A Computer Forensic Investigation generally investigates the Data Recovery Services which could be taken from computer hard disks or any other storage devices with adherence but standard policies and procedures to determine if those devices have been compromised by unauthorized access or not.
Computer Forensics Investigators also investigate the incident and conduct the forensic analysis by using various methodologies and tools to ensure the computer network system is secure in an organization.
Data Recovery Services Stages of an examination :
Evaluation- Includes the receiving of instructions, the clarification of those instructions if unclear or ambiguous, risk analysis and the allocation of roles and resources.
Collection- Involves the labelling and bagging of evidential items from the site, to be sealed in numbered tamper evident bags. Consideration should be given to securely and safely transporting Data Recovery Services the material to the examiner’s laboratory. If acquisition is to be carried out on-site rather than in a computer forensic laboratory, then this stage would include identifying and securing devices which may store evidence and documenting the scene.
Analysis- Analysis depends on the specifics of each job. The examiner usually provides feedback to the client during analysis and from this dialogue the analysis may take a different path or be narrowed to specific areas. Analysis must be accurate, thorough, impartial, recorded, repeatable and completed within the time-scales available and resources allocated.
Presentation- This stage involves the examiner producing a report on their findings, addressing the points in the initial instructions along with any subsequent instructions.