Legal Cyber Academy
Standard or guidanceFreeCurrent

NIST Cloud Computing Forensic Science Challenges

Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Richard Lee, Nancy Landreville, Anand Kumar Mishra, Yien Wang, Rodrigo Sardinas · National Institute of Standards and Technology · NISTIR 8006, final, August 2020 · 2020

Identifier: NISTIR 8006

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A catalogue produced by the NIST Cloud Computing Forensic Science Working Group that aggregates and categorises the forensic challenges of investigating incidents in cloud ecosystems — multi-tenancy, data location, provider dependency, chain of custody across parties, and the rest. The draft circulated from 2014; the final was issued in August 2020.

Who it is for, and when

Read it when scoping a cloud investigation or writing the limitations section of a cloud-evidence report, because it gives a named, citable federal source for why a particular artefact could not be obtained. Lawyers can use it to frame discovery requests to providers and to anticipate authentication arguments.

What it does not cover

It only states challenges; it deliberately offers no solutions, no acquisition procedures and no provider-specific guidance, and it names no APIs or tools. For the architectural response, read NIST SP 800-201 instead.

Go to the source

Open at csrc.nist.gov (opens in a new tab)

https://csrc.nist.gov/pubs/ir/8006/final

Details

Type
Standard or guidance
Written for
Working examinerLawyers and courtsWorking examiner, Lawyers and courts
Author
Martin Herman, Michaela Iorga, Ahsen Michael Salim, Robert Jackson, Mark Hurst, Ross Leo, Richard Lee, Nancy Landreville, Anand Kumar Mishra, Yien Wang, Rodrigo Sardinas
Publisher
National Institute of Standards and Technology
Version verified
NISTIR 8006, final, August 2020
Year
2020
Identifier
NISTIR 8006
Topics
cloud, cloud-forensics, evidence-handling, chain-of-custody, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.

  • Two subsections of Rule 902 that let a party authenticate electronic evidence by written certification instead of live testimony: 902(13) covers a record generated by an electronic process or system that produces an accurate result, and 902(14) covers data copied from an electronic device, storage medium, or file when authenticated by a process of digital identification. Both borrow the certification and pretrial notice machinery of Rule 902(11).

  • An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.

  • The successor work to NISTIR 8006: a forensic reference architecture that maps the challenges onto the NIST cloud computing reference architecture and identifies where forensic readiness has to be designed in, with mitigation strategies tied to specific architectural elements. It includes a methodology plus a preliminary worked implementation.

  • SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.