ASTM E2678-09(2014)
(Guide)Standard Guide for Education and Training in Computer Forensics (Withdrawn 2023)
Standard Guide for Education and Training in Computer Forensics (Withdrawn 2023)
SIGNIFICANCE AND USE
3.1 With the proliferation of computers and other electronic devices, it is difficult to imagine a crime that could not potentially involve digital evidence. Because of the paucity of degree programs in computer forensics, practitioners have historically relied on practical training through law enforcement or vendor-specific programs or both.
3.2 In this guide, curricula for different levels of the educational system are outlined. It is intended to provide guidance to:
3.2.1 Individuals interested in pursuing academic programs and professional opportunities in computer forensics,
3.2.2 Academic institutions interested in developing computer forensics programs, and
3.2.3 Employers seeking information about the educational background of graduates of computer forensics programs and evaluating continuing education opportunities for current employees.
SCOPE
1.1 This guide will improve and advance computer forensics through the development of model curricula consistent with other forensic science programs.
1.2 Section 4 describes the alternative paths by which students may arrive at and move through their professional training. Sections 5 through 7 cover formal educational programs in order of increasing length: a two- year associate degree, a four-year baccalaureate degree, and graduate degrees. Section 8 provides a framework for academic certificate programs offered by educational institutions. Section 9 outlines model criteria and implementation approaches for training and continuing education opportunities provided by professional organizations, vendors, and academic institutions.
1.3 Some professional organizations recognize computer forensics, forensic audio, video, and image analysis as subdisciplines of computer forensics. However, the curricula and specific educational training requirements of subdisciplines other than computer forensics are beyond the scope of this guide.
1.4 This standard does not purport to address all of the safety concerns, if any, associated with its use. It is the responsibility of the user of this standard to establish appropriate safety and health practices and determine the applicability of regulatory limitations prior to use.
WITHDRAWN RATIONALE
This guide will improve and advance computer forensics through the development of model curricula consistent with other forensic science programs.
Formerly under the jurisdiction of Committee E30 on Forensic Sciences, this guide was withdrawn in January 2023 in accordance with section 10.6.3 of the Regulations Governing ASTM Technical Committees, which requires that standards shall be updated by the end of the eighth year since the last approval date.
General Information
Standards Content (Sample)
NOTICE: This standard has either been superseded and replaced by a new version or withdrawn.
Contact ASTM International (www.astm.org) for the latest information
Designation: E2678 − 09 (Reapproved 2014) An American National Standard
Standard Guide for
Education and Training in Computer Forensics
This standard is issued under the fixed designation E2678; the number immediately following the designation indicates the year of
original adoption or, in the case of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. A
superscript epsilon (´) indicates an editorial change since the last revision or reapproval.
1. Scope 2.1.2 capstone project, n—design and implementation-
oriented project typically completed during the final year of a
1.1 This guide will improve and advance computer foren-
degree program that requires students to apply and integrate
sics through the development of model curricula consistent
knowledge and skills gained from several courses.
with other forensic science programs.
2.1.3 central processing unit (CPU), n—computer chip that
1.2 Section 4 describes the alternative paths by which
interprets commands and runs programs.
students may arrive at and move through their professional
2.1.4 compiler, n—software that translates a high- level
training. Sections 5 through 7 cover formal educational pro-
program into a form that can be executed by a computer.
grams in order of increasing length: a two- year associate
degree,afour-yearbaccalaureatedegree,andgraduatedegrees.
2.1.5 digital forensics, n—science of identifying, collecting,
Section 8 provides a framework for academic certificate
preserving, documenting, examining, and analyzing evidence
programsofferedbyeducationalinstitutions.Section9outlines
from computer systems, the results of which may be relied
model criteria and implementation approaches for training and
upon in court.
continuing education opportunities provided by professional
2.1.6 cryptography, n—using the sciences of encryption to
organizations, vendors, and academic institutions.
transformdatatohideitsinformationcontentanddecryptionto
1.3 Some professional organizations recognize computer restore the information to its original form.
forensics, forensic audio, video, and image analysis as subdis-
2.1.7 datafusion,n—processofassociating,correlating,and
ciplines of computer forensics. However, the curricula and
combining data and information from single and multiple
specific educational training requirements of subdisciplines
sources.
other than computer forensics are beyond the scope of this
2.1.8 debugger, n—software that is used to find faults in
guide.
programs.
1.4 This standard does not purport to address all of the
2.1.9 demultiplexing, v—process of isolating individual im-
safety concerns, if any, associated with its use. It is the
ages from a video flow.
responsibility of the user of this standard to establish appro-
2.1.10 digital evidence, n—information of probative value
priate safety and health practices and determine the applica-
that is stored or transmitted in binary form that may be relied
bility of regulatory limitations prior to use.
upon in court.
