Information technology - Security techniques - Incident investigation principles and processes (ISO/IEC 27043:2015)

This International Standard provides guidelines based on idealized models for common incident
investigation processes across various incident investigation scenarios involving digital evidence. This
includes processes from pre-incident preparation through investigation closure, as well as any general
advice and caveats on such processes. The guidelines describe processes and principles applicable to
various kinds of investigations, including, but not limited to, unauthorized access, data corruption,
system crashes, or corporate breaches of information security, as well as any other digital investigation.
In summary, this International Standard provides a general overview of all incident investigation
principles and processes without prescribing particular details within each of the investigation
principles and processes covered in this International Standard. Many other relevant International
Standards, where referenced in this International Standard, provide more detailed content of specific
investigation principles and processes.

Informationstechnik - IT-Sicherheitsverfahren - Grundsätze und Prozesse für die Untersuchung von Vorfällen (ISO/IEC 27043:2015)

Technologies de l'information - Techniques de sécurité - Principes d'investigation numérique et les processus (ISO/IEC 27043:2015)

Informacijska tehnologija - Varnostne tehnike - Načela in postopki za preiskovanje incidentov (ISO/IEC 27043:2015)

Ta mednarodni standard podaja smernice na podlagi idealiziranih modelov za običajne
postopke za preiskovanje incidentov v različnih scenarijih preiskovanja incidentov, ki vključujejo digitalne dokaze. Vključeni so postopki priprave na incident prek zaključka preiskave ter splošni nasveti in opozorila v zvezi s takimi postopki. Smernice opisujejo postopke in načela za različne preiskave, ki med drugim vključujejo nepooblaščen dostop, poškodbo podatkov, zrušitev sistema ali poslovno kršitev varnosti podatkov ter druge digitalne preiskave.
Če povzamemo, ta mednarodni standard podaja splošen pregled vseh načel in postopkov za preiskovanje incidentov, pri čemer ne predpisuje posebnih podrobnosti v zvezi s posameznimi načeli in postopki preiskovanja, ki so obravnavani v tem mednarodnem standardu. Številni drugi ustrezni mednarodni standardi, kjer je tako navedeno v tem mednarodnem standardu, zagotavljajo podrobnejše informacije o določenih načelih in postopkih preiskovanja.

Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Symbols and abbreviated terms . 3
5 Digital investigations . 4
5.1 General principles . 4
5.2 Legal principles . 4
6 Digital investigation processes . 5
6.1 General overview of the processes . 5
6.2 Classes of digital investigation processes . 5
7 Readiness processes . 7
7.1 Overview of the readiness processes . 7
7.2 Scenario definition process . 9
7.3 Identification of potential digital evidence sources process . 9
7.4 Planning pre-incident gathering, storage, and handling of data representing
potential digital evidence process .11
7.5 Planning pre-incident analysis of data representing potential digital evidence process .11
7.6 Planning incident detection process .11
7.7 Defining system architecture process .11
7.8 Implementing system architecture process .12
7.9 Implementing pre-incident gathering, storage, and handling of data representing
potential digital evidence process .12
7.10 Implementing pre-incident analysis of data representing potential digital
evidence process .12
7.11 Implementing incident detection process .12
7.12 Assessment of implementation process .13
7.13 Implementation of assessment results process .13
8 Initialization processes .13
8.1 Overview of initialization processes .13
8.2 Incident detection process .14
8.3 First response process.15
8.4 Planning process .15
8.5 Preparation process.15
9 Acquisitive processes .16
9.1 Overview of acquisitive processes .16
9.2 Potential digital evidence identification process .16
9.3 Potential digital evidence collection process .17
9.4 Potential digital evidence acquisition process .17
9.5 Potential digital evidence transportation process .17
9.6 Potential digital evidence storage and preservation process .17
10 Investigative processes .18
10.1 Overview of investigative processes .18
10.2 Potential digital evidence acquisition process .19
10.3 Potential digital evidence examination and analysis process .19
10.4 Digital evidence interpretation process .19
10.5 Reporting process .19
10.6 Presentation process .20
10.7 Investigation closure process .

