Computer Forensics
Computer forensics is the discipline of collecting, preserving and analysing digital evidence from computers and networks so that the findings hold up in legal or disciplinary proceedings.
What is Computer Forensics?
Definition
Computer Forensics is the discipline of collecting, preserving and analysing digital evidence from computers, storage media and networks, so that what is found can be relied on afterwards — in court, in a disciplinary process, or in an insurance claim. Its defining constraint is procedural rather than technical: evidence must be acquired without altering the original, and every step must be documented in an unbroken chain of custody, or the analysis is worthless however good it is. In cybersecurity it sits next to incident response, which asks what is happening now, while forensics asks what happened and how that can be proven.
Role in cybersecurity
Computer Forensics plays an important role in building organizational resilience against cyber threats. Implementing appropriate mechanisms in this area is required by regulations such as NIS2, DORA and ISO 27001.