Standard ID | Contents [version] | USD | STEP2 | [PDF] delivered in | Standard Title (Description) | Status | PDF |
GA/T 825-2009 | English | 199 |
Add to Cart
|
3 days [Need to translate]
|
Data search technical specifications of electronic forensics
| Obsolete |
GA/T 825-2009
|
PDF similar to GA/T 825-2009
Basic data Standard ID | GA/T 825-2009 (GA/T825-2009) | Description (Translated English) | Data search technical specifications of electronic forensics | Sector / Industry | Public Security (Police) Industry Standard (Recommended) | Classification of Chinese Standard | A92 | Classification of International Standard | 13.310 | Word Count Estimation | 4,414 | Date of Issue | 2009-04-07 | Date of Implementation | 2009-06-01 | Regulation (derived from) | Industry Standard Record Announcement 2010 No. 2 (No. 122); Ministry of Public Security Bulletin (2015.04.19) | Issuing agency(ies) | Ministry of Public Security | Summary | This standard specifies the method of data search verification. This standard applies to electronic evidence testing in forensic science. |
GA/T 825-2009: Data search technical specifications of electronic forensics---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order.
Data search technical specifications of electronic forensics
ICS 13.310
A92
People's Republic of China Public Security Industry Standards
Electronic evidence data relevant test specifications
Posted 2009-04-07
2009-06-01 implementation
People's Republic of China Ministry of Public Security
Foreword
This standard by the National Standardization Technical Committee Criminal technology of electronic evidence Technical Committee (SAC/TC179/SC7) proposed
And centralized.
This standard was drafted. Ministry of Public Security Evidence Identification Center.
The main drafters of this standard. Zhangguo Chen, Tracing Back Club, Xinggui Dong, Chu Chuan red.
Electronic evidence data relevant test specifications
1 Scope
This standard specifies the data relevant test methods.
This standard applies to forensic science in the field of electronic evidence.
2 Terms and definitions
The following terms and definitions apply to this standard.
2.1
Find censorship or media storage devices known or keyword tests, including file search and physical search in two ways.
2.1.1
According to the known or keyword data file storage device or media censorship search test.
2.1.2
According to the known or keywords for binary data storage device or media censorship search test.
2.2
The raw data complete, accurate, non-destructive backup.
3 Equipment
3.1 Hardware
Storage media, the preservation of backup devices, with electronic evidence examination workstation read-only interface.
3.2 Software
3.2.1 Operating system. Windows, Unix, Linux, MacOS, etc.
3.2.2 software tools. EnCase, ForensicToolkit, X-WaysForensics, the resources provided by the operating system (file) management and so on.
4 steps
4.1 samples and sample number
Submission of samples and the samples were unique number.
4.2 samples and sample pictures
Submission of samples and the sample was photographed.
4.3 samples and sample preservation backup
With the preservation of the conditions of samples and sample preservation backup.
4.4 Inspection
4.4.1 Start antivirus software on electronic evidence workstation system antivirus.
4.4.2 for samples and samples (if preservation, preservation of the use of the storage device) interfaces connected to the workstation via a read-only electronic evidence.
4.4.3 by known or keyword search for files you can use EnCase, ForensicToolkit, X-WaysForensics or operation
Resources as provided by the system (file) Manager and other software tools.
|