ACPO Principles
Definition
Four principles for digital evidence handling published by the UK's Association of Chief Police Officers (now maintained by the Forensic Science Regulator): no action shall change data; those accessing original data must be competent; an audit trail must exist; and the person in charge is responsible for ensuring these principles apply.
- Number of principles
- Four
- Origin
- UK Association of Chief Police Officers
- Current custodian
- Forensic Science Regulator
- Domain
- Digital evidence handling
- Core rule
- No action shall change data
Common questions
What happens when accessing original digital evidence unavoidably changes data?+
The person doing so must be competent to explain the reasons for that access and the implications of any change, and the change and its justification must be recorded in the audit trail rather than concealed.
How do the ACPO principles relate to chain of custody documentation?+
The audit trail principle requires that every process applied to digital evidence be capable of independent review reaching the same result, which is exactly what the chain of custody record is meant to demonstrate.
Related terms
- Chain of Custody Log
- The continuous record documenting every person who accessed a digital exhibit, every transfer of possession, every examination action, and the hash values...
- Forensic Image
- A bit-for-bit verified copy of a storage medium, created using a write-blocker to prevent modification of the original. The copy is verified...
- Hash Value (Digest)
- A fixed-length output produced by a cryptographic algorithm such as SHA-256 applied to a data set. Any change to the input data,...
- Working Copy
- A copy of an exhibit on which examination work is performed, created from a verified forensic image. The original or master copy...
- Write Blocker
- A hardware or software device interposed between a digital storage medium and the forensic workstation that prevents any write commands from reaching...