- Digital Forensics and Incident Response
- Gerard Johansen
- 201字
- 2021-07-02 18:49:47
Physical security
Access to the forensic lab needs to be strictly controlled. In order to maintain a chain of custody, only those with a justifiable need should be allowed access to the lab. This limitation is necessary to remove any chance that the evidence can be tampered with or destroyed. The lab therefore should be locked at all times. Ideally, access should be granted via access cards or fobs with a central management system granting access. This allows for a complete reconstruction of all personnel who access the laboratory within a specific time period.
The laboratory should also contain evidence lockers so that evidence can be properly stored while not being examined. Lockers should be secured either through an onboard lock or through the use of a combination lock. The keys to these lockers should be secured within the laboratory and access given to examiners. If the organization has adequate resources, each specific incident should have its own locker with all the evidence contained within a single locker. This reduces the chance of digital evidence becoming comingled.
Climate should be controlled in much the same way as in any data center. Climate and humidity should be set to the appropriate levels.
- Intel Galileo Essentials
- Android Studio Essentials
- 高級(jí)C/C++編譯技術(shù)(典藏版)
- Windows Forensics Cookbook
- C#程序設(shè)計(jì)基礎(chǔ):教程、實(shí)驗(yàn)、習(xí)題
- 蘋果的產(chǎn)品設(shè)計(jì)之道:創(chuàng)建優(yōu)秀產(chǎn)品、服務(wù)和用戶體驗(yàn)的七個(gè)原則
- Mobile Device Exploitation Cookbook
- MySQL入門很輕松(微課超值版)
- C#程序設(shè)計(jì)(項(xiàng)目教學(xué)版)
- Getting Started with Python and Raspberry Pi
- QGIS Python Programming Cookbook(Second Edition)
- Learning AWS
- Image Processing with ImageJ
- Learning Ionic
- jQuery從入門到精通(微課精編版)