week 24 - forensics: investigation 101 Flashcards
what is evidence?
information/material used to refute or support an allegation/belief
what are the 2 categories of evidence?
spoken evidence verbal
physical evidence
tangible
ASCII ?
american standard for information interchange - assigns numerical value to letters and characters
hexadecimal (base 16 system)
0-9 then letters a-f - thus 16 different values instead of 10 (decimal 0-15)
forensic readiness?
planning for cyber security attacks- aim to preserve relevant digital data
document, document, document
preservation
detailed, meticulous record keeping is a core skill for the digital forensic investigator
contemporaneous notes
notes taken at the time of the event
CoC
chain of custody, every effort must be made to preserve evidence
CoC is also the name of the form - change of custody of location