ABSTRACT

Resulting from strategic integrations through the enterprise, digital forensic capabilities can be invoked to support several key business functions. Like the principles, methodologies, and techniques found within the digital forensics discipline, the incident management lifecycle provides organizations with a consistent, repeatable, and structured framework to manage and handle security events and incidents. As a component of the framework, digital forensic practitioners will be called upon to provide their subject matter and technical expertise during the incident-response activities. The incident response workflow consists of four major phases where subsets of specific activities are performed to manage the incident. The phases are Preparation; Respond; Restore; and Learn. Reverse engineering is about taking a product and dissecting it to uncover and better understand its design, so that similar or better products can be made.