Businesses urged to devise digital-forensics plans

By Tom Espiner, ZDNet UK
Thursday, December 04, 2008 11:43 AM

Firms should put in place forensics plans for incidents that may require computer evidence to be handed over, according to an influential security body.

The Information Assurance Advisory Council (IAAC) published a report earlier this week, that aims to provide organizations with guidance on retaining computer forensics evidence.

Evidence of disputed transactions, suspected fraud, complaints of negligence, cyber attacks and theft of data is required to support an organization's position in legal proceedings, according to the Directors' and Corporate Advisors' Guide to Digital Investigations and Evidence.

Formulating a "forensics readiness plan" would enable organizations to be prepared for high-frequency, low-impact situations, and should go hand in hand with a disaster-recovery plan, according to the report's author, professor Peter Sommer.

"Unless the organization has developed a detailed planned response to typical risk scenarios, much potential evidence will never be collected or will become worthless as a result of contamination," wrote Sommer, a visiting professor for the London School of Economics. "What is needed is a forensic readiness plan."

Businesses should first identify the threats faced by their organization that may require digital forensic evidence. Firms should then identify to what extent they can already collect that evidence, and what remains to be done. Once organizations have familiarized themselves with potential legal issues--including admissibility, data protection and limits to surveillance--an action plan should be produced, wrote Sommer.

An IAAC guide to digital forensics was first made available in 2005. The present guide was written from scratch by Sommer, in response to changes in technology and the law since 2005.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web