Advertisement
Promo

Become a member of the ZDNet UK community

Adrian Mars

View blog's RSS Feed

It shouldn't happen to an IT consultant

Spend your time doing business, not IT.

Friday 12 December 2008, 12:49 AM

Compliance - 2b Forensic readiness planning, really, you need to do this.

Posted by Adrian Mars

Most businesses are aware of the need to keep personal and other data secure, and to have a disaster recovery plan in place, but haven't even heard of, let alone considered a forensic readiness plan. The Information Assurance Advisory Coucil’s Directors’ and Corporate Advisors’ Guide to Digital Investigations and Evidence Written as it is by Prof. Peter Sumner, it is an authoritative easy to read guide to creating one.

As Sumner points out, “…much more common than the catastrophic event is the one where there is a threatened legal outcome. Examples include disputed transactions, suspected fraud, employee problems, complaints of negligence, “smaller” cyber attacks, theft of data. These may be comparatively low impact but they are also high frequency events; most organisations will experience some form of them over the period of just a few months and some may expect them daily.
Common to all of them is the need for evidence, usually in digital form, to support the organisation’s position. Hence the need for a Forensic Readiness Plan, a sibling of the Disaster Recovery Plan.


There is considerable overlap between the two, preserving and recovering damaged data in the event of a disaster requires similar digital forensics skills as those needed to defend (or pursue) a court case (which can itself result from a disaster). As the size of data storage grows and the pervasiveness of the digital world increases it becomes increasingly likely that everything from insurance claims to employee fraud demand an awareness of digital forensics.

As well as providing a basic grounding in the technical side Sommer succinctly provides an excellent overview of the legal issues and the planning process itself. I highly recommend giving this guide a read and implementing its recommendations.

Comments on this post

Adrian Mars

This member is ranked #68 in our top 100

  • Adrian Mars
  • IT Consultant, UK
  • Member since: September 2008

Site Activity Rating 3

Contacts' Latest Discussions

Number of Tracked Discussions: 2,096

Rupert Goodwins Rupert Goodwins

I'm not sure that's true

Thursday 3 December 2009, 12:45 PM

7 comments
ator1940 ator1940

ACTA

Wednesday 2 December 2009, 12:07 PM

6 comments
ator1940 ator1940

Real security

Tuesday 1 December 2009, 4:21 PM

2 comments
J.A. Watson J.A. Watson

Reporting Other's Problems?

Monday 30 November 2009, 2:19 PM

15 comments

Contacts' Latest Blogs

Number of Contacts Blogs: 8

Avatar Karen Friar

HP workers set dates for strikes

Thursday 3 December 2009, 7:57 PM

0 comments
Avatar Rupert Goodwins

Google announces Public DNS

Thursday 3 December 2009, 5:57 PM

0 comments
Avatar J.A. Watson

Linux Mint 8 (Helena) Released

Monday 30 November 2009, 10:23 AM

0 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters