Digital Forensics and Investigations: People, Process, and Technologies to Defend the Enterprise

Jason Sachowski

商品描述

Digital forensics has been a discipline of Information Security for decades now. Its principles, methodologies, and techniques have remained consistent despite the evolution of technology, and, ultimately, it and can be applied to any form of digital data. However, within a corporate environment, digital forensic professionals are particularly challenged. They must maintain the legal admissibility and forensic viability of digital evidence in support of a broad range of different business functions that include incident response, electronic discovery (ediscovery), and ensuring the controls and accountability of such information across networks.

 

Digital Forensics and Investigations: People, Process, and Technologies to Defend the Enterprise provides the methodologies and strategies necessary for these key business functions to seamlessly integrate digital forensic capabilities to guarantee the admissibility and integrity of digital evidence. In many books, the focus on digital evidence is primarily in the technical, software, and investigative elements, of which there are numerous publications. What tends to get overlooked are the people and process elements within the organization.

 

Taking a step back, the book outlines the importance of integrating and accounting for the people, process, and technology components of digital forensics. In essence, to establish a holistic paradigm―and best-practice procedure and policy approach―to defending the enterprise. This book serves as a roadmap for professionals to successfully integrate an organization’s people, process, and technology with other key business functions in an enterprise’s digital forensic capabilities.

商品描述(中文翻譯)

數位取證已經是資訊安全領域的一個學科數十年了。儘管科技不斷演進,但其原則、方法論和技術一直保持一致,最終可以應用於任何形式的數位數據。然而,在企業環境中,數位取證專業人員面臨特殊挑戰。他們必須在支援各種不同的業務功能(包括事件回應、電子發現和確保跨網路的控制和負責任性)的同時,維護數位證據的法律可採納性和取證可行性。

《數位取證與調查:保護企業的人員、流程和技術》提供了實現這些關鍵業務功能所需的方法和策略,以無縫整合數位取證能力,以確保數位證據的可採納性和完整性。在許多書籍中,對數位證據的關注主要集中在技術、軟體和調查元素上,有許多相關出版物。但往往忽視了組織內的人員和流程元素。

回顧一下,本書概述了整合和考慮數位取證的人員、流程和技術組件的重要性。本質上,建立一個全面的範式,以及保護企業的最佳實踐程序和政策方法,以防禦企業。本書為專業人士提供了一個路線圖,以成功地將組織的人員、流程和技術與企業的數位取證能力的其他關鍵業務功能無縫整合。