Source status matters. Evidence First distinguishes final, draft, archived and historical material. A draft or archived document is not presented as current final guidance. Source status for this edition was verified on 14 August 2026.

International standards

Digital-investigation framework

The ISO/IEC 27037–27043 forensic core is used as standards context for identification, collection, acquisition, preservation, method suitability, analysis/interpretation and the overall investigation process. Evidence First does not represent its ten-step editorial method as an ISO/IEC standard.

ISO/IEC 27037:2012

Guidelines for identification, collection, acquisition and preservation of digital evidence.

Official ISO record

ISO/IEC 27041:2015

Guidance on assuring suitability and adequacy of incident investigative method.

Official ISO record

ISO/IEC 27042:2015

Guidelines for the analysis and interpretation of digital evidence.

Official ISO record

Forensic guidance

Computer collection, acquisition and validation

SWGDE · Computer acquisition

17-F-002-2.1 · Best Practices for Computer Forensic Acquisitions, Version 2.1.

Official source

SWGDE · Tool testing

18-Q-001-2.1 · Minimum Requirements for Testing Tools Used in Digital and Multimedia Forensics, Version 2.1.

Official source

SWGDE · Digital evidence collection

18-F-002-2.0 · Best Practices for Digital Evidence Collection, Version 2.0.

Official source

SWGDE · Computer examination

18-F-001-2.0 · Best Practices for Computer Forensic Examinations, Version 2.0.

Official source

SWGDE · Damaged storage

14-F-002-2.0 · Best Practices for Handling Damaged Digital Storage Devices.

Official source

SWGDE · Remote endpoint collection

22-F-003-2.0 · Best Practices for Remote Collection of Digital Evidence from an Endpoint.

Official source

NIST · Forensic techniques

SP 800-86 · Guide to Integrating Forensic Techniques into Incident Response.

NIST publication

NIST · Incident response

SP 800-61r3 · Incident Response Recommendations and Considerations for Cybersecurity Risk Management.

NIST publication

Platform documentation

Version-sensitive behavior and syntax are verified against primary platform and upstream documentation, including Microsoft Learn, Apple Platform Security and Developer documentation, systemd, procps-ng, iproute2, util-linux, cryptsetup, GNU Coreutils, tcpdump, VMware/Broadcom, Kubernetes and libvirt. The owning Evidence First card still determines whether an action is appropriate; syntax alone never owns the decision.

Draft and historical material

SWGDE 06-F-001-2.0 (Data Integrity, 17 June 2026) and SWGDE 23-F-005-1.1 (Apple macOS Forensic Acquisition, 23 October 2025) were consulted as drafts for public comment, not as final approved guidance. Historical first-response material may be retained for context when it does not override current platform or forensic guidance.

Corrections to bibliographic status or decision-relevant source changes are recorded through the Updates page rather than silently changing the edition record.