NIST SP 800-72: Guidelines on PDA Forensics, and What Replaced It
NIST SP 800-72, Guidelines on PDA Forensics, was published in November 2004 and is archived — it is a real publication, not a hypothetical one, but it has not been current guidance for over a decade. For mobile forensics today, use SP 800-101 Revision 1, Guidelines on Mobile Device Forensics.
NIST Special Publication 800-72, Guidelines on PDA Forensics, was published in November 2004 by Wayne Jansen and Rick Ayers of the NIST Computer Security Division, with sponsorship from the Department of Homeland Security. It is a real publication, not a placeholder — but it is archived, and it has not been current guidance for over a decade. If you are looking for how to conduct mobile forensics today, the document you want is SP 800-101 Revision 1.
What SP 800-72 actually covers
The subject is Personal Digital Assistants: the handheld organisers that preceded smartphones. The guide addresses three device families that mattered in 2004 — Pocket PC, Palm OS, and Linux-based handhelds — and sets out how to recover digital evidence from them without compromising its admissibility.
Its stated objective was twofold: to help organisations develop policies and procedures for dealing with PDAs, and to prepare forensic specialists for devices they had not encountered before. That second aim is the more interesting one, and it is why the document is still worth reading. It was written for a moment when a whole category of evidence-bearing device had appeared faster than the profession's methods for handling it.
The forensic process it defined
SP 800-72 structures handling into distinct phases, each of which has to be completed and documented before the next begins:
- Preservation — secure the device and its state, including isolating it from networks and maintaining power so that volatile memory survives.
- Acquisition — copy the data using a method that does not alter the original, and record exactly what was done.
- Examination — surface the data of interest from the acquired image, including deleted and hidden content.
- Analysis — interpret what was found and establish its significance to the investigation.
- Reporting — document findings, method and chain of custody so that another examiner could follow and challenge the work.
The devices are obsolete. The sequence is not. Every subsequent NIST forensics publication uses the same shape, and the reason is that it encodes an evidential principle rather than a technical one: you cannot analyse what you have already contaminated, and you cannot rely on findings whose provenance you cannot show.
Why it is no longer current
PDAs disappeared into smartphones, and the assumptions underneath the guidance went with them. SP 800-72 predates full-device encryption as a default, cloud synchronisation, secure enclaves, and the current reality that a handset holds more evidential data than the desktop it once accompanied. Its tool recommendations name products that in most cases no longer exist.
NIST hosts SP 800-72 in its legacy archive. Treat it as a historical record of how the discipline handled a new class of device, not as procedure.
What to use instead
For mobile forensics, the current publication is SP 800-101 Revision 1, Guidelines on Mobile Device Forensics (May 2014). It supersedes SP 800-101, Guidelines on Cell Phone Forensics (May 2007), which is withdrawn. Revision 1 covers the same ground for modern handsets and adds a validation phase ahead of preservation — a direct response to the growth of forensic tooling whose output has to be verified before it is relied upon.
Two related publications are usually more relevant to organisations than to specialist examiners:
- SP 800-86, Guide to Integrating Forensic Techniques into Incident Response (September 2006) — how forensic capability fits into incident handling, rather than how to examine a particular device.
- SP 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management (April 2025) — the current incident response guidance, restructured as a Cybersecurity Framework 2.0 community profile. It supersedes Revision 2, the Computer Security Incident Handling Guide.
Talk to a SubRosa security engineer
Get a straight answer on where your defenses actually stand. No pitch, no obligation.
Book a consultationHow the NIST SP 800 series is organised
The SP 800 series is NIST's computer security publication line, run by the Information Technology Laboratory. It contains guidelines, recommendations and technical specifications. Most of it is not law: it becomes binding when a regulator, a contract or a framework references it, which happens often enough that the distinction is easy to lose.
The numbers are issue order, not hierarchy. SP 800-72 is not a subdivision of SP 800-7, and a higher number implies nothing about scope or importance. Revisions are marked separately — SP 800-53 Rev. 5, SP 800-171 Rev. 3 — and a revision supersedes the version before it in full. A publication can be current, revised, or withdrawn, and it is worth checking which before citing one.
The SP 800 publications most organisations meet
- SP 800-53 — the security and privacy control catalogue used across US federal systems, and the source most other control sets borrow from.
- SP 800-171 — protecting Controlled Unclassified Information in non-federal systems. Revision 3 was published in May 2024 alongside its assessment companion, SP 800-171A Rev. 3. This is the one that reaches defence contractors and their supply chains.
- SP 800-37 — the Risk Management Framework: how to categorise a system, select and implement controls, assess them, and authorise operation.
- SP 800-61 — incident response, now at Revision 3.
- SP 800-63 — digital identity: identity proofing, authentication and federation.
- SP 800-207 — zero trust architecture, and the reference most zero trust programmes cite.
Why archived publications still matter
An archived publication has two remaining uses. It explains older work — an assessment or court submission from 2009 that cites SP 800-72 was correct to do so, and reading the current guidance will not tell you what the examiner was following. And it sometimes still describes the environment in front of you: organisations running legacy handheld equipment in logistics, healthcare and industrial settings will find SP 800-72 closer to their devices than SP 800-101 Rev. 1 is.
What matters is knowing the status of what you cite. A document that is archived, withdrawn or superseded is not thereby wrong, but presenting it as current guidance is — and that distinction is exactly what an auditor, a regulator or opposing counsel will test.
Frequently asked questions
Does NIST SP 800-72 exist?
Yes. NIST Special Publication 800-72, Guidelines on PDA Forensics, was published in November 2004 by Wayne Jansen and Rick Ayers of the NIST Computer Security Division, with sponsorship from the Department of Homeland Security. It is archived rather than current, but it is a genuine publication.
What is NIST SP 800-72 about?
Recovering digital evidence from Personal Digital Assistants — the handheld organisers that preceded smartphones. It covers Pocket PC, Palm OS and Linux-based devices, and sets out procedures for preservation, acquisition, examination, analysis and reporting.
Has NIST SP 800-72 been superseded?
In practice, yes. NIST hosts it as a legacy publication, and mobile device forensics guidance now lives in SP 800-101 Revision 1, Guidelines on Mobile Device Forensics (May 2014), which itself superseded SP 800-101, Guidelines on Cell Phone Forensics (May 2007).
What is the NIST SP 800 series?
NIST’s computer security publication line, produced by its Information Technology Laboratory: guidelines, recommendations and technical specifications covering controls, risk management, identity, incident response and more. The numbers reflect issue order, not hierarchy or importance.
Which NIST SP 800 publications matter most?
SP 800-53 for security and privacy controls, SP 800-171 for protecting Controlled Unclassified Information in non-federal systems, SP 800-37 for the Risk Management Framework, SP 800-61 for incident response, SP 800-63 for digital identity, and SP 800-207 for zero trust architecture.
Can I still cite a withdrawn or archived NIST publication?
You can cite it for what it is — a historical record, or the standard someone was working to at the time. What you cannot do is present it as current guidance. State the status alongside the citation, because an auditor or opposing counsel will check it.