Publication details

Forensic experts' view of forensic-ready software systems: A qualitative study

Investor logo
Authors

DAUBNER Lukáš BÜHNOVÁ Barbora PITNER Tomáš

Year of publication 2024
Type Article in Periodical
Magazine / Source Journal of Software: Evolution and Process
MU Faculty or unit

Faculty of Informatics

Citation
Web https://onlinelibrary.wiley.com/doi/full/10.1002/smr.2598
Doi http://dx.doi.org/10.1002/smr.2598
Keywords digital forensics; forensic by design; forensic readiness; forensic-ready software; interview; software engineering
Attached files
Description Software engineers widely acknowledge the inclusion of security requirements in the early stages of the development process. However, the need to prepare the software for the failure of the implemented security controls and subsequent investigation of the incident is often not discussed. Forensic-ready software systems represent an evolution of secure systems being designed for the eventual digital forensic investigation. However, their exact properties remain largely unexplored, beyond preliminary high-level conceptualizations of requirements and capabilities. Further obstacles hindering the adoption of forensic-ready software systems are the different priorities and goals of involved parties and a gap in the digital forensics expertise of software engineers. In this paper, we conduct an empirical qualitative study identifying the problems and needs of forensic readiness while framing the notion of an ideal forensic-ready software system and how it should treat potential evidence. To this end, we conducted semisupervised interviews with digital forensics experts on their idea, experience, and suggestions. The results provide insights into the needs of the experts to facilitate the definition of correct requirements towards forensic-ready software systems to support the anticipated investigations properly.
Related projects:

You are running an old browser version. We recommend updating your browser to its latest version.

More info