Summary
Incident response spans a number of disciplines from legal to scientific. Those CSIRT members that have the responsibility for conducting digital forensic examinations should be very familiar with the legal and technical aspects of digital forensics. In addition, they should be familiar with the wide variety of tools and equipment necessary to acquire, examine, and present data discovered during an examination. The proper application of forensic techniques is critical to gain insight into the chain of events that led to the deployment of the CSIRT to investigate an incident. This chapter has delved into the various legal aspects of digital forensics such as the rules of evidence and laws pertaining to cyber crime. Next, the science ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access