- Scams, spams & shams
- Hijacked Web sites attack visitors
- Zappos gets savvy with social media
- Baited and duped on Facebook
- How hackers find weak spots
- BT's Web 2.0 security strategy
- Public cloud vs. internal social networks
- IT forensic experts find lucrative work
- Profile of IT forensics professional Rob Lee
- Opinion: Web 2.0 security depends on users
IT forensics experts find lucrative work
An inquisitive nature helps these security pros investigate data breaches
Computerworld - Last year, when UCLA Medical Center announced the firing of 13 workers and disciplined several others for snooping into the electronic medical records of pop star Britney Spears, it was IT forensics work that enabled the hospital to correctly identify the culprits.
And after part of a large cargo ship sank in international waters, it was IT forensics experts who recovered and analyzed the computer log files associated with the ship's loading processes. Information resulting from their investigation revealed that the log files had been altered after the ship sank and a month before the computers were turned over to authorities for inspection.
The role of IT forensics expert typically falls under the broader job category of IT security. These security pros are in high demand at private companies, law enforcement agencies and law firms, which hire them to gather evidence and serve as expert witnesses during court proceedings.
The primary job of an IT forensics expert, as described by the SANS Institute, is to analyze "how intruders breach an IT infrastructure in order to identify additional systems and networks that have been compromised." Investigating attacks requires proficiency in forensics and reverse-engineering, as well as exploit methodologies, SANS notes.
Several certifications in IT forensics are available through both vendor-neutral organizations like SANS, which offers the GIAC Certified Forensics Analyst certification, and security software vendors, including Guidance Software's EnCase Certified Examiner certification.
Salary expectations
Pay for IT forensics experts varies depending on where in the country they work and what their exact titles are. Specific job titles of professionals who perform IT forensics work include security analyst and security administrator. The national average annual salaries for those titles are $84,700 and $85,300, respectively, according to data collected in 64 U.S. cities through July 2009 by Foote Partners LLC.
Training requirements
At least for now, there is no definitive route for becoming an IT forensics expert. For example, Steve Hunt, a security industry analyst at the Computer Technology Industry Association (CompTIA), believes liberal arts students who majored in math or philosophy make the best IT forensics experts. "These are people who will take different ideas and reassemble them in different ways," Hunt says.
"There's a natural talent for it," says Alan Paller, research director at the SANS Institute. "The ones who are best have an inquisitive, take-it-apart personality. They'll spend hours and hours and hours digging into things."
Not surprisingly, that can be the downside of the work. "It can be lonely," says Gregory Evans, CEO of Atlanta-based Ligatt Security International LLC. But it can also be incredibly rewarding, adds Evans, whose IT security firm recently helped track down a child molester by tracing his e-mails.
Next: Profile of an IT forensics professional
Related Links
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts