8. Examine the number of drive partitions and their names. Record this information in the Disk
Imaging Report. If not using FTK Imager, use the command “disktype” to create a record of
the partitions. Use the following example command (this will also output the results into a text
file:
$ disktype [path to device, for example /dev/sr0] > [Destination path]/[Component number
of physical media]_disktype.txt
9. In the imaging program, choose to acquire the image in the E01 format.
10. Fill out the metadata fields as follows in the imaging program:
o
Case Number
— Use the component number assigned to the disk image itself (For
example, 99.4088.2).
o
Evidence Number
— Enter the text "Disk image taken from", then type the
component number assigned to the computer or physical media that is the source of
the disk image. (for example, 99.4088.1). If the computer or drive will not become a
component, use a brief description of the source computer, for example "SRGM
device #101070".
o Unique Description — Fill in this field using the following format: [Artist], [Title of
Artwork]
o Examiner — Fill in the name of the person creating the disk image.
o Notes — Start this field with the text "Inscriptions:" and after the colon, record any
inscriptions that are deemed important on the drive or computer. This would typically
include the drive's serial number, or any text that the artist or SRGM staff wrote on
the computer or the drive that might identify it. If there are no inscriptions worth
noting, type "Inscriptions: None." After listing the inscriptions type a comma. Now
include any information about the version or iteration of the artwork that the computer
is running, for example "2016 version" or "2017 SRGM iteration". If there are multiple
hard drives within the same computer, the number of the drive should be recorded as
“X of X”. The examiner should also include information about where the drive is
plugged into the computer or where it sits in a cable run in relation to other the drives.
11. Select the following path on the imaging computer to save the image: Disk Imaging
/[Accession number]_Artist_Artwork
12. The filename of the image should be formatted as follows:
[Component number]_Artist_ArtworkTitle_SRGM_DiskImage_YearofImaging". The
imaging program should automatically add the appropriate file extension when it creates the
image.
13. Choose to verify the image after creation. If using Guymager, choose to re-read the source
media after imaging.
14. If the program has a fragmentation option, do not use it. In FTK Imager type 0 for no
fragmentation. The goal is to produce a single file for the entire disk image.