8.1 Forensic Laboratory Accreditation: ISO/IEC 17025 Standards & Hardware/Software Controls

Key Takeaways

  • ISO/IEC 17025:2017 specifies general requirements for testing and calibration competence, establishing laboratory management mandates (Clauses 4 through 8) spanning impartiality, metrological traceability, validation of forensic methods, and proficiency testing.
  • ASCLD/LAB accreditation (transitioned under the ANAB forensic accreditation program) mandates strict adherence to Standard Operating Procedures (SOPs), comprehensive evidence intake custody logs, annual internal audits, and external blind proficiency testing.
  • A defensible forensic lab physical perimeter demands defense-in-depth across three tiers: facility access control, a secure lab entrance featuring mantrap airlocks and multi-factor biometric authentication, and dual-custody evidence storage vaults constructed with slab-to-slab walls.
  • Forensic environmental controls strictly mandate relative humidity maintained between 40% and 50% RH (preventing destructive electrostatic discharge below 40% and condensation/corrosion above 60%), static-dissipative ESD flooring, and clean-agent gaseous fire suppression (FM-200 or Novec 1230) rather than water sprinklers.
  • Forensic workstations require dedicated hardware write-blocking bridges (Tableau/WiebeTech), air-gapped forensic analysis networks isolated from corporate LANs and the public Internet, high-capacity online UPS systems with voltage regulation, and rigorous software validation under NIST CFTT methodologies.
Last updated: September 2026

8.1 Forensic Laboratory Accreditation: ISO/IEC 17025 Standards & Hardware/Software Controls

Quick Answer: A digital forensics laboratory must satisfy rigorous international accreditation standards—primarily ISO/IEC 17025:2017 and ASCLD/LAB (now part of ANAB)—to ensure evidentiary findings withstand legal scrutiny under Federal Rules of Evidence 702 and Daubert/Frye standards. Physical lab security requires defense-in-depth: multi-factor biometric mantraps, 24/7 CCTV surveillance with 90+ day retention, and dual-custody evidence vaults with slab-to-slab walls. Environmental systems must maintain temperature at 68°F–72°F (20°C–22°C) and relative humidity strictly between 40% and 50% RH (preventing ESD below 40% and condensation/corrosion above 60%), backed by clean-agent gaseous fire suppression (FM-200 or Novec 1230). Forensic workstations must operate on an air-gapped forensic network, use verified hardware write-blockers, and undergo structured validation following NIST Computer Forensic Tool Testing (CFTT) methodologies.


Digital Forensic Laboratory Accreditation

Digital forensics laboratories process, preserve, and analyze digital evidence for criminal prosecutions, civil litigation, and corporate incident response. To ensure that analytical methods, evidence handling, and expert conclusions are legally defensible and scientifically sound, forensic laboratories seek formal accreditation and certification from recognized international and national bodies.

+-------------------------------------------------------------------------+
|          FORENSIC ACCREDITATION & STANDARDS GOVERNANCE MATRIX           |
+-------------------------------------------------------------------------+
| Standard / Body | Scope & Mandate                                       |
|-----------------|-------------------------------------------------------|
| **ISO/IEC**     | "General requirements for the competence of testing   |
| **17025:2017**  |  and calibration laboratories." The international     |
|                 |  benchmark for technical competence, management,      |
|                 |  method validation, and metrological traceability.    |
|-----------------|-------------------------------------------------------|
| **ASCLD/LAB**   |  American Society of Crime Laboratory Directors /     |
| **(ANAB)**      |  Laboratory Accreditation Board (now ANSI National    |
|                 |  Accreditation Board - ANAB). Provides forensic-      |
|                 |  specific accreditation based on ISO/IEC 17025.       |
|-----------------|-------------------------------------------------------|
| **ASTM E30**    |  ASTM International Committee E30 on Forensic         |
|                 |  Sciences; develops technical consensus standards for |
|                 |  digital evidence collection, preservation, analysis. |
|-----------------|-------------------------------------------------------|
| **SWGDE**       |  Scientific Working Group on Digital Evidence;        |
|                 |  publishes operational guidelines, peer-reviewed      |
|                 |  procedures, and minimum standards for digital labs.  |
|-----------------|-------------------------------------------------------|
| **NIST CFTT**   |  National Institute of Standards and Technology       |
|                 |  Computer Forensic Tool Testing program; establishes  |
|                 |  empirical testing criteria for forensic utilities.   |
+-------------------------------------------------------------------------+

