Plan for processing the potential crime incident scene

Assignment Help Basic Computer Science
Reference no: EM13235842

Scenario

You are the lead forensics investigator for XYZ, Inc. -- an industry leading cyber forensic company. You have just been notified that a top 5 health care company (HCC Partners in Life) has hired your company to investigate a potential breach of their medical records system.

The HCC Security Operations Center (SOC) identified some "inconsistencies" in the intrusion detection system (IDS) logs that caused the reliability to be questioned. HCC uses Snort IDS' running on Linux systems. In addition, the lead HCC database administrator received a strange e-mail from Human Resources (HR), which contained a benefits attachment. When she opened the attachment, the document was blank. She noticed that her system has been acting "strangely" after opening the attachment. She operates a Microsoft Windows XP workstation.

Your team has been tasked with analyzing the HCC network, database server, and any workstations you suspect to determine if there was a breach and any potential patient data leakage. The database server is a Microsoft Windows 2003 Server running Microsoft SQL Server 2008.
If there is any evidence of a breach, HHC has a history of taking these types of incidents to court for prosecution to the full extent of the law.

Note: You are representing the forensic team in this case scenario. The final exam is individual work with no collaboration permitted. 


Your Tasking

• Describe your plan for processing the potential crime/incident scene. (30 points). Some of the items you will want to cover include (not all inclusive):
1. How will your team identify potential digital evidence?
2. How will you prepare for the search?
3. What steps will your team take if you need to seize any digital evidence?
4. What documentation processes will you follow to help support any potential legal proceedings?
5. How will your team/company ensure proper storage/chain of evidence processes are followed?

• Discuss how your team will approach and process the database administrator's computer -- considering the potential malware on her system. (15 points).
1. Include the steps you will use to image her drive.
2. The areas on her system you will analyze for potential evidence of infection and/or modification.
3. Other items.
4. Discuss how your team will approach and process the database server -- as this is the location for patient medical records. (15 points).
5. Include the steps you will use to image the server's hard drive.
6. The areas on the server's system you will analyze for potential evidence of infection and/or modification.
7. Other items.


• Discuss how you prepare your team to be expert witnesses or support any expert testimony court requirements. (15 points).
1. Include the steps you take in the documentation phases of your investigation.
2. How you prepare your team for court testimony.
3. Ethics responsibilities you follow and require in your team's performance.

Required minimum-20  page

Reference no: EM13235842

Questions Cloud

What are your assessments of moral and ethical development : What are your assessments of the moral and ethical development and moral intelligence of the manager you worked for?
Database life cycle : Database Life Cycle
Compare and contrast the continuous review system : Compare and contrast the continuous review system with the periodic review system. Is the continuous review or periodic review inventory system more likely to result in higher safety stock? Which is likely to require more time and effort to admi..
Find the mass of the rod : A sphere of mass M is supported by a string that passes over a pulley at the end of a horizontal rod of length L, Find the mass of the portion of the string above the rod
Plan for processing the potential crime incident scene : Describe your plan for processing the potential crime/incident scene. Some of the items you will want to cover include
Compute the minimum mass of ethane : Calculate the minimum mass of ethane that could be left over by the chemical reaction. Be sure your answer has the correct number of significant digits. 2 C2H6 + 7 O2 = 4 CO2 + 6 H2O
Figure out the possible delays associated with admitting : As a process analyst with a Hospital, you have been assigned the task to figure out the possible delays associated with admitting and treating patients in the ER. Please provide a fishbone / cause-effect diagram to analyze the problem.
What is the income elasticity of demand for rainbow sandals : Consider the market for rainbow sandals. Suppose average household income increases from $44,000 per year to $61,000 per year. As a result, the demand for rainbow sandals increases from 427 to 535.
What are the limits to an open communication style : What are the limits to an open communication style when faced with ongoing rounds of downsizing?

Reviews

Write a Review

Basic Computer Science Questions & Answers

  How (it) support supply chains and business processes

How does information technology (IT) support supply chains and business processes in the global marketplace

  Identify and correct the errors

Identify and correct the erros in the following program. void nPrintln(string message, int n){int n=1;for (int i=0; i int main (){nPrintln(5, "Welcome to C++!");}

  Explain the role of such calculations in clipping algorithms

Given a line segment with endpoints (2. 5) and (9, 15), provide the equation for that line segment using a parameterized representation.

  Executing critical section in mutual exclusion protocol

In Lamport's mutual exclusion protocol, if process i is implementing critical section.

  Write advantages of group work on project

When working in group are you generally a leader, a follower, a slacker or some other role? Describe. Write down two advantages of group work and two disadvantages of working on project in group?

  Discuss whether you accept demand from manager

Discuss whether you should accept this demand from your manager or whether you should persuade your team to give their time to the organization rather than to their families. What factors might be significant in your decision?

  Information system staff members can afford to employ

How many Information system staff members do you think Reliable can reasonably afford to employ? What mix of skills would they require?

  Kinds of attitudes for upper management personnel

Explain in scholarly detail why it is recommended that business communications be oriented toward upper management and what kinds of attitudes should these upper management personnel possess.

  Assume that the input to each statement is the same

Assume that the input to each statement is the same: 5 28 36 a. cin >> x >> y >> ch; b. cin >> ch >> x >> y; c. cin >> x >> ch >> y; d. cin >> x >> y; cin.get(ch);

  How repeated measurement enhanced accuracy

Assume that hypothesis to be tested was that girls are taller than boys. This time boy and the girl were each measured 30 times with ruler which read to 1,400 of an inch.

  Create an instance variable credit limit to indicate

Create another sub class CreditCustomer. Create an instance variable credit limit to indicate the maximum limit ($500). Credit customers get a markup of 2% on the order price.

  Procedural structure of a simple inventory-accounting system

Using a structure chart, recognize the procedural structure of a simple inventory/accounting system for a small store (perhaps a rivately owned curio shop in a resort community)

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd