ENGLISH

Implementing Digital Forensic Readiness: From Reactive to Proactive Process

Book information

Publisher
CRC Press
Year
2019
ISBN
1138338958, 9781138338951
Language
english
Format
PDF
Filesize
12 MB (12463836 bytes)
Edition
2
Pages
xxii+480\503
Topic
Computers Security
Time added
2020-02-16 12:52:16

Description

Implementing Digital Forensic Readiness: From Reactive to Proactive Process, Second Edition presents the optimal way for digital forensic and IT security professionals to implement a proactive approach to digital forensics. The book details how digital forensic processes can align strategically with business operations and an already existing information and data security program. Detailing proper collection, preservation, storage, and presentation of digital evidence, the procedures outlined illustrate how digital evidence can be an essential tool in mitigating risk and redusing the impact of both internal and external, digital incidents, disputes, and crimes. By utilizing a digital forensic readiness approach and stances, a company's preparedness and ability to take action quickly and respond as needed. In addition, this approach enhances the ability to gather evidence, as well as the relevance, reliability, and credibility of any such evidence. New chapters to this edition include Chapter 4 on Code of Ethics and Standards, Chapter 5 on Digital Forensics as a Business, and Chapter 10 on Establishing Legal Admissibility. This book offers best practices to professionals on enhancing their digital forensic program, or how to start and develop one the right way for effective forensic readiness in any corporate or enterprise setting. Cover Half Title Title Page Copyright Page Table of Contents Preface Acknowledgments Introduction Author Section I: ENABLING DIGITAL FORENSICS 1: Understanding Digital Forensics Introduction The Role of Technology in Crime History of Digital Crime and Forensics Prologue (1960s–1980s) Infancy (1980–1995) Childhood (1995–2005) Adolescence (2005–2015) The Future (2015 and Beyond) Evolutionary Cycle of Digital Forensics “Ad Hoc” Phase “Structured” Phase “Enterprise” Phase Principles of Digital Forensics Evidence Exchange Forensics Soundness Authenticity and Integrity Chain of Custody Types of Forensics Investigations Legal Aspects Jurisdiction Digital Forensics Resources Summary 2: Investigative Process Methodology Introduction Existing Process Models Digital Forensics Readiness Model Summary 3: Digital Evidence Management Introduction Types of Digital Evidence Common Sources of Digital Evidence Log Files Computer Systems Infrastructure Devices Virtual Systems Cloud Computing Mobile Devices External Sources Federal Rules of Evidence Investigative Process Methodology Preparation Information Security Management Lab Environment Hardware and Software Gathering Operating Procedures Processing Presentation Evidence Storage Networks Summary 4: Ethics and Conduct Introduction Importance of Ethics Principles of Ethics Personal Ethics Professional Ethics Computer Ethics Business Ethics Ethics in Digital Forensics Certifications and Professional Organizations Digital Forensics Certification Board (DFCB) International Association of Computer Investigative Specialists (IACIS) International Society of Forensics Computer Examiners (ISFCE) Principles for Digital Forensics Impartiality and Objectivity Openness and Disclosure Confidentiality and Trust Due Diligence and Duty of Care Certifications and Accreditations Summary 5: Digital Forensics as a Business Introduction The Role of Digital Forensics in an Enterprise Starting a Digital Forensics Program Step #1: Understand Business Risks Step #2: Outline Business Scenarios Step #3: Establish Governance Framework Step #4: Enable Technical Execution Step #5: Define Service Offerings Maintaining a Digital Forensics Program Educational Roadmap Forensics Toolkit Maintenance Key Performance Indicators (KPI) Resource Capacity Challenges and Strategies Team Placement Industry Regulation Political Influences Summary Section II: ENHANCING DIGITAL FORENSICS 6: Understanding Digital Forensic Readiness Introduction What Is Digital