# What is Digital Forensics and Incident Response (DFIR)?

> Digital forensics and incident response is an operating discipline that integrates incident response with the collection and analysis of digital evidence.

- Canonical URL: https://yellowcube.eu/glossary/digital-forensics-and-incident-response/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Incident response focuses on preparing for incidents, detecting and assessing them, limiting harm, removing causes, restoring operations and learning from what happened. Digital forensics focuses on identifying, preserving, acquiring, examining, analyzing and reporting evidence in a supportable way.

The disciplines work together: forensic findings can establish scope, sequence and root cause, while response priorities determine which questions and systems matter most. They do not collapse into one activity. An urgent response may need to isolate a host before a complete acquisition is possible, while a legal, regulatory or disciplinary matter may require stricter preservation, provenance and documentation than routine operations.

### Key points

- **Evidence readiness:** Maintain trustworthy time, suitable logging and retention, acquisition capability, trained personnel, documented authority and secure evidence storage before an incident occurs.
- **Typical questions:** What happened, when, how, which identities and assets were affected, what evidence supports the conclusion, and what risk remains?
- **Decision discipline:** Record who collected or handled evidence, methods and tool versions, integrity checks, analysis assumptions, response actions and material gaps.
- **Important limitation:** Not every incident requires full forensic imaging, and preservation is not always the only priority. Teams must balance evidentiary value with safety, privacy, legal duties, service availability and the need to stop ongoing harm.

### Related terms

[Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Chain of custody](<https://yellowcube.eu/glossary/chain-of-custody/>) · [Root cause analysis](<https://yellowcube.eu/glossary/root-cause-analysis/>) · [Malware analysis](<https://yellowcube.eu/glossary/malware-analysis/>) · [Security incident](<https://yellowcube.eu/glossary/security-incident/>)

### Sources

[NIST SP 800-86](https://csrc.nist.gov/pubs/sp/800/86/final) · [NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [NIST IR 8428: DFIR Framework for Operational Technology](https://www.nist.gov/publications/digital-forensics-and-incident-response-dfir-framework-operational-technology-ot) · [NIST digital evidence resources](https://www.nist.gov/itl/ssd/software-quality-group/computer-forensics-tool-testing-program-cftt/digital-evidence)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

