Tips on testifying in a computer crimes case
WindowSecurity.com - As an IT professional and working network administrator, you may find yourself called upon to testify as a victim or a witness (i.e., a representative of a company whose network is victimized) in a computer-related crime.
Another possibility is that you might someday want to use your technical expertise to become a professional expert witness in computer-related cases. In this article, we examine the basics of testifying in either capacity in a case involving computer crimes, and how you can move into the lucrative field of computer forensics, on either a full- or part-time basis.
Note: The discussion in this article is based on the U.S. legal system. The process of testifying is similar in most jurisdictions, but different rules and procedures may apply in other countries.
Understanding computer crime concepts
As the incidence of intrusions, attacks and release of malicious code (viruses, worms, Trojan horses, etc.) has grown and the real cost to businesses of dealing with these attacks has become more evident, prosecution of computer crime has become more common despite the difficulties involved in identifying and proving the case against an offender, who most often does his dirty work from a remote location.
Before testifying in court, it's important to understand basic legal concepts surrounding network attacks and intrusions. In the U.S. (and many other countries), a case can be brought against attackers and intruders under either criminal or civil law. A civil case, called a tort, is a lawsuit brought by a private citizen (or a corporation, which is an entity under law) against another person or legal entity, seeking some sort of relief (usually this is money, but sometimes it's in the form of an injunction, which is a court order compelling the other person to do or not do something).
A criminal case is an action brought by the government (local, state or federal) on the behalf of society, and seeks to punish the offender. The punishment can be in the form of a fine, jail or imprisonment, or even (in capital cases, which generally only apply to the offense of murder with special circumstances) the death penalty.
The civil and criminal justice systems are completely separate. The same act can be both a crime and a tort, and a hacker could be sued in civil court and prosecuted in criminal court for the same act (the prohibition on double jeopardy applies only to criminal cases). In both civil and criminal cases, rules of evidence apply. These rules are not the same for both



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts