You are the lead forensics investigator for XYZ, Inc. — an industry leading cyber forensic company. You have just been notified that a top 5 health care company (HCC Partners in Life) has hired your company to investigate a potential breach of their medical records system.
The HCC Security Operations Center (SOC) identified some “inconsistencies” in the intrusion detection system (IDS) logs that caused the reliability to be questioned. HCC uses Snort IDS’ running on Linux systems. In addition, the lead HCC database administrator received a strange e-mail from Human Resources (HR), which contained a benefits attachment. When she opened the attachment, the document was blank. She noticed that her system has been acting “strangely” after opening the attachment. She operates a Microsoft Windows XP workstation.
Your team has been tasked with analyzing the HCC network, database server, and any workstations you suspect to determine if there was a breach and any potential patient data leakage. The database server is a Microsoft Windows 2003 Server running Microsoft SQL Server 2008.
If there is any evidence of a breach, HHC has a history of taking these types of incidents to court for prosecution to the full extent of the law.
________________________________________________________________
Your Tasking
Describe your plan for processing the potential crime/incident scene. . Some of the items you will want to cover include (not all inclusive):
How will your team identify potential digital evidence?
How will you prepare for the search?
What steps will your team take if you need to seize any digital evidence?
What documentation processes will you follow to help support any potential legal proceedings?
How will your team/company ensure proper storage/chain of evidence processes are followed?
Discuss how your team will approach and process the database administrator’s computer — considering the potential malware on her system.
Include the steps you will use to image her drive.
The areas on her system you will analyze for potential evidence of infection and/or modification.
Other items.
Discuss how your team will approach and process the database server — as this is the location for patient medical records.
Include the steps you will use to image the server’s hard drive.
The areas on the server’s system you will analyze for potential evidence of infection and/or modification.
Other items.
Discuss how you prepare your team to be expert witnesses or support any expert testimony court requirements.
Include the steps you take in the documentation phases of your investigation.
How you prepare your team for court testimony.
Looking for the best essay writer? Click below to have a customized paper written as per your requirements.
You May Also Like This:
- Forensic Science
- Criminal-Digital Forensics
- Cyber-crime Forensics
- Cyber crime forensics
- CCJS Project
- Digital forensic
- Digital forencic
- Mapping Consumer Digital Journey
- How social media/digital technology is affecting the society
- Branding in the Digital Age and Online Distribution
- Disaster Recovery Plan
- SQL Security and High Availability
- Network Design and Implementation
- NETWORKING ADMINISTRATION AND MANAGEMENT
- Public Key Infrastructure
- implement a network using VMware Workstation to develop a Postfix mail system secured by an OSSEC HIDS
- Designing documents
- Technical writing : Document Design
- Marketing Excellence: Microsoft
- Forensic Biology
- Management and Information Systems and Strategy
- Assignment 6
- GMO food
- Provide three pieces of advice for marketers seeking to use digital technology as part of their marketing strategy. Your answers should include appropriate academic references and, where necessary, evidence from marketing practice.
- STATS MANAGERIAL REPORT
- sockets to create a client server application
- program by C#
- state court system.
- Court Alternatives for the Mentally ILL
- Identifying and analyzing DNA from a person who has been in prison for 10 years.