The Search and Seizure of Digital Evidence by Forensic Investigators in South Africa
The discipline of digital forensics requires a combination of skills, qualifications and knowledge in the area of forensic investigation, legal aspects and information technology. The uniqueness of digital evidence makes the adoption of traditional legal approaches problematic. Information techno...
Main Authors: | , |
---|---|
Format: | Article |
Language: | Afrikaans |
Published: |
North-West University
2019-04-01
|
Series: | Potchefstroom Electronic Law Journal |
Subjects: | |
Online Access: | https://journals.assaf.org.za/index.php/per/article/view/4886 |
_version_ | 1819013280918667264 |
---|---|
author | Jacobus Gerhardus Nortje Daniel Christoffel Myburgh |
author_facet | Jacobus Gerhardus Nortje Daniel Christoffel Myburgh |
author_sort | Jacobus Gerhardus Nortje |
collection | DOAJ |
description | The discipline of digital forensics requires a combination of skills, qualifications and knowledge in the area of forensic investigation, legal aspects and information technology. The uniqueness of digital evidence makes the adoption of traditional legal approaches problematic.
Information technology terminology is currently used interchangeably without any regard to being unambiguous and consistent in relation to legal texts. Many of the information technology terms or concepts have not yet achieved legal recognition.
The recognition and standardisation of terminology within a legal context are of the utmost importance to ensure that miscommunication does not occur.
To provide clarity or guidance on some of the terms and concepts applicable to digital forensics and for the search and seizure of digital evidence, some of the concepts and terms are reviewed and discussed, using the Criminal Procedure Act 51 of 1977 as a point of departure.
Digital evidence is often collected incorrectly and analysed ineffectively or simply overlooked due to the complexities that digital evidence poses to forensic investigators. As with any forensic science, specific regulations, guidelines, principles or procedures should be followed to meet the objectives of investigations and to ensure the accuracy and acceptance of findings. These regulations, guidelines, principles or procedures are discussed within the context of digital forensics: what processes should be followed and how these processes ensure the acceptability of digital evidence. These processes include international principles and standards such as those of the Association of Chiefs of Police Officers and the International Organisation of Standardisation. A summary is also provided of the most influential or best-recognised international (IOS) standards on digital forensics.
It is concluded that the originality, reliability, integrity and admissibility of digital evidence should be maintained as follows:
Data should not be changed or altered.
Original evidence should not be directly examined.
Forensically sound duplicates should be created.
Digital forensic analyses should be performed by competent persons.
Digital forensic analyses should adhere to relevant local legal requirements.
Audit trails should exist consisting of all required documents and actions.
The chain of custody should be protected.
Processes and procedures should be proper, while recognised and accepted by the industry.
If the ACPO (1997) principles and ISO/IEC 27043 and 27037 Standards are followed as a forensic framework, then digital forensic investigators should follow these standards as a legal framework. |
first_indexed | 2024-12-21T01:57:27Z |
format | Article |
id | doaj.art-c71c56d0c79f497bba7b913364a54d72 |
institution | Directory Open Access Journal |
issn | 1727-3781 |
language | Afrikaans |
last_indexed | 2024-12-21T01:57:27Z |
publishDate | 2019-04-01 |
publisher | North-West University |
record_format | Article |
series | Potchefstroom Electronic Law Journal |
spelling | doaj.art-c71c56d0c79f497bba7b913364a54d722022-12-21T19:19:45ZafrNorth-West UniversityPotchefstroom Electronic Law Journal1727-37812019-04-0122201914210.17159/1727-3781/2019/v22i0a4886The Search and Seizure of Digital Evidence by Forensic Investigators in South AfricaJacobus Gerhardus Nortje 0Daniel Christoffel Myburgh 1North-West UniversityNorth-West UniversityThe discipline of digital forensics requires a combination of skills, qualifications and knowledge in the area of forensic investigation, legal aspects and information technology. The uniqueness of digital evidence makes the adoption of traditional legal approaches problematic. Information technology terminology is currently used interchangeably without any regard to being unambiguous and consistent in relation to legal texts. Many of the information technology terms or concepts have not yet achieved legal recognition. The recognition and standardisation of terminology within a legal context are of the utmost importance to ensure that miscommunication does not occur. To provide clarity or guidance on some of the terms and concepts applicable to digital forensics and for the search and seizure of digital evidence, some of the concepts and terms are reviewed and discussed, using the Criminal Procedure Act 51 of 1977 as a point of departure. Digital evidence is often collected incorrectly and analysed ineffectively or simply overlooked due to the complexities that digital evidence poses to forensic investigators. As with any forensic science, specific regulations, guidelines, principles or procedures should be followed to meet the objectives of investigations and to ensure the accuracy and acceptance of findings. These regulations, guidelines, principles or procedures are discussed within the context of digital forensics: what processes should be followed and how these processes ensure the acceptability of digital evidence. These processes include international principles and standards such as those of the Association of Chiefs of Police Officers and the International Organisation of Standardisation. A summary is also provided of the most influential or best-recognised international (IOS) standards on digital forensics. It is concluded that the originality, reliability, integrity and admissibility of digital evidence should be maintained as follows: Data should not be changed or altered. Original evidence should not be directly examined. Forensically sound duplicates should be created. Digital forensic analyses should be performed by competent persons. Digital forensic analyses should adhere to relevant local legal requirements. Audit trails should exist consisting of all required documents and actions. The chain of custody should be protected. Processes and procedures should be proper, while recognised and accepted by the industry. If the ACPO (1997) principles and ISO/IEC 27043 and 27037 Standards are followed as a forensic framework, then digital forensic investigators should follow these standards as a legal framework.https://journals.assaf.org.za/index.php/per/article/view/4886Digital forensicsdigital devicesdigital search and seizuredigital evidenceforensic investigationinternational standards |
spellingShingle | Jacobus Gerhardus Nortje Daniel Christoffel Myburgh The Search and Seizure of Digital Evidence by Forensic Investigators in South Africa Potchefstroom Electronic Law Journal Digital forensics digital devices digital search and seizure digital evidence forensic investigation international standards |
title | The Search and Seizure of Digital Evidence by Forensic Investigators in South Africa |
title_full | The Search and Seizure of Digital Evidence by Forensic Investigators in South Africa |
title_fullStr | The Search and Seizure of Digital Evidence by Forensic Investigators in South Africa |
title_full_unstemmed | The Search and Seizure of Digital Evidence by Forensic Investigators in South Africa |
title_short | The Search and Seizure of Digital Evidence by Forensic Investigators in South Africa |
title_sort | search and seizure of digital evidence by forensic investigators in south africa |
topic | Digital forensics digital devices digital search and seizure digital evidence forensic investigation international standards |
url | https://journals.assaf.org.za/index.php/per/article/view/4886 |
work_keys_str_mv | AT jacobusgerhardusnortje thesearchandseizureofdigitalevidencebyforensicinvestigatorsinsouthafrica AT danielchristoffelmyburgh thesearchandseizureofdigitalevidencebyforensicinvestigatorsinsouthafrica AT jacobusgerhardusnortje searchandseizureofdigitalevidencebyforensicinvestigatorsinsouthafrica AT danielchristoffelmyburgh searchandseizureofdigitalevidencebyforensicinvestigatorsinsouthafrica |