In this guide you will learn how to implement ISO 27001 Annex A 5.28 Collection of Evidence and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.28 is about collection of evidence which means you must have a system to handle the the collection and management of evidence from information security events.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.28 Training Video
- Implementation Guide
- How to implement ISO 27001 Annex 5.28
- ISO 27001 Templates
- How to comply
- How to pass an ISO 27001 Annex 5.28 audit
- What an auditor will check
- Top 3 Mistakes People Make and How to Avoid Them
- Further Reading
- ISO 27001 Controls and Attribute values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.28 is to ensure a consistent and effective management of evidence related to information security incidents for the purposes of disciplinary and legal actions.
The ISO 27001 standard defines ISO 27001 Annex A 5.28 as:
The organisation should establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events.
ISO 27001:2022 Annex A 5.28 Collection of Evidence
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.28 Training Video
In this free training video you will learn How to implement ISO 27001 Collection Of Evidence (Annex A 5.28) and Pass Your Audit.
Implementation Guide
It is my experience that the best way to implement Annex A 5.28 is to have a procedure that calls in the professionals to do the work. This would form part of your incident management process and would be instigated at the earliest opportunity. This usually means as soon as it becomes clear that evidence collection will be required to support a legal or disciplinary process.
Having a Collection of Evidence Policy and a process that has the contact details for a pre selected, pre vetted supplier is the best way to implement Annex A 5.28.
The standard that relates to information security incident management for further reading if required is ISO/IEC 27035
The requirements of evidence collection
As the control is looking at the collection of evidence to support legal and disciplinary action the first requirement is to understand the different laws and jurisdictions that apply to you. If you understand the needs of these laws you will understand what requirements they have and increase your chances of successfully admitting your evidence for consideration.
The requirements of the control are based around having documented processes and procedures that meet the requirements of applicable laws. Those processes and procedures are going to cover
- Identification of evidence
- Collection of evidence
- Acquisition of evidence
- Preservation of evidence
When implementing those processes and procedures you are going to ensure that
- Evidence and records are complete and have not been tampered with
- Copies of electronic evidence are identical to the origionals
- Evidence from systems was from systems operating as intended at the time of collection
It is best practice and recommended that people that are involved in the process and collection of evidence and trained, qualified and certified to the appropriate level.
How to implement ISO 27001 Annex 5.28
Implementing ISO 27001 Annex A 5.28 ensures that your organisation can identify, acquire, and preserve evidence in a manner that is legally admissible and technically sound. This process transforms raw security logs and hardware into verifiable proof for disciplinary or judicial proceedings. Following these steps ensures your incident management programme meets lead auditor expectations for forensic readiness.
1. Formalise the Evidence Management Framework
Establish a topic-specific policy that defines the legal and jurisdictional requirements for evidence handling. This action ensures that all collection activities align with local laws such as the Police and Criminal Evidence Act (PACE) or equivalent regional regulations.
- Define clear Roles and Responsibilities for the incident response team.
- Identify relevant jurisdictions to ensure the Rules of Engagement (ROE) meet local admissibility criteria.
- Document the triggers for evidence collection to prevent accidental data spoliation during initial triage.
2. Authorise and Pre-vet Specialist Forensic Suppliers
Provision external forensic expertise and retainers before an incident occurs. Because digital forensics requires specialised skills and certified tools, using pre-vetted professionals reduces the risk of evidence being ruled inadmissible due to improper handling.
- Maintain a register of authorised forensic investigators with recognised certifications.
- Ensure third-party contracts include strict non-disclosure agreements (NDAs) and data protection clauses.
- Review the ISO 27001 certification status of external forensic labs to maintain the security chain.
3. Standardise Technical Acquisition Procedures
Deploy rigorous acquisition protocols to maintain data integrity. The goal is to prove that the evidence collected is an exact, bit-for-bit representation of the original source at the time of seizure.
