Indonesia regulates electronic evidence across several statutes without an integrated technical guideline comparable to international standards, so handling practice varies between agencies and may trigger disputes over evidentiary validity. This study analyzes chain of custody application in digital forensic investigation through a review of standards and practice. A qualitative document analysis examined NIST SP 800-86, ISO/IEC 27037, 27041, 27042, and 27043, Indonesian statutes on electronic evidence, and scholarly articles from 2015 to 2025, using a three-stage procedure of coverage mapping against a six-question handling framework, gap analysis against four contemporary technology conditions, and synthesis. The two principal standards proved complementary rather than competing, with NIST stronger on incident response integration and custodian documentation and ISO stronger on identification and first responder competence. Neither adequately covers cloud computing or multi-tenancy, and full-disk encryption forces a shift in emphasis from repeatability toward auditability. Seven guideline elements are proposed, four of them high priority and implementable without regulatory change.
Copyrights © 2024