Forensic Examination of Digital Evidence: A Guide for Law Enforcement
National Institute of Justice, U.S. Department of Justice · April 2004 · 2004
Identifier: NCJ 199408
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.
Who it is for, and when
Still worth reading for the examination-request and reporting structure, which many US agency SOPs were built from and which shows up in discovery as the shape of a police examiner's report. Useful for a lawyer trying to work out what an examiner should have documented and why a report is organised the way it is.
What it does not cover
NIJ states the recommendations are not legal mandates, are not the only correct courses of action, and may not be feasible in all circumstances. Technically it is a 2004 document: no mobile devices, no cloud, no encryption-at-rest defaults, and none of the current tooling.
Go to the source
Open at ojp.gov (opens in a new tab)https://www.ojp.gov/pdffiles1/nij/199408.pdf
Details
- Type
- Standard or guidance
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Publisher
- National Institute of Justice, U.S. Department of Justice
- Version verified
- April 2004
- Year
- 2004
- Identifier
- NCJ 199408
- Topics
- evidence-handling, reporting, chain-of-custody, imaging, us-federal
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.
SWGDE Best Practices for Mobile Device Evidence Collection & Preservation, Handling and Acquisition
FreeSWGDE's guidance on the front half of mobile device work: isolating and preserving a seized handset, handling power and network state, and choosing among logical, file system and physical acquisition routes. The version verified here is 18-F-003-2.0 dated 21 August 2025.
The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.
An 81-page NIJ guide on the legal handling of digital evidence: search and seizure issues including the Fourth Amendment, the Electronic Communications Privacy Act and the Privacy Protection Act; maintaining evidence integrity; pretrial preparation including authentication and hearsay; courtroom presentation and expert testimony; and a chapter on child pornography cases. Appendices include consent forms and evidence return stipulations.
NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.