📖 ABSTRACT/OVERVIEW
Nigerian law enforcement agencies increasingly encounter cybercrime evidence in investigations, yet inconsistent digital forensics methodologies undermine evidence admissibility and prosecution outcomes. This study designed a digital forensics investigation protocol for application by the Economic and Financial Crimes Commission, the Nigeria Police Force Cybercrime Unit, and the Department of State Services. A professional protocol design methodology was employed, drawing on ACPO Good Practice Guide for Digital Evidence, ISO/IEC 27037 digital evidence preservation standards, the Nigerian Evidence Act 2011 provisions on electronic evidence, and structured consultations with 10 EFCC forensic investigators, 6 prosecution lawyers, and 5 digital forensics specialists. Review of current forensic practice confirmed chain-of-custody documentation gaps in 60.0 percent of reviewed case files, inconsistent evidence acquisition methods, and absence of formal forensic tool validation records. The protocol designed covers four phases: evidence identification and seizure, acquisition and preservation, examination and analysis, and reporting. Specific provisions address mobile device forensics (dominant evidence type in Nigerian cybercrime cases), cryptocurrency tracing protocols, cloud evidence acquisition procedures, and expert witness testimony standards. Expert review by nine forensics and legal specialists confirmed the protocol's legal admissibility alignment. The study recommends the protocol be formally adopted through a joint EFCC-NPF-DSS digital forensics coordination committee and that a national digital forensics laboratory capable of ISO 17025 accreditation be established.
Keywords: digital forensics, investigation protocol, EFCC, Nigerian law enforcement, evidence admissibility
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