The role of Digital Forensics
Digital forensics usage
May be used in every phase of IR
Heavily used for investigations
Remember to not interferewith overall IR process
Forensics resources will usually be shared
Supporting role
Forensics is a supporting function
Not IR itself
Goal of forensics in IT is different from traditional forensics
Traditional primary goal was evidence preservation and admissibility
IR forensics primary goal is usually help move from one phase to the other
Admissibility is a consideration, but usually not primary
Vitally important function
Needed to answer IR questions
Often needed to add context to discovered artifacts
Key component of investigative functions
Traditional forensics procedures
May not work
Could be contrary to IR goals
Could interfere with IR goals
Traditional forensics analyst need IR training to work in IR
Maintaining evidence gathered
Evidence should still be life-cycled
Still follow sound forensics procedure
Documentation and chains of custody can still apply
Refer to overall corporate or agency security policy on evidence maintenance
Last updated