Knowledgebase

Understanding Digital Forensics Print

  • 0

What the discipline does.

WHAT DIGITAL FORENSICS IS

Establishing what happened on a system, from the evidence it holds, in a way that can be relied upon afterwards.

WHERE IT IS USED

After a security incident In employment investigations In disputes about what someone did In fraud investigations Where evidence may be used in proceedings

WHAT DISTINGUISHES IT FROM ORDINARY TROUBLESHOOTING

The findings must withstand challenge.

WHY THAT CHANGES EVERYTHING

Evidence gathered carelessly is worthless, and it can be worse than none.

WHAT THAT REQUIRES

Preserving evidence before examining it Recording what was done Maintaining a record of custody Working on copies rather than originals

WHY ON COPIES

Examining a system changes it, and the original must remain as it was.

WHAT ORGANISATIONS TYPICALLY DO WRONG

Log in to the affected machine to look around Delete what appears malicious Rebuild the system immediately Wait days before preserving anything

WHY EACH DESTROYS EVIDENCE

Access changes timestamps, deletion removes what explains it, rebuilding eliminates everything, and delay allows logs to expire.

WHAT TO ESTABLISH BEFORE ANY INVESTIGATION

What question you are trying to answer.

WHY

It determines what must be preserved and how far to go.

WHAT TO TREAT THIS CATEGORY AS

Guidance for businesses on preserving evidence, conducting proportionate internal investigation, and knowing when to involve specialists.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot