Priority Action Report



Similar documents
INNOVATION. Campus Box 154 P.O. Box Denver, CO Website:

Scientific Working Group on Digital Evidence (SWGDE)

An Historical Perspective of Digital Evidence: A Forensic Scientist s View

QUALITY STANDARDS FOR DIGITAL FORENSICS

SWGDE Minimum Requirements for Quality Assurance in the Processing of Digital and Multimedia Evidence

INTEGRITY FORENSICS. Where the Evidence Tells the Truth. Charles M. Pruitt 2545 Bellwood Road Richmond, Virginia

Digital Forensics at the National Institute of Standards and Technology

Diablo Valley College Catalog

Jeff M. Smith

CURRICULUM VITAE (updated 3/11/13)

Blueprint to Becoming a Forensic Scientist. Lawrence Quarino, Ph.D., D-ABC, Dwight Adams, Ph.D. Steve Lee, Ph.D.

Mobile Device Forensics. Rick Ayers

WILLIAM OETTINGER PHONE (702)

American Academy of Forensic Sciences

Board/Authority Authorised Course Framework Template

DIGITAL FORENSICS SPECIALIST GROUP

DIABLO VALLEY COLLEGE CATALOG

Rapid DNA Analysis in the Police Booking Suite: FBI Initiative for Reference Sample Point-of-Collection Analysis

Deleted File Recovery Tool Testing Results

MINUTES OF THE MEETING OF MAY 16, 2013

Chapter 2 Planning, Resource Allocation, and Institutional Renewal

Forensic Science Career Webinar Digital & Multimedia Sciences. Catalin Grigoras, PhD Mark Pollitt, PhD Marcus Rogers, PhD

Curriculum Vitae. EDUCATION Bachelor of Science Major: Zoology; Minor Chemistry (1980) South Dakota State University Brookings, SD

American Academy of Forensic Sciences

Curriculum Vita. Gregg M. Stutchman Forensic Analyst & Expert Witness in Audio, Video & Image Forensics & Forensic Photography

Forensic Science II: Course Syllabus Forensic Science II: More Secrets of the Dead

What can I do with a degree in CRIMINAL JUSTICE?

ADOPTED AMERICAN BAR ASSOCIATION JUDICIAL DIVISION CRIMINAL JUSTICE SECTION REPORT TO THE HOUSE OF DELEGATES RESOLUTION

What can I do with a major in Justice Studies: Criminal Justice?

PAUL JOHNSON CRIMINAL DISTRICT ATTORNEY 1450 E. MCKINNEY, STE 3100 P. 0. BOX 2344 DENTON, TEXAS HOT CHECKS

SOCIOLOGY What can I do with this major?

DIGITAL AND MULTIMEDIA FORENSICS JUSTIFIED: AN APPRAISAL ON PROFESSIONAL POLICY AND LEGISLATION AMY LYNNETTE POPEJOY

Curriculum Vita. Gregg M. Stutchman Forensic Analyst & Expert Witness in Audio & Video Forensics Forensic Photography

Office-Based Treatment of Opioid Dependence

Dennis J. Bona, Ed.D.

How To Improve The Criminal Justice System

TCJIU Members: Judge Barbara Hervey, Texas Court of Criminal Appeals Senator Rodney Ellis, Texas Senate Mary Anne Wiley, Deputy General Counsel to

WPI Personnel Location Briefing. Joe Heaps Deputy Chief Information and Sensor Technologies Division National Institute of Justice

SALARY RANGE (approximate) $ $55.42 Hour $6, $9, Monthly $78, $115, Annually

CENTER ON JUVENILE AND CRIMINAL JUSTICE. JANUARY Research Brief. Interest Groups and Criminal Justice Policy.

Syllabus. No: CIS 207. Title: Intro to Computer Forensics. Credits: 3. Coordinator: Dr. B. Dike-Anyiam, Computer Science & Networking Lecturer

NIST Activities in Forensic Science: National Commission on Forensic Science (NCFS) Organization of Scientific Area Committees (OSAC)

INTEGRITY FORENSICS. Where the Evidence Tells the Truth. Marjorie E. Harris 2545 Bellwood Road Richmond, Virginia

ACADEMIC AFFAIRS COUNCIL ******************************************************************************

Programme Specification and Curriculum Map for MSc Electronic Security and Digital Forensics

CLEMSON UNIVERSITY. College Of Business and Behavioral Science Department of Sociology and Anthropology

Reasons for need for Computer Engineering program From Computer Engineering Program proposal

South Dakota Board of Regents New Baccalaureate Degree Minor. President of the University

CURRICULUM VITAE OF BONNIE BLUME GOLDSAMT THE LAW & MEDIATION OFFICES OF BONNIE BLUME GOLDSAMT, MA, JD, APM

Scientific Working Group on Digital Evidence

CAREER: FORENSIC SCIENCE TECHNICIAN 1

Nottingham Trent University Course Specification

Albert S. Cook Library, Towson University, 8000 York Rd., Towson, MD

Course Title: Computer Forensic Specialist: Data and Image Files

Federated Testing: Well-Tested Tools, Shared Test Materials & Shared Test. Reports; The Computer Forensics Tool Catalog Website: Connecting

AN INITIAL COMPARISON OF EDUCATIONAL TECHNOLOGY COURSES FOR TRAINING TEACHERS AT MALAYSIAN UNIVERSITIES: A COMPARATIVE STUDY

Program Review for Mechanical and Aerospace engineering, UCSD 4/29/13-4/30/13

Digital Forensics: DFCB and the ABA Resolution

How To Get A Criminal Justice Degree

How To Run A Forensic Lab

BlackLight v Test Results for Mobile Device Acquisition Tool

SUBCOMMITTEE REPORTS

Should you wish to contact me: o Barry Fisher o (213) o bajfisher@earthlink.net

Dean, College of Health and Human Services California State University, Los Angeles

Washburn University School of Applied Studies Department of Criminal Justice and Legal Studies

Summary of Qualifications: Education: Professional Experience: Kenneth R. Moses

Criteria for Accrediting Computer Science Programs Effective for Evaluations during the Accreditation Cycle

NAC Institutional Committee Meeting

The Keyed-Hash Message Authentication Code (HMAC)

CURRICULUM VITAE (updated 4/7/14)

Vice President Field Operations, Morrow- Meadows Corporation. National Electrical Contractors Association

Authority: State Trooper - Pennsylvania State Police United States Marshall Special Deputy

S C., ~.S h,?fis Q ff. _

Part III. Self-Study Report Template

Tableau TD3 Forensic Imager Test Results for Digital Data Acquisition Tool

FORENSIC SCIENCE EDUCATION PROGRAMS ACCREDITATION COMMISSION. FEPAC Computing and Information Science Technology. Call for Comments September 2015

Transcription:

Priority Action Report Digital Evidence Digital / Multimedia James Darnell 2/1/2016

Subcommittee Leadership Position Name Organization Term Email Chair James Darnell U.S. Secret Service Vice Chair Sam Brothers Customs and Border Protection Executive Secretary Andrew Neal TransPerfect Legal Solutions 2 james.darnell@usss.d hs.gov 3 sam.i.brothers@cbd.d hs.gov 2 aneal@transperfect.c om 2

Subcommittee Members # Name Organization Term Email 1 Bill Eber Department of Defense 2 buzzbill@gmail.com 2 Mark Phillips Johnson County Sheriffs Office 4 mark.phillips@jocogov.org 3 Mary Horvath Federal Bureau of Investigation 4 mary.horvath@ic.fbi.gov 4 Ryan Pittman NASA, OIG 4 ryan.d.pittman@nasa.gov 5 Sabrina Feve U.S. Atty Office, San Diego, CA 3 sabrina.feve@usdoj.gov 6 Ovie Carroll Department of Justice 4 ovie.carroll@usdoj.gov 7 Dave Hallimore Houston Forensic Science Center 4 forensicaudio@gmail.com 8 Jeff Taylor Arkansas State Crime Laboratory 4 jeff.taylor@crimelab.arkansas.gov 9 Jim Lyle NIST 3 Jlyle@nist.gov 10 Marcus Rogers Purdue University 3 rogersmk@purdue.edu 11 Joshua Brunty Marshall University 4 josh.brunty@marshall.edu 12 James Adam Holland Wal-Mart Stores, Inc. 3 James.A.Holland@walmart.com 13 David Papagiris Iron Mountain 2 David.Papargiris@ironmountain.c om 14 Joseph Cassilly State s Atty, Harford County, MD 2 jicassilly@harfordcountymd.gov 15 Daren Ford Weld County Sheriff's Office 2 dford@co.weld.co.us 16 Paul Reedy Washington D.C. Consolidated Lab 3 paul.reedy@dc.gov 3

Discipline Description The Digital Evidence Subcommittee focuses on standards and guidelines related to information of probative value that is stored or transmitted in binary form. 4

Summary of Standards/Guidelines Priority Actions Priority Working Title of Document 1 Minimum Requirements for Quality Assurance in the Processing of Digital and Multimedia Evidence 2 ASTM E2678-09 Standard Guide for Education and Training in Computer Forensics 3 Forensic Audio Examination, Retrieval, Workflow; new standards derived from SWGDE Best Practices for Forensics Audio (3 new documents) 4 Best Practices for Preservation, Isolation, Acquisition of Mobile and other Embedded Systems; new guidelines derived from NIST 800-101 (3 new documents) 5

Standards/Guidelines Development Priority 1 Document Document Title: Minimum Requirements for Quality Assurance in the Processing of Digital and Multimedia Evidence Scope: This document proposes minimum requirements regarding training/education, examiner certification, examination requirements and lab requirements Objective/rationale: Describe the minimum requirements necessary to achieve quality assurance in regard to completing digital evidence forensic examinations Issues/Concerns: The minimum bar may be too high for some to achieve Task Group Name: Training/Certification Task Group Chair Name: Andrew Neal Task Group Chair Contact Information: aneal@transperfect.com Date of Last Task Group Meeting: 1/29/2016 6

Standards/Guidelines Development Priority 1 Document Key Components of Standard: Employment Qualifications DME Training / Certification Apprenticeship Ongoing Training Competency and Proficiency Assessments Laboratory Standards Examination Procedures Review Reporting 7

Priority 1: Minimum Requirements for Quality Assurance in the Processing of Digital and Multimedia Evidence Task Group/Subcommittee Action Plan Planned Actions Complete AAFS template and move through SDO Process OSAC Process Stage (e.g., SDO 100) Assignee Estimated Completion Date SDO 100 Andrew Neal 8/1/2016 8

Standards/Guidelines Development Priority 2 Document Document Title: ASTM E2678-09 Standard Guide for Education and Training in Computer Forensics Scope: This standard is specific to the computer forensics sub discipline of digital and multimedia evidence. Objective/rationale: Improve and advance computer forensics through the development of model curricula consistent with other forensics science programs Issues/Concerns: Work with organizations to adopt the model curricula Task Group Name: Education Task Group Chair Name: Marcus Rogers Task Group Chair Contact Information: rogersmk@purdue.edu Date of Last Task Group Meeting: 1/29/2016 9

Standards/Guidelines Development Priority 2 Document Key Components of Standard: Qualifications Core Competencies Model curriculum Implementation including assessment, faculty, and facilities 10

Priority 2: Standard Guide for Education and Training in Computer Forensics Task Group/Subcommittee Action Plan Planned Actions Complete registry approval process for existing standard OSAC Process Stage (e.g., SDO 100) Assignee Estimated Completion Date RA-100 Mark Rogers 4/1/2016 11

Standards/Guidelines Development Priority 3 Documents Document Title: Forensic Audio Examination, Retrieval, Workflow, three new standards derived from SWGDE Best Practices for Forensics Audio. Scope: This document will comment on only those matters that may effect the audio forensic examination process. Objective/rationale: Provide forensic audio practitioners recommendations for the handling and examination of forensic audio evidence. Issues/Concerns: None Task Group Name: Audio Task Group Chair Name: David Hallimore Task Group Chair Contact Information: forensicaudio@gmail.com Date of Last Task Group Meeting: 1/29/2016 12

Standards/Guidelines Development Priority 3 Documents Key Components of Standard: Audio Laboratory Considerations Evidence Retrieval Receiving Evidence Examination Administrative and Technical Review 13

Priority 3: Audio Examination, Retrieval, Workflow Task Group/Subcommittee Action Plan Planned Actions Original document broken into three sections; complete AAFS template for each and submit OSAC Process Stage (e.g., SDO 100) Assignee Estimated Completion Date SD-100 David Hallimore 8/1/2016 14

Standards/Guidelines Development Priority 4 Document Document Title: Best Practices for Preservation, Isolation, Acquisition of Mobile and other Embedded Systems, three new guidelines derived from NIST 800-101 Scope: Organizations should find these documents helpful in establishing their policies and procedures. Objective/rationale: Help organizations evolve appropriate policies and procedures for dealing with mobile devices and to prepare forensic specialists to conduct forensically sound examinations involving mobile devices. Issues/Concerns: None Task Group Name: Mobile Devices Task Group Chair Name: Steve Watson Task Group Chair Contact Information: forensics@stevewatson.net Date of Last Task Group Meeting: 1/29/2016 15

Standards/Guidelines Development Priority 4 Document Key Components of Standard: Forensic tools and classification system Preservation Acquisition Examination and analysis Reporting 16

Priority 4: Preservation, Isolation, Acquisition of Mobile and other Embedded Systems Task Group/Subcommittee Action Plan Planned Actions Original document broken into three sections; complete AAFS template for each and submit OSAC Process Stage (e.g., SDO 100) Assignee Estimated Completion Date SD-100 Steve Watson 8/1/2016 17

Summary of Standards/Guidelines Priority Actions Priority Working Title of Document 1 Minimum Requirements for Quality Assurance in the Processing of Digital and Multimedia Evidence 2 ASTM E2678-09 Standard Guide for Education and Training in Computer Forensics 3 Forensic Audio Examination, Retrieval, Workflow; new standards derived from SWGDE Best Practices for Forensics Audio (3 new documents) 4 Best Practices for Preservation, Isolation, Acquisition of Mobile and other Embedded Systems; new guidelines derived from NIST 800-101 (3 new documents) 18

Standards/Guidelines Reviewed For Technical Merit Title Developing Organization Status* OSAC Process Stage (e.g., RA 100) Minimum Requirements for Quality Assurance in the Processing of Digital and Multimedia Evidence AAFS Complete AAFS template and move through SDO Process SD-100 ASTM E2678-09 Standard Guide for Education and Training in Computer Forensics ASTM Complete registry approval process for existing standard RA-100 19

Standards/Guidelines Reviewed For Technical Merit Title Developing Organization Status* OSAC Process Stage (e.g., RA 100) Forensic Audio Examination, Retrieval, Workflow; new standards derived from SWGDE Best Practices for Forensics Audio (3 new documents) AAFS Original document broken into three sections; complete AAFS template for each and submit SD-100 20

Standards/Guidelines Reviewed For Technical Merit Title Developing Organization Status* OSAC Process Stage (e.g., RA 100) Best Practices for Preservation, Isolation, Acquisition of Mobile and other Embedded Systems; new guidelines derived from NIST 800-101 (3 new documents) AAFS Original document broken into three sections; complete AAFS template for each and submit SD-100 21

Research Gaps Identified The digital evidence community uses file hashing as a means to determine if files, be they image or user, are a match. A research project was requested that examines the underlying scientific principles of using the file hash algorithms in such a manner 22

Additional Items of Interest Short Term SDO and tech merit forms completed TGs working into appropriate SDO templates Long Term Lab accreditation Mandatory; Minimum requirements; Possibly addessed in a DE specific supplemental Method / process validation Effects of long term exposure of examiners to questionable material 23

Priority Action Report Digital Evidence Digital / Multimedia James Darnell 2/1/2016

25