Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Workstation Security
• Workstations should be shielded from transmitting electromagnetic signals. It is a known fact that
electronic equipment emits electromagnetic radiation. There are certain pieces of equipment that can
intercept this radiation.
• The radiation can be used to determine the data that the equipment is transmitting or displaying. There is
a solution to shield the emissions. The U.S. Department of Defense has named this solution
Telecommunications Electronics Material Protected from Emanating Spurious Transmissions, or TEMPEST
Fire Safety
Fire-Suppression Systems
The following are some fire-suppression systems
that should be in place in a forensic lab:
• Dry chemical fire extinguisher system to deal with
fires that occur due to chemical reactions
• Sprinkler system that should be checked
frequently to make sure it is still working
Fire extinguishers should be placed within and
outside the lab.
Evidence Locker Recommendations
Checking the Security of a Forensic Lab
Work Area of a Computer Forensic Lab
General Configuration of a Forensic Lab
Electrical Needs
• Amperage: Amperage is a measurement of the electric current.
• Emergency power and lighting: Emergency power and lighting should be
provided for the following parts of the lab:
• All the evidence sections
• All the security sections, electronic security systems, and telephones
• X-ray processing rooms and photography dark rooms
• Electrical outlets: There must be easy access to the electrical outlets in the lab.
• UPS:
Communications
The following factors should be considered
when assessing the communications systems
available in the lab:
• Bandwidth
• Dial-up access
• Disconnection
• Network
Basic Workstation Requirements in a Forensic Lab
• SATA cables
• A variety of detachable storage media like Jaz cartridges, Zip cartridges, and USB drives
• Other electronic storage devices (CompactFlash cards, SmartMedia cards, Secure Digital cards, Multi-Media cards,
and Memory Stick)
• CD/DVD readers and writers
• Ribbon cables for floppy disks
• Extra IDE hard drives
• Extra RAM
• Extra SCSI cards
• Graphics cards (ISA, PCI, AGP, and PCI Express)
• Extra power cords
• A variety of hard disk drives
• Laptop hard drive connectors
• Handheld devices
• Supplementary storage devices for creating bit-stream copies or clones of the suspect storage
media for examination purposes
Maintaining Operating System and
Application Inventories
The following are the applications and operating systems that must be maintained:
• Windows Vista, XP, 2003, and 2000 operating systems
• Linux, Unix, and Mac OS X operating systems
• Microsoft Office XP, 2007, 2003, 2000, 97, and 95
• Programming language applications such as Visual Studio
• Specialized viewers such as QuickView and ACDSee
• Corel Office Suite
• StarOffice/OpenOffice
• Peachtree accounting applications
• Older operating systems and applications such as MS-DOS, Windows 3.11, and Novell for examining
older systems
• Forensic software with advanced features and functionalities, such as:
• Bit-stream backup utilities
• Password recovery tools
• Recovery tools for deleted data
• Partition recovery tools
• Searching tools
• Firewalls and intrusion detection systems
• Updated antivirus software
Required Forensic Tools
Storage Bags
• Wireless storage bags: These types of bags are
used to store wireless devices
• Passport bags: Many passports contain radio-
frequency identification (RFID) chips.
Remote Chargers
Paraben’s Passport StrongHold Bag is used to
keep data stored on RFID chips in passports
secure.
Remote chargers allow a forensic investigator to
provide power to any device in the field.
This write block protection device allows an
investigator to attach a storage device to a
computer’s SATA connector.
This device allows an investigator to attach a storage
device to a computer’s USB or Firewire port without
fear of altering the data.
Data Acquisition Tools
• Cables
• Rapid action imaging devices (RAIDs)
• SIM card readers
• Video-capture devices
• Forensic Archive and Restore Devices
• Mobile Forensic Laptops
• Forensic Workstations
• Imaging Workstations
• Software
This cable connects a serial
device to a computer’s USB port.
This RAID is used to quickly make copies of
hard drives.
This SIM card reader connects a SIM card to a
computer’s USB port.
This device is used to record video of a device’s
screens when there is no other way to acquire
the data on the device.
This is the kind of workstation found in a
forensic lab.
Investigations at a Computer Forensic Lab