Forensic Fundamentals

Forensic science can be defined as the application of scientific principles to legal matters. In an incident, CSIRT members may be called upon to perform analysis on digital evidence acquired during the incident, utilizing digital forensics tools, techniques, and knowledge. To make certain that the evidence is processed correctly and can subsequently be admitted into a courtroom, digital forensic examiners need to understand the legal issues along with the fine points of the digital forensic process.

In this chapter, we will examine the legal statutes that impact the CSIRT and digital forensics examiners as well as the rules that govern how evidence is admitted into court. To give context to actions taken, we will also ...

Get Digital Forensics and Incident Response now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.