In the enterprise setting, there's no such thing as a digital investigation. Or a physical one. Searching for clues and resolutions requires a blend of disciplines governed by a flexible forensic mind-set.
This article simply echoes a fundamental difference that has long been known by investigators as it relates to forensics. Forensics is one peice of the evidence. The title Forensic Examiner is often confused with an Investigator. They are not the same position. An examiner takes the data given to them and reports on his/her findings. Their expertise is reviewing/examining the forensic evidence provided to them. This evidence is only one piece of the puzzle.
An investigator's role is to put all the peices together. They do not focus on one item, like a computer hard drive, to answer the question.
It is amazing to me the number of companies and corporation who hire forensic experts and expect them to be able to conduct a real investigation. They cant, they have never been trained in the various methodologies of truly looking at everything rather than just the evidence presented to them.
In one article you talk about Anti-forensics and how the tools will hurt investigations. That could not be further from the truth. Though a forensic examiner may not be able to obtain any forensic evidence, an investigator sees the use of the anti-forensic tools as evidence.
The idea that in the good old days there was strictly a digital investigation or a physical investigation is also hogwash. There may have been a digital or physical examination in order to determine what happened and when. It may also point out how to fix the problem.
True investigations answer all the questions of who what where when how and most importantly why. They address all potential sources of evidence not just the physical or digital.
In the case of the financial center employee hacking the hospital, after they figured out the how and who, did they think to look what else he was doing? Did they address the why behind it and the fact that the why may have resulted in other hacks or attacks to their own network.
A true investigation would have revealed this and a trained investigator would know the questions to ask.
Investigations: Merge Ahead
In the enterprise setting, there's no such thing as a digital investigation. Or a physical one. Searching for clues and resolutions requires a blend of disciplines governed by a flexible forensic mind-set.
» View Article
This article simply echoes a fundamental difference that has long been known by investigators as it relates to forensics. Forensics is one peice of the evidence. The title Forensic Examiner is often confused with an Investigator. They are not the same position. An examiner takes the data given to them and reports on his/her findings. Their expertise is reviewing/examining the forensic evidence provided to them. This evidence is only one piece of the puzzle.
An investigator's role is to put all the peices together. They do not focus on one item, like a computer hard drive, to answer the question.
It is amazing to me the number of companies and corporation who hire forensic experts and expect them to be able to conduct a real investigation. They cant, they have never been trained in the various methodologies of truly looking at everything rather than just the evidence presented to them.
In one article you talk about Anti-forensics and how the tools will hurt investigations. That could not be further from the truth. Though a forensic examiner may not be able to obtain any forensic evidence, an investigator sees the use of the anti-forensic tools as evidence.
The idea that in the good old days there was strictly a digital investigation or a physical investigation is also hogwash. There may have been a digital or physical examination in order to determine what happened and when. It may also point out how to fix the problem.
True investigations answer all the questions of who what where when how and most importantly why. They address all potential sources of evidence not just the physical or digital.
In the case of the financial center employee hacking the hospital, after they figured out the how and who, did they think to look what else he was doing? Did they address the why behind it and the fact that the why may have resulted in other hacks or attacks to their own network.
A true investigation would have revealed this and a trained investigator would know the questions to ask.
Dirty Tricks: Social Engineers' Favorite Pickup Lines
Tabletop Exercises: 3 Sample Scenarios
19 Ways to Build Physical Security Into Your Data Center
Get instant notifications when whitepapers, webcasts and case studies are added to our library. Sign up for a Resource Alert now!
CSO Corporate Partners
» More blogs
CSO Perspectives
Santa Clara, California
(ISC)2 members can earn up to 24 CPE Credits!
Trend Micro ranked #1 against real-world malware. Read more.
64-page prescriptive guide to security, compliance, and IT operations.
Removing Barriers To Better Server Virtualization Efficiency
Mining for Gold: Cybercrime Prevention and the Role of Log Management
The Executive Guide to Data Loss Prevention
Organizations can spend up to 50% more on compliance efforts than necessary.
White Paper: A Security Blueprint Delivered From within the Network
Read the RSA report: Security for Business Innovation
Upgrading to VMware vSphere with vWire
Explore the increasing importance of log management as cybercrime threats grow.
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
Implementing Best Practices for Web 2.0 Security
Five Ways to Reduce Your IT Audit Burden
THE IDG NETWORK