It is very important because during the investigation

  • No School
  • AA 1
  • 72

This preview shows page 11 - 21 out of 72 pages.

It is very important because during the investigation you need to get access or need to make copies of the sensitive data, if the written permission is not with you then you may find yourself in trouble for breaching the IT security policy
Image of page 11
6. Be ready to testify Since you are collecting the evidence than you should make yourself ready to testify it in the court, otherwise the collected evidence may become inadmissible
Image of page 12
7. Your action should be repeatable You should be confident enough to perform the same action again to prove the authenticity of the evidence You should be confident enough to perform the same action again to prove the authenticity of the evidence Make sure to document every step taken. Make sure to document every step taken. Do not work on trial-and -error, else no one is going to believe you and your investigation. Do not work on trial-and -error, else no one is going to believe you and your investigation.
Image of page 13
fast to reduce data loss Work fast to eliminate the chances of data loss, volatile data may lost if not collected in time. While automation can also be introduced to speed up the process, do not create a rush situation. Increase the human workforce where needed. Always start collecting data from volatile evidence
Image of page 14
shut down before collecting evidence This is a rule of thumb, since the collection of data or evidence itself is important for an investigation. You should make sure not to shut down the system before you collect all the evidence. If the system is shut down, then you will lose the volatile data. Shutdown and rebooting should be avoided at all cost
Image of page 15
program on the affected system Collect all the evidence, copy them, create many duplicates and work on them. Do not run any program, otherwise you may trigger something that you don't want to trigger. Think of a Trojanhorse.
Image of page 16
A's of Computer Forensics Acquire the evidence without altering or damaging the original. Authenticate that the recovered evidence is same as the original seized data. Analyze data without any alterations
Image of page 17
Current computer Forensic tools Computer forensics tools are constantly being developed, updated, patched, and revised. Therefore, checking vendors’ Web sites routinely to look for new features and improvements is important. Before purchasing any forensics tools, consider whether the tool can save you time during investigations and whether that time savings affects the reliability of data you recover.
Image of page 18
Evaluating Computer Forensics Tool Needs Some questions to ask when evaluating computer forensic tools: On which O S does the forensics tool run? Is the tool versatile? For example, does it work in Windows different versions and produce the same results in all versions? Can the tool analyze more than one file system, such as FAT, NTFS, and Ext fs?
Image of page 19
Can a scripting language be used with the tool to automate repetitive functions and tasks?
Image of page 20
Image of page 21

You've reached the end of your free preview.

Want to read all 72 pages?

  • Fall '19
  • Computer Forensics

What students are saying

  • Left Quote Icon

    As a current student on this bumpy collegiate pathway, I stumbled upon Course Hero, where I can find study resources for nearly all my courses, get online help from tutors 24/7, and even share my old projects, papers, and lecture notes with other students.

    Student Picture

    Kiran Temple University Fox School of Business ‘17, Course Hero Intern

  • Left Quote Icon

    I cannot even describe how much Course Hero helped me this summer. It’s truly become something I can always rely on and help me. In the end, I was not only able to survive summer classes, but I was able to thrive thanks to Course Hero.

    Student Picture

    Dana University of Pennsylvania ‘17, Course Hero Intern

  • Left Quote Icon

    The ability to access any university’s resources through Course Hero proved invaluable in my case. I was behind on Tulane coursework and actually used UCLA’s materials to help me move forward and get everything together on time.

    Student Picture

    Jill Tulane University ‘16, Course Hero Intern

Stuck? We have tutors online 24/7 who can help you get unstuck.
A+ icon
Ask Expert Tutors You can ask You can ask You can ask (will expire )
Answers in as fast as 15 minutes
A+ icon
Ask Expert Tutors