Approaches to Collecting Electronic Evidence in Cloud Computing for Forensic Purposes
Keywords:
Electronic Evidence, Cloud Computing Environments, Digital Forensics, Chain of Custody, Justice SystemAbstract
This study aims to examine effective approaches for collecting electronic evidence in cloud computing systems in compliance with legal standards and to analyze practical challenges. This qualitative research employs document analysis and in-depth interviews with ten key informants, including police officers, digital forensic experts, prosecutors, and judges. Data were analyzed using content analysis. The findings indicate that the admissibility of electronic evidence in judicial proceedings depends on process reliability and data integrity. Key considerations include legal compliance, preservation of the chain of custody, and traceability throughout all stages. Essential practices include non-intrusive data acquisition, forensic imaging, and systematic documentation, which enhance transparency and reduce disputes in court. However, several challenges remain, including technological complexity, cross-border jurisdictional issues, and limitations in personnel expertise. Therefore, an integrated approach to collecting and managing electronic evidence in cloud computing environments encompassing legal frameworks, technological development, and human resource capacity is necessary to strengthen the effectiveness of the justice system in the digital era.
References
ไทยรัฐออนไลน์. (2567). รู้ทันกลลวงมิจฉาชีพ 2567 ใช้ AI ก่ออาชญากรรมออนไลน์ เช็กก่อนตกเป็นเหยื่อ.
https://www.thairath.co.th/news/society/2749252#google_vignette
พิชศาล พันธุ์วัฒนา. (2562). ความน่าเชื่อถือในการนำเอกสารอิเล็กทรอนิกส์มาใช้เป็นพยานหลักฐาน.
วารสารวิชาการอาชญาวิทยาและนิติวิทยาศาสตร์, 5(1), 142–161.
วรินทรา ศรีวิชัย. (2563). การตรวจพิสูจน์พยานหลักฐานดิจิทัลกับคดีเกี่ยวกับความมั่นคง. CMU Journal of Law and Social Sciences, 13(1), 78–101.
สำนักงานกิจการยุติธรรม. (2565). รายงานสถานการณ์อาชญากรรมทางเทคโนโลยีในประเทศไทย. https://www.oja.go.th/justicedata/
Carrier, B., & Spafford, E. H. (2004). An event-based digital forensic investigation framework.
Digital Investigation, 1(2), 133–147.
Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the Internet (3rd ed.). Academic Press.
Casey, E., Ferraro, M., and Nguyen, L. (2009). Investigation delayed is justice denied:
Proposals for expediting forensic examinations of digital evidence. Journal of Forensic Sciences, 54(6), 1353–1364. https://doi.org/10.1111/j.1556-4029.2009.01150.x
Horsman, G. (2021). Contemporaneous notes for digital forensic examinations. Forensic
Science International: Digital Investigation, 37, Article 301173. https://doi.org/10.1016/j.fsidi.2021.301173
Kerr, O. S. (2005). Digital evidence and the new criminal procedure. Columbia Law Review, 105(1), 279–318.
Kohn, M. D., Eloff, M. M., and Eloff, J. H. P. (2013). Integrated digital forensic process model. Computers & Security, 38, 103–115. https://doi.org/10.1016/j.cose.2013.05.001
Martini, B., and Choo, K.-K. R. (2012). An integrated conceptual digital forensic framework for cloud computing. Digital Investigation, 9(2), 71–80.
Moussa, A. F. (2021). Electronic evidence and its authenticity in forensic evidence. Egyptian Journal of Forensic Sciences, 11, Article 20. https://doi.org/10.1186/s41935-021-00234-6
Quick, D., and Choo, K.-K. R. (2014). Impacts of increasing volume of digital forensic data: A survey and future research challenges. Digital Investigation, 11(4), 273–294. https://doi.org/10.1016/j.diin.2014.09.002
Ruan, K., Carthy, J., Kechadi, T., and Crosbie, M. (2011). Cloud forensics: An overview. In Advances in digital forensics VII (pp. 35–46). Springer.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 NEU ACADEMIC AND RESEARCH JOURNAL

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.