ISO/IEC 27037 — Information technology — Security techniques — Guidelines for identification, collection, acquisition and preservation of digital evidence
International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2012-10; reviewed and confirmed 2018; a further systematic review closed 2023-12-03 · 2012
Identifier: ISO/IEC 27037:2012
Access and status
Cost
Paywalled
Behind a subscription or per-item charge. Check whether your firm, university or public library already has access before paying at the door.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A 38-page international standard covering the first four handling activities for potential digital evidence: identification, collection, acquisition and preservation. It names the device classes in scope, including computer storage media, mobile phones, memory cards, navigation systems, still and video cameras including CCTV, and TCP/IP networks.
Who it is for, and when
Read it if you are writing or auditing a seizure and acquisition SOP, or if you need a citable international reference for why an acquisition was done the way it was. Lawyers use it to frame cross-examination on whether first responders followed a recognised process. It is the most frequently cited ISO standard in digital forensics reports. It is paywalled: iso.org listed it at CHF 181 in September 2026, and readers should check iso.org for a newer revision before relying on this edition.
What it does not cover
It stops at preservation — analysis, interpretation and reporting are out of scope and are handled by ISO/IEC 27042. It also sets no competence or accreditation requirements and does not tell you which tool to use. ISO's page shows it under systematic review, so check iso.org for a newer edition before citing it as current.
Go to the source
Open at iso.org (opens in a new tab)https://www.iso.org/standard/44381.html
Details
- Type
- Standard or guidance
- Written for
- Working examinerLawyers and courtsWorking examiner, Lawyers and courts
- Publisher
- International Organization for Standardization / International Electrotechnical Commission
- Version verified
- Edition 1, published 2012-10; reviewed and confirmed 2018; a further systematic review closed 2023-12-03
- Year
- 2012
- Identifier
- ISO/IEC 27037:2012
- Topics
- evidence-handling, chain-of-custody, imaging, mobile, standards-development
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
SWGDE Best Practices for Mobile Device Evidence Collection & Preservation, Handling and Acquisition
FreeSWGDE's guidance on the front half of mobile device work: isolating and preserving a seized handset, handling power and network state, and choosing among logical, file system and physical acquisition routes. The version verified here is 18-F-003-2.0 dated 21 August 2025.
An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.
NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.
A 27-page code of practice setting out requirements and guidance for each ediscovery activity, from initiating a matter and issuing preservation instructions through to producing ESI. It is the operational part of the ISO/IEC 27050 series.
SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.