DF




Digital Forensics


What Is Digital Forensics?
 
Digital forensic science is a branch of forensic science that focuses on the recovery and investigation of material found in digital devices related to cybercrime. The term digital forensics was first used as a synonym for computer forensics. Since then, it has expanded to cover the investigation of any devices that can store digital data.

Although the first computer crime was reported in 1978, followed by the Florida computers act, it wasn’t until the 1990s that it became a recognized term. It was only in the early 21st century that national policies on digital forensics emerged.

Digital forensics is the process of identifying, preserving, analyzing, and documenting digital evidence. This is done in order to present evidence in a court of law when required.
Steps of Digital Forensics

In order for digital evidence to be accepted in a court of law, it must be handled in a very specific way so that there is no opportunity for cyber criminals to tamper with the evidence.
 
1. Identification: First, find the evidence, noting where it is stored.
 
2. Preservation: Next, isolate, secure, and preserve the data. This includes preventing people from possibly tampering with the evidence.
 
3. Analysis: Next, reconstruct fragments of data and draw conclusions based on the evidence found.
 
4. Documentation: Following that, create a record of all the data to recreate the crime scene.
 
5. Presentation: Lastly, summarize and draw a conclusion.


When Is Digital Forensics Used in a Business Setting?
 
For businesses, Digital Forensics is an important part of the Incident Response process. Forensic Investigators identify and record details of a criminal incident as evidence to be used for law enforcement. Rules and regulations surrounding this process are often instrumental in proving innocence or guilt in a court of law.