Digital Forensics: Collecting and Examining Electronic Evidence
This paper examines the field of digital forensics and the challenges law enforcement faces when investigating electronic crimes. It discusses the wide range of devices that can serve as sources of digital evidence—from personal computers and tablets to telephone systems and access control devices—and explains why electronic evidence is particularly sensitive and prone to alteration. The paper outlines the four core phases of a forensic investigation: collection, examination, analysis, and reporting. It emphasizes proper handling procedures, documentation requirements, and the importance of preserving evidence for court proceedings, including the potential role of forensic examiners as expert witnesses.
- Introduction to Electronic Crime: Overview of digital crimes and devices involved
- The Nature of Electronic Evidence: Latent quality of digital evidence explained
- Sensitivity and Handling of Digital Evidence: Why electronic evidence requires careful handling
- Phase One: Collection: Warrants, documentation, and scene procedures
- Phase Two: Examination: Uncovering, documenting, and reporting digital evidence
- Conclusion: Packaging, Transportation, and Testimony: Final phase and courtroom role of examiners
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Consistently supports claims with citations from authoritative sources, including the U.S. Department of Justice and the National Institute of Justice, lending credibility to procedural descriptions.
- Organizes the forensic process in a logical, phase-by-phase sequence (collection → examination → packaging/testimony), making it easy to follow the investigative workflow.
- Balances broad contextual framing—explaining why electronic crime is a growing concern—with concrete procedural detail about how investigators should handle digital evidence.
Key academic technique demonstrated
The paper demonstrates effective use of direct quotation integrated with analysis. Rather than simply stringing together quotes, the writer introduces each quotation with context, then briefly explains its significance to the overall argument about proper forensic procedure. This technique shows readers how cited material supports the paper's claims without letting the sources speak entirely for themselves.
Structure breakdown
The paper opens with a broad introduction to electronic crime and the devices involved, then narrows to explain the latent nature and sensitivity of digital evidence. It proceeds through the forensic investigation phases in order, dedicating a paragraph to collection and another to examination. The conclusion addresses the post-examination phase—packaging, transportation, and potential courtroom testimony—rounding out the full lifecycle of a digital forensic investigation.
Introduction to Electronic Crime
The computer age has brought with it a whole new host of problems for law enforcement. According to the research, "the Internet, computer networks, and automated data systems present enormous new opportunity for committing criminal activity" (U.S. Department of Justice, 2013, p. 6). Many electronic devices are becoming facilitators for electronic crime. Hackers and other criminals frequently use computer systems and the Internet to commit crimes against both individuals and larger organizations. Crimes committed digitally include auction fraud, computer intrusion, economic fraud, e-mail harassment, extortion, identity theft, and software piracy, among many others (Protext International, 2003).
Personal consumer products such as desktops, laptops, and tablets can all be used in digital crime. Larger electronic systems in business or enterprise operations can equally be sources of digital crime; towers, modular racks, minicomputers, and mainframes can all be locations where evidence is found (Protext International, 2003). Additionally, access control devices such as smart cards, dongles, and biometric scanners may also contain evidence (Protext International, 2003). Even telephone switching systems, answering machines, and fax machines can contain hidden data that points to evidence of digital crime. As technology advances, so do the crimes committed with it. In order to combat this type of crime, investigators need an entirely new set of skills in the digital realm. Electronic crimes are still crimes, and law enforcement must treat them accordingly. "The law enforcement response to electronic evidence requires that officers, investigators, forensic examiners, and managers all play a role" (U.S. Department of Justice, 2013, p. 16).
The Nature of Electronic Evidence
Much of the evidence left behind in electronic crime is latent. This means that residual evidence of a crime exists because it was at some point stored or transmitted by a computer or other electronic device. "Electronic evidence is latent evidence in the same sense that fingerprints or DNA evidence are latent. In its natural state, we cannot see what is contained in the physical object that holds the evidence" (U.S. Department of Justice, 2013, p. 17). Special skills and processes are therefore needed to uncover the evidence that remains on a computer's hardware or other electronic device.
New devices and processes are continually being designed to combat digital crime. Research suggests that "cloud computing brings opportunities for network forensics tracing Internet criminals in a distributed environment" (Fu et al., 2010, p. 1). These new developments in cloud computing create new potential for gathering forensic evidence on a scale previously not possible in computer crime investigations.
Sensitivity and Handling of Digital Evidence
Electronic evidence is extremely sensitive. It "can be altered, damaged, or destroyed by improper handling or improper examination. For this reason, special precautions should be taken to document, collect, preserve, and examine this type of evidence" (U.S. Department of Justice, 2013, p. 17). Rigorous forensic processes are required in order to collect electronic data that is usable in a court of law. There are four specific phases involved in the forensic investigation of electronic evidence: collection, examination, analysis, and reporting.
Electronic evidence can also be time-sensitive. Certain aspects of the data may erase or eliminate incriminating evidence after a certain amount of time, or after the evidence is overwritten with other data (Protext International, 2003). Even "components such as keyboards, mice, removable storage media, and other items may hold latent evidence such as fingerprints, DNA, or other physical evidence that should be preserved" (National Institute of Justice, 2013). Careful consideration of electronic evidence must therefore be conducted in the same manner as collecting physical evidence at a crime scene.
Conclusion: Packaging, Transportation, and Testimony
The investigation concludes with the "packaging and transportation of the evidence" back into the hands of law enforcement (Protext International, 2003). This is technically where the forensic examiner's primary role ends. However, the forensic examiner may also be called into court to testify regarding the validity of the evidence. Research suggests that "an examiner may need to testify about not only the conduct of the examination but also the validity of the procedure and his or her qualifications to conduct the examination" (U.S. Department of Justice, 2013, p. 19). A suspect's legal counsel may attempt to question the validity of the search and evidence collection, and the forensic investigator must then be called upon to support the conclusions derived from the digital evidence.
Always verify citation format against your institution’s current style guide requirements.