What Is ISO/IEC 27037 Used For? The Digital Evidence Management Standard
ISO/IEC 27037:2012 = the international standard for digital evidence identification, collection, acquisition and preservation. Compatible with CMK 134. 4 stages + chain of custody + hash verification.
ISO/IEC 27037:2012 is an international guideline standard prepared for the identification, collection, acquisition and preservation of digital evidence. It defines the roles of the first responder personnel at the scene (DEFR) and the specialist examiner (DESS), and mandates evidence integrity via hashing. In Turkey, together with CMK 134, it is the foundation of court admissibility.
TL;DR
- ISO/IEC 27037:2012 is the 4-stage international guideline for digital evidence management.
- The stages: identify, collect, acquire, preserve.
- It defines two fundamental roles: DEFR (first responder) and DESS (specialist).
- In Turkey it is used in compliance with CMK 134.
- Hash verification (SHA-256 recommended) and a chain of custody document are mandatory.
Detailed answer
Scope of the standard
ISO/IEC 27037 belongs to the information security investigation branch of the ISO 27000 series. The standard applies to any medium containing a digital device or potential digital evidence (PDE):
- Hard disks, SSD, NVMe media
- Memory (RAM) images
- Mobile devices, IoT and embedded systems
- Network traffic capture (PCAP), cloud logs
- CCTV and digital camera recordings
The standard does not dictate what to do and how with strict rules; it offers a process framework that is verifiable in hindsight and defensible. Detailed technical methods are complemented by ISO/IEC 27041, 27042 and 27043.
The four fundamental stages
| Stage | Description | Typical output |
|---|---|---|
| Identify | Determining the digital assets that could be evidence | Scene inventory, photo |
| Collect | Physical collection and transport of the device | Labeling, chain-of-custody form |
| Acquire | Taking an image (bit-by-bit or live) | dd/E01 image + hash |
| Preserve | Storing the evidence, protecting from unauthorized access | Faraday bag, safe, log |
The DEFR and DESS roles
The standard separates two roles. The DEFR (Digital Evidence First Responder) recognizes and safely collects the evidence at the scene; they do not perform advanced analysis. The DESS (Digital Evidence Specialist), on the other hand, has the authority for imaging, advanced analysis and reporting in the laboratory. This distinction is exactly parallel to the Cyber Incident Response Playbook NIST 800-61 process.
The hash verification requirement
ISO/IEC 27037 requires a cryptographic hash for integrity. In practice SHA-256 is the standard, and MD5 is kept as a double verification. The hash is computed at the moment the image is taken and written into the chain of custody form. The value recomputed at two separate times must be the same; otherwise the integrity of the evidence is considered broken. For algorithm selection details, you can look at our article What is hash verification, MD5 SHA1 SHA256.
Turkey application: compliance with CMK 134
Article 134 of the CMK No. 5271 orders that in the search of digital devices the image be taken by a judge's order and that two copies be made, one of which is given to the suspect/possessor. The acquire and preserve stages of ISO/IEC 27037 technically meet this legal requirement. In the Court of Cassation decisions, the evidentiary value of an examination conducted without taking an image has been found questionable.
It must not be forgotten that in corporate incidents the KVKK Board decisions expect evidence presentation in the data breach process; the KVKK 72-hour data breach notification template meets this need.
Practical checklist
- When the scene is reached, the device is photographed, and if it is running, a screenshot is taken.
- If the device is on, a RAM image (FTK Imager, Magnet RAM Capture) is taken first.
- If it is off, the cables are removed without turning it on; it is placed in a Faraday bag.
- In the laboratory it is connected with a write-blocker.
- A bit image is taken with dd, FTK Imager or X-Ways.
- SHA-256 + MD5 are computed and recorded in the report.
- The original device is stored in a secure safe, and the image on a redundant system.
- Every access is written into the chain-of-custody form.
Common mistakes
- Trying to turn on the device (alters the evidence).
- Connecting without a write-blocker (corrupts timestamps).
- Using only MD5; a double hash is recommended.
- Transporting a mobile without a Faraday bag; a remote wipe command may arrive.
- Not taking a backup image; if the single image is lost, the process ends.
Our crisis documents such as the Ransomware first 24 hours action schedule take ISO/IEC 27037 as a starting point.
Certification and training
ISO/IEC 27037 itself does not offer an individual certificate; however, certifications such as ENFSI (European Network of Forensic Science Institutes), IACIS CFCE, and GIAC GCFE/GCFA provide training compatible with this standard. In Turkey, TUBITAK BILGEM and the digital forensics master's programs of universities cover similar content.
Volatile evidence priority (order of volatility)
ISO/IEC 27037, in line with RFC 3227, sets the collection priority from the most volatile evidence to the most persistent:
- CPU register and cache content.
- RAM (live memory), open network connections, running processes.
- Temporary files, swap, hibernation file.
- Disk content, user files.
- Remote logs, physical configuration.
- Backup media, archive media.
If the DEFR does not have the competence to take a RAM image at the scene, keeping the device on and waiting until the DESS arrives is preferred. This rule especially ensures that the key remains in memory on devices where disk encryption (FileVault, BitLocker, LUKS) is enabled.
FAQ
Is ISO/IEC 27037 mandatory?
It is not legally mandatory, but it is the de facto standard for evidence admissibility in court. Within the scope of corporate policies and KVKK compliance, complying with it is a strong recommendation.
What is the difference between ISO/IEC 27037 and 27041?
27037 focuses on the collection and preservation of evidence; 27041, on the other hand, is a guide on how the validity of the analysis method is to be proven. 27042 is analysis and interpretation, 27043 is the incident investigation processes.
Should the device be left on or powered off?
If there is volatile data (RAM, open connections, encryption keys) on a running system, it is left on and a live image is taken first. If there is no such concern, unplugging is preferred; a proper shutdown can alter the evidence with cache writes.
How is cloud evidence collected?
The cloud service provider's log APIs and official legal request channels are used. For the cloud, ISO/IEC 27037 is interpreted together with 27050 and the CSA guides.
Does DSET provide ISO/IEC 27037-compliant service?
Yes. At its Hacettepe Teknokent Beytepe campus, DSET carries out imaging, hash verification and chain of custody management processes compliant with ISO/IEC 27037. Contact: +90 536 662 38 09, [email protected].
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.