Computer Forensics
Computer forensics is the process of collecting, preserving, analyzing, and presenting digital evidence for investigations involving security incidents or legal matters.
“The practice of determining how a security attack has succeeded and assessing the damage caused.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Computer Forensics?
Computer forensics follows controlled procedures to ensure digital evidence remains reliable and legally admissible while identifying the cause of incidents.
Evidence preservation: Digital evidence must remain unchanged during investigation.
Incident analysis: Investigators reconstruct events from logs, files, and system artifacts.
Security support: Findings help improve future security measures.
Real World Example
A regulated product team is preparing a release where Computer forensics appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats Computer forensics as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Computer forensics and similar ideas.
The page becomes useful in practice because Computer forensics is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
Which action MOST preserves evidence integrity?
Question 2
Which record MOST supports chain‑of‑custody?
Test your knowledge with real ISTQB-style questions
You’ve learned Computer Forensics. Test your understanding with topic-specific questions in our Mock Exams.