Teesside University, Middlesbrough, UK.
J Forensic Sci. 2021 Jan;66(1):179-189. doi: 10.1111/1556-4029.14582. Epub 2020 Oct 9.
As digital evidence now features prominently in many criminal investigations, such large volumes of requests for the forensic examination of devices has led to well publicized backlogs and delays. In an effort to cope, triage policies are frequently implemented in order to reduce the number of digital devices which are seized unnecessarily. Often first responders are tasked with performing triage at scene in order to decide whether any identified devices should be seized and submitted for forensic examination. In some cases, this is done with the assistance of software which allows device content to be "previewed"; however, in some cases, a first responder will triage devices using their judgment and experience alone, absent of knowledge of the devices content, referred to as "decision-based device triage" (DBDT). This work provides a discussion of the challenges first responders face when carrying out DBDT at scene. In response, the COLLECTORS ranking scale is proposed to help first responders carry out DBDT and to formalize this process in an effort to support quality control of this practice. The COLLECTORS ranking scale consists of 10 categories which first responders should rank a given device against. Each devices cumulative score should be queried against the defined "seizure thresholds" which offer support to first responders in assessing when to seize a device. To offer clarify, an example use-case involving the COLLECTORS ranking scale is included, highlighting its application when faced with multiple digital devices at scene.
随着数字证据在许多刑事调查中占据重要地位,对设备进行法医检查的大量请求导致了众所周知的积压和延迟。为了应对这种情况,通常会实施分类政策,以减少不必要扣押的数字设备数量。通常,第一响应者的任务是在现场进行分类,以决定是否应扣押和提交任何已识别的设备进行法医检查。在某些情况下,这是借助允许“预览”设备内容的软件来完成的;但是,在某些情况下,第一响应者将仅根据自己的判断力和经验对设备进行分类,而不了解设备的内容,这被称为“基于决策的设备分类”(DBDT)。这项工作讨论了第一响应者在现场进行 DBDT 时面临的挑战。作为回应,提出了 COLLECTORS 排名量表,以帮助第一响应者进行 DBDT,并使该过程正式化,以支持该实践的质量控制。COLLECTORS 排名量表由 10 个类别组成,第一响应者应根据这些类别对给定设备进行排名。应根据定义的“扣押阈值”查询每个设备的累计得分,该阈值为第一响应者评估何时扣押设备提供了支持。为了说明问题,包括了一个涉及 COLLECTORS 排名量表的示例用例,突出了在现场面对多个数字设备时如何应用该量表。