Legal Cyber Academy
Standard or guidancePaywalledCurrent

ISO/IEC 27043 — Information technology — Security techniques — Incident investigation principles and processes

International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-03; reviewed and confirmed 2020; a further systematic review closed 2025-12-03 · 2015

Identifier: ISO/IEC 27043:2015

Access and status

Cost

Paywalled

Behind a subscription or per-item charge. Check whether your firm, university or public library already has access before paying at the door.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A 30-page standard setting out an idealised, process-class model for investigating incidents involving digital evidence, from readiness through initialisation, acquisition and investigation to reporting. It is the umbrella document that 27037, 27041 and 27042 sit under.

Who it is for, and when

Read it first if you are designing a whole investigative capability rather than a single procedure, because it gives you the vocabulary and the process map the other 270xx standards assume. It is also the easiest of the four to use when explaining to a non-technical audience where a given step sits in the overall process. It is paywalled: iso.org listed it at CHF 159 in September 2026, and readers should check iso.org for a newer revision before relying on this edition.

What it does not cover

It is deliberately abstract: no technical procedures, no tooling, and no legal or jurisdictional content. It also does not cover incident management itself — that is the ISO/IEC 27035 series (parts 1:2023 and 2:2023, part 3:2020 and part 4:2024, all published as at September 2026).

Go to the source

Open at iso.org (opens in a new tab)

https://www.iso.org/standard/44407.html

Details

Type
Standard or guidance
Written for
Working examinerWorking examiner
Publisher
International Organization for Standardization / International Electrotechnical Commission
Version verified
Edition 1, published 2015-03; reviewed and confirmed 2020; a further systematic review closed 2025-12-03
Year
2015
Identifier
ISO/IEC 27043:2015
Topics
incident-response, standards-development, evidence-handling
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.

  • The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.

  • A Kroll-owned Windows triage tool that collects forensically relevant files from a live or mounted system using configurable Targets, then runs parsers over what it collected using Modules. It bypasses file locks with raw disk reads and preserves original timestamps on the copies.

  • An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.

  • A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.