Options
Tiered Forensic Methodology Model for Digital Field Triage by Non-Digital Evidence Specialists
Author(s)
Date Issued
2016-03-29
Date Available
2018-02-22T17:10:01Z
Abstract
Due to budgetary constraints and the high level of training required, digital forensic analysts are in short supply in police forces the world over. This inevitably leads to a prolonged time taken between an investigator sending the digital evidence for analysis and receiving the analytical report back. In an attempt to expedite this procedure, various process models have been created to place the forensic analyst in the field conducting a triage of the digital evidence. By conducting triage in the field, an investigator is able to act upon pertinent information quicker, while waiting on the full report. The work presented as part of this paper focuses on the training of front-line personnel in the field triage process, without the need of a forensic analyst attending the scene. The premise has been successfully implemented within regular/non-digital forensics, i.e., crime scene investigation. In that field, front-line members have been trained in specific tasks to supplement the trained specialists. The concept of front-line members conducting triage of digital evidence in the field is achieved through the development of a new process model providing guidance to these members. To prove the model's viability, an implementation of this new process model is presented and evaluated. The results outlined demonstrate how a tiered response involving digital evidence specialists and non-specialists can better deal with the increasing number of investigations involving digital evidence.
Type of Material
Journal Article
Publisher
Elsevier
Journal
Digital Investigation
Volume
16
Issue
S1
Start Page
75
End Page
85
Copyright (Published Version)
2016 the Authors
Language
English
Status of Item
Peer reviewed
This item is made available under a Creative Commons License
File(s)
Loading...
Name
TieredForensicMethodologyModelForDigitalFieldTriage.pdf
Size
646.01 KB
Format
Adobe PDF
Checksum (MD5)
5b2db903ff77125a3a14ec03415c02fb
Owning collection