evidence
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (15)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-11mostlyaligns with — Both controls address the retention and preservation of records so they remain available and usable for investigations or legal proceedings.
- AU-9mostlyaligns with — Both controls focus on protecting audit and evidence records from unauthorized modification or loss to ensure their integrity for later review or legal use.
- IR-4mostlyaligns with — Both controls require structured handling of incident-related evidence to support investigation, disciplinary action, and potential legal proceedings.
- AU-10partialaligns with — Both controls emphasize the ability to demonstrate that records have not been altered, supporting non-repudiation and evidentiary value.
- AU-10partialcovers — A.5.28's focus on consistent evidence management for incidents (including legal/disciplinary use) addresses only a slice of au-10's broader non-repudiation mechanisms that must apply to any designated action, not solely incident evidence.
- SI-7partialaligns with — Both controls require mechanisms to verify that information and evidence have not been tampered with since collection or recording.
- AU-11covers — A.5.28's narrow focus on evidence handling for incidents (to support disciplinary/legal action) addresses only a slice of AU-11's broader audit-record retention requirements for investigations plus regulatory/organizational retention needs.
- AU-9covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SI-7covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (14)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RS.AN-06mostlyaligns with — The ISO control's emphasis on preserving evidence integrity and provenance directly supports the CSF outcome of recording investigation actions while maintaining record integrity.
- RS.AN-07mostlyaligns with — Procedures for collecting and preserving evidence in a tamper-evident manner align with the CSF requirement to collect incident data and metadata while preserving their integrity and provenance.
- GV.SC-08partialaligns with — The control's consideration of cross-jurisdictional evidence collection aligns with the CSF outcome of including relevant suppliers and third parties in incident response activities that may involve evidence handling.
- ID.RA-08partialaligns with — The control's requirement for admissible, unaltered evidence supports the CSF outcome of establishing processes to receive, analyze, and respond to vulnerability disclosures that may require legal or disciplinary follow-up.
- GV.SC-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- RS.AN-06implements — A.5.28's operational processes for consistent collection and management of incident evidence directly give effect to the recording, integrity, and provenance requirements named in RS.AN-06 within the shared investigation/response domain
- RS.AN-07implements — A.5.28's defined purpose (consistent/effective collection and management of incident evidence with integrity/provenance guarantees for legal/disciplinary use) directly operationalizes exactly what RS.AN-07 requires
Related OWASP ASVS 5.0 requirements (5)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (3)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-284nonedetects — Requiring documented procedures and qualified personnel for evidence handling reduces the likelihood that an attacker or insider can manipulate or access evidence outside authorised channels.
- CWE-200finds — By requiring that evidence be collected and preserved so that its completeness and integrity can be demonstrated, the control reduces the chance that sensitive information will be exposed to unauthorized parties during or after an incident.
Mitigated MITRE ATT&CK techniques (179)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003detects — A.5.28 procedures for identification, collection and preservation of evidence can surface credential-dumping artifacts once they exist as admissible evidence, but the control is scoped to post-incident evidentiary handling rather than real-time or proactive detection of the technique itself.
- T1041detects — A.5.28 procedures for identification, collection and preservation of admissible evidence from incidents directly surface knowledge of T1041 when it is treated as an information security event, but the control is silent on proactive detection mechanisms and only acts once the exfiltration has already produced collectible evidence.
- T1204responds — A.5.28 procedures for identification/collection/preservation of incident evidence directly enable the containment/eradication steps of responding to a user-execution event once underway, with the bounded remainder being non-forensic response actions such as immediate user coaching or endpoint isolation that do not rely on evidence handling.
- T1218.005detects — A.5.28 procedures for identification/collection/preservation of admissible evidence from incidents can surface the use of mshta.exe as part of post-incident forensic handling, but this is scoped only to evidence-management after the technique has already run and is not a detection control.
- T1218.008detects — A.5.28 procedures for identification, collection and preservation of admissible evidence can surface the technique once it has produced observable artifacts (e.g. executed DLL, altered ODBC config, or signed binary invocation), but the control is scoped to post-incident evidence handling rather than continuous or proactive detection of the living-off-the-land abuse itself.
- T1218.012detects — A.5.28 procedures for identification, collection and preservation of admissible evidence from information security incidents can surface the use of verclsid.exe as part of post-incident forensic handling, but the control itself is scoped to evidence management rather than mandating proactive or real-time detection mechanisms.
- T1219.002detects — A.5.28 procedures for identification, collection, acquisition and preservation of evidence (with integrity and admissibility requirements) surface and document use of remote desktop software when it is treated as incident evidence, but this is after-the-fact and only for incidents that are already under investigation rather than broad detection of the technique.
- T1486responds — A.5.28 procedures for identification/collection/preservation of evidence (including post-incident forensic handling admissible for legal/disciplinary action) directly support the containment/eradication phase of responding to a ransomware event once T1486 has executed and data is already encrypted.
- T1491.001responds — A.5.28 procedures for identification, collection, acquisition, preservation, and admissibility of evidence (including showing integrity and system correctness) directly support the containment/eradication and post-event handling of an already-underway internal defacement incident once discovered.
- T1531responds — A.5.28 procedures for identification/collection/preservation of admissible evidence directly support the incident response process once T1531 (and linked ransomware behaviors) are underway, enabling disciplinary/legal actions that bound and help eradicate the actor's foothold.
- T1546.003detects — A.5.28 procedures for identification, collection and preservation of admissible evidence can surface the malicious WMI subscription artifacts (filters, MOF files, consumers) once an incident is known, but the control is scoped to post-incident evidence handling rather than continuous or proactive detection of the technique itself.
- T1546.007detects — A.5.28 procedures for identification, collection and preservation of admissible evidence can surface the registry modification and helper DLL artifact once an incident is known or suspected, but the control is silent on proactive monitoring or detection mechanisms for the technique itself.
- T1546.017detects — A.5.28 procedures for identification, collection, acquisition and preservation of evidence can surface udev rule modifications as admissible artifacts once an incident is known, but the control itself is silent on proactive detection mechanisms and does not require monitoring for the technique.
- T1547.012detects — A.5.28 procedures for identification, collection, acquisition and preservation of evidence can surface artifacts of a print-processor DLL being added/loaded at boot (e.g. registry keys, spoolsv.exe activity, file-system objects) once the incident is known, but the control is scoped to post-incident evidence handling rather than continuous or proactive detection of the technique.
- T1555.006detects — A.5.28 procedures for identification, collection and preservation of evidence from information security incidents directly surface credential-acquisition events from cloud secrets stores when they are treated as incidents, but the control is silent on proactive detection mechanisms and only addresses post-incident evidence handling.
- T1556.008detects — A.5.28 procedures for identification, collection and preservation of admissible evidence can surface the malicious DLL (or its artifacts) once an incident is known, but the control is scoped to post-event evidence handling rather than continuous or proactive detection of the technique itself.
- T1578.003detects — A.5.28 procedures for identification, collection, acquisition and preservation of evidence (including showing systems operated correctly and records are complete) surface and document the deletion act and its forensic gap once the incident is known, but do not instrument or surface the deletion in real time or before the evidence is gone.
- T1578.003responds — A.5.28's incident-evidence procedures (identification, collection, acquisition, preservation for legal/disciplinary use) directly engage once the deletion has run, enabling containment via forensic handling and eradication of the actor's clean-up attempt by preserving recoverable artifacts across jurisdictions and media states.
- T1578.004detects — A.5.28 procedures for identification, collection, acquisition and preservation of evidence (including showing records are complete/untampered) can surface the use of revert/snapshot operations that erase prior evidence of malicious activity, but this is a post-facto forensic slice rather than broad detection of the technique itself.
- T1578.004responds — A.5.28's procedures for identification, collection, acquisition and preservation of evidence (with integrity, provenance and admissibility requirements) directly enable the containment/eradication actions of incident response once T1578.004 has run and the revert has occurred, by ensuring any surviving artifacts can still be forensically used to support eradication and legal/disciplinary follow-up.
- T1685.005detects — A.5.28 procedures for identification, collection and preservation of evidence can surface the fact that logs were cleared (as an indicator of tampering or incident activity), but this is only a slice of the technique's full scope and not the control's primary purpose.
- T1685.006responds — A.5.28 procedures for identification, collection, acquisition and preservation of evidence (including showing logs are complete/untampered) directly enable the incident response act of containing/eradication once the log-clearing technique is underway, with a named remainder around non-forensic response paths.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.