Information technology - Security techniques - Guidelines for the analysis and interpretation of digital evidence (ISO/IEC 27042:2015)

This International Standard provides guidance on the analysis and interpretation of digital evidence
in a manner which addresses issues of continuity, validity, reproducibility, and repeatability. It
encapsulates best practice for selection, design, and implementation of analytical processes and
recording sufficient information to allow such processes to be subjected to independent scrutiny
when required. It provides guidance on appropriate mechanisms for demonstrating proficiency and
competence of the investigative team.
Analysis and interpretation of digital evidence can be a complex process. In some circumstances, there
can be several methods which could be applied and members of the investigative team will be required
to justify their selection of a particular process and show how it is equivalent to another process used
by other investigators. In other circumstances, investigators may have to devise new methods for
examining digital evidence which has not previously been considered and should be able to show that
the method produced is “fit for purpose”.
Application of a particular method can influence the interpretation of digital evidence processed by
that method. The available digital evidence can influence the selection of methods for further analysis
of digital evidence which has already been acquired.
This International Standard provides a common framework, for the analytical and interpretational
elements of information systems security incident handling, which can be used to assist in the
implementation of new methods and provide a minimum common standard for digital evidence
produced from such activities.

Informationstechnik - IT-Sicherheitsverfahren - Leitfaden für die Analyse und Interpretation digitaler Beweismittel (ISO/IEC 27042:2015)

Technologies de l'information - Techniques de sécurité - Lignes directrices pour l'analyse et l'interprétation de preuves numériques (ISO/IEC 27042:2015)

Informacijska tehnologija - Varnostne tehnike - Smernice za analizo in tolmačenje digitalnih dokazov (ISO/IEC 27042:2015)

Ta mednarodni standard podaja smernice za analizo in tolmačenje digitalnih dokazov na način, ki obravnava vprašanja o neprekinjenosti, preverjanju, reprodukciji in ponovljivosti. Vključuje najboljše prakse za izbiro, zasnovo in izvajanje analitičnih procesov in beleženje zadostne količine informacij, da lahko po potrebi takšni procesi postanejo predmet skrbnega pregleda. Podaja smernice za ustrezne mehanizme za prikaz strokovnosti in usposobljenosti preiskovalne ekipe.
Analiza in interpretacija digitalnih dokazov sta lahko zapleten proces. V nekaterih okoliščinah je mogoče uporabiti več metod, člani preiskovalne ekipe pa morajo v takšnem primeru utemeljiti izbiro določenega procesa in prikazati, da je enakovreden drugemu procesu, ki ga uporabljajo drugi preiskovalci. V drugih okoliščinah lahko preiskovalci zasnujejo nove metode za pregled digitalnih dokazov, ki še niso bile uporabljene, pri čemer naj bi prikazali, da je zasnovana metoda »primerna za uporabo«.
Uporaba določene metode lahko vpliva na interpretacijo digitalnih dokazov, obdelanih s
to metodo. Razpoložljivi digitalni dokazi lahko vplivajo na izbiro metod za nadaljnjo analizo digitalnih dokazov, ki so že pridobljeni.
Ta mednarodni standard podaja splošni okvir za analitične in interpretativne
elemente za obravnavanje informacijskega varnostnega incidenta in ga je mogoče uporabiti kot pomoč pri izvajanju novih metod in podaja minimalen skupni standard za digitalne dokaze, ki nastanejo pri takšnih aktivnostih.

Contents Page
European foreword . 3
First edition
Information technology — Security
techniques — Guidelines for the
analysis and interpretation of digital
Technologies de l’information — Techniques de sécurité — Lignes
directrices pour l’analyse et l’interprétation de preuves numériques
Reference number
ISO/IEC 27042:2015(E)
ISO/IEC 2015
ISO/IEC 27042:2015(E)
ISO/IEC 27042:2015(E)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Symbols and abbreviated terms . 4
5 Investigation . 4
5.1 Overview . 4
5.2 Continuity . 5
5.3 Repeatability and reproducibility. 5
5.4 Structured approach . 5
5.5 Uncertainty . 6
6 Analysis . 7
6.1 Overview . 7
6.2 General principles . 7
6.3 Use of tools . 8
6.4 Record keeping . 8
7 Analytical models . 8
7.1 Static analysis . 8
7.2 Live analysis . 8
7.2.1 Overview . 8
7.2.2 Live analysis of non-imageable and non-copyable systems . 9
7.2.3 Live analysis of imageable or copyable systems . 9
8 Interpretation . 9
8.1 General . 9
8.2 Accreditation of fact . . 9
8.3 Factors affecting interpretation .10
9 Reporting .10
9.1 Preparation .10
9.2 Suggested report content .10
10 Competence.11
10.1 Overview .11
10.2 Demonstration of competence .11
10.3 Recording competence .11
11 Proficiency .12
11.1 Overview .12
11.2 Mechanisms for demonstration of proficiency .12
Annex A (informative) Examples of Competence and Proficiency Specifications .13
Bibliography .14
© ISO/IEC 2015 – All rights reserved iii

ISO/IEC 27042:2015(E)
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in field

