Forensic Focus
 
Web www.forensicfocus.com
Login or Register
HomeMy AccountBlogBasicsPapers/ArticlesForumsNewsletterEmail GroupInterviewsEventsTrainingDownloadsLinks
Subscribe to Feeds

Forensic News Jamie's Blog
Main Menu
MY ACCOUNT
COMMUNITY
RESOURCES
MISC
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!

Survey
Which of the following do you usually use for imaging evidence?




Results :: Polls

Votes: 23902
Comments: 0
Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!



The Essentials Of Computer Discovery

Page: 1/13
by Joan E. Feldman, President
Computer Forensics Inc.â„¢
www.forensics.com

I. INTRODUCTION

Chances are good that the date you scheduled, the letter you wrote, and the inter-office message you just read have all been recorded on magnetic media. Like any other business record, electronically stored files are discoverable in litigation and can be used as evidence in the courtroom.

What distinguishes computer-based evidence from traditional paper documents in discovery? "Electronic" documents thought to be lost or destroyed can be recovered. Valuable information such as the time, date, and author's name may be embedded in the electronic version of a document. Comparisons of computer backups to existing documents can be used to show that a critical document was altered and when the event occurred. In the case of electronic mail, casual and candid correspondence may be frozen in time like insects in amber.

GLOSSARY

Computer System refers to the entire computing environment. This environment may consist of one large computer serving many users (e.g., a mainframe or mini-computer) or one or more personal computers working individually or linked together through a network. A computer system includes all hardware and peripherals used (e.g., terminals, printers, modems, data storage devices), as well as the software.

Files are groups of information collectively placed under a name and stored on a computer. Files are organized in various folders sometimes referred to as directories and subdirectories.

Media is the generic term for the various storage devices used to store computer data. For PCs, the most common media are the internal hard drive, CDs, and floppy disks. Backup tapes, thumb drives, and DVDs are other forms of storage media.

Networks are the hardware and software combinations that connect computers and allow them to share data. Two common ways PCs are networked are peer-to-peer and client-server. Peer-to-peer networks physically connect each computer in the network to every other computer in the network. Files are stored on the hard drives of the individual PCs with no centralized file storage. Client-server networks connect individual PCs called "clients" to a central "server" computer. In contrast to peer-to-peer networks, files are stored centrally on the server.






Next Page (2/13) Next Page


User Info

Welcome Anonymous

Nickname

Membership:
Latest: hunter33
New Today: 0
New Yesterday: 2
Overall: 6215

People Online:
Members: 1
Visitors: 5
Bots: 5
Staff: 0
Staff Online:

No staff members are online!
Forensic Focus Blog
· Matthew Shannon, F-Response - Interview questions please!
· UK Criminal Justice Bill - Clause 62 (or is it 63, or 64?)
· Interview with David Sullivan, Appointments-UK
· Reporting (again) and interviews
· Reporting - time for standardization?
· Posts from the blogoshpere
· Site stats
· Why the hell is everything so expensive?
· The problem with power
· Licensing

read more...
This site needs YOU!

Write for Forensic Focus
LINK TO US

OR
WRITE FOR US
OR
START A BLOG

Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Top10 Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: Cache View
  3: ACPO Good Practice Guide for Computer based Electronic Evidence
  4: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  5: PDA Forensic Tools:An Overview and Analysis
  6: Australasian Centre for Policing Research Best Practice Guide
  7: Autopsy Forensic Browser Version 2.03 (source code)
  8: Recover My Files
  9: Directors & Corporate Advisors' Guide to Digital Investigations and Evidence
  10: HELIX incident response CD

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2008 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.