ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Chain-of-Custody Form

Chain-of-Custody Form

1. Purpose

The Chain-of-Custody Form is used to maintain a traceable record of the possession, transfer, handling, storage, and disposition of evidence.

It establishes:

Who had the evidence → When they had it → Why they had it → What they did with it → Where it went next → Whether its integrity was maintained.

The form should be used when evidence requires formal handling controls, particularly for sensitive incident investigations, forensic evidence, legal matters, customer-impacting incidents, regulatory investigations, or evidence transferred to third parties.

ISO/IEC 27001 does not prescribe a specific chain-of-custody form. The organization should determine when formal evidence custody controls are necessary based on risk, legal requirements, contractual obligations, investigation requirements, and the nature of the evidence.


2. Scope

This form may be used for:

  • Security incidents
  • Data breaches
  • Account compromise
  • Cloud compromise
  • Malware and ransomware investigations
  • Unauthorized access
  • Insider investigations
  • Supplier incidents
  • Fraud investigations
  • Vulnerability exploitation
  • Production security incidents
  • CI/CD compromise
  • Digital forensic investigations
  • Legal investigations
  • Regulatory investigations
  • Customer-impacting investigations
  • Evidence transferred to external investigators
  • Evidence provided to legal counsel
  • Evidence provided to insurers
  • Evidence provided to law enforcement where applicable

3. When Chain of Custody Is Required

Not every piece of security evidence requires a formal chain-of-custody process.

Consider using formal chain-of-custody controls when:

  • Evidence may be used in legal proceedings.
  • Evidence may be provided to regulators.
  • Evidence is transferred outside the organization.
  • Evidence is highly sensitive.
  • Evidence could materially affect an investigation conclusion.
  • Evidence is forensic in nature.
  • Evidence could be challenged regarding authenticity or integrity.
  • Evidence is transferred between multiple investigators.
  • Evidence is stored on removable or physical media.
  • Customer or third-party evidence is involved.
  • An insurance or contractual investigation requires traceability.

For routine internal evidence, the Evidence Register and access controls may be sufficient if the organization’s procedure permits this.


4. Chain-of-Custody Principle

The chain of custody should establish:

Evidence Identified → Evidence Collected → Evidence Secured → Evidence Transferred → Evidence Received → Evidence Accessed/Handled → Evidence Transferred Again → Evidence Returned/Archived → Evidence Disposed

Every significant custody change should be recorded.


5. Chain-of-Custody Record Information

Evidence Identification

FieldDetails
Evidence IDEV-YYYY-0001
Incident IDINC-YYYY-0001
Investigation IDINV-YYYY-0001
Event IDSE-YYYY-0001
Evidence TitleDescription
Evidence TypeFile/Log/Image/Device/Export/etc.
Evidence CategoryCloud/Endpoint/Network/etc.
ClassificationInternal/Confidential/Restricted
PriorityCritical/High/Medium/Low

6. Original Evidence Details

Record enough information to identify the original evidence.

FieldDetails
Original SourceSystem/application/device
Source OwnerResponsible person/team
Original LocationOriginal storage location
Hostname/ResourceRelevant resource
Account/TenantRelevant account
EnvironmentProduction/Staging/Development
RegionWhere applicable
Evidence FilenameOriginal filename
File TypeJSON/CSV/EML/IMG/etc.
SizeFile/media size
Record CountWhere applicable
Date/Time CreatedSource timestamp
Evidence PeriodStart/end
Time ZoneUTC/IST/etc.

7. Integrity Information

Where integrity verification is appropriate, record:

FieldDetails
Integrity RequiredYes/No
Hash AlgorithmSHA-256/SHA-512/etc.
Original HashHash calculated at collection
Verification HashHash calculated during verification
Hash MatchYes/No
Verified ByReviewer
Verification Date/TimeDate/time
Integrity NotesAdditional information

Important

Do not place:

  • Passwords
  • API keys
  • Private keys
  • Access tokens
  • MFA recovery codes
  • Secrets

into the Chain-of-Custody Form.

If evidence contains secrets, record only that sensitive credentials/secrets are present and protect the underlying evidence accordingly.


8. Initial Custody Record

The first custody record establishes who collected or received the evidence.

FieldDetails
Evidence IDEV-2026-0042
Released ByPerson/team
Received ByInvestigator
Release Date/TimeDate/time
Receipt Date/TimeDate/time
LocationSecure repository/location
PurposeIncident investigation
ConditionOriginal/working copy/sealed
Integrity VerifiedYes/No
Signature/ApprovalRequired where applicable

9. Custody Transfer Log

Every significant transfer should be recorded.

Transfer #Date/TimeReleased ByReceived ByFromToPurposeConditionIntegrity VerifiedSignature
130-Sep-2026 10:45Security EngineerInvestigatorAWS evidence repositoryInvestigation repositoryInvestigationUnchangedYesRecorded
230-Sep-2026 14:20InvestigatorSecurity LeadInvestigation repositoryRestricted review repositoryReviewUnchangedYesRecorded
301-Oct-2026 11:00Security LeadLegal CounselRestricted repositoryApproved legal repositoryLegal reviewUnchangedYesRecorded

The transfer log should continue until the evidence is returned, archived, or disposed of.


10. Transfer Information

For every transfer, record:

  • Evidence ID
  • Incident ID
  • Date/time released
  • Date/time received
  • Sender
  • Recipient
  • Sender role
  • Recipient role
  • Source location
  • Destination location
  • Reason for transfer
  • Transfer method
  • Evidence condition
  • Integrity verification
  • Authorization
  • Receipt confirmation

11. Transfer Methods

Approved transfer methods may include:

  • Controlled internal repository
  • Encrypted file transfer
  • Secure evidence platform
  • Encrypted removable media
  • Approved secure cloud storage
  • Secure legal/forensic exchange platform
  • Physical handover under controlled conditions

Do not use uncontrolled channels such as:

  • Personal email
  • Personal cloud storage
  • Consumer file-sharing accounts
  • Public messaging platforms
  • Unapproved USB devices

unless explicitly authorized under an appropriate exception process.


12. Physical Evidence

For physical evidence, record additional details.

Examples:

  • Laptop
  • Mobile phone
  • USB device
  • Server media
  • Security appliance
  • Hardware device
  • Printed records
  • Physical access-control media

Record:

FieldExample
Device TypeLaptop
ManufacturerExample manufacturer
ModelExample model
Serial NumberRecorded
Asset IDAST-2026-0012
ConditionPowered off
PackagingTamper-evident packaging
Seal NumberSEC-00482
Storage LocationRestricted evidence locker
CustodianSecurity Investigator

Photographs may be retained where appropriate to document physical condition at collection.


13. Digital Evidence

For digital evidence, record:

  • Evidence ID
  • Source system
  • Host/resource
  • Account
  • Environment
  • Original location
  • Collection method
  • Tool
  • Tool version where relevant
  • Date/time
  • Time zone
  • File name
  • File size
  • Hash
  • Storage location
  • Working-copy information

The original evidence should be preserved where required, while analysis should preferably be performed against an authorized working copy.


14. Cloud Evidence

Cloud evidence requires additional attention because evidence may be:

  • Generated dynamically.
  • Distributed across services.
  • Retained for a limited period.
  • Changed by normal system operations.
  • Accessible through administrative APIs.
  • Located in different regions.
  • Subject to provider retention policies.

AWS Example

For an AWS account compromise, evidence may include:

  • AWS CloudTrail
  • IAM activity
  • GuardDuty findings
  • Security Hub findings
  • S3 access records
  • VPC Flow Logs
  • WAF logs
  • EC2 activity
  • RDS audit records
  • KMS activity
  • Secrets Manager access
  • CI/CD activity

Record the relevant:

AWS Account → Region → Service → Resource → Time Period → Collection Method → Evidence ID → Hash/Integrity → Storage Location


15. Example: AWS CloudTrail Evidence

Evidence

EV-2026-0042

Description

CloudTrail activity covering the period surrounding a suspected AWS administrator account compromise.

Source

AWS CloudTrail

Collection

Exported using an approved AWS security process.

Time Period

30 September 2026 00:00 UTC – 30 September 2026 12:00 UTC

Purpose

Determine:

  • Authentication activity
  • IAM changes
  • Role creation
  • Policy changes
  • S3 access
  • Security-group modifications
  • Other unauthorized API activity

Custody

AWS CloudTrail → Security Engineer → Restricted Evidence Repository → Incident Investigator → Security Lead

Each custody transition is recorded in the transfer log.


16. Evidence Packaging

Where multiple related files are transferred together, create an evidence package.

Example:

EVPKG-2026-0017

Containing:

  • EV-2026-0042 — CloudTrail
  • EV-2026-0043 — IAM policy history
  • EV-2026-0044 — GuardDuty finding
  • EV-2026-0045 — S3 access evidence

The package should have:

  • Package ID
  • List of evidence IDs
  • Package creation date/time
  • Creator
  • Hash where appropriate
  • Storage location
  • Transfer history

This makes large investigations easier to manage.


17. Evidence Condition

Record the condition of evidence at every relevant transfer.

