Showing posts with label ISO/IEC 17025:2005. Show all posts
Showing posts with label ISO/IEC 17025:2005. Show all posts

Tuesday, June 06, 2017

Not Comfortable Fit for Digital Forensics - ISO17025



Within the digital forensics arena there is discomfort amongst labs, academia, businesses and practitioners that ISO/IEC 17025 'General requirements for the competence of testing and calibration laboratories' is not a comfortable fit for digital forensics. Very few digital forensics laboratories and businesses have been accredited so far. To get an understanding of concerns obtained from a pretty good base-data of opinion from replies to UK ISO 17025 Digital Forensics Survey 4/24/2017 created by Professor Peter Sommer, the results have been published and are available here http://goo.gl/KP0HOn .

Not to second guess the Forensic Science Regulator (FSR) there is , of course, the October 2017 deadline looming and the outcomes of that deadline might impact on the way forward. However, I regularly keep an eye on Lab Accreditation and Best Practice Guides (as you can see from some of the pdf tabs open in the above screen shot) in context with digital forensics in order to note the changing approach to digital forensics. The new breeze appears to suggest digital forensics blowing towards ISO standards e.g.

ISO/IEC 27042: 2015. Information Technology - Security Techniques - Guidelines for the Analysis and Interpretation of Digital Evidence.

ISO/IEC 27037: 2012. Information Technology - Security Techniques - Guidelines for Identification, Collection, Acquisition and Preservation of Digital Evidence.

Currently, but this may change, these standards are not substitutes for accreditation. That does not mean though digital forensics may not branch off and have its own unique accreditation and standards. It may well be the British Standards Institute (BSI) may need to produce an equivalent standard for the UK based upon an example of the old BS5750 approach. BS5750 and ISO9000 do enable the UK Government's requirement to be met for "inclusion" of single-person organisations and SMEs to play apart in the economy and not be excluded from it due to globalism or restraint of trade practices or over-burdensome control measures.

Previously, I drew attention to how in the US, Karin Athanas, Program Manager at the American Association for Laboratory Accreditation (A2LA), produced an article titled "Accreditation for the One-Person Organization - The smallest laboratories can teach us the biggest lessons.". This article defined that smaller business entities could achieve accreditation to ISO/IEC17025: http://trewmte.blogspot.co.uk/2016/10/isoiec-1702517020-one-person.html


The UK ISO 17025 Digital Forensics Survey 4/24/2017 isn't the first time attention has been drawn to ISO/IEC17025 that it should works for all, not the few. If the latter accreditation doesn't work then maybe another route will need to be found.


Sunday, April 09, 2017

Digital Evidence ISO/IEC 27037 -v- ISO/IEC 17025

Could ISO/IEC 27037:2012 be the better option for handling and obtaining digital forensic evidence?




ISO/IEC 27037:2012-10 (E)
Information technology - Security techniques - Guidelines for identification,
collection, acquisition and preservation of digital evidence


Contents
Foreword .......................................................................................................................................................... v
Introduction ..................................................................................................................................................... vi
1 Scope ............................................................................................................................................... 1
2 Normative reference ....................................................................................................................... 1
3 Terms and definitions .................................................................................................................... 2
4 Abbreviated terms .......................................................................................................................... 4
5 Overview ......................................................................................................................................... 6
5.1 Context for collecting digital evidence ........................................................................................ 6
5.2 Principles of digital evidence........................................................................................................ 6
5.3 Requirements for digital evidence handling ............................................................................... 6
5.3.1 General ............................................................................................................................................ 6
5.3.2 Auditability ...................................................................................................................................... 7
5.3.3 Repeatability ................................................................................................................................... 7
5.3.4 Reproducibility ............................................................................................................................... 7
5.3.5 Justifiability .................................................................................................................................... 7
5.4 Digital evidence handling processes ........................................................................................... 8
5.4.1 Overview ......................................................................................................................................... 8
5.4.2 Identification ................................................................................................................................... 8
5.4.3 Collection ........................................................................................................................................ 9
5.4.4 Acquisition ...................................................................................................................................... 9
5.4.5 Preservation.................................................................................................................................. 10
6 Key components of identification, collection, acquisition and preservation of digital
evidence ........................................................................................................................................ 10
6.1 Chain of custody .......................................................................................................................... 10
6.2 Precautions at the site of incident.............................................................................................. 11
6.2.1 General .......................................................................................................................................... 11
6.2.2 Personnel ...................................................................................................................................... 11
6.2.3 Potential digital evidence ............................................................................................................ 12
6.3 Roles and responsibilities ........................................................................................................... 12
6.4 Competency .................................................................................................................................. 13
6.5 Use reasonable care .................................................................................................................... 13
6.6 Documentation ............................................................................................................................. 14
6.7 Briefing .......................................................................................................................................... 14
6.7.1 General .......................................................................................................................................... 14
6.7.2 Digital evidence specific ............................................................................................................. 14
6.7.3 Personnel specific ........................................................................................................................ 15
6.7.4 Real-time incidents ...................................................................................................................... 15
6.7.5 Other briefing information ........................................................................................................... 15
6.8 Prioritizing collection and acquisition ....................................................................................... 16
6.9 Preservation of potential digital evidence ................................................................................. 17
6.9.1 Overview ....................................................................................................................................... 17
6.9.2 Preserving potential digital evidence ......................................................................................... 17
6.9.3 Packaging digital devices and potential digital evidence ........................................................ 17
6.9.4 Transporting potential digital evidence ..................................................................................... 18
7 Instances of identification, collection, acquisition and preservation .................................... 19
7.1 Computers, peripheral devices and digital storage media ..................................................... 19
7.1.1 Identification ................................................................................................................................ 19
7.1.2 Collection ..................................................................................................................................... 21
7.1.3 Acquisition ................................................................................................................................... 25
7.1.4 Preservation ................................................................................................................................. 29
7.2 Networked devices ...................................................................................................................... 29
7.2.1 Identification ................................................................................................................................ 29
7.2.2 Collection, acquisition and preservation .................................................................................. 31
7.3 CCTV collection, acquisition and preservation ........................................................................ 33
Annex A (informative) DEFR core skills and competency description ................................................... 35
Annex B (informative) Minimum documentation requirements for evidence transfer .......................... 37
Bibliography .................................................................................................................................................. 38

Saturday, October 15, 2016

ISO/IEC 17025/17020 - One-Person Organisation

Having just finished part two of the work study into QA and Laboratory Accreditation MTEB UK SEMINARS 2016 II v03- QA Lab Accreditation.pdf ( http://trewmte.blogspot.co.uk/2016/10/qa-and-laboratory-accreditation.html ) I came across this cracking article by Karin Athanas, Program Manager at the American Association for Laboratory Accreditation (A2LA) titled "Accreditation for the One-Person Organization - The smallest laboratories can teach us the biggest lessons." ( http://forensicfoundations.com/resources/Documents_CLR/2016_10_3_SUMMER.pdf )

Basically Karin's article helps us understand that one, two or three person/s organisation/s should not be put off but can and should apply for ISO/IEC 17020 and 17025 as the requirements are not insurmountable, particularly when it comes to allocation to whom the quality manager's role, audits etc. will be allocated and deemed to be responsible. I also read this to mean that ABs might need to widen their scope to appreciate many roles in a accredited system can be held by one person.

Karin's article is a recommended read.

Sunday, October 09, 2016

QA and Laboratory Accreditation

MTEB UK SEMINARS 2016 II v03- QA Lab Accreditation.pdf
Read more - updated link http://tinyurl.com/zr2oqyp

QA and Laboratory Accreditation. Previously, lab criteria applied to mobile phone forensic testing was randomly applied:

- various industry standards
- public and private approach to best practice
- guidelines/training courses
- Some certified ISO9001, some sought UKAS accreditation.

The introduction of a UK Forensic Science Regulator (FSR), there are now mandated ‘Codes of Practice and Conduct’, standards and accreditation applicable to mobile phone forensic evidence:

- ISO/IEC 17025 e.g. requirements for the competence to carry out tests and calibrations...
- ISO/IEC 17020 e.g. scene of crime and in the field activity
- UKAS Accreditation

The FSR’s strategy moves the goalposts away from simply applying industry best practice and random approaches to a common purpose – provision of forensic science across the criminal justice system is "subject to an appropriate regime of scientific quality standards"

That common purpose approach has been developing for approximately 6 years but only really in the last several years ISO/IEC 17025:2005 has  started to make its mark and the first accreditation to requirements of Forensic Science Regulator’s ‘Codes of Practice and Conduct’ was  2014.

- still early days for the public and private sectors
- very small number of organisations accredited for mobile phone forensic evidence
- it could be said we are all pioneers to new endeavours
- common purpose does not dilute ‘speciality’ distinguishing one organisation from another
- FSR deadlines for public sector forensic science overall 2017-2020
- e.g. Law enforcement mobile phone forensic test laboratory accreditation by Oct 2017
- Lead times of 18-months to implement suggests 2017 deadline could be missed
- ‘devil in the detail’ causing much more work than at first thought

There is increased demand for practical solutions and helpful insights that may assist prepare for accreditation.