Forensics Readiness? Costs and Benefits of Digital Forensics Readiness Cost Assessment Benefits Analysis Implementing Forensics Readiness Summary 7: Defining Business Risk Scenarios Introduction What Is Business Risk? Forensics Readiness Scenarios Scenario #1: Reduce the Impact of Cybercrime Scenario #2: Validate the Impact of Cybercrime or Disputes Mitigating Control Logs Overhead Time and Effort Indirect Business Loss Recovery and Continuity Expenses Scenario #3: Produce Evidence to Support Organizational Disciplinary Issues Scenario #4: Demonstrating Compliance with Regulatory or Legal Requirements Scenario #5: Effectively Manage the Release of Court- Ordered Data Scenario #6: Support Contractual and Commercial Agreements Scenario Assessment Summary 8: Identify Potential Data Sources Introduction What Is a Data Source? Background Evidence Foreground Evidence Cataloguing Data Sources Phase #1: Prepare an Action Plan Phase #2: Identify Data Sources Phase #3: Document Deficiencies Insufficient Data Availability Unidentified Data Sources External Data Considerations Data Exposure Concerns Forensic Architectures Systems Lifecycle Waterfall and Agile Models Summary 9: Determine Collection Requirements Introduction Pre-collection Questions Evidence Collection Factors Best Evidence Rule Time Metadata Cause and Effect Correlation and Association Corroboration and Redundancy Storage Duration Storage Infrastructure Data Security Requirements Summary 10: Establishing Legal Admissibility Introduction Legal Admissibility Preservation Challenges Preservation Strategies Administrative Controls Policies Guidelines Standards Procedures Technical Controls Storage Security Integrity Monitoring Cryptographic Algorithms Remote Logging Secure Delivery Physical Controls Deter Detect Deny Delay Summary 11: Establish Secure Storage and Handling Introduction Secure Storage Attributes Least Privilege Access End-to-End Cryptography Integrity Checking Physical Security Administrative Governance Foundations Personnel Evidence Storage Evidence Handling Incident and Investigative Response Assurance Controls Backup and Restoration Strategies Near Real-Time Data Replication Data Replication Data Restoration from On-line Backup Media Data Restoration from Off-line Backup Media Summary 12: Enabling Targeted Monitoring Introduction What Is (un)acceptable Activity? Digital Forensics in Enterprise Security Information Security vs. Cyber Security Defense-in-Depth Traditional Security Monitoring Modern Security Monitoring Positive Security Australian Signal Directorate (ASD) Analytical Techniques Misuse Detection Anomaly Detection Specification-Based Detection Machine Learning Extractive Forensics Inductive Forensics Deductive Forensics Implementation Concerns Summary 13: Mapping Investigative Workflows Introduction Incident Management Lifecycle Integrating the Digital Forensic Readiness Model Incident Handling and Response Phase #1: Preparation “Event” versus “Incident” Policies, Plans, and Procedures Team Structure and Models Communication and Escalation Escalation Management Phase #2: Respond Detection Analysis Prioritization Phase #3: Restore Containment Eradication and Recovery Phase #4: Learn The Incident Response Team (IRT) The Role of Digital Forensics During an Incident Practitioner Advisor Investigation Workflow Types of Security Investigations Summary 14: Establish Continuing Education Introduction Types of Education and Training Awareness Basic Knowledge Functional Knowledge Professional Certification Specialized Knowledge Organizational Roles and Responsibilities The Digital Forensics Team Roles Titles An Educational Roadmap Technical Knowledge Introductory Intermediate Advanced Non-Technical Knowledge Introductory Intermediate Advanced Digital Forensics Experts Summary 15: Maintaining Evidence-Based Reporting Introduction Importance of Factual Reports Types of Reports Creating Understandable Reports Arranging Written Reports Inculpatory and Exculpatory Evidence Summary 16: Ensuring Legal Review Introduction The Role of Technology in Crime Laws and Regulations Information Technology (IT) Law Cyberlaw or Internet Law