1. Andrew, M. (2007). Defining a process model for forensic analysis of digital devices and storage media. In Northwest security institute and pacific northwest national laboratory (Eds.), SADFE 2007: Second International Workshop on Systematic Approaches to Digital Forensic Engineering: Proceedings: 10–12 April 2007, Seattle, Washington, USA, 16–30. Los Alamitos, Calif: IEEE Computer Society.
2. Association of Chief Police Officers (ACPO). (2012). Good practice guide for computer-based electronic evidence, v. 5. Retrieved from
3. Beebe, N., & Clark, J. G. (2005). A hierarchical, objectives-based framework for the digital investigations process. Digital Investigation, 2(2), 147–167.
4. Blackwell, C. (2011). A framework for investigating questioning in incident analysis and response. In G. Peterson & S. Shenoi (Eds.), Advances in digital forensics VII (pp. 23–34). IFIP AICT 361. IFIP International Federation for Information Processing.
5. Carrier, B. (2003a). Defining digital forensic examination and analysis tools using abstraction layers. International Journal of Digital Evidence, 1(4), 1–12.