ASTM E2763-2010 Standard Practice for Computer Forensics《计算机法医学标准实施规程》.pdf
《ASTM E2763-2010 Standard Practice for Computer Forensics《计算机法医学标准实施规程》.pdf》由会员分享,可在线阅读,更多相关《ASTM E2763-2010 Standard Practice for Computer Forensics《计算机法医学标准实施规程》.pdf(3页珍藏版)》请在麦多课文档分享上搜索。
1、Designation: E2763 10Standard Practice forComputer Forensics1This standard is issued under the fixed designation E2763; the number immediately following the designation indicates the year oforiginal adoption or, in the case of revision, the year of last revision. A number in parentheses indicates th
2、e year of last reapproval. Asuperscript epsilon () indicates an editorial change since the last revision or reapproval.1. Scope1.1 This practice describes techniques and procedures forcomputer forensics within the context of a criminal investiga-tion.1.1.1 This practice can be applicable to civil li
3、tigation.1.2 This practice describes seizing possible evidence,proper evidence handling, digital imaging, forensic analysis/examination, evidence-handling documentation, and reporting.1.3 This practice is not all inclusive and does not containinformation relative to specific operating systems or for
4、ensictools.1.4 The values stated in SI units are to be regarded asstandard. No other units of measurement are included in thisstandard.1.5 This standard does not purport to address all of thesafety concerns, if any, associated with its use. It is theresponsibility of the user of this standard to est
5、ablish appro-priate safety and health practices and determine the applica-bility of regulatory limitations prior to use.2. Referenced Documents2.1 ASTM Standards:2E2678 Guide for Education and Training in ComputerForensics2.2 SWGDE Standards:3Recommended Guidelines for Validation Testing3. Significa
6、nce and Use3.1 The purpose of this practice is to describe techniquesand procedures for computer forensics in regard to evidencehandling, computers, digital imaging, and forensic analysis andexamination.3.2 The examiner should be trained in accordance withGuide E2678.3.3 Individuals not trained in p
7、roper digital evidence proce-dures should consult with an appropriate specialist beforeproceeding.3.4 When dealing with technology outside your area ofexpertise, consult with an appropriate specialist before pro-ceeding.4. Seizing Evidence4.1 General guidelines concerning the seizing of evidenceare:
8、4.1.1 Consult with the investigator or responsible party todetermine the necessary equipment to take to the scene.4.1.2 Review the legal authority to seize the evidence,ensuring any restrictions are noted. If necessary during theexecution of the seizure, obtain additional authority for evi-dence out
9、side the scope of the search.4.1.3 When it is impractical to remove the evidence fromthe scene, the evidence items shall be copied or imagedaccording to organizational policy.4.1.4 All suspects, witnesses, and bystanders shall be re-moved from the proximity of digital evidence to ensure theintegrity
10、 of potential evidence.4.1.5 Solicit information from potential suspects, witnesses,system administrators, and so forth, to ascertain knowledge ofthe systems to be seized (for example, password(s), operatingsystem(s), screen names, remote access users, and E-mailaddresses).4.1.6 The scene shall be s
11、earched systematically and thor-oughly for evidence. Searchers shall be trained to recognize thedifferent types of evidence. Check for additional media thatmay be attached to the computer system.5. Evidence Handling5.1 Document the scene, which can include: taking clear,detailed photographs (of the
12、computer screen, of the front andback of the computer, and of the area around the computer tobe seized) and making a sketch/notation of the computerconnections and surrounding area, or both.5.2 If the computer is turned off, DO NOT turn on thecomputer.1This practice is under the jurisdiction of ASTM
13、 Committee E30 on ForensicSciences and is the direct responsibility of Subcommittee E30.12 on Digital andMultimedia Evidence.Current edition approved Aug. 15, 2010. Published September 2010. DOI:10.1520/E2763-10.2For referenced ASTM standards, visit the ASTM website, www.astm.org, orcontact ASTM Cus
14、tomer Service at serviceastm.org. For Annual Book of ASTMStandards volume information, refer to the standards Document Summary page onthe ASTM website.3Available from Scientific Working Group on Digital Evidence (SWGDE),http:/www.swgde.org/documents.1Copyright ASTM International, 100 Barr Harbor Dri
15、ve, PO Box C700, West Conshohocken, PA 19428-2959, United States.5.2.1 Before powering down a computer, consider thepotential of encryption software being installed on the com-puter or as part of the operating system. If present, appropriateforensic methods should be used to capture the unencryptedd
16、ata and any volatile data that would be lost if the computer ispowered down.5.2.2 Be aware that storage devices may not be physicallyconnected and a proper search for wireless devices must beconducted.5.2.3 Assess the power needs for devices with volatilememory and follow organizational policy for t
17、he handling ofthose devices.5.2.4 Document the condition of the evidence, includingany preexisting damage.5.2.5 Appropriately document the connection of the exter-nal components.5.3 Stand-Alone Computer (Non-Networked):5.3.1 Disconnect all power sources by unplugging from theback of the computer. Al
18、so, remove batteries from laptops.5.3.2 Place evidence tape over the power plug connector onthe back of the computer.5.4 Networked Computer:5.4.1 WorkstationsRemove the power connector from theback of the computer.5.4.2 Place evidence tape over the power plug connector onthe back of the computer.NOT
19、E 1Any network computer can be used for file sharing and thosesystems should follow normal shutdown procedures.5.5 Servers:5.5.1 Determine whether the network connection should bedisconnected after consulting with an individual trained inproper digital evidence procedures.5.5.2 A determination shall
20、 be made as to the extent of datathat should be seized.5.5.3 Capture volatile data if necessary.5.5.4 If shutdown is necessary, use the appropriate com-mands. (WarningPulling the plug could severely damagethe system, disrupt legitimate business, or create officer anddepartment liability, or combinat
21、ions thereof.)5.6 Each piece of evidence shall be protected from changeand a chain of custody maintained as determined by organiza-tional policy. Appropriate packaging of evidence can includeany of the following:5.6.1 Plastic/paper bags or sleeves;5.6.2 Computer case sealed with evidence tape over c
22、aseaccess points and power connector;5.6.3 Some devices may require power to maintain thevolatile memory and should be packaged appropriately; and5.6.4 Specific care shall be taken with the transportation ofdigital evidence material to avoid physical damage, vibration,and the effects of magnetic fie
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ASTME27632010STANDARDPRACTICEFORCOMPUTERFORENSICS 计算机 法医学 标准 实施 规程 PDF

链接地址:http://www.mydoc123.com/p-531847.html