Preview

5 steps in a process to collect digital evidence

Good Essays
Open Document
Open Document
314 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
5 steps in a process to collect digital evidence
Some important steps in the process of collecting digital evidence from the time you are called to assist and the time when you have to testify are: identifying evidence, collecting evidence, preserving evidence, analyzing evidence and presenting evidence (Solomon et. al, 2011, Loc 2332).
One of the first steps in identifying evidence is understanding the purpose of the investigation. This knowledge will help you to decide what evidence you will need based on the type of case you’re participating in. A critical part of identifying evidence if it is a criminal investigation would be to know what is allowed on the search warrant. As the Computer Forensics Jumpstart we are using for our textbook, seldom is “take everything” allowed (Solomon et. al, 2011, Loc 2332). Even if the investigation does not involve a search warrant, care must be taken to operate within legal guidelines because ANY investigation may “end up as prime evidence for lawsuits in the future” (Solomon et. al, 2011, Loc 2341).
The second step in identifying the evidence is to take a look around. Perform a site survey (Solomon et. al, 2011, Loc 2351). Take pictures, make notes, sketch the area and make sure you have enough information to describe the area in detail should you need at some future date (Solomon et. al, 2011, 2361). Take note of what you see and what you think it means. You will look at the usual laptop or computer and at the hard drive and other portable storage devices of course, but remember to look beyond the obvious. The textbook uses the example of seeing a high-speed scanner and a credit card reader (Solomon et. al, 2011, Loc 2389) and thinking about what possibilities these items would be used for. Credit card readers are now available for iPhones and iPads and are quite portable (as small as 1” x 1”) and affordable

You May Also Find These Documents Helpful

  • Powerful Essays

    272. Newman, R. (2007). Computer Forensics: Evidence Collection and Managment. Boca Raton FL: Taylor & Francis Group. LLC.…

    • 4846 Words
    • 17 Pages
    Powerful Essays
  • Good Essays

    Cis 417 Assignment 1

    • 755 Words
    • 4 Pages

    There are many challenges for a computer forensics specialist and everyone faces the same challenges. There first challenge is to find a way to examine an increasing number of digital devices, each containing an immense volume of data, in a timely manner with limited resources (Charles L Cohen, n.d.). Another challenge is the fact that offenders are finding easier ways to store data. They…

    • 755 Words
    • 4 Pages
    Good Essays
  • Satisfactory Essays

    The next step is for the investigator to take notes of the crime scene. The process of note taking should be extensive, containing even notes they may seem insignificant but may become valuable evidence later (Fisher & Fisher, 2012). At this point evidence should not be moved or touched. Next pictures are taken at the crime just as it happened. The pictures should include scales to show accuracy in the evidence produced. Next is sketching the areas where the evidence was found is a way to support the picture evidence at court. The sketches should be accurate and contain measurements of the scene.…

    • 673 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Forensic evidence has been used since the beginning of investigating. It could be anything from ammunition, to a handprint on the door, to the drops of blood on the crime scene. As seen in “Forensic Evidence” by Andrea Campbell, the indisputable forensic evidence is the best kind to use in a trial.…

    • 276 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Week 5 Assignment

    • 349 Words
    • 1 Page

    A computer forensic investigation has three phases. List what they are and describe the activities that happen in each phase. The three phases of computer forensic investigations are; acquire the evidence, authenticate the evidence, and analyze the evidence. In acquiring the evidence the data is collected. Authenticating the evidence a chain of custody is used for the evidence to ensure its trustworthiness. Finally in analyzing the evidence the data is viewed and if need be a copy of the evidence can be created.…

    • 349 Words
    • 1 Page
    Satisfactory Essays
  • Satisfactory Essays

    Lab 1

    • 414 Words
    • 2 Pages

    2. Which items within WinAudit’s initial report would you consider to be of critical importance in a computer forensic investigation?…

    • 414 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Following the proper procedures within the means of the law and following a chain of command will help to ensure a conviction in cybercrimes. There are many different kinds of cybercrime, knowing the investigative process for the differences will assist in locating electronic evidence. The electronic evidence may include following Internet Protocol (IP) addresses, computer history logs, emails, files, and videos. While poor investigating will let the criminal avoid prosecution, conducting a proper cybercrime investigation can ensure a conviction.…

    • 664 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Unit Three Text Questions

    • 512 Words
    • 2 Pages

    1. What are the four types of evidence in a criminal investigation? The four types of evidence in a criminal investigation are physical, documentary, a testimony and demonstrative evidence.…

    • 512 Words
    • 2 Pages
    Satisfactory Essays
  • Powerful Essays

    DBQ Essay

    • 2260 Words
    • 10 Pages

    2Read the prompt. Determine what sort of evidence you will have to find in the documents based on the prompt…

    • 2260 Words
    • 10 Pages
    Powerful Essays
  • Satisfactory Essays

    Sometimes there can be a sudden requirement to perform hard drive forensic examination. The goals of your forensic examination can be related to virtually any subject, since any type of case/action can take place. Sometimes many instances you may not always perform a full-scale investigation or “fishing expedition” when reviewing the contents of media; in other words, your forensic examination of media may include criteria that focuses and narrows your examination.…

    • 140 Words
    • 1 Page
    Satisfactory Essays
  • Satisfactory Essays

    After the preservation phase, forensics are required to locate and identify any evidence that can be used to aid the crime case. There are several locations where evidence are usually found such as in the hard drive on the user’s personal computer, laptop, smart phone or tablet (ACPO, 2012). It is also critical that forensics are aware of the intention of the particular investigation. This aids in the forensics' efforts of locating digital evidences that are relevant to the case. For example, in the case of a server intrusion, forensics should look out for signs such as a rootkit installation, analyze configuration files, logs files and etc. These are possible locations and processes where traces of evidence can be picked out from (Carrier and Spafford, 2003).…

    • 257 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Evidence is any information gathered at the scene of a crime that may be relevant to a criminal investigation. There are different types of evidence that varies from Paperwork, Photographs, DNA, Finger prints; etc... These different kinds of evidence also require different types of opinions and explanations. Analyzing DNA is the best way to get your evidence. Every effort must be made to ensure that evidence is not lost, damaged, or contaminated. Evidence has many different roles in the investigation of a crime. It can link…

    • 406 Words
    • 2 Pages
    Satisfactory Essays
  • Powerful Essays

    Evidence Collection Policy

    • 2535 Words
    • 10 Pages

    That you are thorough, collect everything, do it in the proper and official manner, and that you do not tamper with or alter anything.…

    • 2535 Words
    • 10 Pages
    Powerful Essays
  • Good Essays

    Forensic evidence is scientific evidence provided by expert witnesses, obtained by scientific methods such as ballistics, blood testing, and DNA testing. There are two major types of forensic evidence, there is fragile or ‘transient’ evidence such as, hairs, fibers, glass, fractured objects, fire accelerants, skin cells; found on items touched or worn, barefoot impressions; latent and in blood, shoe and tire impressions, toolmarks; focus on point of entry, body fluids; blood, semen, and saliva, gunshot residue or patterns, and latent fingerprints, and there is solid or ‘tangible’ evidence such as, firearms, unfired cartridges, fired cartridge cases, fired bullets, other weapons; knives, metal bars, bats etc.., computers and devices, documents; checks, notes and receipts, drugs, and paraphernalia (MSP,…

    • 1556 Words
    • 7 Pages
    Good Essays
  • Powerful Essays

    Trace Evidence

    • 1605 Words
    • 7 Pages

    Crime scenes are known to have many clues left behind. The obvious would be a the body or bodies, clothing, and sometimes even the murder weapon. While these are great way to solve a case there's another kind of evidence; trace evidence. Trace evidence are small pieces of evidence that are laying around a crime scene. There are many types of trace evidence some of them include metal filings, plastic fragments, gunshot residue, glass fragments, feathers, food stains, building materials, lubricants, fingernail scrapings, pollens and spores, cosmetics, chemicals, paper fibers and sawdust, human and animal hairs, plant and vegetable fibers, blood and other body fluids, asphalt or tar, vegetable fats and oils, dusts and other airborne particles, insulation, textile fibers, soot, soils and mineral grains, and explosive residues. Although these are the most common found elements, they are not the only ones. The Trace Evidence Unit is known to examine the largest variety of evidence types and used the biggest range of analytical methods of any unit. materials are compared with standards or knowns samples to determine whether or not they share any common characteristics. In this paper I will discuss the different kinds of trace evidence and how crime scene investigaros use it to solve cases and convict criminal.…

    • 1605 Words
    • 7 Pages
    Powerful Essays