The most important rule in computer forensics is minimal handling of the original. This is when you can make a copy of the evidence you’ve discovered but is has to be an exact duplicate and must also authenticate the copy that has been made. If not, questions can arise. Account for any change is when changes to the evidence may be ruined when you have to shut down or turn the computer on to boot it up. The changes may be to the memory or temporary files. If any changes do occur, they must all be documented. Comply with the rules of evidence. These are the rules investigators must follow when examining and or handling evidence. They follow these rules to make sure that the evidence they do seize is accepted by the court of law. The last is do not exceed your knowledge. This is when you don’t continue an investigation if it is above your skill level and
The most important rule in computer forensics is minimal handling of the original. This is when you can make a copy of the evidence you’ve discovered but is has to be an exact duplicate and must also authenticate the copy that has been made. If not, questions can arise. Account for any change is when changes to the evidence may be ruined when you have to shut down or turn the computer on to boot it up. The changes may be to the memory or temporary files. If any changes do occur, they must all be documented. Comply with the rules of evidence. These are the rules investigators must follow when examining and or handling evidence. They follow these rules to make sure that the evidence they do seize is accepted by the court of law. The last is do not exceed your knowledge. This is when you don’t continue an investigation if it is above your skill level and