Mobile devices provide key evidence for criminal investigations, but accessing the critical information on mobile devices can often be challenging. Getting access to the data is only one part of the challenge. Establishing and maintaining device chain of custody (CoC) is also extremely important in order to streamline and limit any potential risks associated with your digital forensic investigation.
What is Chain of Custody?
What is Chain of Custody? Device Chain of Custody, is defined as the chronological documentation or paper trail that records the sequence of custody, control, transfer, analysis, and disposition of materials, including physical or electronic evidence. Maintaining the Chain of Custody is essential in order to prevent any type of contamination of seized evidence through improper device and data handling.
Essentially, you must document each and every person who came into contact with the evidence and identify how the evidence was handled. The best time to establish device Chain of Custody is upon initial contact with the device at which you should document as much information as possible, including:
- Time and physical location of seizure
- Device specifications like make, model, and serial number
- Who took control of the physical evidence
- How was the device secured (e.g. faraday bag)
Why is Chain of Custody Important?
Digital forensics access tools, such as GrayKey, can extract encrypted or inaccessible data from mobile devices and offers same-day extraction on locked iOS and leading Android devices — often in less than one hour, helping maintain the chain of custody. GrayKey reduces the risk of breaking the Chain of Custody and compromising evidentiary integrity by providing the ability to quickly access and extract evidence from mobile devices with complete control. Having this ability to quickly extract data from a mobile device not only helps expedite your investigations, but it also ensures that you are maintaining control over the chain of evidence.
To learn more about the importance of maintaining chain of custody and GrayKey, check out our latest e-book.