IT-Forensik
IT Forensics / Digital Forensics
IT-Forensik
IT forensics is the methodical, evidentially sound investigation of digital systems in order to reconstruct, after an incident, what happened — who, when, how and with what effect. It combines technical analysis with strict methodology so that the results are traceable and admissible in court. It turns data traces into robust statements.
History & facts. From an initially improvised field, a discipline with recognised principles has emerged: immutability of the evidence, traceability of every step and seamless documentation (chain of custody). In Germany, the Federal Office for Information Security (Germany) (BSI) guideline on IT forensics provides a structured framework. Common phases are strategic preparation, data preservation (acquisition/imaging), examination and analysis, and the documentation and presentation of the results.
Outlook & recommendation. With the increasing shift to the cloud, mobile devices and volatile memory, forensics moves from the classic data carrier towards distributed, transient traces — which makes preparation and fast, correct preservation more important. For regulated entities, forensic capability is at the same time a precondition of the Network and Information Security Directive 2 (NIS2) evidence duties. NEOSEC brings this competence from practice; the management (J. Benjamin Espagné) is certified, among other things, as an ISO/IEC 27001 — Information Security Management System (ISO 27001) lead auditor.