1.5 This international standard was developed in accor-
dance with internationally recognized principles on standard-
2.1.11 computer forensics, n—science of identifying,
ization established in the Decision on Principles for the collecting, preserving, documenting, examining, and analyzing
Development of International Standards, Guides and Recom-
evidence from computer systems, networks, and other elec-
mendations issued by the World Trade Organization Technical tronicdevices,theresultsofwhichmayberelieduponincourt.
Barriers to Trade (TBT) Committee.
2.1.12 distributed denial of service (DDoS), n—intentional
paralyzing of a computer or a computer network by flooding it
2. Terminology
with data sent simultaneously from many locations.
2.1 Definitions of Terms Specific to This Standard:
2.1.13 Electronic Communications Privacy Act (ECPA),
2.1.1 assembler, n—software that translates a low-level
n—regulates interception of wire and electronic communica-
program into a form that can be executed by a computer.
tions (18 USC §2510 et seq.) and retrieval of stored wire and
electronic communications (18 USC §2701 et seq.).
2.1.14 embedded device, n—special-purpose computer sys-
This guide is under the jurisdiction of ASTM Committee E30 on Forensic
tem that is completely encapsulated by the device it controls.
Sciences and is the direct responsibility of Subcommittee E30.12 on Digital and
Multimedia Evidence.
2.1.15 enterprise system, n—computer systems or networks
Current edition approved Oct. 1, 2014. Published October 2014. Originally
or both integral to the operation of a company or large entity,
approved in 2009. Last previous edition approved in 2009 as E2678 – 09. DOI:
10.1520/E2678-09R14. possibly global in scope.
Copyright © ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken, PA 19428-2959. United States
E2678 − 09 (2014)
2.1.16 ext2/ext3 (Linux-extended 2/Linux-extended 3) file 2.1.34 thumb drive, n—smalldigitalstoragedevicethatuses
system, n—file system typically used with Linux-based oper- flash memory and a universal serial bus (USB) connection to
ating systems. interface with a computer.
2.1.17 file allocation table (FAT) file system, n—original file 2.1.35 topology, n—physical layout or logical operation of a
system used with Microsoft and IBM-compatible operating
network.
systems still in common use.
2.1.36 virtual private network (VPN), n—computer network
2.1.18 intrusion detection system (IDS), n—software or that uses encryption to transmit data in a secure fashion over a
hardware that are used to identify attacks or anomalies on public network.
computers or networks or both.
2.1.37 voice over internet protocol (VoIP), n—technique for
2.1.19 link analysis, n—type of analysis often used by law
transmitting real-time voice communications over the internet
enforcement that uses visual or other means of showing or another transmission control protocol/internet protocol
relationships between people, places, events, and things by
(TCP/IP) network.
linking them through timelines, telephone calls, emails, or any
2.1.38 wide-area network (WAN), n—computer network
other consistent scheme.
covering a wide geographical area.
2.1.20 local area network (LAN), n—computer network
2.2 Acronyms:
covering a local area such as a home, office, or small group of
2.2.1 FDA, n—Food and Drug Administration
buildings, such as a college.
2.2.2 FTC, n—Federal Trade Commission
2.1.21 malware, n—malicious software designed to cause
2.2.3 IP, n—internet protocol
unexpected and frequently undesirable actions on a system (for
example, viruses, worms, spyware, or Trojan horses).
2.2.4 IRS, n—Internal Revenue Service
2.1.22 mock trial, n—often referred to as “moot court,”
2.2.5 KSA, n—knowledge, skill, and ability
role-playing court proceedings intended to prepare students for
2.2.6 SEC, n—Securities and Exchange Commission
courtroom testimony.
2.2.7 TCP, n—transmission control protocol
2.1.23 new technology file system (NTFS), n—advanced file
system with security features commonly used with the Win-
3. Significance and Use
dows and all subsequent sytems.
3.1 With the proliferation of computers and other electronic
2.1.24 open system interconnect (OSI), n—layered model
devices, it is difficult to imagine a crime that could not
that describes the way computers communicate on a network.
potentially involve digital evidence. Because of the paucity of
2.1.25 personalareanetwork(PAN),n—networkingscheme
degree programs in computer forensics, practitioners have
that enables computers and other electronic devices to com-
historically relied on practical training through law enforce-
municate with each other over short distances either with or
ment or vendor-specific programs or both.
without wires.
3.2 In this guide, curricula for different levels of the
2.1.26 partitioning,v—softwaremethodofdividingaphysi-
educational system are outlined. It is intended to provide
cal hard drive into logical containers that will appear as
guidance to:
multiple logical drives.
3.2.1 Individuals interested in pursuing academic programs
2.1.27 peer to peer (P2P), n—communications network that
and professional opportunities in computer forensics,
allows multiple computers to share files.
3.2.2 Academic institutions interested in developing com-
puter forensics programs, and
2.1.28 personal electronic device (PED), n—consumerelec-
tronic device that is typically mobile or handheld (for example, 3.2.3 Employers seeking information about the educational
background of graduates of computer forensics programs and
personal digital assistant (PDA), cell phone, or iPOD).
evaluating continuing education opportunities for current em-
2.1.29 photogrammetry, n—science of obtaining dimen-
ployees.
sional information of items depicted in photographs.
