Steve Burgess is a highly regarded expert in computer forensics, frequently testifies in court and is a well-regarded public speaker. He is a freelance technology writer, the principal of Burgess Forensics, and a contributor to recently released Scientific Evidence in Civil and Criminal Cases, 5th Edition by Moenssens, et al.
Copyright (c) 2008 Steve Burgess
Computer forensics practices and procedures can diverge significantly depending upon whether the investigation is criminal or civil litigation. Standards for data collection evidence can be different, as can the process of data collection and imaging. Furthermore, the consequences of the case may have dramatically different impacts.
A couple of quick definitions may be in order. Criminal law deals with offenses against the state - the prosecution of a person accused of breaking a law. These offenses may include crimes perpetrated against an individual. "The People", in the form of a state representative (for instance, the District Attorney) makes formal charges and the accused must then face the government's full resources. Guilty outcomes can result in fines, probation, incarceration, or even death.
Civil law covers everything else, such as violations of contracts and lawsuits between two or more parties. The prevailing party often is entitled to payment, property or services from the loser. Imprisonment is not at issue in civil cases. As a result, the standard for evidence is not as high in civil cases as in criminal cases.
For the law enforcement computer forensics specialist, a certain amount of extra care should be taken in collecting data and producing results, for the standard of proof is higher. There are advantages on the data collection end, however. For once a court has authorized a search warrant, an officer (and possibly several) with badge and gun can go seize the defendant's computer by surprise and by force. Once the computer has been seized and imaged, all data is accessible and may result in additional charges being brought against the defendant.
By contrast, in a civil case, there tends to be a lot of negotiation over what computers and what data can be inspected, as well as where and when. There is not likely to be any seizing of computers, and quite a long time may take place between the time the request to inspect a computer is made and the time the computer is made available to be inspected. It is common for one party to have access to a very limited area of data from the other party's computer. During this time, a defendant may take the opportunity to attempt to hide or destroy data. The author has had several cases wherein the computer needed for analysis was destroyed before the plaintiff had the opportunity to inspect. Such attempts at hiding data are often discovered by the digital forensic sleuth, who may in turn present evidence of such further wrongdoing in expert witness testimony.
Opportunities for learning techniques and interacting with other professionals may differ as well. While some computer forensic software suites and training, such as Access FTK, EnCase, or SMART Forensics are available to most who can pay, others, such as iLook are available only to law enforcement and military personnel. While many support and professional organizations and groups are available to all, some, such as the High Technology Crime Investigation Association (HTCIA) are not open to professionals who provide for criminal defense (with a few minor exceptions).
Police, Homeland Security, and other law enforcement personnel's goal is to generate a body of evidence significant enough (presuming such evidence exists) to find the criminal defendant guilty. The standard for information presented to the court and jury in such a case is fairly high. From the time digital data or hardware is seized and acquired, Rules of Evidence must be kept in mind (Cornell University has the complete and voluminous code on its website). Law enforcement personnel must follow accepted procedures or evidence could be thrown out. Acquisition of data and discovery in criminal cases often must follow sometimes strict and differing procedures depending upon whether the jurisdiction is federal, state, or municipality and at times depending upon a judge's preferences.
The expert in a civil case may not analyze all of the data on a computer at a very deep level Initial efforts may rather be a kind of fact-finding mission, intended to determine the value of digging deeper and at greater expense. As such, the initial presentation of data may be fairly informal, and be just enough to induce the parties to settle the case. On the other hand, the data found may be so minimal the line of inquiry into electronic evidence is dropped.
Although we use many of the same tools, computer forensic professionals in private practice and those in law enforcement are held to different standards, have access to different resources, and their work results in substantially different outcomes between the criminal and civil cases to which they contribute.
- Related Videos
- Related Articles
- Ask / Related Q&A




Nokia 7510 Supernova Mobile Phone Review - The Ultimate Fun But Affordable Phone
By: Carlson Osbourne | 29/11/2009The Supernova series that Nokia has released over the past few years has been met with a variety of reactions from mobile phone reviewers, with the most prevalent feeling being one of disappointment. Well, the Nokia 7510 Supernova is the latest model and it appears at first glance that Nokia...
Save All Your Crucial Data With Best in Class Desktop Sync
By: Michael Hutton | 29/11/2009Do you own a desktop PC for all your personal and business purposes? Are you anyway vexed with the messed up with the scattering of things and bulky arrangements?
Eyes Designing on your Ecommerce Website
By: monika | 29/11/2009In a recent article I talked about Google AdSense placement based on eye-tracking research. However, research by The Poynter Institute, Eyetools and the Estlow Center for Journalism and New Media has a lot to say about more than where to put an AdSense block.
Camcorder Recording Methods and Technology
By: Allen Roberts | 29/11/2009Over the years, camcorders have evolved from tape (which has spanned many decades), to DVD, and more recently to Harddrives(HDD) and Flash Memory. [1] Tape Camcorders - The oldest technology has evolved from reel to reel, VHS, VHS-C, 8mm, Hi8, and finally to today's best tape technology, the MiniDV tape. The...
Netbook vs Laptop
By: Nestor Hayden | 28/11/2009Going back a few years, the one question which was continuously asked of me was, should I get a laptop instead of a desktop PC? Whilst there is no definitive answer, as each person's needs are different, the answer has probably changed from 90% NO to 90% YES. The reason for this is the narrowing gap between desktop and laptop computers in terms of performance, reliability and storage capacity. Now we have a stand-off between netbook and laptop computers as people explore the possibi...
The Key Features of a HP CP3525 Printer
By: Derek Rogers | 28/11/2009The Hewlett Packard CP3525 is an incredibly advanced series of Laser Jet printers. They provide fantastic quality prints in double quick time; the compact size of the CP3525 lends it for use in the home and small offices. Including three individual models - HP CP3525n, 3525dn and 3525x - there is...
A Windows 7 review you will understand
By: Mark Kelly | 28/11/2009This is a nice review of Windows 7 that covers all of the main points in a manner you will understand. The big question is... should we embrace or avoid Windows 7? This is the question I am going examine in this entry and I hope that I will be able to help you make an informed choice about whether to adopt Windows 7.
How To Share Files Between Windows 7 and Windows XP
By: Elias Rizos | 28/11/2009If you have multiple computers at home and want to network them together to share files and devices then this article is for you! In this article I'll show how to setup file sharing in a mixed environment consisting of Windows 7 and Windows XP.
Computer Forensics is Different for Police and Other Law Enforcement
By: Steve Burgess | 28/09/2008 | ComputersIn the field of computer forensics, as in the field of law, procedures in civil cases differ somewhat from those in criminal cases. The collection of data and presentation of evidence may be held to different standards, the process of data collection and imaging can be quite different, and the consequences of the case may have very different impacts. A couple of quick definitions may be in order.