|
Standard |
Posted: 08/15/07
|
R State Standard £
Institutionally Developed
College: n/a |
CIS 1120 – Computer Forensics
Course
Description
This course serves as a capstone course for the information security
specialist. The course will include implementing a plan to detect intruders,
determine the damage caused, and discuss what precautions to use to avoid
disasters.
|
Competency Areas |
Hours |
|
|
Discuss
current computer forensic tools |
Class |
4 |
|
Discuss
and demonstrate the steps in evidence collection |
D. Lab |
4 |
|
Discuss
and demonstrate the steps in evidence analysis |
P.
Lab/O.B.I. |
0 |
|
Discuss
and demonstrate the steps in crime/incident scene processing |
Credit |
6 |
|
Interpret
clues from mail messages, news postings, graphic images and file signatures |
|
|
|
Define
and discuss the components of disaster recovery |
|
|
|
Discuss
ways to recover from various disasters |
|
|
|
Prerequisite: |
CIS1116; CIS1117; CIS1118 and CIS1119 |
|
Corequisite: |
CIS1119 Computer Forensics and Disaster Recovery |
|
Course Guide |
|
Competency |
After
completing this section, the student will be able to: |
Hours |
||
|
Class |
D. Lab
|
P. Lab/ O.B.I. |
||
|
Discuss current computer forensic
tools |
8 |
0 |
0 |
|
|
|
Define
computer forensics |
|
|
|
|
|
Discuss
the computer investigation process |
|
|
|
|
|
List
current forensic tools and their purpose |
|
|
|
|
|
|
|
|
|
|
Discuss and demonstrate the steps
in evidence collection |
8 |
10 |
0 |
|
|
|
Discuss
legal methods of evidence collection |
|
|
|
|
|
List
methods of evidence collection |
|
|
|
|
|
Demonstrate
tools used in evidence collection |
|
|
|
|
|
|
|
|
|
|
Discuss and demonstrate the steps
in evidence analysis |
8 |
10 |
0 |
|
|
|
Discuss
legal methods of evidence analysis |
|
|
|
|
|
List
methods of evidence analysis |
|
|
|
|
|
Demonstrate
tools used in evidence analysis |
|
|
|
|
|
|
|
|
|
|
Discuss and demonstrate the steps
in crime/incident scene processing
|
8 |
10 |
0 |
|
|
|
List
considerations in crime/incident scene processing |
|
|
|
|
|
Demonstrate
proper crime/incident scene processing |
|
|
|
|
|
|
|
|
|
|
Interpret clues from mail
messages, news postings, graphic images and file signatures |
8 |
10 |
0 |
|
|
|
Retrieve
and interpret evidence from mail messages |
|
|
|
|
Retrieve
and interpret evidence from news postings |
|
|
|
|
|
|
Retrieve and
interpret evidence from file signatures |
|
|
|
|
Retrieve
graphic images |
|
|
|
|
|
Suggested Resources |
Books:
Guide to Computer Forensics and
Investigations, Second Edition, ISBN: 0-619-21706-5, Phillips, Nelson, Enfinger,
Course Technology