<?xml version="1.0" encoding="UTF-8"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-08-15T16:33:17Z</responseDate>
  <request identifier="4549" metadataPrefix="oai_dc" verb="GetRecord">https://drops.dagstuhl.de/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:drops-oai.dagstuhl.de:4549</identifier>
        <datestamp>2024-03-06T10:26:10Z</datestamp>
        <setSpec>ddc:004</setSpec>
        <setSpec>open_access</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>Digital Evidence and Forensic Readiness (Dagstuhl Seminar 14092)</dc:title>
          <dc:creator>Dardick, Glenn S.</dc:creator>
          <dc:creator>Endicott-Popovsky, Barbara</dc:creator>
          <dc:creator>Gladyshev, Pavel</dc:creator>
          <dc:creator>Kemmerich, Thomas</dc:creator>
          <dc:creator>Rudolph, Carsten</dc:creator>
          <dc:subject>digital evidence</dc:subject>
          <dc:subject>forensic readiness</dc:subject>
          <dc:subject>mobile forensic</dc:subject>
          <dc:subject>trusted computing</dc:subject>
          <dc:subject>Cyberlaw</dc:subject>
          <dc:description>The seminar on Digital Evidence and Forensic Readiness provided the space for interdisciplinary discussions on clearly defined critical aspects of engineering issues, evaluation and processes for secure digital evidence and forensic readiness. A large gap exists between the state-of-the-art in IT security and best-practice procedures for digital evidence. Experts from IT and law used this seminar to develop a common view on what exactly can be considered secure and admissible digital evidence. &#13;
&#13;
In addition to  sessions with all participants, a separation of participants for discussing was arranged. The outcome of these working sessions was used in the general discussion to work on a common understanding of the topic.  The results of the seminar will lead to new technological developments as well as to new legal views to this points and to a change of organizational measures using ICT. Finally, various open issues and research topics have been identified. In addition to this report, open research issues will also be published in the form of a manifesto on digital evidence.&#13;
&#13;
One possible definition for Secure Digital Evidence was proposed by Rudolph et al. at the Eighth Annual IFIP WG 11.9 International Conference on Digital Forensics 2012. It states that a data record can be considered secure if it was created authentically by a device for which the following holds:&#13;
&#13;
- The device is physically protected to ensure at least tamper-evidence.&#13;
- The data record is securely bound to the identity and status of the device (including running software and configuration) and to all other relevant parameters (such as time, temperature, location, users involved, etc.)&#13;
- The data record has not been changed after creation.&#13;
&#13;
Digital Evidence according to this definition comprises the measured value  and additional information on the state of the measurement device. This additional information on the state of the measurement device aims to document the operation environment providing evidence that can help lay the foundation for&#13;
admissibility. &#13;
&#13;
This definition provided one basis of discussion at the seminar and was compared to other approaches to forensic readiness. &#13;
&#13;
Additional relevant aspects occur in the forensic readiness of mobile device, cloud computing and services. Such scenarios are already very frequent but will come to full force in the near future. &#13;
&#13;
The interdisciplinary Dagstuhl seminar on digital evidence and forensic readiness has  provided valuable input to the discussion on the future of various types of evidence and it has build the basis for acceptable and sound rules for the assessment of digital evidences. Furthermore, it has established new links between experts from four continents and thus has set the foundations for new interdisciplinary and international co-operations.</dc:description>
          <dc:publisher>Schloss Dagstuhl – Leibniz-Zentrum für Informatik</dc:publisher>
          <dc:contributor>Glenn S. Dardick and Barbara Endicott-Popovsky and Pavel Gladyshev and Thomas Kemmerich and Carsten Rudolph</dc:contributor>
          <dc:date>2014</dc:date>
          <dc:relation>Is Part Of Dagstuhl Reports, Volume 4, Issue 2 (2014)</dc:relation>
          <dc:type>Article</dc:type>
          <dc:type>Text</dc:type>
          <dc:type>doc-type:ResearchArticle</dc:type>
          <dc:type>publishedVersion</dc:type>
          <dc:format>application/pdf</dc:format>
          <dc:identifier>doi:10.4230/DagRep.4.2.150</dc:identifier>
          <dc:identifier>urn:nbn:de:0030-drops-45490</dc:identifier>
          <dc:identifier>https://drops.dagstuhl.de/entities/document/10.4230/DagRep.4.2.150</dc:identifier>
          <dc:language>eng</dc:language>
          <dc:rights>https://creativecommons.org/licenses/by/3.0/legalcode</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
