Ten Tips for Preserving Computer Evidence After an Incident
If you have a possible trade secret case in your hands and believe you will
need computer forensics in the near future, there are some important steps to
take to ensure the collection of valuable data without spoliation. Treat the
scene as a true crime scene, and use these tips as a guideline for your trade
secret case:
Consult your computer forensics experts. Have computer forensic “images”
of hard drives created to preserve evidence.
to “search” the machines for evidence… this can destroy or
“overwrite” important files, or deem any evidence inadmissible in
court.
devices such as external drives, CD-ROMs and disks.
and portable digital devices such and Blackberries, Palm products and iPods.
voicemail accounts to avoid evidence spoliation.
related media that may be important to your case.
protect against unauthorized access from outside the workplace.
computer serial numbers, user locations, transportation of evidence, and important
times and dates. Mark evidence appropriately and use property receipts. Document
the steps you have taken to obtain and preserve computer evidence. Consider
taking photos of computers, serial numbers and workspaces.
such as passwords, printed versions of electronic files and other relevant
evidence.
and control and restrict access to anything electronic.