1/30
Vocabulary flashcards covering fundamental concepts, legal rules, roles, and procedures in digital forensics and investigations.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Digital Forensics
The application of computer science and investigative procedures for a legal purpose involving the analysis of digital evidence after proper search authority, chain of custody, validation with mathematics, use of validated tools, repeatability, reporting, and possible expert presentation.
ISO 27037
An ISO standard for digital forensics ratified in October 2012 titled 'Information technology - Security techniques'.
Federal Rules of Evidence (FRE)
Rules signed into law in 1973 created to ensure consistency in federal legal proceedings, to which many states' rules map.
Computer Analysis and Response Team (CART)
An FBI unit formed in 1984 to handle cases involving digital evidence.
Fourth Amendment
An amendment to the U.S. Constitution that protects everyone's right to be secure from unreasonable search and seizure.
Consent Search
A search conducted without a warrant when the target of the search explicitly gives permission.
Exigent Circumstances
An urgent or emergency situation (such as a risk of imminent harm, destruction of evidence, or a suspect fleeing) where law enforcement can perform a warrantless search because waiting for a warrant would be impractical or dangerous.
Electronic Storage Detection (ESD) K9s
Canines trained to detect the presence of electronic storage devices, such as hard drives, USB drives, and cell phones.
Triphenylphosphine Oxide (TPPO)
The chemical compound byproduct of electronic circuit board manufacturing that ESD K9s are trained to detect in electronic devices.
Hydroxycyclohexyl Phenyl Ketone (HPK)
A chemical compound typically found on storage media such as CDs, DVDs, and floppy disks that some ESD dogs are trained to detect.
Public-Sector Investigations
Investigations involving government agencies responsible for criminal investigations and prosecution, which are restricted by Fourth Amendment search and seizure rules.
Private-Sector Investigations
Investigations involving private companies and lawyers that focus on policy violations, litigation disputes, and minimizing corporate risk.
Computer Fraud and Abuse Act (CFAA)
A federal law passed in 1986 regarding computer-related crimes.
Police Blotter
A historical database of previous crimes maintained by police departments.
Digital Evidence First Responder (DEFR)
A professional who arrives on an incident scene, assesses the situation, and takes precautions to acquire and preserve digital evidence.
Digital Evidence Specialist (DES)
An investigator with the skills to analyze digital data and determine when another specialist should be called in to assist.
Affidavit
A sworn statement of support of facts about or evidence of a crime, required by law enforcement to obtain a search warrant.
Acceptable Use Policy
An organizational policy that defines the rules for using a company's computers and networks.
Line of Authority
A corporate policy specification that states who has the legal right to initiate an investigation, take possession of evidence, and access evidence.
Warning Banner
A displayed notice on computer screens informing users that the organization reserves the right to inspect computer systems and network traffic at will.
Authorized Requester
A designated group or individual in a business (such as corporate security, ethics, internal auditing, or general counsel) with the power to initiate private-sector investigations.
Bring Your Own Device (BYOD)
An environment where personal devices connected to a business network fall under the same policy rules and inspection rights as company property.
Chain of Custody
The route evidence takes from the time it is found until the case is closed or goes to court.
Attorney-Client Privilege (ACP)
A legal protection requiring investigators to keep all findings confidential and mark documents with headers such as 'Privileged Legal Communication—Confidential Work Product'.
Interview
A process usually conducted to collect information from a witness or suspect about specific facts related to an investigation.
Interrogation
The process of trying to get a suspect to confess.
Write-Blocker
A device that enables booting an operating system without writing data to the evidence drive, allowing data to flow only from the storage device to the imaging device.
Bit-Stream Copy
A bit-by-bit exact copy of the original storage medium, capable of copying deleted files, email messages, and file fragments that backup software cannot.
Bit-Stream Image
A file containing the bit-stream copy of all data on a disk or partition.
First Rule of Computer Forensics
Preserve the original evidence by conducting analysis only on a copy of the data.
Autopsy
A digital forensics software application used to examine evidence, run keyword searches, display file contents, and generate case reports.