Advertisement
Promo

Disaster recovery Toolkit

Businesses urged to devise digital-forensics plans

Tom Espiner ZDNet.co.uk

Published: 03 Dec 2008 17:29 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Firms should put in place forensics plans for incidents that may require computer evidence to be handed over, according to an influential security body.

The Information Assurance Advisory Council (IAAC) published a report on Tuesday that aims to provide organisations with guidance on retaining computer forensics evidence.

Evidence of disputed transactions, suspected fraud, complaints of negligence, cyberattacks and theft of data is required to support an organisation's position in legal proceedings, according to the Directors' and Corporate Advisors' Guide to Digital Investigations and Evidence.

Formulating a "forensics readiness plan" would enable organisations to be prepared for high-frequency, low-impact situations, and should go hand in hand with a disaster-recovery plan, according to the report's author, professor Peter Sommer.

"Unless the organisation has developed a detailed planned response to typical risk scenarios, much potential evidence will never be collected or will become worthless as a result of contamination," wrote Sommer, a visiting professor for the London School of Economics. "What is needed is a forensic readiness plan."

Businesses should first identify the threats faced by their organisation that may require digital forensic evidence. Firms should then identify to what extent they can already collect that evidence, and what remains to be done. Once organisations have familiarised themselves with potential legal issues — including admissibility, data protection and limits to surveillance — an action plan should be produced, wrote Sommer.

An IAAC guide to digital forensics was first made available in 2005. The present guide was written from scratch by Sommer, in response to changes in technology and the law since 2005.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Discussions

Tezzer Tezzer

Excuuuuuse me!

Wednesday 2 December 2009, 4:34 PM

3 comments
1000266930 1000266930

Typical dictatorial attitude from the...

Wednesday 2 December 2009, 12:22 PM

3 comments
ator1940 ator1940

ACTA

Wednesday 2 December 2009, 12:07 PM

3 comments
hkommedal hkommedal

It certainly does.

Wednesday 2 December 2009, 12:15 AM

5 comments
Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters