COIT20267 - Computer Forensics Methodologies - Analysis of Case Study - A Computer Forensic Investigation Plan Case Study - Computer Science Assessment Answer

Download Solution Order New Solution
Assignment Task

COIT20267: Computer Forensics

Objectives
This assessment item relates to the unit learning outcome 1 to 7 as stated on the unit profile.
1. Apply the computer forensics methodologies.
2. Write an analysis of a case study.
3. Prepare an outline of a professional computer forensic plan.

 

The Case – A Computer Forensic Investigation Plan
This assignment is based on the following case. Please read it carefully:
High-Tech Pty Ltd is a leading technology company in Australia store providing a wide range of computers and office equipment for businesses. The company established in 2005 and had grown rapidly, which now employs 250 employees and serves more than 5000 businesses around Australia. The company placed its main office in Melbourne with branch offices in Sydney, Brisbane, Adelaide, and Perth.
In order to gain competitive advantages over its competitors, High-Tech Pty Ltd has invested heavily in information technology for supporting its business operations. One of the Major investments were made by the company in 2010, however, the management team has lost focus on updating the networks and application infrastructure in recent years. As a result, the network environment between all of High-Tech Pty Ltd offices is flat and relatively unrestricted, where users from one office can access systems and servers from another office. Workstations and servers are typically Microsoft Windows-based. Firewalls and network segmentation were not properly secured throughout the environment. Intrusion detection and logging were installed on systems, but they were not frequently maintained and thus malfunction.
Since early 2019, High-Tech Pty Ltd has been receiving complaints from logistic departments of its clients. Their online purchases have been confirmed and payments have been processed successfully through an online portal, but these clients are yet to receive their equipment to date. As a result of this, a team leader has contacted the Information Security Office urgently to deal with this matter. An initial investigation was conducted and the investigator found that there were no records of online orders placed by these customers in High-Tech‘s main database. In addition, the investigator noted that someone from the Brisbane office has introduced a new computer program to the computer system.
As an information security officer, you are asked by the management to form a team of computer forensic investigators and find out the extent of computer crime. You are tasked to undertake digital forensic analysis of the network and computer systems. This involves conducting network analysis, gathering digital evidence from servers, PCs and e-mail accounts, conducting a cloud and social media investigations if necessary.

 

Instructions:

Incapacity of a computer forensics specialist, your task is to prepare a computer forensics investigation plan to enable a systematic collection of evidence and subsequent forensic analysis of the electronic and digital data. This plan should detail the following:
1- Justify why the use of the digital forensic methodology and approach is warranted including appropriate procedures for the Company’s investigation.
2- Describe the resources required to conduct a digital forensic investigation, including skill sets and the required software and hardware for the forensics team members.
3- Outline an approach for data/evidence identification and acquisition that should occur in order to be able to identify and review the digital evidence.
4- Outline an approach and steps to be taken during the analysis phase. In particular, explain what would be involved in the network, servers, PCs, e-mail, cloud and social media investigations.
5- Develop relevant security policies for the Company.
6- Provide recommendations to the Company for dealing with similar future problems.

 

Tips for preparing your computer forensics investigative plan
In writing the computer forensics investigative plan, students need to address the following points. Do note that points listed below are not exhaustive and need to be considered as helpful tips.
- Justify a need for computer forensics methodology and consider the scope of the case including the nature of alleged misconduct leading to consideration of how electronic and digital evidence may support the investigation. The plan should consider how computer forensics differs from other techniques (such as network forensics, data recovery) and detail the overall steps for the systematic computer forensics approach.
- Consider the required resources and include details regarding preparation plan for evidence gathering (such as evidence forms, types, storage media and containers), forensics workstation and peripherals needed, software/tools for analysis depending on the type of evidence to be gathered including rationale for selected tools, and consideration of team member skills in digital analysis (such as OS knowledge, skills for interviewing, consultation, working as per the needs of the auditing team and understanding of law and corporate policies).
- Detail the approach for data acquisition including the different types of evidence that can be gathered and their source depending upon the nature of the case and scope of investigation, develop a plan for data acquisition including rationale for selected plan and contingency planning, detail type of data acquisition tools needed including rationale and an outline for the data validation & verification procedures.
- Provide an outline of the forensic analysis procedures/steps depending upon the nature of evidence to be collected, and detail the validation approach. This can include techniques to counter data hiding, recovering deleted files, procedures for network and e-mail analysis.
- Develop suitable security policies for the Company.
- Provide appropriate recommendations to the Company for dealing with the problems.

 

This COIT20267 - Computer Science Assessment has been solved by our Computer Science experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our experts are well trained to follow all marking rubrics & referencing style.

Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.