: Incident Response and Computer Forensics are two areas with similar goals but distinct process models. While in both cases the goal is to investigate computer security incidents and contain their effects, Incident Response focusses more on restoration of normal service and Computer Forensics on the provision of evidence that can be used in a court of law. In this paper we present a common model for both Incident Response and Computer Forensics processes which combines their advantages in a flexible way: It allows for a management oriented approach in digital investigations while retaining the possibility of a rigorous forensics investigation.
Felix C. Freiling, Bastian Schwittay