- Use hardware write-blockers for all physical drive acquisitions to prevent data modification.
- Generate cryptographic hashes (such as SHA-256) immediately upon acquisition to provide a digital fingerprint.
- Document the system state and any environmental anomalies at the time of collection to provide necessary context for the data.
4. Execute Rigorous Chain of Custody Protocols
Document every interaction with the evidence using a formal Chain of Custody log. This action creates a transparent audit trail that accounts for the location, possession, and purpose of movement for every evidence item.
- Assign a unique Evidence ID to every physical and digital asset seized.
- Record the date, time, and precise location of seizure for all items.
- Require signatures or digital timestamps for every handover between personnel or departments.
5. Enforce Secure Preservation and Access Controls
Protect evidence from unauthorised access, tampering, or environmental degradation. Secure storage ensures that the evidence remains in its original state until it is required for legal or disciplinary review.
- Store physical evidence in tamper-evident bags within a restricted-access safe or locker.
- Utilise encrypted, write-once storage repositories for digital evidence and log files.
- Implement Multi-Factor Authentication (MFA) and strict IAM roles for access to forensic workstations and image repositories.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

ISO 27001 Templates

How to comply
To comply with ISO 27001 Annex A 5.28 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:
- Have an ISO 27001 topic specific policy for the collection of evidence
- Implement a process that outsource the collection of evidence to an appropriate, qualified, certified, pre vetted supplier at the earliest opportunity
- Incorporate that process into your information security incident management process
How to pass an ISO 27001 Annex 5.28 audit
To pass an audit of ISO 27001 Annex A 5.28 you are going to make sure that you have followed the steps above in how to comply and be able to evidence it in operation. It maybe that you have not had to implement the process for the collection of evidence, which is acceptable, in which case just your policy and procedures will be audited.
- Have an ISO 27001 topic specific policy for the collection of evidence
- Implement a process that outsource the collection of evidence to an appropriate, qualified, certified, pre vetted supplier at the earliest opportunity
- Incorporate that process into your information security incident management process
- Be able to evidence that you followed the documented process in the event that you have had to collect evidence as part of your business operations.
What an auditor will check
The audit is going to check a number of areas. Lets go through the main ones
1. That you have documented your collection of evidence process
The audit will check the documentation, that you have reviewed it and signed and it off and that it represents what you actually do not what you think they want to hear.
2. That you can demonstrate the process working
They are going to ask you for evidence to the collection of evidence process and take at least one example. For this example you are going to show them and walk them through the process and prove that you followed it and that the process worked.
3. That you can learn your lesson
Documenting your lessons learnt and following this through to continual improvements or incident and corrective actions will be checked.
Top 3 Mistakes People Make and How to Avoid Them
The most common mistakes people make for ISO 27001 Annex A 5.28 are
1. Not having a documented collection of evidence process and policy.
This is the most common mistake made by organisations. A documented collection of evidence policy and collection of evidence process is essential for effective incident response.
2. Not having evidence collected by professionals
There are so many mistakes that can be made in the collection of evidence that would render the evidence useless. The standard guidance is to use trained and qualified personnel. Whether in house or out sourced you should ensure that you engage with professionals at the earliest opportunity and at least as soon as it becomes evident that evidence is required for legal or disciplinary purposes.
3. Not monitoring the effectiveness of the collections of evidence process
It is important to monitor its effectiveness of the collection of evidence process. This means reviewing the process, conducting internal audits and reviewing actual incidents for lessons learnt.
By avoiding these mistakes, you can ensure that you have an effective collection of evidence plan in place.
Further Reading
- The complete guide to ISO/IEC 27002:2022
- ISO 27001 Incident and Corrective Action Log Template
- Business Continuity Incident Action Log Template
ISO 27001 Controls and Attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
| Corrective | Confidentiality | Detect | Information Security Event Management | Defence |
| Integrity | Respond | |||
| Availability |
