IS4670 CHAPTER 4 TERMS & DEFINITIONS Flashcards
1
Q
- An organization that provides guidelines for managing a forensics lab. ASCLD also certifies computer forensics labs.
A
American society of Crime Laboratory directors (AsCLd)
2
Q
- A reasoned proposal for making a change, such as a plan that justifies acquiring newer and better resources to investigate computer forensics cases.
A
Business case
3
Q
- Records that are produced by a computing device. This information includes logs, content analysis, packet captures, reconstructed artifacts, and so on. The admissibility of computer-generated records depends on their authenticity.
A
Computer-generated information
4
Q
- A process in which an organization records all updates it makes to its workstations.
A
Configuration management
5
Q
- A framework for ensuring forensic soundness that has six classes: identification, preservation, collection, examination, analysis, and presentation.
A
DFRWs framework
6
Q
- A nonprofit volunteer organization that aims to enhance the sharing of knowledge and ideas about digital forensics research. The DFRWS sponsors annual conferences, technical working
A
Digital Forensics Research Workshop (DFRWs)
7
Q
- A plan that helps a lab restore its workstations and file servers to their original condition after a catastrophic failure occurs.
A
Disaster recovery plan
8
Q
- A model for forensic investigation that has five phases: readiness, deployment, physical crime scene investigation, digital crime scene investigation, and presentation.
A
Event-based digital forensic investigation framework
9
Q
- A container that stores evidence and is secured so that no unauthorized person can easily access the evidence. Also known as an evidence locker.
A
Evidence storage container
10
Q
- A room that stores large computer components, such as computers, monitors, and other peripheral devices. It may or may not be located within the lab itself.
A
Evidence storage room
11
Q
- A code of evidence law that governs the admission of facts by which parties in the U.S. federal court system may prove their cases.
A
Federal Rules of Evidence (FRE)
12
Q
- a state in which data is complete and materially unaltered.
A
Forensic soundness
13
Q
- Information created by humans. It includes e-mail messages, text messages, word processing documents, digital photos, and other records that are transmitted or stored electronically.
A
Human-generated information
14
Q
- An individual who performs general management tasks for a computer forensics lab, such as promoting group consensus in decision making, maintaining fiscal responsibility for lab needs, and enforcing ethical standards among staff members.
A
Lab manager
15
Q
- Rules that govern whether, when, how, and why proof of a legal case can be placed before a judge or jury. The rules vary depending on the type of court and the jurisdiction.
A
Rules of evidence