Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 29 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Nice Article on Corporate Forensics
EH-Net
May 20, 2013, 12:14:11 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Nice Article on Corporate Forensics  (Read 3634 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: October 23, 2006, 12:00:37 AM »

Good article in SC Magazine by Jim Carr on how to handle a data-stealing breach. Enterprises need to have forensics systems and personnel inplace, whether that be inside your organization or fropm an outsourcer. Either way, this article helps inform you on how to make some of those decisions.

Quote
How do you stop a criminal mind from getting into your key line-of-business systems? You probably can't, which is why Mike Jones (not his real name) keeps a computer forensics services company at his beck and call. The attempts to steal the personal identifying information on credit cards never ceases.

Jones, an investigative manager for a large U.S. financial services company (who asked to remain anonymous because of the sensitive nature of his business), relies on Cybertrust, Herndon, Va., to help him identify, forensically examine, and remediate database compromises intended to steal the information on credit cards' magnetic strips processed by his company's systems. The data-stealing breaches don't occur on his firm's systems. They actually take place on those of the retailers, restaurants and other merchants that accept credit cards as payment for goods or services.

Quote
Jones certainly isn't alone in this regard, says Michael Gavin, a senior analyst with Forrester Research. "It takes a bit of an expert to run forensics tools and know what you're doing when investigating computer-related crimes," he says.

Some of the enterprise-class computer forensics tools available include CA's eTrust Network Forensics, Guidance Software's EnCase Enterprise Forensic Edition, AccessData's FTK, NetWitness's NetWitness, and the open source Helix. They are all extremely complicated applications that require considerable training and expertise to use properly, according to Matthew Shannon, a principal with Agile Risk Management, a forensics and litigation support services provider based in Tampa, Fla.

Quote
Looking to outsource
But it often doesn't make sense to hire and keep forensics experts on staff full-time, notes Shannon. Consequently, most companies find a consulting firm they can partner with for their forensics investigations, Gavin says. PricewaterhouseCoopers and Ernest & Young, are among those Gavin points to. Others include Agile, Kroll Ontrack, Mandiant, and Neohapsis.

Quote
Keeping it inside

Still, many enterprises do keep computer forensics in-house. Just how many is open to discussion, says Forrester's Gavin.

Deploying and maintaining an enterprise-class forensics application in-house is something that requires training and a certain amount of experience, Brill says. "And, after a certain amount of time, you have to update the software, and you have to understand how the update affects how you use the software."

For full story:
http://www.scmagazine.com/us/news/article/599022/digging-dirt

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.079 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.