02 - Data Acquisition

Class: CYBR-405


Notes:

Cyber History

What is Cybersecurity?

image-12.png518

Computer security, physical security, information security

Cybersecurity Umbrella

GRC Prevention Defense
Policy/Procedures Firewalls/IAM/Technical SoC
Business Continuity Vulnerability Mgmt Threat Hunters
Information Assurance Penetration Testing Threat Intel
Risk Assessment Security Researchers Incident Response
Security Audits Backups Digital Forensics

The Right Mindset

Cybersecurity is about much more than IT.

Develop an Acquisition Plan

Understanding Storage Formats for Digital Evidence

Raw Format

Proprietary Formats

Advanced Forensics Format

Determining the Best Acquisition Method

It's Just Data...Right?

Rule 901. Authenticating or Identifying Evidence
(a) In General. To satisfy the requirement of authenticating or identifying an item of evidence, the proponent must produce evidence sufficient to support a finding that the item is what the proponent claims it is.

Best Evidence Rule says a copy can be used in place of the original but it has to be properly authenticated.

Validating Data Acquisitions

Windows Validation Methods

RAID

R - Redundant
A - Array
I - Independent
D - Disks

Performing RAID Data Acquisitions

Understanding RAID

Acquiring RAID Disks