Forensic Focus
 
Web www.forensicfocus.com
Login or Register
HomeMy AccountBlogBasicsPapers/ArticlesForumsNewsletterEmail GroupInterviewsEventsTrainingDownloadsLinks
Subscribe to Feeds

Forensic News Jamie's Blog
Main Menu
MY ACCOUNT
COMMUNITY
RESOURCES
MISC
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!

Survey
Which of the following do you usually use for imaging evidence?




Results :: Polls

Votes: 23902
Comments: 0
Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!



Learning from Other's Mistakes: Issues Arising from Electronic Discovery

by Setec Investigations
http://www.setecinvestigations.com

Computer forensics and the associated electronic evidence and electronic discovery are relatively new to the litigation game. The use of such information is growing steadily and it has become impossible for legal professionals or their clients to claim that they are unaware of the existence of electronic information. The following intends to make clear mistakes involving computer forensics, electronic evidence, and electronic discovery that are often made:

Issue 1: Ignoring electronic information or attempting discovery of it in a disorganized manner
As almost all written information is now stored in electronic form rather than hard copy form, it is important for legal professionals to understand what electronic evidence is, how it can be identified, how it can be utilized to enhance a case, how to avoid the pitfalls associated with it, and how to avoid sanctions resulting from inadequately presenting it. When properly planned for, gathered, analyzed, and produced, almost every case would benefit from the utilization of electronic evidence.

Issue 2: Believing that deleted information is actually irreparably destroyed
Electronic evidence that has been "deleted" is rarely actually destroyed, as every electronic document leaves a fingerprint that is stored in unallocated space, as well as other locations on the computer hard drive. Even after information is "deleted" this fingerprint remains, and some semblance of it can usually be identified even if a powerful wipe tool has been used.

Issue 3: Lack of a backup or document retention policy
A document retention policy consists of the manner in which electronic documents are reviewed, retained, and destroyed throughout the course of normal business operations. Such a document retention policy should be based on state and federal statutes/rules that identify the length of time documents must be retained. The policy should also include steps for recording all documents that have been destroyed and should be updated as discovery obligations arise.

Issue 4: Not complying with preservation orders
Once a lawsuit is pending, it is the organization's obligation to immediately cease the destruction of electronic documents, as they may contain relevant evidence. It is crucial that the IT personnel responsible for such actions be informed of the preservation order, as they are often overlooked. In addition, any automated destruction systems must also be discontinued.


Issue 5: Failure to utilize certain forms of evidence
Electronic information is often stored on media devices that can be more difficult to work with, such as backup tapes, PDAs, or electronic tablets, and are often ignored. However, these forms of media often contain useful and relevant electronic evidence that can prove critical to the case. Many experts are able to work with these more difficult types of media, and retaining them early will help if the court orders production of electronic information contained within them.

Issue 6: Failure to produce all electronic evidence
The same rules apply for electronic evidence as they do for more traditional forms of evidence. The court system has broad discretion when applying sanctions for failing or waiting excessively to produce electronic evidence, including declaring a mistrial, delaying the start of the trial, imposing monetary penalties, or issuing an adverse inference instruction. Sanctions may be applied not only when a party has been grossly negligent or acted in bad faith, but also due to ordinary negligence.

Issue 7: Failure to forensically duplicate hard drives used by departing employees
Policies should be in place regarding the management of computer systems used by departing employees, both those that were terminated and those that resigned. In the event that litigation arises, the information stored on the forensic duplication of a hard drive could act as a smoking gun, especially if the employee has taken the computer system in question with him/her or if it has been reallocated to another employee.

Issue 8: Failure to use experienced computer forensic investigators
In all likelihood, the average IT professional, although good at his/her job, does not have the necessary knowledge or experience to properly conduct and manage a computer forensic investigation. IT professionals are very well-informed with regards to the organization, media types, software used, and data retention policies, all of which is important to a computer forensic investigation. However, it is best if IT professionals work with computer forensic investigators as, if not done properly with the correct tools and techniques, files stored on the computer system can be destroyed or date and timestamps can be changed, thus tainting the evidence stored within them. Therefore, experts in the field of computer forensics should be retained in order to ensure that evidence is properly collected and admissible in a court of law.




--
Setec Investigations is a subsidiary of Setec Security, a leading independent provider of vendor neutral information security solutions, incorporating a cross-disciplinary team comprised of computer forensic investigators, attorneys, law enforcement specialists, and seasoned business professionals who have established a proven track record of success since 1997.


Maintaining offices and forensic laboratories strategically positioned throughout North America, Setec Investigations is committed to providing intelligent, effective, and forensically sound computer investigative and litigation support solutions.



User Info

Welcome Anonymous

Nickname

Membership:
Latest: hunter33
New Today: 0
New Yesterday: 2
Overall: 6215

People Online:
Members: 2
Visitors: 4
Bots: 5
Staff: 0
Staff Online:

No staff members are online!
Forensic Focus Blog
· Matthew Shannon, F-Response - Interview questions please!
· UK Criminal Justice Bill - Clause 62 (or is it 63, or 64?)
· Interview with David Sullivan, Appointments-UK
· Reporting (again) and interviews
· Reporting - time for standardization?
· Posts from the blogoshpere
· Site stats
· Why the hell is everything so expensive?
· The problem with power
· Licensing

read more...
This site needs YOU!

Write for Forensic Focus
LINK TO US

OR
WRITE FOR US
OR
START A BLOG

Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Top10 Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: Cache View
  3: ACPO Good Practice Guide for Computer based Electronic Evidence
  4: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  5: PDA Forensic Tools:An Overview and Analysis
  6: Australasian Centre for Policing Research Best Practice Guide
  7: Autopsy Forensic Browser Version 2.03 (source code)
  8: Recover My Files
  9: Directors & Corporate Advisors' Guide to Digital Investigations and Evidence
  10: HELIX incident response CD

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2008 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.