Chain of Custody
What is Chain of Custody?
Chain of CustodyThe chronological, documented trail showing every person, location, and action affecting a piece of evidence from seizure through final disposition.
Chain of custody (CoC) preserves the integrity and admissibility of digital and physical evidence. Every transfer is logged with timestamps, identifiers (case number, exhibit ID, hash values), and signatures, while items are stored in tamper-evident containers in access-controlled facilities. Best practice aligns with ISO/IEC 27037, NIST SP 800-86, and ACPO/SWGDE guidance: acquire with write blockers, calculate cryptographic hashes (SHA-256) before and after copying, and maintain duplicate working copies.
The discipline is codified in several standards. RFC 3227 ("Guidelines for Evidence Collection and Archiving," 2002) established the order of volatility — capture RAM, caches, and network state before disk and archival media, since the most transient data is lost first. The ISO/IEC 27037/27041/27042/27043 series covers identification, collection, acquisition, preservation, and analysis, while NIST SP 800-86 details the collect-examine-analyze-report cycle. In U.S. courts, evidence must be authenticated under Federal Rule of Evidence 901 and survive the Daubert reliability standard; a demonstrable, unbroken custody chain is how a party proves the exhibit shown to the jury is the same one seized and was not tampered with. A broken chain — missing entries, mismatched hashes, unsealed containers, or a gap where an item was unaccounted for — lets opposing counsel move to suppress, and can render otherwise decisive evidence inadmissible, collapsing litigation, insurance claims, or regulatory enquiries. Defences include dual-signed handoffs, hardware write blockers, contemporaneous hashing, and cryptographically time-stamped audit logs.
flowchart LR
A[Seizure / Identification] --> B[Acquisition<br/>write blocker + hash]
B --> C{Hash matches?}
C -- No --> X[Integrity failure<br/>evidence at risk]
C -- Yes --> D[Tamper-evident storage<br/>access-controlled]
D --> E[Analysis on<br/>working copy]
E --> F[Every transfer logged:<br/>who / when / why / signature]
F --> G[Court production<br/>FRE 901 authentication]
G --> H[Final disposition /<br/>return or destruction]● Examples
- 01
A signed CoC form tracking a seized laptop from acquisition to courtroom production.
- 02
A SHA-256 hash log demonstrating that a disk image was not altered between collection and analysis.
● Frequently asked questions
What is Chain of Custody?
The chronological, documented trail showing every person, location, and action affecting a piece of evidence from seizure through final disposition. It belongs to the Forensics & IR category of cybersecurity.
What does Chain of Custody mean?
The chronological, documented trail showing every person, location, and action affecting a piece of evidence from seizure through final disposition.
How do you defend against Chain of Custody?
Defences for Chain of Custody typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for Chain of Custody?
Common alternative names include: CoC, Evidence custody chain.