You should be okay updating specific applications so long as they're not part of the digital forensics tools in BitCurator or major system components. The problem with the updater is that if you hit the "update all" button, you could be updating anything as trivial as a web plugin or something as significant as the Linux kernel, so it's best not to use it. Or, rather, to only use it to update applications you know you need to update and can back out of.
Regarding your second question, I would say that is totally up to the individual user. However, keep in mind that if you're installing BitCurator from the ISO and not just using the VirtualBox VM, none of your choices during the install process matter after disk partitioning. You get the customized BitCurator version of Linux no matter what you select (that's why the username and password are always "bcadmin"). So if there were additional software apps that you wanted, you would need to install them after the OS installation process.