The Experts below are selected from a list of 282 Experts worldwide ranked by ideXlab platform
Hein S. Venter - One of the best experts on this subject based on the ideXlab platform.
-
Requirements for IoT Forensics
2019 Conference on Next Generation Computing Applications (NextComp), 2019Co-Authors: Jaco-louis Kruger, Hein S. VenterAbstract:The main objective of this paper is to determine the requirements for IoT Forensics. The development of requirements for Internet of Things (IoT) Forensics will make a groundbreaking contribution to the current body of knowledge. The secondary objective of the paper is the formulation of a Digital Forensic Readiness (DFR) model for the implementation of IoT Forensics. The model aims to address the shortfalls of the requirements, as well as incorporate various Digital Forensic (DF) techniques that can be used in IoT environments. The model is presented in theoretical as well as graphical form. The model is then discussed to highlight various areas of possible new research. The model is furthermore evaluated to determine the level of contribution it makes to the current body of research.
-
Digital behavioral-fingerprint for user attribution in Digital Forensics: Are we there yet?
Digital Investigation, 2019Co-Authors: Adeyemi Richard Ikuesan, Hein S. VenterAbstract:Abstract the need for a reliable and complementary identifier mechanism in a Digital Forensic analysis is the focus of this study. Mouse dynamics have been applied in information security studies, particularly, continuous authentication and authorization. However, the method applied in security is void of specific behavioral signature of a user, which inhibits its applicability in Digital Forensic science. This study investigated the likelihood of the observation of a unique signature from mouse dynamics of a computer user. An initial mouse path model was developed using non-finite automata. Thereafter, a set-theory based adaptive two-stage hash function and a multi-stage rule-based semantic algorithm were developed to observe the feasibility of a unique signature for Forensic usage. An experimental process which comprises three existing mouse dynamics datasets were used to evaluate the applicability of the developed mechanism. The result showed a low likelihood of extracting unique behavioral signature which can be used in a user attribution process. Whilst Digital Forensic Readiness mechanism could be a potential approach that can be used to achieve a reliable behavioral biometrics modality, the lack of unique signature presents a limitation. In addition, the result supports the logic that the current state of behavioral biometric modality, particularly mouse dynamics, is not suitable for Forensic usage. Hence, the study concluded that whilst mouse dynamics-based behavioral biometrics may be a complementary modality in security studies, more will be required to adopt it as a Forensic modality in litigation. Furthermore, the result from this study finds relevance in other human attributional studies such as user identification in recommender systems, e-commerce, and online profiling systems, where the degree of accuracy is not relatively high.
-
Digital Forensic Readiness Framework for Ransomware Investigation
Digital Forensics and Cyber Crime, 2019Co-Authors: Avinash Singh, Adeyemi Richard Ikuesan, Hein S. VenterAbstract:Over the years there has been a significant increase in the exploitation of the security vulnerabilities of Windows operating systems, the most severe threat being malicious software (malware). Ransomware, a variant of malware which encrypts files and retains the decryption key for ransom, has recently proven to become a global Digital epidemic. The current method of mitigation and propagation of malware and its variants, such as anti-viruses, have proven ineffective against most Ransomware attacks. Theoretically, Ransomware retains footprints of the attack process in the Windows Registry and the volatile memory of the infected machine. Digital Forensic Readiness (DFR) processes provide mechanisms for the pro-active collection of Digital footprints. This study proposed the integration of DFR mechanisms as a process to mitigate Ransomware attacks. A detailed process model of the proposed DFR mechanism was evaluated in compliance with the ISO/IEC 27043 standard. The evaluation revealed that the proposed mechanism has the potential to harness system information prior to, and during a Ransomware attack. This information can then be used to potentially decrypt the encrypted machine. The implementation of the proposed mechanism can potentially be a major breakthrough in mitigating this global Digital endemic that has plagued various organizations. Furthermore, the implementation of the DFR mechanism implies that useful decryption processes can be performed to prevent ransom payment.
-
novel Digital Forensic Readiness technique in the cloud environment
Australian Journal of Forensic Sciences, 2018Co-Authors: Victor R. Kebande, Hein S. VenterAbstract:AbstractThis paper examines the design and implementation of a feasible technique for performing Digital Forensic Readiness (DFR) in cloud computing environments. The approach employs a modified obfuscated Non-Malicious Botnet (NMB) whose functionality operates as a distributed Forensic Agent-Based Solution (ABS) in a cloud environment with capabilities of performing Forensic logging for DFR purposes. Under basic Service Level Agreements (SLAs), this proactive technique allows any organization to perform DFR in the cloud without interfering with operations and functionalities of the existing cloud architecture or infrastructure and the collected file metadata. Based on the evaluation discussed, the effectiveness of our approach is presented as the easiest way of conducting DFR in the cloud environment as stipulated in the ISO/IEC 27043: 2015 international standard, which is a standard of information technology, security techniques and incident investigation principles and processes. Through this technique...
-
a Digital Forensic Readiness architecture for online examinations
South African Computer Journal, 2018Co-Authors: Ivans Kigwana, Hein S. VenterAbstract:Some institutions provide online courses to students to ease the courses’ workload. Online courses can also be convenient because the online course content management software conducts marking of tests and examinations. However, a few students could be willing to exploit such a system’s weaknesses in a bid to cheat in online examinations because invigilators are absent. Proactive measures are needed and measures have to be implemented in order to thwart unacceptable behaviour in situations where there is little control of students’ conduct. Digital Forensic Readiness (DFR) employs a proactive approach for an organisation to be Forensically prepared for situations where there is little control over people. This can be achieved by gathering, storing and handling incident response data, with the aim of reducing the time and cost that would otherwise be spent in a post-event response process. The problem this paper addresses is that, at the time of writing this paper, there existed no known DFR architecture that can be used to collect relevant information for DFR purposes, specifically in the course of an online examination, as described in the standard published by the International Standards Organisation (ISO) and the International Electrotechnical Commission (IEC) (ISO/IEC 27043:2015) for incident investigation principles and processes. Due to the lack of DFR architecture, the authors propose an Online Examination Digital Forensic Readiness Architecture (OEDFRA) that can be used to achieve DFR when online examinations are conducted. This architecture employs already existing DFR techniques, discussed in the study, to help educational institutions achieve DFR in online examinations. This architecture, (OEDFRA), when implemented, will be tested in future research in order to confirm its contribution to the field of DFR.
H. S. Venter - One of the best experts on this subject based on the ideXlab platform.
-
functional requirements for adding Digital Forensic Readiness as a security component in iot environments
International Journal on Advanced Science Engineering and Information Technology, 2018Co-Authors: Victor R. Kebande, Nickson Karie Menza, H. S. VenterAbstract:For every contact made on a Digital device, a trace is left behind; this means that every Digital device contains some form of electronic evidence that may be associated to the behaviour of the users in a given environment. This evidence can be used to prove or disprove facts if a cyber-incident is detected. However, the world has seen a shift on how devices communicate and connect as a result of increased devices and connectivity, which has led to the creation of “smart environments” where the Internet of Things (IoT) plays a key role. Still, we can harness this proliferation of Digital devices and smart environments to Digital Forensic (DF) technology which might help to solve the puzzle of how proactive strategies can help to minimise the time and cost needed to conduct a Digital investigation. This article introduces the Functional Requirements (FRs) and processes needed when Digital Forensic Readiness (DFR) process is employed as a security component in the IoT-based environment. The paper serves as a continuation of the initially proposed architecture for adding DFR as a security component to IoT environment. The aspects and claims presented in this paper can be used as basic building blocks for implementing DFR technologies that guarantee security in the IoT-based environment. It is worth noting again that the processes that have been defined in this paper comply with the ISO/IEC 27043: 2015 International Standard.
-
on Digital Forensic Readiness in the cloud using a distributed agent based solution issues and challenges
Australian Journal of Forensic Sciences, 2018Co-Authors: Victor R. Kebande, H. S. VenterAbstract:The need to perform Digital investigations has, over the years, led to the exponential growth of the field of Digital Forensics (DF). However, quite a number of challenges face the act of proving – for purposes of Digital Forensic Readiness (DFR) – that an electronic event has occurred in cyberspace. The problem that this research addresses involves the challenges faced when an Agent-Based Solution (ABS) is used in the cloud to extract Potential Digital Evidence (PDE) for DFR purposes. Throughout the paper the authors have modified the functionality of an initially malicious botnet to act as a distributed Forensic agent to conduct this process. The paper focuses on the general, technical and operational challenges that are encountered when trying to achieve DFR in the cloud environment. The authors finally propose a contribution by assessing the possible solutions from a general, technical and operational point of view.
-
adding Digital Forensic Readiness as a security component to the iot domain
International Journal on Advanced Science Engineering and Information Technology, 2018Co-Authors: Victor R. Kebande, Nickson M. Karie, H. S. VenterAbstract:The unique identities of remote sensing, monitoring, self-actuating, self–adapting and self-configuring “things” in Internet of Things (IoT) has come out as fundamental building blocks for the development of “smart environments”. This experience has begun to be felt across different IoT-based domains like healthcare, surveillance, energy systems, home appliances, industrial machines, smart grids and smart cities. These developments have, however, brought about a more complex and heterogeneous environment which is slowly becoming a home to cyber attackers. Digital Forensic Readiness (DFR) though can be employed as a mechanism for maximizing the potential use of Digital evidence while minimizing the cost of conducting a Digital Forensic investigation process in IoT environments in case of an incidence. The problem addressed in this paper, therefore, is that at the time of writing this paper, there still exist no IoT architectures that have a DFR capability that is able to attain incident preparedness across IoT environments as a mechanism of preparing for post-event response process. It is on this premise, that the authors are proposing an architecture for incorporating DFR to IoT domain for proper planning and preparing in the case of security incidents. It is paramount to note that the DFR mechanism in IoT discussed in this paper complies with ISO/IEC 27043: 2015, 27030:2012 and 27017: 2015 international standards. It is the authors’ opinion that the architecture is holistic and very significant in IoT Forensics.
-
user attribution based on keystroke dynamics in Digital Forensic Readiness process
2017 IEEE Conference on Application Information and Network Security (AINS), 2017Co-Authors: Martha Mohlala, Adeyemi Richard Ikuesan, H. S. VenterAbstract:As the development of technology increases, the security risk also increases. This has affected most organizations, irrespective of size, as they depend on the increasingly pervasive technology to perform their daily tasks. However, the dependency on technology has introduced diverse security vulnerabilities in organizations which requires a reliable preparedness for probable Forensic investigation of the unauthorized incident. Keystroke dynamics is one of the cost-effective methods for collecting potential Digital evidence. This paper presents a keystroke pattern analysis technique suitable for the collection of complementary potential Digital evidence for Forensic Readiness. The proposition introduced a technique that relies on the extraction of reliable behavioral signature from user activity. Experimental validation of the proposition demonstrates the effectiveness of proposition using a multi-scheme classifier. The overall goal is to have Forensically sound and admissible keystroke evidence that could be presented during the Forensic investigation to minimize the costs and time of the investigation.
-
a generic Digital Forensic Readiness model for byod using honeypot technology
IST-Africa Week Conference, 2016Co-Authors: Victor R. Kebande, Nickson M. Karie, H. S. VenterAbstract:Proliferation and mobility trends on Digital devices has seen a significant realization of Bring Your Own Device (BYOD) which is a phenomenon that allows employees in an organizational enterprise network to access computing resources through their personal mobile devices irrespective of their location. This technology has enabled cost effectiveness in organizations through increased accessibility of Digital devices in daily business activities. However, the development of this technology faces a number of security challenges due to lack of effective proactive security model with Digital Forensic capability that is able to plan and prepare before potential security incidents occur in an organization that has allowed BYOD. It is on this premise that the authors have proposed a generic Digital Forensic Readiness (DFR) model that uses honeypot technology to detect and trap potential security incidents. In this paper, therefore, a significant security model with DFR capability has been proposed. The model is aimed at harvesting, encrypting and Digitally preserving potential Digital evidence (PDE) based on the DFR processes and guidelines that have been highlighted in the ISO/IEC 27043: 2015 international standard for information technology, security techniques, incident investigation principles and processes. Finally, the proposed model is meant to reduce the effort required to conduct Digital Forensic Investigation (DFI) by capturing potential Digital evidence and make it available when needed by Digital Forensic investigators which eventually saves cost and time. A generic DFR model for BYOD using honeypot technology is the main focus of this paper.
Victor R. Kebande - One of the best experts on this subject based on the ideXlab platform.
-
novel Digital Forensic Readiness technique in the cloud environment
Australian Journal of Forensic Sciences, 2018Co-Authors: Victor R. Kebande, Hein S. VenterAbstract:AbstractThis paper examines the design and implementation of a feasible technique for performing Digital Forensic Readiness (DFR) in cloud computing environments. The approach employs a modified obfuscated Non-Malicious Botnet (NMB) whose functionality operates as a distributed Forensic Agent-Based Solution (ABS) in a cloud environment with capabilities of performing Forensic logging for DFR purposes. Under basic Service Level Agreements (SLAs), this proactive technique allows any organization to perform DFR in the cloud without interfering with operations and functionalities of the existing cloud architecture or infrastructure and the collected file metadata. Based on the evaluation discussed, the effectiveness of our approach is presented as the easiest way of conducting DFR in the cloud environment as stipulated in the ISO/IEC 27043: 2015 international standard, which is a standard of information technology, security techniques and incident investigation principles and processes. Through this technique...
-
functional requirements for adding Digital Forensic Readiness as a security component in iot environments
International Journal on Advanced Science Engineering and Information Technology, 2018Co-Authors: Victor R. Kebande, Nickson Karie Menza, H. S. VenterAbstract:For every contact made on a Digital device, a trace is left behind; this means that every Digital device contains some form of electronic evidence that may be associated to the behaviour of the users in a given environment. This evidence can be used to prove or disprove facts if a cyber-incident is detected. However, the world has seen a shift on how devices communicate and connect as a result of increased devices and connectivity, which has led to the creation of “smart environments” where the Internet of Things (IoT) plays a key role. Still, we can harness this proliferation of Digital devices and smart environments to Digital Forensic (DF) technology which might help to solve the puzzle of how proactive strategies can help to minimise the time and cost needed to conduct a Digital investigation. This article introduces the Functional Requirements (FRs) and processes needed when Digital Forensic Readiness (DFR) process is employed as a security component in the IoT-based environment. The paper serves as a continuation of the initially proposed architecture for adding DFR as a security component to IoT environment. The aspects and claims presented in this paper can be used as basic building blocks for implementing DFR technologies that guarantee security in the IoT-based environment. It is worth noting again that the processes that have been defined in this paper comply with the ISO/IEC 27043: 2015 International Standard.
-
on Digital Forensic Readiness in the cloud using a distributed agent based solution issues and challenges
Australian Journal of Forensic Sciences, 2018Co-Authors: Victor R. Kebande, H. S. VenterAbstract:The need to perform Digital investigations has, over the years, led to the exponential growth of the field of Digital Forensics (DF). However, quite a number of challenges face the act of proving – for purposes of Digital Forensic Readiness (DFR) – that an electronic event has occurred in cyberspace. The problem that this research addresses involves the challenges faced when an Agent-Based Solution (ABS) is used in the cloud to extract Potential Digital Evidence (PDE) for DFR purposes. Throughout the paper the authors have modified the functionality of an initially malicious botnet to act as a distributed Forensic agent to conduct this process. The paper focuses on the general, technical and operational challenges that are encountered when trying to achieve DFR in the cloud environment. The authors finally propose a contribution by assessing the possible solutions from a general, technical and operational point of view.
-
adding Digital Forensic Readiness as a security component to the iot domain
International Journal on Advanced Science Engineering and Information Technology, 2018Co-Authors: Victor R. Kebande, Nickson M. Karie, H. S. VenterAbstract:The unique identities of remote sensing, monitoring, self-actuating, self–adapting and self-configuring “things” in Internet of Things (IoT) has come out as fundamental building blocks for the development of “smart environments”. This experience has begun to be felt across different IoT-based domains like healthcare, surveillance, energy systems, home appliances, industrial machines, smart grids and smart cities. These developments have, however, brought about a more complex and heterogeneous environment which is slowly becoming a home to cyber attackers. Digital Forensic Readiness (DFR) though can be employed as a mechanism for maximizing the potential use of Digital evidence while minimizing the cost of conducting a Digital Forensic investigation process in IoT environments in case of an incidence. The problem addressed in this paper, therefore, is that at the time of writing this paper, there still exist no IoT architectures that have a DFR capability that is able to attain incident preparedness across IoT environments as a mechanism of preparing for post-event response process. It is on this premise, that the authors are proposing an architecture for incorporating DFR to IoT domain for proper planning and preparing in the case of security incidents. It is paramount to note that the DFR mechanism in IoT discussed in this paper complies with ISO/IEC 27043: 2015, 27030:2012 and 27017: 2015 international standards. It is the authors’ opinion that the architecture is holistic and very significant in IoT Forensics.
-
Adding Digital Forensic Readiness as a Security Component to the IoT Domain
International Journal on Advanced Science Engineering and Information Technology, 2018Co-Authors: Victor R. Kebande, Nickson M. Karie, Hein S. VenterAbstract:© Advanced Science Engineering Information Technology. 2018. The unique identities of remote sensing, monitoring, self-actuating, self-adapting and self-configuring "things" in Internet of Things (IoT) has come out as fundamental building blocks for the development of "smart environments". This experience has begun to be felt across different IoT-based domains like healthcare, surveillance, energy systems, home appliances, industrial machines, smart grids and smart cities. These developments have, however, brought about a more complex and heterogeneous environment which is slowly becoming a home to cyber attackers. Digital Forensic Readiness (DFR) though can be employed as a mechanism for maximizing the potential use of Digital evidence while minimizing the cost of conducting a Digital Forensic investigation process in IoT environments in case of an incidence. The problem addressed in this paper, therefore, is that at the time of writing this paper, there still exist no IoT architectures that have a DFR capability that is able to attain incident preparedness across IoT environments as a mechanism of preparing for post-event response process. It is on this premise, that the authors are proposing an architecture for incorporating DFR to IoT domain for proper planning and preparing in the case of security incidents. It is paramount to note that the DFR mechanism in IoT discussed in this paper complies with ISO/IEC 27043: 2015, 27030:2012 and 27017: 2015 international standards. It is the authors' opinion that the architecture is holistic and very significant in IoT Forensics.
Aleksandar Valjarevic - One of the best experts on this subject based on the ideXlab platform.
-
A Comprehensive and Harmonized Digital Forensic Investigation Process Model
Journal of Forensic Sciences, 2015Co-Authors: Aleksandar Valjarevic, Hein S. VenterAbstract:Performing a Digital Forensic investigation (DFI) requires a standardized and formalized process. There is currently neither an international standard nor does a global, harmonized DFI process (DFIP) exist. The authors studied existing state-of-the-art DFIP models and concluded that there are significant disparities pertaining to the number of processes, the scope, the hierarchical levels, and concepts applied. This paper proposes a comprehensive model that harmonizes existing models. An effort was made to incorporate all types of processes proposed by the existing models, including those aimed at achieving Digital Forensic Readiness. The authors introduce a novel class of processes called concurrent processes. This is a novel contribution that should, together with the rest of the model, enable more efficient and effective DFI, while ensuring admissibility of Digital evidence. Ultimately, the proposed model is intended to be used for different types of DFI and should lead to standardization.
-
implementation guidelines for a harmonised Digital Forensic investigation Readiness process model
Information Security for South Africa, 2013Co-Authors: Aleksandar Valjarevic, H. S. VenterAbstract:Digital Forensic investigation Readiness enables an organisation to prepare itself in order to perform a Digital Forensic investigation in a more efficient and effective manner. Benefits of achieving a high level of Digital Forensic investigation Readiness include, but are not limited to, higher admissibility of Digital evidence in a court of law, better utilisation of resources (including time and financial resources) and higher awareness of Forensic investigation Readiness. The problem that this paper addresses is that there is no harmonised Digital Forensic investigation Readiness process model with appropriate implementation guidelines and, thus, there is a lack of an effective and standardised implementation of Digital Forensic investigation Readiness measures within organisations. Valjarevic and Venter have, in their previous work, proposed a harmonised Digital Forensic investigation Readiness process model. This paper proposes implementation guidelines for such a harmonised Digital Forensic investigation process model in order to help practitioners and researchers to successfully implement the proposed model. The authors believe that these guidelines will significantly help to properly and consistently implement Digital Forensic Readiness measures in different organisations in a bid to achieve higher admissibility of Digital evidence in a court of law, as well as more efficient and effective Digital Forensic investigations.
-
ISSA - Implementation guidelines for a harmonised Digital Forensic investigation Readiness process model
2013 Information Security for South Africa, 2013Co-Authors: Aleksandar Valjarevic, Hein S. VenterAbstract:Digital Forensic investigation Readiness enables an organisation to prepare itself in order to perform a Digital Forensic investigation in a more efficient and effective manner. Benefits of achieving a high level of Digital Forensic investigation Readiness include, but are not limited to, higher admissibility of Digital evidence in a court of law, better utilisation of resources (including time and financial resources) and higher awareness of Forensic investigation Readiness. The problem that this paper addresses is that there is no harmonised Digital Forensic investigation Readiness process model with appropriate implementation guidelines and, thus, there is a lack of an effective and standardised implementation of Digital Forensic investigation Readiness measures within organisations. Valjarevic and Venter have, in their previous work, proposed a harmonised Digital Forensic investigation Readiness process model. This paper proposes implementation guidelines for such a harmonised Digital Forensic investigation process model in order to help practitioners and researchers to successfully implement the proposed model. The authors believe that these guidelines will significantly help to properly and consistently implement Digital Forensic Readiness measures in different organisations in a bid to achieve higher admissibility of Digital evidence in a court of law, as well as more efficient and effective Digital Forensic investigations.
-
a harmonized process model for Digital Forensic investigation Readiness
International Conference on Digital Forensics, 2013Co-Authors: Aleksandar Valjarevic, H. S. VenterAbstract:Digital Forensic Readiness enables an organization to prepare itself to perform Digital Forensic investigations in an efficient and effective manner. The benefits include enhancing the admissibility of Digital evidence, better utilization of resources and greater incident awareness. However, a harmonized process model for Digital Forensic Readiness does not currently exist and, thus, there is a lack of effective and standardized implementations of Digital Forensic Readiness within organizations. This paper presents a harmonized process model for Digital Forensic investigation Readiness. The proposed model is holistic in nature and properly considers Readiness and investigative activities along with the interface between the two types of activities.
-
IFIP Int. Conf. Digital Forensics - A Harmonized Process Model for Digital Forensic Investigation Readiness
Advances in Digital Forensics IX, 2013Co-Authors: Aleksandar Valjarevic, Hein S. VenterAbstract:Digital Forensic Readiness enables an organization to prepare itself to perform Digital Forensic investigations in an efficient and effective manner. The benefits include enhancing the admissibility of Digital evidence, better utilization of resources and greater incident awareness. However, a harmonized process model for Digital Forensic Readiness does not currently exist and, thus, there is a lack of effective and standardized implementations of Digital Forensic Readiness within organizations. This paper presents a harmonized process model for Digital Forensic investigation Readiness. The proposed model is holistic in nature and properly considers Readiness and investigative activities along with the interface between the two types of activities.
Lessing Labuschagne - One of the best experts on this subject based on the ideXlab platform.
-
cognitive approaches for Digital Forensic Readiness planning
International Conference on Digital Forensics, 2013Co-Authors: Antonio Pooe, Lessing LabuschagneAbstract:This paper focuses on the use of cognitive approaches for Digital Forensic Readiness planning. Research has revealed that a well-thought-out and legally contextualized Digital Forensic Readiness strategy can provide organizations with an increased ability to respond to security incidents while maintaining the integrity of the evidence gathered and keeping investigative costs low. This paper contributes to the body of knowledge in Digital Forensics related to the design and implementation of Digital Forensic Readiness plans aimed at maximizing the use of Digital evidence in organizations. The study uses interviews as part of a mixed-methods approach. In particular, it employs a mix of informal conversational and standardized open-ended interview styles conducted with industry experts over a variety of communication media.
-
IFIP Int. Conf. Digital Forensics - Cognitive Approaches for Digital Forensic Readiness Planning
Advances in Digital Forensics IX, 2013Co-Authors: Antonio Pooe, Lessing LabuschagneAbstract:This paper focuses on the use of cognitive approaches for Digital Forensic Readiness planning. Research has revealed that a well-thought-out and legally contextualized Digital Forensic Readiness strategy can provide organizations with an increased ability to respond to security incidents while maintaining the integrity of the evidence gathered and keeping investigative costs low. This paper contributes to the body of knowledge in Digital Forensics related to the design and implementation of Digital Forensic Readiness plans aimed at maximizing the use of Digital evidence in organizations. The study uses interviews as part of a mixed-methods approach. In particular, it employs a mix of informal conversational and standardized open-ended interview styles conducted with industry experts over a variety of communication media.
-
a conceptual model for Digital Forensic Readiness
Information Security for South Africa, 2012Co-Authors: Antonio Pooe, Lessing LabuschagneAbstract:The ever-growing threats of fraud and security incidents present many challenges to law enforcement and organisations across the globe. This has given rise to the need for organisations to build effective incident management strategies, which will enhance the company's reactive capability to security incidents. The aim of this paper is to propose proactive activities an organisation can undertake in order to increase its ability to respond to security incidents and create a Digitally Forensic ready workplace environment. The study constitutes exploratory research, with the use of a systematic literature review as a basis to identify activities relating to a Digitally Forensic ready environment.While much has been written about how organisations can prepare to respond to security incidents, findings show an absence of a Digital Forensic Readiness model. This paper concludes by presenting such a conceptual model. This study contributes to the greater body of knowledge on the design and implementation of a Digital Forensic Readiness programme, aimed at maximising the use of Digital evidence in an organisation.
-
ISSA - A conceptual model for Digital Forensic Readiness
2012 Information Security for South Africa, 2012Co-Authors: Antonio Pooe, Lessing LabuschagneAbstract:The ever-growing threats of fraud and security incidents present many challenges to law enforcement and organisations across the globe. This has given rise to the need for organisations to build effective incident management strategies, which will enhance the company's reactive capability to security incidents. The aim of this paper is to propose proactive activities an organisation can undertake in order to increase its ability to respond to security incidents and create a Digitally Forensic ready workplace environment. The study constitutes exploratory research, with the use of a systematic literature review as a basis to identify activities relating to a Digitally Forensic ready environment.While much has been written about how organisations can prepare to respond to security incidents, findings show an absence of a Digital Forensic Readiness model. This paper concludes by presenting such a conceptual model. This study contributes to the greater body of knowledge on the design and implementation of a Digital Forensic Readiness programme, aimed at maximising the use of Digital evidence in an organisation.