5 steps in a process to collect digital evidence

Good Essays
Some important steps in the process of collecting digital evidence from the time you are called to assist and the time when you have to testify are: identifying evidence, collecting evidence, preserving evidence, analyzing evidence and presenting evidence (Solomon et. al, 2011, Loc 2332).
One of the first steps in identifying evidence is understanding the purpose of the investigation. This knowledge will help you to decide what evidence you will need based on the type of case you’re participating in. A critical part of identifying evidence if it is a criminal investigation would be to know what is allowed on the search warrant. As the Computer Forensics Jumpstart we are using for our textbook, seldom is “take everything” allowed (Solomon et. al, 2011, Loc 2332). Even if the investigation does not involve a search warrant, care must be taken to operate within legal guidelines because ANY investigation may “end up as prime evidence for lawsuits in the future” (Solomon et. al, 2011, Loc 2341).
The second step in identifying the evidence is to take a look around. Perform a site survey (Solomon et. al, 2011, Loc 2351). Take pictures, make notes, sketch the area and make sure you have enough information to describe the area in detail should you need at some future date (Solomon et. al, 2011, 2361). Take note of what you see and what you think it means. You will look at the usual laptop or computer and at the hard drive and other portable storage devices of course, but remember to look beyond the obvious. The textbook uses the example of seeing a high-speed scanner and a credit card reader (Solomon et. al, 2011, Loc 2389) and thinking about what possibilities these items would be used for. Credit card readers are now available for iPhones and iPads and are quite portable (as small as 1” x 1”) and affordable

You May Also Find These Documents Helpful

  • Better Essays

    Abstract Physical evidence is what is collected after a crime has been committed. This evidence may be introduced into a trial. This would be the evidence that is collected that is from a non-living origin. There are many types of physical evidence that the investigators collect. This type of evidence can conceivably include all or part of any object. The evidence that is found at the scene of a crime is considered evidence. One type of evidence that is found is physical evidence. This type can…

    • 1185 Words
    • 5 Pages
    Better Essays
  • Powerful Essays

    Digital Evidence

    • 3954 Words
    • 14 Pages

    Table of content 1. Introduction1 2. Description of Digital Evidence2 3. Principles of Cyber Forensics3 4. Examination of Digital Evidence4 4.1 Preserving the evidence5 4.2 Locating the evidence6 4.3 Selecting the evidence 7 4.4 Analysing the evidence 8 4.5 Validating the evidence 9 4.6 Presenting the evidence 12 5. The Importance of Crime Reconstruction Hypotheses and Alternate Hypotheses 14 6. Conclusion 15 References 16 1. Introduction…

    • 3954 Words
    • 14 Pages
    Powerful Essays
  • Better Essays

    Digital Evidence

    • 799 Words
    • 4 Pages

    head: Digital Evidence Darlene Sampson Digital Evidence January 8, 2012 Abstract This paper will help explain the basic understanding of computer forensics. I will also identify five areas in computers and computer application a forensic investigator can look for digital evidence. I will identify three types of criminal investigations that can utilize the services of computer forensic investigators. This paper will help with the understanding of computer forensics. Digital Evidence…

    • 799 Words
    • 4 Pages
    Better Essays
  • Good Essays

    The 5 Steps of the Writing Process 1. Prewriting : Prewriting is the first step in writing. When you are prewriting you are writing freely without worrying about grammar and spelling. You are just getting all of your thoughts down on paper. 2. Outlining the structure of ideas: This step is taking all of your thoughts and sorting them into a more organized idea. It helps you develop a topic sentence. 3. Drafting: This is your first version of a complete paper or writing. 4. Revising:…

    • 522 Words
    • 3 Pages
    Good Essays
  • Good Essays

    expensive and long process in court. It is a process of the examination of claims and determining the outcome of these claim benefits. When the claim is filed and received goes through a 5 stage process to determine how the claim should be paid, (1) initial processing, (2) automated review, (3) manual review, (4) determination, and (5) payment. The purpose of this flow chart is to show you the steps you must take and explain the process of each step and what the purpose is for. 5 STEPS OF THE ADJUDICATION…

    • 532 Words
    • 2 Pages
    Good Essays
  • Good Essays

    Digital Evidence

    • 342 Words
    • 2 Pages

    Digital evidence refers to any piece of electronic information that can be found or retrieve from any electronic device which can be used to provide evidence for any use of violation. Basically, “Any information of probative value that is saved or stored in a binary form is digital evidence.” (SWGDE, 1998, p5). Below are the lists of electronic devices that stores digital evidence and some of the possible ways that the information can be manipulated: Information stored inside mobile phones such…

    • 342 Words
    • 2 Pages
    Good Essays
  • Satisfactory Essays

    Digital Evidence

    • 353 Words
    • 2 Pages

    A cybercrime suspect can sometimes use creative means to commit his or her criminal offense. Some examples of sources a cybercrime suspect controls from which digital evidence may be obtained are listed below. 1) Computer systems, which consists of hardware and software that process data and is likely to include the case containing circuit boards, microprocessors, hard drive, memory, and interface connections, the monitor, keyboard, and mouse. A cybercrime suspect with a computer anywhere in…

    • 353 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    There are 5 steps to the physical evidence process. Step 1 of the physical process is to respond to the crime. Police officers will need to secure the crime scene and set up communication with other officers and investigators to establish a plan of action. These same officers and investigators must be able to communicate with witnesses at the crime scene. To accomplish this goal, the police on the scene must establish what has happened, was a crime committed, and if a crime was committed how…

    • 522 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Digital Forensic Evidence

    • 592 Words
    • 3 Pages

    Evidence should be collected according to procedures that meet all applicable laws and regulations that have been developed from previous discussions with legal staff and appropriate law enforcement agencies, so that any evidence can be acceptable in court [10]. 1. Legal investigation 2. Digital forensic support 3. Get system photos after the incident has occurred 4. Report on date and time of the incident A. Phase 5: Containment and Eradication An incident should have a different containment and…

    • 592 Words
    • 3 Pages
    Satisfactory Essays
  • Satisfactory Essays

    preservation phase, forensics are required to locate and identify any evidence that can be used to aid the crime case. There are several locations where evidence are usually found such as in the hard drive on the user’s personal computer, laptop, smart phone or tablet (ACPO, 2012). It is also critical that forensics are aware of the intention of the particular investigation. This aids in the forensics' efforts of locating digital evidences that are relevant to the case. For example, in the case of a server…

    • 257 Words
    • 2 Pages
    Satisfactory Essays