Name Forensic Science
Computer Forensics
The word “computer” can mean any device
capable of storing digital information. That
information could be a digital file or the metadata associated with it.
Metadata (data that provides information about other data) can include
when a document was created, who the author is, etc. Computer
forensic examination proceeds through the following stages:
The Readiness stage includes educating the client, as well as testing and
verification of the software and equipment to be used, gaining familiarity
with relevant legislation, and preparing for how to handle unexpected
issues. In the Evaluation stage instuctions are recieved and clarified and
risks are analyzed and mitigated.
In the Collection stage, the examiner usually makes a copy of the
information that is on the device while it is turned off. A write-blocker is
used to make a bit-for-bit copy of the information. The examiner works
from this copy, so that the original is not changed. If a device cannot be
turned off, then the examiner will run a program on the device to copy
the contents of it to his or her own hard drive. This changes the data on
the source computer. However, as long as the examiner can prove that
the actions were necessary and were recorded, and the consequences
of it can be explained in court, evidence obtained is still admissable.
In the Analysis stage, the examiner analyzes what they have found. In the
Presentation stage, the examiner presents their findings. In the Review
stage, the examiner conducts a Lessons Learned assessment, and may
also seek feedback from the client.
Computer forensic investigators must not alter any data on the device in
question which may later be relied upon in court. If they access data,
they must be able to give evidence about the relevance and implications
of thier actions. Finally, they must create and preserve an audit trail of
their actions.
©[Link]