1. Home
  2. Computing & Technology
  3. Internet / Network Security

Book Review: Incident Response & Computer Forensics - 2nd Edition

About.com Rating 4.5

From Tony Bradley, CISSP, MCSE2k, MCSA, A+, About.com Guest

Incident Response & Computer Forensics
The Bottom Line
Incident response and computer forensics is a passion of mine right now (if you can be "passionate" about such a thing). Maybe I have watched too many episodes of CSI, but I find the whole concept very intriguing. This book is arguably the best I have read on the subject. Incident Response is in larger print on the cover, but much of the book, and in my opinion the best and most important parts of the book, comes from the Computer Forensics side. I highly recommend this excellent book.
Compare Prices
Pros
  • One of the best books on computer forensics and evidence collection
  • Tons of new and updated information since the first edition
  • "Eye Witness Reports" help give real-world perspective
Cons
  • None
Description
  • If collected wrong, computer evidence is useless in court- this book will help you do it right
  • Comprehensive coverage of handling an incident from first response through investigation
  • Real world scenarios help the reader to understand how these concepts work in real life
  • Much of the book is new or significantly rewritten since the first edition
Guide Review - Book Review: Incident Response & Computer Forensics - 2nd Edition
The whole idea of forensics- computer or otherwise- is in reality not as glamorous as shows like CSI would have you believe. It is fun to watch them piece together small, seemingly unrelated tidbits of evidence to form a complete case- but the fact that they do it in a 1-hour show doesn't do it justice.

Collecting forensic evidence is often a slow and tedious process. If it is done wrong the evidence will be corrupt and may be inadmissable in court based on a technicality.

Being responsible for incident response means you usually get called for one of two jobs- either an attack is ongoing and you need to take the necessary steps to stop or block the incident from continuing while also preserving evidence, or you may be asked to do a forensic investigation of a computer of an ex-employee or something. In either event you would do well to have this book nearby.

Incident Response & Computer Forensics - 2nd Edition is one of the best books on the market for these subjects. Kevin Mandia and Chris Prosise bring extensive real-world experience to the table and share tons of valuable and useful information with their readers.

The book covers everything from establishing policies and procedures to collecting data from live Windows or Unix machines. The chapters on Forensic Duplication and Evidence Handling are excellent.

It may not be glamorous, but for some it is still a thrill to be able to extract evidence and solve the puzzle. If you are one of those people- get this book.

Compare Prices
Explore Internet / Network Security
About.com Special Features

Holiday Central

What to eat, where to go, fun things to do and how to save money on the perfect gifts. More >

Family Tech Center

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

  1. Home
  2. Computing & Technology
  3. Internet / Network Security
  4. Product and Book Reviews
  5. Read Book Reviews
  6. Sorted by Title
  7. I
  8. Book Review: Incident Response & Computer Forensics - 2nd Edition

©2009 About.com, a part of The New York Times Company.

All rights reserved.