unified
UC-IR-07 — Investigate incidents and preserve evidence and records
Track and document every incident from declaration to closure in a system of record covering status, actions performed, decisions, and timeline. Collect incident data and evidence using documented procedures that preserve integrity, provenance, and chain of custody so evidence remains suitable for disciplinary and legal proceedings, and record investigation actions as they are performed. Perform analysis, including root-cause analysis, to establish what took place and why, and record the conclusions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Incident Management & Response
- type
- corrective
- category
- administrative
Details
- unified_id
- UC-IR-07
- title
- Investigate incidents and preserve evidence and records
- statement
- Track and document every incident from declaration to closure in a system of record covering status, actions performed, decisions, and timeline. Collect incident data and evidence using documented procedures that preserve integrity, provenance, and chain of custody so evidence remains suitable for disciplinary and legal proceedings, and record investigation actions as they are performed. Perform analysis, including root-cause analysis, to establish what took place and why, and record the conclusions.
- domain
- Incident Management & Response
- control_type
- corrective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- IR-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.AN-03
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.AN-06
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- RS.AN-07
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.28
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-IR-07 — Investigate incidents and preserve evidence and records mitigates Missing or insufficient logging and audit trails
- strength
- primary
- rationale
- Recording investigation actions and preserving evidence integrity, provenance, and chain of custody defends against unattributable and tampered records (mustKeep).
- Cybersecurity Incident Response operates UC-IR-07 — Investigate incidents and preserve evidence and records
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-IR-07 — Investigate incidents and preserve evidence and records
- UC-IR-07 — Investigate incidents and preserve evidence and records maps_to IR-5 — Incident Monitoring
- framework
- nist-800-53
- control_id
- IR-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Fraud & Forensic Investigation Engagement operates UC-IR-07 — Investigate incidents and preserve evidence and records
- UC-IR-07 — Investigate incidents and preserve evidence and records mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Root-cause analysis establishes the full extent and method of a multi-stage intrusion so eradication can be made complete.
- UC-IR-07 — Investigate incidents and preserve evidence and records maps_to RS.AN-06 — Incident Analysis: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
- framework
- nist-csf-2
- control_id
- RS.AN-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-07 — Investigate incidents and preserve evidence and records maps_to RS.AN-03 — Incident Analysis: Analysis is performed to establish what has taken place during an incident and the root cause of the incident
- framework
- nist-csf-2
- control_id
- RS.AN-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-IR-07 — Investigate incidents and preserve evidence and records maps_to A.5.28 — Collection of evidence
- framework
- iso-27001
- control_id
- A.5.28
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Incident Management Lifecycle operates UC-IR-07 — Investigate incidents and preserve evidence and records
- UC-IR-07 — Investigate incidents and preserve evidence and records maps_to RS.AN-07 — Incident Analysis: Incident data and metadata are collected, and their integrity and provenance are preserved
- framework
- nist-csf-2
- control_id
- RS.AN-07
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.