Understanding forensic concepts
An organization must be prepared to undertake computer forensics to support both legal investigations and internal corporate purposes. When considering different scenarios, it will be important to understand where external agencies or law enforcement need to be involved. If the investigation is to be performed by internal staff, then they should have the appropriate training and tools. Guidance for integrating forensic techniques into incident response is covered in NIST SP800-86. More information can be found here: https://tinyurl.com/nistsp80086.
Forensic process
It is important to follow the correct forensic process. This can be broken down into four steps, as shown in the following diagram:
These four steps are covered in the following list. We will discuss the appropriate tools to be used in more detail later in this chapter:
- Data collection involves identifying sources...