Picture of old bailey statue
Courts could throw out evidence

Digital forensics lack standards

Lack of checks by police on digital investigators jeopardising evidence

Written by Tom Young

Court cases involving digital evidence are at risk of collapsing because some police forces fail to check the security of computer forensics suppliers.

A Computing investigation has revealed that while some firms providing conventional forensics services must attain an ISO standard, there is no such requirement for handling digital evidence.

Joel Tobias, managing director of forensics firm Cy4or, says most forensics specialists maintain high standards, but there are some that may not have had their security checked by police.

‘Some forces make a little bit more of an assumption over a company’s security than I am comfortable with,’ he said.

‘There is definitely a possibility that a company that did not have adequate security or expertise might be able to slip through the net and be used by the police.’

Vendor LGC performs digital and non-digital analysis for police forces. Non-digital work must adhere to the ISO 17025 standard.

But LGC says that customers, including the police, do not demand ISO 17025 accreditation when awarding digital contracts.

One senior manager at a major UK forensics firm describes the way digital forensic outsourcing operates as a ‘sham’.

If a piece of evidence was tampered with or stolen, there would be no case to answer in a court,’ said the manager.

‘We have worked for 20 law enforcement agencies in Britain and have only ever had visits by two of them. Technically, we have no security clearance whatsoever.’

It has also emerged that practices vary widely between forces. The Metropolitan Police rigorously inspects all firms it uses, according to another source in the digital forensics industry who points out that some forces often use suppliers on a recommendation from colleagues in other regions.

‘They will put in a phone call to another force to check our credentials, but would not necessarily send someone to check on us,’ said the source. ‘This creates a danger that once a company is in the loop, forces will no longer bother to check their security credentials.’

The Council for the Registration of Forensic Practitioners only accredits individuals and not companies. Its accreditations are not obligatory for undertaking digital forensic work.

reader comments

related articles

All forensics are the same

Evidence is evidence and digital forensics are not different from the more traditional kind 12 Apr 2007

 

Ecrime efforts stall over staff

Computing probe shows lack of resources in fight against electronic crime 25 Jan 2007

Police limit e-crime probes

Lower-value incidents overlooked by local forces, say businesses 01 Mar 2007

Review 2007: IT security and e-crime

Computing's review of the year looks back at the top IT security and cybercrime stories 20 Dec 2007

Card fraud factory raided

Devices for stealing Chip and PIN card details found by police 13 Aug 2008

Organisations lose confidential data

Experts warn that password security is not sufficient 25 Sep 2007

today's top stories

Analysis: Will IE8 cause more problems than it solves?

Microsoft's new browser may lead to compatibility issues and affect online advertising 29 Aug 2008

CIO morale plummets as crunch hits

Fewer opportunities and less responsibility depress IT managers 27 Aug 2008

The pIT stop Q&A: Should packaged software users adopt SOA?

Our expert panel answer readers' questions 29 Aug 2008

Computing podcast 28 August 2008

CIO job satisfaction plummets, and why schools' IT spending is set to top £1bn 28 Aug 2008

The definitive guide to collaboration

Five key technologies and five best practice tips to improve your collaborative IT 28 Aug 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Job of the week

Job alerts

Sign up here

Find your next job here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you recruit a student with an IT degree?

Would you recruit a student with an IT degree?

As IT student numbers plummet - would you recruit an IT graduate?

Previous poll results

Latest audio and video articles

A stressed CIOAudio

Computing podcast 28 August 2008

CIO job satisfaction plummets, and why schools' IT spending is set to top £1bn 28 Aug 2008

Bryan Glick video whiteboardVideo

The definitive guide to collaboration

Five key technologies and five best practice tips to improve your collaborative IT 28 Aug 2008

Latest in-depth articles

Myron HrycykAnalysis

General management skills are now as important as technical ability

A selection of leading chief information officers talk about what they see as the most important aspects of the role 28 Aug 2008

Internet Explorer logoAnalysis

Analysis: Will IE8 cause more problems than it solves?

Microsoft's new browser may lead to compatibility issues and affect online advertising 29 Aug 2008

Primary Navigation