Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
Cyber Forensics and Digital Evidence: Process and Admissibility
Updated 11 October 2026 · Fact-checked
Cyber forensics is the scientific process of identifying, preserving, collecting, analysing and reporting digital evidence so it can be used in court. Electronic records are admissible only if the legal conditions are met. Under the Bharatiya Sakshya Adhiniyam, 2023, this means a certificate under Section 63 (earlier Section 65B of the Evidence Act, 1872).
Understand Cyber Forensics and Digital Evidence
Cyber forensics (digital forensics) is the application of scientific methods to find, secure and examine data on computers, phones, servers, cloud accounts and networks. The goal is evidence that a court will accept. It is used in hacking, data theft, online fraud, insider misuse and employee misconduct.
The process follows a fixed order. Identification finds the devices and data sources. Preservation stops the data from changing: you isolate the device and make a forensic image (a bit-by-bit copy) and work on the copy, never the original. Collection gathers the data, including volatile data such as RAM. Analysis recovers deleted files, logs and timelines. Documentation and reporting records every step. Presentation puts the findings before the court or authority. Different books name the stages slightly differently, so learn the logic, not just the labels.
Two ideas protect the value of evidence. Chain of custody is the written record of who held the evidence, when, where and why, from seizure to court. Hash value (for example, a checksum generated by an algorithm such as SHA-256) is a digital fingerprint. If the hash of the copy matches the hash of the original, the copy is unaltered. A broken chain or mismatched hash weakens the evidence.
Legally, an electronic record is treated as a document. The Bharatiya Sakshya Adhiniyam, 2023 (BSA) replaced the Indian Evidence Act, 1872. Its Section 63 carries forward the rule of the old Section 65B: an electronic record can be proved by a computer output only if the conditions are met and a certificate accompanies it. The BSA also prescribes a certificate format in a Schedule, to be signed by the person in charge of the device and by an expert. Under the old law, the Supreme Court in Anvar P.V. v. P.K. Basheer held that this certificate is mandatory for secondary electronic evidence. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal reaffirmed it. Where you produce the original device itself in court, no certificate is needed.
Investigation agencies matter too. The police investigate cyber offences under the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) and the IT Act, 2000. Government forensic laboratories and the Examiner of Electronic Evidence assist courts with expert opinion. CERT-In handles incident response and coordination. Companies often run an internal forensic review first, and a CS must know that such a review must preserve evidence properly if a complaint will follow.
Key rules to remember
- Forensic process sequence
- Identification → Preservation → Collection → Analysis → Documentation/Reporting → Presentation
- Learn this order. Preservation always comes before analysis, and analysis is done on the image, not the original.
- Admissibility rule for electronic records
- Electronic record as secondary evidence = Section 63 BSA conditions + certificate
- Section 63 BSA corresponds to Section 65B of the Evidence Act, 1872. Original device produced in court needs no certificate.
- Integrity check
- Hash(original) = Hash(image) ⇒ copy is unaltered
- A mismatch means the data changed and its reliability can be challenged.
- Chain of custody
- Seizure → Sealing → Labelling → Transfer log → Storage → Court
- Every handover is recorded with date, time, name and purpose.
- Certificate signatories
- Certificate signed by person in charge of the device/management and by an expert
- The BSA gives a prescribed format in its Schedule. Check the format when drafting.
- Electronic record as document
- Electronic record = document for purposes of evidence
- This lets electronic records be proved like documents, under BSA conditions.
How to solve Cyber Forensics and Digital Evidence questions
Use this method for any case-based question on cyber forensics or digital evidence. Keep the provision, analysis and conclusion structure.
- 1Read the facts and list the digital sources: laptop, server, phone, email, cloud, logs, CCTV.
- 2Identify what is asked: forensic process, admissibility, or the role of an agency.
- 3State the rule: the forensic stages, or the Section 63 BSA conditions and the certificate (and its old equivalent, Section 65B).
- 4Apply it to the facts: was the device preserved, imaged, hashed, and the custody recorded? Who can sign the certificate?
- 5Spot the defect or strength: missing certificate, no hash, broken chain, original altered, wrong person signing.
- 6Add practical points: engage a qualified forensic expert, preserve logs, report to police or CERT-In as needed, and draft the certificate.
- 7Conclude clearly: admissible, inadmissible, or admissible if the certificate is produced, with a one-line reason.
Quickest way: Process, Proof, Person
When to use it: Use when time is short and the question mixes forensics steps with admissibility.
- Process: write the six stages in order in one line, and tick which ones the facts cover.
- Proof: name Section 63 BSA, the certificate, and the original-versus-copy distinction.
- Person: name who acts, such as the expert, the person in charge, the police or CERT-In.
- Finish with a one-sentence conclusion tied to the facts.
Common mistakes in Cyber Forensics and Digital Evidence
Citing only Section 65B of the Evidence Act, 1872.
Most notes and case law were written under the old Act.
