Legal Cyber Academy
Standard or guidanceFreeCurrent

ENFSI Best Practice Manual for the Forensic Examination of Digital Technology

European Network of Forensic Science Institutes · Version 01, November 2015 · 2015

Identifier: ENFSI-BPM-FIT-01

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A 65-page manual from ENFSI's Forensic Information Technology working group covering personnel, equipment, accommodation, peer review, examination protocols, validation and uncertainty of measurement, proficiency testing, handling items, case assessment and prioritisation. It is one of ten ENFSI best practice manuals issued in November 2015 under the EU-funded TEFSBPM project.

Who it is for, and when

Read it if you run a European digital forensics unit, because it maps the quality-system obligations of ISO/IEC 17025 onto digital work in a way the standard itself does not. It is free, which makes it a practical alternative when you need a citable laboratory-practice reference and cannot buy the ISO texts.

What it does not cover

It is version 01 from November 2015 and ENFSI has not published a later version of this manual, so it predates current mobile, cloud and full-disk-encryption realities; ENFSI's own cover material directs readers to check its website for updates. It is a laboratory practice manual, not a technique-by-technique procedure set.

Go to the source

Open at enfsi.eu (opens in a new tab)

https://enfsi.eu/wp-content/uploads/2016/09/1._forensic_examination_of_digital_technology_0.pdf

Details

Type
Standard or guidance
Written for
Working examinerWorking examiner
Publisher
European Network of Forensic Science Institutes
Version verified
Version 01, November 2015
Year
2015
Identifier
ENFSI-BPM-FIT-01
Topics
lab-accreditation, quality-assurance, validation, eu-practice, evidence-handling
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • NIST's long-running programme that builds tool specifications, test assertions, test procedures and test data for categories of forensic function — disk imaging, hardware and software write blocking, deleted file recovery, file carving, string searching, media preparation, mobile device and cloud data extraction, Windows registry and SQLite tools — and publishes the resulting test reports with DHS Science and Technology.

  • A CFTT offshoot that packages NIST's test methodology so labs can run it themselves and optionally share results: distributed as bootable Linux ISOs and a portable Windows web-server build, with report templates. Current suites cover disk imaging, forensic media preparation, hardware write blocking, string searching, SQLite recovery, mobile device acquisition and cloud data extraction, with companion datasets in CFReDS.

  • The statutory code of practice the Forensic Science Regulator is required to publish under the Forensic Science Regulator Act 2021, setting quality standard requirements for forensic science activities relating to the investigation of crime in England and Wales. Version 2 replaced version 1 and came into force on 2 October 2025.

  • INTERPOL's guidance on establishing and managing a digital forensics laboratory, together with technical guidelines for managing and processing electronic evidence. INTERPOL lists it on its digital forensics page alongside two related publications, Framework for Responding to a Drone Incident and Guidelines for Digital Forensics First Responders.

  • The 30-page accreditation standard against which forensic laboratories, including digital forensics units, are assessed for technical competence, impartiality and consistent operation. The third edition (2017) replaced the 2005 edition and was confirmed on systematic review in 2023.