GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INC-007 Evidence Collection and Preservation

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Procedures are in place to identify, collect, and preserve digital evidence related to security incidents. Evidence is collected in a manner that maintains chain of custody and supports potential legal proceedings. Evidence is stored securely and retained for a period consistent with regulatory and legal requirements.

Rationale

Evidence collected without chain of custody may be inadmissible in legal proceedings and insufficient for regulatory investigations. Establishing procedures before an incident ensures disciplined collection under pressure.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (6)

SEF-09Incident Records Managementfull
SEF-09Incident Records Managementfull
GDPR-Art.33.5Internal Breach Documentationfull
5.28Collection of evidencefull
NIS2-CIR-3.5Incident Responseinformative
IR-4Incident Handlinginformative

Evidence (2)

policydocumentmanual

Evidence collection and preservation procedure defining how digital evidence is identified, collected, and stored with chain of custody to support legal proceedings.

Example: Digital Evidence Collection Procedure or IRP forensics annex (version-controlled, reviewed within last 12 months) specifying collection tools, chain of custody form, storage location, access controls, and retention period

Test: Request the evidence collection procedure. Verify: (1) a chain of custody process is defined with a named custodian role; (2) approved collection tools and methods are specified; (3) evidence storage requirements (integrity, access restriction, retention) are documented; (4) the procedure covers both cloud and endpoint evidence collection; (5) the document has been reviewed within the last 12 months.

recorddocumentmanual

Completed chain of custody records for evidence collected during past incidents, demonstrating the procedure was followed in practice.

Example: Chain of custody form or evidence register entry for the most recent incident requiring evidence collection, showing item description, collection date, collector identity, storage location, and access log

Test: Request chain of custody records for the last two incidents where evidence was collected. Verify: (1) a chain of custody form or register entry exists for each evidence item; (2) records include collection date, collector identity, and storage location; (3) evidence is stored in a restricted location with an access log; (4) evidence retention period is within regulatory and legal requirements.

Questions (2)

boolean

Are there documented procedures for identifying, collecting and preserving digital evidence from security incidents?

Evidence collection procedures should specify approved tools, chain of custody requirements, storage location, access controls, and retention period aligned to legal and regulatory requirements.

multi

Which elements are included in your evidence collection and preservation procedure?

Defined chain of custody process with a named custodian roleApproved collection tools and methods specifiedSecure evidence storage with restricted access and access loggingDefined evidence retention period aligned to regulatory requirementsCoverage of cloud-based evidence (e.g. log exports, API call records, cloud resource snapshots)Coverage of endpoint evidence (e.g. memory capture, disk imaging)None of the above

Chain of custody and secure storage are the minimum requirements. Cloud-based evidence collection procedures are essential where the service runs on cloud infrastructure.