In brief

Instead of a talk — a panel on four topics: BYOD versus COPE, whether to notify an employee that an investigation has begun, whether to keep a departing employee's device, and proactive forensics versus reactive. Calling it a debate is a stretch: on the first topic everyone agreed that BYOD has no advantages, on the last — that "proactive forensics" is an oxymoron to begin with. What the panel does have is practice: a company with a turnover of more than a billion, with no domain and personal laptops, where the key figure "forgot the password" and ran into BitLocker; a notice of an audit given three days in advance and met with bags of shredded paper; several hundred Macs left without control after the sanctions. The most honest conclusion — from a forensic examiner: the data turns out to be where it was expected, "twice in my practice".

Key points

Tools, artifacts, technologies

The most legal panel of the conference. Notifying an employee is treated as an obligation — "not notifying isn't entirely legal" — but with the caveat that the company chooses the lead time. The basis for monitoring is derived from the trade secrets law: documents signed on hiring that state that the work computer may be monitored, and a recommendation to have them re-signed if the policies were rolled out after the fact. A corporate investigation is tied to the electronic document disclosure procedure so that the evidence meets the requirements of completeness, integrity and reproducibility under Federal Law 73 — otherwise "it won't be accepted as evidence". Time frames were named too: images are kept for at least six months, with a reference to the practice of the law enforcement agencies, and the eight-year horizon is explained by the ten-year statute for especially serious economic crimes. Separately — the pragmatics: to fire an employee a forensic investigation is not always needed, "it's probably easier to run it through some HR mechanisms".

Questions from the audience

The participants' positions

The forensic examiners speak from the position of "what will I get for examination", and both put COPE above BYOD for purely practical reasons; at the same time both admit that configured policies and readiness are rare. The man from the business side is the bluntest of all: BYOD has no advantages, what decides it is the economics of a uniform fleet, and everything comes down to the internal regulations signed by the employee. The general tone — not a vendor one: their own product is not being sold, but they readily tell of failures — the key computer that was not collected, the bags of shredded paper, the hundreds of uncontrolled Macs. The downside of the format: there is almost none of the advertised debate, the participants quickly agree with each other, and the contentious pieces of advice (notify in order to trigger panic; the intimidation mailing) go unchallenged.

Quotes