Feeds

US laws restrict computer forensics to gumshoes

Jobs for the boys?

Build a business case: developing custom apps

More US states are moving towards laws that limit computer forensics work to those with Private Investigator licences, or people contracted to work for licensed investigative agencies.

Pending legislation in South Carolina would limit the specialist work of capturing and making sense of evidence on computer discs and server logs to businesses whose main line of work is serving legal process or matrimonial investigations. The bill covers computers forensic evidence presented in court.

Computer evidence compiled by unlicensed practitioners would be excluded from admission in either civil or criminal cases under the regulation. Those caught practicing without a licence to collect evidence for court (though not on a private basis) could face criminal prosecution.

Enterprises or private individuals would still be free to hire anyone they choose for private investigations. Computer forensics is often used as an internal investigatory tool following computer intrusions, or in response to suspicion of staff misuse of internet resources.

Georgia, New York, Nevada, North Carolina, Texas, Virginia and Washington already have similar legislation, Baseline Magazine reports. The idea is that by restricting the preparation of computer forensics work for presentation in court promotes higher standards and keeps out the cowboys.

However, expecting computer forensics experts to have a PI licence makes about as much sense as requiring PIs to have computer science degrees. Most private investigators come from a police or forces background. The regulations smack of protectionism.

Commonly, specialist agencies handle IT-related work such as counter-surveillance and forensic examination. Data recovery firms and others with computer forensics expertise may be equally capable in preserving and processing computer evidence, but are locked out of the business in the US, unlike other countries such as the UK where such firms are typically swamped with work. ®

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
Plug and PREY: Hackers reprogram USB drives to silently infect PCs
BadUSB instructs gadget chips to inject key-presses, redirect net traffic and more
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?