What the discipline does.
WHAT DIGITAL FORENSICS IS
Establishing what happened on a system, from the evidence it holds, in a way that can be relied upon afterwards.
WHERE IT IS USED
After a security incident In employment investigations In disputes about what someone did In fraud investigations Where evidence may be used in proceedings
WHAT DISTINGUISHES IT FROM ORDINARY TROUBLESHOOTING
The findings must withstand challenge.
WHY THAT CHANGES EVERYTHING
Evidence gathered carelessly is worthless, and it can be worse than none.
WHAT THAT REQUIRES
Preserving evidence before examining it Recording what was done Maintaining a record of custody Working on copies rather than originals
WHY ON COPIES
Examining a system changes it, and the original must remain as it was.
WHAT ORGANISATIONS TYPICALLY DO WRONG
Log in to the affected machine to look around Delete what appears malicious Rebuild the system immediately Wait days before preserving anything
WHY EACH DESTROYS EVIDENCE
Access changes timestamps, deletion removes what explains it, rebuilding eliminates everything, and delay allows logs to expire.
WHAT TO ESTABLISH BEFORE ANY INVESTIGATION
What question you are trying to answer.
WHY
It determines what must be preserved and how far to go.
WHAT TO TREAT THIS CATEGORY AS
Guidance for businesses on preserving evidence, conducting proportionate internal investigation, and knowing when to involve specialists.