1 option
Implementing digital forensic readiness : from reactive to proactive process / Jason Sachowski ; Dmitri Ivtchenko, technical editor.
- Format:
- Book
- Author/Creator:
- Sachowski, Jason, author.
- Language:
- English
- Subjects (All):
- Computer crimes--Investigation.
- Computer crimes.
- Physical Description:
- 1 online resource (378 p.)
- Edition:
- 1st edition
- Place of Publication:
- Amsterdam, [Netherlands] : Syngress, 2016.
- System Details:
- text file
- Summary:
- Implementing Digital Forensic Readiness: From Reactive to Proactive Process shows information security and digital forensic professionals how to increase operational efficiencies by implementing a pro-active approach to digital forensics throughout their organization. It demonstrates how digital forensics aligns strategically within an organization’s business operations and information security’s program. This book illustrates how the proper collection, preservation, and presentation of digital evidence is essential for reducing potential business impact as a result of digital crimes, disputes, and incidents. It also explains how every stage in the digital evidence lifecycle impacts the integrity of data, and how to properly manage digital evidence throughout the entire investigation. Using a digital forensic readiness approach and preparedness as a business goal, the administrative, technical, and physical elements included throughout this book will enhance the relevance and credibility of digital evidence. Learn how to document the available systems and logs as potential digital evidence sources, how gap analysis can be used where digital evidence is not sufficient, and the importance of monitoring data sources in a timely manner . This book offers standard operating procedures to document how an evidence-based presentation should be made, featuring legal resources for reviewing digital evidence. Explores the training needed to ensure competent performance of the handling, collecting, and preservation of digital evidence Discusses the importance of how long term data storage must take into consideration confidentiality, integrity, and availability of digital evidence Emphasizes how incidents identified through proactive monitoring can be reviewed in terms of business risk Includes learning aids such as chapter introductions, objectives, summaries, and definitions
- Contents:
- Front Cover; Implementing Digital Forensic Readiness; Copyright; Contents; Preface; Introduction; About the Author; Acknowledgments; A - Digital Forensics; 1 - Understanding Digital Forensics; INTRODUCTION; HISTORY OF DIGITAL CRIME AND FORENSICS; PROLOGUE (1960-80); INFANCY (1980-95); CHILDHOOD (1995-2005); ADOLESCENCE (2005-15); THE FUTURE (2015 AND BEYOND); DIGITAL FORENSICS OVERVIEW; WHY IS IT IMPORTANT?; LEGAL ASPECTS; COLLECTING DIGITAL EVIDENCE; VOLATILE DATA; NONVOLATILE DATA; ORDER OF VOLATILITY; TYPES OF FORENSIC INVESTIGATIONS; DIGITAL FORENSIC RESOURCES; SUMMARY; TAXONOMY
- 2 - Investigative Process ModelsINTRODUCTION; EXISTING PROCESS MODELS; DIGITAL FORENSIC READINESS MODEL; SUMMARY; 3 - Evidence Management; INTRODUCTION; EVIDENCE RULES; PREPARATION; INFORMATION SECURITY MANAGEMENT; Policies; Guidelines; Standards; Procedures; DIGITAL FORENSIC TEAM; Roles and Responsibilities; Education and Certification; LAB ENVIRONMENT; HARDWARE AND SOFTWARE; GATHERING; OPERATING PROCEDURES; Identification; Securing the Scene; Documenting the Scene; Search and Seizure; Collection and Preservation; PROCESSING; PRESENTATION; SUMMARY; RESOURCES; TAXONOMY
- B - Digital ForensicReadines4 - Understanding Forensic Readiness; INTRODUCTION; DIGITAL FORENSICS AND INFORMATION SECURITY; PROACTIVE ACTIVITIES; REACTIVE ACTIVITIES; WHAT IS FORENSIC READINESS?; COST AND BENEFIT OF FORENSIC READINESS; COST ASSESSMENT; BENEFITS; IMPLEMENTING FORENSIC READINESS; SUMMARY; TAXONOMY; 5 - Define Business Risk Scenarios; INTRODUCTION; WHAT IS BUSINESS RISK?; FORENSIC READINESS SCENARIOS; SCENARIO #1: REDUCING THE IMPACT OF CYBERCRIME; SCENARIO #2: VALIDATING THE IMPACT OF CYBERCRIME OR DISPUTES; Mitigating Control Logs; Overhead Time and Effort
- Indirect Business LossRecovery and Continuity Expenses; SCENARIO #3: PRODUCING EVIDENCE TO SUPPORT ORGANIZATIONAL DISCIPLINARY ISSUES; SCENARIO #4: DEMONSTRATING COMPLIANCE WITH REGULATORY OR LEGAL REQUIREMENTS; SCENARIO #5: EFFECTIVELY MANAGING THE RELEASE OF COURT ORDERED DATA; SCENARIO #6: SUPPORTING CONTRACTUAL AND/OR COMMERCIAL AGREEMENTS; SCENARIO ASSESSMENT; SUMMARY; TAXONOMY; 6 - Identify Potential Data Sources; INTRODUCTION; WHAT IS A DATA SOURCE?; BACKGROUND EVIDENCE; FOREGROUND EVIDENCE; CATALOGING DATA SOURCES; PHASE #1: PREPARATION; PHASE #2: IDENTIFICATION
- PHASE #3: DEFICIENCIESInsufficient Data Availability; Content Awareness; Context Awareness; Unidentified Data Sources; EXTERNAL DATA CONSIDERATIONS; DATA EXPOSURE CONCERNS; FORENSICS IN THE SYSTEM DEVELOPMENT LIFE CYCLE; SUMMARY; TAXONOMY; 7 - Determine Collection Requirements; INTRODUCTION; PRECOLLECTION QUESTIONS; EVIDENCE COLLECTION FACTORS; TIME; METADATA; CAUSE AND EFFECT; CORRELATION AND ASSOCIATION; CORROBORATION AND REDUNDANCY; STORAGE DURATION; STORAGE INFRASTRUCTURE; DATA SECURITY REQUIREMENTS; SUMMARY; TAXONOMY; 8 - Establish Legal Admissibility; INTRODUCTION; LEGAL ADMISSIBILITY
- PRESERVATION CHALLENGES
- Notes:
- Includes bibliographical references and index.
- Description based on print version record.
- ISBN:
- 9780128045015
- 0128045019
- OCLC:
- 961332396
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.