{"id":{"repo_id":"emich","oai_identifier":"oai:commons.emich.edu:theses-2673"},"canonical_url":"https://search.dev.ndltd.org/etd/emich/oai:commons.emich.edu:theses-2673","repository":{"repo_id":"emich","name":"Eastern Michigan University","base_url":"https://commons.emich.edu/do/oai/"},"display":{"title":"Digital evidence in cybersecurity: Legal constraints and technical hurdles","abstract":"<p>The increasing use of digital technologies such as Internet of Things devices, cloud computing, and networked information systems has made digital evidence essential to modern cybersecurity investigations. Digital evidence supports the reconstruction of cyber incidents, identification of responsible parties, and legal proceedings. However, its collection and preservation pose substantial technical and legal challenges. Rapid technological change, strong encryption, data volatility, cloud-based and distributed storage, and variations in jurisdictional privacy and evidentiary laws complicate the timely, reliable, and legally admissible acquisition of digital evidence. This study addresses how investigators can effectively collect and preserve digital evidence while maintaining data integrity, legal compliance, and respect for individual privacy rights. The research examines three questions: the technical and legal challenges affecting digital evidence collection, the influence of jurisdictional differences and privacy regulations on admissibility, and strategies that enhance the reliability and legal defensibility of digital evidence. The study aims to integrate technical forensic practices with legal requirements. A qualitative approach is employed, drawing on an extensive review of academic literature, legal frameworks, case law, and established digital forensic standards. Technical methods for evidence acquisition and preservation are analyzed alongside legal principles governing privacy, jurisdiction, chain of custody, and admissibility. The findings show that encryption, data volatility,</p>","abstract_html":"&lt;p&gt;The increasing use of digital technologies such as Internet of Things devices, cloud computing, and networked information systems has made digital evidence essential to modern cybersecurity investigations. Digital evidence supports the reconstruction of cyber incidents, identification of responsible parties, and legal proceedings. However, its collection and preservation pose substantial technical and legal challenges. Rapid technological change, strong encryption, data volatility, cloud-based and distributed storage, and variations in jurisdictional privacy and evidentiary laws complicate the timely, reliable, and legally admissible acquisition of digital evidence. This study addresses how investigators can effectively collect and preserve digital evidence while maintaining data integrity, legal compliance, and respect for individual privacy rights. The research examines three questions: the technical and legal challenges affecting digital evidence collection, the influence of jurisdictional differences and privacy regulations on admissibility, and strategies that enhance the reliability and legal defensibility of digital evidence. The study aims to integrate technical forensic practices with legal requirements. A qualitative approach is employed, drawing on an extensive review of academic literature, legal frameworks, case law, and established digital forensic standards. Technical methods for evidence acquisition and preservation are analyzed alongside legal principles governing privacy, jurisdiction, chain of custody, and admissibility. The findings show that encryption, data volatility,&lt;/p&gt;","abstract_has_math":false,"creators":["Butler, Steffany"],"institution":null,"degree_name":"Master of Science (MS)","degree_level":"Open Access Thesis","degree_discipline":"Information Security and Applied Computing","degree_department":null,"school":null,"contributors":["Rachel Ledesma-Kinsella, MS","Munther Abualkibash, PhD"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-01-01T08:00:00Z","date_published":"2025-01-01T08:00:00Z","updated_at":"2026-07-24T02:17:53Z","subjects":["Computer Sciences","Information Security"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://commons.emich.edu/theses/1342","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Rachel Ledesma-Kinsella, MS","Munther Abualkibash, PhD"]},{"key":"dc:creator","label":"Author","values":["Butler, Steffany"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2026-06-22T07:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Information Security and Applied Computing"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Open Access Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MS)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Computer Sciences","Information Security"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://commons.emich.edu/theses/1342"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>The increasing use of digital technologies such as Internet of Things devices, cloud computing, and networked information systems has made digital evidence essential to modern cybersecurity investigations. Digital evidence supports the reconstruction of cyber incidents, identification of responsible parties, and legal proceedings. However, its collection and preservation pose substantial technical and legal challenges. Rapid technological change, strong encryption, data volatility, cloud-based and distributed storage, and variations in jurisdictional privacy and evidentiary laws complicate the timely, reliable, and legally admissible acquisition of digital evidence. This study addresses how investigators can effectively collect and preserve digital evidence while maintaining data integrity, legal compliance, and respect for individual privacy rights. The research examines three questions: the technical and legal challenges affecting digital evidence collection, the influence of jurisdictional differences and privacy regulations on admissibility, and strategies that enhance the reliability and legal defensibility of digital evidence. The study aims to integrate technical forensic practices with legal requirements. A qualitative approach is employed, drawing on an extensive review of academic literature, legal frameworks, case law, and established digital forensic standards. Technical methods for evidence acquisition and preservation are analyzed alongside legal principles governing privacy, jurisdiction, chain of custody, and admissibility. The findings show that encryption, data volatility,</p>"]},{"key":"dc:title","label":"Title","values":["Digital evidence in cybersecurity: Legal constraints and technical hurdles"]}]}],"canonical_facts":{"dc:contributor":["Rachel Ledesma-Kinsella, MS","Munther Abualkibash, PhD"],"dc:creator":["Butler, Steffany"],"dc:date.available":["2026-06-22T07:00:00Z"],"dc:description.abstract":["<p>The increasing use of digital technologies such as Internet of Things devices, cloud computing, and networked information systems has made digital evidence essential to modern cybersecurity investigations. Digital evidence supports the reconstruction of cyber incidents, identification of responsible parties, and legal proceedings. However, its collection and preservation pose substantial technical and legal challenges. Rapid technological change, strong encryption, data volatility, cloud-based and distributed storage, and variations in jurisdictional privacy and evidentiary laws complicate the timely, reliable, and legally admissible acquisition of digital evidence. This study addresses how investigators can effectively collect and preserve digital evidence while maintaining data integrity, legal compliance, and respect for individual privacy rights. The research examines three questions: the technical and legal challenges affecting digital evidence collection, the influence of jurisdictional differences and privacy regulations on admissibility, and strategies that enhance the reliability and legal defensibility of digital evidence. The study aims to integrate technical forensic practices with legal requirements. A qualitative approach is employed, drawing on an extensive review of academic literature, legal frameworks, case law, and established digital forensic standards. Technical methods for evidence acquisition and preservation are analyzed alongside legal principles governing privacy, jurisdiction, chain of custody, and admissibility. The findings show that encryption, data volatility,</p>"],"dc:identifier":["https://commons.emich.edu/theses/1342"],"dc:subject":["Computer Sciences","Information Security"],"dc:title":["Digital evidence in cybersecurity: Legal constraints and technical hurdles"],"thesis:degree_discipline":["Information Security and Applied Computing"],"thesis:degree_level":["Open Access Thesis"],"thesis:degree_name":["Master of Science (MS)"]},"updated_at":"2026-07-24T02:17:53Z"}