DATA SOURCE IDENTIFICATION · A GUIDE FOR UK LAWYERS
Finding the Evidence
A Lawyer's Map of Modern Electronic Data Sources
COMPUTER FORENSICS LAB
· E-DISCOVERY. UK
§ ABOUT THE AUTHOR
PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM
CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS
In this guide
01 Executive summary
02 The problem in plain English, and why identification is a legal duty
03 How to read the map: custodians, systems, control and volatility
04 The map · Endpoints: computers, laptops, phones and tablets
05 The map · Communications: email, messaging apps, Teams, Slack, social media
06 The map · Storage: file servers, NAS, cloud storage and backups
07 The map · Business systems: SaaS, CRM, ERP, databases and finance
08 The map · Ambient and physical: CCTV, access control, telephony, IoT
09 The map · Infrastructure and logs: identity, network, MDM, audit trails
10 The map · Third-party providers, and the legal routes to their data
11 The volatility league table: what dies first
12 "Have we identified all potentially relevant systems?" Proving a defensible process
13 The custodian and source questionnaire (Parts A, B and C)
14 Common mistakes and technical limitations
15 Questions for the opponent and the provider · Suggested instruction wording
16 Checklist and red flags · When to involve a digital forensic expert
17 Frequently asked questions
18 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION
Executive summary
§ 02 · FIRST PRINCIPLES
The problem in plain English: why identification is a legal duty
FOR THE PRACTITIONER
§ 03 · READINGTHEMAP
How to read the map: custodians, systems, control and volatility