ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Evidence Collection Form

Evidence Collection Form

1. Purpose

The Evidence Collection Form is used to formally record the collection of information-security evidence during an incident, investigation, security event, audit, assessment, or other authorized activity.

The form creates a traceable record showing:

What was collected → Where it came from → Who collected it → When → How → Integrity → Where it was stored → Who accessed it

This form should be used together with the Evidence Collection Procedure and, where applicable, the Evidence Preservation Procedure and Chain of Custody Record.


2. Evidence Collection Record

Evidence ID

EV-YYYY-0001

Incident / Investigation ID

Event ID

Related Record

Incident / Security Event / Audit / Investigation / Security Test / Other

Collection Date

Collection Time

Time Zone

Collected By

Role

Approved By


3. Collection Objective

Why is this evidence being collected?

Investigation Question

What question is the evidence expected to help answer?

Example:

Determine whether the compromised AWS identity accessed customer S3 data.


4. Evidence Description

Evidence Title

Evidence Description

Evidence Type

Select one or more:

  • Authentication
  • Identity / IAM
  • Cloud
  • Network
  • Endpoint
  • Application
  • Database
  • Email
  • Source Code
  • CI/CD
  • Security Alert
  • Configuration
  • Backup
  • Communication
  • Physical
  • Audit
  • Other

5. Evidence Source

Source Organization

Source System

Hostname / Resource ID

Account / Tenant / Environment

Application / Service

Original Location

Source Owner

Source Contact


6. Evidence Time Period

Start Date/Time

End Date/Time

Time Zone

Source-System Time

Time Synchronization Considerations

Record any known difference between the source-system clock and the investigation timeline.


7. Collection Method

Collection Method

  • System export
  • Security-tool export
  • API
  • Log download
  • Screenshot
  • File copy
  • Forensic image
  • Database export
  • Email export
  • Cloud-platform export
  • Supplier-provided evidence
  • Physical collection
  • Other

Collection Procedure Used

Tool / Platform Used

Tool Version

Command / Query / Filter Used

Where appropriate, record the query or filter used to obtain the evidence so the collection can be reproduced or reviewed.


8. Original Evidence Information

Original File / Record Name

File Type / Format

File Size

Number of Records

Original Location

Original System

Original Timestamp

Read-Only / Original Preserved?

  • Yes
  • No
  • Not Applicable

If No, Explain


9. Evidence Integrity

Integrity Verification Required?

  • Yes
  • No

Hash Algorithm

Example:

SHA-256

Hash Value

Hash Calculated By

Hash Date/Time

Hash Reverified?

  • Yes
  • No
  • Not Applicable

Reverification Result


10. Evidence Classification

Information Classification

  • Public
  • Internal
  • Confidential
  • Restricted

Does the Evidence Contain Personal Data?

  • Yes
  • No
  • Unknown

Does the Evidence Contain Customer Data?

  • Yes
  • No
  • Unknown

Does the Evidence Contain Sensitive Security Information?

  • Yes
  • No
  • Unknown

Does the Evidence Contain Credentials or Secrets?

  • Yes
  • No
  • Unknown

If credentials or secrets are identified, do not record the secret value in this form. Follow the organization’s credential-compromise and secret-rotation process.


11. Evidence Relevance

Relevance to Investigation

Explain why the evidence is relevant.

Related Activity

Related System

Related Identity

Related Information

Related Timeline Event


12. Evidence Priority

Priority

  • Critical / Volatile
  • High
  • Normal
  • Supporting

Reason for Priority

Was Volatile Evidence Considered?

  • Yes
  • No
  • Not Applicable

If Not Collected


13. Evidence Storage

Storage Location

Repository / System

Storage Classification

Encryption Applied?

  • Yes
  • No
  • Not Applicable

Access Restricted?

  • Yes
  • No

Authorized Access Group

Backup Required?

  • Yes
  • No

14. Evidence Access

Record significant access to sensitive evidence.

Date/TimePersonEvidence IDActionPurpose
View
Copy
Analyze
Transfer

Actions may include:

  • View
  • Copy
  • Export
  • Analyze
  • Transfer
  • Restore
  • Verify
  • Dispose

15. Chain of Custody

Complete this section when the evidence requires formal chain-of-custody tracking.

Date/TimeEvidence IDReleased ByReceived ByPurposeLocationIntegrity Verified

Current Evidence Custodian

Current Storage Location


16. Evidence Transfer

Transfer Required?

  • Yes
  • No

Transferred From

Transferred To

Transfer Date/Time

Transfer Method

Transfer Reason

Integrity Verified After Transfer?

  • Yes
  • No

Verification Result


17. Third-Party Evidence

Evidence Provided By

Organization

Provider Contact

Provider Reference / Ticket

Date Received

Method Received

Provider Integrity Information

Restrictions on Use

Examples:

  • Confidentiality restriction
  • Customer restriction
  • Legal restriction
  • Contractual restriction
  • Provider terms

18. AWS / Cloud Evidence

Complete where the evidence comes from AWS or another cloud environment.

Cloud Provider

Account / Subscription / Project

Region

Service

Examples:

  • CloudTrail
  • IAM
  • GuardDuty
  • Security Hub
  • S3
  • RDS
  • EC2
  • ECS
  • EKS
  • Lambda
  • VPC
  • WAF
  • KMS
  • Secrets Manager

Resource ID

Cloud Evidence Type

Relevant Activity

Cloud Timestamp

Export Method

Cloud Evidence Integrity


19. Email Evidence

Complete when collecting email-related evidence.

Mailbox / Account

Sender

Recipient

Subject

Message ID

Date/Time

Attachment

URL / Link

Full Headers Preserved?

  • Yes
  • No

Original Message Preserved?

