Notifications
Clear all

drive wiping

31 Posts
13 Users
0 Reactions
2,609 Views
(@patrick4n6)
Honorable Member
Joined: 16 years ago
Posts: 650
 

I've always worked on the basis that restore or forensic copy drives MUST be wiped, but containers for image files don't.

The reason is not some kind of data leakage, but that your forensic tools on a restore drive may pick up unpartitioned space on the drive at the end of your forensic clone, and therefore could introduce evidence from a previous case. I have never heard of an issue with a forensic tool picking up outside data from an image file. In order for this to happen, you'd have to have some major drive corruption, and if this happens, you've got more problems than just cross-contamination, you've likely got data loss too, and you're going to need to re-do your case from an uncorrupted image. (This is why I always have an image file drive untouched after verification in my evidence locker.)

The only other consideration giving rise to wiping drives is the privacy / privilege issue. My clients are informed in the contract that case files, images, etc. will be held for 1 year, more if needed (and paid for). Once that storage time is elapsed, I wipe the drives.


   
ReplyQuote
Page 4 / 4
Share: