I know there are a lot of IT people around here and at least some security specialists, so maybe there won’t be much of a demand for this thread. But I’ll give it a whirl.
I’m an IT guy with about 14 years of overall IT experience. The last 8 years or so, I’ve been focused on information security, and most recently on forensics and investigations. I’m currently the lead forensic investigator on the in-house incident response team of a Fortune 50 company with over 30,000 employees. I’m a member of a team that responds to suspected external breaches, suspected insider abuse, and legal discovery requests.
I’ve done security of one kind or another, including forensics, for big for-profit companies, large and small healthcare organizations, and a medium-sized university.
Among my industry certifications is the Certified Computer Examiner (CCE) from The International Society of Forensic Computer Examiners (terrible website, but a respected organization and credential in the forensic community.)
Almost all of my forensic and investigative experience has been as an in-house incident response guy for private organizations. So, I’ve never done any criminal defense, divorce cases, child porn cases, etc. Somehow I’ve also managed to avoid being called to testify in court (got close recently, but the other side settled the day before the trial was supposed to start).
So, is there anything you’ve always wanted to know about computer forensics? Security incident response? Computer security in general?
A few disclaimers:
[ol]
[li]I am not a lawyer.[/li][li]Please don’t ask me how to destroy evidence of whatever bad thing you’ve done.[/li][li]I don’t watch a lot of TV, but the few times I’ve seen TV characters try to do computer forensics, it has made me cry. If you ask me how realistic a particular show is, I probably have no idea. My guess is “not realistic at all.”[/li][li]I have not been following the Lois Lerner thing, and I don’t know what the deal is with her emails.[/li][/ol]
Ask away!