Computer Forensics: A Newly Certifiable Field

February 4, 2002, 12:00 AM —  ITworld — 

I've always secretly wanted to wear a trench coat and conduct secret
investigations. I'd have an office on Market Street above the cable car
route, a secretary named Madge, and a bottle of cheap whiskey in my
desk drawer next to my trusty revolver. Okay, so maybe I have watched
too many old movies with William Powell and Myrna Loy, but it's still a
romantic idea.

For those of you who may have similar fantasies, I have a practical
alternative and a brand new field. Computer forensics experts collect,
preserve, and analyze computer evidence that may be critical to
criminal investigations, civil litigation, and corporate internal
investigations. A forensics expert may, for example, use specialized
techniques to retrieve information off of a hard drive that has already
been erased. The expert may find that "smoking gun" the prosecutor is
after, and may even be called to testify in court. A rapidly growing
field that is just a few years old, computer forensics experts come
from both an IT background and a law enforcement background.

A company called Guidance Software, Inc.
(http://www.guidancesoftware.com) has a large share of the marketplace
for the hardware and software needed to conduct computer forensics.
Guidance Software Vice President Bob Sheldon tells me that certified
computer forensics practitioners can make anywhere from about $60,000
to $120,000 a year. But, like most subfields of information technology,
you have to be certified.

Get Trained, Get the Cert
Besides providing the tools, Guidance Software also provides the
training and certification to people who use them. Guidance Software
offers three courses in computer forensics -- introductory,
intermediate, and advanced -- that are available at their three
locations in Pasadena, California; Leesburg, Virginia; and Liverpool,
England. Guidance Software also conducts in-house training sessions for
law enforcement agencies in various locations around the country. Each
course is four days.

After taking the intermediate course and working in the field for six
months, you can qualify for the EnCase Certified Examiner (EnCE)
certification. If you do not take the Guidance Software course, you can
also qualify for the certification by showing that you have had 32
hours of classroom computer forensics training, and a year of practical
experience.

Besides working towards the EnCE certification, Guidance Software's
training courses can also be applied to certifications sponsored by the
High Tech Crime Network, the State Bar of California, and the National
Association of State Boards of Accountancy.

Prospects
So once you've been certified, who do you work for? "It used to be
limited to police departments," said Sheldon, "because they were the
ones that were doing computer forensics in support of criminal
investigations. Now there are a number of private sector consultants
that do computer forensics and each of the Big Five accounting firms
have dedicated computer forensics units."

» posted by ITworld staff

ITworld

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
peer-to-peer

Esther Schindler
If the comments are ugly, the code is ugly

claird
SVG a graphics format for 21st century

pasmith
Take Chrome OS for a test spin

Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?

sjvn
64-bits of protection?

jfruh
Android fragments vs. the iPhone monolith

mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive

 

Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace