CS 6963 WK 9

CS 6963 WK 9 - make a forensic image, The image has been...

Info iconThis preview shows pages 1–9. Sign up to view the full content.

View Full Document Right Arrow Icon
Page 1 of 9 To: IS Security Officer Subject: Forensic Examination Request For the past several months, we have been conducting an investigation of an employee concerning the possible theft of our proprietary company information. It is believed that this employee removes corporate information in electronic form and passes it on to our competitors a company called BadCo. This employee, Sally Smith is believed to be preparing to transfer some of ForCorp’s proprietary information to BadCo. A BadCo employee, Joe Doaks has been developed as a possible contact for Smith. An informant has recently obtained a disk which may assist us in our investigation. The informant was not able to keep the disk, but was able to
Background image of page 1

Info iconThis preview has intentionally blurred sections. Sign up to view the full version.

View Full DocumentRight Arrow Icon
Background image of page 2
Background image of page 3

Info iconThis preview has intentionally blurred sections. Sign up to view the full version.

View Full DocumentRight Arrow Icon
Background image of page 4
Background image of page 5

Info iconThis preview has intentionally blurred sections. Sign up to view the full version.

View Full DocumentRight Arrow Icon
Background image of page 6
Background image of page 7

Info iconThis preview has intentionally blurred sections. Sign up to view the full version.

View Full DocumentRight Arrow Icon
Background image of page 8
Background image of page 9
This is the end of the preview. Sign up to access the rest of the document.

Unformatted text preview: make a forensic image, The image has been uploaded to the ePoly Doc Sharing section as Final.zip, which contains: Final.img and the digital signature in a file called sig.txt. EXAMNINATION REQUEST: Please determine if there is any information concerning Sally Smith, her contacts or her activities in connection with the theft and sale of ForCorp data on this disk. If any information is located, you are requested to identify the file name, location (physical and logical), the type of application used to create the information and any information of probative value that can be determined from this data. Page 2 of 9 Page 3 of 9 Page 4 of 9 Page 5 of 9 Page 6 of 9 Page 7 of 9 Page 8 of 9 Page 9 of 9...
View Full Document

Page1 / 9

CS 6963 WK 9 - make a forensic image, The image has been...

This preview shows document pages 1 - 9. Sign up to view the full document.

View Full Document Right Arrow Icon
Ask a homework question - tutors are online