Forensics

From Working EDRM

Jump to: navigation, search
Comments: Please submit comments to the EDRM Glossary forum
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 1 2 3 4 5 6 7 8 9
  • For electronic data, the discovery discipline that includes the physical acquisition of digital data using methodology that satisfies evidentiary requirements of chain-of-custody and authentication. Preserving the evidence includes performing code and encryption cracking, searching and retrieving elusive data, determining if files have or have not been deleted, recovering deleted files, and determining use, including Internet, network access, printing, filing, and copying.[1]
  • In document management terms, forensic work is comprised of:
    • Recreating “deleted” or missing files from hard drives
    • Validating dates and logged in authors / editors of documents
    • Certifying key elements of documents and/or hardware for legal purposes[2]


See also

Footnotes

  1. ^  Ibis Consulting, Glossary.
  2. ^  American Document Management, Glossary of Terms, http://www.amdoc.com/glossary.shtml.
Personal tools
additional information