Risk-Oriented Design Approach For Forensic-Ready Software Systems
Lukas Daubner, Raimundas Matulevi\v{c}ius

TL;DR
This paper introduces a risk-oriented design approach for forensic-ready software systems, integrating forensic requirements into security risk management to enhance digital evidence collection and analysis.
Contribution
It proposes a novel method combining forensic requirement identification and BPMN modeling to improve forensic readiness in software systems.
Findings
The approach effectively identifies potential evidence sources.
It provides a high-level overview of forensic requirements.
Demonstrated on an automated parking scenario.
Abstract
Digital forensic investigation is a complex and time-consuming activity in response to a cybersecurity incident or cybercrime to answer questions related to it. These typically are what happened, when, where, how, and who is responsible. However, answering them is often very laborious and sometimes outright impossible due to a lack of useable data. The forensic-ready software systems are designed to produce valuable on-point data for use in the investigation with potentially high evidence value. Still, the particular ways to develop these systems are currently not explored. This paper proposes consideration of forensic readiness within security risk management to refine specific requirements on forensic-ready software systems. The idea is to re-evaluate the taken security risk decisions with the aim to provide trustable data when the security measures fail. Additionally, it also…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
