A three-day training session on the topic "Handling Digital Evidence in the Conduct of Investigative Actions" was held by the Almaty Academy of the Ministry of Internal Affairs of the Republic of Kazakhstan named after Makan Yesbulatov in cooperation with the OSCE Programme Office.

The event was aimed at preparing instructors to conduct training on the handling of digital evidence and at forming a pool of trainers for further work with practicing officers of internal affairs bodies, including the Almaty City Police Department. International and national experts were engaged in the preparation of law enforcement and special agency officers, as well as trainers in the field of countering cybercrime.

The training programme was aimed at identifying, suppressing, solving, and investigating cybercrimes and crimes involving the use of ICT, based on international practices, with the involvement of international and domestic experts. The Center, in cooperation with the OSCE Programme Office, also engaged instructors of the Academy in participation. The acquisition of professional knowledge and methodology for its subsequent transfer to trainees, with the composition of instructors determined and training topics distributed, makes it possible to conduct similar training sessions for practicing officers of internal affairs bodies.

The training was conducted by international expert Ion Gaina and national experts Zh. Mugalova and A. Kaliyev. Interaction with the OSCE was ensured by national project coordinator M. Asafov and project assistant N. Isakhanov.

At the opening of the training, speeches were given by the Head of the Academy, Police Colonel K. Koblandin, Deputy Head of the Department for Work with Personnel of the Ministry of Internal Affairs of the Republic of Kazakhstan, Police Colonel A. Almagambetova, and, on behalf of the OSCE Programme Office, M. Asafov.

The training began with the legal foundations of digital forensics, the admissibility of digital evidence, and initial actions upon detecting electronic devices. During the classes, the role of the Forensic Science Center of the Ministry of Internal Affairs of the Republic of Kazakhstan, the concept of digital forensics, and the types of digital devices as sources of evidentiary information were examined. Separate attention was given to the legislation of the republic and the requirements for the admissibility of digital evidence, as well as the ACPO/NPCC principles for handling digital evidence. Within the framework of the training programme, a practical demonstration was held on calculating hash values used to verify the integrity of digital data, and the first actions at the scene of the incident, preparation for a search, issues of authorization, and the information required before the start of investigative actions were also examined.
It is also important that all theoretical provisions were analyzed using practical examples. Participants compared international approaches with domestic practice, identified differences, and discussed the possibilities of applying foreign experience taking into account the norms of the republic's legislation.

A separate block of the programme was devoted to practical issues of detecting, seizing, and preserving electronic evidence. Participants examined issues of managing the power supply of digital devices, decision-making during their seizure, and the use of the MouseJiggler device. During the group simulation "Digital Scene," actions at the scene of the incident were modeled, and an analysis was conducted of decisions made and errors committed. This form of work allowed participants to practice the sequence of actions with digital devices and to become familiar with the methodology for organizing similar exercises for future trainees.

Separate classes were devoted to handling smartphones: determining the IMEI code, using airplane mode and Faraday bags, and choosing actions depending on the state of the device. Procedures for working with computers and servers, issues of shutting them down, and the specifics of handling all-in-one computers and RAID arrays were examined. During the practical workshop on packaging digital devices, participants analyzed correct and incorrect methods of packaging them, labeling requirements, and the use of packaging materials. Particular attention was paid to errors capable of leading to alteration or loss of digital information.

When examining issues of procedural documentation and preparing participants for independent teaching of the course, the mandatory elements of the search and seizure protocol, the specifics of photo and video documentation of investigative actions, working with passwords and cloud data, and the making of corresponding entries in the protocol were considered.

The methodological block included consideration of entrance and exit testing, criteria for certifying trainees, and the logistical support of the course. Participants became familiar with a set of teaching and methodological materials, including presentations, a trainer's manual, and methodological developments. Within the framework of the practical workshop, attention was drawn to lesson planning, distribution of instructional time, selection of examples from professional practice, and organization of group work. The discussion concluded with methodological aspects of teaching the course and preparation for conducting similar training sessions for practicing officers of internal affairs bodies.

It should be noted that the theoretical material was examined using practical examples and international experience. This made it possible to highlight the differences between foreign and domestic approaches, as well as the conditions for applying international recommendations in the activities of the internal affairs bodies of the republic.

At the end of each topic, an interactive knowledge check was conducted using the Mentimeter application. This format made it possible to promptly assess mastery of the material, identify issues requiring additional explanation, and study ways of explaining complex material, setting practical tasks, analyzing completed exercises, and organizing feedback.

The practical result of the training was the determination of the composition of instructors from among 13 representatives of the departments of criminal procedure and forensic science, operational-search activity, cybersecurity and information technology, the faculty of professional training, and the Center for Training Specialists in Countering Cybercrime, who will subsequently conduct the training. It covers a wide range of topics, including the legal foundations of working with digital evidence, initial actions at the scene of the incident, handling mobile devices, computers, and servers, packaging, labeling, and procedural documentation.

This creates the basis for preparing and conducting subsequent training sessions for practicing officers of internal affairs bodies. The acquired knowledge and teaching and methodological materials will be used in the educational process of the Academy in training cadets and in advanced training of serving officers of internal affairs bodies, which creates conditions for the subsequent transfer of international experience to practical units taking into account the requirements of national legislation.
Following the three-day training, certificates were presented to the participants. The presentation ceremony was attended by the Deputy Head of the Academy, Police Colonel D. Yeremeyev.

Arman BEKTAS,
Head of the Center for Training Specialists in Countering Cybercrime
of the Almaty Academy of the Ministry of Internal Affairs
of the Republic of Kazakhstan named after Makan Yesbulatov, Police Colonel

Comments powered by CComment