Applying Resource Protection
Both forensic and backup data are sensitive and must be protected against leaks, destruction, or modification. This section will discuss some resource protection approaches such as media management, media protection techniques, and “break-glass” (or emergency access) scenarios.
Media Management
Media with forensic data is subject to a chain of custody and must be kept in a secure physical location when not needed.
Backups are usually stored in a secure location offsite so that they can be accessed even when the data center is unavailable. Cloud backups often use replication in the cloud to ensure that a copy is kept in several locations.
Media Protection Techniques
A number of techniques can be used to protect media when not in active use:
- Offline backup: This approach focuses on ensuring that the backups cannot be modified through a compromise of the network by keeping the backup system offline or on an airgapped network...