Investigating Computer Center Incidents

Robert C. Newman · Auerbach Publications eBooks · 2007

Chapter Objectives Distinguish between white-collar and blue-collar crimes and corporate security violations Identify those processes taken when responding to security and policy violations See how corporate incidents differ from law enforcement investigations Learn specific steps taken when identifying, collecting, and protecting electronic evidence Become familiar with the requirements regarding the chain-of-custody for forensic evidence Look at the possible areas where computer and electronic evidence resides Introduction Computer and electronic evidence consists of data and information that is stored on or transmitted by some device. It is fragile and can be easily damaged, modified, or destroyed. Any corporate security investigator or law enforcement investigator arriving at an incident scene must exercise due diligence. Evidence may be present on cell phones, electronic organizers, personal digital assistants (PDAs), and can be compromised by remote electronic transmissions.

Read the paper · More papers on PaperTik