Question

In: Computer Science

The computer forensics investigative process includes five steps: Identification, Preservation, Collection, Examination, and Presentation. When a...

The computer forensics investigative process includes five steps: Identification, Preservation, Collection, Examination, and Presentation. When a breach has occurred in a medium to large-sized company, cybersecurity experts, and sometimes forensics specialists will investigate using this process. In a small company, it’s likely that the IT staff will have multiple roles, but what do you think about the larger companies? Should the experts who do penetration testing or maintain the security defenses be involved in the forensics investigation after a breach? What are some pros and cons you can see in having a lot of people examining the breach?

Solutions

Expert Solution

Back ground
some basic terms should be clear in context of cyber security
a)Vulnerability:
Vulnerabilities are the flaws present in security system.
b)Threat:
Any person,any malicious program, or any object which can exploit
vulnerability to access the data/information/IT resources in an unauthorized manner is a threat for the system.
Ans:
Now a days there is a pressing need to protect data,information, and other IT resources from cyber attack.so in large organization entire computerized system should be protected from cyber attack.
penetration testing is performed to find the vulnerability( flaws in security system)present in the security system.these vulnerabilities should be removed by the experts to make entire system more secure.

after a breach ,experts involved in penetration testing should be involved in investigation because they are aware of vulnerabilities and can help in investigation process.

group of these experts should be considered as a single entity.it means all the expert members should reach to a common opinion otherwise different opinions may lead to confusion.


having a lot of people in investigation may be beneficial because all the aspects related to the incident can be considered.
having a lot of people in investigation may be a time saving approach.

having a lot of people in investigation may lead to confusion due to various opinions.
investigation may be expensive due to presence of a lot of people in investigation team.


Related Solutions

Characteristics of the SSD forensics - Identification & Preservation. Explain in 800 words
Characteristics of the SSD forensics - Identification & Preservation. Explain in 800 words
1. the major steps in the “policy analysis process ” are: •Problem identification •Process definition •Process...
1. the major steps in the “policy analysis process ” are: •Problem identification •Process definition •Process analysis •Qualitative analysis •Evaluation and choice •Implementation strategy — which step do you think is the most important? Why do you think so? Please state your reasons in 3 or more sentences using one policy analysis example. (In Policy Issue in healthcare)
List and describe the steps of the nursing process: subjective data collection; objective data collection; validation...
List and describe the steps of the nursing process: subjective data collection; objective data collection; validation of data, documentation of data, and analysis of data. . Describe the steps of the analysis phase of the nursing process. Compare and contrast the four basic types of nursing assessment: (a) initial comprehensive (b) ongoing or partial (c) focused/problem-oriented (d) emergency Explain how the nurse’s role in assessment has changed over the past century. Discuss what the nurse’s role might be 25 years...
Describe the five steps in the marketing research process
Describe the five steps in the marketing research process
Explain the below five steps in the decision-making process that consumers pass through when purchasing a...
Explain the below five steps in the decision-making process that consumers pass through when purchasing a product or service and apply each step to a shoe product, mainly targeted for students. 1. Problem recognition 2. Information search 3. Evaluation of alternatives 4. Outlet selection and purchase 5. Post- Purchase behaviour
List and describe the steps of the nursing process : subjetive data collection ; objetive data...
List and describe the steps of the nursing process : subjetive data collection ; objetive data collection ; validation of data , documentation of data , and analysis of data . Describe the steps of analysis phase of the nursing process. Compare and contrast the four basic types of nursing assessment : a ) Initial comprehensive b ) Ongoing or partial c ) Focused / problem - oriented d ) Emergency Explain how thw nurses role in assessment has change...
Explain the five fundamental steps in the financial planning process.
Explain the five fundamental steps in the financial planning process.
What is data saturation? When in the data collection process or data analysis process can data...
What is data saturation? When in the data collection process or data analysis process can data saturation be identified? How does a qualitative researcher know that he or she reached data saturation?
Explain in detail with examples the five (5) steps of job analysis process.
Explain in detail with examples the five (5) steps of job analysis process.
there are typically five steps involved in a standard water treatment process. Identify which of these...
there are typically five steps involved in a standard water treatment process. Identify which of these steps of the water treatment process and describe how they are performed.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT