Concepts of digital forensics and incident response (DFIR)
In this section, we are going to review the basic concepts of DFIR and the main differences between an event and an incident.
Digital forensics
Digital forensics is a field of expertise that integrates components of criminalistics and informatics. According to the National Institute of Standards and Technology (NIST), Digital forensics is the application of science to the identification, collection, examination, and analysis of data while preserving the integrity of the information and maintaining a strict chain of custody for the data.
This definition's basis is relevant as the application of science refers to the use of clear and proven methodologies, procedures, and tools so that the evidence obtained has reliability and validity in the event of a legal process.
Identifying and collecting potential evidence is an essential part of first-response procedures in a cybersecurity incident. Suppose there is no...