ISO/IEC 27042 — Information technology — Security techniques — Guidelines for the analysis and interpretation of digital evidence
International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03 · 2015
Identifier: ISO/IEC 27042:2015
Access and status
Cost
Paywalled
Behind a subscription or per-item charge. Check whether your firm, university or public library already has access before paying at the door.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A 14-page standard that picks up where ISO/IEC 27037 stops, covering the analysis and interpretation of potential digital evidence and the competence and proportionality considerations that go with them.
Who it is for, and when
Read it alongside 27037 if you are building an end-to-end process document and need an international citation for the analysis and interpretation stages, not just handling. Its value to lawyers is mainly as a reference point for the distinction between what an examiner observed and what the examiner concluded. It is paywalled: iso.org listed it at CHF 100 in September 2026, and readers should check iso.org for a newer revision before relying on this edition.
What it does not cover
It is very short and stays at the level of principles: no file system, mobile or cloud specifics, no statistical framework for evaluating findings, and no report template. For evaluative interpretation with likelihood ratios, ISO 21043-4 and the ENFSI evaluative reporting guideline are the substantive documents.
Go to the source
Open at iso.org (opens in a new tab)https://www.iso.org/standard/44406.html
Details
- Type
- Standard or guidance
- Written for
- Working examinerLawyers and courtsWorking examiner, Lawyers and courts
- Publisher
- International Organization for Standardization / International Electrotechnical Commission
- Version verified
- Edition 1, published 2015-06; reviewed and confirmed 2021; a further systematic review closed 2026-09-03
- Year
- 2015
- Identifier
- ISO/IEC 27042:2015
- Topics
- interpretation, reporting, evidence-handling, standards-development
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
A 10-page international standard specifying requirements for forensic reports and for the communication of findings, published June 2025 as part of the ISO 21043 series.
The paper that introduced CASE, the Cyber-investigation Analysis Standard Expression, an open community-developed specification language aligned with the Unified Cyber Ontology for representing and exchanging cyber-investigation information. It is co-authored by a NIST researcher and supersedes the earlier DFAX approach.
Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.
The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.
The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.