1. Purpose
This document outlines the procedure for reviewing requests, tenders, and contracts related to ISFCE’s Proficiency Testing (PT) Scheme. It ensures that all agreements are properly reviewed, documented, and meet the objectives of the PT scheme, ISO/IEC 17043, and the customer’s needs.
2. Scope
This procedure applies to all incoming requests, tenders, and contracts related to the delivery of ISFCE’s PT activities. It ensures that requirements are understood, documented, and aligned with ISFCE’s capacity to deliver.
3.2 Agreement with Customer’s Needs
4.1 Capability Assessment
Before accepting any contract, ISFCE evaluates its internal resources and capabilities to ensure it can meet the specified requirements. This includes evaluating:
4.2 Technical Appropriateness
The PT scheme is evaluated to ensure it is technically appropriate for the given field of application, and the customer’s needs are addressed in terms of the desired outcomes and results.
5. Review of Externally Provided Products and Services
Criteria for External Providers: Any external services or products are reviewed to ensure they meet ISFCE’s established requirements and ISO/IEC 17043 standards.
6.1 Documenting the Review
ISFCE retains detailed records of:
6.2 Retention of Records
All records are retained for a minimum of 5 years, or as required by contract or law, to demonstrate compliance with review procedures.
7. Communication of Deviations
8.1 Review of Amended Contracts
If a contract or request is amended after the PT scheme is already underway, the contract is re-reviewed to ensure ISFCE can meet the revised requirements.
8.2 Communication of Amendments
ISFCE ensures that all amendments are communicated to relevant personnel, both internal and external, involved in the delivery of the PT scheme.
8.3 Repeat Review Process
The review process is repeated for the amended contract, and all changes are documented in accordance with ISO/IEC 17043 requirements.
9. Responsibilities
10. Review and Approval
This procedure is reviewed annually by the ISFCE management team to ensure continued compliance with ISO/IEC 17043 and customer requirements.
Shawn Loutsch is a seasoned digital forensics and incident response expert with over 15 years of experience, specializing in investigations involving ransomware, malware, phishing, corporate litigation, and incident response. He excels in managing security incidents, performing root cause analysis, and providing detailed reporting to executive, legal, and compliance teams. Shawn has led global incident response teams, built relationships across cybersecurity departments to enhance security posture, and contributed to regulatory and compliance goals. With a strong focus on ensuring forensic accuracy and timely project execution, he is known for delivering in high-stakes environments.
Currently serving as Senior Manager at TransUnion, Shawn leads security incident investigations and develops incident response capabilities across platforms such as M365, AWS, and on-premise resources. He manages forensic tools, conducts tabletop exercises, and mentors junior analysts. In his previous roles at Stroz Friedberg, he led forensic investigations and large-scale digital forensics and eDiscovery projects for both civil and criminal matters. Shawn holds several prestigious certifications, including multiple SANS GIAC credentials and Certified Computer Examiner (CCE). His technical proficiency spans tools such as EnCase, FTK, Cellebrite, Splunk, and numerous forensic and security platforms.
Michael Chaves is an experienced Detective and Digital Forensics Examiner with nearly 20 years of investigative experience at the Monroe CT Police Department. Specializing in complex digital forensic examinations, Chaves has played a critical role in high-profile cases involving POS malware, financial crimes, narcotics, and murder. He has served as a Task Force Officer with the US Secret Service and DEA, conducting investigations into financial crimes and narcotics operations. Chaves is a recognized Subject Matter Expert, having conducted hundreds of digital forensic examinations and testified as an expert witness in federal and state courts.
In addition to his law enforcement duties, Chaves is an Adjunct Professor at Sacred Heart University, where he teaches graduate courses on computer and cell phone forensics. He holds numerous certifications, including Cellebrite Certified Physical Analyst (CCPA), Certified Computer Examiner (CCE), and Certified Cryptocurrency Investigator (CCI). As the Vice President of the Connecticut Chapter of the International Association of Financial Crimes Investigators (IAFCI), Chaves continues to be a leader in the field of digital forensics and cybersecurity.
John W. Akerman, Esq., is a seasoned Computer Forensics Examiner and Electronic Discovery Consultant at Rosen Litigation Technology Consulting, Inc., based in Charleston, SC. With over 15 years of experience, he holds multiple certifications, including Certified Computer Examiner (CCE) and AccessData Certified Examiner (ACE). John has provided expert analysis and testimony in numerous high-profile cases across state and federal courts. His deep expertise in digital forensics, mobile device analysis, and e-discovery has made him a trusted advisor in complex legal matters involving digital evidence.
John’s educational background includes a Bachelor of Science in Finance from Auburn University and a Juris Doctor from Charleston School of Law. In addition to his legal practice, he is an active member of the American Bar Association and the International Society of Forensic Computer Examiners. John frequently presents at conferences and seminars, sharing his insights on emerging trends in digital forensics and e-discovery, and is committed to staying at the forefront of advancements in forensic technology.
Jason L. Berryhill currently serves as the Assistant Special Agent in Charge at the Department of the Interior, Office of Inspector General, overseeing the Computer Crimes Unit. With over two decades of expertise in digital forensics, he has held positions at the U.S. Secret Service, where he coordinated the Electronic Crimes Task Force in Las Vegas, and as an officer in the U.S. Army. Jason is highly certified, holding credentials such as Certified Information Systems Security Professional (CISSP), EnCase Certified Examiner (EnCE), and Magnet Certified Forensic Examiner (MCFE), among others. His extensive experience includes handling complex cybercrimes, fraud, and digital forensic investigations.
Jason’s education includes a BBA in Logistics Management from Kent State University and an MS in Information Technology from Everglades University. He has undergone extensive digital forensics and IT security training from leading institutions and is a frequent speaker at law enforcement and cybersecurity conferences. He also serves as an Adjunct Associate Professor at the University of Maryland Global Campus, bringing his wealth of knowledge to the next generation of forensic professionals.
Dr. Eric Eppley is an accomplished Cybersecurity Director with over 30 years of experience leading technical and managerial teams. Specializing in Security Architecture, Risk Assessment, and Network/System Design, Dr. Eppley has successfully overseen complex cybersecurity initiatives for high-profile government agencies, including the Department of Defense, Homeland Security, and Health and Human Services. His extensive technical expertise is backed by a Doctor of Information Technology from Capella University, along with multiple industry certifications such as CISSP, CCSP, and CCE. Dr. Eppley currently serves as Chief Information Security Officer (CISO) for the ICON Program at ManTech, where he manages multi-disciplined teams focused on implementing cybersecurity solutions within the Risk Management Framework (RMF).
In addition to his leadership roles, Dr. Eppley is a seasoned educator with over nine years of teaching experience at institutions such as Southern New Hampshire University and the University of Maryland Global Campus. He has instructed courses on Cybersecurity, Network Forensics, and Digital Forensics, providing hands-on learning and practical guidance to students. His vast skill set, from incident response and forensic analysis to cloud security and compliance with standards like NIST 800 and HIPAA, makes him a leading expert in the cybersecurity field.
Jason L. Berryhill currently serves as the Assistant Special Agent in Charge at the Department of the Interior, Office of Inspector General, overseeing the Computer Crimes Unit. With over two decades of expertise in digital forensics, he has held positions at the U.S. Secret Service, where he coordinated the Electronic Crimes Task Force in Las Vegas, and as an officer in the U.S. Army. Jason is highly certified, holding credentials such as Certified Information Systems Security Professional (CISSP), EnCase Certified Examiner (EnCE), and Magnet Certified Forensic Examiner (MCFE), among others. His extensive experience includes handling complex cybercrimes, fraud, and digital forensic investigations.
Jason’s education includes a BBA in Logistics Management from Kent State University and an MS in Information Technology from Everglades University. He has undergone extensive digital forensics and IT security training from leading institutions and is a frequent speaker at law enforcement and cybersecurity conferences. He also serves as an Adjunct Associate Professor at the University of Maryland Global Campus, bringing his wealth of knowledge to the next generation of forensic professionals.
Tino Kyprianou is a seasoned expert in digital forensics and the President and CEO of the International Society of Forensic Computer Examiners (ISFCE), which he took over after its divestiture from Raytheon. He also leads Axiana Digital Forensics, a New Jersey-based firm specializing in computer forensics, cybersecurity, and fraud detection.
With over two decades of experience, Tino is a Certified Computer Examiner (CCE) and Certified Fraud Examiner (CFE), having worked on complex litigation cases involving trade secrets, employee terminations, financial fraud, and criminal defense. He has provided expert testimony in both State and Federal Courts and authored various policy and training manuals on computer forensics. Tino remains dedicated to expanding ISFCE’s reach by enhancing membership benefits, refining training programs, and strengthening the organization’s certification offerings. His vision is to position ISFCE as the global leader in digital forensics education and expertise, ensuring that its certifications set the standard for excellence in the field.
David Sun is a highly experienced cybersecurity expert with over 25 years of expertise in IT management, data breach response, and forensic investigations. As a Principal at CohnReznick, he leads the firm’s security incident response and recovery services, along with its computer forensic and litigation support offerings. His work spans across a variety of domains, including cloud security, digital forensics, eDiscovery, and privacy compliance, allowing him to provide comprehensive solutions to public and private sector clients. David has extensive experience responding to cyber-attacks, investigating data breaches, and managing post-breach remediation efforts. He also specializes in handling complex cases of internal employee malfeasance, theft of sensitive information, and high-profile federal investigations.
David’s expertise has led him to serve as a court-appointed expert and testifying witness in hundreds of litigation matters, including significant cases involving government agencies and major corporations. He has contributed to high-stakes investigations, including a national federal investigation into the handling of classified information and advising on data privacy violations for state attorneys general. Prior to joining CohnReznick, David founded SunBlock Systems, a global litigation advisory firm specializing in electronic evidence. He holds numerous certifications, including Certified Computer Examiner (CCE), Certified Information Systems Security Professional (CISSP), and EnCase Certified Examiner (EnCE), and is a recognized thought leader in cybersecurity, regularly speaking at industry conferences and contributing to various publications.