ISO/IEC 27037:2012
Guidelines for identification, collection, acquisition and preservation of digital evidence.
Maintained source base · 2027 Edition
Primary standards, forensic guidance and platform documentation used to verify decision-relevant technical claims in Evidence First.
International standards
The ISO/IEC 27037–27043 forensic core is used as standards context for identification, collection, acquisition, preservation, method suitability, analysis/interpretation and the overall investigation process. Evidence First does not represent its ten-step editorial method as an ISO/IEC standard.
Guidelines for identification, collection, acquisition and preservation of digital evidence.
Guidance on assuring suitability and adequacy of incident investigative method.
Guidelines for the analysis and interpretation of digital evidence.
Incident investigation principles and processes.
Forensic guidance
17-F-002-2.1 · Best Practices for Computer Forensic Acquisitions, Version 2.1.
18-Q-001-2.1 · Minimum Requirements for Testing Tools Used in Digital and Multimedia Forensics, Version 2.1.
18-F-002-2.0 · Best Practices for Digital Evidence Collection, Version 2.0.
18-F-001-2.0 · Best Practices for Computer Forensic Examinations, Version 2.0.
14-F-003-2.0 · Considerations for Focused Collection of Digital Evidence, Version 2.0.
14-F-002-2.0 · Best Practices for Handling Damaged Digital Storage Devices.
22-F-003-2.0 · Best Practices for Remote Collection of Digital Evidence from an Endpoint.
SP 800-86 · Guide to Integrating Forensic Techniques into Incident Response.
SP 800-61r3 · Incident Response Recommendations and Considerations for Cybersecurity Risk Management.
Version-sensitive behavior and syntax are verified against primary platform and upstream documentation, including Microsoft Learn, Apple Platform Security and Developer documentation, systemd, procps-ng, iproute2, util-linux, cryptsetup, GNU Coreutils, tcpdump, VMware/Broadcom, Kubernetes and libvirt. The owning Evidence First card still determines whether an action is appropriate; syntax alone never owns the decision.
SWGDE 06-F-001-2.0 (Data Integrity, 17 June 2026) and SWGDE 23-F-005-1.1 (Apple macOS Forensic Acquisition, 23 October 2025) were consulted as drafts for public comment, not as final approved guidance. Historical first-response material may be retained for context when it does not override current platform or forensic guidance.
Corrections to bibliographic status or decision-relevant source changes are recorded through the Updates page rather than silently changing the edition record.