Forensic Procedures Flashcards
What ensures that personnel handle forensics properly, effectively, and in compliance with required regulations?
Forensic Procedures
What are the four main area’s of forensic procedures?
Identification
Collection
Analysis
Reporting
What phase of forensic procedures ensures the scene is safe and secure to prevent evidence contamination, and identifies the scope of evidence to be collected?
Identification
Note: Imagine that you are the police arriving on scene, you have to make sure its safe before you can start investigating.
In what phase must you obtain authorization to collect evidence, and then document and prove the integrity of the evidence as its collected?
COLLECTION
In what phase must you create copies of evidence and use repeatable methods and tools?
ANALYSIS
In what phase do you create a report of the methods and tools used in the investigation, and present the detailed findings?
REPORTING
What is the first ethical principal of collecting forensic data?
The analysis must be performed without bias
What is the second ethical principal of collecting forensic data?
Analysis methods must be repeatable by third parties
What is the third ethical principal of collecting forensic data?
Evidence must not be changed or manipulated
When building a forensic timeline, what are 5 questions you need to answer?
How was access to the system obtained? What tools have been installed? What changes to files were made? What data has been retrieved? Was data exfiltrated?