Digital Forensics and Investigations: People, Process, and Technologies to Defend the Enterprise
暫譯: 數位鑑識與調查:保護企業的人民、流程與技術
Sachowski, Jason
- 出版商: CRC
- 出版日期: 2021-03-31
- 售價: $3,380
- 貴賓價: 9.5 折 $3,211
- 語言: 英文
- 頁數: 366
- 裝訂: Quality Paper - also called trade paper
- ISBN: 0367778653
- ISBN-13: 9780367778651
-
其他版本:
Digital Forensics and Investigations: People, Process, and Technologies to Defend the Enterprise
相關主題
商品描述
Digital forensics has been a discipline of Information Security for decades now. Its principles, methodologies, and techniques have remained consistent despite the evolution of technology, and, ultimately, it and can be applied to any form of digital data. However, within a corporate environment, digital forensic professionals are particularly challenged. They must maintain the legal admissibility and forensic viability of digital evidence in support of a broad range of different business functions that include incident response, electronic discovery (ediscovery), and ensuring the controls and accountability of such information across networks.
Digital Forensics and Investigations: People, Process, and Technologies to Defend the Enterprise provides the methodologies and strategies necessary for these key business functions to seamlessly integrate digital forensic capabilities to guarantee the admissibility and integrity of digital evidence. In many books, the focus on digital evidence is primarily in the technical, software, and investigative elements, of which there are numerous publications. What tends to get overlooked are the people and process elements within the organization.
Taking a step back, the book outlines the importance of integrating and accounting for the people, process, and technology components of digital forensics. In essence, to establish a holistic paradigm--and best-practice procedure and policy approach--to defending the enterprise. This book serves as a roadmap for professionals to successfully integrate an organization's people, process, and technology with other key business functions in an enterprise's digital forensic capabilities.
商品描述(中文翻譯)
數位鑑識已經成為資訊安全的一個學科數十年。其原則、方法論和技術儘管隨著技術的演變而保持一致,最終可以應用於任何形式的數位數據。然而,在企業環境中,數位鑑識專業人員面臨特別的挑戰。他們必須維持數位證據的法律可接受性和鑑識有效性,以支持包括事件響應、電子發現(ediscovery)在內的各種業務功能,並確保這些資訊在網絡中的控制和問責。
《數位鑑識與調查:保護企業的人民、流程和技術》提供了這些關鍵業務功能所需的方法論和策略,以無縫整合數位鑑識能力,確保數位證據的可接受性和完整性。在許多書籍中,對數位證據的關注主要集中在技術、軟體和調查元素上,這方面的出版物不勝枚舉。然而,組織內部的人員和流程元素往往被忽視。
退一步來看,本書概述了整合和考量數位鑑識的人員、流程和技術組件的重要性。實質上,建立一個整體範式——以及最佳實踐程序和政策方法——來保護企業。本書作為專業人士的路線圖,幫助他們成功地將組織的人員、流程和技術與企業數位鑑識能力中的其他關鍵業務功能整合。
作者簡介
Jason Sachowski has over twelve years of experience in digital forensic investigations, secure software development, and information security architecture. He currently manages a team of forensic investigators and data breach analysts for The Bank of Nova Scotia, commonly known as Scotiabank, Canada's third largest and most international bank.
Throughout his career, Jason has performed hundreds of digital forensic investigations involving Enterprise servers, network logs, smart phones, and database systems. Complimentary to his technical experiences, he has also developed and maintained processes and procedures, managed large information security budgets, and governed the negotiation of third-party contracts.
In addition to his professional career, Jason is the author of book 'Implementing Digital Forensic Readiness: From Reactive to Proactive Process'. He also serves as a contributing author and content moderator for DarkReading, is a subject matter expert for (ISC)2 professional exam development, and volunteers as an advocate for CyberBullying prevention and CyberSecurity awareness.
He holds several Information Security and Digital Forensic certifications including: Certified Information Systems Security Professional - Information Systems Security Architecture Professional (CISSP-ISSAP), Certified Cyber Forensics Professional (CCFP), Certified Secure Software Lifecycle Professional (CSSLP), Systems Security Certified Practitioner (SSCP), and EnCase Certified Examiner (EnCE).
作者簡介(中文翻譯)
Jason Sachowski 擁有超過十二年的數位鑑識調查、安全軟體開發和資訊安全架構的經驗。他目前在加拿大第三大且最具國際化的銀行——新斯科舍銀行(Scotiabank)管理一支數位鑑識調查員和資料洩漏分析師的團隊。
在他的職業生涯中,Jason 進行了數百次涉及企業伺服器、網路日誌、智慧型手機和資料庫系統的數位鑑識調查。除了技術經驗外,他還開發和維護流程與程序,管理大型資訊安全預算,並負責第三方合約的談判。
除了專業生涯外,Jason 還是書籍《實施數位鑑識準備:從反應式到主動式流程》的作者。他同時擔任 DarkReading 的貢獻作者和內容審核員,是 (ISC)² 專業考試開發的主題專家,並自願擔任網路霸凌預防和網路安全意識的倡導者。
他擁有多項資訊安全和數位鑑識的認證,包括:認證資訊系統安全專業人員 - 資訊系統安全架構專業人員 (CISSP-ISSAP)、認證網路鑑識專業人員 (CCFP)、認證安全軟體生命週期專業人員 (CSSLP)、系統安全認證從業人員 (SSCP) 和 EnCase 認證考官 (EnCE)。