3.2 Discussion
Getting Started
The three standards used to assess the admissibility of scientific evidence from expert testimony in the United States are Frye v. United States (1923), Daubert v. Merrell Dow Pharmaceuticals (1993), and Federal Rules of Evidence 702.
Applying these standards to the forensic investigation profession has established best practices for the identification, preservation, and analysis of forensics artifacts. For our purposes, the stages of a digital forensics investigation are:
1. Survey/Identification
2. Collection/Acquisition
3. Examination/Analysis
4. Report/Presentation
In this discussion, we will look at the various stages of a digital forensics investigation and you will explain why you think one particular stage is the most important in the investigatory process.
Upon successful completion of this discussion, you will be able to:
· Evaluate the effectiveness of stages in a digital forensic investigation.
· Prepare a critique of the U.S. Supreme Court’s decision in the case of Daubert v. Merrell Dow Pharmaceuticals.
Resources
· Textbook: Cybercrime and Digital Forensics: An Introduction
· Video: Digital Forensics
· Website: Computer Forensics Tool Testing Program
· IWU Resources
· Website: OCLS Critical Evaluation Checklist for Internet Websites
· Background Information
The digital forensics process provides professionals a methodology to ensure that their actions are consistent with established best practices and the results of their investigation rise to the level of admissibility in a court of law. Again, for our purposes, the stages of a digital forensics investigation are:
1. Survey/Identification
2. Collection/Acquisition
3. Examination/Analysis
4. Report/Presentation
Within each stage, the forensic investigations team must complete a number of critical actions and tasks:
· Survey/Identification: Tasks include establishing the safety of the crime scene, determining the best and safest approach to the scene, searching devices that might contain evidentiary artifacts, and photographing and documenting the collection process.
· Collection/Acquisition: Tasks include the collection of evidence articles, transporting the artifacts to a forensic laboratory, processing and analyzing evidentiary items with forensic tools, and preparing a report.
· Examination/Analysis: Tasks include data recovery, extraction, and analysis of the digital data to identify potential artifacts that might be included as evidentiary items.
· Report/Presentation: Tasks include presenting the report to the case agents, preserving the report and evidence items while awaiting the court case, testifying as an expert witness in support of the analysis, and finalizing the disposition of the case and related evidence.
The entire process is built around the five rules of evidence: admissibility, authenticity, completeness, reliability, and believability.
Instructions
1. Review the rubric to make sure you understand the criteria for earning your grade.
2. Read the following chapters in the textbook, Cybercrime and Digital Forensics: An Introduction:
a. Chapter 11, “Evolution of Digital Forensics”
b. Chapter 13, “Acquisition and Examination of Forensic Evidence”
c. Chapter 14, “Legal Challenges in Digital Forensic Investigations”
3. Review the NIST website for it Computer Forensics Tool Testing project. https://www.nist.gov/itl/ssd/software-quality-group/computer-forensics-tool-testing-program-cftt
4.
5. Watch the video “ Digital Forensics .” https://www.youtube.com/watch?v=Pf-JnQfAEew
6. Navigate to the threaded discussion and respond to the following:
a. Identify the stage in a digital forensic investigation that you consider to be the most important in the investigatory process and explain why you think so.
b. Your post should be between 200 and 300 words long.