Your company reputation is something that when you lose you can’t get back. Now think of how you can defend against that?
The answers to the most fundamental litigation questions – the “who, what, where, when, and why” – are often contained in electronically stored information (ESI), which can be retrieved through electronic discovery (e-discovery) and/or computer forensics.
Before your investigation get out of hand you need to understand both the applications and parameters of e-discovery and computer forensics as it can be critical to the outcome of a litigation.
The primary focus of standard e-discovery is the collection of information that is active or undeleted and its metadata; which tells us about the document’s author, time of creation, source, and history. Information readily available to the user, such as e-mail, electronic calendars, word processing files, and databases from multiple hard drives, social media and other locations. Data collected in e-discovery can be limited; for deeper recovery where computer forensics tools and techniques are often used.
The goal of computer forensics is to conduct an autopsy of a computer hard drive – searching hidden folders and unallocated disk space to identify the who, what, where, when, and why from a computer. A significant amount of evidence is not readily accessible on a computer; when this occurs, a computer forensic examination is necessary.
Information gleaned from a computer forensics investigation can be very beneficial to many types of litigation and proceeding.
Computer Forensics can recover:
- Automatically stored data: Data automatically stored by the computer, such as an automated backup. A file that has been deleted may still exist as backup or temporary copy on the users hard drive.
- Deleted files: “Deleted data often remains on a hard drive until it is overwritten or forensically wiped. .
- Residual or “ghost” data: Data that remains recoverable from a computer system, but isn’t readily accessible, such as deleted files or file fragments. .
- System data: An electronic history of activity on a computer or network such as login, last users, print logs and more. .
- Wiping software: Detecting if wiping software has been used can identify potential malicious intent, tampering or advanced user capability. .
Preservation of the original evidence is absolutely crucial to any investigation and to maintain admissibility of the evidence. Creating a mirror image of the evidence device produces an exact duplicate, bit for bit, of the original evidence that allows investigator’s use without alteration of the evidence.
