24.2 – Approach and Process

Digital forensics includes the protection, identification, extraction, understanding, and documentation of digital evidence. The sector of digital forensics has different aspects and is not described by one particular process. At a very basic level, digital forensics is the investigation of information contained within and created with digital systems, usually in the interest of understanding what occurred, when it occurred, how it occurred, and who was involved. Digital evidence is found in servers, computers, smart phones, e-mail, tablets, external hard drives, USB flash drives and removable media. The digital forensics process includes: Acquisition Preservation Analysis Reporting Acquisition:…