ISO/IEC 17025:2017 Core Structure

ISO/IEC 17025:2017 is structured into five normative operational clauses that govern laboratory operations from top-level management to bench-level artifact analysis:

  1. Clause 4: General Requirements (Impartiality & Confidentiality)

    • Impartiality (4.1): Laboratory activities must be undertaken impartially, structured and managed to safeguard impartiality. Forensic personnel must be free from commercial, financial, or political pressures that could compromise technical judgment (e.g., performance incentives tied to criminal conviction rates are strictly prohibited).
    • Confidentiality (4.2): The laboratory is legally responsible for the management of all information obtained or created during laboratory activities. Evidence data, case notes, customer information, and reports must be cryptographically protected and disclosed only under legal mandate.
  2. Clause 5: Structural Requirements

    • Defines the laboratory as a legally identifiable entity, defines the organizational chart, identifies the technical management team possessing overall responsibility for operations, and establishes the role of the Quality Manager.
  3. Clause 6: Resource Requirements

    • Personnel (6.2): All personnel who influence laboratory activities must be competent, qualified through education, training, technical knowledge, and documented competency tests before performing casework.
    • Facilities and Environmental Conditions (6.3): Environmental conditions must not adversely affect the validity of results. Access to and use of areas affecting laboratory activities must be controlled.
    • Equipment (6.4): Laboratory equipment (hardware write-blockers, imaging bridges, sanitization stations) must be uniquely tracked, calibrated, maintained, and validated before operational deployment.
    • Metrological Traceability (6.5): Measurement results must be traceable through an unbroken chain of comparisons to national/international standards (e.g., NIST-traceable time sources used to calibrate workstation system clocks).
  4. Clause 7: Process Requirements

    • Review of Requests, Tenders, and Contracts (7.1): Structured evaluation of incoming investigative requests to verify the lab possesses necessary capabilities, legal jurisdiction, and resources.
    • Selection, Verification, and Validation of Methods (7.2): Standardized, validated forensic methodologies must be used. All commercial, open-source, or internally developed tools must undergo formal validation against known ground truth datasets prior to active casework.
    • Handling of Test or Calibration Items (7.4): Complete procedures for the transportation, receipt, handling, protection, storage, retention, and disposal/return of digital evidence, including comprehensive Chain of Custody tracking.
    • Technical Records (7.5): Contemporaneous case documentation. Case notes, tool command lines, script parameters, error outputs, and hex offsets must be recorded at the time work is performed, enabling another competent examiner to replicate the analysis exactly.
    • Evaluation of Measurement Uncertainty (7.6): Systematic evaluation of potential uncertainty (e.g., file timestamp resolutions across FAT, NTFS, and APFS, or clock drift on seized hardware).
  5. Clause 8: Management System Requirements

    • Establishes policies for document control, control of records, corrective action requests (CARs), internal audits, and annual management review meetings.

ASCLD/LAB and the ANAB Forensic Accreditation Program

Historically, the American Society of Crime Laboratory Directors / Laboratory Accreditation Board (ASCLD/LAB) was the dominant accreditation entity for forensic laboratories in North America. In 2016, ASCLD/LAB merged into the ANSI National Accreditation Board (ANAB). Today, digital evidence laboratories achieve accreditation under the ANAB ISO/IEC 17025 Forensic Science Testing and Calibration Laboratories program.

Key ANAB supplemental requirements for digital forensics include:

  • Standard Operating Procedures (SOPs): Detailed, version-controlled written procedures covering every routine task, including evidence intake, hash verification, bit-stream imaging, memory dump extraction, and forensic reporting.
  • Annual Proficiency Testing: Examiners must participate in annual external proficiency testing administered by approved third-party providers (such as Collaborative Testing Services - CTS). Tests provide simulated digital evidence with hidden artifacts; examiners must submit formal reports without prior knowledge of the ground truth.
  • Blind Testing & Competency Exams: New examiners must pass an exhaustive competency test before handling active evidence, followed by periodic internal blind tests where test items are submitted as routine casework without examiner foreknowledge.
  • Corrective and Preventive Action (CAPA): Formal protocols triggered when analytical errors, software failures, or chain of custody breaches occur. CAPA demands root-cause analysis, containment of affected cases, corrective action implementation, and follow-up audit verification.

