Alessandro AleddaInsider Threat and Risk

INTRA/IV/IV006Chain of custody

The unbroken record of who held what, when, and in what state.

Pillar
IV  |  Investigation and digital forensics
Sources cited
2
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
RecommendedBelgiumwhere writtenCyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch.Everyone involved in the response records what they did, in a way that prevents the record being tampered with or deleted, and the lead is answerable for documenting the whole investigation, its timelines, its decisions, and the sources of what it relied on. The incident data and their metadata, the source and the time of collection among them, are collected and protected so that they stay accurate, authentic, and traceable to where they came from.
RecommendedGermanywhere writtenIT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured.Every step taken in securing evidence should be documented, and the documentation should show without a gap how the original evidence was handled, which methods were used, and why the people responsible chose them. The originals should be stored so that only the staff conducting the examination, known by name, can reach them.