| Forensics Services |
|
|
|
|
Defensible Forensics for Electronic Discovery Computer Forensic Services from Iris Data Services
Iris’ Forensic Services Minimize Expense by…
Benefits Speed. Iris forensic engineers are able to simultaneously image multiple computer systems, effectively doubling or tripling the speed of other service providers. Overall electronic discovery project velocity is further increased by Iris’ Forensic Culling process, which safely and effectively isolates essential data and funnels out the extraneous items. Cost. Iris understands the balance between eDiscovery and forensics and can design a cost-effective—yet still reasonable and defensible—approach for any matter. Also, by employing Forensic Culling, Iris can significantly reduce the base population of data that is ultimately subjected to processing, reviewing, hosting and production, reducing overall electronic discovery costs by up to 50% or more. Defensibility. Iris follows Department of Justice guidelines for the handling of all evidence. Each step of the discovery process is fully documented and all findings are supported by facts obtained during examinations. Iris’ professionals have a variety of certifications including CCE, CHFI and EnCE. Certified and reliable experts handle all planning and work. Documentation. For all evidence collected, the chain of custody is properly documented to assure integrity and provide an audit trail back to the original source. This includes numbering and tagging of evidence, photographing computer systems and relevant components, and thoroughly recording all descriptive details such as the make, model, serial number, employee name, and asset ID that are associated with each device from which evidence is collected. Security. Iris’ standard best practices for handling evidence include measures to ensure that it is not altered in any way during the collection process and can be safely preserved. Iris employs the latest advanced tools and software such as write blocking appliances which prevent change or damage to originals. Specialized forensic tools and processes such as hash comparisons are used to verify that an exact copy is acquired and preserved. Expert Testimony. Iris’ experts cannot only develop a defensible process based on best practices and the Federal Rules, they will also testify in hearings or in court as to the validity of that process. Iris can also provide expert services to audit and analyze the preservation efforts of opposing parties and provide documentation in support of briefings. Services
Iris’ Forensic Culling Can Save Up to 50% on Electronic Discovery Costs Forensic Culling reduces the amount of data that must be subsequently processed and searched from custodian hard drives after they’ve been collected and imaged in the field. Typical forensic reduction only involves the elimination of system files by using NIST or NSRL known system file lists as a guide, but Iris’ Forensic Culling goes beyond traditional de-NISTing to include and isolate other extraneous folders such as program files or IT user accounts. These can hold large volumes of data that are typically not useful or relevant for electronic discovery review. For example, the PC may contain a profile which is merely used for IT administrative purposes to store a backup of the installation set or standard package of applications, utilities and shortcuts to resources that are deployed for all users within their organization. Iris individually can confirm each such case and omit them from the data extractions where appropriate. Typically, less than 50% of the data remains to be forensically extracted, resulting in a greater than 50% reduction in downstream processing, hosting and review costs. Iris: One Company, One Solution |
