7 Pgs Powerpoint Presentation - Due 10 November

profileShiaRo
TeamAssignment-FA.doc

RUNNING HEADER: Team Proposal for XYZ’s Digital Forensics Lab

Business Proposal for

XYZ Digital Forensics Lab

CSEC 650 – Fall 2017

Professor Babak Shoraka

Team Members: Caleb Mcmillin, Christopher Ortoleva, Hugo Lozano, Joesph Queen, Shira Roberts-Rodney

Abstract

Following is a proposal for XYZ’s Computer Forensics Laboratory. This proposal provides an analysis and recommendation for designing a fully functional Computer Forensics Laboratory. This project will provide a comprehensive analysis the technical, physical, environmental, personnel and budgetary requirements needed to construct this laboratory enabling development be seamless and functionality flawless with the equipment required for successful investigative outcomes.

TABLE OF CONTENTS

INTRODUCTION 1

LEGAL CONSIDERATIONS FOR XYZ 2

ISO-17025 Accreditation 3

ISO-27000: Information Security management 5

Digital Evidence Management 6

Legal Counsel for XYZ INC. 7

FORENSICS HARDWARE 7

FORENSICS SOFTWARE 9

Hardware and Software Costs 11

Initial Acquisition Costs 11

Operating Costs per Year 12

PHYSICAL AND ENVIRONMENTAL 12

Building Location 13

Building size 15

Building Physical Layout 16

Analyst Work Space 17

Analyst Furniture 17

Power Requirements 18

Environmental 18

Physical Security 18

FORENSIC PERSONNEL FOR XYZ, INC. 19

CONCLUSION 24

APPENDIX A: COST TABLE 25

REFERENCES 28

INTRODUCTION

This team proposal for XYZ Computer Forensic Laboratory provides a complete analysis on the construction of a functioning laboratory which meets provided requirements. This proposal will provide XYZ Inc. a broad view into the technical, physical, environmental, personnel and budgetary necessities which would allow XYZ to perform at optimal proficiency.

Technical requirements for XYZ’s facility will include hardware and software which will set the company apart of all existing laboratories. Software included in the proposal will provide an overview of software packages including licensing that will be superior within the industry. This includes operating systems and data tools used to recovery items being investigated. Using software best in the industry will allow existing staff and future possible employees to become a step ahead of their counterparts. Technical requirements will meet the mainstay infrastructure requirement needed to collect, stock, protect, and transfer evidence required State by law.

The Physical features of this proposal will outline construction, security procedures that will to safeguard the integrity and security of the evidence collected. Securing the building is the single most important factor when maintaining and investigating evidence. Evidence should be stored in an environment where there is minimal chance of compromise or tampering. This puts XYZ a step ahead, demonstrating the ability to be relied upon to ensure the evidence being presented in cash hasn’t be compromised or manipulated.

Personnel and budgetary factors will speak too the staffing requirement to include skillset, required of each existing staff member or new hire within the new facility. An important consideration when thinking of staffing needs is the incumbent or new hires ability to perform the requirements of the organization. Providing specific details helps in making a determination when interview or realigning staff. This proposal will address the needs of XYZ in detail, enabling the organization a broad overview of how the processes will determine the organizations success.

LEGAL CONSIDERATIONS FOR XYZ

It is important to take into account the legal considerations that should be implemented when designing a digital forensics laboratory. Digital forensics is a field that deals mostly with the criminal justice system, and thus has many regulations/standards in place to ensure appropriate actions are taken in the handling and investigation of digital evidence. These standards and accreditations are critical when designing and implementing a functional digital forensics laboratory as they will provide a testimony to the legitimacy of the XYZ lab. Also, it has recently been mandated that digital forensic laboratories must adhere to certain standards if they are to be utilized in criminal court proceedings. As one of XYZ laboratories core foundations is to investigate digital evidence for use in criminal trials, it is critical to adhere to these standards and achieve the necessary accreditations. A significant aspect of the digital forensic lab’s standards deals with ensuring the proper handling and management of digital evidence. Due to the importance of evidence management and its relation to lab accreditations, it is essential that we also discuss proper evidence handling procedures and documentation. Additionally, legal counsel for representation on behalf of XYZ Inc. should be discussed to ensure counsel is available in the event of charges being brought against our new forensics laboratory.

ISO-17025 Accreditation

Arguably, the most important accreditation/standard in regards to digital forensic laboratories is the ISO-17025. The main reason for this is because this accreditation is required for digital forensics laboratories who investigate evidence for the criminal justice system. Starting October 2017, it has been mandated that providers of Digital Forensic investigative services who contract for the criminal justice system must be accredited to the ISO-7025 standard (IntaForensics, 2017). So, what is the ISO-17025? ISO-17025 is a standard that was set forth upon testing and investigative laboratories (IntaForensics, 2017). It was first established in 1999, and was revised/re-released in 2005. ISO-17025 sets forth standards and active measures to ensure relevant digital laboratories adhere to rigorous quality control measures as well as ensures accountability for evidence handling. The main scope of the standard deals with ensuring chain of custody is kept as well as ensure quality control measures are adhered to thoroughly. 17025 also pays close attention to the actual testing done upon the digital evidence. As mentioned initially, 17025 was created for specifically placing standards upon testing and calibration laboratories. Regarding the digital forensics field, testing is a large part of what occurs in a standard digital forensics laboratory (ANAB, 2015). The ISO 17025 standard ensures proper testing techniques are utilized regarding modern-day best practices as well as limit the possibility of data corruption (ANAB, 2015). The standard also ensures a quality control management procedure is put into place. This ensures that current practices do not impact the integrity of daily production, as well as mandates the laboratory adheres to modern practices for the sake of maintaining optimal investigative quality. Finally, standard also bases the accreditation on a personnel basis. The standard ensures that all personnel are technically competent in their specific field.

Now that we have an idea of what the ISO-17025 standard actually is, how do we obtain it? To begin the accreditation process, XYZ must first hire a third-party accreditation body. This accreditation body is certified to perform an in-depth quality and investigative assessment that is required to obtain the 17025 accreditation. It is the duty of this certified accreditation body to ultimately decide if XYZ’s digital forensic laboratory is approved for 17025 accreditations. The accreditation process can be summarized with the following chart (ANAB, 2016):

image1.png

To follow along with the above flow chart, the first step is to get a quote from the third-party accreditation body. This discusses the one-time cost for the initial accreditation process as well as the recurring cost to keep up with the accreditation annually. The next step is the pre-assessment visit. This visit will help XYZ laboratories have an in-depth understanding on where we currently stand in the 17025 accreditation requirements. This will allow the accreditation body to make a preliminary assessment on where XYZ needs to improve in order to meet the requirements. The next steps entail the application and documents review. This ensures everything is in order from a paperwork and licensing perspective. The most important part of the process is the on-site assessment. This is the rigorous official assessment from the accreditation body that ensures XYZ laboratories adheres to all in-place standards set forth in the ISO 17025. Once that is completed, a period for the ‘resolution of nonconformities’ is given for XYZ to make minor adjustments to adhere to the standards. After that period, the accreditation decision is made to determine if XYZ digital laboratories adheres to all relevant standards.

ISO-27000: Information Security management

Another important security standard to consider when developing our digital forensics lab is the ISO-27000. This standard contains a grouping of standards that deal directly with insuring information assets are kept secure (ISO, 2016). This is important in the digital forensics world as we are often dealing with sensitive information and possible incriminating digital evidence. It is vastly important to keep our laboratory data secure to protect sensitive information as well as prevent data corruption from an outside source (ISO, 2016). This standard implements best practices that should be utilized in a digital laboratory. This not only deals with network security, but also ensuring security of storage data and physical evidence such as hard-drives. To adhere to this standard, an accreditation body conducts extensive on-site visits as well as penetration tests to ensure security is up-to-date and in place. Unlike ISO 17025, this standard is not required to work in conjunction with the criminal justice system. However, it is still highly sought after to prove organizational legitimacy and to provide XYZ laborites with a reputation for adhering to secure practices.

Digital Evidence Management

An important aspect of a digital forensics laboratory is ensuring the proper management of digital evidence. This is important due to the nature of the work that is being conducted. A majority of evidence investigated will be utilized in criminal trials, so it is critical to ensure this data is admissible which must be done by following change management procedures (Scalet, 2005). Of the more important aspects of digital evidence management is the chain of custody. The chain of custody details who exactly as accessed a piece of digital evidence and when (Scalet, 2005). This is important to keep track of as a lot of this evidence that is being investigated may be utilized in a court proceeding. For this evidence to be admissible as well as to be found credible, it must be documented that no undesirable personnel or individuals have accessed the evidence and possibly corrupted it. It would be very easy for a defense to have evidence thrown out if investigators cannot provide a well-documented timeline of the handling of evidence. Therefore, documentation is critical in respect to chain of custody. Proper documentation provides an accurate timeline and ‘check-in/check-out’ procedure as to who accessed evidence and when (Scalet, 2005). This ensures that the evidence has remained untouched by unauthorized forces and allows for admissibility in a court setting. Another important aspect of digital evidence management is data integrity. Data integrity ensures that data has not been corrupted, changed, or tampered with. The goal of data integrity is for the initial digital evidence to not change at all throughout the investigative process. This is important, especially in court proceedings, to ensure no outside sources have manipulated the data in anyway. Hashes ensure data has not changed, and it is also important to keep several different backups and/or images.

Legal Counsel for XYZ INC.

For the budgetary concerns of this project, we have ensured that XYZ Inc. already had legal counsel in place prior to the creation of this new digital forensics laboratory. However, it is still essential to discuss how they would be utilized relevant to the digital forensics laboratory itself. It is important to have legal counsel in place to ensure XYZ labs maintains the proper accreditations and adheres to any new federal standards that may be put in place (Delatorre, 2015). To prevent legal action against XYZ, it is critical for a legal team to continuously ensure our lab maintains appropriate standards. It is also important for a legal team to be in place in the event legal action is taken against XYZ for improper handling of evidence (Delatorre, 2015). Although this is very unlikely, there is still the chance a defending party may accuse of XYZ of improper manipulation of evidence or not adhering to correct investigative procedures. The legal team will be able to set forth the in-place standards and control measures we follow to properly combat these suits that may occur.

FORENSICS HARDWARE

In this forensics lab, there are to be various hardware tools such as workstations, servers, portable storage devices, adaptors, cables, and network storage devices. Company XYZ will need to buy the best computer workstations they can afford because computers are the backbone of any digital forensics lab. Because of the large computations required by the forensics software, quit a bit of computing power is needed. The money saved at the time of purchasing hardware can amount to tens of thousands of dollars lost over the lifetime of the system as a result of losses and delays in analysis (Jones & Valli, 2009). All the hardware being purchased is on an approved vendor’s list for the operating systems Windows and Red Hat Linux. To retain the accepted standards of the hardware, only certified driver’s and patches with be used with the operating system.

It is being proposed that there be three forensic workstations within the lab. The workstation is to comprise of multicore processors, 64 GB of RAM, a fast 2 TB solid state drive and as many ports possible to accommodate the multiple types a cables which may be needed to connect hard drives. For imaging, the workstations will require controller cards and connectors for the purpose of connecting to both 2.5-inch and 3.5-inch disks profiles IDE and SCSI, as well as FireWire and high-speed USB ports. Because the world of digital forensics is no longer only computer centric with the introduction of smartphones, the workstation with have the latest cables to connect these mobile devices. Using a private 10 GB Ethernet network, removed from the company office network, is highly suggested because the transfer of large amounts of data to and from the network storage filer is required.

There is to be one high end server for the purpose of malware analysis. This server is to be off any network and removed from all in-production systems. It is never recommended to store or archive copies of malicious code on production systems because doing so increases the risk of accidental execution (UMUC, 2016). For storage on such a system, the hard drives will be removed regularly and stored in a controlled safe so are to not have them accidentally inserted into a production system. Also, to have more separation on the server, it will be used as a virtualized server so as to keep any malware in a deeper layered sandbox.

Forensic examiners frequently search through massive amounts of data. Therefore, forensic labs need the capacity to store voluminous amounts of data. In forensics, the two basic types of storage are live and archive (Jones & Valli, 2009). Live storage is needed for active cases, while archive storage is for data that needs to be archived and preserved for a certain amount of time. To meet the live storage requirement, it is proposed that the forensics lib have a Network Access Server (NAS) filer. This filer would be available to all forensic workstations and has the reliability that is needed for such critical data. There is a high cost to this network appliance, but the authors of this report believe that in the long run the reliability and the scalability of such a device will pay off in the long run. The Network Appliance (NetApp) filer would start with 100 TB of disks space and as the forensic workload increased additional disks could be added to expand it. Using industry standards is also a plus when it comes to credibility. The vendor Network Appliance was chosen for their outstanding support of their product and the ease for which it takes to train staff to manage it. This would help with keeping personnel training within budget. Because archive storage will not be frequently accessed as live storage, we are opting to use traditional media such as DVD-R discs. Discs will have to be properly inventoried and will have to be re-written to fresh media every 5 years (Craig & Valli, 2009). By using discs, instead of larger magnetic tapes, the cost normally associated with an expensive tape library and the backup software needed will have been eliminated.

FORENSICS SOFTWARE

Regarding forensic software, aspects of stability and admissibility must considered when deciding which software is to be used in the forensic lab. Given the choice of commercial or open source software, the lab is to have a majority of its software be commercial because of the ease in which it can be validated and vendor support. Free open source software is to provide a secondary role where the commercial software lacks features or is used to gather supportive evidence to the major findings in a case.

In General, there are five broad categories of software tools that should at a minimum in any digital forensics laboratory (Britz, 2013). The categories are (1) data preservation, duplication, & verification, (2) data recovery & extraction, (3) data analysis, (4) data reporting, and (5) network. A data preservation tool has the ability to image the original suspect drive bit for bit. The image is the data from which the examiners will work from, thus preserving the original evidence. A data and extraction utility should be able to reveal obscure information and restore files which have been deleted. As for data analysis tools, they have the arduous task of searching for pertinent information that might be used as evidence. Lastly, reporting software is for the purpose of documentation for the findings. Having one software solution from one vendor would save time in training and the start of the lab. Therefore, the majority of the forensics software is to be provided by Ultimate Toolkit (UTK) by Access Data.

Ultimate Toolkit is an automated program which bundles a variety of stand-alone programs by vendor Access Data. If XYZ Inc. was to buy each of these individual tools, whether from Access Data or another software vendor, the costs would be significantly higher. Should the company choose to try other vendor’s software at a later time, these bundled programs are compatible with programs such as EnCase, Snapback and Safeback. Among the many utilities found in the program, there are tools which provide hashing verification, known file filtering, encrypted file identification; deleted file recovery and INSO file viewing. Incorporated into the program are password crackers, imagining software, registry viewers, wiping tools and network software. An automated feature of the program has the ability to generate professional reports. Access Data’s product is considered to be more intuitive and less proprietary when compared to other forensics software (Britz, 2013). If it is determined that a necessary tool is missing, open source software should be able to fill in the gaps. Having in the lab the operating system Red Hat Linux, whether virtualized or on a physical workstation, should allow for many options with open source software.

Hardware and Software Costs

Having discussed the hardware and software requirements for the forensics lab, we shall now move onto to acquisition costs for each item and the operating costs associated with keeping the tools functioning.

Initial Acquisition Costs

3 HP Z240 Tower Forensics Workstations $6,000

1 HP LaserJet Enterprise Flow MFP M631 $2,700

4 LCD Monitors $1,500

1 HP ProLiant 380 G9 Server $5,000

1 Cisco Catalyst Switch $1,900

1 Network Appliance (NAS) FAS3010 filer $50,000

2 Large Lock File Safes $6,000

Multiple Removable Storage Devices $3,000

2 Crime Scene Tool Kit $2,500

Operating Systems Windows & Red Hat $500

Access Data Ultimate Toolkit $1,949

VMware Workstation $400

Operating Costs per Year

Operating Systems Support Contract $1,000

Network Appliance Support Contract $2,000

Access Data Support Contract $1,000

Hardware Parts and Repairs $2,000

PHYSICAL AND ENVIRONMENTAL

This section of the proposal will cover our team’s physical recommendations for XYZ’s forensic lab. As noted in previous sections, XYZ is experiencing exponential growth and currently has a staff of 100 hundred employees. That information withstanding, the physical recommendations will be based on researched conducted utilizing public, private and internationally managed forensic labs. Specifically, we will make recommendations about:

1. Building Location

2. Building size

3. Building physical layout

4. Analyst work space

5. Analyst furniture

6. Power requirements

7. Environmental

8. Physical security

Due to the limited budget and current economic climate of real estate, it is our recommendation that XYZ lease a building and follow the detailed information in this section to select a location for its lab. A scalable budget proposal will be provided to help XYZ determine the cost benefits of leasing versus building a lab space.

Building Location

The Federal Bureau of Investigation (FBI) currently has sixteen (16) Regional Computer Forensic Laboratory (RCFL) service areas strategically located throughout the continental United States (FBI, 2014). The figure below is a graphical representation of RCFL locations.image9.png

Figure P1 Courtesy FBI (2014)

Our research also located five (5) public and privately managed forensic labs in

1. New York, New York (Public);

2. San Diego Count, California (Public);

3. Jackson County, Kansas (Public);

4. Phoenix Arizona (Public); and

5. Dawlat al Kuwayt (State of Kuwait) (Private)

Considering the budget and current location of existing forensic labs it is our recommendation that XYZ’s lab be located either in Silicon Valley; Northern Virginia technology corridor or Western Maryland/Southern Pennsylvania rural areas. This is because these areas meet the minimum recommended physical criterial for a good location for a forensics lab. As outlined by Jones (2009), “site's susceptibility to naturally occurring events that can impact operations, namely fire, flood, storm, and earthquake” should be avoided. As noted by both BH Consulting (2016) and Jones (2009) forensic lab locations should have access to major ingress and egress transportation mediums (i.e. roads, air ports, rail or shipping) as well as sufficient access to highly reliable power and communication grids. The location should also be sustainable independently; if a manmade or natural disaster occurs.

Building size

image2.png

image3.png

image4.png

image5.png

Table P1 (images Courtesy Crime Lab Designs, 2014)

As noted by the figure P1 above the average size of the public and private forensics labs researched, is 308,677 Square Feet with an average cost of 121.1 million dollars. RCFL (2014) does not provide this specific information, however they have indicated that

“A mid-size RCFL consists of 15 people: 12 of the staff members are Examiners and 3 staff members support the RCFL” and that “RCFL start-up costs vary from site to site depending upon the number of personnel assigned, real estate costs, and site preparation/renovation”.

With RCFL being the standard model for forensic labs in the United States, we would recommend that XYZ lease a 300,000 Square Foot dwelling as the current budget does not appear to have allocated enough funding for new building construction. Also, the lease cost can be written off as a business expense that can, in turn, be placed into a capital improvement fund, until enough funding is procured to construct a new building asset. Alternatively, a request for Capital Funding can be made outside of the current budget, if management wants to create an asset immediately.

Building Physical Layout

Per Jones (2009), we are recommending that XYZs hire an architectural firm to design a single-story forensics lab that closely mirrors the layout in Figure P2 below.

image6.png

Figure P2 Courtesy Jones (209)

We are recommending that all rooms leading from the reception area be secured with both physical digital key locks and biometric card key swipes. The internal analysis, sensitive investigation and imaging areas should also include biometric eye iris and/or finger print scanning authorization for access. We are also recommending as per Jones (2009), that no windows be installed in any of the sensitive areas and that clouding of any other windows installed on premise be installed.

Analyst Work Space

Per Evans (2015), since analyst will spend several hours beyond the normal eight-hour work day or may be required to work outside of the traditional 9 am to 5pm schedule. All work areas should at a minimum be 48 square feet by 64 square feet and 34 inches deep. Ergonomic designs that restrict viewing of evidence on monitors as well as desk should be considered and are highly recommended to protect the integrity of evidence collected.

Analyst Furniture

Analyst furniture should be flexible and the option to sit or stand i.e. an adjustable desk should be procured as recommended by Evans (2015). Also, desks with lockable monitor lifts such as those designed by Nexus21 should be procured. These types of desks, provide another layer of security by restricting access to keyboards, monitor and workstations. See Figure P3 for an example of this type of unit

image7.png

Figure P3 Courtesy Nexus 21

Power Requirements

Multiple electrical, data and voice connections should be installed in each analyst work area. We recommend a minimum of 8 electrical, 6 data and 6 voice connections. All electrical circuits should be connected to a building UPS. The building UPS should be connected to dedicated power generators. We recommend that redundant generators be placed on premise that have a load time of less than 30 seconds and a fuel capacity that can sustain the entire complex for 7 to 10 business days before refueling is needed.

Environmental

Dedicated and separated SCADA systems with room controllable thermostats should be setup for the analysis, secure, imaging and analysis areas. All other areas of the building can be feed off of the main SCADA system. Access to the analysis, secure, imaging and analysis areas’ SCADA equipment should be restricted to personnel that work in those areas.

Physical Security

Per Jones (2009) and Evans (2015) the selected location should instigate a posture that includes the principles of defense in depth. Defense in depth, in this case, speaks directly not only to the physical security of the building, but also the physical ingress and egress traffic for vehicles as well as data. For example, it is highly recommended that surveillance systems, monitored alarm systems, LED lighting be installed as well as cellular and data signal deadening materials be infused into walls and windows. These measures should ensure that collected data stays within the lab and stops non-authorized entities from stealing or monitoring data without consent. Figure P4 is a graphical example of the defense in depth recommendations.

image8.png

Figure P4 Courtesy Jones (2009)

If XYZ adheres to these recommendations then they will indeed have a secure, state of the art building to conduct forensic commerce within budget.

FORENSIC PERSONNEL FOR XYZ, INC.

In order to come up with a proposal of personnel required for XYZ, Inc, we first have to consider the various roles and responsibilities necessary to operate a forensic laboratory. The major roles within the area of digital forensic science are Lab Manager, Case Forensic Investigator, Forensic Examiner/Analyst, and Laboratory Technician. Some of the roles are quite similar and could overlap with one another which is why they are frequently used interchangeably. For example a Lab Manager and Case Investigator do not generally perform data capture and analyses but while the Lab Manager deals more with the day to day management of the lab such as budgeting, personnel management, operations and quality control and communications with Executives. The Case Investigator serves more as a liaison to clients or others outside the organization. The same holds true for the Forensic Examiner and the Lab Technician. Both bring expertise to the forensic world but while Forensic Examiners utilize forensic tools and generally hold certifications within the industry, Lab Technicians perform fundamental laboratory tasks relating to defined standards, procedures, and metrics (Jones, Valli, 2009) Our proposal for XYZ, Inc. is to recruit personnel with various skill sets in order to keep personnel costs down. For example, a Lab Manager who can perform the functions of a Manager and Case Investigator as well as provide segregation of duties functions for the lab. A Lab Examiner who can perform the typical functions of a Forensic Examiner and Lab Technician while having the expertise to collect and analyze data from all digital means as well as reporting and communicating results which includes the ability to testify as a subject matter expert (SME) in a court of law. By utilizing individuals with these varied skill sets, XYZ, Inc. will have better coverage of assignments and the ability to account for personnel due to absenteeism such as annual leave, illness or bereavement while reducing personnel costs. An Administrative Assistant is recommended in order to assist the Lab Manager with the day to day rudimentary operations of the lab such as ordering supplies and answering the phone, or assisting Lab Examiners with non-forensic related obligations. We assumed that XYZ, Inc. already had a legal department or legal counsel on hand for its existing operations. Legal counsel would play an important role within the forensics department by guiding the Lab Manger and Lab Examiners with interpreting privacy laws as well as other related laws such as search and seizure which could affect the collection and analyses of data. Legal counsel could also assist the forensic team with guidance when serving as an expert witness in a court of law for criminal cases. By assuming XYZ, Inc. already possessed legal representation, meeting the budget for the forensic lab proposal would be achievable.

As a starting point, we recommend XYZ, Inc. appoint one Lab Manager, one Administrative Assistant and three Lab Examiners, until better clarity can be determined from the case load of work which is needed. Salary ranges for the Lab Manager, Lab Examiner, and Administrative Assistant vary depending on experience and region. Based on the geographic location of XYZ, Inc. we feel the following salary estimates for the Lab Manager, $70,000; Lab Examiner, $65,000 (each); and Administrative Assistant, $30,000 (Forensic Salaries in the U.S. n.d.); totaling $295,000, would be a reasonable estimate.

There are a variety of certifications forensics examiners can choose to obtain such as: Certified Computer Examiner (CCE); Certified Computer Forensics Examiner (CCFE); Certified Forensic Computer Examiner (CFCE); and (Global Information Assurance Certification GIAC) Certified Forensic Analyst (GCFA). These certifications test the practical knowledge examiners should have for conducting forensics examinations. Vendors also offer certifications for use of their own products such as EnCase which offers an EnCase Certified Examiner (EnCE) credential. AccessData is another vendor that offers a certification, AccessData Certified Examiner (ACE), for use of its Forensic Toolkit (FTK) product (Nelson, Phillips, & Steuart, 2014). Examiners selected to work for the XYZ, Inc. forensic lab will be required to hold at least one of the previously mentioned certifications.

Due to the sensitive nature of the worked performed by forensics personnel, it is imperative XYZ, Inc. perform pre-employment screening, background checks, and security clearances. Pre-employment screening should be in the form of psychological testing which can help determine an applicant’s honesty, integrity, and ethical standards as well as to determine whether the applicant exhibits any negative characteristics such as mental issues or unethical behavior. The pre-screening procedure should also help determine the applicant’s willingness to collaborate with his or her team as well as determine their communication and organizational skills. Background checks are another necessity for hiring forensic team members. This form of screening should look into an applicant’s financial and credit history, previous references, Police or FBI criminal checks, and verification of certifications (Jones, Valli, 2009). It would be detrimental to XYZ, Inc. if one of their forensic team members was found to have a criminal background which could discredit any forensic work performed by the team including testifying in a court of law. Security clearances may not be absolutely necessary for forensic team members; however it could benefit the team as a whole by having some or even all members with the ability to deal with classified or restricted material.

XYZ, Inc. should incorporate a continuing education program for their forensic personnel. With the level of change within the technology field, new products or services continue to evolve requiring forensic examiners to maintain their level of expertise. Smartphones alone are changing every year with more functions and features than the previous version. The hardware and software toolsets which forensic examiners utilize every day as part of their roles and responsibilities are also advancing, albeit maybe not as quickly as other forms of technology. Therefore, a third party curriculum would be suitable for personnel since it offers independence revolved around a developed educational process with established textbooks and guides. The previously mentioned certifications are one method of continuing education for forensic professionals. These certifications range in cost. For example, the CFCE costs $750 to $2750 depending on whether the student attends a two week classroom session or performs online training (CFCE n.d.). Most certifications can be expected to cost anywhere from $2,000 to $3,000 U.S dollars. Post graduate degree programs could be another option although XYZ, Inc. may want to include approval based on a contractual basis such as the employee would have to commit to work for XYZ, Inc. for three years after graduating from the program. The University of Maryland University College offers a Digital Forensics and Cyber Investigation graduate degree program. The curriculum requires completion of six courses or thirty six total credits and costs just under $25,000 U.S dollars (Digital Forensics and Cyber Investigation Master's Degree (n.d.). Based on the aforementioned information, we recommend XYZ, Inc. set a budget of $2,500 for each of the three Lab Examiners and Lab Manager totaling $10,000 annually. Post graduate costs would have to be considered on a case by case basis or incorporated into the pre-qualification of candidates.

Finally, some consideration was given to the notion of utilizing a certain level of outsourcing for Lab Examiners. For example, this issue could be more prevalent in a situation where the case load was higher than expected and the current staff was not able to complete the level of work required. However, there are some advantages and disadvantages to this notion. Having the ability to outsource some of the work could provide cost savings, flexibility with scheduling, expertise, and resource management transfer to the outsourcer. Having some optionality with outsourcing would save XYZ, Inc. with costs especially when taking into account health care and other company benefits. Costs would only be payable for work actually performed by the outsourcer. If an unforeseen situation occurred whereby the current staff was unable to meet caseload requirements, outsourcing could provide a readily available resource or possibly meet a level of expertise not readily available with existing forensic staff. Also, resource management or the day to day management for the outsourced staff would be the responsibility of the outsourcing entity relieving the Lab Manager of additional responsibilities. Some of the disadvantages are evident as well. There could be a loss of continuity amongst staff, uncertainty of the quality of outsourced personnel, and lack of organizational understanding. Turnover within an outsource environment could lead to miscommunication or less than satisfactory collaboration among staff since there is less of a chance a vendor would provide consistent resources. Having an outsourced member provide assistance doesn’t necessarily guarantee a high quality of service. There is less control the Lab Manager would have as to the expertise or continuing education from a vendor. Finally, utilizing an outsourcer could limit the knowledge of internal policy and procedures as well as other protocols of XYZ, Inc. Unless a consistent resource was provided by the vendor, the learning curve would be very high for the outsourced personnel to be able to grasp XYZ’s own internal policy and procedures and building professional relationships with XYZ, Inc. staff. Therefore we would recommend outsourcing only as an emergency circumstance.

CONCLUSION

This proposal outline an overview addressing each requirement needed to design and develop a comprehensive, competent, full performance laboratory which is unmatched within the industry and well within State and Federal guidelines for conducting operations. The proposal delivers software and hardware well within the project for the overall cost to construct this facility. The team addressed physical security elements which would enable the facility to maintain its integrity by ensuring evidence will be secure always. This speaks to staying power industry of a laboratory which takes the security of data and its authenticity serious aided XYZ to present competent evidence. With all the requirements addressed, this team has presented a plan which will aid XYZ in becoming top-in class.

APPENDIX A: COST TABLE

Department

Necessities

Description

Initial Cost

Annual Cost

Legal Considerations

ASCLD Certification

American Society of Crime Lab. Directors certification

$18,000.00

$14,000.00

ISO-17025 Accreditation

Accreditation required forensics laboratories

$2,000.00

$500.00

ISO-27000 Accreditation

Accreditation for securing systems and environment

$1,800.00

$300.00

Property/Physical

Building/Facility

The building itself that the forensic lab will be in

Furniture

Desks, chairs, etc.

Environmental Requirements

SCADA and HVAC system

Physical Security Measures

Gates, surveillance, etc.

Other

Hardware/Software

Forensics Hardware Devices

4 LCD Monitors

$1,500.00

$2,000.00

$4,000.00

HP ProLiant 380 G9 Server

$5,000.00

Cisco Catalyst Switch

$1,900.00

FAS3010 NAS

$50,000.00

2 Large Lock File Safes

$6,000.00

Multiple Removable Storage Devices

$3,000.00

3 HP Z240 Tower Forensics Workstations

$6,000.00

HP LaserJet Enterprise Flow MFP M631

$2,700.00

Forensics Software

O.S. Windows and Linux

$500.00

Access Data Ultimate Toolkit

$2,000.00

VMware Workstation

$400.00

Annual Support Contracts

$4,000

Personnel

Necessary Personnel for Forensics Laboratory Operation

Lab Manager

$70,000.00

$70,000.00

Lab Examiner

$195,000.00

$195,000.00

Administrative Assistant

$30,000.00

$30,000.00

Personnel Certifications and Continued Education

Encase, Forensics Toolkit, graduate programs, etc.

$10,000.00

$10,000.00

Total Initial Cost

Total Annual Cost

Total

$409,800.00

$325,800.00

Initial Cost

Annual Cost

Provided budget

$750,000.00

$575,000.00

Actual Cost

$409,800.00

$325,800.00

Amount under budget

$340,200.00

$249,200.00

REFERENCES

Anab. (2015). Accreditation manual for forensic service providers. ANAB. Retrieved from https://anab.qualtraxcloud.com/ShowDocument.aspx?ID=7183

Anab. (2016). How to achieve ISO/IEC 17025 accreditation. ANAB. Retrieved from http://www.anab.org/forensic-accreditation/iso-iec-17025-forensic-labs

Delatorre, O. (2015, July 21). 10 things attorneys should know about digital forensics. Law Technology Today. Retrieved from http://www.lawtechnologytoday.org/2015/07/10-things-attorneys-should-know-about-digital-forensics/

IntaForensics. (2017, September 19). ISO-17025 mandatory for digital forensics in the criminal justice system. IntaForensics. Retrieved from https://www.intaforensics.com/2017/09/19/iso-17025-mandatory-for-digital-forensics-in-the-criminal-justice-system/

ISO. (March 2016). ISO/IEC 27000 family-information security management systems. International Organization of Standardization. Retrieved from https://www.iso.org/isoiec-27001-information-security.html

Scalet, S.D. (2005, Dec. 1). How to keep a digital chain of custody. CSO Online. Retrieved from https://www.csoonline.com/article/2118807/investigations-forensics/how-to-keep-a-digital-chain-of-custody.html

Britz, M. (2013). Computer Forensics and Cyber Cfrime. New Jersy: Pearson.

Jones, A., & Craig, V. (2009). Building a Digital Forensic Laboratory. Burlington, MA: Elsevier.

Sammons, J. (2015). The Basics of Digital Forensics. Waltham, MA: Elsevier.

UMUC. (2016). CSEC 650 Module 7. Retrieved from https://learn.umuc.edu/content/enforced/248542-026828-01-2178-GO1-9046/CSES-650/CSES-650-week1/sco_content/en/resources/csec650_07.pdf

CFCE. (n.d.). Retrieved October 13, 2017, from https://www.iacis.com/certification-2/cfce/

Digital Forensics and Cyber Investigation Master's Degree. (n.d.). Retrieved October 13, 2017, from https://www.umuc.edu/academic-programs/masters-degrees/digital-forensics-cyber-investigation-ms.cfm

Forensic Salaries in the U.S. (n.d.). Retrieved October 11, 2017, from https://www.indeed.com/salaries/Forensics-Manager-Salaries

Jones, Andy & Valli, Craig. ( © 2009). Building a digital forensic laboratory: establishing and managing a successful facility. [Books24x7 version] Available from http://common.books24x7.com.ezproxy.umuc.edu/toc.aspx?bookid=37236.

Nelson, B., Phillips, A., & Steuart, C. (2014, November 7). Guide to Computer Forensics and Investigations. Retrieved October 11, 2017, from https://books.google.com/books?hl=en&lr=&id=PUh9AwAAQBAJ&oi=fnd&pg=PR3&dq=how to create a digital forensicslaboratory&ots=B6_aIxB9Cb&sig=Cqxu6ktWrCLzC1UHd8Ro62H9zSE#v=onepage&q=how%20to%20create%20a%20digital%20forensics%20laboratory&f=false