O'Reilly logo

System Forensics, Investigation, and Response by K Rudolph, John R. Vacca

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Chapter 7. Collecting, Seizing, and Protecting Evidence

ORGANIZATIONS ARE BATTLING ATTACKERS with increasingly sophisticated skills. System forensics is crucial to determining how an attack succeeded and developing controls to prevent future strikes. However, companies often make mistakes that prevent successful forensic investigations. They may fail to incorporate security controls to prevent attacks. They may also fail to collect appropriate data to support a forensic examination. Businesses should have their environments forensically ready.

Collecting data as evidence is difficult in any situation. This is why forensic examiners document the process and maintain a chain of custody throughout their investigations. Collecting electronic evidence ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required