ISO 27001 5.28 Collection of Evidence Requirement:
"The organization shall establish and implement procedures for the identification, collection, acquisition and preservation of evidence related to information security events."[1]
ISO 27001 5.28 Collection of Evidence Requirement Explanation:
As part of the incident response process you must collect evidence of the incident. This includes system logs screen shots user reports system images and potentially physical hardware related to the incident.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you