<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>ForensicsFAQ.com &#187; Computer Forensics</title>
	<atom:link href="http://forensicsfaq.com/category/forensic-disciplines/computer-forensics/feed" rel="self" type="application/rss+xml" />
	<link>http://forensicsfaq.com</link>
	<description>Forensics explained.</description>
	<pubDate>Sun, 02 Nov 2008 08:02:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Introduction To Computer Forensics</title>
		<link>http://forensicsfaq.com/introduction-to-computer-forensics.html</link>
		<comments>http://forensicsfaq.com/introduction-to-computer-forensics.html#comments</comments>
		<pubDate>Wed, 02 Apr 2008 23:45:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Computer Forensics]]></category>

		<guid isPermaLink="false">http://forensicsfaq.com/introduction-to-computer-forensics.html</guid>
		<description><![CDATA[In essence, computer forensics is the investigation of electronic devices or computer media.
Typically, the purpose of such an investigation is to analyse and discover any available, deleted, or &#8216;hidden&#8217; data that can then be subsequently used as evidence in legal proceedings.
Additionally, computer forensic techniques can be employed in some cases of hardware failure.

As with all [...]]]></description>
			<content:encoded><![CDATA[<p>In essence, computer forensics is the investigation of electronic devices or computer media.</p>
<p>Typically, the purpose of such an investigation is to analyse and discover any available, deleted, or &#8216;hidden&#8217; data that can then be subsequently used as evidence in legal proceedings.</p>
<p>Additionally, computer forensic techniques can be employed in some cases of hardware failure.</p>
<p><img src="http://forensicsfaq.com/wp-content/uploads/2008/04/computer_forensics.jpg" alt="computer forensics" align="left" height="176" width="300" /></p>
<p>As with all technology, computer forensics is a fast-moving discipline in which new hardware, tools and software are consistently being developed.</p>
<p>This means, generally, that it is becoming increasingly simpler for computer forensic experts to find &amp; restore more evidence and/or data, not only faster, but also with far more accuracy.</p>
<p><strong>Anti-Forensics </strong></p>
<p>Obviously, technological advances also mean that <a href="http://www.networkintrusion.co.uk/foranti.htm">forensic countermeasures</a> are also improving at a similar rate, leading to some interesting challenges.</p>
<p><strong>Digital Evidence </strong></p>
<p>The advent of computer forensics has significantly changed the way in which digital evidence is gathered and used as evidence of a crime, and is performed via advanced techniques and technologies.</p>
<p>A computer forensic expert will use their knowledge of these techniques to aid in the discovery of evidence from an electronic storage device, possibly for either proving or disproving a crime.</p>
<p>Such data can be derived from a wide variety of electronic devices, such as flash drives, discs, tapes, handheld computers, PDAs, memory sticks, emails, logs, or even hidden or deleted files.</p>
<p><strong>Tracking </strong></p>
<p>The average computer user probably thinks that the simple act of deleting a file or item of internet history will remove it completely from the their system.</p>
<p>Reality, however, is somewhat different - deleting a file simply removes it&#8217;s marker from the &#8216;index&#8217; of a hard drive - the actual file will remain on the computer, in whole or in part, until it has been completely overwritten by new data, as can been seen in this <a href="http://forensicsfaq.com/encase.html" title="Encase video">video of Encase</a>.</p>
<p>A computer forensic expert has the tools and knowledge required to find such deleted files and to reconstitute them to varying degrees, such that they could be used as admissible evidence.</p>
<p><strong>Enron </strong></p>
<p>The Enron scandal placed computer forensics firmly on the map as it arguably remains the biggest computer forensics investigation ever.</p>
<p>In recent years, computer forensics has become a standard part of many types of litigation, especially litigations of a corporate nature in which there are large amounts of data.</p>
<p><strong>Data Security </strong></p>
<p>In this digital age, data security is a growing issue for the corporate world, covering topics such as internet policies (and the consequences of violating them), and the signing of compliance documents by employees.</p>
<p>Perhaps the best way in which businesses can monitor their own computer systems, in a proactive way, in order to avoid legal consequences in future is to utilise some level of computer forensics.</p>
<p>Simply by making employees aware that such a facility exists could prove a sufficient deterrent to any wrong doing.</p>
<p><strong>Growing Niche </strong></p>
<p>With the huge increase in the use of computers, both in the business sector and in the home, and the increasing number of hi-tech crimes, computer forensics is certainly a growing niche within the litigation support sector.</p>
<p>Unlike many other jobs within the information technology sector, computer forensic work is highly unlikely to be outsourced to other, cheaper, countries, due to the confidentiality of the data which is involved.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicsfaq.com/introduction-to-computer-forensics.html/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
