Response to peers

profilePrashanthi
ArjunJujjuri-ERM.docx

Top of Form

Among the cybercrimes that have occurred in recent years, it is said that there are many internal crimes. Log data that is constantly collected within a company and digital forensics technology that analyzes it are useful in pursuing the crime. Digital forensics is the collection and analysis of information recorded on digital devices (Reddy & Venter, 2013). It is being used as evidence for internal investigations and trials within companies against the increasing number of cybercrimes. Most of the crimes are other than unauthorized access from outside the company, and it can be seen that there are many security incidents caused by people inside the company. Specific examples include internal fraud, unintended use, unauthorized information removal, management mistakes, setting mistakes, and erroneous operations (Serra & Venter, 2011). Given the risk that security incidents can lead to enormous damage these days, companies are required to take some measures, whether intentional or not.

USB memory and email are often used as cases where trade secrets are intentionally leaked. However, there is also an investigation report that the internal fraud could not be punished or prosecuted due to lack of evidence or the inability to identify the individual who committed the fraud (Serra & Venter, 2011). That is where digital forensics comes in. The purpose of digital forensic is to identify digital evidence that can be used to identify the suspect and punish accordingly. Digital forensic entails three major steps that are all key to risk management program.  

As we know, risk management is a series of management processes that identify the risks that can cause loss in corporate management and take measures to avoid or minimize the effects in advance. Digital forensic can be handy in identifying the risks and in creation of strategies that can help the company avoid or minimize risks. For example, if the digital forensic determines that the lack of good password policy system is the main cause of internal fraud, then it is possible for the company to take appropriate measures earlier.

Internal fraud is when all three elements of 'motivation', ' opportunity', and 'justification' are in place.  “Therefore, as measures to prevent internal fraud, it is necessary to strengthen internal control, such as reducing the motive for running fraud and introducing a mechanism to make fraud difficult. In other words, there is a need for measures to pluck the buds of internal fraud by creating an environment that makes crime difficult, increases the risk of being caught, reduces the incentives for crime, and prevents criminal justification. On the other hand, the possibility of an incident cannot be completely ruled out. In that case, it has become necessary to take advance preparations so that digital forensics can be performed promptly. Thoroughly record computer operation logs to quickly detect access to suspicious data (Reddy & Venter, 2013). Alternatively, the criminal can be identified smoothly by taking measures such as thoroughly setting the administrator authority so that the necessary person can access only appropriate information. Preserving evidence through digital forensic techniques will allow for follow-up measures, including disciplinary action and prosecution.

References

Reddy, K., & Venter, H. S. (2013). The architecture of a digital forensic readiness management system. Computers & security32, 73-89.

Serra, S. M., & Venter, H. S. (2011, August). Mobile cyber-bullying: A proposal for a pre-emptive approach to risk mitigation by employing digital forensic readiness. In 2011 Information Security for South Africa (pp. 1-5). IEEE.

Bottom of Form