Digital forensics is the collection, preservation and analysis of digital evidence in a way that can stand up to scrutiny, whether in court, in a regulatory inquiry, or in an internal disciplinary process. Even when no one expects a court case, following forensic principles means the investigation's conclusions can be trusted. Security+ focuses on the procedures that protect evidence: collecting it in the right order, keeping a documented chain of custody, preserving it under legal hold, and acquiring copies without altering the original.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.