eDiscovery Data Collections
	Data collection is perhaps the most technically rigorous and complex of all the e-discovery phases. It involves the extraction of potentially relevant electronically stored information (ESI) from its native source into a separate repository.
		Discuss Objectives
			Discuss the EDRM Model
			Understand the eDiscovery Collection portion of the EDRM Model
			Understand what ESI is and where it can reside.
			Discuss the difference between eDiscovery and Computer Forensics.
			Discuss Best Practices when collecting ESI.
			Discuss indicators of a successful eDiscovery collection.
			Discuss issues during an eDiscovery collection.
			Organizing the data after an eDiscovery collection.

		What is the EDRM Model?
			The Electronic Discovery Reference Model (EDRM) is a framework that outlines standards for the recovery and discovery and of digital data. The EDRM is designed to serve as guidance for gathering and assimilating electronic data during the legal process, including criminal evidence discovery.  We will be using this model to discuss how an eDiscovery project should be handled from start to finish.

		What is the Preservation Phase?
			Consultants work with Legal Counsel and IT Department in providing notifications known as Legal Holds to data custodians.
Legal Holds inform the data custodians of their obligation to preserve data during the eDiscovery process.

		What is the Collection Phase?
			Consultants work with Legal Counsel and IT Department in developing a collection plan.
Part of a successful collection is proper Project Management.
Prior to beginning a collection job, all parties should have an agreed upon list of custodians and the data sources they will be collecting from in order to scope out an adequate project completion timeline.
The decision to perform an eDiscovery Collection versus a Computer Forensics Collection must be made prior to beginning the Collection Phase.

		What is ESI?
			Electronically stored information, for the purpose of the Federal Rules of Civil Procedure is information created, manipulated, communicated, stored, and best utilized in digital form, requiring the use of computer hardware and software.
				What are some examples of ESI?
					Email, Websites, Source Code, Office documents (Word, Excel, Access, PowerPoint), Compressed Archives (ZIP, RAR, TAR), PDF, Text files, Databases.
						- Four slides
				Where can ESI be found?
					PC's, laptops, servers, mobile devices, cloud repositories, virtual machines, removable devices, surveillance equipment, audio recording devices.
						- Four slides
				What are the most important things to consider when conducting eDiscovery collections?
					Chain of Custody and ensuring that the original data is acquired without altering its contents.  Ensuring hash values are obtained to verify the integrity of the data collected at any time during the duration of the case.
						- Four slides
				How does eDiscovery differ from Computer Forensics?
					eDiscovery is focused on Active data files, while Computer Forensics takes a look at all areas of acquired digital media such as Active, Deleted, Slack, and Unallocated Space.
						- Four slides
				How can an eDiscovery case transition into a Computer Forensics case?
					Initially a case might start off as eDiscovery, but after Legal Review, the Legal Team decides to take a deeper dive into the collected media by analyzing Deleted, Slack, and Unallocated Space.  If you have a forensic image of the media, then you will be in a position to do so, however if your initial collection was just Active data, then you will need to go back and recollect the media using forensic imaging tools.  We recommend collecting as a forensic image the first time so as not to have to spend additional funds on recollections IF a Computer Forensic analysis is needed.
						- Four slides
				What are the indicators of a successful collection strategy?
					A collection is deemed successful if all pieces of media have been collected and hash verified with no errors.  Errors during the collection do occur though.  Bad sectors can cause a collection to fail or to partially complete.  Mailbox collections in which users change their passwords during the collection can also cause incomplete collections.  Part of a successful collection process is to validate the collection logs after each piece of media has been acquired.  If the collection logs do NOT indicate they were collected successfully, then a recollection is performed.  Once all pieces of media have been acquired, a Chain of Custody is utilized to document the media devices collected.  When the collected pieces of media are transferred to the Legal Team or Law Enforcement Agency, the individual releasing the media and the individual receiving the media sign the Chain of Custody document.  In summary, the methods used to collect ESI must be repeatable and defensible in a court of law.  They must be able to be replicated by any other analyst using available tools in the Computer Forensics and/or eDiscovery market.
						- Four slides
				What are some issues one might face during the collection process?
					There are several security measures that require additional steps in order to get a proper collection.  Encryption, two-factor authentication, physical damage to the media, and power outages.  Each of these security measures or issues must be handled in a unique manner.  Part of a successful collection strategy is to identify the presence of these security measures prior to beginning a collection.  If during the collection an analyst encounters physical damage or power outages, then their objective is conduct a 'best collection'.  If bad sectors are encountered, then that is a physical limitation that restricts the analyst from making a full forensic image.  In a scenario like this, the bad sectors are ignored and an MD5 hash is conducted on the sectors that were able to be copied over.  You will need to annotate the bad sectors encountered in order to account for the missing data.
						- Four slides
				How can we organize the data collected?
					There are several ways in which you can organize your collected data.  Your case will be assigned a project number and you can either choose to categorize the media by media source type (i.e. PC, Mobile Device, Mailbox Account, Network Share, Server, Cloud Repository, or Virtual Machine.)  However, the best method is by Custodian Name.  Prior to beginning a collection, a Custodian List along with all their data sources should be given to the analysts.  This Custodian List should be utilized to ensure all data sources are collected and verified.  If additional data sources arise for any custodians, then those data sources should be added to that Custodian List.  This method transfers over into the Processing and Review stage of the EDRM Model and allows for the Legal Teams to review the data much more efficiently.
						-Four slides
						

33 slides = 1 minute per slide = 33 minute presentation.
