When the company Enron declared bankruptcy in Dec 2001, thousands of employees were left unemployed while some executives seemed to benefit from the company’s collapse. The United States The legislature decided to investigate after hearing accusations of corporate wrong doings. Much of Congress’ investigation trusted pc details files as proof. A specialized investigator force began to look for through thousands of Enron employee computer systems using pc ‘forensics’.
The purpose pc ‘forensics’ methods is to look for, preserve and evaluate details on pcs to find potential proof for a trial. Many of the methods investigators use in criminal activity scene research have electronic alternatives, but there are also some unique aspects to pc research.
For example, just starting a pc details file changes the details file — the pc records the date and time it was utilized on the details file itself. If investigators take a pc and then start starting details files, there’s no way to tell for sure that they didn’t modify anything. Lawyers can contest the credibility of the proof when the case goes to court.
Some people say that using electronic details as proof is a bad idea. If it’s easy to modify details, how can it be used as reliable evidence? Many countries allow pc proof in tests, but that could modify if electronic proof shows untrustworthy in future cases.
Computers are getting more powerful, so the field pc ‘forensics’ must constantly progress. In the beginning of computer systems, it was possible for a single investigator to sort through details files because storage capacity was so low. Today, with hard disks capable of holding gb and even terabytes of details, that’s a daunting task. Detectives must discover new ways to look for for proof without devoting too many resources to the process