1
00:00:06,440 --> 00:00:08,130
- In this lesson, 21.3,

2
00:00:08,130 --> 00:00:10,980
we're gonna focus in on evidence handling.

3
00:00:10,980 --> 00:00:13,950
Now cyber-related
investigations can be triggered

4
00:00:13,950 --> 00:00:15,660
by a whole variety of incidents.

5
00:00:15,660 --> 00:00:16,950
Right, there could be an intrusion,

6
00:00:16,950 --> 00:00:20,820
there could be insider activity,
there could be extortion.

7
00:00:20,820 --> 00:00:25,470
And if there's an incident
that leads to an investigation,

8
00:00:25,470 --> 00:00:28,110
well, we're gonna have
to collect evidence.

9
00:00:28,110 --> 00:00:30,570
Now, there are three
types of investigations.

10
00:00:30,570 --> 00:00:33,480
There's criminal, there's
civil, and there's internal,

11
00:00:33,480 --> 00:00:35,760
also referred to as administrative.

12
00:00:35,760 --> 00:00:37,860
And here's the thing
you wanna keep in mind.

13
00:00:37,860 --> 00:00:41,070
In practice, it's really
difficult for organizations

14
00:00:41,070 --> 00:00:44,700
or for responders to identify the type of

15
00:00:44,700 --> 00:00:47,250
and the impact of a cyber incident

16
00:00:47,250 --> 00:00:50,310
until they've carried
out an investigation.

17
00:00:50,310 --> 00:00:52,980
Now evidence collection is the first step

18
00:00:52,980 --> 00:00:55,650
in an investigation, and
it's absolutely critical

19
00:00:55,650 --> 00:00:58,140
that first responders are knowledgeable

20
00:00:58,140 --> 00:01:02,130
about forensically-sound
evidence collection and handling,

21
00:01:02,130 --> 00:01:04,590
so they don't compromise an investigation.

22
00:01:04,590 --> 00:01:08,070
And there's a good chance
that a security practitioner

23
00:01:08,070 --> 00:01:12,000
or an IT person will
be the first responder.

24
00:01:12,000 --> 00:01:14,940
You'll be the one that will
be collecting evidence.

25
00:01:14,940 --> 00:01:18,360
Later on, you'll bring in
forensic experts if necessary,

26
00:01:18,360 --> 00:01:20,040
but you'll be that first responder,

27
00:01:20,040 --> 00:01:22,320
so you really wanna be knowledgeable

28
00:01:22,320 --> 00:01:25,053
about forensically-sound
evidence collection.

29
00:01:27,720 --> 00:01:32,100
So digital evidence is any
information or data of value

30
00:01:32,100 --> 00:01:35,430
to an investigation that's
stored on, received by,

31
00:01:35,430 --> 00:01:39,240
or transmitted by an
electronic or digital device.

32
00:01:39,240 --> 00:01:41,490
Now there are two types of evidence,

33
00:01:41,490 --> 00:01:44,370
direct evidence and
circumstantial evidence.

34
00:01:44,370 --> 00:01:47,490
Direct evidence supports the
truth of an assertion directly,

35
00:01:47,490 --> 00:01:50,790
you don't need any additional
evidence or inference,

36
00:01:50,790 --> 00:01:53,670
where circumstantial
evidence relies on inference

37
00:01:53,670 --> 00:01:56,430
to connect it to conclusion of fact.

38
00:01:56,430 --> 00:01:58,350
So in the physical world, an example

39
00:01:58,350 --> 00:02:01,050
of circumstantial evidence
would be a fingerprint

40
00:02:01,050 --> 00:02:02,373
at the scene of a crime.

41
00:02:05,177 --> 00:02:08,040
Now eDiscovery, also called
electronic discovery,

42
00:02:08,040 --> 00:02:11,400
actually refers to the
process in which digital data

43
00:02:11,400 --> 00:02:15,420
is sought, located, secured,
and searched with the intent

44
00:02:15,420 --> 00:02:19,323
of using it as evidence in
a civil or a criminal case.

