Understanding and Complying with Investigations
A cyber investigation can be complex and lengthy. For those reasons, it is important that cybersecurity leadership in an organization has the requisite knowledge of local legislation and law enforcement obligations, as well as the security team’s responsibilities, roles, evidential standards, and strategies needed to collect evidential information on a wide range of artifacts.
It should go without saying that these elements need to be in place before any incident occurs since creating them during the incident will likely result in errors and carry significant risks; incidents may not be handled as well as they should be, and important steps may get missed.
A security program should operate from a clear set of responsibilities, guidelines, and understanding of its own legal obligations and should develop a robust set of practices that are predictable, repeatable, and well practiced so that they can be executed in the heat...