16. Laws and regulations - Evidence Flashcards
Laws and regulations - Evidence
Real Evidence
Tangiable and Physical Objects
- Hard disks
- USB drives
- Servers
- NOT the data
Laws and regulations - Evidence
Direct Evidence
Testimony from first hand witness
- witness experienced with their 5 senses
Laws and regulations - Evidence
Circumstantial Evidence
Evidence to support;
1. Circumstances for a point
2. Other evidence
- cannot be used to conclusively prove somebody did something
Laws and regulations - Evidence
Corroborative Evidence
Not facts on their own
Supports facts or elements of the case
- if you have a number of circumstantial evidences that point to a conclusion, this is corroborative
- Each piece of evidence corroborates the fact that X is likely to have happened
Laws and regulations - Evidence
Hearsay
Not first hand knowledge
- Log files are considered hearsay
- Logs however are admissible in a court of law
Laws and regulations - Evidence
Best Evidence
- Accurate
- Complete
- Relevant
- Authentic
- Convincing
Laws and regulations - Evidence
Secondary Evidence
Common in cases involving IT
Logs and documents from systems considered secondary
Laws and regulations - Evidence
Evidence Integrity
Integrity cannot be questioned
- Forensics done on copies, never originals
- Check hash of both original and copy before and after forensics
- if hashes do not match, something has changed and cannot be provided in court of law
Laws and regulations - Evidence
Chain of Custody
To prove integrity of the data
- Prove that no tampering was done
1. Who handled it
2. When did they handle it
3. What did they do with it
4. Where did they handle it
Laws and regulations - Evidence
Reasonable Searches
Evidence obtained legally
- 4th amendment in US contitution - protects citizens from unreasonable search and seizure
- Court will determine if evidence was obtained legally
- Employees must be aware their actions are monitored
Laws and regulations - Evidence
Entrapment
Illegal and Unethical
- someone is persauded to commit a crime they had no intention of
Laws and regulations - Evidence
Enticement
Legal and Ethical
- Making committing a crime more enticing
- Person has already broken the law
- Honeypots are a good example of enticement
Honeypots and Honeynets
Ensure to have signup from;
1. Senior management
2. HR
3. Legal
- Honeypots and nets present both legal and practical risks