نوع مقاله : مقاله پژوهشی
نویسندگان
1 گروه مدیریت فن آوری اطلاعات ، واحد بین المللی کیش، دانشگاه آزاد اسلامی، کیش، ایران
2 گروه مدیریت فناوری اطلاعات، دانشکده مدیریت و اقتصاد، واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران.
3 گروه مدیریت صنعتی، دانشکده مدیریت، دانشگاه آزاد اسلامی، واحد کرج، دانشگاه آزاد اسلامی، واحد کرج، ایران
چکیده
کلیدواژهها
موضوعات
عنوان مقاله [English]
نویسندگان [English]
The rapid expansion of social media usage in Iran has transformed these platforms into primary environments for the occurrence and proliferation of cybercrimes. Characteristics such as data volatility, the ease of deleting or manipulating digital content, the platform-based dispersion of evidence, and dependency on third-party service providers significantly complicate crime detection, digital evidence preservation, and forensic attribution. In the practical context of Iran’s judicial system, cybercrime investigations largely follow a reactive, post-incident approach, where technical and forensic actions are initiated only after a complaint has been filed. In many social media-related cases, this reactive orientation has resulted in the loss of critical digital traces, weakened chain-of-custody integrity, and reduced evidentiary reliability in court proceedings. Within digital forensics literature, forensic readiness is conceptualized as a proactive and structured approach aimed at establishing the necessary technical, legal, and organizational prerequisites for preserving and managing potential digital evidence before an incident occurs. Despite the development of several international conceptual frameworks, many lack empirical validation or fail to account for the institutional and legal specificities of non-Western jurisdictions such as Iran. Domestically, prior studies have primarily focused on descriptive or legal analyses of cybercrime, with limited integration of technical forensic preparedness and almost no empirically validated indigenous model tailored to social media environments. This gap highlights the need for a context-sensitive and empirically tested forensic readiness framework.
The present study aimed to validate a localized forensic readiness model designed to enhance secondary and deterrent prevention of cybercrimes in social media within Iran’s institutional context. A mixed exploratory–validation research design was adopted. In the qualitative phase, 48 semi-structured interviews were conducted with cybercrime judges, specialized attorneys, and certified digital forensic experts. Thematic analysis was performed through open, axial, and selective coding. A total of 64 initial codes were identified and subsequently consolidated into 26 conceptual components, which were organized into three principal dimensions: technical requirements, legal requirements, and organizational requirements. Based on these findings, a researcher-developed questionnaire was constructed. Content validity was assessed by expert review, and a pilot study confirmed preliminary reliability. In the quantitative phase, the final instrument was distributed among 214 targeted respondents with professional experience in cybercrime adjudication and digital evidence assessment. Data were analyzed using Partial Least Squares Structural Equation Modeling (PLS-SEM) with SmartPLS software.
The measurement model demonstrated strong reliability and validity indicators. Cronbach’s alpha values exceeded 0.84 across all constructs, composite reliability (CR) values were above 0.89, and Average Variance Extracted (AVE) values surpassed the recommended threshold of 0.50, ranging above 0.58. Discriminant validity was confirmed using both the Fornell–Larcker criterion and the HTMT ratio, with HTMT values below 0.85 for all construct pairs. Factor loadings ranged from 0.71 to 0.89, indicating adequate indicator reliability. The structural model exhibited acceptable fit indices (SRMR = 0.061; NFI = 0.91), reflecting a satisfactory model-data fit within established PLS-SEM evaluation criteria. All hypothesized paths were positive and statistically significant at p < 0.001. Technical requirements demonstrated the strongest effect on forensic readiness (β = 0.38), followed by organizational requirements (β = 0.34) and legal requirements (β = 0.29). The coefficient of determination (R² = 0.62) indicated substantial explanatory power, suggesting that the three dimensions collectively account for 62% of the variance in forensic readiness.
The findings confirm that forensic readiness in social media environments is inherently multidimensional and requires the simultaneous alignment of technological infrastructure, legal admissibility frameworks, and coordinated organizational mechanisms. The primary contribution of this study lies in the empirical extraction of model components from real-world judicial and forensic experiences and the subsequent quantitative validation of its structural integrity. By bridging the gap between abstract theoretical frameworks and practical institutional needs, the proposed model offers a contextually grounded structure suitable for Iran’s cybercrime investigation ecosystem. From a policy and operational perspective, the validated model can serve as a foundation for designing proactive digital evidence management procedures, strengthening chain-of-custody practices, and supporting technology-driven and intelligent cyber policing strategies. The preventive dimension addressed in this study is conceptualized as secondary and deterrent prevention, achieved not through direct technical suppression of criminal activity but by enhancing the probability of detection, attribution, and effective prosecution. Future research is recommended to examine the operational implementation of the model across diverse institutional settings, conduct cross-national comparative validation, and integrate emerging technological variables such as AI-driven forensic automation to further refine and extend the framework.
کلیدواژهها [English]
ارسال نظر در مورد این مقاله