<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>innovative-csi.com Blog &#187; Electronic Discovery</title>
	<atom:link href="http://innovative-csi.com/blog/index.php/category/ediscovery/feed/" rel="self" type="application/rss+xml" />
	<link>http://innovative-csi.com/blog</link>
	<description>Innovative-CSI Information Security Blog</description>
	<lastBuildDate>Sun, 23 Nov 2008 23:35:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Computer Forensic changing environment!</title>
		<link>http://innovative-csi.com/blog/2008/09/02/computer-forensic-changing-environment/</link>
		<comments>http://innovative-csi.com/blog/2008/09/02/computer-forensic-changing-environment/#comments</comments>
		<pubDate>Tue, 02 Sep 2008 18:01:41 +0000</pubDate>
		<dc:creator>dhopkins</dc:creator>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>

		<guid isPermaLink="false">http://innovative-csi.com/blog/2008/09/02/computer-forensic-changing-environment/</guid>
		<description><![CDATA[Rapid changes in computer forensics investigations are starting to shape the future of the industry and solidify the profession.  If you are not adaptable to change then computer forensics is not the place for you.  The constant change in the industry and technology advances the profession into multiple areas of growth for the industry.  One [...]]]></description>
			<content:encoded><![CDATA[<p><font size="3"><font face="Calibri">Rapid changes in computer forensics investigations are starting to shape the future of the industry and solidify the profession.  If you are not adaptable to change then computer forensics is not the place for you.  The constant change in the industry and technology advances the profession into multiple areas of growth for the industry.  One of the major changes with computer forensics professionals is the nationwide acceptance of states going to a professional investigator licensing under state law.  The last time I checked 42 states had something on the books under licensing computer forensics professionals.    It is easier to track the states not on the books than the ones that are on the books .  Many challenges will need to be worked out as the individual states license the profession.  The need for affiliation with other states will become a necessity to meet the common practices of the computer forensics industry due to our national and global environment.  This change is good for the profession of computer forensics, but states should take a closer look at best practices and knowledge from the computer forensics professionals into account.   I would venture to say that the license professional investigator may someday have federal regulations as computer forensics investigations are so transverse across multiple states and/or countries.  It will be interesting how the field and state regulations play out over the next few years.   Should States engage in reciprocal and standardizing the process between States or should this be regulated at a federal level?</font></font></p>
<p><font size="3"><font face="Calibri"><br />
</font></font><font face="Calibri" size="3">As the battle goes on about defining the profession, technology is advancing the industry to provide more information to the computer forensic investigator.  The latest trend is memory analysis that is providing detailed information that the investigator did not think of in past investigations.  Memory forensics is providing clear analysis of the whole picture when it comes to the investigation.  The advantage of memory analysis is that it is putting you at the crime spot with your camera in hand.  Vital state information of the machine is becoming key in the process of computer forensics.  The value of live investigations provides rapid response, meets the challenge of large network topology, and circumvents encrypted file systems.  The analysis with live investigations becomes a quick and easy way to find out the state of the system with accessible areas like current user activity, running processes, handles, registered drivers, physical memory analysis, system info, network connectivity and attached peripherals.  The amount of information provides investigators the ability to connect the dots a lot faster and/or provide a pre-incident triage of the computer before arriving on the scene.  The challenge that live investigations creates is a total paradigm shift in the investigation process.  The investigation becomes a proactive thought process to implement.   What comes with the paradigm shift is another level of education for the legal profession and the process of memory analysis is looking at the state of the system in a constantly changing environment.  In a live environment, users are still using the computer and changing the system state all the time.  Remember you have your camera in hand and the snap-shot is a moment in time which is very different than the post-mortem analysis.   Will the courts accept the premises of memory analysis or will they struggle and continue to revert back to the post-mortem process?</font><br />
 </p>
]]></content:encoded>
			<wfw:commentRss>http://innovative-csi.com/blog/2008/09/02/computer-forensic-changing-environment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The First Test for Michigan&#8217;s Public Act 146</title>
		<link>http://innovative-csi.com/blog/2008/08/13/the-first-test-for-michigans-public-act-146/</link>
		<comments>http://innovative-csi.com/blog/2008/08/13/the-first-test-for-michigans-public-act-146/#comments</comments>
		<pubDate>Wed, 13 Aug 2008 18:16:55 +0000</pubDate>
		<dc:creator>dhopkins</dc:creator>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>

		<guid isPermaLink="false">http://innovative-csi.com/blog/2008/08/13/the-first-test-for-michigans-public-act-146/</guid>
		<description><![CDATA[Less than two months old Public Act 146 will be put to the challenge.  Public Act 146 impacts the computer forensics industry by requiring all investigators to become licensed in the State of Michigan.  Individuals and companies must meet the qualifications by the Act that is administered by the Department of Labor and Economic Growth [...]]]></description>
			<content:encoded><![CDATA[<p><font size="3"><font face="Calibri">Less than two months old Public Act 146 will be put to the challenge.  Public Act 146 impacts the computer forensics industry by requiring all investigators to become licensed in the State of Michigan.  Individuals and companies must meet the qualifications by the Act that is administered by the Department of Labor and Economic Growth (DLEG).  Public Act 146 was immediate effective on May 28, 2008 and holds stiff penalty of a four year felony charge for non-licensed individuals. </font></font><font size="3"><font face="Calibri"><br />
<font size="3"><font face="Calibri"> </font></font></font></font></p>
<p><font size="3"><font face="Calibri"><font size="3"><font face="Calibri">Reported in ComputerWorld on August 12<sup>th</sup> 2008, </font></font></font></font><font size="3"><font face="Calibri"><font size="3"><font face="Calibri">Belcamp, Maryland based MediaSentry parent company SafeNet had complaints filed against the company for violations of the new Public Act 146 for the investigation of students from Central Michigan University and University of Michigan.  According to the SafeNet website, “they help clients detect and deter unauthorized distribution of copyrighted content and prosecute those who engage in media and software piracy.”  Read more of the details in the article by ComputerWorld:</font></font></font></font><font size="3"><font face="Calibri"> </font></font><font size="3"><font face="Calibri"><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9112467&#038;pageNumber=1">http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9112467&#038;pageNumber=1</a></font></font></p>
<p><font size="3"><font face="Calibri"><br />
This news is interesting on several levels as the new law takes form in the State of Michigan.  Is the new law actually doing some good by protecting the legitimacy of the profession of Computer Forensics investigations?  Or is this a tactical approach for the defense?  As the Act claims it first victim it will be very interesting how this will play out over the next few months.</font></font><font size="3"><font face="Calibri"><font size="3"><font size="3"><font size="3"><font face="Calibri"> </p>
<p></font></font></font></font> </p>
<p></font></font></p>
]]></content:encoded>
			<wfw:commentRss>http://innovative-csi.com/blog/2008/08/13/the-first-test-for-michigans-public-act-146/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Breaking down the process of the Public Act 146</title>
		<link>http://innovative-csi.com/blog/2008/07/22/breaking-down-the-process-of-the-public-act-146/</link>
		<comments>http://innovative-csi.com/blog/2008/07/22/breaking-down-the-process-of-the-public-act-146/#comments</comments>
		<pubDate>Tue, 22 Jul 2008 14:24:21 +0000</pubDate>
		<dc:creator>dhopkins</dc:creator>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>

		<guid isPermaLink="false">http://innovative-csi.com/blog/2008/07/22/breaking-down-the-process-of-the-public-act-146/</guid>
		<description><![CDATA[Public Act 146 impacts the computer forensics industry by requiring all investigators to become licensed in the State of Michigan.  Individuals and companies that meet the qualifications have had to scramble due to the immediate effective date of May 28, 2008 and the stiff penalty of a four year felony charge for none licensed individuals.  [...]]]></description>
			<content:encoded><![CDATA[<p><font size="3"><font face="Calibri">Public Act 146 impacts the computer forensics industry by requiring all investigators to become licensed in the State of Michigan.  Individuals and companies that meet the qualifications have had to scramble due to the immediate effective date of May 28, 2008 and the stiff penalty of a four year felony charge for none licensed individuals.  The time table you can expect is roughly about two weeks for the collection of information you will need to meet the required qualifications listed below in the link.  The application time can range from 4 to 16 weeks to receive the license.  The last time I checked they posted 12 to 16 weeks to be safe.  </font></font></p>
