Directive 5.30 digital evidence , Flashcards
According to Directive 5.30 digital evidence , What is the purpose of Digital evidence ?
A. To provide guidelines and procedures for the seizure of any electronic device or
digital evidence generated, collected, or otherwise encountered and utilized by the
Philadelphia Police Department in legal matters.
B. For safeguarding, identifying, collecting, and preserving electronic evidence in a
prescribed manner to safely preserve stored data for recovery, preservation and
examination at a later time by department personnel trained in these techniques.
(PLEAC 1.5.5
According to Directive 5.30 digital evidence , It is the policy of the Police Department to collect and analyze all evidence of a crime
which may aid in identifying and/or__________?
prosecuting an offender.
According to Directive 5.30 digital evidence , who may collect digital evidence ?
Only
personnel with accepted and approved training
According to Directive 5.30 digital evidence , who may analyze and process electronic devices ?
Only employees who have been trained in the appropriate forensic processes and
techniques,
Digital Evidence (DE):
Any data in electronic format that can be read, processed or
otherwise utilized by an electronic device and pertains to, or otherwise has significance
and relevance to a criminal investigation, prosecution, or other critical interest to the
department.
Digital Evidence Management System (DEMS):
A collection of hardware, software
and/or firmware designed to provide for the security, storage, organization and/or
distribution of digital evidence.
Digital Watermark:
A method of integrity verification that works by embedding a
files hash value into the binary structure of the file during its creation. The digital
watermark is verified by rehashing the file and comparing the new value against the
embedded value. Proprietary software is generally required to validate a watermark.
Electronic Devices:
Devices that process and generate data using electronically based
circuitry and components. The definition shall also include any associated
hardware/software or peripheral device. This includes but is not limited to personal
computers, laptop computers, servers, tablets, smart phones, video recorders, printers,
routers, cables, manuals, etc.
Integrity verification:
The determination of whether the information is complete and
unaltered since the time of acquisition.
National Institute of Standards and Technology (NIST) and United States Naval
Observatory (NSNO):
Represent the two official time keeping agencies in the United
States. Using a multitude of highly accurate atomic clocks, time from the two
organizations is usually within 20 nanoseconds of each other.
Recovering Personnel:
A person that has been sufficiently trained by the department
or approved third party in the recovery, examination and/or analysis of a particular type
of evidence. This may include but is not limited to Computer Forensic Analysis,
DIVRT technicians, Forensic Video Analysts, and Cell Phone Examiners.
Smart Device:
Any of a number of devices not generally considered a computer but
still capable of processing and storing electronic data. Smart devices typically include
cell phones, smart phones, PDA devices, GPS devices and tablet computers.
Storage Media:
Any device that is capable of storing, archiving, or conveying digital
evidence to an electronic device. This includes, Hard Disk Drives, Solid State Drives,
USB Drives, DVD’s, CD’s, SD cards, Compact Flash, etc.
Super Hash Algorithm (SHA):
A cryptographic hash function designed by the United
States National Security Agency (NSA) and accepted by the US National Institute of
Standards. The algorithm generates a digital fingerprint by running data through a
mathematical process and generating a code value. It can detect with absolute certainty
that a file has been altered. Various version of the SHA create fingerprints with
increasing statistical probability that a data is complete and exact.
According to Directive 5.30 digital evidence , Negligence, recklessness or the performance of tasks in a manner that grossly deviates
from accepted methods and procedures will result in________?
termination of the employee’s ability to collect digital evidence.