Physical Security Perimeter & Defense-in-Depth

A digital forensics laboratory handles sensitive evidentiary media, classified corporate records, and contraband. Physical security must follow the principle of defense-in-depth, utilizing multiple nested, concentric rings of security controls.

+-------------------------------------------------------------------------+
|               CONCENTRIC LAB PHYSICAL SECURITY PERIMETERS               |
+-------------------------------------------------------------------------+
| Security Ring   | Controls & Physical Implementations                   |
|-----------------|-------------------------------------------------------|
| **Layer 1:**    | • Armed security desk & building access gates         |
| **Facility**    | • Government photo ID verification                    |
| **Perimeter**   | • Electronic visitor management system & visitor badge|
|                 | • Continuous employee escort policy                   |
|-----------------|-------------------------------------------------------|
| **Layer 2:**    | • Interlocking mantrap / airlock vestibule            |
| **Forensic Lab**| • Dual-factor authentication (RFID badge + biometric) |
| **Entrance**    | • Anti-tailgating / anti-piggybacking turnstiles      |
|                 | • Contemporaneous electronic ingress/egress logging   |
|-----------------|-------------------------------------------------------|
| **Layer 3:**    | • Slab-to-slab reinforced concrete walls              |
| **Secure Vault**| • Solid steel reinforced doors with heavy deadbolts   |
| **& Lockers**   | • Dual-custody key / combination locks                |
|                 | • Class 5 fire-rated evidence safes                   |
|                 | • Dedicated Evidence Custodian control strictly       |
+-------------------------------------------------------------------------+

Layer 1: Facility Perimeter Controls

  • Access Filtering: Physical barrier controls at the building envelope, including security turnstiles, exterior perimeter fencing, and staffed guard stations.
  • Visitor Management: Every non-cleared individual (vendors, janitorial staff, external investigators, legal counsel) must present government-issued identification, be entered into an electronic visitor logbook with timestamped arrival and departure records, receive a color-coded visitor badge, and remain under continuous physical escort by authorized laboratory personnel.

Layer 2: Forensic Laboratory Entrance

  • Mantrap / Airlock Vestibule: An interlocking two-door vestibule where the second door cannot physically open until the first door is completely closed and locked. This prevents tailgating (unauthorized entry behind an authorized person) and forced entry.
  • Multi-Factor Authentication (MFA): Laboratory entrance doors require dual-factor authentication combining something you have (encrypted RFID smart badge / PIV card) with something you are (biometric fingerprint scanner, iris recognition, or facial geometry).
  • Electronic Audit Logging: All door access attempts (successful and rejected) are logged electronically with millisecond timestamps and integrated with perimeter alarm monitoring.

Layer 3: Secure Evidence Vault & Storage Lockers

  • Slab-to-Slab Construction: The walls of the evidence storage room must extend from the true structural concrete subfloor to the true concrete ceiling deck above ("slab-to-slab"). Dropped acoustic tile ceilings provide an easy penetration vector and are strictly disallowed around evidence vaults.
  • Dual-Custody Management: Access to the evidence vault requires dual custody (two authorized individuals presenting independent credentials simultaneously) or is restricted exclusively to a designated Evidence Custodian.
  • Reinforced Storage Hardware: Evidence is organized within heavy-gauge steel lockers or fire-rated security safes (UL Class 350 fire endurance rating). Individual lockers are assigned to specific examiners for active working cases, secured with unique padlocks or digital pin codes.

Continuous CCTV Surveillance & Archival Standards

  • Camera Coverage: Closed-Circuit Television (CCTV) cameras must provide 100% visual coverage of all lab entry/exit points, the evidence intake counter, the interior of the evidence vault, and all individual evidence lockers. No camera blind spots may exist over evidence hand-off or transfer surfaces.
  • Camera Specifications: High-definition IP cameras equipped with infrared (IR) night vision and wide dynamic range (WDR) to handle contrasting lighting.
  • Video Retention: CCTV footage must be recorded continuously (or on motion triggers with 5-second pre-buffering) and retained for a minimum of 90 days (with many accredited government labs requiring 1 to 3 years of immutable, write-once archival storage).

Environmental & Ergonomic Controls

Electronic evidence is exceptionally vulnerable to physical environmental degradation. Forensic laboratories must maintain strict climate and power parameters to prevent evidence destruction during intake and analysis.

+-------------------------------------------------------------------------+
|             FORENSIC LABORATORY ENVIRONMENTAL SPECIFICATIONS            |
+-------------------------------------------------------------------------+
| Parameter           | Target Threshold       | Failure Consequences     |
|---------------------|------------------------|--------------------------|
| **Temperature**     | 68°F–72°F (20°C–22°C)  | Hardware thermal throttling;|
|                     | (Continuous 24/7)      | premature disk failure;  |
|                     |                        | component expansion stress|
|---------------------|------------------------|--------------------------|
| **Relative**        | 40% to 50% RH          | • <40%: Severe ESD hazard|
| **Humidity (RH)**   | (Tight regulation)     | • >60%: Condensation &   |
|                     |                        |   galvanic corrosion     |
|---------------------|------------------------|--------------------------|
| **Flooring**        | Static-Dissipative     | Uncontrolled electrostatic|
|                     | (<10^9 ohms resistance)| shock damaging exposed PCBs|
|---------------------|------------------------|--------------------------|
| **Fire**            | Clean Agent Gas        | Water sprinklers cause   |
| **Suppression**     | (FM-200 / Novec 1230)  | catastrophic electrical  |
|                     |                        | short circuits & residue |
|---------------------|------------------------|--------------------------|
| **Power**           | Online Double-         | Voltage spikes, sags, or |
| **Conditioning**    | Conversion UPS + AVR   | brownouts corrupting bit- |
|                     |                        | stream image streams     |
+-------------------------------------------------------------------------+

Relative Humidity (RH) Regulation: The 40%–50% Window

Maintaining relative humidity within the 40% to 50% RH range is an absolute operational requirement in digital forensics:

  • Failure Mode 1: Low Humidity (< 40% RH): When air becomes dry, the triboelectric charging effect escalates dramatically. Everyday movements generate static charges exceeding 15,000 to 25,000 volts on personnel. A human cannot perceive an electrostatic discharge (ESD) below approximately 3,000 volts, but modern semiconductor gate oxide layers in NAND flash, SSD controllers, and DDR RAM can suffer catastrophic puncture breakdown at less than 100 volts. Low humidity turns the laboratory into an active ESD hazard zone.
  • Failure Mode 2: High Humidity (> 60% RH): When humidity exceeds 60%, water vapor condenses onto microelectronic circuits, especially as hot workstations cool down. Moisture promotes galvanic corrosion across solder joints, causes micro-shorting across dense PCB traces, degrades the reflective layers of optical media, and stimulates fungal and mold growth on magnetic tape binder materials.

Anti-Static Protection Protocols

To eliminate ESD risks when handling disassembled hard drives, open computer chassis, and bare PCB boards:

  • Static-Dissipative Flooring: Lab floors must utilize grounded vinyl composition tile (VCT) or epoxy coatings with a surface resistance between $10^6$ and $10^9$ ohms.
  • Grounded Workbenches & Mats: Workstations feature static-dissipative rubber bench mats bonded to electrical ground through a 1-megohm current-limiting safety resistor.
  • Examiner Grounding: Analysts must wear grounded anti-static wrist straps (or heel grounders on ESD conductive flooring) whenever touching exposed internal hardware or circuit boards.

Fire Suppression: Clean Agent vs. Traditional Sprinklers

Traditional wet-pipe fire sprinkler systems utilize pressurized water to extinguish flames through cooling. In a digital forensics lab, deploying water is catastrophic: it causes immediate phase-to-phase electrical short circuits, introduces dissolved mineral contaminants into delicate disk platter assemblies, and irreversibly destroys evidence media.

Accredited forensic facilities deploy Clean-Agent Gaseous Fire Suppression Systems:

  • FM-200 (HFC-227ea) / Novec 1230 (FK-5-1-12): Liquefied gases discharged into the room within 10 seconds of multi-sensor optical/thermal ionization smoke detection.
  • Suppression Mechanism: Clean agents extinguish fire primarily through heat absorption at the molecular level, interrupting the chemical chain reaction of combustion without depleting ambient oxygen to levels hazardous to occupants.
  • Forensic Benefit: Clean agents are electrically non-conductive, leave zero chemical residue, cause zero thermal shock to electronic components, and do not damage energized hardware or delicate storage media.

