Title :
The Governance of Corporate Forensics Using COBIT, NIST and Increased Automated Forensic Approaches
Author :
Nnoli, H. ; Lindskog, Dale ; Zavarsky, Pavol ; Aghili, Shaun ; Ruhl, Ron
Author_Institution :
ATB Financial, Edmonton, AB, Canada
Abstract :
Today, the ability to investigate internal matters such as policy violations, regulatory compliance, and employee separation has become important in order for corporations to manage risk. The degree of information security threats evolving on a daily basis has increasingly raised concerns for enterprise organizations. These threats include but are not limited to fraud, insider threat and intellectual property (IP) theft. These have increased the demand for organizations to implement corporate forensics as a deterrent to illegitimate acts or for linking perpetrators to their illegitimate acts. This explains why forensic practices are expanding from the traditional role in law enforcement and becoming an essential part of business processes. However, most organizations may not be maximizing the benefits of corporate forensic capabilities because of lack of corporate forensic governance best practices, needed to ensure organizations prepare their operating environment for digital forensic investigation. Corporate forensic governance will help ensure that digital evidence is obtained in an efficient and effective way with minimal interruption to the business. This paper presents a corporate forensic governance framework intended to enhance forensic readiness, governance, and management, and increase the use of automated forensic techniques and in-house forensically sound practices in large organizations that have a need for these practices.
Keywords :
business data processing; digital forensics; fraud; industrial property; organisational aspects; risk management; COBIT; IP theft; NIST; automated forensic approach; automated forensic technique; business process; corporate forensic governance; corporation; digital evidence; digital forensic investigation; employee separation; enterprise organization; forensic management; forensic readiness; fraud; information security threat; insider threat; intellectual property; law enforcement; policy violation; regulatory compliance; risk management; Best practices; Digital forensics; Organizations; Risk management; Standards organizations; corporate forensic governance; corporate forensic readiness; digital evidence; digital forensic investigation; increased automated forensic solutions;
Conference_Titel :
Privacy, Security, Risk and Trust (PASSAT), 2012 International Conference on and 2012 International Confernece on Social Computing (SocialCom)
Conference_Location :
Amsterdam
Print_ISBN :
978-1-4673-5638-1
DOI :
10.1109/SocialCom-PASSAT.2012.109