When it comes to using online content as evidence in a lawsuit, it’s not sufficient to have a screen capture or other image of the content. Cernam is introducing new “capture and preserve” technology that precisely captures online content and its metadata and other properties so the content is valid as evidence.
When I worked for a large corporation, every now and then my co-workers and I would get a notice from the legal department about a lawsuit the company was involved in. We’d be told that any documents and other business records we had generated or used were subject to scrutiny as evidence in the suit, and that we shouldn’t delete or destroy any records. Everything had to be preserved for potential admission in court.
With business lawsuits being fairly common, the practice of e-discovery is standard operating procedure for digital evidence. And for data and other records that are generated and stored in-house on the corporate network, saving an unadulterated copy is not a problem. The IT department can relatively easily create and preserve copies of every electronic record and document within its domain.
Today, however, legal departments are facing a new challenge that is largely the result of the consumerization of IT: Electronic documents and data that are central to a lawsuit may not reside within the company’s firewalls. Today it’s very likely that critical evidence could be posted to a blog or a social media website; saved to a cloud based storage system; stored in a SaaS application; or otherwise reside on some transient medium that is outside the control of the company. In this case, it’s difficult to capture the information in a way that satisfies legal requirements for the validity of evidence.
STUDY: IDC: IT hasn’t grasped consumerization trend
For example, suppose an employee posted information about a pending corporate takeover on his Facebook account. The stock price of the target company suddenly plunges in value and a lawsuit follows. By the time the lawyers attempt to preserve a copy of the Facebook post — the critical piece of evidence — it has been removed. Even if the lawyers had captured a screen shot of the Facebook post, it may be defective in terms of evidence because the screen shot could have been faked or altered.
Now there is a new solution coming to market that addresses this specific problem of online content as digital evidence. Cernam is a firm that specializes in digital investigations with a focus on online evidence and investigations. Cernam’s founder and managing director, Owen O’Connor, says “the use of online productivity tools has emerged as one of the biggest emerging sources of digital evidence and litigation type content. Online data is more fragile because it can be removed or changed. There is a need to bring forensic rigor to the capture and preservation of this content.”
Cernam is raising the bar in the use of online content as evidence. Today what people are doing in collecting online evidence is primarily focused on screen shots, printouts and PDF captures. Whereas when you look at email, which is a very mature area in terms of digital evidence, no one would consider a screen shot of an email as acceptable as evidence. If that were acceptable, the entire industry around e-discovery and digital forensics would not exist today, and we would be exchanging screen shots as evidence.
In an effort to fill the forensic reliability gap, Cernam has developed capture and preserve (C&P) technology which allows an organization to point to a piece of content on the Web and to capture and record it along with important metadata that is unique to that piece of content. So, rather than just taking a screen shot that is a picture of the evidence, C&P makes a perfect real copy — in forensic terms, the equivalent of a disk image of the data — which can be laid down as evidence. This evidence container can be independently assessed and can be accessed at a later date, regardless of whether the original online data is available or not.
Consider, for example, a tweet sent out via Twitter. You and I might only see the 140 characters of the tweet, but Cernam’s technology captures the hidden content of almost 100 separate properties pertaining uniquely to that message from that specific account, the metadata. All of these properties together provide forensic evidence of the original message that is far more persuasive in court.
Cernam’s technology is highly specialized and is aimed at law firms and corporations that are frequently involved in lawsuits. The software is in beta testing now and is expected to be generally available by the end of the year.
While it’s great to have such a tool to collect digital evidence if necessary, it’s even better to avoid the need altogether. You know, “an ounce of prevention is worth a pound of cure.” Given that O’Connor’s background before Cernam is in corporate security and electronic discovery, he shares with us his best practices for determining if (and how) employees are using online applications and services that might be putting your company at risk from data exposure.
• Review Web proxy logs to gain visibility into what applications are being used outside the firewall. Such logs can reveal, for example, that employees are sending files with Facebook messages. This begs the questions, what are these services being used for and what is potentially being stored there?
• Also look at these logs during key milestones such as the end of a quarter to determine access patterns. If you see a spike of activity with a particular application, it might indicate that a key business process has been hooked into an online service.
• Analyze company-issued mobile devices to see if apps such as Dropbox are installed. This is a red flag that could indicate that employees are sending or storing company data where it shouldn’t be going.
• There are popular collaboration applications in the cloud like Huddle and Basecamp that might be great for employee productivity but may breach policy and represent a risk for storing corporate data. Review your email and spam logs to determine what messages are coming in from these cloud services and who is using them.
• By tracking Web services usage trends, you can determine how access to online services is changing over time and potentially save yourself a few headaches when an e-discovery must take place.
Brian Musthaler is a principal consultant with Essential Solutions Corporation. You can write to him at Bmusthaler@essential-iws.com.
______________________________________________________________
About Essential Solutions Corp:
Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.




