• DocumentCode
    3544193
  • Title

    Harmonised digital forensic investigation process model

  • Author

    Valjarevic, Aleksandar ; Venter, Hein S.

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Pretoria, Pretoria, South Africa
  • fYear
    2012
  • fDate
    15-17 Aug. 2012
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    Digital forensics gained significant importance over the past decade, due to the increase in the number of information security incidents over this time period, but also due to the fact that our society is becoming more dependent on information technology. Performing a digital forensic investigation requires a standardised and formalised process to be followed. There is currently no international standard formalising the digital forensic investigation process, nor does a harmonised digital forensic investigation process exist that is acceptable in this field. This paper proposes a harmonised digital forensic investigation process model. The proposed model is an iterative and multi-tier model. The authors introduce the term “parallel actions”, defined as the principles which should be translated into actions within the digital forensic investigation process (i.e. principle that evidence´s integrity must be preserved through the process and that chain of evidence must be preserved). The authors believe that the proposed model is comprehensive and that it harmonises existing state-of-the-art digital forensic investigation process models. Furthermore, we believe that the proposed model can lead to the standardisation of the digital forensic investigation process.
  • Keywords
    computer forensics; iterative methods; parallel processing; formalised process; harmonised digital forensic investigation process model; information security; information technology; iterative model; parallel actions; Analytical models; Digital forensics; Guidelines; Information systems; Planning; digital forensics; information systems security; model; process;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security for South Africa (ISSA), 2012
  • Conference_Location
    Johannesburg, Gauteng
  • Print_ISBN
    978-1-4673-2160-0
  • Type

    conf

  • DOI
    10.1109/ISSA.2012.6320441
  • Filename
    6320441