Download presentation
Presentation is loading. Please wait.
Published byCornelius Brooks Modified over 9 years ago
1
THE IMPACT OF USING NON- VALIDATED FORENSIC ACQUISITION TOOLS ON DIGITAL EVIDENCE Lex Informatica Conference 25 th September 2014
2
DIGITAL EVIDENCE Digital evidence is increasingly common in court proceedings Digital evidence is a very fragile form of evidence and requires special methods to collect and preserve Digital forensics is a crucial tool in the collection and preservation of digital evidence
3
THE FORENSIC ACQUISITION PROCESS ProtectCollectVerify
4
FORENSIC ACQUISITION TOOLS Forensic Acquisition Write Blocking Forensic Imaging
5
MINIMUM ACCEPTABLE FORENSIC SCIENCE STANDARD Forensic Acquisition Tools Validated Findings Verifiable Correct Processes
6
THE CURRENT SITUATION IN SOUTH AFRICA
7
TRAINING ON THE IMPORTANCE OF VALIDATION
8
TRAINING ON HOW TO CONDUCT VALIDATION TESTING
9
KNOWLEDGE OF VALIDATION STANDARDS
10
CLAIMED TO USE VALIDATED WRITE BLOCKERS
11
HOW WRITE BLOCKING VALIDITY WAS ENSURED
12
REASONS FOR NOT USING VALIDATED WRITE BLOCKERS
13
HOW VALIDATION WAS CONFIRMED WHEN NOT TESTED PERSONALLY
14
PERSONAL VALIDATION TESTING OF WRITE BLOCKERS
15
CLAIMED USE OF VALIDATED FORENSIC IMAGING HARDWARE OR SOFTWARE
16
HOW FORENSIC IMAGER VALIDATION WAS ASSURED
17
REASONS FOR NOT USING VALIDATED FORENSIC IMAGING HARDWARE OR SOFTWARE
18
HOW VALIDATION WAS CONFIRMED FOR FORENSIC IMAGERS
19
PERSONAL VALIDATION TESTING OF FORENSIC IMAGERS
20
SO WHAT DOES THIS ALL MEAN At least 81 percent of all digital evidence that finds it way into South African courts cannot be objectively verified as having any evidential integrity. In the 19 percent of other cases, the means of objectively verifying evidential integrity is so poor that it would be unlikely to survive robust cross-examination.
21
SECTION 15 OF THE ECT ACT One of the key aspects that the courts must take into consideration when examining the weight of digital is the manner in which the integrity of the digital evidence was determined and maintained If non-validated tools are used to preserve the evidence, there is no way to prove to the court that the integrity of the digital evidence was determined or maintained at all
22
THE WAY FORWARD Insist on proof of all hardware and software tools used in the forensic acquisition process Insist on detailed proof of how validation was determined Don’t use any digital evidence that has not been obtained using validated forensic acquisition tools
23
THANK YOU Jason Jordaan CFCE, CFE, PMIITPSA, GCFE MSc, MTech, BComHons, BSc, BTech Principal Forensic Scientist jason@dfirlabs.com
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.