Reference and guide to SFIA version 7. Framework status: Beta. Show revision-marked text

Digital forensics DGFS

(modified)

The collection, processing, preserving, analysis, and presentation of forensic evidence based on the totality of findings including computer-related evidence in support of security vulnerability mitigation and/or criminal, fraud, counterintelligence, or law enforcement investigations.

Digital forensics: Level 6

(modified)

Sets policies and standards and guidelines for how the organisation conducts digital forensic investigations. Leads and manages complex investigations engaging additional specialists if required. Authorises the release of formal forensics reports.

Digital forensics: Level 5

(modified)

Conducts investigations to correctly gather, analyse and present the totality of findings including digital evidence to both business and legal audiences. Collates conclusions and recommendations and presents forensics findings to stakeholders. Contributes to the development of policies, standards and guidelines.

Digital forensics: Level 4

(modified)

Contributes to digital forensic investigations. Processes and analyses evidence in line with policy, standards and guidelines and supports production of forensics findings and reports.