2.1.30 public key infrastructure (PKI), n—system that uses
4. Qualifications for a Career in Computer Forensics
encryption to verify and authenticate network transactions.
4.1 Introduction:
2.1.31 random access memory (RAM), n—computer’s read/
4.1.1 Computer forensics plays a fundamental role in the
write memory; it provides temporary memory space for the
investigation and prosecution of crimes. Since any type of
computer to process data.
criminal activity may involve the seizure and examination of
2.1.32 redundant array of inexpensive/independent disks
digital evidence, the percentage of cases that involves digital
(RAID),n—systemthatusestwoormoredrivesincombination
evidence will continue to increase. The preservation,
for fault tolerance or performance.
examination, and analysis of digital evidence require a foun-
2.1.33 steganography, n—technique for embedding infor- dation in the practical application of science, computer
mation into something else, such as a text file in an image or a technology, and the law. A practitioner of computer forensics
sound file, for the sole purpose of hiding the existence of the shall be capable of integrating knowledge, skills, and abilities
embedded information. in the identification, preservation, documentation,
E2678 − 09 (2014)
examination, analysis, interpretation, reporting, and testimo- (8) History of hacking
nial support of digital evidence. A combination of education (9) Personal associations
and practical training can prepare an individual for a career in (10) Psychological screening
computer forensics, and this section addresses the qualifica- (11) Medical or physical examination
tions an individual will need to pursue such a career. (12) Polygraph examination
4.1.2 As in all forensic disciplines, a combination of
4.2.5 Academic Qualifications—Practitioners of computer
personal, technical, and professional criteria will influence a
forensics historically have not been required to have a degree.
prospective computer forensics practitioner’s suitability for However, the trend within some areas of the field is to
employment. Effective written and oral communication skills
strengthen the academic requirements for this discipline and
are essential to computer forensics practitioners because they require a baccalaureate degree, preferably in a science. The
may have to testify to their examination results in court. New
academic qualifications for computer forensics practitioners
employees may be hired provisionally or go through a proba- are discussed in greater detail later in this guide and may
tionaryperiodthatrequiressuccessfulcompletionofadditional
include the following knowledge, skills, and abilities:
training or competency testing or both as a prerequisite for
4.2.5.1 Technical:
continued employment.
(1) Computer hardware and architecture
(2) Storage media
4.2 Career Paths in Computer Forensics:
(3) Operating systems
4.2.1 Numerous competent, accurate, and admissible digital
(4) File systems
forensic examinations are performed every year by qualified
(5) Database systems
and experienced examiners who have no college education. In
(6) Network technologies and infrastructures
fact, much of the expertise in this field is represented by
(7) Programming and scripting
professionals whose practical experience, on-the-job training,
(8) Computer security
and work credentials qualify them in this discipline. Few
(9) Cryptography
institutions offer degrees in the discipline because the field is
(10) Software tools
relatively new.As academic programs are developed and made
(11) Validation and testing
available, it will become preferable for forensic examinations
(12) Cross-discipline awareness
to be performed by individuals who have a degree in computer
4.2.5.2 Professional:
forensics (or a related field) supported by experience and
(1) Critical thinking
training.
(2) Scientific methodology
4.2.2 The discussion of qualifications presents three alter-
(3) Quantitative reasoning and problem solving
native career paths into computer forensics which are depicted
(4) Decision making
in Fig. 1:
(5) Laboratory practices
4.2.2.1 One is for law enforcement personnel who seek to
(6) Laboratory safety
move into computer forensics after they become sworn
(7) Attention to detail
officers,
(8) Interpersonal skills
4.2.2.2 Another is for persons with relevant technical and
(9) Public speaking
critical thinking skills that are equivalent to a bachelor’s
(10) Oral and written communication
degree, and
(11) Time management
4.2.2.3 A third is for persons who have earned the formal
(12) Task prioritization
degree.
(13) Application of digital forensic procedures
4.2.3 A description of careers in computer forensics is
(14) Preservation of evidence
provided in Appendix X1.
(15) Interpretation of examination results
4.2.4 Personal Characteristics—Computer forensics, like
(16) Investigative process
other forensic disciplines, requires personal honesty, integrity,
(17) Legal process
and scientific objectivity. Those seeking careers in this field
4.2.5.3 Copies of diplomas and formal academic transcripts
should be aware that background checks similar to those
are generally required as proof of academic qualification.
required for law enforcement officers are likely to be a
Awards,publications,internships,andstudentactivitiesmaybe
condition of employment. The following may be conducted or
used to differentiate applicants. Claims in this regard are
reviewed or both before an employment offer is made and may
subject to verification through the background investigation
be ongoing conditions of employment (this list is not all-
process.
inclusive):
(1) Past work performance 4.2.6 Credentials—A digital forensic practitioner should
(2) Drug tests demonstrate continued professional development that is docu-
(3) History of drug use mented by credentials. A credential is a formal recognition
...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.