Computer forensics-Collecting non-electronic evidence

Recovery of non-electronic evidence can be crucial in the investigation of cybercrime. Proper care should be
taken to ensure that such evidence is recovered and preserved. Items relevant to subsequent examination of electronic evidence may exist in other forms (e.g. written passwords and other handwritten notes, blank pads of paper with indented writing, hardware and software manuals, literature, or computer printouts, and photographs) and should be secured and preserved for future analysis. These items frequently are in close proximity to the computer or related hardware items. All evidence should be identified, secured, and preserved in compliance with your policies.

principle: Computer evidence, like all other evidence, must be handled carefully and in a manner that preserves its evidential value. This relates not just to the integrity of an item or device, but also to the electronic data it contains. Certain types of computer evidence therefore require special collection, packaging, and transportation. Consideration should be given to protect data that may be susceptible to damage or alteration from electromagnetic fields such as those generated by static electricity, magnets, radio transmitters, and other devices.

policy: Electronic evidence should be collected according to your organizational guidelines. In the absence of guidelines outlining procedures for electronic evidence collection, the following procedures are recommended.

Note: Prior to collection of evidence, it is assumed that locating and documenting has been done as previously described. Appreciate that other types of evidence such as DNA, or fingerprints may exist.

