preview

Incident Response And Forensics Investigation Essay

Good Essays

Introduction

Incident response and forensics investigations are closely related aspects of managing the activities that occurs after an information technology (IT) incident occurs. In this paper, we will explore the various aspects of incident response and forensics as they apply to an IT incident and by examining the details in the enclosed case study, we will show how those aspects apply to that situation. To begin with, we will discuss the differences between incident response and forensic activities. Next, we will cover some of the challenges involved with first responder handling of evidence as it applies to incident response and computer forensics. We will also be covering some of the steps required for a comprehensive forensics and incident response plan. Additionally, we will outline the steps required for effective integration of forensics and incident response procedures in externally contracted forensic situations. Lastly, we will present a brief evaluation of the incident response resources available to manage incident response and forensics activities. The Differences Between Incident Response and Forensics
Understanding the differences between incident response and forensic activities is a key aspect of any effective organizational IT management plan. Due to their similarities and their close relationship to each other, these terms are sometimes used interchangeably but it is important to understand they each have their own specific function. Both

Get Access