  • Yes
  • No

20. Endpoint Evidence

Device / Hostname

Device ID

User

Operating System

EDR / Security Tool

Relevant Process

File / Artifact

Network Connection

Collection Method


21. Application / Database Evidence

Application / Database

Environment

  • Production
  • Staging
  • Development
  • Other

Account / User

Relevant Activity

Log / Query Source

Query / Filter Used

Data Exposure Consideration

Avoid copying actual customer or personal data unless necessary and authorized.


22. Evidence Gaps

Was Any Required Evidence Unavailable?

  • Yes
  • No

Evidence Not Available

Reason

  • Log not enabled
  • Log expired
  • System unavailable
  • Access unavailable
  • Supplier limitation
  • Technical limitation
  • Data overwritten
  • Evidence destroyed before preservation
  • Other

Impact on Investigation

Compensating Evidence


23. Evidence Quality Assessment

Evaluate the reliability of the evidence.

QuestionAssessment
Source known?Yes / No
Collector known?Yes / No
Collection time known?Yes / No
Time zone known?Yes / No
Collection method documented?Yes / No
Integrity verified?Yes / No / N/A
Evidence complete?Yes / No / Unknown
Evidence relevant?Yes / No
Evidence protected?Yes / No
Corroborated by another source?Yes / No / Unknown

Evidence Reliability Notes


24. Analysis Notes

Facts Established From Evidence

Observations

Hypotheses

Unknowns

Preliminary Conclusion

Important:

A hypothesis should not be recorded as a confirmed fact until supported by sufficient evidence.


25. Evidence Relationships

Link the evidence to related ISMS records.

Incident ID:

Security Event ID:

Investigation ID:

Timeline Record:

Root Cause Analysis ID:

Data Breach Assessment ID:

Corrective Action ID:

Lessons Learned ID:

Risk ID:


26. Collection Validation

The collector confirms:

  • Evidence source was identified.
  • Collection was authorized.
  • Relevant time period was defined.
  • Collection method was recorded.
  • Original evidence was preserved where practical.
  • Evidence ID was assigned.
  • Integrity was considered.
  • Evidence was securely stored.
  • Access was restricted.
  • Sensitive information was handled appropriately.
  • Chain of custody was established where required.
  • Evidence gaps were documented.

27. Collector Declaration

I confirm that the evidence described in this form was collected using the documented method and, to the best of my knowledge, the information recorded accurately represents the collection activity.

Collected By:

Role:

Signature / Electronic Approval:

Date:


28. Evidence Reviewer

Reviewed By

Role

Review Date

Review Result

  • Accepted
  • Accepted With Limitations
  • Additional Evidence Required
  • Collection Repeated
  • Rejected

Reviewer Comments


29. Evidence Closure

Investigation Complete?

  • Yes
  • No

Further Collection Required?

  • Yes
  • No

Evidence Retention Requirement

Retention Until

Legal / Regulatory Hold?

  • Yes
  • No
  • Unknown

Disposal Authorized?

  • Yes
  • No
  • Not Yet

30. Evidence Disposition

Complete when evidence is no longer required.

Disposition

  • Retained
  • Archived
  • Securely Deleted
  • Returned to Source
  • Transferred
  • Other

Disposal / Transfer Date

Authorized By

Method

Evidence Register Updated?

  • Yes
  • No

31. Example — AWS Account Compromise

Evidence ID

EV-2026-0042

Incident ID

INC-2026-0017

Evidence

AWS CloudTrail records covering the suspected compromised administrator identity.

Source

AWS CloudTrail

Account

Production AWS Account

Time Period

30 September 2026 09:00–14:00 IST

Collection Method

Authorized CloudTrail export using approved administrative access.

Investigation Objective

Determine whether the compromised identity created unauthorized IAM resources and accessed customer information.

Related Evidence

  • IAM role changes
  • GuardDuty finding
  • S3 access activity
  • Security Group changes
  • CI/CD activity

Integrity

SHA-256 hash recorded in the Evidence Register.

Storage

Restricted incident evidence repository.

Access

Incident Response Team only.

Analysis

The CloudTrail evidence is correlated with IAM and S3 records to establish:

Identity → Authentication → Privilege → Resource → Data Access → Timeline


32. Minimum Evidence Collection Form

For smaller incidents, the organization may use a simplified form:

FieldInformation
Evidence ID
Incident ID
Evidence Description
Source
System
Collected By
Date/Time
Time Zone
Collection Method
Original Location
Classification
Hash
Storage Location
Access Restrictions
Related Finding
Evidence Gaps
Reviewer
Status

This provides a lightweight starting point while retaining basic traceability.


33. Relationship With the Evidence Collection Procedure

The Evidence Collection Procedure defines how evidence should be collected.

The Evidence Collection Form records what was actually collected.

The relationship is:

Procedure → Collection Activity → Evidence Collection Form → Evidence Register → Investigation → Findings → Root Cause → Corrective Action → Closure


34. Audit Trail

Investigation Authorized → Evidence Requirement Identified → Collection Scope Defined → Evidence Source Identified → Collector Authorized → Time Window Defined → Evidence Collected → Evidence ID Assigned → Source Recorded → Collection Method Recorded → Integrity Verified → Evidence Classified → Evidence Secured → Access Restricted → Chain of Custody Recorded → Evidence Reviewed → Findings Linked → Evidence Gaps Recorded → Retention Determined → Evidence Disposed/Archived → Record Closed


Final Principle

Every Important Piece of Evidence Should Have an Identity, a Source, a Collector, a Time, a Method, an Integrity Record, a Secure Location, and a Traceable Relationship to the Investigation.

Identify → Collect → Record → Verify → Protect → Analyze → Trace → Retain → Dispose.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *