Evidence Preservation In Procedural Investigation

648 Words2 Pages

Due to the volatile nature of the computer memory, information might be lost or overwritten over time. The chip in the random access memory helps the computer to run its programs more efficiently by pulling the data from the RAM. However, every time a machine is switched on, some data stored in the RAM is lost. Whereas the data stored on the hard drive is known as persistent data, the RAM is known as volatile memory. The RAM is constantly swapping the rarely used data that is the hard drive to create space for new information. Therefore, the longer the investigators wait, the more likely they will lose the incriminating data since the computer is not indefinitely persistent. It is fortunate that the investigators have found ways to preserve the evidence without necessarily switching on the computer. The contents are used in courts as the lawyers can use them as evidence for criminal activity. …show more content…

The purpose of preserving the data is to ensure that it can be utilized in court. If the evidence is not properly handled and protected, it might be hard for it to be admitted in the legal actions against the criminals. It is at the heart of computer forensics to collect, document, preserve and interpret the computer data. The aim of performing computer forensics is to determine who was responsible for an activity in a digital environment through a procedural investigation. In preserving the digital data, the investigators use different technologies to get access to and analyze the data in the computer systems. Preservation of data also relates to how the official data is, by analysis using various techniques and aspects. This practice needs an advanced expertise that is not conversant with the regular system users and the system support

Open Document