The Computer Forensic Series by EC-Council provides the knowledge and skills to identify, track, and prosecute the cyber-criminal. The series is comprised of five books covering a broad base of topics in Computer Hacking Forensic Investigation, designed to expose the reader to the process of detecting attacks and collecting evidence in a forensically sound manner with the intent to report crime and prevent future attacks. Learners are introduced to advanced techniques in computer investigation and analysis with interest in generating potential legal evidence. In full, this and the other four books provide preparation to identify evidence in computer related crime and abuse cases as well as track the intrusive hacker's path through a client system. The series and accompanying labs help prepare the security student or professional to profile an intruder's footprint and gather all necessary information and evidence to support prosecution in a court of law. The first book in the Computer Forensics series is Investigation Procedures and Response. Coverage includes a basic understanding of the importance of computer forensics, how to set up a secure lab, the process for forensic investigation including first responder responsibilities, how to handle various incidents and information on the various reports used by computer forensic investigators.
This book is an excellent introduction to incident response as it pertains to computer forensics, but I would also recommend this book for those who are looking to design a company security, or incident response policy for their technical and non-technical staff.
The general structure of this book is self-reinforcing, in that, the author first goes through the principles, then principles in relation to incident management and forensic procedures, then principles in relation to organizational roles of responders, and forensic and non-forensic staff. This makes the book a relatively quick read, but I will definitely recommend reading this book at least twice.
I took a chance and bought a "very good" condition copy and got lucky because the previous owner didn't use the online access card for this book. Make sure that the copy you order has the online Cengage learning access card. This will give you access to exercises which are truly helpful in understanding the material in this book.