Assignment On Evidence Collection Policy: Is3340-Windows Security

474 Words2 Pages
IS3340-windows security | Evidence Collection Policy | Unit 9 Assignment 1 | | | 5/22/2014 | | During the process of collecting digital evidence, the investigator will ensure that the data remains intact and unaltered. For later proof that evidence hasn't been tampered with, they will calculate and record a cryptographic hash of an evidence file, to be compared to the original as proof that the evidence has not been modified. He will further assure the integrity of digital evidence by imaging computer media with a write blocking tool, establishing a chain of custody and documenting everything done to the evidence. He will examine a computer's RAM for evidence prior to powering it down, as some digital evidence may be

More about Assignment On Evidence Collection Policy: Is3340-Windows Security

Open Document