Legal Cyber Academy
Standard or guidanceFreeCurrent

Electronic Crime Scene Investigation: An On-the-Scene Reference for First Responders

National Institute of Justice, U.S. Department of Justice · November 2009 · 2009

Identifier: NCJ 227050

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A pocket flipbook companion to NIJ's first responder guide, condensing device types, scene securing, documentation, collection and packaging into an on-scene quick reference, with digital evidence considerations by crime category.

Who it is for, and when

Intended to be carried, not studied: give it to officers or field staff who need a one-page prompt at the moment of seizure rather than a 70-page guide. It is also a useful yardstick when assessing whether a seizure met the minimum documented steps.

What it does not cover

By design it is abbreviated, with no reasoning, no examination guidance and no legal analysis; it cannot substitute for the full second-edition guide. It dates from 2009 and reflects the device landscape of that time.

Go to the source

Open at ojp.gov (opens in a new tab)

https://www.ojp.gov/ncjrs/virtual-library/abstracts/electronic-crime-scene-investigation-scene-reference-first

Details

Type
Standard or guidance
Written for
New to the fieldNew to the field
Publisher
National Institute of Justice, U.S. Department of Justice
Version verified
November 2009
Year
2009
Identifier
NCJ 227050
Topics
first-responder, evidence-handling, triage, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.

  • SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.

  • A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.

  • Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.

  • FTK Imager

    Partly free

    A free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.