Use controlled values such as:

ConditionMeaning
OriginalOriginal evidence preserved
Working CopyAuthorized copy used for analysis
SealedEvidence packaged/sealed
UnchangedIntegrity verified and unchanged
ModifiedEvidence changed — document why
DamagedEvidence damaged
IncompleteEvidence appears incomplete
UnknownCondition cannot be established

If evidence appears altered or corrupted, immediately document the condition and investigate the cause.


18. Integrity Verification During Transfer

Where integrity controls are required:

  1. Calculate or record the original hash.
  2. Transfer the evidence through an approved method.
  3. Calculate the receiving hash.
  4. Compare the values.
  5. Record the result.
  6. Investigate any mismatch.

Example

Original SHA-256: Recorded in controlled record

Receiving SHA-256: Same

Result: Integrity verified

If hashes do not match:

Do not silently replace the evidence.

Record the discrepancy, preserve both versions where appropriate, determine the cause, and escalate for investigation.


19. Evidence Access During Custody

Access should be limited to authorized personnel.

Record access where required:

Date/TimeEvidence IDPersonPurposeActionResult
30-Sep-2026 13:10EV-2026-0042InvestigatorTimeline analysisViewedCompleted
30-Sep-2026 14:05EV-2026-0042Security LeadInvestigation reviewReviewedCompleted

Access should follow least-privilege and need-to-know principles.


20. Third-Party Evidence

Evidence may be received from:

  • Cloud providers
  • SaaS providers
  • Managed security providers
  • Customers
  • Suppliers
  • External investigators
  • Penetration testers
  • Legal counsel
  • Insurance providers
  • Law enforcement where applicable

For third-party evidence, record:

  • Provider
  • Contact
  • Date received
  • Method received
  • Evidence description
  • Provider’s evidence reference
  • Integrity information provided
  • Original source
  • Restrictions
  • Confidentiality requirements
  • Storage location
  • Internal Evidence ID

Example:

AWS Provider Reference: CASE-XXXX

Internal Evidence ID: EV-2026-0051

This allows the organization’s internal investigation record to remain linked to the external provider record.


21. Evidence Receipt Confirmation

The receiving person should confirm:

☐ Correct Evidence ID received
☐ Correct evidence package received
☐ Source identified
☐ Date/time recorded
☐ Transfer method recorded
☐ Evidence condition checked
☐ Integrity checked where required
☐ Storage location confirmed
☐ Access restrictions applied
☐ Receipt recorded


22. Lost, Damaged, or Missing Evidence

If evidence is lost, damaged, corrupted, or cannot be located:

  1. Record the event immediately.
  2. Do not alter the original record.
  3. Identify the last known custodian.
  4. Review access and transfer records.
  5. Determine potential impact.
  6. Attempt recovery where appropriate.
  7. Determine whether another copy exists.
  8. Document evidence limitations.
  9. Escalate according to incident/investigation requirements.
  10. Record corrective action if necessary.

Example

Evidence: EV-2026-0031

Issue: Original endpoint image unavailable.

Impact: Full forensic review cannot be completed.

Alternative: EDR telemetry and authentication logs available.

Decision: Investigation proceeds with documented evidence limitation.


23. Evidence Copy Management

When a copy is created:

  • Assign a relationship to the original Evidence ID.
  • Identify it as a working copy.
  • Record creation date/time.
  • Record who created it.
  • Record purpose.
  • Preserve the original where required.
  • Apply appropriate integrity controls.

Example:

Original: EV-2026-0042

Working Copy: EV-2026-0042-WC01

Purpose: Investigation analysis

This prevents analysts from accidentally treating a working copy as the original evidence.


24. Chain-of-Custody Closure

Before closing custody, confirm:

☐ Evidence identity confirmed
☐ All transfers recorded
☐ All relevant custodians identified
☐ Integrity verified where required
☐ Evidence access reviewed
☐ Investigation completed
☐ Evidence linked to findings
☐ Retention requirement determined
☐ Legal hold checked where applicable
☐ Archive/disposal decision approved
☐ Final storage location recorded
☐ Final custodian recorded
☐ Chain-of-custody record completed


25. Final Disposition

Evidence may be:

Retained

Evidence remains in the approved repository.

Archived

Evidence is moved to controlled long-term storage.

Returned

Evidence is returned to the owner or source organization.

Disposed

Evidence is securely destroyed or deleted after authorized retention expiry.

Legal Hold

Evidence remains preserved because of legal, regulatory, contractual, or investigation requirements.

The final disposition should be recorded in the Evidence Register.


26. Chain-of-Custody Form — Minimum Template

FieldEntry
Evidence ID
Incident ID
Investigation ID
Evidence Title
Evidence Type
Source
Original Location
Collection Date/Time
Collected By
Collection Method
Classification
Integrity Required
Hash Algorithm
Original Hash
Current Hash
Storage Location
Current Custodian
Chain-of-Custody Status
Retention Requirement
Final Disposition
Closure Date
Approved By

27. Custody Transfer Record

Transfer #Released ByReceived ByDate/TimeFromToPurposeMethodConditionIntegrity VerifiedAuthorization
1
2
3
4

28. Declaration

Collector Declaration

I confirm that the evidence identified in this form was collected or received through an authorized process and that the information recorded in this Chain-of-Custody Form is accurate to the best of my knowledge.

Name: ______________________

Role: ______________________

Date/Time: __________________

Signature/Approval: __________________


Receiving Custodian Declaration

I confirm that I received the evidence identified above and that the evidence condition and integrity were checked where applicable.

Name: ______________________

Role: ______________________

Date/Time: __________________

Signature/Approval: __________________


Final Reviewer

I confirm that the Chain-of-Custody record has been reviewed and that all material custody transfers have been recorded.

Name: ______________________

Role: ______________________

Date/Time: __________________

Signature/Approval: __________________


29. Startup Implementation

A startup does not need a complex forensic management platform to establish basic chain-of-custody controls.

A practical model is:

Evidence Collection Form

↓

Evidence Register

↓

Chain-of-Custody Form — when required

↓

Restricted Evidence Repository

↓

Investigation

↓

Findings / RCA

↓

Corrective Action

↓

Closure / Retention / Disposal

For a SaaS startup, the most important controls are:

  • Centralized evidence repository
  • Restricted access
  • Unique Evidence IDs
  • Reliable timestamps
  • Source tracking
  • Integrity verification where appropriate
  • Transfer logging
  • Clear ownership
  • Retention and disposal decisions
  • Linkage to the incident investigation

30. Relationship With Evidence Management

The complete evidence process becomes:

Evidence Collection Procedure
Defines how evidence is collected.

↓

Evidence Collection Form
Records what was collected and how.

↓

Evidence Register
Provides the central inventory of evidence.

↓

Chain-of-Custody Form
Records who handled or transferred important evidence.

↓

Incident Investigation
Determines what the evidence demonstrates.

↓

Root Cause Analysis
Determines why the issue occurred.

↓

Corrective Action Tracker
Records what will be changed.

↓

Incident Closure Report
Documents the final decision and outcome.


31. ISO 27001 Alignment

The Chain-of-Custody Form can support the organization’s information-security evidence and incident-management processes, including:

  • Information security incident management
  • Evidence preservation
  • Access control
  • Logging and monitoring
  • Information classification
  • Protection of documented information
  • Investigation support
  • Corrective action
  • Risk management
  • Continual improvement

The exact level of chain-of-custody control should be determined according to the organization’s risk, legal and regulatory environment, contractual commitments, and investigation requirements.

The form should therefore be treated as a risk-based organizational control, rather than as a document that every organization must maintain for every security event.


32. Audit Evidence

An auditor, investigator, customer, regulator, or authorized reviewer should be able to select an Evidence ID and establish:

Where did it come from?

→ Who collected it?

→ When was it collected?

→ How was it collected?

→ Was its integrity protected?

→ Where was it stored?

→ Who accessed it?

→ Who transferred it?

→ Why was it transferred?

→ What investigation did it support?

→ What happened to it at the end?

This creates a defensible evidence trail.


33. Final Audit Trail

Evidence Identified

→ Collection Authorized

→ Evidence Collected

→ Evidence ID Assigned

→ Evidence Condition Recorded

→ Integrity Established Where Required

→ Evidence Secured

→ Custodian Identified

→ Evidence Transferred

→ Transfer Recorded

→ Evidence Received

→ Integrity Reverified Where Required

→ Evidence Access Recorded

→ Evidence Reviewed

→ Evidence Linked to Findings

→ Further Transfer Recorded Where Applicable

→ Retention Determined

→ Final Custodian Recorded

→ Archived / Returned / Disposed

→ Final Disposition Recorded

→ Chain of Custody Closed


34. Final Principle

If evidence changes hands, the organization should be able to explain who handled it, when, why, where it went, and whether its integrity was maintained.

Chain-of-Custody Principle

Identify → Secure → Record → Transfer → Verify → Trace → Protect → Review → Retain → Dispose

The objective is not to create paperwork for every log or screenshot.

The objective is to ensure that important evidence remains identifiable, controlled, traceable, and defensible throughout its lifecycle.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *