Foreword |
|
xxiii | |
Preface |
|
xxv | |
Acknowledgments |
|
xxvii | |
|
Section I Creating a Digital Forensics Laboratory |
|
|
1 | (110) |
|
An Introduction to Digital Forensics |
|
|
5 | (15) |
|
|
6 | (1) |
|
|
6 | (1) |
|
Principles of Digital Forensics |
|
|
7 | (11) |
|
|
8 | (1) |
|
Phases of a Digital Forensic Investigation |
|
|
9 | (1) |
|
|
10 | (1) |
|
|
11 | (1) |
|
Potential Sources of Evidence |
|
|
11 | (1) |
|
The Digital Forensic Examiner |
|
|
12 | (2) |
|
|
14 | (1) |
|
|
14 | (3) |
|
Legal Aspects of Digital Forensics |
|
|
17 | (1) |
|
|
18 | (172) |
|
|
18 | (2) |
|
Types of Digital forensic Investigation |
|
|
19 | (8) |
|
|
20 | (1) |
|
Reasons for Conducting a Digital Forensic Investigation |
|
|
20 | (6) |
|
The role of the Computer in a Crime |
|
|
20 | (1) |
|
Tupes of Devices and Systems that May Require Investigation |
|
|
20 | (1) |
|
Issues to Be Considered When Dealing with a Single Computer |
|
|
21 | (1) |
|
Issues to Be Considered When Dealing with a Networked Computer |
|
|
21 | (1) |
|
Issues to Be Considered When Dealing with Handheld Devices |
|
|
22 | (1) |
|
|
23 | (1) |
|
Reasons for Conducting an Investigation |
|
|
24 | (1) |
|
|
24 | (1) |
|
Civil Litigation Investigations |
|
|
24 | (1) |
|
|
25 | (1) |
|
|
25 | (1) |
|
|
26 | (1) |
|
|
26 | (1) |
|
Establishing and Managing a Digital Forensics Laboratory |
|
|
27 | (20) |
|
|
28 | (1) |
|
Establishing the Laboratory |
|
|
28 | (17) |
|
The Role of the Laboratory |
|
|
29 | (1) |
|
|
30 | (1) |
|
Staff Considerations---Digital Forensics Laboratory Management |
|
|
30 | (1) |
|
Staff Considerations---Staff Levels and Roles |
|
|
31 | (1) |
|
|
32 | (1) |
|
Staff Training and Experience |
|
|
33 | (1) |
|
Staff and Laboratory Productivity |
|
|
33 | (1) |
|
|
33 | (1) |
|
Outsourcing Policies and the Use of External Experts |
|
|
34 | (1) |
|
Accommodation Requirements |
|
|
34 | (2) |
|
Other Issues to Consideration in the Development of the Laboratory |
|
|
36 | (1) |
|
An xample of a Digital Forensics Laboratory |
|
|
37 | (1) |
|
Identification of the ``Customer'' Base |
|
|
38 | (1) |
|
|
38 | (1) |
|
Quality Review Procedures |
|
|
39 | (1) |
|
|
39 | (1) |
|
|
39 | (1) |
|
|
39 | (1) |
|
|
40 | (1) |
|
|
40 | (1) |
|
|
41 | (1) |
|
Ditigal Forensics Software |
|
|
41 | (1) |
|
|
41 | (1) |
|
|
42 | (1) |
|
|
43 | (1) |
|
|
43 | (1) |
|
Data Retention and Storage Policy |
|
|
44 | (1) |
|
The Reporting of Findings |
|
|
44 | (1) |
|
|
44 | (1) |
|
|
44 | (1) |
|
|
45 | (2) |
|
|
45 | (2) |
|
Scoping the Requirement for the Laboratory |
|
|
47 | (12) |
|
|
48 | (1) |
|
|
48 | (2) |
|
|
50 | (1) |
|
The Hardware and Software |
|
|
50 | (8) |
|
Forensic Analysis Workstations |
|
|
50 | (2) |
|
|
52 | (1) |
|
Mobile Device Imaging Stations |
|
|
53 | (1) |
|
|
54 | (1) |
|
|
55 | (1) |
|
|
56 | (1) |
|
|
56 | (1) |
|
Updates, Maintenance, Equipment Obsolescence, and Retirement |
|
|
56 | (2) |
|
|
58 | (1) |
|
Developing the Business Plan |
|
|
59 | (12) |
|
|
60 | (1) |
|
|
60 | (10) |
|
|
70 | (1) |
|
|
70 | (1) |
|
|
71 | (8) |
|
|
72 | (1) |
|
The Location of a Laboratory |
|
|
72 | (6) |
|
|
75 | (1) |
|
|
75 | (1) |
|
|
76 | (1) |
|
|
76 | (1) |
|
|
77 | (1) |
|
|
78 | (1) |
|
|
78 | (1) |
|
|
78 | (1) |
|
|
79 | (8) |
|
|
80 | (1) |
|
Roles within the Laboratory |
|
|
80 | (1) |
|
|
80 | (1) |
|
Digital Forensics Examiners/Analysts |
|
|
80 | (1) |
|
Case Investigator/Managers |
|
|
80 | (1) |
|
|
81 | (1) |
|
|
81 | (3) |
|
Qualifications vs. Experience |
|
|
81 | (1) |
|
Pre-Empployment Screening |
|
|
82 | (1) |
|
|
83 | (1) |
|
|
84 | (1) |
|
|
84 | (1) |
|
Ancillary and Contract Staff |
|
|
85 | (1) |
|
|
86 | (1) |
|
|
87 | (14) |
|
|
88 | (1) |
|
|
88 | (12) |
|
|
89 | (1) |
|
Training: The Good, the Bad, and the Ugly |
|
|
89 | (1) |
|
|
90 | (2) |
|
|
92 | (1) |
|
Developing Specializations |
|
|
92 | (2) |
|
|
94 | (1) |
|
Assessing Training and Competence |
|
|
94 | (3) |
|
|
97 | (1) |
|
|
97 | (2) |
|
Protecting Your Investment |
|
|
99 | (1) |
|
|
100 | (1) |
|
|
100 | (1) |
|
Legislation, Regulation, and Standards |
|
|
101 | (10) |
|
|
102 | (1) |
|
The Doctrine of Documentary Evidence |
|
|
102 | (1) |
|
Prevailing Health and Safety Laws in the UK |
|
|
103 | (7) |
|
The Health & Safety at Work Act 1974 |
|
|
103 | (1) |
|
The Management of Health & Safety at Work Regulatins Act 1999 |
|
|
104 | (1) |
|
The Electricity at Work Regulations Act 1989 |
|
|
104 | (1) |
|
The Provision and Use of Work Equipment Regulations (PUWER) 1998 |
|
|
104 | (6) |
|
|
110 | (1) |
|
|
110 | (1) |
|
Section II Digital Forensic Incident and Crime Investigation Management |
|
|
111 | (66) |
|
Responding to Crimes Requireing Ditital Forensic Investigation |
|
|
115 | (12) |
|
|
116 | (1) |
|
|
116 | (1) |
|
|
116 | (4) |
|
|
120 | (1) |
|
|
121 | (4) |
|
Health and Safety Risk Assessments |
|
|
121 | (1) |
|
|
122 | (1) |
|
|
123 | (1) |
|
|
124 | (1) |
|
|
125 | (2) |
|
Management of the Collection of Evidence |
|
|
127 | (2) |
|
|
128 | (1) |
|
|
128 | (9) |
|
Designing the collection System |
|
|
130 | (1) |
|
|
130 | (2) |
|
Authority Verification and Validation |
|
|
132 | (1) |
|
Archiving and Advailability |
|
|
132 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
134 | (1) |
|
|
134 | (1) |
|
|
135 | (2) |
|
|
137 | (2) |
|
Management of Evidence Storage |
|
|
139 | (1) |
|
|
140 | (1) |
|
management of Evidence Storage |
|
|
140 | (6) |
|
Managing Electronic Evidence Storage |
|
|
142 | (1) |
|
Electronic Evidence Management for Analysis |
|
|
142 | (1) |
|
Movement of Electronic Evidence |
|
|
142 | (1) |
|
Availability versus Viability |
|
|
143 | (1) |
|
|
144 | (1) |
|
|
144 | (1) |
|
Optical Media: CD, DVD, BluRay |
|
|
145 | (1) |
|
Large Disk Drive Clusters (RAID, NAS) |
|
|
145 | (1) |
|
Management and Maintenance of the Archival Storage |
|
|
145 | (1) |
|
|
146 | (3) |
|
|
149 | (10) |
|
|
150 | (1) |
|
|
150 | (1) |
|
|
150 | (2) |
|
QA in Ditigal Forensic Acquisition |
|
|
152 | (1) |
|
|
152 | (1) |
|
QA for the Evidence Presentation |
|
|
153 | (1) |
|
|
153 | (2) |
|
|
155 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
QA of Process Documentation |
|
|
156 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
|
157 | (2) |
|
High Technology Crimes: Case Summaries |
|
|
159 | (18) |
|
|
160 | (1) |
|
High Technilogy Crime Cases |
|
|
160 | (15) |
|
|
160 | (2) |
|
|
162 | (1) |
|
|
163 | (1) |
|
Discrediting of Expert Witnesses |
|
|
164 | (1) |
|
Police Accused of Negligence in Porn Case |
|
|
165 | (1) |
|
|
165 | (1) |
|
|
166 | (1) |
|
|
167 | (1) |
|
|
168 | (1) |
|
Israeli Industrial Espionage |
|
|
168 | (1) |
|
|
169 | (1) |
|
|
170 | (1) |
|
|
171 | (1) |
|
|
171 | (1) |
|
|
172 | (1) |
|
The Disappearing Evidence |
|
|
173 | (2) |
|
|
175 | (2) |
|
|
175 | (2) |
|
Section III Overview of the Digital Forensic Investigations Profession and Unit |
|
|
177 | (70) |
|
Understanding the Role of the Digital Forensic Laboratory manager |
|
|
181 | (10) |
|
|
182 | (1) |
|
The Laboratory Manager's Major Functions |
|
|
182 | (2) |
|
|
182 | (1) |
|
|
182 | (1) |
|
|
183 | (1) |
|
|
184 | (2) |
|
|
184 | (1) |
|
|
184 | (1) |
|
|
185 | (1) |
|
|
185 | (1) |
|
Occupational Health and Safety |
|
|
186 | (1) |
|
|
186 | (2) |
|
|
186 | (1) |
|
|
187 | (1) |
|
|
188 | (1) |
|
|
188 | (2) |
|
|
188 | (1) |
|
|
189 | (1) |
|
Software and Hardware Facilities |
|
|
189 | (1) |
|
|
190 | (1) |
|
The Digital Forensics Laboratory: Strategic, Tactical, and Annual Plans |
|
|
191 | (10) |
|
|
192 | (1) |
|
Relationship of the Business Plans |
|
|
192 | (8) |
|
The Digital Forensic Laboratory Strategic Plan |
|
|
193 | (1) |
|
The Ditigal Forensic Laboratory Strategic Plan Objective |
|
|
193 | (1) |
|
Communication and Coordination of Digital Forensic Laboratory Strategic Plan |
|
|
193 | (1) |
|
Planning considerations for the Digital Forensic Laboratory Strategic Plan |
|
|
194 | (1) |
|
Mapping the Ditigal Forensic Laboratory Strategic Plan to the Security Department's and Parent Organization's Strategic Business Plan |
|
|
195 | (1) |
|
Writing the Digital Forensic Laboratory Strategic Plan |
|
|
195 | (1) |
|
The Digital Forensic Laboratory Tactical Plan |
|
|
196 | (1) |
|
Writing the Digital Forensic Laboratory Tactical Plan |
|
|
197 | (1) |
|
The Digital Forensic Laboratory Annual Plan |
|
|
197 | (1) |
|
Projects within the Digital Forensic Laboratory Annual Plan |
|
|
198 | (1) |
|
Mapping the Digital Forensic laboratory Annual Plan to the Security Department and the Overall Organization Annual Business Plan |
|
|
199 | (1) |
|
Writing the Ditigal Forensic Laboratory Annual Plan |
|
|
199 | (1) |
|
Mapping Digital Forensic Laboratory Strategic Plan, the Tactical Plan, and Annual Plan to Projects Using a Matrix |
|
|
200 | (1) |
|
|
200 | (1) |
|
Networking, Liaison, and Sources of Information |
|
|
201 | (10) |
|
|
202 | (1) |
|
|
202 | (1) |
|
|
202 | (1) |
|
|
203 | (1) |
|
Networking with Contracts inside the Organization |
|
|
203 | (1) |
|
Networking outside the Organization |
|
|
204 | (1) |
|
Maintaining the List of Contracts |
|
|
204 | (1) |
|
Collecting and Storing Information |
|
|
205 | (1) |
|
Other Sources of Information and Knowledge |
|
|
205 | (2) |
|
Classifying the Reliability of sources and the accuracy of Their Information |
|
|
207 | (2) |
|
|
209 | (2) |
|
|
209 | (2) |
|
Computer Forensic Investigation Unit Metrics Management System |
|
|
211 | (8) |
|
|
212 | (1) |
|
|
212 | (5) |
|
|
212 | (1) |
|
|
213 | (1) |
|
|
214 | (1) |
|
|
214 | (3) |
|
|
217 | (2) |
|
Workload Management and the Outsourcing Option |
|
|
219 | (14) |
|
|
220 | (1) |
|
In-house Workload Management |
|
|
220 | (1) |
|
|
220 | (1) |
|
|
221 | (11) |
|
A Definition of Outsourcing |
|
|
222 | (1) |
|
The Advantages and Disadvantages of Carrying Out Tasks In-house |
|
|
222 | (1) |
|
|
223 | (1) |
|
|
223 | (1) |
|
The Advantages and Disadvantages of Outsourcing Work from the Digital Forensic Laboratory |
|
|
224 | (1) |
|
|
224 | (1) |
|
|
225 | (1) |
|
Analysis or Outsourcing Options |
|
|
226 | (1) |
|
|
226 | (1) |
|
|
227 | (1) |
|
|
228 | (1) |
|
|
229 | (1) |
|
|
229 | (1) |
|
Likelihood of Successful Outcome |
|
|
229 | (1) |
|
|
230 | (1) |
|
Final Decision on Outsourcing |
|
|
231 | (1) |
|
|
231 | (1) |
|
|
232 | (1) |
|
|
232 | (1) |
|
Developing a Career in Digital Forensic Management |
|
|
233 | (8) |
|
|
234 | (1) |
|
|
235 | (1) |
|
Characteristics of a Manager |
|
|
235 | (1) |
|
Positioning Yourself for the Job |
|
|
236 | (1) |
|
|
237 | (2) |
|
|
238 | (1) |
|
Leadership or Management? |
|
|
239 | (1) |
|
|
239 | (2) |
|
A Summary of Thoughts, Issues, and Problems |
|
|
241 | (6) |
|
|
242 | (1) |
|
What Makes a Digital Forensic Laboratory Successful? |
|
|
243 | (1) |
|
Are You Up for the Job of Digital Forensic Laboratory Manager? |
|
|
243 | (1) |
|
|
244 | (3) |
|
Section IV Future Digital Forensic Investigation Challenges |
|
|
247 | (18) |
|
The Future of Digital Forensics and Its Role in Criminal Investigations |
|
|
249 | (6) |
|
|
250 | (1) |
|
The Implication of Changes in Criminal Investigations |
|
|
251 | (1) |
|
The Changing Face of Crime |
|
|
251 | (1) |
|
The Changing Role of Digital Forensics |
|
|
252 | (1) |
|
|
253 | (2) |
|
|
253 | (2) |
|
The Future of Digital Forensics in the Criminal Justice System |
|
|
255 | (6) |
|
|
256 | (1) |
|
|
257 | (1) |
|
|
258 | (1) |
|
|
259 | (2) |
|
Conclusions and Final Thoughts |
|
|
261 | (4) |
|
|
262 | (1) |
|
|
262 | (2) |
|
Skills and Knowledge Areas |
|
|
262 | (1) |
|
Personality Profile of a Manager |
|
|
263 | (1) |
|
|
264 | (1) |
|
Appendix A Digital Forensic Resources |
|
|
265 | (10) |
|
|
266 | (1) |
|
Laboratory and Staff Certification Authorities |
|
|
266 | (1) |
|
|
267 | (1) |
|
|
268 | (1) |
|
Digital Forensic Guidelines |
|
|
268 | (1) |
|
|
269 | (2) |
|
|
271 | (1) |
|
|
271 | (1) |
|
|
272 | (2) |
|
|
274 | (1) |
|
Appendix B Risk Assessment Template |
|
|
275 | (4) |
Index |
|
279 | |