Legal Cyber Academy
Standard or guidanceFreeCurrent

Electronic Crime Scene Investigation: A Guide for First Responders, Second Edition

National Institute of Justice, U.S. Department of Justice · Second edition, April 2008 · 2008

Identifier: NCJ 219941

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.

Who it is for, and when

The right starting point for anyone who arrives at a scene before an examiner — officers, investigators, corporate security, internal auditors — and for lawyers testing whether seizure was handled in line with accepted practice. The crime-category chapter is a practical prompt list for what devices to look for in a given case type.

What it does not cover

It stops at the lab door: no examination, analysis or interpretation, and no legal authority analysis for the search or seizure itself. Being a 2008 second edition, it predates smartphone-dominant scenes, cloud accounts, IoT devices and live-encryption decisions, so its device inventory is dated.

Go to the source

Open at ojp.gov (opens in a new tab)

https://www.ojp.gov/pdffiles1/nij/219941.pdf

Details

Type
Standard or guidance
Written for
New to the fieldNew to the field
Publisher
National Institute of Justice, U.S. Department of Justice
Version verified
Second edition, April 2008
Year
2008
Identifier
NCJ 219941
Topics
first-responder, evidence-handling, chain-of-custody, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • The UK guide that states the four ACPO principles for handling digital evidence — do not change the original data, record everything done, have a competent person do any live examination, and place responsibility for compliance on the officer in charge. Its own front matter records that ACPO agreed the revised guide for adoption by police forces in England, Wales and Northern Ireland.

  • A pocket flipbook companion to NIJ's first responder guide, condensing device types, scene securing, documentation, collection and packaging into an on-scene quick reference, with digital evidence considerations by crime category.

  • Two subsections of Rule 902 that let a party authenticate electronic evidence by written certification instead of live testimony: 902(13) covers a record generated by an electronic process or system that produces an accurate result, and 902(14) covers data copied from an electronic device, storage medium, or file when authenticated by a process of digital identification. Both borrow the certification and pretrial notice machinery of Rule 902(11).

  • An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.

  • A catalogue produced by the NIST Cloud Computing Forensic Science Working Group that aggregates and categorises the forensic challenges of investigating incidents in cloud ecosystems — multi-tenancy, data location, provider dependency, chain of custody across parties, and the rest. The draft circulated from 2014; the final was issued in August 2020.