Simplifying forensic investigations: 10 questions to ask
- By Maurice (Mo) Cook
- Oct 01, 2020
The overwhelming number of mobile phones and computers flooding crime labs are creating a major problem for agencies conducting forensic investigations. Data overloads are causing huge bottlenecks in investigative workflows, which slows time to evidence and ultimately leads to fewer cases being solved. It also places additional pressure on understaffed agencies, which in many cases lack the proper tools to do their best work.
Fortunately, there are a number of digital intelligence solutions that can help alleviate device analysis backlogs, but these solutions must be considered in the context of an agency’s overall environment and workflow. With budgets tightening, agency managers must think about where their challenges lie and how they can best meet them.
Here are 10 questions managers should ask to ensure they are uncovering, managing and leveraging all the digital intelligence -- data extracted from smartphones, computers and the cloud -- to more efficiently run their investigations.
1. Are the right tools available?
The road to digital intelligence readiness starts by assessing current challenges and the assets available meet them. Managers must look at their mission and workflow, but also assess the tools and infrastructure they have in place -- all with an eye to the future. They should look at the trends in the digital intelligence workspace and decide where they need to be in the next three to five years. From there they can perform a gap analysis to help determine what tools should be incorporated into the agency’s workflow to make the whole process run more efficiently.
2. Are frontline officers used to best advantage to gather data at crime scenes?
Frontline officers can be an invaluable resource not only in preserving evidence at the crime scene, but in gathering data on site to jumpstart investigations. Many agencies are equipping their frontline team members with portable data extraction tools that provide a single-point extraction -- a photo or video clip.
When deployed at a crime scene, these tools help frontline officers transfer extracted photos, video clips or other information, secured in a forensically sound manner, back to command-and-control centers, giving agency managers a starting point for investigations. This is the first step in a tiered data-collection strategy where simple information is fed to the police station and then to a forensics lab where the most complicated part of the investigation takes place.
3. How is data accessed?
Being able to properly access data to expedite investigations requires the right equipment and training for investigative personnel both at the crime scene and the police station. Many agencies are challenged, however, because they don’t have protocols in place to ensure data is extracted properly (and in a manner appropriate with the situation) so that it remains uncompromised and that the evidence chain remains secure.
The goal is to simplify the chain of custody. Sending devices out to third parties for extraction is fine for agencies that may be short on resources, but bringing the extraction process in-house simplifies management of the chain of custody. It also saves time, which can be critical in cases when every second counts. More importantly, keeping extraction in-house affords agency managers far more control over the data and how it can be relayed to key team members to move investigations forward quickly.
4. How is data managed?
With today’s extraction capabilities, accessing data from digital devices is actually not that hard if trained personnel have the right solutions. What to do with the data once it is acquired, however, is a more difficult challenge. Managing data to protect the chain of evidence and ensure compliance has never been more important, especially for departments that are authorized to share information with other units or outside agencies. This is where having a proper digital evidence management system (DEMS) is key.
Agencies must manage digital evidence the same way they manage physical evidence with procedures in place to maintain data integrity and a clear process to get the right information to the right team members when they need it.. By deploying a DEMS, agencies can protect and manage data for appellate processes, simplify discovery, handle retention and comply with expungement requirements.
5. Are artificial intelligence and machine learning applied to data?
A typical case involving digital intelligence may involve multiple devices and terabytes of information. How to parse and filter this data to provide actionable intelligence is key to moving cases forward. This is where the power of analytics is so important.
Modern AI-powered analytics solutions allow investigators to quickly sort through mountains of data to find key insights automatically. Workloads are drastically reduced and agency managers can rest easy knowing that all the digital data is being fully leveraged and securely shared throughout the investigation to obtain critical intelligence. Analysts can merge information from disparate mobile, cloud, computer and CCTV sources to provide teams with a full picture of data insights in a single view.
6. Is the team trained to return actionable intelligence?
Utilizing digital intelligence to its fullest cannot be accomplished unless investigators fully understand what it is, how it works, and how to use it. That takes training. Forward-leaning managers understand that the best investment they can make is in their people. The more they know, the more efficient they can become, and the more knowledge they can share with other team members.
7. How is the agency managing compliance and ensuring the chain of evidence remains secure?
In court, defense attorneys are notorious for trying to poke holes in the chain of evidence to provide an easy out for their clients. Having a DEMS that’s secure is the first step, but that security can only be ensured if there are procedures in place that clearly limit who has access to what data.
Leveraging case management and workflow orchestration tools helps managers enforce standard procedures to ensure that investigations are carried out the right way. These tools also allow managers to audit all the steps that were taken and all the warrants that were necessary to bring the case forward from start to finish and ensure transparency.
8. How is the team collaborating?
By design, law enforcement agencies are hierarchical. The chain of command produces order in a department, but it can also stymie the most important part of the investigation process -- collaboration. When allowed, teams must be able to share information quickly and efficiently. Copying little pieces of data and sharing thumb drives and hard drives -- a common practice in many departments -- is a recipe for disaster. Here again, the right DEMS is critical, but having the right tools to enable collaboration is equally important. A central data and analytics repository is also critical to making the workflow more efficient. Just like physical evidence, data must be managed and tracked. Having the right tools and reference architecture in place to do so is critical.
9. How is information sharing managed?
When allowed, sharing information across departments, agencies and even internationally can be critical to solving crimes and, in many instances, saving lives. Having the right tools and protocols in place to move swiftly when another agency reaches out for help or when investigators need assistance from outside their department is key. Tools with appropriate collaboration capabilities simplify the workflow between forensic operations, investigative operations and courtroom and discovery sharing, allowing forensic agencies to be more proactive and provide better insights during investigations.
10. Is evidence presented to prosecutors in a way that they (and jurors) can easily understand?
Gathering evidence is important, but it is of little value if those prosecuting the case don’t understand what it represents and how the dots in a crime are connected. Data must be presented in a way that is easily absorbed by prosecutors and jurors alike. Visualization and simplification are key. Data points from many sources related to the same person or incident can be correlated and presented in a logical timeline, graph or map that’s easy to understand. Tools that enable the simple creation of such courtroom-ready artifacts are the answer.