CS809 - Digital Forensics and Incidence Response
| TIMETABLE | TEACHING MATERIAL |
| Credits | 15 |
| Level | 5 |
| Semester | Term 1 |
| Availability | Not available as an elective. |
| Prerequisites | None. |
| Learning Activities Breakdown | 2 campus day, 4 online Q&A sessions, online study and assignment preparation. |
| Items of Assessment | 3 |
| Assessment | 100% by coursework. An individual assignment 45%, a group assignment 45%, participation 10% (online quizzes). |
| ILO Assessment Mapping | |
| Pedagogical Methods Used to Support Competency Development | |
| Resit | 100% by coursework. |
| Lecturer | Sotirios Terzis |
Aims and Objectives
The aim of this class is to provide an in depth coverage of incidence management and response procedures and digital investigations techniques from the perspective of enhancing organisational cyber resilience while ensuring compliance with legal and regulatory requirements.
Learning Outcomes
At the end of this class learners should be able:
- To understand the different types of investigations, their associated evidence requirements, and the procedures of ensuring evidence integrity in accordance with legal requirements and industry guidelines.
- To appreciate the different digital forensic investigation techniques, their application taking into consideration the associated legal and ethical issues, and the reporting of their findings.
- To understand the important role that incidence management and response plays in supporting cyber resilience within organisations, and meeting legal and regulatory compliance requirements.
- To design and implement incidence management and response procedures to meet organisational needs and as a means of cyber resilience enhancement.
- To appreciate the different forms and evolving nature of cyber crime and the requirements it places for forensic readiness and incidence management and response preparedness on organisations.
Syllabus
Investigation Types: Administrative, Criminal, Civil, Regulatory
Evidence Types, Chain of Evidence, Evidence Collection (media, network, software and hardware/embedded device analysis),
Investigation Process: ACPO Guidelines, Ethical Conduct in Investigations, Reporting and Document Investigations
Computer Crime: Military & Intelligence Attacks; Business Attacks; Financial Attacks; Terrorist Attacks; Grudge Attacks; Thrill Attacks
Managing Incident Response: Forensic Readiness, Computer Security Incident Response Teams, Reporting
NIST Cyber Security Framework 2.0
Recommended Reading
This list is indicative only – the class lecturer may recommend alternative reading material. Please do not purchase any of the reading material listed below until you have confirmed with the class lecturer that it will be used for this class.
- Sheward, Mike. Hands-on Incident Response and Digital Forensics. Swindon, UK: BCS Learning & Development, 2018.
- Johansen, Gerard. Digital Forensics and Incident Response : Incident Response Tools and Techniques for Effective Cyber Threat Response. 3rd edition.. Birmingham, UK: Packt Publishing Ltd., 2022.
- Kävrestad, Joakim, Birath, Marcus, Clarke, Nathan, Fundamentals of digital forensics : a guide to theory, research, and applications. 3rd edition, Cham: Springer 2024.
Last updated: 2026-07-06 12:37:15