Integrity is the assurance that digital evidence remains complete, accurate, and unaltered from the moment of acquisition through analysis, storage, and presentation in court.

Explanation

Integrity is the bedrock of forensic work: if a file, log, or memory image cannot be shown to be exactly what was collected, everything derived from it collapses. In digital forensics this is usually demonstrated rather than assumed — investigators compute a cryptographic hash (such as SHA-256) of the original media, work only on forensic copies, and re-hash those copies to prove they match the original. Any mismatch means the evidence is compromised and must be re-acquired or excluded.

Integrity operates at several levels. At the technical level, write-blockers and read-only mounting prevent the acquisition host from modifying source media. At the procedural level, a documented Chain Of Custody ties every transfer, access, and storage event to a responsible person, so no unexplained gap can suggest tampering. At the analytical level, analysts avoid running tools that alter timestamps or file contents against original evidence, and they record tool versions and commands so results are reproducible by another examiner.

Integrity also underpins Defensibility: a finding that cannot be challenged is one that survives cross-examination, and the hash values plus custody records are what make that possible. It connects directly to the broader Core Principles of Forensic Science, where it pairs with objectivity and documentation as a non-negotiable expectation. Modern complications — such as live systems that change state when touched, and AI-generated artifacts whose provenance is unclear — make deliberate, documented integrity practices more important, not less.

Examples

The standard workflow: image a suspect drive, immediately compute its SHA-256 hash, document the value, and verify that every working copy re-hashes to the identical value before and after analysis.

sha256sum evidence.img        # at acquisition
sha256sum working_copy.img    # before analysis — must match

A chain-of-custody form recording who received the drive, when, sealed in what container, and every subsequent transfer is the procedural counterpart of the hash.