Forensic Workstation Specifications & Network Architecture

A forensic analysis workstation is an engineered, high-performance computing system built to ingest, process, and analyze massive volumes of raw data without introducing evidentiary alteration.

+-------------------------------------------------------------------------+
|             FORENSIC WORKSTATION HARDWARE & NETWORK SPECS               |
+-------------------------------------------------------------------------+
| Subsystem           | High-Performance Specification                    |
|---------------------|---------------------------------------------------||
| **Processor (CPU)** | High core-count multi-threaded processor          |
|                     | (e.g., AMD Ryzen Threadripper 32/64-core or Intel  |
|                     | Xeon W-series) for parallel cryptographic hashing |
|                     | and multi-threaded data carving.                  |
|---------------------|---------------------------------------------------|
| **Memory (RAM)**    | 64 GB to 128 GB+ ECC (Error-Correcting Code)      |
|                     | DDR5 RAM to prevent single-bit flips during deep  |
|                     | memory indexing and RAM dump analysis.            |
|---------------------|---------------------------------------------------|
| **Storage I/O**     | Three-tier storage architecture:                  |
|                     | 1. OS/Applications: NVMe PCIe 4.0 SSD (M.2)       |
|                     | 2. Scratch/Temp/Index: High-speed NVMe RAID 0     |
|                     | 3. Evidence Image Repository: Redundant RAID 5/6  |
|---------------------|---------------------------------------------------|
| **Write-Blocker**   | Integrated hardware write-blocking bridge bays    |
| **Hardware**        | (Tableau T35u SATA/IDE, T8u USB 3.0, T7u PCIe,    |
|                     | WiebeTech DriveLock) with physical write-block LED|
|---------------------|---------------------------------------------------|
| **Power (UPS)**     | True Online Double-Conversion UPS (2000VA–3000VA) |
|                     | with Automatic Voltage Regulation (AVR).          |
|---------------------|---------------------------------------------------|
| **Network**         | Completely isolated / air-gapped forensic subnet;  |
| **Isolation**       | dual-homing between corporate LAN and forensic    |
|                     | network is strictly prohibited by policy.         |
+-------------------------------------------------------------------------+

Hardware Write-Blockers: Operational Validation

A write-blocker is a specialized device that intercepts commands traveling between the forensic host workstation and the suspect storage media, permitting read commands while intercepting, modifying, or dropping all write, erase, and modification commands.

  • Hardware Write-Blockers: Dedicated physical micro-controllers placed in-line between the evidentiary drive and the forensic analysis machine (e.g., Tableau T35u SATA/IDE or WiebeTech Forensic UltraDock). Hardware write-blockers operate independently of the host OS, making them immune to host OS driver bugs, background automounting routines, or file system indexing services.
  • Command Interception: When a hardware write-blocker receives an ATA/SATA WRITE SECTORS, WRITE DMA, or SCSI WRITE (10) command, it intercepts the command packet and immediately returns a write-protect error code or drops the command, ensuring zero bits on the target disk are altered.
  • Write-Block Verification: Accredited SOPs require examiners to verify write-blocker functionality prior to every imaging session:
    1. Connect a non-evidentiary test drive through the write-blocker.
    2. Attempt to write a temporary file or issue an explicit raw disk write command.
    3. Verify that the write operation fails with an Access Denied or Write-Protected error.
    4. Confirm that the drive's cryptographic hash remains unchanged.

Clean Media Sanitization Station

Accredited laboratories must maintain dedicated, stand-alone media sanitization stations to prepare destination storage media prior to acquiring bit-stream disk images.

  • Wiping Protocols: Target destination drives must be sanitized in compliance with NIST SP 800-88 Rev. 1 (Guidelines for Media Sanitization) "Clear" or "Purge" standards, or DoD 5220.22-M multi-pass wiping protocols.
  • Zero-Fill Verification: A sanitized drive must be overwritten with known fixed characters (typically all zeros: 0x00) or cryptographically erased, followed by an automated verification pass confirming that 100% of readable sectors contain 0x00.
  • Sanitization Log: Every wiped destination drive is labeled with a sanitization sticker detailing the wipe date, wiping utility used, technician initials, and pre-image zero verification status.

