For electronic evidence to be admissible, it must comply with the ‘best evidence rule’ and ‘chain of custody’ must be so that rules out any tampering. The chain of custody in digital forensics can also be referred to as the forensic link, the paper trail, or the chronological documentation of electronic evidence. It indicates the collection, sequence of control, transfer, and analysis. It also documents each person who handled the evidence, the date/time it was collected or transferred, and the purpose for the transfer.
Chain of custody requires to
establish positively the possession of an item of evidence from time it is
collected till the time it is used in court. In order to preserve digital
evidence, the chain of custody should span from the first point of data collection, through
examination, analysis, reporting, and the time of presentation to the
Courts.
In order to ensure that the
chain of custody is as authentic as possible and enabled forensics run on the evidences to stand
in court, the following steps can be followed:
·
Work with
copies of the digital evidence as opposed to the original.
·
Photos of
physical (electronic) evidence establish the chain of custody and make it more
authentic.
·
Take
screenshots of digital evidence content
·
Document
date, time, and any other information of receipt. - Recording the timestamps of
whoever has had the evidence allows investigators to build a reliable timeline
of where the evidence was prior to being obtained.
·
Inject
a bit-for-bit clone of digital evidence content into the forensic
computers.
·
Creation
and preservation of MD5 Hashes - Performing a hash test ensures that the data
obtained from the previous bit-by-bit copy procedure is not corrupt and
reflects the true nature of the original evidence.

No comments:
Post a Comment