Computer Forensics Flashcards
What is Computer Forensics?
Set of methodological procedures and techniques that help identify, gather, preserve, extract, interpret, document and present evidence from computing equipment, such that any discovered evidence is acceptable during a legal and/or administrative proceeding.
What are the objectives of Computer Forensics?
- Identify, gather and preserve the evidence.
- Estimate the potential impact.
- Assess the intent of the perpetrator.
- Minimize the losses (tangible and intangible).
- Protect from the similar incidents in the future.
- Support the prosecution of the perpetrator.
Impact of Cybercrimes at the Organizational Level
- Loss of confidentiality, integrity and availability.
- Data theft.
- Disruption of business activities.
- Loss of customer and stakeholder trust.
- Reputational damage.
- Financial losses.
- Penalties arising from the failure to comply with regulations.
What is Digital Evidence?
Any information of probative value that is either stored or transmitted in a digital form.
What does Locard’s Exchange Principle say?
Anyone or anything entering a crime scene takes something of the scene with them, and leaves something of themselves behind when they leave.
What are the rules of evidence?
- Understandable
- Admissible
- Authentic
- Reliable
- Complete
What does it mean that evidence has to be complete?
Prove the attacker’s actions of his/her innocence.
What is the best evidence rule?
The court only allows the original evidence of a document, photograph or recording at the trail rather than a copy.