45
00:02:21,000 --> 00:02:25,470
Now a legal hold is an order
that suspends the modification,

46
00:02:25,470 --> 00:02:29,550
deletion, or destruction
of any records or media.

47
00:02:29,550 --> 00:02:32,730
So if something happened,
right, there may be a legal hold

48
00:02:32,730 --> 00:02:37,020
that's placed, you know,
around a body of information

49
00:02:37,020 --> 00:02:40,230
and systems that say you
can't make any changes

50
00:02:40,230 --> 00:02:42,060
to this, right, 'cause we wanna ensure

51
00:02:42,060 --> 00:02:45,930
that we don't have any
destruction of records or media.

52
00:02:45,930 --> 00:02:47,940
That legal hold really is issued

53
00:02:47,940 --> 00:02:50,520
to avoid evidence spoilation.

54
00:02:50,520 --> 00:02:54,030
Evidence spoilation being the
intentional, the reckless,

55
00:02:54,030 --> 00:02:58,050
or the negligent withholding,
hiding, altering, fabricating,

56
00:02:58,050 --> 00:03:00,123
or destroying of evidence.

57
00:03:00,123 --> 00:03:02,730
Now, the only people you're
ever gonna hear use the term,

58
00:03:02,730 --> 00:03:04,710
eDiscovery, are attorneys,

59
00:03:04,710 --> 00:03:06,453
but it might show up in your exam.

60
00:03:07,800 --> 00:03:09,990
So let's talk about evidence collection.

61
00:03:09,990 --> 00:03:12,720
Collection of digital evidence
is really the first step

62
00:03:12,720 --> 00:03:15,090
in a forensic investigation.

63
00:03:15,090 --> 00:03:16,950
Now evidence collection
is gonna be governed

64
00:03:16,950 --> 00:03:20,220
by two main rules, the
admissibility of the evidence

65
00:03:20,220 --> 00:03:21,750
and the weight of the evidence.

66
00:03:21,750 --> 00:03:23,490
Admissibility of evidence refers

67
00:03:23,490 --> 00:03:25,470
to whether the evidence
can actually be used

68
00:03:25,470 --> 00:03:27,900
in a court of law, and
the weight of evidence

69
00:03:27,900 --> 00:03:30,120
is all about the quality
and the completeness

70
00:03:30,120 --> 00:03:31,200
of the evidence.

71
00:03:31,200 --> 00:03:34,230
And invariably, there's a lot of tension

72
00:03:34,230 --> 00:03:37,950
between the response,
the find and fix teams,

73
00:03:37,950 --> 00:03:39,840
and the evidence collectors,

74
00:03:39,840 --> 00:03:41,460
'cause you think back to earlier lessons,

75
00:03:41,460 --> 00:03:43,680
we talked about incident
and incident response,

76
00:03:43,680 --> 00:03:46,260
and we get in and we detect the incident,

77
00:03:46,260 --> 00:03:47,580
and we're confirming the incident,

78
00:03:47,580 --> 00:03:49,320
we're containing the incident,

79
00:03:49,320 --> 00:03:50,700
we're eradicating the incident,

80
00:03:50,700 --> 00:03:52,740
we're recovering from the incident,

81
00:03:52,740 --> 00:03:55,290
but if we have to do an investigation

82
00:03:55,290 --> 00:03:56,880
and we need to collect evidence,

83
00:03:56,880 --> 00:03:59,100
we have to do like,
whoa, whoa, whoa, right?

84
00:03:59,100 --> 00:04:01,590
We have to stop really
early in that process

85
00:04:01,590 --> 00:04:04,410
so that we can collect
the evidence, you know,

86
00:04:04,410 --> 00:04:07,413
before we go through some
of the higher-level phases.

87
00:04:09,780 --> 00:04:12,510
So, if you are going to collect evidence,

88
00:04:12,510 --> 00:04:14,850
I want you to always assume
evidence will be used

89
00:04:14,850 --> 00:04:17,520
in a court of law and act accordingly.

90
00:04:17,520 --> 00:04:19,320
Now the chance that it
will actually be used

91
00:04:19,320 --> 00:04:21,960
in a court of law is relatively small.

92
00:04:21,960 --> 00:04:25,290
But here's the thing, if you
don't act accordingly, right,

93
00:04:25,290 --> 00:04:28,350
and you don't follow
evidence collection rules,

94
00:04:28,350 --> 00:04:30,570
if it needs to be in a court of law

95
00:04:30,570 --> 00:04:31,950
and you haven't done it right,

96
00:04:31,950 --> 00:04:34,023
it's gonna get thrown out and that's bad.

97
00:04:35,190 --> 00:04:37,500
So here, there are
evidence collection rules.

98
00:04:37,500 --> 00:04:39,300
Preservation is key.

99
00:04:39,300 --> 00:04:41,160
You're gonna act in the
order of volatility.

100
00:04:41,160 --> 00:04:43,080
I'll explain what that means in a sec.

101
00:04:43,080 --> 00:04:45,090
You're gonna maintain
an evidentiary chain,

102
00:04:45,090 --> 00:04:48,600
also known as a chain of custody,
for all evidence collected

103
00:04:48,600 --> 00:04:52,050
during the investigation,
and you need to be aware

104
00:04:52,050 --> 00:04:55,110
that evidence may become public record.

105
00:04:55,110 --> 00:04:56,550
And you wanna be very careful

106
00:04:56,550 --> 00:05:00,270
about including any company
confidential information, right,

107
00:05:00,270 --> 00:05:02,730
in your evidence, unless it's necessary.

108
00:05:02,730 --> 00:05:04,890
Obviously, if it's necessary,
you're gonna include it,

109
00:05:04,890 --> 00:05:07,200
but if it's not necessary,
you don't want it

110
00:05:07,200 --> 00:05:09,300
in your evidence because
if it goes to court,

111
00:05:09,300 --> 00:05:10,923
it will become public record.

112
00:05:12,480 --> 00:05:15,540
Now the purpose of
preserving digital evidence

113
00:05:15,540 --> 00:05:19,410
is to maintain its integrity
and its reliability,

114
00:05:19,410 --> 00:05:21,750
ensuring that it can be used effectively

115
00:05:21,750 --> 00:05:24,780
in a legal or an investigative context.

116
00:05:24,780 --> 00:05:27,690
So how are ways that we
could contaminate evidence?

117
00:05:27,690 --> 00:05:30,420
Well, installing or running
any diagnostic tools

118
00:05:30,420 --> 00:05:35,280
or scanning software, removing
files, making any changes

119
00:05:35,280 --> 00:05:38,010
to the system, including
logging a user out,

120
00:05:38,010 --> 00:05:41,700
turning off a device
prior to data acquisition,

121
00:05:41,700 --> 00:05:43,350
or leaving a compromised system

122
00:05:43,350 --> 00:05:46,380
or device unattended or unsecured.

123
00:05:46,380 --> 00:05:48,660
You can see why there's
gonna be tension, right,

124
00:05:48,660 --> 00:05:51,930
between those who wanna
fix the situation quickly

125
00:05:51,930 --> 00:05:53,780
and those who wanna collect evidence.

126
00:05:55,691 --> 00:05:58,080
Now the order of volatility
refers to the acquisition

127
00:05:58,080 --> 00:06:00,720
of evidence before it
disappears, is overwritten,

128
00:06:00,720 --> 00:06:02,610
or it's no longer useful.

129
00:06:02,610 --> 00:06:04,950
And the goal, right,
is to create a snapshot

130
00:06:04,950 --> 00:06:08,280
of the environment as it
existed at the time of,

131
00:06:08,280 --> 00:06:12,390
or as close to, if possible,
of the attack or the incident.

132
00:06:12,390 --> 00:06:14,550
Now there are two types of
data you wanna recognize,

133
00:06:14,550 --> 00:06:17,070
persistent data and volatile data.

134
00:06:17,070 --> 00:06:19,560
Persistent data is data
that does not change,

135
00:06:19,560 --> 00:06:21,660
and it's preserved when
the device is turned off,

136
00:06:21,660 --> 00:06:26,250
so when you unplug, un-power,
or the battery runs out.

137
00:06:26,250 --> 00:06:29,580
Volatile data is data
that's easily degradable

138
00:06:29,580 --> 00:06:34,080
and can be lost, right, when
that device is turned off

139
00:06:34,080 --> 00:06:35,610
or you don't have power anymore

140
00:06:35,610 --> 00:06:37,263
or the battery finally runs out.

141
00:06:39,300 --> 00:06:42,630
So let me give you examples
of the order of volatility.

142
00:06:42,630 --> 00:06:45,420
The first thing we might
collect is memory, right?

143
00:06:45,420 --> 00:06:48,660
Data in memory is the
most volatile, right?

144
00:06:48,660 --> 00:06:51,949
And that includes data that's in the CPU,

145
00:06:51,949 --> 00:06:55,950
registers, caches, and in RAM

146
00:06:55,950 --> 00:06:57,870
'cause we know what's
ever in memory, right,

147
00:06:57,870 --> 00:07:01,620
when we shut our system off or
we run out of battery, right,

148
00:07:01,620 --> 00:07:03,570
it's gone, and we also
know things don't stay

149
00:07:03,570 --> 00:07:04,833
in memory for very long.

150
00:07:05,790 --> 00:07:06,930
Then we have virtual memory.

151
00:07:06,930 --> 00:07:10,470
Virtual memory, also known as
a swap file or a paging file,

152
00:07:10,470 --> 00:07:12,540
it's a file that's
stored on the system disk

153
00:07:12,540 --> 00:07:13,800
that extends the amount of RAM

154
00:07:13,800 --> 00:07:15,480
that's available to a computer.

155
00:07:15,480 --> 00:07:18,120
But again, that can
disappear fairly quickly

156
00:07:18,120 --> 00:07:21,120
because virtual memory is
swapped in and out, right,

157
00:07:21,120 --> 00:07:24,390
as the processor needs
to use that information.

158
00:07:24,390 --> 00:07:26,160
Next would be log files.

159
00:07:26,160 --> 00:07:28,500
The log files are written
by our operating systems,

160
00:07:28,500 --> 00:07:32,970
our applications, our databases,
a whole host of other type

161
00:07:32,970 --> 00:07:35,790
of software and operating
systems and other devices.

162
00:07:35,790 --> 00:07:38,730
We've already talked about
how important log files are.

163
00:07:38,730 --> 00:07:41,370
Now, log files are actually
written to the media,

164
00:07:41,370 --> 00:07:45,330
so they remain even when
there's no more power, right,

165
00:07:45,330 --> 00:07:47,340
either by battery or being plugged in.

166
00:07:47,340 --> 00:07:49,530
But here's the thing
about log files, right,

167
00:07:49,530 --> 00:07:51,360
they are size-limited, right?

168
00:07:51,360 --> 00:07:53,730
We don't let them just
grow endlessly, right?

169
00:07:53,730 --> 00:07:58,260
So they generally are size-limited
and can be overwritten.

170
00:07:58,260 --> 00:08:00,780
And then lastly, we get
to some static data.

171
00:08:00,780 --> 00:08:03,600
Right, now that's data
files that are stored

172
00:08:03,600 --> 00:08:06,990
on a disk drive are considered static,

173
00:08:06,990 --> 00:08:08,610
and they remain there, right?

174
00:08:08,610 --> 00:08:11,340
Until steps are taken to erase them

175
00:08:11,340 --> 00:08:13,560
or until a disk drive fails.

176
00:08:13,560 --> 00:08:15,960
Now this is inclusive of
traditional hard drives,

177
00:08:15,960 --> 00:08:18,690
flash drives, and solid state drives.

178
00:08:18,690 --> 00:08:20,640
So if we think about
this, as just an example,

179
00:08:20,640 --> 00:08:22,350
we were at volatility, right?

180
00:08:22,350 --> 00:08:25,500
If we needed all of this memory,
virtual memory, log files,

181
00:08:25,500 --> 00:08:27,930
and static data, this would be the order

182
00:08:27,930 --> 00:08:31,470
that we wanna collect it in
before it is overwritten,

183
00:08:31,470 --> 00:08:33,960
no longer useful, or disappears.

184
00:08:33,960 --> 00:08:35,610
So when we're thinking
about our evidence, right,

185
00:08:35,610 --> 00:08:36,840
we're gonna think about,
we're gonna make a list

186
00:08:36,840 --> 00:08:39,540
of everything we need, and
then we're gonna order them

187
00:08:39,540 --> 00:08:41,313
in the order of volatility.

188
00:08:42,690 --> 00:08:45,360
Now, an evidentiary chain
or a chain of custody

189
00:08:45,360 --> 00:08:47,220
is a chronological documentation

190
00:08:47,220 --> 00:08:50,520
that records the collection,
the control, the transfer,

191
00:08:50,520 --> 00:08:53,763
the analysis, and the
disposition of evidence.

192
00:08:55,800 --> 00:08:58,710
Why do we need an evidentiary
chain or a chain of custody?

193
00:08:58,710 --> 00:09:01,530
Because the evidentiary
chain documentation,

194
00:09:01,530 --> 00:09:03,720
which is that chronological documentation

195
00:09:03,720 --> 00:09:06,000
that says who collected it, you know,

196
00:09:06,000 --> 00:09:08,010
what everybody did with
it, who controlled it,

197
00:09:08,010 --> 00:09:11,070
when was it transferred,
anything that was done

198
00:09:11,070 --> 00:09:14,880
to analyze it, all of that
has to be in that chain

199
00:09:14,880 --> 00:09:17,520
because it demonstrates trust to the court

200
00:09:17,520 --> 00:09:21,120
that the evidence has not been
subject to any mishandling

201
00:09:21,120 --> 00:09:23,460
or evidence spoilation.

202
00:09:23,460 --> 00:09:25,620
You don't wanna get
evidence that goes to court,

203
00:09:25,620 --> 00:09:28,687
particularly, great evidence,
and then have the judge say,

204
00:09:28,687 --> 00:09:31,560
"Sorry, that evidence,
gotta throw it out," right?

205
00:09:31,560 --> 00:09:33,560
We can't trust it, it's not trustworthy.

206
00:09:35,610 --> 00:09:38,550
Now, in court, witnesses
can be called to testify

207
00:09:38,550 --> 00:09:41,370
by either the defense or the prosecution,

208
00:09:41,370 --> 00:09:43,170
and there are two type of witnesses.

209
00:09:43,170 --> 00:09:46,290
There are factual witnesses
and expert witnesses.

210
00:09:46,290 --> 00:09:49,680
A factual witness is an
individual who's knowledgeable

211
00:09:49,680 --> 00:09:51,120
about the facts of the case

212
00:09:51,120 --> 00:09:54,750
through direct participation
or observation.

213
00:09:54,750 --> 00:09:56,520
Now you might be called, if you were part

214
00:09:56,520 --> 00:09:59,280
of an investigation, to
be a factual witness.

215
00:09:59,280 --> 00:10:01,860
An expert witness is a
person who has knowledge

216
00:10:01,860 --> 00:10:05,490
beyond that of an ordinary
layperson, enabling him or her

217
00:10:05,490 --> 00:10:07,770
to give testimony regarding an issue

218
00:10:07,770 --> 00:10:10,410
that requires expertise to understand.

219
00:10:10,410 --> 00:10:12,240
The experts can also give an opinion.

220
00:10:12,240 --> 00:10:14,520
They don't always have to be fact-based.

221
00:10:14,520 --> 00:10:17,550
If you were involved in a
trial that had witnesses,

222
00:10:17,550 --> 00:10:21,840
you may find that a forensic
expert is called in to testify.

223
00:10:21,840 --> 00:10:25,440
So we have factual witnesses
and expert witnesses.

224
00:10:25,440 --> 00:10:28,260
It's really important that
you have a good understanding

225
00:10:28,260 --> 00:10:31,230
of how to handle evidence
for both the exam

226
00:10:31,230 --> 00:10:33,990
and for your everyday security practice

227
00:10:33,990 --> 00:10:35,730
'cause you never know when
you're gonna be called on

228
00:10:35,730 --> 00:10:36,563
to do that.

229
00:10:38,010 --> 00:10:40,500
That, my friends, brings us
to a three-second challenge.

230
00:10:40,500 --> 00:10:43,400
Five challenge questions, three
seconds each, let's do it.

231
00:10:44,370 --> 00:10:46,590
The process of collecting,
preserving, examining,

232
00:10:46,590 --> 00:10:49,473
analyzing, and presenting evidence.

233
00:10:50,670 --> 00:10:52,140
What is that called?

234
00:10:52,140 --> 00:10:53,673
One, two, three.

235
00:10:54,720 --> 00:10:57,723
That's in the aggregate
referred to as forensics.

236
00:11:00,930 --> 00:11:03,930
The quality and completeness
of the evidence.

237
00:11:03,930 --> 00:11:05,523
One, two, three.

238
00:11:06,600 --> 00:11:08,750
That's gonna be the
weight of the evidence.

239
00:11:10,740 --> 00:11:13,140
Number three, the acquisition of evidence

240
00:11:13,140 --> 00:11:17,463
before it disappears is
overwritten or is no longer useful.

241
00:11:18,360 --> 00:11:19,713
One, two, three.

242
00:11:20,805 --> 00:11:23,310
And that's the order of volatility.

243
00:11:23,310 --> 00:11:27,693
Number four, a document that
establishes evidence integrity.

244
00:11:28,590 --> 00:11:29,973
One, two, three.

245
00:11:31,140 --> 00:11:32,850
That's gonna be your evidentiary chain

246
00:11:32,850 --> 00:11:34,770
or your chain of custody.

247
00:11:34,770 --> 00:11:38,550
And lastly, number five,
intentional, reckless,

248
00:11:38,550 --> 00:11:41,490
or negligent withholding,
hiding, altering,

249
00:11:41,490 --> 00:11:44,910
fabricating, or destroying of evidence.

250
00:11:44,910 --> 00:11:47,190
What's the term we use to describe that?

251
00:11:47,190 --> 00:11:49,200
One, two, three.

252
00:11:49,200 --> 00:11:50,883
That's evidence spoilation.

253
00:11:53,460 --> 00:11:54,810
Let's do a security-in-action,

254
00:11:54,810 --> 00:11:58,200
so we can apply our knowledge
about evidence collection.

255
00:11:58,200 --> 00:11:59,790
The police department was called in

256
00:11:59,790 --> 00:12:03,570
to investigate an IP theft crime.

257
00:12:03,570 --> 00:12:06,960
The IT department claimed
that they had solid evidence

258
00:12:06,960 --> 00:12:10,020
that the criminal had
logged into the system,

259
00:12:10,020 --> 00:12:14,160
downloaded files, and
emailed them to a competitor.

260
00:12:14,160 --> 00:12:17,970
But much to their dismay, the
law enforcement forensic team

261
00:12:17,970 --> 00:12:20,610
declined to use their findings.

262
00:12:20,610 --> 00:12:21,960
So my question to you is,

263
00:12:21,960 --> 00:12:25,500
why would law enforcement not
be able to use the evidence?

264
00:12:25,500 --> 00:12:27,690
Okay, so the police are brought in

265
00:12:27,690 --> 00:12:30,180
to investigate an IP theft crime.

266
00:12:30,180 --> 00:12:34,350
We talked about IP before, IP
being intellectual property.

267
00:12:34,350 --> 00:12:35,850
The IT department said, "Oh man,

268
00:12:35,850 --> 00:12:37,867
we got solid evidence," right?

269
00:12:37,867 --> 00:12:41,190
"We can tell that a criminal
logged into the system,

270
00:12:41,190 --> 00:12:45,330
downloaded files, and then
emailed them to a competitor.

271
00:12:45,330 --> 00:12:47,640
We got 'em dead to rights."

272
00:12:47,640 --> 00:12:49,410
And boy, were they bummed to hear, right?

273
00:12:49,410 --> 00:12:52,140
When law enforcement said, "Hmm, sorry,

274
00:12:52,140 --> 00:12:55,530
we can't use your findings," so why not?

275
00:12:55,530 --> 00:12:56,940
That's my question to you.

276
00:12:56,940 --> 00:12:59,910
Why would law enforcement not
be able to use their evidence?

277
00:12:59,910 --> 00:13:01,740
Go ahead and put me on
pause, jot down some notes,

278
00:13:01,740 --> 00:13:03,633
come back with some possible reasons.

279
00:13:07,020 --> 00:13:10,500
Well, there are several possible
reasons or explanations.

280
00:13:10,500 --> 00:13:13,293
Could be suspicion that the
evidence was contaminated,

281
00:13:14,160 --> 00:13:17,073
it could be suspicion
of evidence spoilation,

282
00:13:18,030 --> 00:13:20,970
there could be fact that
the evidentiary chain

283
00:13:20,970 --> 00:13:25,530
was not maintained and
that the credentials

284
00:13:25,530 --> 00:13:28,800
and the independence of
the evidence collectors

285
00:13:28,800 --> 00:13:30,453
could be called into question.

286
00:13:31,590 --> 00:13:32,850
So it could be, again,

287
00:13:32,850 --> 00:13:35,220
that the evidence might've
been contaminated.

288
00:13:35,220 --> 00:13:37,980
the evidence might've
been spoiled in some way,

289
00:13:37,980 --> 00:13:40,500
and evidentiary chain was not maintained.

290
00:13:40,500 --> 00:13:42,390
And if you don't have a
good evidentiary chain,

291
00:13:42,390 --> 00:13:45,600
you can't prove the two other
ones about contamination

292
00:13:45,600 --> 00:13:49,350
and spoilation, or not
having it, the lack of.

293
00:13:49,350 --> 00:13:51,180
And, you know, there are times

294
00:13:51,180 --> 00:13:54,000
when the credentials and the independence

295
00:13:54,000 --> 00:13:57,060
of the evidence collectors
could be called into question,

296
00:13:57,060 --> 00:13:58,920
so those are some possible reasons

297
00:13:58,920 --> 00:14:02,760
why the police would
decline to use that evidence

298
00:14:02,760 --> 00:14:04,380
or use their findings.

299
00:14:04,380 --> 00:14:06,150
So there you go, you've
got your word cloud.

300
00:14:06,150 --> 00:14:07,530
It's a fairly large one.

301
00:14:07,530 --> 00:14:09,720
You know what to do, make
sure you really can speak

302
00:14:09,720 --> 00:14:13,440
to all of these terms and
concepts before you move on.

303
00:14:13,440 --> 00:14:16,140
Go back to the lesson if you
need to, and when you're ready,

304
00:14:16,140 --> 00:14:18,290
I'll be waiting for
you at the next lesson.
