Digital forensics examiners all confront ethical dilemmas made possible because they use privileged access to information systems and data, and because their services are almost always engaged incident to controversies. Examiners at one time or another will be exposed to trade secrets, threats to national security, information that private parties may pay handsomely for (or for the spoliation thereof), and highly personal information, including diaries, notes, personal photographs, and the like. Evidence found, overlooked, or determined not to exist by an examiner may decide the outcome of a multi-million dollar case, whether someone is imprisoned or set free, or which parent will be awarded custody of a child.

In fact, examiners are ill prepared to solve these dilemmas. The reasons include the lack of industry regulation, a paucity of ethics coverage in training curricula, and that the law applied to this subject matter is not well settled.1 Arguably, what is needed in the digital forensics profession is some combination of “good moral character,”2 an above-average understanding of evolving law, a well-drafted engagement contract, and continuing ethics training. Such a combination might equip the examiner either with the ability to answer some of the questions, or at least to spot the dilemma, so that he or she can seek advice from a mentor or legal counsel.

The profession has, for its part, endeavored to provide examiners with a framework within which the digital forensics examiner must not only recognize, classify, and manage ethical dilemmas, but also respect boundaries and honor obligations. This framework is the code of ethics, and this comment is intended to examine the need for and contours of these codes.3

The Need for Professional Ethics in Digital Forensics
The relatively recent and rapid evolution of computers and information systems has resulted in novel capabilities to store, retrieve, and process information. In just the few years preceding this writing, new fields of expertise, such as “ethical hacking” and cloud forensics4 have emerged, all of which have added to the “huge demand” for highly educated specialists in the discipline of digital forensics.5 Likewise, the capabilities made possible by the evolution of computers and information systems have given rise to novel controversies regarding boundaries and obligations, intellectual property rights, privacy rights, diplomatic relations and military affairs, critical infrastructure, and the public welfare. Although some controversies can (and should) be anticipated and prospectively addressed by contract, the remainder, whether novel or familiar, are to be resolved in civilized societies by the courts of law.6 But both civil and criminal law has failed to keep pace with technological and societal trends catalyzed by technological advances.7 For example, neither statutory language of the Electronic Communications Privacy Act nor its legislative history makes any reference to the Internet.8 And even where the law may seem certain, pursuing a judicial remedy is costly and burdensome. Consequently, certifying organizations have adopted a code of professional ethics to provide examiners with the framework necessary to avoid or mitigate liabilities likely to require judicial remedies or likely to bring disrepute to the organization.9 In this regard, the code of ethics provides articulable principles against which one’s decision-making is objectively measured. Codes of ethics serve other important interests, including presenting an image of prestige and credibility for the organization and the profession,10 eliminating unfair competition,11 and fostering cooperation among professionals.12

One way to define codes of ethics may be to suggest what the code of ethics is not: first and foremost, it should not be regarded as mere aspirational platitudes. And, it is neither an approximation of nor a substitute for the law. Rather, the code of ethics is designed to establish a minimum standard of acceptable conduct for all reasonably foreseeable activities within the profession. Such activities include: representations of one’s skills and expertise; research; interactions with clients, supervisors, government authorities, judicial officers, and attorneys; collection, preservation, and analysis of evidence; testing (i.e., validation of hardware and software tools), consultation (advising); report writing; testifying; mentoring; teaching; and continuing education. Further, as discussed above, cyber forensics involves recognizing, classifying, and managing ethical dilemmas, respecting boundaries, and honoring obligations. In light of the wide range of cyber forensics activities, one other thing to say the code is not is an exhaustive list of prohibited behaviors or of permissible behaviors.

Although codes of ethics maybe somewhat prescriptive, prohibitive, or a combination of both, they are intended to provide guidance for reasonable persons acting in good faith. What this means is that not every proper behavior can feasibly be enumerated (and if every conceivable prohibited behavior was attempted to be enumerated, the improper ones omitted might be construed as permissible loopholes).13 Therefore, codes of ethics typically are purposefully broad and vague.14 This differs significantly from the criminal law, which must be written such that a reasonable person of ordinary intelligence would understand what conduct is prohibited. And, although codes of ethics do not enumerate every possible prohibited act, they often do prescribe proper behavior in hortatory terms, and are otherwise presumptive: Examiners are presumed to possess good moral character15 and de minimus experience and training regarding, among other things: separation of duties; the criminal law applicable to digital forensics investigations; intellectual property law (e.g., trade secrets and copyright), the duty of reasonable care; the duties of loyalty, independence, and confidentiality; and contractual obligations.16

