The temptation for IT departments to become digital detectives and deal with a breach of security in house is understandable, says Tobias, as companies worry about investor confidence, company reputation and business in general.
CY4OR’s guide to crime scene investigations Treat the matter seriously.
– Tell your legal team not your colleagues about your suspicions.
– Do not inform your IT department. Instead, hire computer forensic experts.
Professional analysts from reputable companies adhere to ACPO (Association of Chief Police Officer) guidelines, can identify digital evidence quickly and ensure that it will stand up in court by following the correct procedures. They can even image your computers at night, to avoid inevitable discussions by the water cooler.
The principle of forensics which says that “every contact leaves a trace” cannot be emphasised enough, says Tobias.
http://www.theregister.co.uk/2005/11/18/csi_forensics_gaffe/