INTRA/IV/IV005Forensic acquisition
The capture of data from a device or system in a manner that preserves what it contained.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| IV005/EUMandatory | European Union | NTH Haustechnik GmbH v EMCourt of Justice of the European Union, Fifth Chamber · read 16 Aug 2026 | That a court may rely on data obtained in breach, subject to minimization of what it admits and to considering anonymization before disclosure. | What a court admits has to be confined to the adequate, relevant, and necessary, and anonymization or pseudonymization considered before it goes to other parties. |
| IV005/NOMandatory | Norway | Forskrift om arbeidsgivers innsyn i e-postkasse og annet elektronisk lagret materialeArbeids- og inkluderingsdepartementet · read 29 Aug 2026 | When an employer may look into a work mailbox or a worker’s personal areas on its equipment, that monitoring of internet use is outside what it may do at all, and that the regulation cannot be contracted around. | The access is carried out so that the data are so far as possible not altered, and so that what it produced can be checked afterwards. |
| Recommended | Belgiumwhere written | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The sequence of events is reconstructed and the systems, assets, and resources involved identified, with forensic analysis used on the collected data where it is needed, and the analysis is to reach the underlying systemic cause rather than stopping at what triggered the event. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The order in which data are secured follows how volatile they are: what is quickly lost is taken first, then what is not, the contents of fixed storage, and last of all the backups. A storage medium should be duplicated forensically in full, and where that cannot be done, on memory or on a storage network partition, the method chosen is the one that alters least. Originals are kept sealed, written cryptographic checksums are made of them and held separately in several copies and secured against alteration, and for the result to be usable in court a witness should confirm how it was done and attest the checksums. Only trained staff or a forensic service provider should carry out the securing. |
