Acquire digital forensic data

Formats and tools

Unit Description
Reconstruct the unit from the xml and display it as an HTML page.
Assessment Tool
an assessor resource that builds a framework for writing an assessment tool
Assessment Template
generate a spreadsheet for marking this unit in a classroom environment. Put student names in the top row and check them off as they demonstrate competenece for each of the unit's elements and performance criteria.
Assessment Matrix
a slightly different format than the assessment template. A spreadsheet with unit names, elements and performance criteria in separate columns. Put assessment names in column headings to track which performance criteria each one covers. Good for ensuring that you've covered every one of the performance criteria with your assessment instrument (all assessement tools together).
Wiki Markup
mark up the unit in a wiki markup codes, ready to copy and paste into a wiki page. The output will work in most wikis but is designed to work particularly well as a Wikiversity learning project.
Evidence Guide
create an evidence guide for workplace assessment and RPL applicants
Competency Mapping Template
Unit of Competency Mapping – Information for Teachers/Assessors – Information for Learners. A template for developing assessments for a unit, which will help you to create valid, fair and reliable assessments for the unit, ready to give to trainers and students
Observation Checklist
create an observation checklist for workplace assessment and RPL applicants. This is similar to the evidence guide above, but a little shorter and friendlier on your printer. You will also need to create a seperate Assessor Marking Guide for guidelines on gathering evidence and a list of key points for each activity observed using the unit's range statement, required skills and evidence required (see the unit's html page for details)

Self Assessment Survey
A form for students to assess thier current skill levels against each of the unit's performance criteria. Cut and paste into a web document or print and distribute in hard copy.
Moodle Outcomes
Create a csv file of the unit's performance criteria to import into a moodle course as outcomes, ready to associate with each of your assignments. Here's a quick 'how to' for importing these into moodle 2.x
Registered Training Organisations
Trying to find someone to train or assess you? This link lists all the RTOs that are currently registered to deliver ICTCYS607, 'Acquire digital forensic data'.
Google Links
links to google searches, with filtering in place to maximise the usefulness of the returned results
Books
Reference books for 'Acquire digital forensic data' on fishpond.com.au. This online store has a huge range of books, pretty reasonable prices, free delivery in Australia *and* they give a small commission to ntisthis.com for every purchase, so go nuts :)


Elements and Performance Criteria

ELEMENT

PERFORMANCE CRITERIA

Elements describe the essential outcomes.

Performance criteria describe the performance needed to demonstrate achievement of the element.

1. Confirm incident and prepare to acquire data

1.1 Confirm and gather initial information on reported incident according to organisational policies and procedures

1.2 Research and assess occurrence according to organisational forensic data extraction requirements

1.3 Research and identify all laws and legislation required for data extraction tasks

1.4 Discuss and confirm if acquisition is required with required personnel

1.5 Consult and gather key incident information from required personnel

1.6 Identify device and components pertaining to incident according to task requirements

1.7 Develop and document data extraction plan and information gathered according to organisational requirements

1.8 Submit documentation to required personnel and seek and respond to feedback

2. Acquire forensic data

2.1 Contact and gather information from required personnel

2.2 Seize device pertaining to incident according to incident and legislation

2.3 Access and open device according to data extraction task requirements

2.4 Secure device’s networks, data logs, firewalls and hashing according to task requirements

2.5 Initiate data extraction according to task requirements and confirm that no data is tampered or deleted

2.6 Confirm completion of retrieval according to task requirements

2.7 Verify the hash according to task requirements

2.8 Document observations and findings and methodology

3. Analyse forensic data

3.1 Analyse data and verify against incident scope, information, devices and evidence

3.2 Document findings and analysis and submit to required personnel

3.3 Discuss abnormalities and confirm further evidence, devices and information needed

3.4 Make additional extractions according to task and technical requirements

3.5 Analyse network conversations according to task requirements

3.6 Verify chain of custody according to hash according to task requirements

3.7 Update findings and methodology in documentation according to organisational needs

4. Finalise data acquisition

4.1 Prepare data extracts and documentation for submission according to organisational and legislative requirements

4.2 Submit data extracts and analysis according to organisational and legislative requirements

4.3 Retrieve sign off from required personnel and gather feedback according to organisational policies and procedures