* DOJ document provides tips for electronic crime scene investigation
endif; ?>When I reviewed a forensics newsletter earlier this week, I was reminded of _Electronic Crime Scene Investigation: A Guide for First Responders_, issued in 2001 by the technical working group for electronic crime scene investigation at the Office of Justice Programs, National Institute of Justice of the U.S. Department of Justice.
The free 93-page document begins with an introduction to information technology for law enforcement and other investigators.
Chapter 2 describes investigative tools and equipment such as screwdrivers, pliers, plastic bags and so on – obvious for investigators but less so for information technology geeks.
Chapter 3 discusses how to secure and evaluate the scene of a putative crime. The guide warns that in the initial phase of the investigation “do not alter the condition of any electronic devices: If it is off, leave it off. If it is on, leave it on.”
Chapter 4 explains how to document the scene for use in possible prosecutions or cases under civil law. Photographs are useful in this phase of data gathering.
Chapter 5 reviews evidence collection. In particular, the guide warns the investigator to remove the power cord at the computer side, not the wall outlet side. This procedure makes it more likely that the computer will be halted rather than shutting down (Sometimes computers are connected to uninterruptible power supplies which can signal the loss of main power and initiate a shutdown procedure, thus destroying some of the dynamic data on disk such as the swap file).
Chapter 6 gives instructions on safe packaging, transportation and storage of evidence. It is critically important that a proper chain of custody be established and documented for evidence at all stages of handling.
Chapter 7 and several appendices provide checklists of the types of evidence that are particularly useful in different types of crime; e.g., in auction fraud, accounting data and address books are on the list whereas in child exploitation cases, chat logs are particularly valuable.
This guide is written simply and clearly and should be used by anyone who is establishing or revising policy and procedures for computer emergency response teams to deal with the collection and safe handling of evidence in computer crime investigations.




