Guide To Computer Forensics and Investigations, Second Edition
Guide To Computer Forensics and Investigations, Second Edition
Forensics and
Investigations,
Second Edition
Chapter 1
Computer Forensics and
Investigations as a Profession
Objectives
1
Understanding Computer Forensics
(continued)
2
Computer Forensics Versus Other
Related Disciplines (continued)
3
Computer Forensics Versus Other
Related Disciplines (continued)
4
Preparing For Computer Investigations
5
Understanding Enforcement Agency
Investigations
• Understand:
– Local city, county, state or province, and federal
laws on computer-related crimes
– Legal processes and how to build a criminal case
6
Following the Legal Process
(continued)
7
Understanding Corporate
Investigations
8
Displaying Warning Banners
(continued)
9
Displaying Warning Banners
(continued)
10
Conducting Security Investigations
(continued)
11
Distinguishing Personal and Company
Property
• Maintaining objectivity
– Sustain unbiased opinions of your cases
• Avoid making conclusions about the findings until
all reasonable leads have been exhausted
• Considered all the available facts
• Ignore external biases to maintain the integrity of
the fact-finding in all investigations
• Keep the case confidential
12
Maintaining Professional Conduct
(continued)
• Stay current with the latest technical changes in
computer hardware and software, networking, and
forensic tools
• Learn about the latest investigation techniques that
can be applied to the case
• Record fact-finding methods in a journal
– Include dates and important details that serve as
memory triggers
– Develop a routine of regularly reviewing the journal
to keep past achievements fresh
Summary
• Computer forensics: systematic accumulation of
digital evidence in an investigation
• Differs from network forensics, data recovery, and
disaster recovery in scope, technique, and
objective
• Laws relating to digital evidence were established
in the late 1960s
• To be successful, you must be familiar with more
than one computing platform
13
Summary (continued)
Summary (continued)
Summary (continued)
14
Questions & Discussion
15