"Forensic Computing is the process of identifying, preserving, analyzing and presenting digital evidence in a manner that is legally acceptable" - Rodney McKemmish This week we are introduced to advanced forensics. Our primary goals are to learn how to approach and react to incidents when collecting evidence. We are also going to learn how to set up a forensic environment. There are several case types that require forensic analysis, including but not limited to: fraud, intellectual property theft, data breaches, inappropriate use of Internet, child exploitation, and eDiscovery support for court cases. There are three steps to forensics: evidence acquisition, investigation and analysis, and reporting the findings. There are four principles that have to be applied to every case: minimize data loss, record everything that you do, analyze all data collected, and report your findings. Evidence in computer forensics can be found is many locations such as the operating syste...
Comments
Post a Comment