TY - BOOK AU - Brown,Christopher L.T. TI - Computer evidence: collection and preservation SN - 9781584506997 (pbk.) AV - HV8079.C65 B76 2010 U1 - 363.25968 22 PY - 2010/// CY - Boston, Mass. PB - Course Technology/Cengage Learning KW - Computer crimes KW - Investigation N1 - Previous ed.: Hingham, Mass.: Charles River Media, 2005; Includes CD-ROM N2 - This volume shows law enforcement, system administrators, information technology security professionals, legal professionals, and computer forensics students how to identify, collect, and maintain digital artifacts to preserve their reliability as evidence. It focuses on the first two phases of computer forensics--collection and preservation--and uses evidence dynamics as its main approach. This edition has been updated to take into account changes in federal rules of evidence and case law, as well as changes in the industry and technology. The CD-ROM contains sample batch files, forms, and demo and freeware software applications discussed in the book. Brown (network security and computer forensics, U. of California at San Diego) retired from the US Navy in the area of information warfare and network security operations ER -