A.5.28 Organizational
Collection of evidence
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-11mostlyaligns with — Both controls address the retention and preservation of records so they remain available and usable for investigations or legal proceedings.
- AU-9mostlyaligns with — Both controls focus on protecting audit and evidence records from unauthorized modification or loss to ensure their integrity for later review or legal use.
- IR-4mostlyaligns with — Both controls require structured handling of incident-related evidence to support investigation, disciplinary action, and potential legal proceedings.
- AU-10partialaligns with — Both controls emphasize the ability to demonstrate that records have not been altered, supporting non-repudiation and evidentiary value.
- SI-7partialaligns with — Both controls require mechanisms to verify that information and evidence have not been tampered with since collection or recording.
Aligned NIST CSF 2.0 outcomes (7)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RS.AN-06mostlyaligns with — The ISO control's emphasis on preserving evidence integrity and provenance directly supports the CSF outcome of recording investigation actions while maintaining record integrity.
- RS.AN-07mostlyaligns with — Procedures for collecting and preserving evidence in a tamper-evident manner align with the CSF requirement to collect incident data and metadata while preserving their integrity and provenance.
- GV.SC-08partialaligns with — The control's consideration of cross-jurisdictional evidence collection aligns with the CSF outcome of including relevant suppliers and third parties in incident response activities that may involve evidence handling.
- ID.RA-08partialaligns with — The control's requirement for admissible, unaltered evidence supports the CSF outcome of establishing processes to receive, analyze, and respond to vulnerability disclosures that may require legal or disciplinary follow-up.
Related OWASP ASVS 5.0 requirements (5)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (7)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialfinds — By requiring that evidence be collected and preserved so that its completeness and integrity can be demonstrated, the control reduces the chance that sensitive information will be exposed to unauthorized parties during or after an incident.
- CWE-222nonenone — Evidence collection benefits from complete logs, yet the control itself does not mandate non-truncated recording.
- CWE-223nonenone — Evidence collection depends on logs and records that the weakness fails to produce.
- CWE-284nonedetects — Requiring documented procedures and qualified personnel for evidence handling reduces the likelihood that an attacker or insider can manipulate or access evidence outside authorised channels.
- CWE-532nonenone — Mandating controlled identification, acquisition and preservation of evidence limits the risk that sensitive data will be inadvertently written into log files or other externally accessible artefacts.
- CWE-693nonenone — Insisting on verifiable chain-of-custody and integrity checks for collected evidence helps ensure that any protection mechanisms that were in place at the time of the incident remain demonstrably intact.
Mitigated MITRE ATT&CK techniques (3)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1565partialdetects — Mandating that evidence copies be demonstrably identical to originals and that source systems were functioning correctly reduces the attacker’s chance of successfully manipulating stored or transmitted data without detection.
- T1070nonemitigates — Documented evidence-handling procedures that require proof of completeness and non-tampering make it harder for an adversary to erase or alter artifacts without detection, thereby reducing the effectiveness of indicator-removal actions.
- T1070.004nonemitigates — Requiring verifiable chain-of-custody and integrity checks for collected data limits an attacker’s ability to delete files or logs without leaving admissible traces.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A09partialfinds — By mandating tamper-evident collection, chain-of-custody procedures, and verifiable integrity of logs and records, the control ensures that security events can be reliably reconstructed and acted upon, directly strengthening the organization’s ability to detect, investigate, and respond to incidents.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.