What is computer forensics?

What is computer forensics?
June 22, 2020 Comments Off on What is computer forensics? Uncategorized Assignment-help
Words: 1072
Pages: 4
Subject: Uncategorized

#1(Q1) Domain 1 – Security and Risk Management – Shawn ReifContains unread posts The way I think about defense in depth is layered security. Your residence may have a fence surrounding your home. Inside the fence, you may have a dog. Outside your home you have added passive infrared sensor lighting. Locked windows and doors of your home is another layer. The Ring Home Security System allows you to monitor your home remotely from your cellular phone. Bypassing any one security layer causes an intruder to face another layer. Defeating each layer may prove to be too risky, so they move on the easier targets of opportunity. Defense in depth within a computer network is both physically and virtually maintained. Access to the office building is the first physical layer. Access to a desk containing an information system would be a second physical layer. Access to computer network endpoints (e.g. laptops, desktops, printers, and scanners) is usually limited to authorized personnel with usernames and passwords. A third layer requires employees use something they have, physical tokens with PKI certificates(e.g. Common Access Cards), with something they know, their security pins to access information systems with their PKI certificates. Additional physical layers include a locked network server room to prevent unauthorized physical access. Additional virtual layers will restrict and limit network access and permissions to the operating system and other files and folders. Active directory facilitates a process for assigning network, file and folder permissions to groups or individuals. These permissions are controlled virtually with software. Administrative controls can add an additional layer of defense in depth to a computer network. Separation of duties, job rotation, and mandatory vacations used together is a best business practice. Separation of duties divides and applies tasks to specific job functions (Purcell, 2020). Network administrators give employees just enough permissions to do their job (Purcell, 2020). Network administrators themselves must divide network responsibilities to ensure one person does not possess root permissions and complete access to destroy or corrupt the networks confidentiality, integrity, or availability (Purcell, 2020). Requiring two person integrity to execute network changes is one way to keep network administrators honest (Purcell, 2020). Job rotation is a change in the employees roles and responsibilities (Purcell, 2020). Job rotation limits the duration an employee can conduct malicious or fraudulent activity (Purcell, 2020). Mandatory vacations ensures employees are out of the office for a period of time (Purcell, 2020). One or two weeks away from work is enough time to audit and detect fraud or malicious activity in the workplace (Purcell, 2020). Employed together, separation of duties, job rotation, and mandatory vacations can identify employees who are involved in fraud or other malicious activities (Purcell, 2020). Maintaining network confidentiality integrity, and availability is a goal of every network administrator. Many of us only seem concerned with the availability of the network since it directly impacts our ability to complete our own work. Unfortunately security can be compromised when an employee carelessly clicks on the link in a phishing email. In Gualt’s Wired magazine article, he opined system administrators should expect the networks will or already have been compromised (Gualt, 2015). Instead of attempting to guarantee network are free from virus and malware, network administrators should design networks to be resilient against attacks and have methods to mitigate the risk to sensitive company information (Gualt, 2015). The article gives reasons for why integrity is more important than confidentiality (Gualt, 2015). Gualt claims confidentiality only gives an attacker insight whereas integrity gives an attacker control (Gualt, 2015). He uses a military weapon system as an example (Gualt, 2015). I will have to disagree with him on this point. Even if integrity can give an adversary control of a weapons system, confidentiality can give our adversaries enough insight to kill, counter, or clone our technologies. If our adversaries know what frequency range we employ, then they can jam that part of the frequency spectrum or deny our use of GPS guided weapons. I would argue both confidentiality and integrity are equally important. And not having network availability makes any discussion of confidentiality and integrity a moot point.———————————- #2(Q2) Domain 1A patent protects the right of an individual or organization to be the sole manufacturer of a certain invention. The protection of a patent expires after a certain amount of time, at which point the invention may be developed by other organizations. Patents are offered by the United States Patent and Trademark Office in exchange for public disclosure of the invention.A copyright protects intellectual property developed by an individual or organization. The copyright grants the exclusive right to produce copies of the work. Copyright protection also expires after a set amount of time determined by the United States Copyright Office.“A trademark is a word, phrase, symbol, and/or design that identifies and distinguishes the source of the goods of one party from those of others” (United States Patent and Trademark Office, n.d.). Trademarks differ from patents and copyrights in that they do not expire after a certain amount of time. Trademarks are protected while the trademark is still in use.—————————————#3CCJSWeek 1Contains unread postsProvide at least one example of how being familiar with and following digital forensic best practices, AND criminal justice standards would benefit you, even if you worked in a non-criminal justice digital forensics position.Digital forensics is the collection and analysis of electronic data. With the introduction and constant evolution of technology, crime has been in lockstep. Because of this, digital forensics has become an important component in the investigation and prosecution of criminal cases. Personally, I do not work directly in criminal justice, but as a computer network analyst, the paths between digital forensics and criminal justice often intertwine. To conduct any sort of analysis, whatever evidence is collected must be thoroughly reviewed, but then there lies these questions: “Has this collection been legally obtained?” and “Does it infringe on the rights of those involved?” There are policies in place that safeguard the rights of the parties involved such as USSID SP0018, which defines U.S. persons, or the Fourth Amendment, which protects against unlawful search and seizure (Lytle, Stephens, Conner, Bashiri, & Jones, 2018). Tying into the fourth of the ACPO Guide principles, policies such as these ensure that we remain legally compliant in the collection and analysis of our evidence and prevents myself and other analyst from running into compliance issues and compromising the integrity of our work and the investigation (“What is computer forensics?”, n.d.).