ISO/IEC 27037
Definition
An international standard providing guidelines for the identification, collection, acquisition, and preservation of digital evidence. Published by ISO in 2012. Used by forensic practitioners globally to benchmark collection procedures and support admissibility arguments in court.
- Publisher
- ISO/IEC
- Year published
- 2012
- Scope
- Identification, collection, acquisition, preservation of digital evidence
- Use
- Benchmark for procedures and admissibility arguments
Common questions
Does following ISO/IEC 27037 guarantee digital evidence is admissible in court?+
No. The standard describes sound practice for handling digital evidence, but admissibility is decided under the rules of the jurisdiction where the case is heard. Following it strengthens an argument that evidence was collected properly, but a court still applies its own legal tests.
Who is ISO/IEC 27037 written for?+
It targets first responders, digital evidence specialists, and anyone else who may handle digital devices or data during an investigation, not only dedicated forensic examiners. It is deliberately written to be applicable across different legal systems and types of digital device.
Related terms
- A2LA / UKAS / ANAB
- National accreditation bodies: A2LA (American Association for Laboratory Accreditation) and ANAB in the US; UKAS (United Kingdom Accreditation Service) in the UK....
- Forensic Readiness
- The organisational state in which people, processes, and technology are prepared to collect and preserve digital evidence with minimum disruption to business...
- ISO/IEC 17025
- The international standard for testing and calibration laboratories, published jointly by the International Organization for Standardization and the International Electrotechnical Commission. It...
- Jump Bag
- A pre-packed kit containing the hardware and media required for immediate on-site forensic response: write-blockers, imaging drives, bootable USB, cables, evidence labels,...
- Order of Volatility
- The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
- OSAC
- Organization of Scientific Area Committees for Forensic Science: established by NIST and DOJ in 2014, it develops consensus forensic standards through structured...
- Pre-Positioned Agent
- Lightweight endpoint software deployed across the organisation before any incident occurs. When an incident is declared, the IR team tasks agents remotely...
- SWGDE
- Scientific Working Group for Digital Evidence. A US multi-agency body that publishes consensus best-practice documents for digital forensic disciplines, including image authentication,...
- SWGIT
- Scientific Working Group for Imaging Technologies (US); publishes multi-section guidelines on crime-scene photography, digital imaging, and specialised photographic techniques for law enforcement.
- Write Blocker
- A hardware or software device interposed between a digital storage medium and the forensic workstation that prevents any write commands from reaching...
Explained in these topics
- Forensic Readiness and Response Toolkits
- SWGDE and SWGIT Standards for Digital and Imaging EvidenceThe international standard (2012) for identification, collection, acquisition, and preservation of digital evidence. Jurisdictionally neutral and widely refere...