Legal Cyber Academy
Standard or guidancePaywalledCurrent

ISO/IEC 27042 — Information technology — Security techniques — Guidelines for the analysis and interpretation of digital evidence

International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03 · 2015

Identifier: ISO/IEC 27042:2015

Access and status

Cost

Paywalled

Behind a subscription or per-item charge. Check whether your firm, university or public library already has access before paying at the door.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A 14-page standard that picks up where ISO/IEC 27037 stops, covering the analysis and interpretation of potential digital evidence and the competence and proportionality considerations that go with them.

Who it is for, and when

Read it alongside 27037 if you are building an end-to-end process document and need an international citation for the analysis and interpretation stages, not just handling. Its value to lawyers is mainly as a reference point for the distinction between what an examiner observed and what the examiner concluded. It is paywalled: iso.org listed it at CHF 100 in September 2026, and readers should check iso.org for a newer revision before relying on this edition.

What it does not cover

It is very short and stays at the level of principles: no file system, mobile or cloud specifics, no statistical framework for evaluating findings, and no report template. For evaluative interpretation with likelihood ratios, ISO 21043-4 and the ENFSI evaluative reporting guideline are the substantive documents.

Go to the source

Open at iso.org (opens in a new tab)

https://www.iso.org/standard/44406.html

Details

Type
Standard or guidance
Written for
Working examinerLawyers and courtsWorking examiner, Lawyers and courts
Publisher
International Organization for Standardization / International Electrotechnical Commission
Version verified
Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03
Year
2015
Identifier
ISO/IEC 27042:2015
Topics
interpretation, reporting, evidence-handling, standards-development
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • A 10-page international standard specifying requirements for forensic reports and for the communication of findings, published June 2025 as part of the ISO 21043 series.

  • The paper that introduced CASE, the Cyber-investigation Analysis Standard Expression, an open community-developed specification language aligned with the Unified Cyber Ontology for representing and exchanging cyber-investigation information. It is co-authored by a NIST researcher and supersedes the earlier DFAX approach.

  • Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.

  • The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.

  • The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.