Questions: Evidence dynamics is anything that changes, moves, or obliterate evidence. Discuss what is digital evidence, in addition, what does the difficulties related to obtaining digital evidence exist?

profileshan77chan
Replytodoc1.docx

According to Easttom, digital evidence is information that has been processed and assembled so that it is relevant to an investigation and supports a specific finding or determination. All the data has to be relevant to the case in order for it to be considered evidence. Our textbook describes 4 different types of evidence, the first type of evidence discussed is real evidence. Real evidence is a physical object that someone can touch, hold, or directly observe like a laptop for example. The second type of evidence is documentary evidence which is data that is sorted in a written manner, on paper or in electronic files like emails, logs, and photographs. The third type of evidence discussed is testimonial evidence which is information that forensic specialist use to support or interpret real or documentary evidence. This type of evidence is typically the simplest because it’s usually a statement made by a witness and it doesn’t require any other piece of evidence to support it. The last type of evidence discussed is demonstrative evidence which is information that helps explain other evidence like a chart or graph.  

When obtaining digital evidence you need to make sure of the laws that would effect the investigation. Every jurisdiction has different legal requirements and some have passed laws that require the investigator to either be a law enforcement officer or to be a licensed private investigator for them to extract the evidence. Another complication when dealing with digital evidence is the handling of it. When dealing with digital evidence you want to handle the original evidence as little as possible to avoid altering any of the information. There’s a chance of accidentally altering the data which would prevent another investigator from doing a fresh analysis. Altering information can be something as small as changing the time stamp on a file.  

 Reference: 

Easttom, C. (2019). System forensics, investigation, and response (Third). Burlington, MA: Jones & Bartlett Learning.