
272 ◾ Information Security Fundamentals
forensic analysis if they are not trained and certified because you can disqualify
good evidence that might win the case. Is this case going to court? Start thinking
E-discovery requirements (Figure 11.2).
How Critical Is It?
ere are several methods of determining how critical the event is. e higher the
critical score, the longer it usually takes and the more people usually get involved.
Tools of the team
Tool/resource
Baselines of network: how has the network changed?
Blank media: for validation
Contact information: team, law, legal, e-mail, public keys, team off-hours phones
Encryption software: team com