Chain of custody is the documented, unbroken record of who collected, handled, transferred, and stored a piece of evidence from the moment of acquisition until it is presented in court.
Explanation
Chain of custody is the procedural backbone that makes digital evidence trustworthy. Because digital artifacts are trivially copied, modified, or fabricated, the only thing that distinguishes an authentic exhibit from a manufactured one is the story of its handling. That story is told through documentation: seizure records, evidence labels, transfer logs, storage access records, and hash verifications at each step. Every person who touches the evidence must be identified, every movement must be timestamped, and every container must be sealed and tracked.
A gap in the chain does not automatically destroy the evidence, but it opens the door to challenge. Defense counsel will exploit any undocumented handoff to argue that the evidence could have been tampered with between collection and presentation. This is why the chain begins at acquisition—before the first byte is copied, the investigator documents the scene, photographs the system state, and records who is present. Each subsequent transfer (from responder to analyst, from analyst to lab, from lab to courtroom) adds another link that must be provable.
Chain of custody operationalizes several broader forensic principles: Lawfulness demands that seizure itself was authorized, Integrity requires proving the evidence was never altered, and Reproducibility depends on preserving the original so independent examiners can verify findings. Without a defensible chain, even perfectly analyzed evidence may be ruled inadmissible, which is why it sits at the heart of Evidence Acquisition Fundamentals.
Examples
A responder images a suspect laptop, computes a SHA-256 hash of the image, and records both on an evidence tag signed by herself and a witness. The drive goes into a tamper-evident bag, logged into an evidence locker. Months later, an analyst checks out a working copy, verifies its hash matches the original, and documents the checkout. At trial, the hash match plus the signed log proves the analyst examined the same data the responder seized.