enterprisesecuritymag

| | APRIL 2021ENTERPRISE SECURITY8IN MY OPINIONIN MY OPINIONigital forensics is the act of assisting an investigation by accumulating evidence from digital artifacts. These digital artifacts include computers, network, cloud, hard drive, server, phone, or any endpoint system connected to the infrastructure. The activity also includes collecting information from emails, SMS, images, deleted files, and much more. In short, the responsibility of a digital forensic investigator is a threefold process:· Preserving or recording the state of a digital device· Analyzing the state of digital device· Reporting retrieved informationIn the case of cybercrime, a digital forensic examiner analyzes digital devices and digital data to gather enough evidence to help track the attacker. · The proper protocol should be followed for the acquisition of evidence irrespective of whether it physical or digital. Gentle handling should be exercised for those situations where the device may be damaged.· Special handling may be required for some situations. E.g., when the device is actively destroying data through disk formatting, it may need to be shut down immediately to preserve the evidence. On the other hand, in some situations, it would not be appropriate to shut down the device so that the digital forensics expert can examine the device's temporary memory.· All artifacts, physical and/or digital should be collected, retained and transferred using a preserved chain of custody.· All materials should be date and time stamped, identifying who collected the evidence and the location it is being transported to after initial collection.· Proper logs should be maintained when transferring possession.· When storing evidence, suitable access controls should be implemented and tracked to certify that the evidence has only been accessed by authorized individuals.Forensic readiness helps an organization streamline its activities, so that retrieval of digital evidence becomes streamlined and more efficient. Meaning, the digital evidence is appropriately recorded and stored even before an incident takes place, without interruption of operations. The following is a sample list of scenarios where digital evidence would become necessary: · Disputed transactions· Allegations of employee misconduct· Showing legal and regulatory compliance· Avoidance of negligence and breach-of-contract charges· Assisting law enforcement investigations· Meeting disclosure requirements in civil claims· Supporting insurance claims when a loss occurs Forensic readiness planning is part of a quality information risk management approach. Risk areas have to be identified and assessed, and measures must be taken to avoid and minimize the impact of such risk. Organizations with a good risk assessment and information security framework would find it easier to adopt a forensic readiness plan. A forensic readiness plan should have the following goals: · To gather admissible evidence legally without interfering with business processes· To gather evidence targeting potential crimes and disputes that could have an adverse impact on an organization· To allow investigations to proceed at costs proportional to the incident· To minimize interruption of operations by investigations· To ensure that evidence impacts positively on the outcome of any legal actionThe benefits of forensic readiness planning include:· Preparing for the potential need for digital evidence. In the event that an organization has to go to litigation where digital evidence is required, there will be a need for electronic discovery (e-discovery). · Minimizing the cost of investigations. Because evidence is gathered in anticipation of an incident, costs, as well as the disruption of operations, are minimal, and investigations are efficient and rapidly completed. · Blocking the opportunity for malicious insiders to cover DDigital Forensic Readiness Planning and Readiness Checklist in Order to Reduce Business RiskBy Dr. Rebecca Wynn, Head of Information Security & Data Protection Officer (DPO), Senior Director, Matrix Medical Network
< Page 7 | Page 9 >