Summary

Incident response spans a number of disciplines from legal to scientific. Those CSIRT members that have the responsibility for conducting digital forensic examinations should be very familiar with the legal and technical aspects of digital forensics. In addition, they should be familiar with the wide variety of tools and equipment necessary to acquire, examine, and present data discovered during an examination. The proper application of forensic techniques is critical to gain insight into the chain of events that led to the deployment of the CSIRT to investigate an incident. This chapter has delved into the various legal aspects of digital forensics such as the rules of evidence and laws pertaining to cyber crime. Next, the science of digital forensics was discussed, providing an understanding of how the techniques to be discuss have developed. To enhance this knowledge was how these techniques fit into a framework of digital investigations. This lead to the various tools available for digital forensic examiners. In the next chapter, the focus will be on jumping on to the wire with a discussion of network forensics.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.216.117.191