1 / 7100%
Running Head: ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
Final Project Milestone Two: Draft of Memo
ISE 640 Investigation Digital Forensic
SNHU
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
To: MR XYZ (Non-expert stakeholder)
From: Mr. ABC, Cyber Practitioner
Subject: Communication on details of cyber investigation
Date: December 18, 2019
Key Details
A major violation of IT security has taken place in ACME Construction
Company which has affected its intellectual property (IP). Drew Patrick, a director-level
employee of the business undertaking has been stealing intellectual property from the
concern for quite some time. He has not just violated the corporate policy of ACME
relating to the ‘security’ aspect but he has also jeopardized the survival and
sustainability of the entire organization. Without the knowledge of the business
organization, Drew has coped confidential and sensitive business information to his
computer system.
In order to carry out the assigned responsibilities in the business context, Drew
has access to various sensitive elements such as design documentation, support
documents, schematics, and other technical references that are maintained in the firm’s
Research and Development database. Drew Patrick basically took advantage of his
position in the organizational setting to steal sensitive data. Since he is planning to leave
the business company, he could use the sensitive IT data against it by joining hands
with a competitor.
The forensic investigation that has been carried out by the digital forensic team
sheds light on the involvement of Drew in stealing intellectual property (IP) from the
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
manufacturing organization. The security incident is extremely severe in nature so
special attention was given to capture relevant pieces of evidence against Drew so that
his involvement could be proved.
The role of the forensic investigation was of paramount importance as it helped
to identify Drew Patrick as the key culprit who was acting as an internal threat for the
organization. The investigation of the complex security issue revealed that an anonymous
account had been created on the suspect computer system which was used to
compromise the security of the business entity. The investigation of the Network logs
from the Intrusion Prevention Systems showed that in order to violate the security
setting of the manufacturing firm, Drew transferred the files of interest to his desktop
computer before it was externally transferred. The file access logs that were present on
the Research and Development servers confirmed the fact that the account responsible
for the copying of the sensitive business data belonged to Drew.
In order to carry out the forensic investigation in a professional and disciplined
manner, the high emphasis was given to the appropriate forensic methodologies. For
instance, the original data source was used in a restricted manner so that its genuineness
would not get adversely affected during the investigation process. A copy of the original
data was created by assigning hash values. It made sure that the team had proper control
over the changes that were made by the forensic team. A diverse range of resources was
used by the forensic team members so that the investigation would generate accurate
and valid results Some of the key resources that were employed during the investigation
process include knowledge and skill-set of the investigation team and their ability to
assess the security situation. Some of the key elements that were used to conduct the
investigation include a forensic toolkit, md5deep software package, and an additional
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
hard disk. The forensic toolkit was used by the team to create a forensic image. The
md5deep software package was used for creating hash values for the original image as
well as the copied image. An additional hard disk was used by the team so that
different activities associated with forensic images could be conducted in an effective
and efficient manner.
All the tangible and intangible resources that were used by the forensic
investigation team played a key role to ascertain the involvement of Drew in the
security breach incident.
Implications of legal actions
The serious security incident that had occurred in ACME Construction Company
was of high magnitude. The assigned forensic team made sure to follow proper
procedures and protocols so that the entire investigation process would be accurate,
reliable and authentic. One of the core objectives was to make sure that all the legal
standards were taken into consideration throughout the forensic investigation process.
Special attention was given to Daubert Standard. It is a rule of evidence that is
used for evaluating the credibility of expert witnesses whose testimony would be used or
presented in the court of law (What standards does the judge use to evaluate whether a
witness is allowed to testify, 2019).
In addition to this, the forensic team that was involved in the investigation
process made sure to give emphasis to “Chain of Custody.” While conducting a forensic
investigation the integrity of data and information is a fundamental necessity that has to
be taken care of. A Chain of Custody can be defined as the “documentation of the
history of samples through all possession and handling from the time of collection
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
through analysis and final disposition.” This systematic approach primarily allows the
investigation team to adopt a systematic and methodical approach so that a well-defined
sequence can be adopted for analyzing, controlling, maintaining custody and disposing
of the physical or digital piece of evidence (Chain of Custody, 2019, p 5). This vital
rule of evidence was strictly followed by the forensic investigation team so that the
collected pieces of evidence could be presented before the court of law.
The Federal Rules of Evidence (FRE) was also taken into account by the
forensic investigation team while investigating Drew Patrick. FRE has been designed to
offer proper guidance to the investigators and responders while gathering and presenting
evidence before the court of law (Johnson, 2013). The assigned security team of ACME
Construction Company followed the legal rules and regulations so that the authenticity
of the collected data would be given top priority. Hash values were used by the forensic
investigation team so that the digital evidence could be presented in the court of law.
The team ensured that all the investigation aspects were in sync with the legal
requirements. Such an approach was adopted so that the collected pieces of evidence
could be used by the business undertaking against Drew Patrick who had been stealing
sensitive business information.
The thorough forensic investigation that was carried out by the assigned team
was carefully designed so that high priority could be given to the accuracy, defensibility
and validity aspects. The team of investigators used a diverse range of tangible and
intangible resources so that a thorough and in-depth investigation could be carried out to
help ACME Construction Company in the legal context.
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
The security incident that has taken place in the manufacturing organization
shows that Drew Patrick was primarily involved in it. He had been using his high
position in the organization so that he could steal confidential and sensitive information
pertaining to the manufacturing concern. The forensic investigation team gave high
emphasis to the legal aspects so that the collected pieces of evidence could be used in
the court of law to prove the involvement of Drew. The legal considerations by the
team could be used in favor of ACME as it could help the organization to prove how
Drew was stealing the confidential data and information that was stored in the Research
and Development (R&D) database of the manufacturing organization. Various aspects of
the forensic investigators have been captured here which showcase Drew’s involvement
in the intellectual property breach incident.
ISE 640 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 7
References
Chain of Custody. (2019). Retrieved December 19, 2019, from
https://www.in.gov/idem/airquality/files/qa_manual_chap_10.pdf.
Johnson, L., 2013. Computer incident response and forensics team management:
Conducting a successful incident response. Newnes.
What standards does the judge use to evaluate whether a witness is allowed to testify?
(2019). Retrieved December 19, 2019, from
https://www.factsabouttalc.com/_document/about-daubert-information-on-federal-
rules-of-evidence?id=0000016d-b710-d9c2-a17f-b7b199020000.
Students also viewed