SECURITY 508SECURITY 508


GIAC Certification Available
CCE Bootcamp Logo

Course PDF

Legal issues, especially liability, remain foremost in the minds of an incident handler or forensic investigator; therefore, this class has more discussion than any other we offer. Learn to investigate incidents while minimizing the risk for legal trouble. This course is designed not for management, but for the individuals actually performing a computer-based investigation. The content focuses on challenges that every investigator needs to understand before, during, and post investigation. Since most investigations could potentially bring a case to either a criminal or civil courtroom, it is essential for you to understand how to perform a computer-based investigation legally and ethically.

The information presented confronts head-on many of the legal mythologies that have caused you to hesitate when developing your incident handling procedures and pursuing incidents. You will also gain a realistic perspective on the strengths and limitations of law enforcement assistance in the investigation of incidents and the prosecution of attackers. The information presented in this course will provide an essential legal foundation for professionals managing or working in incident handling teams.

You will receive a course book that covers United States and European Union legal challenges surrounding computer-based investigations. The instruction will focus on the legal challenges surrounding the location where the course is taught. The other section will be used as a reference so that you will be able to compare and contrast legal issues from E.U. law to U.S. law.




  • Who Can Investigate and Investigative Process Laws
    • Internal And External Investigations
    • Involving Law Enforcement In An Investigation
    • Ramification Of An Incident That Involves Multiple Countries
    • Following Agency/Employer Policy And Procedures
    • Digital Forensic Ethical Standards
    • Lines Of Communication Between The Requestor, Examiner, And Analyst
  • Evidence Acquisition/Analysis/Preservation Laws and Guidelines
    • Major Goals Associated With Acquiring Data
    • Legal Authority To Allow For Data Acquisition
    • Stored And Real Time Data
    • Evidence/Information You Can Share With Third Parties And Law Enforcement
    • Legal Authority Necessary To Collect Data
    • Tool Validation And Process
  • U.S. Laws Investigators Should Know
    • Criminal And Civil Law Procedures – Understanding Of The Laws And Procedures Related To Evidence, Search Authority And Scope.
    • U.S. Computer Fraud And Abuse Act
    • Civil Privacy Laws
    • SOX, HIPAA, GLB, FERPA, ECPA
    • Wiretap Act and Pen Register Trap and Trace Laws
    • U.S. Electronic Communication Privacy Act
  • E.U. Laws Investigators Should Know
    • Criminal And Civil Law Procedures –Understanding The Laws And Procedures Related To Evidence, Search Authority, And Scope
    • Legal Entities Involved In International And E.U. Crime Investigations
    • E.U. Data Protection Directive
    • E.U. Data Retention Law
    • E.U. Information System Attacks Decision
  • Presenting Data
    • Evidence admissibility (Authenticity and Relevancy)
    • Basic Rules Of Evidence
    • Proving The Integrity Of The Data
    • “Best Evidence”
    • Lay And Expert Witnesses
    • Daubert And Frye Tests In Court
  • Forensic Reports and Testimony
    • Report Writing
    • Legal Testimony
    • Address Scientific Process, Audience, And Legal Utility
    • How To Document Work So It Is Repeatable
    • Scientific Methods That Show Clear Conclusions Based In Factual Evidence
SECURITY 508 Upcoming Events
Event Location Dates Delivery Method
SANS SelfStudyBooks & MP3s OnlyAnytimeSelf Paced
SANS OnDemandOnlineAnytimeSelf Paced
SANS London 2009London, United KingdomNov 28, 2009 - Dec 06, 2009Live Event
Community SANS Tucson 2009Tucson, AZNov 30, 2009 - Dec 05, 2009Community SANS
Community SANS Colorado Springs 2009Colorado Springs, CONov 30, 2009 - Dec 05, 2009Community SANS
Mentor Session - SEC508Atlanta, GADec 02, 2009 - Feb 17, 2010Mentor
Mentor Session - SEC508Medellín, ColombiaDec 02, 2009 - Dec 04, 2009Mentor
SANS CDI East 2009Washington DCDec 11, 2009 - Dec 18, 2009Live Event
Mentor Session - Security 508Charlotte, NCJan 14, 2010 - Mar 18, 2010Mentor
Mentor Session - Security 508Denver, COJan 19, 2010 - Mar 23, 2010Mentor
Community SANS Lake Tahoe 2010Lake Tahoe, CAJan 25, 2010 - Jan 30, 2010Community SANS
SANS Phoenix 2010Phoenix, AZFeb 14, 2010 - Feb 20, 2010Live Event
SANS India 2010Bangalore, IndiaFeb 22, 2010 - Feb 27, 2010Live Event
SANS 2010Orlando, FLMar 06, 2010 - Mar 15, 2010Live Event
Mentor Session - SEC508Greeley, COMar 11, 2010 - May 13, 2010Mentor
Community SANS Boston 2010Boston, MAMar 15, 2010 - Mar 20, 2010Community SANS
SANS vLive! - SEC 508 - Rob LeeSANS vLive! SEC508 - 201003, VAMar 23, 2010 - Apr 29, 2010
SANS Northern Virginia Bootcamp 2010Reston, VAApr 06, 2010 - Apr 13, 2010Live Event
Mentor Session - SEC508Boise, IDSep 28, 2010 - Nov 30, 2010Mentor
"This is awsome! We're seeing details that most people don't even know exist" - John Wright, Info Tech, Inc.
"The class provided in-depth, real world, hands-on information" - Robert Dale Drollinger, General Dynamics
SANS Institute