CISF210 Computer Forensics II

Department of Science, Technology, Engineering & Mathematics: Computer/Information Science

I. Course Number and Title
CISF210 Computer Forensics II
II. Number of Credits
3 credits
III. Number of Instructional Minutes
IV. Prerequisites
CISF110 (C or better)
V. Other Pertinent Information
VI. Catalog Course Description
This course is a continuation of Computer Forensics I. Topics include the fundamentals of digital computer acquisition, preservation, and analysis. Classroom concepts will be applied in a laboratory setting where students will employ basic rules of evidence, standard operating procedures for computer forensics.
VII. Required Course Content and Direction
  1. Course Learning Goals

    Students will:

    1. describe the features and differences between NTFS and FAT file systems;
    2. effectively utilize a commercial software tool to recover deleted files from a computer;
    3. evaluate the strengths and weaknesses of various software tools for data recovery; and
    4. develop a systematic approach to a computer investigation.
  2. Planned Sequence of Topics and/or Learning Activities

    Course Outline:

    1. Investigative Techniques
      1. The Investigator's Office and Laboratory
      2. Processing Crime and Incident Scenes
      3. Digital Evidence Controls
    2. Computer Forensics Tools
      1. Hardware
      2. Software
        1. Command Line
        2. GUI
    3. Platforms
      1. File Systems
      2. Boot Process
      3. Deleted Files and Slack Space
      4. Network Forensics and E-Mail Investigations
  3. Assessment Methods for Course Learning Goals

    Formal assessment will consist of open-ended questions reflecting theoretical and applied situations, as well as laboratory exercises.
  4. Reference, Resource, or Learning Materials to be used by Student:

    Departmentally-selected textbook and/or readings. Details provided by instructor of each course section. See course syllabus.

Review/Approval Date - 5/07; New Core 8/2015