Air-Gapped Network Architecture

Forensic analysis workstations must operate within a strictly isolated, air-gapped forensic local area network (LAN):

  • No Internet Routing: The forensic subnet must have no physical or logical connection to the public Internet, cloud services, or general corporate enterprise networks.
  • Prohibition on Dual-Homed Workstations: A forensic workstation must never be dual-homed (i.e., simultaneously connected via two NICs or a NIC and Wi-Fi to both the corporate network and the forensic evidence network). Dual-homing creates a bridge that exposes active evidence images to malware propagation, unauthorized network browsing, and potential external data exfiltration.
  • Dedicated Forensic Evidence Server (NAS/SAN): High-volume forensic bit-stream images (.E01, raw .dd) are stored on a centralized, private Storage Area Network (SAN) or Network Attached Storage (NAS) accessible solely by authenticated examiners over an isolated 10GbE/40GbE private switch fabric.

Forensic Software Validation & Quality Assurance

Forensic tool output is frequently challenged under the Daubert standard (Daubert v. Merrell Dow Pharmaceuticals, 1993) and Federal Rule of Evidence 702. To ensure evidence derived from software utilities (e.g., EnCase, FTK, Magnet AXIOM, Autopsy, Volatility) is legally admissible, forensic tools must undergo rigorous, documented validation testing prior to deployment in active casework.

The NIST CFTT Methodology

The National Institute of Standards and Technology (NIST) Computer Forensic Tool Testing (CFTT) project establishes the standard testing methodology used by accredited laboratories worldwide. NIST CFTT evaluates digital forensic tools against core functional requirements:

  1. Core Imaging Requirements:

    • The tool shall make a bit-stream duplicate or image of an original disk or partition.
    • The tool shall not alter any portion of the original source media.
    • The tool shall verify the accuracy of the duplicate using cryptographic hashing (MD5, SHA-1, SHA-256).
    • The tool shall log all input/output errors and anomalous sector encounters accurately.
  2. Validation Against Known Ground Truth (NIST CFReDS):

    • Laboratories test software tools using the NIST Computer Forensic Reference Datasets (CFReDS)—standardized disk and memory images with known ground truth (e.g., specific known deleted files, known file slack artifacts, known hidden partitions, and planted steganographic data).
    • If a carving tool claims to carve fragmented JPEG images, the examiner runs the tool against a CFReDS image with precisely 15 fragmented JPEGs. The tool passes validation only if it accurately reconstructs the images without corrupting file boundaries or generating false positives.

Version Control & Change Management

  • No Untested Updates: Operating system patches, forensic software minor updates, and analysis scripts must never be installed on production forensic workstations during an active case.
  • Controlled Regression Testing: When a vendor releases a software update (e.g., upgrading from FTK 7.4 to FTK 8.0), the new version must be installed in an isolated test environment and subjected to standardized validation scripts against reference datasets. Only after the Technical Leader signs a formal Software Validation Report may the updated software be deployed to the active lab floor.
  • Master Tool Inventory: The laboratory maintains an immutable Master Tool Inventory documenting every software utility, exact version number, cryptographic hash of the installer binary, validation date, and authorized operational scope.
Loading diagram...
Forensic Laboratory Security, Environmental & Operational Architecture
Test Your Knowledge

A digital forensics laboratory is preparing for an ISO/IEC 17025:2017 accreditation audit. During an internal assessment, the Quality Manager discovers that examiners have been utilizing an uncompiled, open-source Python script to parse carved SQLite databases from suspect mobile devices without any formal validation documentation or comparison against known ground truth datasets. Under ISO/IEC 17025:2017 Clause 7.2, how must the laboratory resolve this compliance deficiency?

A
B
C
D
Test Your Knowledge

During a severe winter dry spell, a forensic laboratory's HVAC humidification sub-system fails, causing the ambient relative humidity inside the primary evidence analysis area to plunge from 45% down to 18% RH. If the laboratory continues disassembling suspect laptops and extracting bare NVMe SSD and DDR RAM modules under these conditions, what is the primary forensic and physical risk?

A
B
C
D
Test Your Knowledge

An investigative agency is designing a newly accredited digital forensics suite. The IT engineering team proposes installing a dual-homed network configuration on each examiner workstation, connecting Network Interface Card 1 (NIC 1) to the agency's general corporate network (with Internet access for research) and Network Interface Card 2 (NIC 2) to the private forensic storage network housing raw bit-stream evidence images. Why must the Quality Manager and Lead Forensic Examiner reject this proposed network design?

A
B
C
D