Fix: Write Section 63 of the BSA, 2023 first and mention that it corresponds to the old Section 65B.
Saying a certificate is always required for electronic evidence.
Students memorise the rule without its limit.
Fix: A certificate is needed for secondary evidence such as printouts or copies. Producing the original device in court does not need one.
Analysing the original device directly.
It seems faster and students forget data can change on use.
Fix: State that you make a forensic image, verify the hash, and analyse only the image.
Ignoring chain of custody.
Students focus on technical analysis and treat custody as paperwork.
Fix: Always mention the custody log. A gap lets the other side challenge the evidence.
Mixing up the roles of CERT-In, police and forensic labs.
All three appear in cyber incident answers.
Fix: Police investigate offences, labs and experts examine the evidence, and CERT-In coordinates incident response and advisories.
Giving a conclusion without applying the facts.
Students write theory and stop.
Fix: Link each rule to a specific fact in the question, then conclude.
Worked examples
Example 1
Sharma Textiles Pvt. Ltd. suspects its finance manager of siphoning funds through email. The IT head prints some emails and submits them to the police with a covering letter. No other document is given. Advise on admissibility of these printouts.
Show the solution
- Provision: an electronic record, such as an email, produced as a printout is secondary evidence of the record. Under Section 63 of the BSA, 2023 (earlier Section 65B of the Evidence Act), it is admissible only with the prescribed certificate.
- Analysis: the company gave only printouts and a covering letter. No certificate was given identifying the record, describing how it was produced, and confirming the computer was working properly.
- The Supreme Court in Anvar P.V. v. P.K. Basheer held that the certificate is mandatory for such evidence.
- Practical points: the IT head, as the person in charge, and an expert should sign the certificate in the prescribed format. The company should also preserve the mail server and logs, and take a hash-verified image.
- Conclusion: the printouts alone are inadmissible. They become admissible once the Section 63 certificate is furnished.
Answer: The printouts are not admissible without the Section 63 BSA certificate. The company should prepare the certificate, signed as required, and preserve the original server data.
Example 2
A data breach occurs at Kaveri Fintech Ltd. Explain the forensic steps the company should follow before handing the matter to the police.
Show the solution
- Identification: find affected systems, servers, user accounts and logs that may hold evidence.
- Preservation: isolate the affected systems to stop further changes. Capture volatile data first, then make forensic images and record hash values.
- Collection: gather logs, disk images, emails and access records. Maintain a chain of custody log for each item.
- Analysis: a qualified forensic expert examines the images, not the originals, to trace the entry point, user actions and data taken.
- Documentation: record every step, tool and finding in a report.
- Reporting and presentation: report the incident to CERT-In as required, file a complaint with the police, hand over the evidence with the custody record, and prepare the Section 63 BSA certificate for the electronic records.
- Conclusion: following this order keeps the evidence reliable and admissible.
Answer: Identify, preserve (image and hash), collect with chain of custody, analyse the copy, document, then report to CERT-In and the police with a Section 63 BSA certificate.
Exam tips
- Quote Section 63 BSA, 2023 and mention the old Section 65B. Examiners reward the updated law.
- Use a short list of the forensic stages in order, then apply each to the facts. Do not just list them.
- Mention hash value and chain of custody in every forensic answer. They are the usual marking points.
- For drafting-type questions, set out who signs the certificate and what it must state.
- Name the agencies correctly: police, forensic laboratory or expert, and CERT-In. Do not blur their roles.
Practice questions from Cyber Security
- A Mumbai-based fintech company discovers that an attacker has gained unauthorised access to its customer database through a compromised serv…
- As part of cyber security governance, a listed company's board wants a single accountable executive to design the information security progr…
- Which statement about the liability of an 'intermediary' under the IT Act, 2000 is correct?
- Under the IT Act, 2000, which of the following is the legal function of a digital signature certificate issued by a Certifying Authority?
- A forensic examiner must collect evidence from a running server that is suspected to be compromised. Considering the order of volatility, wh…
Cyber Forensics and Digital Evidence in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Forensics and Digital Evidence: frequently asked questions
What are the stages of cyber forensics?
The usual stages are identification, preservation, collection, analysis, documentation and reporting, and presentation in court. Some books merge or rename stages. Keep the order and the logic, with preservation before analysis.
Is Section 65B still relevant after the Bharatiya Sakshya Adhiniyam?
The BSA, 2023 replaced the Evidence Act, 1872, and Section 63 of the BSA carries forward the rule of Section 65B. Write Section 63 as the current provision and refer to Section 65B when discussing earlier case law.
When is a certificate for electronic evidence not needed?
A certificate is not needed when you produce the original device itself in court as primary evidence. It is needed when you rely on copies or printouts as secondary evidence.
What is chain of custody?
It is the documented record of everyone who handled the evidence, with date, time and purpose, from seizure to court. It helps prove the evidence was not tampered with.