IP Library Patent Application 10952537
Patent Application
App. No. 10/952,537

Methodology for assessing the maturity and capability of an organization's computer forensics processes

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/952,537
Abstract

A method for assessing capability and maturity of an organization's computer forensics processes defines an architecture for a computer forensics capability and maturity model (CMM), a computer forensics CMM appraisal method, implements the computer forensics CMM for improving computer forensics processes within the organization, and conducts an appraisal of the organization according to the CMM appraisal method.

Claims (63)

1 . A method of defining an architecture for a computer forensics capability and maturity model, whereby said architecture is to be used for assessing capability and maturity of an organization's computer forensics processes, said model comprising:

a. establishing a plurality of process areas relating to the domain of computer forensics;

b. establishing a plurality of computer forensics base practices, each corresponding to a fundamental characteristic that is practiced in the computer forensics domain;

c. correlating the base practices to the process areas, whereby related ones of said best practices are respectively grouped as a sub-set within each process area according to a common purpose.

2 . A method according to claim 1 whereby a first group of said process areas relates to technical and operational base practices within the computer forensics domain, and a second group of said process areas relates to administrative and organizational base practices with the computer forensics domain.

3 . A method according to claim 2 whereby said first group of process areas corresponds to one or more of:

(a) identifying electronic devices as potential sources of evidence;

(b) providing access to investigative tools and equipment;

(c) securing and evaluating a crime scene;

(d) documenting a crime scene;

(e) collecting evidence;

(f) packaging, transporting and storing evidence;

(g) conducting forensic examination of evidence;

(h) providing access to a computer forensics laboratory;

(i) generating investigation reports; and

(j) present evidence in a legal proceeding.

4 . A method according to claim 2 wherein said second group of process areas corresponds to one or more of:

(a) ensuring quality; and

(b) providing ongoing skills and knowledge.

5 . A method according to claim 1 comprising establishing a plurality of generic practices, each being common to all of said process areas.

6 . A method according to claim 5 whereby said process areas are categorized under a domain dimension of said computer forensics capability and maturity model and whereby said generic practices are categorized under a capability dimension of said computer forensics capability and maturity model.

7 . A method according to claim 5 comprising grouping the plurality of generic practices according to common features for evaluating capability and maturity of computer forensics processes, thereby to define a plurality of common features each having an associated sub-set of generic practices.

8 . A method according to claim 7 comprising grouping said plurality of common features according to computer forensics processes capability levels, thereby to define a plurality of capability levels each having an associated sub-set of common features.

9 . A method according to claim 8 wherein said capability levels correspond to one or more of:

(a) a first capability level indicative of an informally performed process;

(b) a second capability level indicative of a planned and tracked process;

(c) a third capability level indicative of a well-defined process;

(d) a fourth capability level indicative of a quantitatively controlled process; and

(e) a fifth capability level indicative of a continuously improving process.

10 . A method for assessing capability and maturity of an organization's computer forensics processes, comprising:

a. defining an architecture for a computer forensics capability and maturity model (CMM);

b. defining a computer forensics CMM appraisal method;

c. implementing the computer forensics CMM for improving computer forensics processes within an organization;

d. conducting an appraisal of the organization, according to said computer forensics CMM appraisal method, thereby to derive a respective resultant capability level for each of the computer forensics processes within the organization, and to obtain an assessment of the capability and maturity of an organization's computer forensics processes.

11 . A method according to claim 10 whereby step (a) comprises:

a. establishing a plurality of process areas relating to the domain of computer forensics;

b. establishing a plurality of computer forensics base practices, each corresponding to a fundamental characteristic that is practiced in the computer forensics domain;

c. correlating the base practices to the process areas, whereby related ones of said best practices are respectively grouped as a sub-set within each process area according to a common purpose.

12 . A method according to claim 11 whereby a first group of said process areas relates to technical and operational base practices with the computer forensics domain, and a second group of said process areas relates to administrative and organizational base practices with the computer forensics domain.

13 . A method according to claim 12 whereby said first group of process areas corresponds to one or more of:

(a) identifying electronic devices as potential sources of evidence;

(b) providing access to investigative tools and equipment;

(c) securing and evaluating a crime scene;

(d) documenting a crime scene;

(e) collecting evidence;

(f) packaging, transporting and storing evidence;

(g) conducting forensic examination of evidence;

(h) providing access to a computer forensics laboratory;

(i) generating investigation reports; and

(j) present evidence in a legal proceeding.

14 . A method according to claim 12 wherein said second group of process areas corresponds to one or more of:

(a) ensuring quality; and

(b) providing ongoing skills and knowledge.

15 . A method according to claim 11 comprising establishing a plurality of generic practices, each being common to all of said process areas.

16 . A method according to claim 15 whereby said process areas are categorized under a domain dimension of said computer forensics capability and maturity model and whereby said generic practices are categorized under a capability dimension of said computer forensics capability and maturity model.

17 . A method according to claim 15 comprising grouping the plurality of generic practices according to common features for evaluating capability and maturity of computer forensics processes, thereby to define a plurality of common feature each having an associated sub-set of generic practices.

18 . A method according to claim 17 comprising grouping said plurality of common features according to computer forensics processes capability levels, thereby to define a plurality of capability levels each having an associated sub-set of common features.

19 . A method according to claim 18 wherein said capability levels correspond to one or more of:

(a) a first capability level indicative of an informally performed process;

(b) a second capability level indicative of a planned and tracked process;

(c) a third capability level indicative of a well-defined process;

(d) a fourth capability level indicative of a quantitatively controlled process; and

(e) a fifth capability level indicative of a continuously improving process.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jan 17, 2020
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: VAREC, INC.; REVEAL IMAGING TECHNOLOGY, INC.; QTC MANAGEMENT, INC.; SYSTEMS MADE SIMPLE, INC.; SYTEX, INC.; OAO CORPORATION; LEIDOS INNOVATIONS TECHNOLOGY, INC. (F/K/A ABACUS INNOVATIONS TECHNOLOGY, INC.)
Reel/Frame 051855/0222 →
RELEASE OF SECURITY INTEREST Recorded Jan 17, 2020
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: VAREC, INC.; REVEAL IMAGING TECHNOLOGY, INC.; QTC MANAGEMENT, INC.; SYSTEMS MADE SIMPLE, INC.; SYTEX, INC.; OAO CORPORATION; LEIDOS INNOVATIONS TECHNOLOGY, INC. (F/K/A ABACUS INNOVATIONS TECHNOLOGY, INC.)
Reel/Frame 052316/0390 →
SECURITY INTEREST Recorded Aug 25, 2016
From: VAREC, INC.; REVEAL IMAGING TECHNOLOGIES, INC.; ABACUS INNOVATIONS TECHNOLOGY, INC.; OAO CORPORATION; QTC MANAGEMENT, INC.; SYSTEMS MADE SIMPLE, INC.; LOCKHEED MARTIN INDUSTRIAL DEFENDER, INC.; SYTEX, INC.
To: CITIBANK, N.A.
Reel/Frame 039809/0603 →
SECURITY INTEREST Recorded Aug 25, 2016
From: VAREC, INC.; REVEAL IMAGING TECHNOLOGIES, INC.; ABACUS INNOVATIONS TECHNOLOGY, INC.; OAO CORPORATION; QTC MANAGEMENT, INC.; SYSTEMS MADE SIMPLE, INC.; LOCKHEED MARTIN INDUSTRIAL DEFENDER, INC.; SYTEX, INC.
To: CITIBANK, N.A.
Reel/Frame 039809/0634 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2005
From: KRUTZ, RONALD L.
To: SYTEX, INC.
Reel/Frame 016179/0776 →