|
| This Article | ||
| ||
| Share | ||
| Bibliographic References | ||
| Add to: | ||
| | ||
| Search | ||
| ||
2010 19th IEEE International Workshops on Enabling Technologies: Infrastructures for Collaborative Enterprises
The Importance of Corporate Forensic Readiness in the Information Security Framework
Larissa, Greece
June 28-June 30
ISBN: 978-0-7695-4063-4
| ASCII Text | x | ||
| G. Pangalos, C. Ilioudis, I. Pagkalos, "The Importance of Corporate Forensic Readiness in the Information Security Framework," 2012 IEEE 21st International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises, pp. 12-16, 2010 19th IEEE International Workshops on Enabling Technologies: Infrastructures for Collaborative Enterprises, 2010. | |||
| BibTex | x | ||
| @article{ 10.1109/WETICE.2010.57, author = {G. Pangalos and C. Ilioudis and I. Pagkalos}, title = {The Importance of Corporate Forensic Readiness in the Information Security Framework}, journal ={2012 IEEE 21st International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises}, volume = {0}, year = {2010}, issn = {1524-4547}, pages = {12-16}, doi = {http://doi.ieeecomputersociety.org/10.1109/WETICE.2010.57}, publisher = {IEEE Computer Society}, address = {Los Alamitos, CA, USA}, } | |||
| RefWorks Procite/RefMan/Endnote | x | ||
| TY - CONF JO - 2012 IEEE 21st International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises TI - The Importance of Corporate Forensic Readiness in the Information Security Framework SN - 1524-4547 SP12 EP16 A1 - G. Pangalos, A1 - C. Ilioudis, A1 - I. Pagkalos, PY - 2010 KW - Security Policy KW - Corporate Digital Forensics KW - Digital Forensic readiness VL - 0 JA - 2012 IEEE 21st International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises ER - | |||
Corporate forensics is rapidly becoming an essential component of modern business. Having no a priori knowledge on whether a security related event or corporate policy violation will lead to litigation, it is argued in this paper that digital forensics principles need to be applied to all corporate investigatory, monitoring and auditing activities. Corporate forensics are also necessary in modern organizations in order to credibly investigate what and how it happened, what part of the security policy was breached, whether existing corporate security mechanisms are sufficient and responding promptly, help investigate the impact and costs of a security incident, help management take well documented actions, and so forth. Forensic practices are therefore departing fast from the niche of law enforcement and becoming a business function and infrastructural component. This migration poses new challenges to security professionals that must be resolved. Furthermore, protecting information and information assets solely through technical means and security procedures is also no longer sufficient in modern corporate environments, as accountability from management is also needed. Forensic readiness helps enhance the security strategy of an organization, reduce the impact of a security incident and provide management with the means to demonstrate that reasonable care has been taken to protect information resources. Forensic readiness is becoming important for modern corporate environments and a significant component of the Information Security Good Practice. In this paper we also advocate that the scope of forensics needs to be expanded in order to encompass the whole information security domain and we address a number of related issues that need further attention or must be resolved in order to take full advantage of forensic readiness in a corporate environment. The expanded scope of information security due to the inclusion of forensic readiness is expected to disturb established information security good practices. As such we challenge the concept of a generic good practice, its applicability to a specific organizational context and we investigate alternatives for adapting information security good practices to accommodate digital forensics processes.
Index Terms:
Security Policy, Corporate Digital Forensics, Digital Forensic readiness
Citation:
G. Pangalos, C. Ilioudis, I. Pagkalos, "The Importance of Corporate Forensic Readiness in the Information Security Framework," wetice, pp.12-16, 2010 19th IEEE International Workshops on Enabling Technologies: Infrastructures for Collaborative Enterprises, 2010
Usage of this product signifies your acceptance of the Terms of Use.
