There are two primary workflows for digital forensics:
Workflow | Description |
---|---|
Bulk forensic imaging for preservation | Create forensic images to support acquisition and preservation of born-digital archives. Transfer forensic images into digital backlog until further processing is scheduled. |
Collection-based forensics for archival processing and monetary appraisal | Create forensic images to support acquisition and archival processing of born-digital archives. Select files from forensic images and transfer files to ingest storage for transfer into digital preservation system. |
Bulk forensic imaging for preservation
- Add item to register of digital storage devices.
- Prepare item for forensic imaging.
- Use FTK Imager to create forensic image of item.
- Transfer forensic images to Libraries' digital backlog storage for preservation until further processing.
- Delete local copy of forensic image after transfer validation.
- Update entry in register of digital storage devices.
Collection-based forensics for archival processing and monetary appraisal
- Add item to register of digital storage devices.
- Prepare item for forensic imaging.
- Use FTK Imager to create forensic image of item and create a secondary (i.e., local backup) copy of the forensic image.
- Update entry in register of digital storage devices.
- Load forensic image(s) into FTK.
- Run additional analysis processing.
- Create filters as necessary.
- Create labels to support archival appraisal decisions:
- DeleteĀ
- Review for deletion
- Review for selection
- Select for retention
- Select for retention (contains PII)
- Create word list based on selection criteria.
- Create hierarchical set of bookmarks to support archival arrangement:
- Fonds title
- Series title
- Sub-series title
- Series title
- Series title
- Fonds title
- Use a combination of filters, searching, and browsing to identify and select records for retention. Use labels and bookmarks to facilitate this process.
- Use a combination of tools to identify confidential and personal information. Use labels and bookmarks to facilitate this process.
- Use bookmarks to export files and metadata from FTK.
- Export files option
- Report option
- Transfer package to Libraries' ingest storage for transfer into digital preservation system.
- Delete local backup data and FTK case after successful generation of AIPs.