You are here: silicon.com > Hardware > PDAs

PDAs

Cyber cops get forensics code

To prevent cases collapsing because of corrupted electronic evidence

Tags: forensics, cops, cyber cops, national hi-tech crime unit

By Andy McCue

Published: 26 September 2003 11:47 BST

Police have been issued new guidelines for gathering computer crime and electronic forensic evidence that deals with handling PDAs and mobile phones and the use of outside expert witnesses in investigations.

The revised Good Practice Guide for Computer-based Electronic Evidence has been compiled by the National Hi-Tech Crime Unit and the Association of Chief Police Officers with the aim of assisting the seizure of equipment and data and preventing its corruption.

The guide said: "Computer-based electronic evidence is, by its very nature, fragile. It can be altered, damaged or destroyed by improper handling or improper examination. Operating systems and other programs frequently alter and add to the contents of electronic storage."

A section of the booklet refers to the use of external expert investigators and witnesses in sensitive cases such as those involving images of paedophilia.

Just last month the Soham family police liaison officer Detective Constable Brian Stevens was cleared of 11 charges of possession and distribution of indecent photographs of children after the prosecution admitted a computer expert had made mistakes in assessing the evidence on Stevens' computer.

The guide acknowledges the difficulty police have in selecting external consulting witnesses but says "wherever practicable" all sensitive investigations should be conducted by law enforcement personnel.

General advice at crime scenes is for police to isolate and switch off machines that may contain electronic evidence but new guidance includes the handling of PDAs, organisers and mobile phones.

"With an organiser/PDA there is no hard disk and the concern has to be to change the evidence in the main memory as little as possible," it said. "[For mobile phones] the general advice is to switch the handset off due to the potential for loss of data if the battery fails or new network traffic overwrites call logs or recoverable deleted areas (eg SMS); there is also the potential for sabotage."

Commenting on the new guidelines, Mark Morris, head of forensics intelligence and security at LogicaCMG and former Scotland Yard Computer Crime Squad officer, said it is very easy for officers to unwittingly corrupt data and weaken any case where there is a prosecution.

"The evidence is volatile. It disappears very quickly. It is very easily destroyed and very quickly destroyed. Seize it, quarantine it and take a forensically sound image. Turn the computer off and leave it. [Any accessing of data] can alter the time and date stamp and that is the first hole any defence expert will go for," he said.

The guidelines are available here.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Senior QA (Quality Assurance) Officer, Biopharmaceutical Company

Senior QA (Quality Assurance) Officer, Biopharmaceutical Company, Staffordshire/Oxfordshire Senior QA (Quality Assurance) Officer: My client is a ...

Medical Information officer - Leadnig Pharmaco - South - East

As a medical information officer you responsibilities will include promotional approval, clinical paper summaries and enquiry handling. Leading ...

URGENT: QA (Quality Assurance) Manager, South London

For more information, please apply online or contact: Tom Froggatt at Real Pharma on 0207 758 7311 KEYWORDS: Quality Assurance, QA, quality, ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: