Picture of old bailey statue
Courts could throw out evidence

Digital forensics lack standards

Lack of checks by police on digital investigators jeopardising evidence

Written by Tom Young

Court cases involving digital evidence are at risk of collapsing because some police forces fail to check the security of computer forensics suppliers.

A Computing investigation has revealed that while some firms providing conventional forensics services must attain an ISO standard, there is no such requirement for handling digital evidence.

Joel Tobias, managing director of forensics firm Cy4or, says most forensics specialists maintain high standards, but there are some that may not have had their security checked by police.

‘Some forces make a little bit more of an assumption over a company’s security than I am comfortable with,’ he said.

‘There is definitely a possibility that a company that did not have adequate security or expertise might be able to slip through the net and be used by the police.’

Vendor LGC performs digital and non-digital analysis for police forces. Non-digital work must adhere to the ISO 17025 standard.

But LGC says that customers, including the police, do not demand ISO 17025 accreditation when awarding digital contracts.

One senior manager at a major UK forensics firm describes the way digital forensic outsourcing operates as a ‘sham’.

If a piece of evidence was tampered with or stolen, there would be no case to answer in a court,’ said the manager.

‘We have worked for 20 law enforcement agencies in Britain and have only ever had visits by two of them. Technically, we have no security clearance whatsoever.’

It has also emerged that practices vary widely between forces. The Metropolitan Police rigorously inspects all firms it uses, according to another source in the digital forensics industry who points out that some forces often use suppliers on a recommendation from colleagues in other regions.

‘They will put in a phone call to another force to check our credentials, but would not necessarily send someone to check on us,’ said the source. ‘This creates a danger that once a company is in the loop, forces will no longer bother to check their security credentials.’

The Council for the Registration of Forensic Practitioners only accredits individuals and not companies. Its accreditations are not obligatory for undertaking digital forensic work.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

All forensics are the same

Evidence is evidence and digital forensics are not different from the more traditional kind 12 Apr 2007

 

Ecrime efforts stall over staff

Computing probe shows lack of resources in fight against electronic crime 25 Jan 2007

Police limit e-crime probes

Lower-value incidents overlooked by local forces, say businesses 01 Mar 2007

Eco cleaning products are greenwashing customers, Which? warns

Investigation accuses high-profile green products of failing to back up environmental claims with convincing evidence 29 Apr 2010

EPA and DoE launch Energy Star testing crack down

Products carrying Energy Star certification to face fresh energy efficiency tests 23 Mar 2010

Police shut 1,200 scam websites

Massive combined operation takes down sites selling fake or non-existent designer goods 03 Dec 2009

related white papers

today's top stories

Financial IT job market recovery continues

Recruitment growth suggests IT budgets are increasing 30 Jul 2010

Satellite broadband touted as digital divide clincher

KA-SAT launch promises 10Mbit/s service for hard-to-reach locations 29 Jul 2010

Ofcom slams ISPs for exaggerated broadband speed claims

New code of practice for ISPs planned by the regulator 27 Jul 2010

Aerohive offers traffic light Wi-Fi monitoring

Firm promises simple 'red, yellow or green' system with Client Health Score tool 27 Jul 2010

Flaw in top wireless security protocol WPA2 uncovered

Disgruntled insiders could hack corporate wireless LAN 26 Jul 2010

Advertisement

How to achieve business and financial-system implementation success
A look at how organisations - regardless of size - can work towards successful business software installations and factors that determine the outcome.

Case study: Specsavers put customer care into focus
How Specsavers captured customer feedback at point of sale and incorporated the results into its CRM system.

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

ICO to lean more heavily on public sector bodies

ICO to lean more heavily on public sector bodies

The ICO has said it will lean more heavily on public sector bodies to secure timely FOI responses, do you think this is:

View poll results

Latest audio and video articles

picture of Jason HartVideo

Ethical hacker reveals the security secrets behind cloud computing

Jason Hart, Senior VP at Cryptocard, shows Computing just how easy it is to illegally gain access to corporate cloud services to wreak havoc and steal money. 29 Jun 2010

gartner logoVideo

Part 1: 2010 trends in SOA and Application Development and Integration

Gartner analyst Paolo Malinverno explores trends in SOA 29 Jun 2010

Latest in-depth articles

Map of 3G coverageComment

The risks of selling off the 800MHz radio spectrum at the wrong price

It's a choice between revenue now or universal broadband later 30 Jul 2010

Luton Borough Council officesAnalysis

Local authority leads the way in digital backup technology

Luton Borough Council tells of the benefits of early adopter of VTL, data deduplication and virtualisation 27 Jul 2010

Primary Navigation