APRIL 2021ENTERPRISE SECURITY| | 9their tracks. When individuals become aware that evidence is being constantly gathered, they are deterred from carrying out malicious activities for fear of being caught. · Reducing the cost of regulatory or legal requirements for disclosure of data. Having the evidence easily at hand and preserved in an acceptable manner makes it possible for it to be easily presented when and as required. · Showing due diligence, good corporate governance, and regulatory compliance. Having good information management policies, such as a forensic readiness policy, shows an organization is on top of incident prevention and response. This helps garner goodwill for the organization, providing customers with a feeling that their transactions are secure and protected.· Uncovering bigger cases. In monitoring acceptable usage of endpoints, malware may be discovered to have infiltrated a system and its source subsequently traced, helping to protect against such attacks in the future.A forensic readiness plan is meant to prepare an organization for an event the occurrence of which cannot be predicted. In preparation, an organization should review and analyze security - technical controls, policies, procedures and skill set. This can be carried out by a skilled forensic investigator, who can recommend proper amendments and action that can be taken to improve upon what is in place and ensure a good forensic readiness plan. The plan should contain a forensic readiness checklist:· Define the business scenarios that would require digital evidence. · Identify potential evidence sources and the types of evidence.· Determine evidence collection requirements.· Establish capability for secure evidence gathering and collection in a forensically sound manner.· Establish a policy for proper chain of custody.· Ensure monitoring targets detection and deterrence of major incidents.· Specify the circumstances at which point the escalation of a full formal digital investigation should commence.· Educate and train staff on incident response and awareness to ensure that they comprehend their role in the digital evidence process and the importance and sensitivity of it.· Document evidence-based cases, describing the incident and its impact.· Ensure legal review to facilitate appropriate action in response to an incident.By following a reactive approach to digital forensic investigations, organizations foster a perception that they lack is initiative for managing risk. Conversely, when organizations implement strategies to proactively gather potential sources of digital evidence in support of the business risk scenarios, they showcase their ability to effectively manage risk.As the world continues to immerse deeper and deeper into digital technologies and devices, it will be critical for organizations to develop a well thought out strategy for digital forensics. An understanding of this space and an appropriately crafted approach can help organizations attain positive outcomes in the cases and investigations involving electronic evidence. The goal of this article was to demystify this space and define high-level criteria to develop Digital Forensic Readiness Planning and Readiness Checklist in order to reduce Business Risk. ESDr. Rebecca WynnOrganizations with a good risk assessment and information security framework would find it easier to adopt a forensic readiness plan
<
Page 8 |
Page 10 >