0% found this document useful (0 votes)
8 views1 page

Computer Forensics Overview and Process

Computer forensics involves examining digital information from devices, including metadata. The process includes stages such as readiness, evaluation, collection, analysis, presentation, and review, ensuring that data is not altered and an audit trail is maintained. Investigators must be able to explain their actions and the relevance of the data in court.

Uploaded by

Maria Gioffre'
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views1 page

Computer Forensics Overview and Process

Computer forensics involves examining digital information from devices, including metadata. The process includes stages such as readiness, evaluation, collection, analysis, presentation, and review, ensuring that data is not altered and an audit trail is maintained. Investigators must be able to explain their actions and the relevance of the data in court.

Uploaded by

Maria Gioffre'
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Name Forensic Science

Computer Forensics
The word “computer” can mean any device
capable of storing digital information. That
information could be a digital file or the metadata associated with it.
Metadata (data that provides information about other data) can include
when a document was created, who the author is, etc. Computer
forensic examination proceeds through the following stages:

The Readiness stage includes educating the client, as well as testing and
verification of the software and equipment to be used, gaining familiarity
with relevant legislation, and preparing for how to handle unexpected
issues. In the Evaluation stage instuctions are recieved and clarified and
risks are analyzed and mitigated.

In the Collection stage, the examiner usually makes a copy of the


information that is on the device while it is turned off. A write-blocker is
used to make a bit-for-bit copy of the information. The examiner works
from this copy, so that the original is not changed. If a device cannot be
turned off, then the examiner will run a program on the device to copy
the contents of it to his or her own hard drive. This changes the data on
the source computer. However, as long as the examiner can prove that
the actions were necessary and were recorded, and the consequences
of it can be explained in court, evidence obtained is still admissable.

In the Analysis stage, the examiner analyzes what they have found. In the
Presentation stage, the examiner presents their findings. In the Review
stage, the examiner conducts a Lessons Learned assessment, and may
also seek feedback from the client.

Computer forensic investigators must not alter any data on the device in
question which may later be relied upon in court. If they access data,
they must be able to give evidence about the relevance and implications
of thier actions. Finally, they must create and preserve an audit trail of
their actions.

©[Link]

You might also like