Reference no: EM133459335
Case Study: As more companies store information electronically, there is an increased need for digital forensics to discover the trails of illegal or malicious acts. In this task, you will use the scenario to develop an investigative plan of action that will prepare your investigative team to conduct an analysis on the gathered evidence.
SCENARIO
An oil company's senior management has reason to suspect that John Smith, one of the company's mechanical engineers allegedly took information that was clearly identified as proprietary. The company's legal office has requested digital evidence regarding the potential violation of company policy, which prohibits the sharing of proprietary information without prior approval. The employee was not authorized to access proprietary information. All employees sign nondisclosure agreements (NDAs) and acceptable use policies (AUPs). Senior management and the legal office have approved this request.
You are a member of the investigative team that has been asked to develop an investigative plan of action.
Questions: A. write an investigative plan of action based on forensic best practices or standards that your team will implement by doing the following:
1. Discuss the strategy that your team will use to both maximize the collection of evidence and minimize the impact on the organization.
2. Describe the tools and techniques your team will use in evidence gathering, preparation, and analysis.
3. Describe how your team will collect and preserve required evidence, using standardized and accepted procedures.
4. Describe how your team will examine the seized evidence to determine which items are related to the suspected violation of company policy.
5. Discuss an approach that your team will use to draw conclusions based on the digital evidence that supports the claim of a policy violation.
6. Discuss how the case details and conclusions should be presented to senior management.