Digital forensics is the process of preservation, identification, extraction of data from (and documentation of) the current state of a digital artifact. The term “digital artifact” can include:
- a computer system
- a smart phone
- a PDA
- a storage medium (such as a hard disk or CD-ROM)
- an electronic document (such as an email message or JPEG image)
- a sequence of packets moving over a computer network.
- Results are comprehensive, objective and precise.
Results must be repeatable.
Support internal users.
- data mining for PII compliance
- OHR/OSA complaints
- data recovery (email messages or documents)
- data preservation for eDiscovery
- special investigations