What should be recorded about date, time and time zone?¶
Date, time and time zone are essential to placing digital activity in sequence, but they are often less reliable than they appear.
Evidential caution: that the time shown on a device or account is automatically accurate. Device clocks may be wrong, time zones may differ, daylight-saving settings may be incorrect and applications may display local, server or account-specific time.
What this means¶
Where several systems are involved, record each separately. A phone, laptop, router, cloud service and security platform may all use different time settings.
Be aware that some applications show relative time such as “five minutes ago” or “yesterday”. Photograph that wording and record the reference time when observed.
Time-zone ambiguity should be stated explicitly. Do not silently convert a timestamp or assume that everyone will interpret it the same way.
What to check or do next¶
- Record the date and time visible on the device, application or service exactly as shown. Note whether the display includes a time zone, UTC offset or location setting.
- Record the actual date and time from a reliable independent source at the same moment. This allows any difference between the displayed time and the reference time to be identified later.
- Do not correct the device clock during first response. Changing it may alter logs, timestamps, synchronisation behaviour and the interpretation of later evidence.
- Capture timestamps in context. Record whether they relate to a message, login, file, alert, notification, browser history, system event or provider record. The same numerical time can mean different things depending on what generated it.
- If the device appears to be using the wrong date, note that before any action. Do not try to explain the discrepancy unless you have evidence.
Operational takeaway
Record displayed time, time zone and an independent reference time together so later analysis can identify clock errors and place events accurately.