Preservation Of Digital Evidence

1119 Words3 Pages

I will explain and define what digital evidence is and I will provide a list of devices that could contain or store digital evidence. I will discuss the issue of properly preserving digital evidence. I will discuss how to properly preserve and document a computer crime scene prior to seizing the computer. I will discuss how to properly shut down computers after the crime scene has been properly documented and photographed. I will also discuss transporting and evidence transmittal issues. Digital evidence is also referred to as electronic evidence. Digital evidence is any probative information stored or transmitted digitally (Digital, 2001) and takes the form of electronic data, or information that is stored in bits and bytes on …show more content…

Investigators will take photographs of the computer and especially the computer screen from different angles and up close to document and preserve any applications, images, running programs, documents, open windows, and data files that were opened by the user (Knetzger, 2008). It is in the best interest of the officer and the case that no one touches or moves the mouse, clicks on anything, use the keyboard, or any input device connected to the suspect’s computer. There are two reasons for this. The first is to prevent any possibility of activating a delete or wipe command preinstalled by the suspect. The second reason is that by not touching anything it ensures no data will be written to any part of the suspect’s computer system giving their defense opportunity to say the evidence was altered, changed, or planted (Knetzger, …show more content…

This way if there are two or more computers connected on a network they can’t transfer and store evidence where the police aren’t searching. Before touching anything start by photographing the scene from a wide view and work to get closer so you have the clearest and most detailed photos (Knetzger, 2008). Then document exactly how the computer is set up including pictures of front/back of tower, the screen, mouse if there is one, keyboard, and any other peripheral devices like router or modem. As soon as the scene is documented and preserved color code the cables and correlating ports with one color for each cable, and make sure to document empty ports as well. It is essential that you disconnect the network cable as soon as everything is documented and preserved this prevents remote access to the computer to destroy evidence (Knetzger,

Open Document