Digital forensics is the discipline of identifying, collecting, preserving, and analysing digital evidence to support incident response, legal proceedings, and threat attribution. It defines procedures, tools and governance to ensure evidence integrity and legal admissibility. Forensic readiness reduces investigation time and preserves chain-of-custody.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Digital forensics is the set of methods used to identify, preserve, and examine digital traces so they remain reliable for investigations, incident response, and legal proceedings.
The field grew from the need to preserve traces from PCs, networks, and later mobile and distributed systems so they remain usable in investigations and in court. As computer crime increased in the 1980s and 1990s, specialist teams and ad hoc procedures appeared; in the 2000s, standards and guidance followed, bringing technical examination together with incident response and evidence handling.
Think of digital forensics as a controlled evidence pipeline. First, decide what may be collected at all. Then copy media or storage states as gently as possible, document every handoff, and verify integrity. Next, inspect artifacts, metadata, and timelines to reconstruct events, causes, and attribution in a traceable way. The output is an evidential finding, not just a tool result.
Artifacts from devices, accounts, or networks can support claims about an incident, an action, or a state.
Hashes, documented handoffs, and careful acquisition make tampering or accidental change detectable.
Every access to and transfer of the exhibit remains traceable by time and person.
A bit-for-bit copy allows examination without repeatedly changing or stressing the original.
Forensic results provide reliable traces for containment, analysis, and recovery after an incident.
Digital forensics is useful after security incidents, in internal investigations, and in criminal or civil proceedings. It matters most when statements must later be proven reliably. The trade-off is time, specialist skill, and clean access rights; without early preservation, logs, and enough storage headroom, data can become incomplete or no longer admissible.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.