WGU D431 TASK 1 | DIGITAL FORENSICS IN CYBERSECURITY |
LATEST UPDATE WITH COMPLETE SOLUTIONS
Digital Forensics in Cybersecurity – D431 Task 1
In order to maximize the collection of evidence and minimize the impact on the organization, our
team will invoke a strategy that is outlined in the identify step of the NIST framework for securing
Chain of Custody. This will involve identifying what the company’s critical assets are, and taking an
inventory of all systems, people, data, and software. We will also need to “routinely assess the logs
and forms to understand if there are any gaps in transactions or access that could lead to a break in
chain of custody.” (Cybersecurity and Infrastructure Security Agency [CISA], 2023). Having a good
understanding of these items will ensure evidence collection is precise and pointed which in turn
leads to less impact to the organization.
Our team will be utilizing a digital forensic platform called Autopsy. This tool will take a digital
image of John Smith’s machine. We will then use Autopsy to download and search through all of
John Smith’s deleted files. Next, we will perform a keyword search with Autopsy to look for
evidence of John accessing any confidential or proprietary files. Our team will be analyzing network
logs to gather evidence. We will also be following the guidelines for documenting the digital and
analog forms and logs that track transactions and access to further support non-repudiation. This will
be important in proving the user in question is the one that in fact carried out the breach. We will also
utilize metadata tools provided by Autopsy to gather timestamps and user access files. The second
tool our team will utilize is shared technology known as Encase. Encase will provide comprehensive
reporting of the user’s timeline of activities. This will help our team to understand the chronological
order of events, file access, and changes.
Our team will collect and preserve the data by following the guidance provided in the “Detect”
portion of the NIST framework for securing Chain of Custody. This is done by tracking each asset
using a unique identifier. (Cybersecurity and Infrastructure Security Agency [CISA], 2023). This can
LATEST UPDATE WITH COMPLETE SOLUTIONS
Digital Forensics in Cybersecurity – D431 Task 1
In order to maximize the collection of evidence and minimize the impact on the organization, our
team will invoke a strategy that is outlined in the identify step of the NIST framework for securing
Chain of Custody. This will involve identifying what the company’s critical assets are, and taking an
inventory of all systems, people, data, and software. We will also need to “routinely assess the logs
and forms to understand if there are any gaps in transactions or access that could lead to a break in
chain of custody.” (Cybersecurity and Infrastructure Security Agency [CISA], 2023). Having a good
understanding of these items will ensure evidence collection is precise and pointed which in turn
leads to less impact to the organization.
Our team will be utilizing a digital forensic platform called Autopsy. This tool will take a digital
image of John Smith’s machine. We will then use Autopsy to download and search through all of
John Smith’s deleted files. Next, we will perform a keyword search with Autopsy to look for
evidence of John accessing any confidential or proprietary files. Our team will be analyzing network
logs to gather evidence. We will also be following the guidelines for documenting the digital and
analog forms and logs that track transactions and access to further support non-repudiation. This will
be important in proving the user in question is the one that in fact carried out the breach. We will also
utilize metadata tools provided by Autopsy to gather timestamps and user access files. The second
tool our team will utilize is shared technology known as Encase. Encase will provide comprehensive
reporting of the user’s timeline of activities. This will help our team to understand the chronological
order of events, file access, and changes.
Our team will collect and preserve the data by following the guidance provided in the “Detect”
portion of the NIST framework for securing Chain of Custody. This is done by tracking each asset
using a unique identifier. (Cybersecurity and Infrastructure Security Agency [CISA], 2023). This can