Collection of evidence
Summary
The organisation shall establish and implement procedures for the identification, collection, acquisition, and preservation of evidence related to information security events.
evidenceincident management
Read the full official text: https://www.iso.org/standard/27001
← Clause 5.27
Learning from information security incidents
Clause 5.29 →
Information security during disruption
Track ISO 27001 clause 5.28 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial