CORPORATE GOVERNANCE FOR INFORMATION SYSTEMS SECURITY
For this SLP on Information Security Governance (ISG) assessment, you will use the National Institute of Standards and Technology Computer Forensic Tool Testing Reports (https://www.dhs.gov/science-and-technology/nist-cftt-reports) to select a forensic tool category and discuss how to use that tool category in conducting a forensic analysis at the company you select. Your company can be government, non-profit, for profit, education, etc. Any type of organization can be used. Discuss how you would apply the tool category in performing the forensic testing. Provide references to the sources you use in researching this tool category.
Sample Solution
Forensic Tool Category I will select the Data Acquisition tool category for this SLP. Data acquisition is the process of collecting data from a computer system or device for the purpose of conducting a forensic analysis. This can include data from hard drives, memory, network traffic, and other sources.Full Answer Section
Company I will use the company Google for this SLP. Google is a large, multinational technology company that operates a search engine, cloud computing platform, and a variety of other products and services. How to Use the Tool Category Data acquisition tools can be used to collect data from a variety of sources, including:- Hard drives
- Memory
- Network traffic
- Mobile devices
- Cloud storage
- Collecting data from all of the Google corporate systems
- Collecting data from specific systems that are suspected of being involved in a security breach
- Collecting data from systems that have been compromised by malware