Forensic procedures in incident response
As was stated in the previous chapter, digital forensics is an important component of incident response. It is often the application of digital forensics methods that allows incident responders to gain a clear understanding of the chain of events that led to a malicious action, such as a compromised server or other data breach. For other incidents, such as internal fraud or malicious insider activity, digital forensics may provide the proverbial smoking gun that points to the guilty party. Before a detailed examination of tools and techniques available to incident responders, it is critical to address the foundational elements of digital forensics. These elements not only provide context for specific actions but also a method to ensure that evidence made part of an incident investigation is usable.
A brief history of digital forensics
Law enforcement first started to pay attention to the role that computers play in criminal activity in...