Running Head: ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 1
Final Project Milestone Two: Draft of Memo
ISE 640 Investigation Digital Forensic
SNHU
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 2
To: MR XYZ (Non-expert stakeholder)
From: Mr. ABC, Cyber Practitioner
Subject: Communication on details of cyber investigation
Date: December 18, 2019
Key Details
A major violation of IT security has taken place in ACME Construction
Company which has affected its intellectual property (IP). Drew Patrick, a director-
level employee of the business undertaking has been stealing intellectual property
from the concern for quite some time. He has not just violated the corporate policy
of ACME relating to the ‘security’ aspect but he has also jeopardized the survival
and sustainability of the entire organization. Without the knowledge of the business
organization, Drew has coped confidential and sensitive business information to his
computer system.
In order to carry out the assigned responsibilities in the business context,
Drew has access to various sensitive elements such as design documentation, support
documents, schematics, and other technical references that are maintained in the
firm’s Research and Development database. Drew Patrick basically took advantage of
his position in the organizational setting to steal sensitive data. Since he is planning
to leave the business company, he could use the sensitive IT data against it by
joining hands with a competitor.
The forensic investigation that has been carried out by the digital forensic
team sheds light on the involvement of Drew in stealing intellectual property (IP)
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 3
from the manufacturing organization. The security incident is extremely severe in
nature so special attention was given to capture relevant pieces of evidence against
Drew so that his involvement could be proved.
The role of the forensic investigation was of paramount importance as it
helped to identify Drew Patrick as the key culprit who was acting as an internal
threat for the organization. The investigation of the complex security issue revealed
that an anonymous account had been created on the suspect computer system which
was used to compromise the security of the business entity. The investigation of the
Network logs from the Intrusion Prevention Systems showed that in order to violate
the security setting of the manufacturing firm, Drew transferred the files of interest
to his desktop computer before it was externally transferred. The file access logs that
were present on the Research and Development servers confirmed the fact that the
account responsible for the copying of the sensitive business data belonged to Drew.
In order to carry out the forensic investigation in a professional and
disciplined manner, the high emphasis was given to the appropriate forensic
methodologies. For instance, the original data source was used in a restricted manner
so that its genuineness would not get adversely affected during the investigation
process. A copy of the original data was created by assigning hash values. It made
sure that the team had proper control over the changes that were made by the
forensic team. A diverse range of resources was used by the forensic team members
so that the investigation would generate accurate and valid results Some of the key
resources that were employed during the investigation process include knowledge and
skill-set of the investigation team and their ability to assess the security situation.
Some of the key elements that were used to conduct the investigation include a
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 4
forensic toolkit, md5deep software package, and an additional hard disk. The forensic
toolkit was used by the team to create a forensic image. The md5deep software
package was used for creating hash values for the original image as well as the
copied image. An additional hard disk was used by the team so that different
activities associated with forensic images could be conducted in an effective and
efficient manner.
All the tangible and intangible resources that were used by the forensic
investigation team played a key role to ascertain the involvement of Drew in the
security breach incident.
Implications of legal actions
The serious security incident that had occurred in ACME Construction
Company was of high magnitude. The assigned forensic team made sure to follow
proper procedures and protocols so that the entire investigation process would be
accurate, reliable and authentic. One of the core objectives was to make sure that all
the legal standards were taken into consideration throughout the forensic investigation
process.
Special attention was given to Daubert Standard. It is a rule of evidence that
is used for evaluating the credibility of expert witnesses whose testimony would be
used or presented in the court of law (What standards does the judge use to
evaluate whether a witness is allowed to testify, 2019).
In addition to this, the forensic team that was involved in the investigation
process made sure to give emphasis to “Chain of Custody.” While conducting a
forensic investigation the integrity of data and information is a fundamental necessity
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 5
that has to be taken care of. A Chain of Custody can be defined as the
“documentation of the history of samples through all possession and handling from
the time of collection through analysis and final disposition.” This systematic
approach primarily allows the investigation team to adopt a systematic and
methodical approach so that a well-defined sequence can be adopted for analyzing,
controlling, maintaining custody and disposing of the physical or digital piece of
evidence (Chain of Custody, 2019, p 5). This vital rule of evidence was strictly
followed by the forensic investigation team so that the collected pieces of evidence
could be presented before the court of law.
The Federal Rules of Evidence (FRE) was also taken into account by the
forensic investigation team while investigating Drew Patrick. FRE has been designed
to offer proper guidance to the investigators and responders while gathering and
presenting evidence before the court of law (Johnson, 2013). The assigned security
team of ACME Construction Company followed the legal rules and regulations so
that the authenticity of the collected data would be given top priority. Hash values
were used by the forensic investigation team so that the digital evidence could be
presented in the court of law.
The team ensured that all the investigation aspects were in sync with the
legal requirements. Such an approach was adopted so that the collected pieces of
evidence could be used by the business undertaking against Drew Patrick who had
been stealing sensitive business information.
The thorough forensic investigation that was carried out by the assigned team
was carefully designed so that high priority could be given to the accuracy,
defensibility and validity aspects. The team of investigators used a diverse range of
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 6
tangible and intangible resources so that a thorough and in-depth investigation could
be carried out to help ACME Construction Company in the legal context.
The security incident that has taken place in the manufacturing organization
shows that Drew Patrick was primarily involved in it. He had been using his high
position in the organization so that he could steal confidential and sensitive
information pertaining to the manufacturing concern. The forensic investigation team
gave high emphasis to the legal aspects so that the collected pieces of evidence
could be used in the court of law to prove the involvement of Drew. The legal
considerations by the team could be used in favor of ACME as it could help the
organization to prove how Drew was stealing the confidential data and information
that was stored in the Research and Development (R&D) database of the
manufacturing organization. Various aspects of the forensic investigators have been
captured here which showcase Drew’s involvement in the intellectual property breach
incident.
ISE 640 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 7
References
Chain of Custody. (2019). Retrieved December 19, 2019, from
https://www.in.gov/idem/airquality/files/qa_manual_chap_10.pdf.
Johnson, L., 2013. Computer incident response and forensics team management:
Conducting a successful incident response. Newnes.
What standards does the judge use to evaluate whether a witness is allowed to
testify? (2019). Retrieved December 19, 2019, from
https://www.factsabouttalc.com/_document/about-daubert-information-on-federal-
rules-of-evidence?id=0000016d-b710-d9c2-a17f-b7b199020000.