ISO/IEC 27043 — Information technology — Security techniques — Incident investigation principles and processes
International Organization for Standardization / International Electrotechnical Commission · Edition 1, published 2015-03; reviewed and confirmed 2020; a further systematic review closed 2025-12-03 · 2015
Identifier: ISO/IEC 27043:2015
Access and status
Cost
Paywalled
Behind a subscription or per-item charge. Check whether your firm, university or public library already has access before paying at the door.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A 30-page standard setting out an idealised, process-class model for investigating incidents involving digital evidence, from readiness through initialisation, acquisition and investigation to reporting. It is the umbrella document that 27037, 27041 and 27042 sit under.
Who it is for, and when
Read it first if you are designing a whole investigative capability rather than a single procedure, because it gives you the vocabulary and the process map the other 270xx standards assume. It is also the easiest of the four to use when explaining to a non-technical audience where a given step sits in the overall process. It is paywalled: iso.org listed it at CHF 159 in September 2026, and readers should check iso.org for a newer revision before relying on this edition.
What it does not cover
It is deliberately abstract: no technical procedures, no tooling, and no legal or jurisdictional content. It also does not cover incident management itself — that is the ISO/IEC 27035 series (parts 1:2023 and 2:2023, part 3:2020 and part 4:2024, all published as at September 2026).
Go to the source
Open at iso.org (opens in a new tab)https://www.iso.org/standard/44407.html
Details
- Type
- Standard or guidance
- Written for
- Working examinerWorking examiner
- Publisher
- International Organization for Standardization / International Electrotechnical Commission
- Version verified
- Edition 1, published 2015-03; reviewed and confirmed 2020; a further systematic review closed 2025-12-03
- Year
- 2015
- Identifier
- ISO/IEC 27043:2015
- Topics
- incident-response, standards-development, evidence-handling
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.
The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.
KAPE (Kroll Artifact Parser and Extractor)
Partly freeA Kroll-owned Windows triage tool that collects forensically relevant files from a live or mounted system using configurable Targets, then runs parsers over what it collected using Modules. It bypasses file locks with raw disk reads and preserves original timestamps on the copies.
An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.
A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.