Introduction
This section of the Digital Forensics Lab Manual describes basic digital forensics workflows. There are two primary workflows:
Workflow | Description |
---|---|
Bulk forensic imaging for preservation |
|
Forensic imaging and analysis for archival processing and monetary appraisal |
|
Bulk forensic imaging for preservation
- Add item to register of digital storage devices.
- Prepare item for forensic imaging.
- Use FTK Imager to create forensic image of item.
- Transfer forensic image to Libraries' digital backlog storage until further processing.
- Delete local copy of forensic image after transfer validation.
- Update entry in register of digital storage devices.
Forensic imaging and analysis for archival processing and monetary appraisal
- Add item to register of digital storage devices.
- Prepare item for forensic imaging.
- Use FTK Imager to create forensic image of item and create a secondary (i.e., local backup) copy of the forensic image.
- Update entry in register of digital storage devices.
- Create case in FTK.
- Select an evidence processing profile.
- Add forensic image to case.
- Run additional analysis processing. Use a combination of tools to identify confidential and personal information.
- Create filters as necessary.
- Create labels to support archival appraisal decisions. For example:
- Delete
- Review for deletion
- Review for selection
- Review for selection (contains PII)
- Select for retention
- Select for retention (contains PII)
- Create hierarchical set of bookmarks to support archival arrangement:
- Fonds title
- Series title
- Sub-series title
- Series title
- Series title
- Fonds title
- Create word list based on archival appraisal guidelines.
- Use a combination of filters, searching, and browsing to select and organize records for retention. Use labels and bookmarks to facilitate this process.
- Use bookmarks to export files and metadata from FTK.
- Export files option
- Report option
- Package files into one or more "bags" that conform to the BagIt specification.
- Upload bag(s) to the Libraries' ingest storage.
- Transfer bag(s) into digital preservation system.
- Process transfer and generate AIPs.
- Delete local backup data and FTK case after successful generation of AIPs.
Workflows at other institutions
Princeton University Library, Department of Rare Books and Special Collections, "Born-Digital University Archives Workflows." https://rbsc.princeton.edu/workflows/born-digital/university-archives.