Forensic Readiness

Forensic Readiness

Published by pclnmiit

Published by: pclnmiit on Dec 09, 2009
A Ten Step Processfor ForensicReadiness
Prepared By : Moutasem HamourIbrahim Al qaroutSupervised By: Dr. Lo’ai TawalbehNew York Institute of Technology(NYIT)-Jordan’s campus 2006
A forensic investigation of digital evidence iscommonly employed as a post-event response to aserious information security incident. In fact, thereare many circumstances where an organisation maybenefit from an ability to gather and preserve digitalevidence before an incident occurs.
Forensic readiness is defined as the ability of anorganisation to maximise its potential to use digitalevidence whilst minimising the costs of aninvestigation. The costs and benefits of such anapproach are outlined.
Preparation to use digital evidence may involve : - enhanced system .- staff monitoring.- technical.- physical and procedural means to secure data toevidential standards of admissibility.- processes and procedures to ensure that staff recognise the importance and legal sensitivities of evidence.- appropriate legal advice and interfacing with lawenforcement.