<p><font size="3"><font face="Calibri">The problem that people in the industry are facing is that the act was implemented/rolled out without any planning or grace period to adjust to the new act.  The impact of this new law has affected our current clients and case load prior to the act passing.  The application time period is not fast enough and there will be no time to compensate for the loss of current and potential business.  We have been one of the lucky ones to have a diversified array of services in information security to absorb the impact of this act passing.  </font></font></p>
<p><font face="Calibri" size="3">The Computer Forensics Industry and DLEG will have to work closely together to bring Public Act 146 and the industry into compliance.  The concerning area that will have a greater impact on the industry is the affiliations with other states on computer forensics investigations.  As the network grows and grows in a global economy so does the need for speed and availability of accessing the data in any location.  Public Act 146 has impacted the security and IT industry tremendously from computer forensics, eDiscovery and monitoring of individuals.  According to the act an investigation starts when you are targeting or questioning an individual’s: </font></p>
<p><font face="Calibri" size="3">(e)(ii) – the identity, habits, conduct, business, occupation, honesty, integrity, credibility, trustworthiness, efficiency, loyalty, activity, movement, whereabouts, affiliations, associations, transactions, acts, reputation or character of a person.</font></p>
<p><font size="3"><font face="Calibri">In the IT world this could be the tracking of IP addresses, MAC address, VOIP, email address, etc., that would link the computer to the individual.  This is where I would express extreme caution based on the general statement of targeting individuals.  The impact reaches beyond the computer forensics professional and now applies itself to all investigations as any investigation in today’s working world deals with some kind of computer based evidence that will be used to prove an individual’s wrong doing.  </font></font></p>
<p><font size="3"><font face="Calibri">I believe that Public Act 146 will be good for the industry once we get through the scramble of compliance with the act.  Overall Public Act 146 will become a milestone for the information security industry and serve to increase the amount of professionalism that should be expected by the professionals in the field.  </font></font></p>
<p><font face="Calibri" size="3">Forms &#038; Publications – Private Detective Form </font><a href="http://www.dleg.state.mi.us/dms/results.asp?docowner=BCSC&#038;doccat=Private+Detectives&#038;Search=Search"><font face="Calibri" size="3">http://www.dleg.state.mi.us/dms/results.asp?docowner=BCSC&#038;doccat=Private+Detectives&#038;Search=Search</font></a></p>
<p><a href="http://www.michigan.gov/commerciallicensing"><font face="Calibri" size="3">www.michigan.gov/commerciallicensing</font></a></p>
]]></content:encoded>
			<wfw:commentRss>http://innovative-csi.com/blog/2008/07/22/breaking-down-the-process-of-the-public-act-146/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Where do I start when preserving data in Electronic Discovery?</title>
		<link>http://innovative-csi.com/blog/2007/03/30/where-do-i-start-when-preserving-data-in-electronic-discovery/</link>
		<comments>http://innovative-csi.com/blog/2007/03/30/where-do-i-start-when-preserving-data-in-electronic-discovery/#comments</comments>
		<pubDate>Fri, 30 Mar 2007 14:26:09 +0000</pubDate>
		<dc:creator>dhopkins</dc:creator>
				<category><![CDATA[Electronic Discovery]]></category>

		<guid isPermaLink="false">http://innovative-csi.com/blog/2007/03/30/where-do-i-start-when-preserving-data-in-electronic-discovery/</guid>
		<description><![CDATA[Preservation starts with having a good plan with protocols in place to achieve positive results. Having an incident response plan in place is critical to the success and reduction of stress to a thin IT staff.  The plan should involve or integrate the use of an expert available to consult you in the process. Planning [...]]]></description>
			<content:encoded><![CDATA[<p><font size="3">Preservation starts with having a good plan with protocols in place to achieve positive results. Having an incident response plan in place is critical to the success and reduction of stress to a thin IT staff.  The plan should involve or integrate the use of an expert available to consult you in the process. Planning will serve as the framework to reduce the risk of exposure and maximize the benefit of electronic discovery.  The key steps for the electronic discovery process are the following<font face="Times New Roman">: </font></font></p>
<ul type="disc">
<li><font size="3">Preparation<br />
</font></li>
<li><font size="3">Preservation and Collection of evidence<br />
</font></li>
<li><font size="3">Examination of evidence<br />
</font></li>
<li><font size="3">Analysis of evidence<br />
</font></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://innovative-csi.com/blog/2007/03/30/where-do-i-start-when-preserving-data-in-electronic-discovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.184 seconds -->