Although the code is not law,17 conduct in violation thereof is likely to harm others, and may expose the examiner to criminal liability, sanctions by a court, damages liabilities in a civil suit, or other adverse consequences. Moreover, conduct or ethical decision-making that clearly falls outside the code of ethics may be the examiner’s ruination, because reputation is the examiner’s most important asset. Thus, no less important than competence is compliance with the code, which in turn demands consistent, informed ethical decision-making.

Ethical Decision Making
As mentioned above, an examiner is uniquely situated by the nature of the work to engage in conduct that, even if not unlawful, is nonetheless tortious, in breach of contract, offensive, “improper,” or unethical. Accordingly, ethical decision-making is dictated by a varying combination of law, ethics, and morals, and the management of ethical issues is the “behavior” component about which legal, moral, and ethical obligations are chiefly concerned. But one cannot manage an issue without first successfully discerning it and classifying it. So, whereas criminal law and contract law endeavor to take the guesswork out of discernment and classification (i.e., prohibited acts are rendered in black and white), ethical problems very often appear in chiaroscuro. For this reason, effective training in professional ethics doesn’t primarily consist of rote memorization of rules, but instead must prepare the examiner in the art of ethical issue spotting. Similarly, an effective code of ethics consists not only of certain static core principles, but also may consist of components that can be adapted over time to keep pace with the law and with professional norms (“ethics”).

“Ethics” is a word derived from the ancient Greek ethikos, meaning “moral, showing moral character,” and has alternatively been defined as “a custom or usage.”18 Modernly, ethics is understood to be “[professional] norms shared by a group on a basis of mutual and usually reciprocal recognition.”19 In order to effectively spot ethical problems, an examiner must therefore be familiar with the law and professional norms governing the cyber forensics discipline, and this familiarity is one of several presumptions incorporated into the code of ethics. With this presumption in mind, ethical decision-making in digital forensics work consists of one or more of the following: 1) honesty; 2) prudence; and 3) compliance with the law and professional norms.

The first of these principles, honesty and truthfulness, is particularly vexing, because ethical decisions cannot reliably and consistently be made without good moral character, and because it is widely believed that the further one is from the adverse consequences of his or her actions, and the greater the reward, the more likely he or she will do the expedient thing.20 Although, research suggests this may be an overly pessimistic view,21 the dishonest examiner cannot be bound by any code of ethics, because the code is adopted primarily through the “honor system,” rather than reward and deterrence. Pervasive dishonesty must be dealt with through policies that are preventive (i.e., barring applicants inclined toward dishonesty prior to entry into the profession) or corrective (removing practitioners who commit acts in violation of the code), and few mechanisms are in place—other than market forces or legal action—to accomplish either. Even if the profession had robust self-regulation, the established models of other professions have been roundly criticized as corrupt or ineffective.22 Therefore, because a code of ethics requires this “good moral character” to have any efficacy, it is considered a prerequisite for every entrant into the profession (and is another presumption incorporated therein).

The second and third principles mentioned above—prudence and compliance with the law and professional norms—are of equal importance to truthfulness and honesty. Prudence does not here mean caution, but means “the ability to govern and discipline oneself by the use of reason.”23 Prudence is regarded as auriga virtutum (the charioteer of the virtues), and has been characterized as the “right reason which . . . directs the acts of justice, fortitude, temperance, and the annexed virtues.”24 Prudence guides these other virtues by setting rule and measure, and would likely be evaluated by the courts against an objective “reasonable person” standard.25 Although prudence usually comes with experience and training, it also is a presumption incorporated into the code of ethics, just as is familiarity with and fealty to the law and professional norms.

