Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Process, Secure Storage And The First Responder
Articles

Process, Secure Storage And The First Responder

Professor John WalkerBy Professor John WalkerMarch 29, 2019Updated:December 30, 20214 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

I was watching the Babes-in-the Wood Murders last night on TV, involving Nicola Fellows and Karen Hadaway who were murdered by the, then 20-year-old Russell Bishop who was tried, and acquitted in 1987 – sadly, Bishop having been released went on to reoffend again some years later with the abduction, assault, and attempted murder of a 7 year old female in 1990, leaving her for dead at Devils Dyke on the South Downs – it was thankful that the young girl survived and was able to pick Bishop out on an Identity Parade.  

With the introduction of Double-Jeopardy, based on Police Intelligence and the fact they were convinced Bishop was the offender in both cases, this allowed Law Enforcement Agencies to again look at Bishop with a view to the Babes-in-the-Woods Murders of which he had been acquitted – enter the new science of DNA profiling.

Given the Police still had custody of all Babes-in-the Wood case related materials and artifacts, including a Sweat Shirt which had been dumped at a local Railway Station, and had been subsequently linked to Bishop – and given the proximity of material-to-body contact, this was subjected to DNA acquisition and analysis. However, down to Bishops savvy arrogance and cunning, he argued that any BIO DNA traced which had been discovered on the cuff of the garment was the result of transferred cross-contamination in the Lab. His challenge was enough to place doubt on a key artifact which linked him with the garment.  However, the determination of the Investigative Team located other sources of DNA, which provided a successful match between Bishop and the Babes-in-the Wood Murders, resulting in him being found guilty and finally being brought to justice by the underpin and technological achievement in the field of DNA.  

Having watched this case on TV, prompted a consideration of the most basic facets required when handing any form of evidential materials or artifacts – no matter Biological or Logical based, one area of paramount importance is the application of process. As one Barrister from a London Inn commented:

‘The easiest approach to discrediting any form of evidence is to find a gap in process’

Thus, if robust Handling Processes are not applied, conjoined with the documented control of Bag-and-Tag it could be that any evidence, artifact, or observations acquired and made during the First Responder engagement could be rendered inadmissible or indeed worthless.

As if by some spookiness, the TV documentary was aired on the very same day I had an article published in the eForensics Magazine which focused on the importance of the First Responder, and any associated CSIRT (Computer Security Incident Response Team) engagement which introduced the concept of secure and encrypted storage for controlling access to any valuable evidential materials and artifacts, assuring that robust access control and accountability has been fully accommodated. See Fig 1 below:

                              Fig 1 – CSIRT on a Secure Drive

With this approach, if the incumbent First Responding Professional applies the correct set of applicable robust process on each occasion, they engage an assignment, and utilize robust and secure storage facilities, such an approach will accommodate rigidity in and engagement they take up – give a higher degree of a successful outcome, and of course reduce the opportunities for legal challenge.

ISO 17025

Reflecting on the case of Bishop as outlined above, it is also equally important that when handing any for of evidence, or artifacts, again stressing be they BIO or Logical it is absolutely essential that the handling, processing, and storage elements are fully robust and, as far is practically achievable are beyond reproach.  It is here where consultation with, and application of the ISO 17025 will form the basis of understating the requirements of running a robust facility.

  •  Improving the image of the laboratory
  • The data quality and effectiveness are subject to continuous improvements
  • Provides a fundamental basis for other quality systems related to laboratories such as GMP (Good Manufacturing Practices and GLP (Good Laboratory Practices)
  • It is the recognition of testing competence
  • It protects the laboratory’s data integrity in case of legal implications
  • It enables the assessment of relative quality and capability of other accredited laboratories

Conclusion

As a concluding comment – to be wise before the event can pay dividends – to learn that you should have been wise after the fact can both be professional and case adverse!

Professor John Walker

John is the Principle at Shadow-Intelligence (Si), partnering with PALISCOPE, BreachAware and iStorage. He is a Visiting Professor at the School of Science and Technology, Nottingham, Trent University (NTU) and holds the appointment of Editor in Chief for the International Journal of Cyber Forensics and Advanced Threat Investigations (CFATI). For the last decade he has delivered training courses in the Middle, and Far East to Commercial, Industrial, the Financial Services Sector, and Military Agencies, including the UAE, US, Pakistan, Saudi Arabia, Malaysia (KL), Singapore, Argentina, and Sao Paulo

He served in the Royal Air Force 22 years’, specialising in Counterintelligence, working with UK Agencies such as GCHQ/CESG, and others in the fields of SIGINT, COMINT and Satellite Communications, holding appointments such as System ITSO for a CIA SCIF.

In the commercials sectors of IT/Cyber he has worked for/with Logica, Bae, T5, GM, Experian, Betfair, Palace of Westminster, House of Lords/Commons, TSol (Treasury Solicitors) and provided Consultancy to the Saudi Arabian MOD, TRA (Telecommunications Authority (Dubai) and the Military Academy of Malaysia (KL) on SOC, CSIRT, Digital Forensics and OSINT. Within the last 5 years he has focused on Geopolitics, with global expertise around the UAE and Russia, Anti-Terrorist Operations (ATO), Cyber-Warfare, Dezinformatsiya (Disinformation) and Maskirovka (Military Deception).

  • Professor John Walker
    China Threat Recap: A Deeper Insight
  • Professor John Walker
    Missing The Point In The Current Age Of Cyber
  • Professor John Walker
    Part 1: Historic To 2022 – The APT And Logical Threats
  • Professor John Walker
    A Hairs Breadth

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}