Digital Forensics and Incident Response (DFIR)
DFIRالتعريف
The combined practice of collecting, preserving, analyzing, and presenting digital evidence from cybersecurity incidents while simultaneously containing and remediating the threat. It ensures evidence integrity for potential legal proceedings while enabling rapid recovery and lessons learned documentation.
التعريف بالعربية
الممارسة المشتركة لجمع وحفظ وتحليل وتقديم الأدلة الرقمية من الحوادث السيبرانية مع احتواء التهديد ومعالجته في الوقت نفسه. يضمن سلامة الأدلة للإجراءات القانونية المحتملة مع تمكين التعافي السريع وتوثيق الدروس المستفادة.
مثال عملي
Following a ransomware attack on a Saudi healthcare provider, the DFIR team preserves forensic evidence per PDPL Article 21 requirements for data breach notification, analyzes attack vectors to meet SAMA CSF incident analysis obligations, and coordinates with NCA-CERT while documenting findings to support Vision 2030 cybersecurity maturity goals.