16. Laws and regulations - Evidence Flashcards

1
Q

Laws and regulations - Evidence

Real Evidence

A

Tangiable and Physical Objects

  • Hard disks
  • USB drives
  • Servers
  • NOT the data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Laws and regulations - Evidence

Direct Evidence

A

Testimony from first hand witness

  • witness experienced with their 5 senses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Laws and regulations - Evidence

Circumstantial Evidence

A

Evidence to support;
1. Circumstances for a point
2. Other evidence

  • cannot be used to conclusively prove somebody did something
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Laws and regulations - Evidence

Corroborative Evidence

A

Not facts on their own
Supports facts or elements of the case

  • if you have a number of circumstantial evidences that point to a conclusion, this is corroborative
  • Each piece of evidence corroborates the fact that X is likely to have happened
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Laws and regulations - Evidence

Hearsay

A

Not first hand knowledge

  • Log files are considered hearsay
  • Logs however are admissible in a court of law
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Laws and regulations - Evidence

Best Evidence

A
  1. Accurate
  2. Complete
  3. Relevant
  4. Authentic
  5. Convincing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Laws and regulations - Evidence

Secondary Evidence

A

Common in cases involving IT
Logs and documents from systems considered secondary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Laws and regulations - Evidence

Evidence Integrity

A

Integrity cannot be questioned

  • Forensics done on copies, never originals
  • Check hash of both original and copy before and after forensics
  • if hashes do not match, something has changed and cannot be provided in court of law
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Laws and regulations - Evidence

Chain of Custody

A

To prove integrity of the data

  • Prove that no tampering was done
    1. Who handled it
    2. When did they handle it
    3. What did they do with it
    4. Where did they handle it
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Laws and regulations - Evidence

Reasonable Searches

A

Evidence obtained legally

  • 4th amendment in US contitution - protects citizens from unreasonable search and seizure
  • Court will determine if evidence was obtained legally
  • Employees must be aware their actions are monitored
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Laws and regulations - Evidence

Entrapment

A

Illegal and Unethical

  • someone is persauded to commit a crime they had no intention of
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Laws and regulations - Evidence

Enticement

A

Legal and Ethical

  • Making committing a crime more enticing
  • Person has already broken the law
  • Honeypots are a good example of enticement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Honeypots and Honeynets

A

Ensure to have signup from;
1. Senior management
2. HR
3. Legal

  • Honeypots and nets present both legal and practical risks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly