DIN EN ISO IEC 27037-2016 Information technology - Security techniques - Guidelines for identification collection acquisition and preservation of digital evidence (ISO IEC 27037 20.pdf
《DIN EN ISO IEC 27037-2016 Information technology - Security techniques - Guidelines for identification collection acquisition and preservation of digital evidence (ISO IEC 27037 20.pdf》由会员分享,可在线阅读,更多相关《DIN EN ISO IEC 27037-2016 Information technology - Security techniques - Guidelines for identification collection acquisition and preservation of digital evidence (ISO IEC 27037 20.pdf(47页珍藏版)》请在麦多课文档分享上搜索。
1、December 2016 English price group 20No part of this translation may be reproduced without prior permission ofDIN Deutsches Institut fr Normung e. V., Berlin. Beuth Verlag GmbH, 10772 Berlin, Germany,has the exclusive right of sale for German Standards (DIN-Normen).ICS 35.030!%X“2599153www.din.deDIN
2、EN ISO/IEC 27037Information technology Security techniques Guidelines for identification, collection, acquisition and preservation of digital evidence (ISO/IEC 27037:2012);English version EN ISO/IEC 27037:2016,English translation of DIN EN ISO/IEC 27037:2016-12Informationstechnik ITSicherheitsverfah
3、ren Leitfaden fr die Identifikation, Mitnahme, Sicherung und Erhaltung digitaler Beweismittel (ISO/IEC 27037:2012);Englische Fassung EN ISO/IEC 27037:2016,Englische bersetzung von DIN EN ISO/IEC 27037:2016-12Technologies de linformation Techniques de scurit Lignes directrices pour lidentification, l
4、a collecte, lacquisition et la prservation de preuves numriques (ISO/IEC 27037:2012);Version anglaise EN ISO/IEC 27037:2016,Traduction anglaise de DIN EN ISO/IEC 27037:2016-12www.beuth.deDocument comprises 47 pagesDTranslation by DIN-Sprachendienst.In case of doubt, the German-language original shal
5、l be considered authoritative.01.17 DIN EN ISO/IEC 27037:2016-12 2 A comma is used as the decimal marker. National foreword This document (EN ISO/IEC 27037:2016) has been prepared by Joint Technical Committee ISO/IEC JTC 1 “Information technology”, Subcommittee SC 27 “IT Security techniques” (Secret
6、ariat: DIN, Germany). Based on a decision of CEN/BT, ISO/IEC 27037:2012 has been submitted to the Unique Acceptance Procedure (UAP) and taken over as EN ISO/IEC 27037:2016 without any modification. The responsible German body involved in its preparation was DIN-Normenausschuss Informationstechnik un
7、d Anwendungen (DIN Standards Committee Information Technology and selected IT Applications), Working Committee NA 043-01-27-04 AK IT-Sicherheitsmanahmen und Dienste. The DIN Standard corresponding to the International Standard referred to in this document is as follows: ISO/IEC 27000 E DIN ISO/IEC 2
8、7000*)National Annex NA (informative) Bibliography E DIN ISO/IEC 27000, Information technology Security techniques Information security management systems Overview and vocabulary *)Under preparation. EUROPEAN STANDARD NORME EUROPENNE EUROPISCHE NORM EN ISO/IEC 27037 August 2016 ICS 35.040 English Ve
9、rsion Information technology - Security techniques - Guidelines for identification, collection, acquisition and preservation of digital evidence (ISO/IEC 27037:2012) Technologies de linformation - Techniques de scurit - Lignes directrices pour lidentification, la collecte, lacquisition et la prserva
10、tion de preuves numriques (ISO/IEC 27037:2012) Informationstechnik - IT-Sicherheitsverfahren - Leitfaden fr die Identifikation, Mitnahme, Sicherung und Erhaltung digitaler Beweismittel(ISO/IEC27037:2012) This European Standard was approved by CEN on 19 June 2016. CEN and CENELEC members are bound to
11、 comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical references concerning such national standards may be obtained on application to the CEN-CE
12、NELEC Management Centre or to any CEN and CENELEC member. This European Standard exists in three official versions (English, French, German). A version in any other language made by translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
13、 Management Centre has the same status as the official versions. CEN and CENELEC members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Irel
14、and, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and United Kingdom. EUROPEAN COMMITTEE FOR STANDARDIZATION COMIT EUROPEN DE NORMALISATION EUROPISCHES KOMITEE FR NORMUNG CEN-CENELEC Management Cen
15、tre: Avenue Marnix 17, B-1000 Brussels 2016 CEN and CENELEC All rights of exploitation in any form and by any means reserved worldwide for CEN and CENELEC national Members. Ref. No. EN ISO/IEC 27037:2016 E Contents Page European foreword . 4 Introduction . 6 1 Scope . 8 2 Normative reference 8 3 Ter
16、ms and definitions . 9 4 Abbreviated terms . 11 5 Overview 13 5.1 Context for collecting digital evidence . 13 5.2 Principles of digital evidence 13 5.3 Requirements for digital evidence handling 13 5.3.1 General. 13 5.3.2 Auditability 14 5.3.3 Repeatability . 14 5.3.4 Reproducibility . 14 5.3.5 Jus
17、tifiability 14 5.4 Digital evidence handling processes 15 5.4.1 Overview 15 5.4.2 Identification . 15 5.4.3 Collection 16 5.4.4 Acquisition 16 5.4.5 Preservation 17 6 Key components of identification, collection, acquisition and preservation of digital evidence 17 6.1 Chain of custody 17 6.2 Precaut
18、ions at the site of incident . 18 6.2.1 General. 18 6.2.2 Personnel 18 6.2.3 Potential digital evidence 19 6.3 Roles and responsibilities . 19 6.4 Competency 20 6.5 Use reasonable care . 20 6.6 Documentation . 21 6.7 Briefing 21 6.7.1 General. 21 6.7.2 Digital evidence specific 21 6.7.3 Personnel sp
19、ecific . 22 6.7.4 Real-time incidents . 22 6.7.5 Other briefing information . 22 6.8 Prioritizing collection and acquisition 23 6.9 Preservation of potential digital evidence 24 6.9.1 Overview 24 6.9.2 Preserving potential digital evidence 24 6.9.3 Packaging digital devices and potential digital evi
20、dence . 24 6.9.4 Transporting potential digital evidence 25 DIN EN ISO/IEC 27037:2016-12 EN ISO/IEC 27037:2016 (E)2Foreword . 5 7.1.3 Acquisition 32 7.1.4 Preservation 36 7.2 Networked devices 36 7.2.1 Identification .36 7.2.2 Collection, acquisition and preservation 38 7.3 CCTV collection, acquisit
21、ion and preservation .40 Annex A (informative) DEFR core skills and competency description .42 Annex B (informative) Minimum documentation requirements for evidence transfer .44 Bibliography 45 DIN EN ISO/IEC 27037:2016-12 EN ISO/IEC 27037:2016 (E) 37 Instances of identification, collection, acquisi
22、tion and preservation 26 7.1 Computers, peripheral devices and digital storage media . 26 7.1.1 Identification . 26 7.1.2 Collection 28 European foreword The text of ISO/IEC 27037:2012 has been prepared by Technical Committee ISO/IEC JTC 1 “Information technology” of the International Organization f
23、or Standardization (ISO) and the International Electrotechnical Commission (IEC) and has been taken over as EN ISO/IEC 27037:2016. This European Standard shall be given the status of a national standard, either by publication of an identical text or by endorsement, at the latest by February 2017, an
24、d conflicting national standards shall be withdrawn at the latest by February 2017. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. CEN and/or CENELEC shall not be held responsible for identifying any or all such patent rights. Ac
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- DINENISOIEC270372016INFORMATIONTECHNOLOGYSECURITYTECHNIQUESGUIDELINESFORIDENTIFICATIONCOLLECTIONACQUISITIONANDPRESERVATIONOFDIGITALEVIDENCEISOIEC2703720PDF

链接地址:http://www.mydoc123.com/p-682861.html