Ethics Training for the Profession
Currently, education and training in the digital forensics disciplines is focused primarily on technical competency,26 with much lesser emphasis on the significant legal and ethical challenges confronting examiners. At the time of this writing, at least one academic program does include digital forensics ethics as a separate component.27 Also, much of the informal writing on the topic of ethics is limited to the examiner’s duty to search for exculpatory evidence in addition to the evidence that tends to support the theory of the case asserted by the party who engaged the examiner.28 Therefore, until and unless digital forensics curricula uniformly implement ethics training on par with technical training, and unless new entrants to the profession are required to demonstrate competency in the topic of ethics (such as by written examination), cyber forensics examiners will remain ill-prepared to meet these legal and ethical challenges.29 And this possibility has not gone unnoticed by the courts:

One survey of civil trials estimated that experts appear in 86% of the cases with an average of 3.8 experts per trial. While expert witnesses are appearing in civil cases in increasing numbers, the topic of expert witness ethics and professionalism is largely undeveloped and there are few definitive statements about what exactly the expert witness's ethical obligations are and how they are to handle the subtle as well as the more blatant attempts to influence them . . . . Even where professional associations have established ethical guidelines for conducting investigations, forming opinions, and writing reports, very few explain how the ethical boundaries imposed on judges and lawyers may bear on the performance of their role in the legal system regardless of whether they are employed as a retained forensic expert for one of the parties or as a court-appointed expert.30

Regulation of the Profession
Some of the contemporary informal writing by respected scholars who have considered the codes of ethics in digital forensics suggests that they are inadequate at protecting the integrity of the profession:

The problem with a field like computer forensics is the lack of universally accepted standards that anyone can view and at least have an idea of the level of competency of the expert. Other experts require some sort of professional licensing specific to their field: Certified public accountants, doctors, professional engineers, lawyers[,] etc.[,] where they have had to pass some sort of board certification prior to being allowed to practice. Of course it was not always that way for those professions in the early days, before such boards and licensing bodies were formed. And that is the state of computer forensics today.31

The American Bar Association posits that “investigation and expert testimony in computer forensics and network testing should be based upon the current state of science and technology, best practices in the industry, and knowledge, skills, and education of the expert.”32 Because there are no digital forensics licensing bodies in the United States,33 qualifications are determined by reputational standing, competency tests, fealty to a code of ethics, and membership application screening by certifying organizations. The membership prerequisites designed to screen out unqualified and “unsavory” applicants are often counterparts to the codes of ethics. For example, the International Society of Forensic Computer Examiners (ISFCE) rejects applicants who have a criminal record as defined by the ISFCE for the reason that “An examiner with a criminal record may result in credibility issues in professional settings,” and therefore requires all applicants to submit to a criminal background check. Several states do, however, require digital forensics examiners to be licensed as private investigators.34 The Texas Private Security Bureau, a statutory division of the Department of Public Safety, requires applicants to pay annual fees, tender fingerprint cards, subject to a criminal background check, provide evidence of training and experience, and provide proof of liability insurance.35 And, although most private digital forensics organizations do impose a code of ethics as a condition of membership,36 there is little known about the frequency or efficacy of evangelization or enforcement. Other than the criminal or civil law remedies available in limited circumstances, the only regulatory enforcement mechanisms for regulation of the profession are “loss of reputation and business.”37 In contrast, the legal profession is regulated by states’ supreme courts, most of which have adopted the ABA model rules.38 And, although there has long been criticism of the self-regulation model,39 lawyers are generally cognizant of attorney regulation, are required to take ethics continuing education annually, and most were required to pass a course on professional responsibility in law school,40 and to take the Multistate Professional Responsibility Examination.41

Read about the legal issues surrounding Professional Ethics in the Digital Forensics Discipline in part two of this article appearing in the next issue of DFI News.


Sean Harrington is a cyber security policy analyst and information security risk assessor in the banking industry, as well as a digital forensics examiner in private practice. He is a graduate with honors from Taft Law School, and holds the CCFP, MCSE, CISSP, CHFI, and CSOXP certifications. Harrington has served on the board of the Minnesota Chapter of the High Technology Crime Investigation Association, is a current member of InfraGard, the Financial Services Roundtable’s legislative and regulatory working groups, FS-ISAC, and is a council member of the Minnesota State Bar Association’s Computer & Technology Law Section. Harrington teaches computer forensics for Century College in Minnesota, and recently contributed a chapter on the Code of Ethics for the forthcoming Official (ISC)2® Guide to the Cyber Forensics Certified Professional CBK®, and is an instructor for the new CCFP certification.