Meaning
An international standard provides detailed guidelines for the preservation, identification, collection and acquisition of digital evidence. Law enforcement and corporate security teams follow iso 27037 to ensure that digital data recovered from devices is handled in a manner that preserves its integrity. The standard applies to digital media such as hard drives, mobile phones and cloud storage systems.
It excludes the subsequent analysis and presentation phases of the forensic process.
Handling Phase
Protecting digital evidence from contamination requires immediate isolation of the device from all network connections. First responders must document the state of the device and its surroundings with photographs and written reports. Adherence to iso 27037 prevents the accidental modification of files during the initial recovery stages of an investigation.
For example, investigators use write-blocking hardware to extract data without altering the metadata on the source drive. These measures ensure that the recovered information is defensible in court.
Chain Custody
Maintaining a continuous and detailed log of everyone who handled the evidence is essential for legal admissibility. Every transfer of custody must be signed by both the sender and the receiver, documenting the exact date and time. Any gaps in this documentation can lead to the evidence being excluded from legal proceedings.
Device Acquisition
Extracting data from live systems requires distinct procedures compared to processing powered-off hardware. Live memory capture must occur before turning off a machine to avoid losing volatile information. Following the standard methodology guarantees that the acquisition process remains repeatable and verifiable by third-party experts.