Computer Law Legal Precedence Brady Rule: Inculpatory and Exculpatory Evidence Frye versus Daubert Standard: General Acceptance Testing Jurisdiction Technology Counselling Obtaining Legal Advice Constraints Disputes Employees Liabilities Prosecution Communication Involving Law Enforcement Summary 17: Accomplishing Digital Forensic Readiness Introduction Maintain a Business-Centric Focus Don’t Reinvent the Wheel Understand Costs and Benefits Summary Section III: INTEGRATING DIGITAL FORENSICS 18: Forensics Readiness in Cloud Environments Introduction Brief History of Cloud Computing What Is Cloud Computing? Characteristics Service Models Delivery Models Isolation Models Challenges with Cloud Environments Mobility Hyper-Scaling Containerization First Responders Evidence Gathering and Processing Forensics Readiness Methodology Step #1: Define Business Risk Scenarios Step #2: Identify Potential Data Sources Step #3: Determine Collection Requirements Enterprise Management Strategies Cloud Computing Governance Security and Configuration Standards Reference Architectures Step #4: Establish Legal Admissibility Layers of Trust Step #5: Establish Secure Storage and Handling Step #6: Enable Targeted Monitoring Step #7: Map Investigative Workflows Phase #1: Preparation Phase #2: Gathering Phase #3: Processing Phase #4: Presentation Step #8: Establish Continuing Education General Awareness Basic Training Formal Education Step #9: Maintain Evidence-Based Presentations Step #10: Ensure Legal Review Contractual Agreements Summary 19: Forensics Readiness with Mobile Devices Introduction Brief History of Mobile Devices Challenges with Mobile Devices Loss Theft Replacement Local Storage Cloud Storage Encryption “Burner” Phones Forensics Readiness Methodology Step #1: Define Business Risk Scenarios Step #2: Identify Potential Data Sources Step #3: Determine Collection Requirements Enterprise Management Strategies Step #4: Establish Legal Admissibility Step #5: Establish Secure Storage and Handling Step #6: Enable Targeted Monitoring Step #7: Map Investigative Workflows Phase #1: Preparation Phase #2: Gathering Phase #3: Processing Phase #4: Presentation Step #8: Establish Continuing Education General Awareness Basic Training Formal Education Step #9: Maintain Evidence-Based Presentation Step #10: Ensure Legal Review Summary 20: Forensics Readiness and the Internet of Things Introduction Brief History of the Internet of Things (IoT) What Is the Internet of Things (IoT)? Challenges with the Internet of Things (IoT) Form Factor Security Privacy Evidence Gathering and Processing Forensics Toolkits Forensics Readiness Methodology Step #1: Define Business Risk Scenarios Step #2: Identify Potential Data Sources Step #3: Determine Collection Requirements Step #4: Establish Legal Admissibility Zones of Trust Step #5: Establish Secure Storage and Handling Step #6: Enable Targeted Monitoring Step #7: Map Investigative Workflows Phase #1: Preparation Phase #2: Gathering Phase #3: Processing Phase #4: Presentation Step #8: Establish Continuing Education General Awareness Basic Training Formal Education Step #9: Maintain Evidence-Based Presentation Step #10: Ensure Legal Review Discrimination Privacy Security Consent Summary Section IV: ADDENDUMS Addendum A: Tool and Equipment Validation Program Addendum B: Service Catalog Addendum C: Cost-Benefit Analysis Addendum D: Building a Taxonomy Addendum E: Risk Assessment Addendum F: Threat Modeling Addendum G: Data Warehousing Introduction Addendum H: Requirements Analysis Section V: APPENDIXES Appendix A: Investigative Process Models Appendix B: Education and Professional Certifications Appendix C: Investigative Workflow Section VI: TEMPLATES Template 1: Test Case Template 2: Logbook Template 3: Chain of Custody Template 4: Investigative Final Report Template 5: Service Catalog Template 6: Business Case Template 7: Net Present Value (NPV) Template 8: Threat Risk Assessment Template 9: Data Source Inventory Matrix Template 10: Project Charter Template 11: Requirement Analysis Report Bibliography Resources Glossary Index

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

1809 · PDF